Data Processing Agreement
Effective date: 2 July 2026 | Last updated: 2 July 2026
1. Purpose and scope
This Data Processing Agreement (“DPA”) supplements the Terms of Service and Privacy Policy of KTS Export Solar (“we”, “us”, or “our”). It sets out how we process personal information on behalf of users, customers, and business partners in compliance with the South African Protection of Personal Information Act 4 of 2013 (“POPIA”) and other applicable data-protection laws.
2. Roles and definitions
- Responsible party: KTS Export Solar, the entity that determines the purpose and means of processing personal information.
- Operator: Any third party that processes personal information on our behalf under our written instruction.
- Data subject: The individual to whom the personal information relates.
- Personal information: Any information relating to an identifiable, living natural person or juristic person where applicable.
3. Instructions and purpose limitation
We process personal information only for the purposes described in our Privacy Policy or as otherwise agreed with you. We do not use personal information for our own purposes beyond providing, securing, and improving the Services, unless required by law or with your consent.
4. Data we process
Depending on your relationship with us, we may process identity, contact, account, transaction, technical, and communication information. A detailed list is provided in our Privacy Policy.
5. Sub-processors
We may engage sub-processors to perform specific processing activities, including hosting, email delivery, payment processing, analytics, and customer support. We ensure that any sub-processor:
- is bound by written contractual obligations that provide at least the same level of protection as this DPA;
- processes personal information only in accordance with our documented instructions;
- implements appropriate technical and organisational security measures; and
- assists us in responding to data-subject requests and regulatory inquiries.
A current list of sub-processor categories is available on request.
6. Security measures
We implement reasonable technical and organisational measures to protect personal information, including:
- encryption of data in transit using TLS/SSL;
- access controls and role-based permissions;
- regular security reviews, backups, and monitoring;
- secure development practices and staff training; and
- incident detection and response procedures.
7. Confidentiality
All personnel and sub-processors who access personal information are subject to confidentiality obligations. Access is granted only to those who need it to perform their duties.
8. Data-subject rights
We assist data subjects in exercising their rights under POPIA, including access, correction, objection, deletion, and complaint rights. Requests should be directed to [email protected].
9. Data breaches
In the event of an actual or suspected unauthorised access to, or loss of, personal information, we will:
- take immediate steps to contain, assess, and mitigate the breach;
- notify affected parties and the Information Regulator where required by law;
- co-operate with regulatory authorities and document the incident.
10. International transfers
Where personal information is transferred outside South Africa, we ensure that appropriate safeguards are in place, such as adequacy decisions, contractual clauses, or binding corporate rules, in compliance with POPIA.
11. Term and termination
This DPA applies for as long as we process personal information on your behalf. Upon termination of the relevant service, we will delete, anonymise, or return personal information in accordance with our Data Retention Policy and applicable law.
12. Changes to this agreement
We may update this DPA from time to time. The updated version will be posted on this page with a revised effective date.
13. Contact us
For questions about this Data Processing Agreement, please contact us at [email protected].