Skip to content

Start here

Data processing agreement

Last updated 8 October 2026

Clients that pay by card accept this agreement as part of the terms of service. Clients on an order form can sign it as a separate document, with the client's details filled in where the square brackets are.

Parties

  1. [Client legal name], registration number [number], of [address] (the "Client"), the responsible party; and
  2. Under Bridges Entity (Pty) Ltd, trading as Underwing, registration number 2016/469951/07, of 127 East Road, 47 3rd on East, Pomona, Kempton Park, South Africa ("Underwing"), the operator.

Background

A. The Client uses Underwing's security-awareness training programme (the "Service") under the Underwing terms of service or a signed order form (the "Main Agreement").

B. To provide the Service, Underwing processes personal information about the Client's people on the Client's behalf.

C. Under the Protection of Personal Information Act 4 of 2013 ("POPIA"), the Client is the responsible party for that information and Underwing is its operator. Sections 20 and 21 of POPIA require a written contract between them. This is that contract.

1. Definitions

1.1 Words defined in POPIA have the same meaning here, including personal information, processing, responsible party, operator, data subject, special personal information and Regulator.

1.2 Client Personal Information means the personal information described in Schedule 1 that Underwing processes on the Client's behalf.

1.3 Security Compromise means any situation where there are reasonable grounds to believe that Client Personal Information has been accessed or acquired by an unauthorised person.

1.4 Sub-processor means a third party that Underwing engages to process Client Personal Information.

2. Scope and roles

2.1 This agreement applies to Client Personal Information only. Schedule 1 describes the processing.

2.2 Underwing is the responsible party, not the operator, for:

  • the personal information of the Client's managers and billing contacts, as needed to run their accounts and bill the Client;
  • its own marketing;
  • voice recordings and clones made for the Voice Test add-on, which Underwing collects directly from each participant with their explicit written consent; and
  • anonymised benchmarks under clause 12.

Underwing's privacy policy covers that processing.

2.3 If this agreement and the Main Agreement conflict on the protection of personal information, this agreement applies.

3. Underwing's obligations

Underwing will:

3.1 Process only on instructions. Process Client Personal Information only with the Client's knowledge or authorisation, as POPIA section 20(a) requires. The Main Agreement, this agreement, and the Client's use of the Service's settings and features are the Client's instructions. Underwing will tell the Client if it believes an instruction breaks POPIA.

3.2 Not use it for its own purposes, except to create anonymised benchmarks under clause 12. Underwing will not sell Client Personal Information, use it for marketing, or use it to train artificial intelligence models.

3.3 Keep it confidential. Treat Client Personal Information as confidential and not disclose it unless the law requires it or the Client instructs it, as section 20(b) requires. If the law requires disclosure, Underwing will tell the Client first where it is allowed to.

3.4 Limit access. Allow access only to Underwing staff who need it to provide or support the Service, who are bound by confidentiality, and who have been trained in handling personal information.

3.5 Keep it secure. Establish and maintain the security measures described in POPIA section 19, including those in Schedule 2, as section 21(1) requires.

3.6 Keep it in South Africa. Store Client Personal Information in South Africa, except for the limited processing by Sub-processors set out in Schedule 3 and clause 7.

3.7 Keep it to a minimum. Not collect free-text answers, not keep a learner's per-question answers against their name once they have been converted into field-mark scores, and not process special personal information as part of Client Personal Information.

3.8 Log access. Keep an append-only audit log of sign-ins, exports, views of individual learners' results, billing changes and every action by Underwing staff, and make relevant extracts available to the Client on request.

4. The Client's obligations

The Client will:

4.1 Have a lawful basis under POPIA for enrolling its people and for giving Underwing their personal information.

4.2 Tell its people about the programme before enrolling them: what it is, what personal information it uses, and what managers can see. Underwing also tells each learner directly.

4.3 Not use individual results in disciplinary action, performance reviews, or decisions about pay, promotion or dismissal, as the Main Agreement requires.

4.4 Not give Underwing special personal information. If the Client orders the Voice Test, Underwing collects each participant's voice directly, as responsible party, with their explicit written consent for a stated purpose. The recording and any clone are deleted the same day, and any processing outside South Africa happens only where the law allows, including any prior authorisation the Regulator requires under POPIA section 57.

4.5 Not enrol anyone under 18 without first agreeing it with Underwing in writing.

4.6 Keep manager access limited to people who need it, and remove access promptly when someone leaves or changes role.

5. Security measures

5.1 Underwing will maintain the security measures in Schedule 2, or measures that give at least the same protection.

5.2 Underwing will review these measures at least once a year, and when the Service changes in a way that affects risk, as POPIA section 19(2) requires.

5.3 Underwing will commission an independent penetration test before its first corporate client goes live, and at least once a year after that, and share a summary of the findings and fixes with the Client on request.

6. Sub-processors

6.1 The Client authorises Underwing to use the Sub-processors listed in Schedule 3.

6.2 Underwing will put a written agreement in place with each Sub-processor that protects personal information at least as well as this agreement.

