Creative Media Agency (Pty) Ltd
Reg: 2025/089369/07
Group: Digital Business Solutions Holdings (Pty) Ltd (Reg: 2025/115849/07)
299 Pendoring Street, Northcliff, Johannesburg, South Africa
This Data Processing Addendum ("DPA") forms part of the AgenticSA Terms of Service and any applicable Service Agreement between Creative Media Agency (Pty) Ltd ("AgenticSA", "CMA", "we", "us" or "Operator") and the business customer using AgenticSA ("Customer").
Where Customer Personal Information is processed through AgenticSA on behalf of the Customer, this DPA applies automatically unless the parties enter into a separate written data-processing agreement.
1Purpose
This DPA establishes the terms on which AgenticSA processes Customer Personal Information in connection with services including:
- SMS and WhatsApp AI;
- Email AI;
- Voice AI;
- AI Front Desk;
- CRM;
- automation;
- appointment booking;
- workflows;
- communications;
- integrations; and
- related implementation and support.
2Definitions
"POPIA" means the Protection of Personal Information Act 4 of 2013.
"Personal Information", "Processing", "Responsible Party", "Operator" and "Data Subject" have the meanings given to them under POPIA where applicable.
For international customers:
- "Controller" corresponds generally to the party determining the purposes and means of processing.
- "Processor" corresponds generally to a party processing personal data on behalf of a Controller.
- "Subprocessor" means a further processor engaged to assist with processing.
"Customer Personal Information" means Personal Information processed by AgenticSA on behalf of Customer in providing the Services.
3Roles
For Customer Personal Information:
Customer generally acts as the Responsible Party / Controller.
Customer determines why and how its customer, prospect, employee or other contact information is processed.
Creative Media Agency / AgenticSA generally acts as Operator / Processor.
AgenticSA processes Customer Personal Information in order to provide the Services and according to Customer's documented instructions.
Where Customer itself acts as an Operator/Processor for another Responsible Party/Controller, AgenticSA may act as a further Operator/Subprocessor.
This allocation does not apply where AgenticSA independently determines the purposes and means of processing information for its own business purposes, such as its own billing, account administration, security and direct customer relationship.
4Customer Responsibilities
Customer is responsible for:
- ensuring that Customer Personal Information is lawfully collected;
- establishing an appropriate lawful basis for processing;
- providing required privacy notices;
- obtaining consent where required;
- maintaining consent records where appropriate;
- complying with direct-marketing requirements;
- honouring objections and opt-outs;
- ensuring instructions to AgenticSA are lawful;
- ensuring data supplied is relevant and not excessive;
- determining appropriate retention requirements;
- handling applicable Data Subject requests; and
- complying with industry-specific requirements.
5Processing Instructions
Customer instructs AgenticSA to process Customer Personal Information as reasonably necessary to:
- provide the contracted AgenticSA services;
- configure AI Employees;
- communicate through authorised channels;
- store and manage CRM records;
- perform approved automations;
- process AI interactions;
- facilitate appointment booking;
- provide technical support;
- maintain security;
- troubleshoot;
- maintain and improve configured services; and
- perform other documented instructions consistent with the Agreement.
AgenticSA will not knowingly process Customer Personal Information for materially unrelated purposes except where required or permitted by applicable law.
6Details of Processing
Categories of Data Subjects
Depending on Customer's use, information may relate to:
- prospects;
- leads;
- customers;
- clients;
- callers;
- website visitors;
- employees;
- contractors;
- suppliers;
- business contacts; and
- other persons communicating with Customer.
Categories of Information
Information may include:
- name;
- email;
- telephone number;
- business information;
- messages;
- emails;
- SMS content;
- WhatsApp conversations;
- call audio;
- call transcripts;
- appointment information;
- enquiry information;
- CRM records;
- communication preferences;
- lead information;
- technical information; and
- information voluntarily supplied during interactions.
Nature of Processing
Processing may include:
- collection;
- receipt;
- recording;
- storage;
- organisation;
- retrieval;
- analysis;
- AI processing;
- transmission;
- communication;
- updating;
- routing;
- deletion; and
- other processing necessary to provide the Services.
Duration
Processing generally continues for the duration of the Customer's use of AgenticSA and any reasonable post-termination period required for account closure, backups, legal obligations or agreed data return/deletion.
7Special Personal Information
AgenticSA is not designed to encourage indiscriminate collection of special or highly sensitive Personal Information.
Customer must not instruct AgenticSA to process sensitive information unnecessarily.
Where Customer requires such processing, Customer is responsible for determining that appropriate legal authority, safeguards and contractual arrangements are in place.
8Confidentiality
AgenticSA will take reasonable steps to ensure persons authorised to process Customer Personal Information are subject to appropriate confidentiality obligations.
9Security
AgenticSA will maintain reasonable technical and organisational measures appropriate to the nature and risks of processing.
Depending on the underlying services used, these may include:
- authentication;
- role-based access controls;
- access restrictions;
- encryption;
- secure transmission;
- logging;
- monitoring;
- backup mechanisms;
- security testing; and
- provider security controls.
AgenticSA uses third-party infrastructure and cannot represent that all Customer Personal Information is hosted exclusively by Creative Media Agency.
10Underlying Platform Security
Where AgenticSA services use HighLevel infrastructure, HighLevel currently states that its applicable Personal Data is protected using measures including:
- AES-256 encryption at rest;
- TLS 1.2+ in transit;
- role-based access controls;
- authentication controls;
- managed AWS and Google Cloud infrastructure;
- vulnerability testing;
- penetration testing;
- backups; and
- logging/security controls.
