Legal

Data Processing Addendum

Last updated: 15 July 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Maestro Business Advantage ("Maestro", Operator) and the customer ("you", the Responsible Party) whenever Maestro processes personal information on your behalf — for example, the quote requests, lead posts, member contact details or review content you handle through your dashboard.

It applies the Protection of Personal Information Act 4 of 2013 (POPIA), including sections 19–22 and the Operator obligations in sections 20–21.

1. Roles

  • You are the Responsible Party for the personal information about your customers, leads and staff that you process through the Services.
  • Maestro is the Operator to the extent it processes that information on your instructions.
  • For information Maestro collects for its own purposes (accounts, billing, analytics), Maestro is the Responsible Party — see the Privacy Policy.

2. Scope of processing

  • Subject matter: operation of the Maestro platform.
  • Nature & purpose: hosting, storage, retrieval, display, notification and back-up of personal information you upload.
  • Categories of data subjects: your customers, prospective customers, employees, members of the public who leave reviews or request quotes.
  • Categories of personal information: contact details (name, email, phone), business details, message content, quote/lead content, review content. You must not upload special personal information (health, biometrics, children's data) unless you have obtained the required consents.
  • Duration: for the term of your subscription plus the retention periods in the Privacy Policy.

3. Maestro's obligations as Operator

  • Process personal information only on your documented instructions, which include your use of the platform's standard features.
  • Keep the information confidential and require the same of our personnel.
  • Implement appropriate technical and organisational security measures (section 19 POPIA), including encryption in transit, access controls, row-level security, backups and audit logs.
  • Notify you without undue delay after becoming aware of a security compromise affecting your data (section 22 POPIA), providing enough information for you to comply with your own notification duties.
  • Assist you, at your reasonable cost, in responding to data subject requests, complaints and Information Regulator inquiries.
  • On termination, delete or return personal information within a reasonable period, subject to any legal retention obligations.

4. Your obligations as Responsible Party

  • Ensure you have a lawful basis under POPIA to upload personal information to the platform.
  • Provide the required POPIA notifications (section 18) to the data subjects whose information you upload.
  • Configure the Services (e.g. who on your team has access, which lead posts to make public) in line with your privacy commitments.
  • Not upload personal information that Maestro is not designed to hold (e.g. card data, medical records).

5. Sub-operators

You authorise Maestro to use the following sub-operators, each bound by contracts that offer POPIA-equivalent protection:

  • Supabase — database, authentication, file storage, edge functions.
  • PayFast (DPO Payment Solutions) — payment processing.
  • Email delivery provider — transactional email.
  • Cloud infrastructure providers — hosting and CDN for the platform.

We will notify you at least 30 days before adding or replacing a sub-operator that processes your data. You may object on reasonable data-protection grounds; if we can't resolve the concern, you may terminate the affected Services and receive a pro-rata refund of any prepaid fees.

6. Cross-border transfers

Where personal information is transferred outside South Africa, Maestro relies on section 72 of POPIA — either the recipient is subject to a law providing an adequate level of protection, or a written agreement imposing equivalent obligations is in place.

7. Data subject requests

If a data subject contacts Maestro with a POPIA request that concerns personal information processed on your behalf, we will not respond directly (except to acknowledge receipt) and will forward the request to you within 5 business days.

8. Audit

On reasonable prior written notice (and no more than once per year, unless a security incident has occurred), you may request written evidence that Maestro is meeting the obligations of this DPA. Where an on-site audit is strictly required by law, the parties will agree scope, timing and cost in advance.

9. Liability

The liability caps in the Terms of Service apply to this DPA. Nothing in this DPA limits either party's liability to data subjects under POPIA.

10. Order of precedence

If there is a conflict between this DPA and the Terms of Service in relation to the processing of personal information, this DPA prevails.

11. Contact

Data-protection queries: info@maestroassist.co.za · 015 023 2924 · Johannesburg, South Africa.

Data subjects can also submit requests through our POPIA data subject request form.