6.3 Underwing will give the Client at least 30 days' notice by email before adding or replacing a Sub-processor that processes Client Personal Information, and will update Schedule 3 on its trust centre.

6.4 If the Client has reasonable data protection grounds to object, it may do so in writing within that period. The parties will try in good faith to resolve the objection. If they can't, the Client may end the affected Service without penalty and receive a refund of any prepaid fees for the period after it ends.

6.5 Underwing remains responsible to the Client for the work of its Sub-processors.

7. Cross-border transfers

7.1 Client Personal Information is stored in South Africa (Amazon Web Services, Cape Town region, af-south-1).

7.2 Some Sub-processors process limited personal information outside South Africa, as Schedule 3 shows. Underwing will transfer Client Personal Information outside South Africa only where POPIA section 72 allows. It does this through data processing agreements with each Sub-processor that include standard contractual clauses, giving protection substantially similar to POPIA.

7.3 Underwing will not transfer special personal information outside South Africa unless the law allows it, including any prior authorisation the Regulator requires.

8. Security Compromises

8.1 Immediate notice. Underwing will notify the Client immediately when there are reasonable grounds to believe that Client Personal Information has been accessed or acquired by an unauthorised person, as POPIA section 21(2) requires. Underwing will notify the Client's nominated contact in Schedule 4 by email and by telephone.

8.2 What the notice contains. As far as the information is available at the time (and updated as it becomes available):

  • what happened and when, and when it was discovered;
  • the categories and approximate number of data subjects and records affected;
  • the likely consequences;
  • what Underwing has done and will do to contain it and reduce harm;
  • a contact person at Underwing.

8.3 Help with the Client's notifications. The Client, as responsible party, decides on and makes the notifications that POPIA section 22 requires, to the Regulator (through its eServices portal, the required channel since 1 April 2025) and to affected data subjects. Underwing will give the Client the information and help it reasonably needs to do so.

8.4 Underwing will not notify the Regulator or the Client's data subjects about a Security Compromise affecting Client Personal Information unless the Client instructs it to, or the law requires it.

8.5 Underwing will keep a record of every Security Compromise, its effects and the action taken, and will not charge the Client for help under this clause where the compromise resulted from Underwing's breach of this agreement.

9. Requests from data subjects

9.1 If Underwing receives a request from one of the Client's data subjects (for example to access, correct or delete information, or to object to processing), it will forward the request to the Client within 5 business days and tell the data subject it has done so. Underwing won't respond to the request itself unless the Client asks it to.

9.2 Underwing will help the Client respond to data subject requests within the time POPIA and PAIA allow, through the Service's features (such as editing and removing learners and the evidence export) or, where these aren't enough, by reasonable help on request.

10. Other help

Underwing will give the Client reasonable help with:

  • personal information impact assessments relating to the Service;
  • enquiries, investigations or assessments by the Regulator relating to the Service; and
  • completing the Client's reasonable security questionnaires.

11. Return and deletion

11.1 During the agreement. When a manager removes a learner, Underwing deletes that learner's personal information within 30 days, except entries in the audit log.

11.2 Before the end. Managers can export completion records and certificates at any time before the agreement ends.

11.3 After the end. Underwing will delete Client Personal Information within 90 days after the Main Agreement ends, unless the law requires it to keep some of it. Encrypted backups are overwritten on a rolling cycle of 14 days after deletion from the live systems.

11.4 Anonymised aggregates. Underwing may keep anonymised aggregates that do not identify any person or the Client.

11.5 Exceptions. Underwing keeps audit logs for 2 years, and billing records for 5 years as the Tax Administration Act requires. These records do not contain learners' results.

11.6 On request, Underwing will confirm deletion in writing.

12. Anonymised benchmarks

12.1 Underwing may combine results from the Client with results from other clients to produce anonymised statistics, for example "teams of this size tend to miss borrowed trust".

12.2 Benchmarks contain no names, email addresses or organisation names. Underwing reports a benchmark only when it draws on at least 100 people, so that no team or person can be identified.

12.3 Underwing is the responsible party for creating and using these benchmarks.

13. Audits

13.1 Underwing will make available the information reasonably needed to show that it complies with this agreement, including its security documentation, a completed security questionnaire and a summary of its latest penetration test.

13.2 If that information isn't enough, the Client (or an independent auditor it appoints, bound by confidentiality) may audit Underwing's compliance with this agreement:

  • on at least 30 days' written notice;
  • no more than once in any 12 months, unless there has been a Security Compromise affecting Client Personal Information or the Regulator requires it;
  • during South African business hours, without unreasonably disrupting Underwing's operations;
  • without access to other clients' information or to information that would weaken Underwing's security.

13.3 Each party pays its own costs of an audit, unless the audit reveals a material breach by Underwing, in which case Underwing pays the Client's reasonable costs.

14. Liability

The liability provisions of the Main Agreement apply to this agreement.

15. Term

15.1 This agreement starts when the Main Agreement starts (including a free Team Spot Check) and continues while Underwing processes Client Personal Information.

15.2 Clauses 3.3, 8, 11 and 13 continue after the Main Agreement ends until all Client Personal Information has been deleted.

