Operator agreement

Draft — not yet reviewed by an attorney. This document was prepared from the text of the applicable legislation and published guidance. It is a solid starting point, not a substitute for advice. Have it reviewed before you rely on it, and delete this box once you have.

Last updated: 26 July 2026

Have an attorney review this one before you launch. Of everything on this site, this is the document that carries real liability and that a customer's lawyer will actually read. It is drafted from the text of POPIA and is a sound starting point — but the indemnity, liability and sub-operator clauses in particular deserve professional attention.

Version 2026-07-26

This agreement is concluded between Intellitics Business Solutions ("Intellitics", the operator) and the customer identified in the subscription ("you", the responsible party). It is the written contract required by section 21(1) of the Protection of Personal Information Act, 2013.

It applies from the moment you accept it at signup and remains in force for as long as we hold any personal information on your behalf.

1. Definitions

Personal information, data subject, processing, responsible party and operator carry the meanings given in POPIA. Customer data means personal information you or your users place in the Service. Service means MasterVault and related services we supply to you.

2. Roles

You are the responsible party for Customer Data. You decide what is collected, why, and for how long. We are your operator: we process Customer Data only to supply the Service, and only on your documented instructions — your subscription and your configuration of the Service being those instructions.

We will not process Customer Data for our own purposes, will not use it to train any model, and will not sell, rent or disclose it, except as section 5 requires.

If we believe an instruction from you would breach POPIA, we will tell you promptly rather than simply carrying it out.

3. Our security obligations

We will secure the integrity and confidentiality of Customer Data by taking appropriate, reasonable technical and organisational measures as required by section 19, including:

  • encrypting Customer Data in transit (TLS 1.2 or better) and at rest;
  • storing Customer Data in the Republic of South Africa;
  • logically isolating your instance and storage from other customers';
  • restricting staff access to those who need it to operate the Service, under confidentiality obligations;
  • maintaining access logs, and making them available to you;
  • taking daily backups, retained 30 days, stored in South Africa, and periodically restore-tested;
  • applying security patches on a defined schedule, and out of band for critical advisories;
  • identifying reasonably foreseeable internal and external risks, maintaining safeguards against them, verifying that those safeguards work, and updating them as risks change.

4. Security compromises

Where we have reasonable grounds to believe Customer Data has been accessed or acquired by an unauthorised person, we will notify you immediately, as section 21(2) requires. That notification will describe what we know of the nature and extent of the compromise, the categories of data and the people affected so far as we can determine, what we are doing about it, and what we suggest you do.

We will assist you, at our cost where the compromise arises from our processing, to make the notifications section 22 requires of you. You retain the decision on how and when to notify the Regulator and affected data subjects — that duty is yours as responsible party, and we will not make it on your behalf.

5. Disclosure required by law

If we receive a legally binding demand for Customer Data, we will notify you before disclosing anything, unless the law forbids us from doing so. Where we may not tell you, we will challenge the prohibition where there are reasonable grounds, and disclose only the minimum the demand requires.

6. Sub-operators

You authorise us to appoint sub-operators for infrastructure. Our current sub-operators are:

Sub-operatorPurposeLocation
Amazon Web Services EMEA SARLCompute, storage and backupAfrica (Cape Town), af-south-1

We will impose obligations on each sub-operator no less protective than those in this agreement, and we remain fully liable to you for their performance. We will give you at least 30 days' notice before adding or replacing a sub-operator, and you may terminate without penalty if you reasonably object.

7. Transfers outside South Africa

We will not transfer Customer Data outside the Republic without your prior written consent, except where doing so is strictly necessary to provide the Service and a condition in section 72 is met. As at the version date, Customer Data is not transferred outside South Africa.

8. Assisting you with data subject requests

If a data subject contacts us directly about Customer Data, we will not respond substantively — we will refer them to you and tell you promptly. We will give you the technical means (search, export and access logs) to answer requests for access, correction or deletion, at no additional charge.

9. Your obligations

You warrant that you:

  • have a lawful basis for the Customer Data you place in the Service;
  • have given data subjects the notification section 18 requires;
  • will not use the Service for special personal information or children's information without telling us first, so we can advise on suitability;
  • will manage your own users' access, and remove people who leave;
  • will keep your administrator credentials secure and enable two-factor authentication.

10. Audit

On reasonable written notice, not more than once a year, you may ask us to demonstrate compliance with this agreement. We will respond to a reasonable written security questionnaire and provide our current security documentation. On-site audits are by arrangement and at your cost.

11. Return and deletion

You may export Customer Data at any time during the subscription. On termination we retain Customer Data for 30 days so that you can retrieve it, then delete it permanently from live systems, and from backups within a further 30 days as backup rotation completes. We will confirm deletion in writing on request.

12. Liability

Each party's liability under this agreement is subject to the limitations in the terms of service. Nothing in this agreement limits liability that may not lawfully be limited.

13. Conflicts and duration

Where this agreement conflicts with the terms of service, this agreement prevails in respect of the processing of personal information. It terminates when we no longer hold any Customer Data, and clauses 4, 5, 11 and 12 survive termination.

14. Governing law

South African law governs this agreement, and the parties submit to the jurisdiction of the South African courts.


A countersigned copy of this agreement, recording the version you accepted and the date, is emailed to you when your account is provisioned. If you need it again, email privacy@intellitics.co.za.