Legal Agreement

    AgenticSA Data Processing Addendum

    Last Updated: 2 September 2026

    This Data Processing Addendum ("DPA") forms part of the AgenticSA Terms of Service and any applicable Service Agreement between Creative Media Agency (Pty) Ltd ("AgenticSA", "CMA", "we", "us" or "Operator") and the business customer using AgenticSA ("Customer").

    Where Customer Personal Information is processed through AgenticSA on behalf of the Customer, this DPA applies automatically unless the parties enter into a separate written data-processing agreement.

    Creative Media Agency (Pty) Ltd

    Reg: 2025/089369/07

    Group: Digital Business Solutions Holdings (Pty) Ltd (Reg: 2025/115849/07)

    299 Pendoring Street, Northcliff, Johannesburg, South Africa

    hello@creativemediagency.co.za

    This Data Processing Addendum ("DPA") forms part of the AgenticSA Terms of Service and any applicable Service Agreement between Creative Media Agency (Pty) Ltd ("AgenticSA", "CMA", "we", "us" or "Operator") and the business customer using AgenticSA ("Customer").

    Where Customer Personal Information is processed through AgenticSA on behalf of the Customer, this DPA applies automatically unless the parties enter into a separate written data-processing agreement.

    1Purpose

    This DPA establishes the terms on which AgenticSA processes Customer Personal Information in connection with services including:

    • SMS and WhatsApp AI;
    • Email AI;
    • Voice AI;
    • AI Front Desk;
    • CRM;
    • automation;
    • appointment booking;
    • workflows;
    • communications;
    • integrations; and
    • related implementation and support.

    2Definitions

    "POPIA" means the Protection of Personal Information Act 4 of 2013.

    "Personal Information", "Processing", "Responsible Party", "Operator" and "Data Subject" have the meanings given to them under POPIA where applicable.

    For international customers:

    • "Controller" corresponds generally to the party determining the purposes and means of processing.
    • "Processor" corresponds generally to a party processing personal data on behalf of a Controller.
    • "Subprocessor" means a further processor engaged to assist with processing.

    "Customer Personal Information" means Personal Information processed by AgenticSA on behalf of Customer in providing the Services.

    3Roles

    For Customer Personal Information:

    Customer generally acts as the Responsible Party / Controller.

    Customer determines why and how its customer, prospect, employee or other contact information is processed.

    Creative Media Agency / AgenticSA generally acts as Operator / Processor.

    AgenticSA processes Customer Personal Information in order to provide the Services and according to Customer's documented instructions.

    Where Customer itself acts as an Operator/Processor for another Responsible Party/Controller, AgenticSA may act as a further Operator/Subprocessor.

    This allocation does not apply where AgenticSA independently determines the purposes and means of processing information for its own business purposes, such as its own billing, account administration, security and direct customer relationship.

    4Customer Responsibilities

    Customer is responsible for:

    • ensuring that Customer Personal Information is lawfully collected;
    • establishing an appropriate lawful basis for processing;
    • providing required privacy notices;
    • obtaining consent where required;
    • maintaining consent records where appropriate;
    • complying with direct-marketing requirements;
    • honouring objections and opt-outs;
    • ensuring instructions to AgenticSA are lawful;
    • ensuring data supplied is relevant and not excessive;
    • determining appropriate retention requirements;
    • handling applicable Data Subject requests; and
    • complying with industry-specific requirements.

    5Processing Instructions

    Customer instructs AgenticSA to process Customer Personal Information as reasonably necessary to:

    • provide the contracted AgenticSA services;
    • configure AI Employees;
    • communicate through authorised channels;
    • store and manage CRM records;
    • perform approved automations;
    • process AI interactions;
    • facilitate appointment booking;
    • provide technical support;
    • maintain security;
    • troubleshoot;
    • maintain and improve configured services; and
    • perform other documented instructions consistent with the Agreement.

    AgenticSA will not knowingly process Customer Personal Information for materially unrelated purposes except where required or permitted by applicable law.

    6Details of Processing

    Categories of Data Subjects

    Depending on Customer's use, information may relate to:

    • prospects;
    • leads;
    • customers;
    • clients;
    • callers;
    • website visitors;
    • employees;
    • contractors;
    • suppliers;
    • business contacts; and
    • other persons communicating with Customer.