16. General

16.1 This agreement is governed by the law of the Republic of South Africa.

16.2 Underwing may update this agreement to reflect changes in law or in its Sub-processors, on the notice set out in clause 6.3 or in the Main Agreement. An update may not reduce the protection given to Client Personal Information.


Schedule 1: Description of the processing

Item Description
Subject matter Delivering a security-awareness training programme and free Team Spot Check to the Client's people, and reporting results to the Client's managers
Duration The term of the Main Agreement, plus up to 90 days for deletion
Nature of the processing Collecting, storing, organising, using to send emails, scoring, reporting, exporting and deleting
Purpose To enrol learners, deliver video lessons, quizzes, challenges and alerts, send reminders, show progress and results to managers, issue certificates, provide evidence exports, and keep the Service secure
Data subjects The Client's learners (employees, contractors, volunteers and other people the Client is authorised to train) and Team Spot Check participants
Personal information First name, surname, work email, optional department or group, lesson starts and completions with dates, quiz results stored as scores per field mark (urgency, authority, fear, reward, borrowed trust, secrecy), Field Guide cards, certificates, email delivery events, and audit log entries
Not collected Passwords, free-text answers, per-question answers kept against a name once scored, identity numbers, card numbers
Special personal information None. Voice Test recordings are processed by Underwing as responsible party, with each participant's explicit written consent and same-day deletion, and are not Client Personal Information.
Who sees it The Client's managers (with every view of an individual's results logged); authorised Underwing support staff; the Sub-processors in Schedule 3
Where it is stored South Africa (Amazon Web Services, Cape Town region, af-south-1)

Schedule 2: Security measures

Identity and access

  • No passwords anywhere in the Service.
  • Managers sign in with an email link plus a mandatory passkey that requires the device's own PIN or biometric check.
  • Learners use short-lived, single-purpose links behind a "Start" page, so email link scanners can't use them up.
  • Underwing staff use hardware security keys on a separate admin application, with least-privilege roles. There is no "log in as the customer" feature.
  • Multi-factor authentication and a password manager on every Underwing team member's accounts, with quarterly access reviews.

Data minimisation and retention

  • Only first name, surname, work email, an optional department and scores by field mark are stored for learners.
  • No free-text answers.
  • Learner information is deleted within 90 days after the contract ends; only anonymised aggregates are kept.

Separation between clients

  • Every record carries its organisation.
  • Database row-level security acts as a second lock behind the application's own checks.
  • Automated tests try to read across organisations, and the build fails if any succeeds.

Encryption

  • TLS on every connection, with HSTS preload.
  • Encrypted storage and encrypted backups.

Payments

  • Card details are entered only on Paystack's pages.
  • Every payment webhook's signature is verified, it is processed only once, and the transaction is re-checked with Paystack before access is granted.

Application security

  • Strict security headers and a content security policy.
  • Input validation on every endpoint.
  • Rate limits and bot checks on every public form.
  • Dependency and secret scanning in continuous integration.
  • Least-privilege database roles.
  • Application and error logs contain no personal information; error reports are scrubbed before they are sent to the monitoring service.
  • Background jobs carry internal IDs only, never names or email addresses.

Audit

  • An append-only log of sign-ins, exports, views of individual results, billing changes and every staff action.

Email

  • A dedicated sending subdomain with SPF, DKIM and DMARC at p=reject, plus MTA-STS.
  • One consistent sender name, and no link shorteners.

Operations and assurance

  • Tested backups.
  • An incident response plan that includes the POPIA section 22 notification process and this agreement's clause 8.
  • A public status page, a security.txt file and a vulnerability disclosure policy.
  • A security checklist run before every launch.
  • An independent penetration test before the first corporate client goes live.

Schedule 3: Authorised Sub-processors

Sub-processor What it does Personal information involved Location
Amazon Web Services Database and encrypted backups All Client Personal Information South Africa (Cape Town, af-south-1)
Resend Email delivery Recipients' names and work email addresses, the Client's name, and the content of service emails, including single-use links Ireland (European Union)
Vercel Hosts the application Personal information passes through while requests are handled; server functions run in Cape Town Global edge network; server functions in Cape Town
Paystack Payments and subscriptions Billing contact details and payment status only. No learner information. Card data is handled only by Paystack. Ireland (European Union), on Amazon Web Services
Cloudflare DNS, bot protection on forms (Turnstile) and video streaming (Cloudflare Stream) Technical information such as IP addresses. Videos contain no personal information. Global network

Paystack is not used to process learners' personal information. Paystack processes billing information for which Underwing is the responsible party; it is listed here for completeness.

Schedule 4: Contacts

Client Underwing
Contact for this agreement [Name, role, email] P.J. Mbedzi, Information Officer, privacy@underwing.co.za
Security Compromise notices [Name, email, mobile number] security@underwing.co.za, 071 095 0660
Information Officer [Name, email] P.J. Mbedzi, privacy@underwing.co.za

Signatures

For the Client: ______________________ Name: [ ] Title: [ ] Date: [ ]

For Under Bridges Entity (Pty) Ltd, trading as Underwing: ______________________ Name: [ ] Title: [ ] Date: [ ]