These are underlying provider measures and should not be interpreted as an independent security certification of Creative Media Agency or AgenticSA.
11Security Incidents
Where AgenticSA becomes aware of a confirmed security compromise involving Customer Personal Information processed on Customer's behalf, AgenticSA will notify Customer without undue delay where required by applicable law or contractual obligation.
AgenticSA will provide reasonably available information necessary to assist Customer in evaluating its notification obligations.
Customer remains responsible for determining its obligations as Responsible Party unless applicable law places the relevant obligation directly on AgenticSA.
12Subprocessors / Further Operators
Customer authorises AgenticSA to use third-party service providers reasonably necessary to provide the Services.
These may include providers supporting:
- CRM infrastructure;
- cloud hosting;
- AI models;
- telecommunications;
- SMS;
- WhatsApp;
- email;
- Voice AI;
- telephone numbers;
- automation;
- payment processing;
- support;
- analytics; and
- security.
Such providers may process Customer Personal Information as further Operators/Subprocessors.
AgenticSA will maintain appropriate contractual or other safeguards with material providers where required.
13HighLevel and Downstream Providers
AgenticSA and CMART™ may use HighLevel infrastructure. HighLevel in turn uses contracted processors/subprocessors. Accordingly, the processing chain may operate broadly as:
Customer
Responsible Party / Controller
↓
Creative Media Agency / AgenticSA
Operator / Processor
↓
HighLevel and other contracted infrastructure providers
Further Operator / Subprocessor
↓
Approved downstream providers
AI, telecommunications, email, cloud and other services.
The exact providers used may vary depending on the AgenticSA functionality selected.
14International Processing
Customer acknowledges that AgenticSA uses global technology providers and Customer Personal Information may therefore be processed or stored outside South Africa.
AgenticSA does not represent that all information is stored exclusively in South Africa.
Where Personal Information is transferred outside South Africa, the parties will seek to rely on an appropriate basis permitted under section 72 of POPIA, including appropriate contractual safeguards, adequate protection, consent or another applicable basis.
15Data Subject Requests
Where AgenticSA receives a request relating to Customer Personal Information for which Customer is the Responsible Party, AgenticSA may refer the request to Customer.
AgenticSA will provide reasonable assistance, taking into account the nature of processing and available functionality, where Customer requires assistance responding to applicable Data Subject rights.
16Correction and Deletion
AgenticSA will provide reasonable assistance, subject to available technical functionality and applicable law, where Customer instructs AgenticSA to correct, delete, restrict or otherwise appropriately handle Customer Personal Information.
17Return or Deletion After Termination
Following termination, Customer should export information it requires before account access ends.
Subject to technical limitations, backup cycles, legal requirements and provider retention policies, Customer Personal Information will thereafter be deleted, anonymised or otherwise handled according to applicable retention practices.
AgenticSA may retain information where required by law or reasonably necessary for legal claims, fraud prevention, security or contractual records.
18Audit and Information
Upon reasonable request, AgenticSA may provide information reasonably necessary to demonstrate compliance with this DPA.
Audit requests must:
- be reasonable;
- respect confidentiality;
- not compromise another customer's information;
- not compromise system security;
- avoid unreasonable operational disruption; and
- be subject to appropriate confidentiality arrangements.
19Customer Security Responsibilities
Customer remains responsible for:
- protecting account credentials;
- managing authorised users;
- configuring access appropriately;
- removing former users;
- protecting connected accounts;
- securing customer devices; and
- notifying AgenticSA promptly of suspected compromise.
20AI Processing
Where Customer enables AI functionality, Customer instructs AgenticSA and its relevant technology providers to process information reasonably necessary to provide the requested AI functionality.
Customer should avoid submitting unnecessary Personal Information to AI systems.
Customer remains responsible for determining whether the selected AI use case is appropriate for the information being processed.
21Direct Marketing and Communications
Where Customer uses AgenticSA to communicate with Data Subjects, Customer is responsible for establishing the applicable lawful basis, consent or other authority.
Customer must honour applicable:
- objections;
- opt-outs;
- withdrawals;
- do-not-contact requests; and
- communication restrictions.
22Voice Recordings and Transcripts
Where Voice AI or call recording is enabled, Customer Personal Information may include:
- telephone numbers;
- caller identity;
- call audio;
- transcripts;
- summaries;
- sentiment or interaction information;
- appointment information; and
- information voluntarily disclosed by callers.
Customer is responsible for determining whether call recording and related processing are lawful for its intended use.
23Customer Warranties
Customer warrants that:
- its processing instructions are lawful;
- it is authorised to provide Customer Personal Information;
- its use of AgenticSA does not knowingly violate applicable Data Subject rights; and
- it will not deliberately use AgenticSA to circumvent privacy law.
24Order of Precedence
Where this DPA conflicts with the general AgenticSA Terms of Service regarding processing of Customer Personal Information, this DPA takes precedence on that specific data-protection issue.
Mandatory applicable law takes precedence over contractual terms.
25Changes
AgenticSA may update this DPA where reasonably necessary to reflect:
- legal developments;
- provider changes;
- security developments;
- new functionality; or
- changes in processing.
Material changes will be handled in accordance with applicable contractual and legal requirements.
26Governing Law
This DPA is governed by the laws of the Republic of South Africa unless another mandatory applicable law requires otherwise.
27Data Protection Contact
Information Officer: Yvette Pretorius
Creative Media Agency (Pty) Ltd
Registration Number: 2025/089369/07
299 Pendoring Street, Northcliff, Johannesburg, South Africa
Privacy & Information Requests: hello@creativemediagency.co.za