    Categories of Information

    Information may include:

    • name;
    • email;
    • telephone number;
    • business information;
    • messages;
    • emails;
    • SMS content;
    • WhatsApp conversations;
    • call audio;
    • call transcripts;
    • appointment information;
    • enquiry information;
    • CRM records;
    • communication preferences;
    • lead information;
    • technical information; and
    • information voluntarily supplied during interactions.

    Nature of Processing

    Processing may include:

    • collection;
    • receipt;
    • recording;
    • storage;
    • organisation;
    • retrieval;
    • analysis;
    • AI processing;
    • transmission;
    • communication;
    • updating;
    • routing;
    • deletion; and
    • other processing necessary to provide the Services.

    Duration

    Processing generally continues for the duration of the Customer's use of AgenticSA and any reasonable post-termination period required for account closure, backups, legal obligations or agreed data return/deletion.

    7Special Personal Information

    AgenticSA is not designed to encourage indiscriminate collection of special or highly sensitive Personal Information.

    Customer must not instruct AgenticSA to process sensitive information unnecessarily.

    Where Customer requires such processing, Customer is responsible for determining that appropriate legal authority, safeguards and contractual arrangements are in place.

    8Confidentiality

    AgenticSA will take reasonable steps to ensure persons authorised to process Customer Personal Information are subject to appropriate confidentiality obligations.

    9Security

    AgenticSA will maintain reasonable technical and organisational measures appropriate to the nature and risks of processing.

    Depending on the underlying services used, these may include:

    • authentication;
    • role-based access controls;
    • access restrictions;
    • encryption;
    • secure transmission;
    • logging;
    • monitoring;
    • backup mechanisms;
    • security testing; and
    • provider security controls.

    AgenticSA uses third-party infrastructure and cannot represent that all Customer Personal Information is hosted exclusively by Creative Media Agency.

    10Underlying Platform Security

    Where AgenticSA services use HighLevel infrastructure, HighLevel currently states that its applicable Personal Data is protected using measures including:

    • AES-256 encryption at rest;
    • TLS 1.2+ in transit;
    • role-based access controls;
    • authentication controls;
    • managed AWS and Google Cloud infrastructure;
    • vulnerability testing;
    • penetration testing;
    • backups; and
    • logging/security controls.

    These are underlying provider measures and should not be interpreted as an independent security certification of Creative Media Agency or AgenticSA.

    11Security Incidents

    Where AgenticSA becomes aware of a confirmed security compromise involving Customer Personal Information processed on Customer's behalf, AgenticSA will notify Customer without undue delay where required by applicable law or contractual obligation.

    AgenticSA will provide reasonably available information necessary to assist Customer in evaluating its notification obligations.

    Customer remains responsible for determining its obligations as Responsible Party unless applicable law places the relevant obligation directly on AgenticSA.

    12Subprocessors / Further Operators

    Customer authorises AgenticSA to use third-party service providers reasonably necessary to provide the Services.

    These may include providers supporting:

    • CRM infrastructure;
    • cloud hosting;
    • AI models;
    • telecommunications;
    • SMS;
    • WhatsApp;
    • email;
    • Voice AI;
    • telephone numbers;
    • automation;
    • payment processing;
    • support;
    • analytics; and
    • security.

    Such providers may process Customer Personal Information as further Operators/Subprocessors.

    AgenticSA will maintain appropriate contractual or other safeguards with material providers where required.

    13HighLevel and Downstream Providers

    AgenticSA and CMART™ may use HighLevel infrastructure. HighLevel in turn uses contracted processors/subprocessors. Accordingly, the processing chain may operate broadly as:

    Customer

    Responsible Party / Controller

    Creative Media Agency / AgenticSA

    Operator / Processor

    HighLevel and other contracted infrastructure providers

    Further Operator / Subprocessor

    Approved downstream providers

    AI, telecommunications, email, cloud and other services.

    The exact providers used may vary depending on the AgenticSA functionality selected.

