Data Processing Agreement

Last updated: July 17, 2026

Draft — pending legal review, not yet signed with any customer

This is a starting-point draft based on common POPIA/GDPR-style data processing agreements. It has not been reviewed by a lawyer, has not been countersigned by any institution, and should not be relied on as a binding agreement until qualified legal counsel has reviewed it and both parties have signed it.

1. Parties and Roles

This Data Processing Agreement (“DPA”) forms part of the agreement between My Space-Edu (“Processor”) and the institution or training provider subscribing to the platform (“Responsible Party”, using POPIA’s terminology — equivalent to a “Controller” under GDPR). The Responsible Party determines why and how personal information is processed; the Processor processes personal information only on the Responsible Party’s instructions, as set out below.

2. Subject Matter and Duration

The Processor processes personal information on behalf of the Responsible Party for the purpose of providing the My Space-Edu learner management platform — including enrolment, assessment, moderation, attendance, and SETA/QCTO reporting functionality — for the duration of the subscription agreement between the parties.

3. Categories of Data Subjects and Personal Information

Data subjects: students/learners, lecturers/facilitators, assessors, moderators, and administrative staff of the Responsible Party.

Categories of personal information processed include:

  • Identity and contact details (name, email, phone, physical address)
  • Academic records (enrolments, assessments, grades, attendance, certificates)
  • Special personal information required for SETA/QCTO compliance reporting — race/ethnicity, disability status, and home language — collected only where the Responsible Party has configured the platform to collect it
  • South African ID numbers, where captured by the Responsible Party for student records
  • System usage data (login activity, audit logs)

4. Processor Obligations

  • Process personal information only on the Responsible Party’s documented instructions
  • Ensure encryption of personal information in transit and at rest
  • Restrict access to personal information to personnel who need it to operate the platform
  • Assist the Responsible Party in responding to data subject access, correction, and deletion requests
  • Notify the Responsible Party without undue delay after becoming aware of a personal information breach
  • Not engage a sub-processor without prior notice to the Responsible Party

5. Sub-processors and Cross-Border Transfer

The platform is hosted on Supabase infrastructure, which may store and process data outside South Africa. Under POPIA section 72, cross-border transfer of personal information requires either the data subject’s consent, an adequate level of protection in the destination country, or another recognised legal basis. This is flagged here as a point that requires explicit legal review before this DPA is finalised — it is not yet resolved.

6. Data Retention and Deletion

On termination of the subscription agreement, the Processor will, at the Responsible Party’s election, delete or return all personal information processed on its behalf, except where retention is required by law (for example, SETA/QCTO record-keeping requirements).

7. Security Measures

The Processor maintains technical and organisational measures appropriate to the risk, including encrypted connections, role-based access control, audit logging, and regular security review. A full security measures annex, and an incident response process with defined notification timelines, are still to be finalised and attached to this DPA.

Contact Us

Questions about this draft, or about arranging a signed DPA, can be sent to:
privacy@myspace-edu.co.za

Data Processing Agreement | My Space-Edu