Data Processing Agreement
Last updated: August 2026 · Incorporated into the Terms of Service
1. Parties and roles
This DPA applies where a ZansQuote customer is the responsible party for personal information placed in the service and Zanstech acts as its operator, as those terms are used in POPIA. Zanstech remains a responsible party for account, billing, security, and service-administration data processed for its own purposes.
2. Instructions and purpose
Zanstech will process customer data only on documented instructions expressed through the agreement and normal use of ZansQuote, to host, secure, back up, transmit, support, and delete that data. The customer must have a lawful basis and provide required notices before uploading personal information.
3. Processing details
Processing lasts for the subscription and any limited backup or legal-retention period. Data may include customer and staff names, contact details, addresses, business and tax identifiers, quotations, invoices, signatures, attachments, job and damage reports, compliance documents, payment records, and audit metadata. Data subjects may include the customer's clients, staff, contractors, and suppliers.
4. Confidentiality and security
Personnel authorised to process customer data are subject to confidentiality duties. Zanstech will maintain reasonable safeguards appropriate to the risk, including access control, tenant isolation, encrypted transport, secure token handling, logging, backups, vulnerability management, and malware scanning of supported uploads.
5. Sub-operators and transfers
The customer gives general authorisation for the providers identified in the Privacy Policy. Zanstech remains responsible for placing appropriate data-protection obligations on sub-operators. Cross-border processing will use safeguards required by section 72 of POPIA. Material sub-operator changes will be notified through the website or account email.
6. Security compromises
Zanstech will notify the customer without undue delay after confirming a security compromise affecting customer data, provide reasonably available details, take containment and remediation steps, and assist the customer with legally required notifications. The customer remains responsible for determining its own notification obligations.
7. Assistance
Zanstech will provide reasonable assistance with data-subject requests, security assessments, impact assessments, and regulator enquiries. Requests must be sent to [email protected].
8. Return, deletion, and audit
Customers can export supported records and delete their account. On termination Zanstech will delete customer data from active systems subject to legal obligations and normal backup expiry. On reasonable request, Zanstech will provide information needed to demonstrate compliance; audits must protect other customers, security, and confidentiality.
9. Priority
If this DPA conflicts with the Terms on processing customer personal information, this DPA controls. Liability remains subject to the lawful limitations in the Terms or an executed MSA.