    14International Processing

    Customer acknowledges that AgenticSA uses global technology providers and Customer Personal Information may therefore be processed or stored outside South Africa.

    AgenticSA does not represent that all information is stored exclusively in South Africa.

    Where Personal Information is transferred outside South Africa, the parties will seek to rely on an appropriate basis permitted under section 72 of POPIA, including appropriate contractual safeguards, adequate protection, consent or another applicable basis.

    15Data Subject Requests

    Where AgenticSA receives a request relating to Customer Personal Information for which Customer is the Responsible Party, AgenticSA may refer the request to Customer.

    AgenticSA will provide reasonable assistance, taking into account the nature of processing and available functionality, where Customer requires assistance responding to applicable Data Subject rights.

    16Correction and Deletion

    AgenticSA will provide reasonable assistance, subject to available technical functionality and applicable law, where Customer instructs AgenticSA to correct, delete, restrict or otherwise appropriately handle Customer Personal Information.

    17Return or Deletion After Termination

    Following termination, Customer should export information it requires before account access ends.

    Subject to technical limitations, backup cycles, legal requirements and provider retention policies, Customer Personal Information will thereafter be deleted, anonymised or otherwise handled according to applicable retention practices.

    AgenticSA may retain information where required by law or reasonably necessary for legal claims, fraud prevention, security or contractual records.

    18Audit and Information

    Upon reasonable request, AgenticSA may provide information reasonably necessary to demonstrate compliance with this DPA.

    Audit requests must:

    • be reasonable;
    • respect confidentiality;
    • not compromise another customer's information;
    • not compromise system security;
    • avoid unreasonable operational disruption; and
    • be subject to appropriate confidentiality arrangements.

    19Customer Security Responsibilities

    Customer remains responsible for:

    • protecting account credentials;
    • managing authorised users;
    • configuring access appropriately;
    • removing former users;
    • protecting connected accounts;
    • securing customer devices; and
    • notifying AgenticSA promptly of suspected compromise.

    20AI Processing

    Where Customer enables AI functionality, Customer instructs AgenticSA and its relevant technology providers to process information reasonably necessary to provide the requested AI functionality.

    Customer should avoid submitting unnecessary Personal Information to AI systems.

    Customer remains responsible for determining whether the selected AI use case is appropriate for the information being processed.

    21Direct Marketing and Communications

    Where Customer uses AgenticSA to communicate with Data Subjects, Customer is responsible for establishing the applicable lawful basis, consent or other authority.

    Customer must honour applicable:

    • objections;
    • opt-outs;
    • withdrawals;
    • do-not-contact requests; and
    • communication restrictions.

    22Voice Recordings and Transcripts

    Where Voice AI or call recording is enabled, Customer Personal Information may include:

    • telephone numbers;
    • caller identity;
    • call audio;
    • transcripts;
    • summaries;
    • sentiment or interaction information;
    • appointment information; and
    • information voluntarily disclosed by callers.

    Customer is responsible for determining whether call recording and related processing are lawful for its intended use.

    23Customer Warranties

    Customer warrants that:

    • its processing instructions are lawful;
    • it is authorised to provide Customer Personal Information;
    • its use of AgenticSA does not knowingly violate applicable Data Subject rights; and
    • it will not deliberately use AgenticSA to circumvent privacy law.

    24Order of Precedence

    Where this DPA conflicts with the general AgenticSA Terms of Service regarding processing of Customer Personal Information, this DPA takes precedence on that specific data-protection issue.

    Mandatory applicable law takes precedence over contractual terms.

    25Changes

    AgenticSA may update this DPA where reasonably necessary to reflect:

    • legal developments;
    • provider changes;
    • security developments;
    • new functionality; or
    • changes in processing.

    Material changes will be handled in accordance with applicable contractual and legal requirements.

    26Governing Law

    This DPA is governed by the laws of the Republic of South Africa unless another mandatory applicable law requires otherwise.

    27Data Protection Contact

    Information Officer: Yvette Pretorius

    Creative Media Agency (Pty) Ltd

    Registration Number: 2025/089369/07

    299 Pendoring Street, Northcliff, Johannesburg, South Africa

    Privacy & Information Requests: hello@creativemediagency.co.za