See the Good

Data Processing Agreement

Effective date:

This Data Processing Agreement sets out the processing terms See the Good expects a service provider to follow when it processes personal information on See the Good’s behalf. It is intended to be read with the Privacy Policy and the relevant service agreement.

1. DPA Scope

This Agreement applies when a provider processes personal information for See the Good in connection with the platform, its cards, contributions, payment flows, support, or related services.

The provider may process personal information only for the purposes described in this Agreement, the Privacy Policy, the relevant service agreement, or See the Good’s documented instructions.

2. Roles

See the Good determines the purposes for which it uses personal information in operating the platform. For those activities, See the Good acts as the responsible party under POPIA and, where applicable, as the controller under other privacy laws.

A provider acts as an operator under POPIA, or a processor under equivalent laws, when it processes personal information on See the Good’s behalf and according to See the Good’s documented instructions.

A provider may be a separate responsible party or controller for processing it carries out for its own purposes. That processing is governed by the provider’s own privacy notice and legal responsibilities.

3. Processing details

Subject matter and purposes: account creation and lookup, authorisations, recurring contributions, direct payments, balance and payment checks, cash-outs, refunds, service support, fraud prevention, security, and financial records.

Personal information: names or contact details where provided, email addresses, mobile numbers, card and account identifiers, payment and settlement information, browser and session tokens, provider references, event records, and information included in a service request or response.

People concerned: contributors, card holders, recipients, people requesting support, people making or receiving payments, visitors who use the service, and authorised administrators.

Duration: processing continues for as long as the provider is engaged for the relevant service, subject to any longer period required for legal, financial, security, or dispute-resolution purposes.

Current provider arrangements

Tickle: Tickle is the account network used behind the service. It may process information to create and manage accounts, look up accounts, create authorisations, manage recurring payments, process payments, check balances, and support cash-outs.

ThanksRaphy: ThanksRaphy may process information to support certain cash-outs and related refunds, including payment references, amounts, account identifiers, mobile numbers, and email addresses where provided.

Each provider remains responsible for any processing it carries out for its own purposes. Its own privacy notice should explain that processing and will apply alongside this Agreement where relevant.

4. Documented instructions

The provider must process personal information only on See the Good’s documented instructions, unless a law requires the provider to process it otherwise. If the law requires such processing, the provider should tell See the Good before processing unless the law prevents that notice.

The provider must tell See the Good if an instruction appears to breach applicable privacy law. The provider must not use the information for advertising, profiling, sale, or another independent purpose unless it is separately authorised to do so.

5. Provider responsibilities

The provider must ensure that people authorised to process personal information are bound by confidentiality obligations and receive only the access needed for their work.

The provider must maintain appropriate technical and organisational measures, keep processing records where required, and cooperate with See the Good’s reasonable instructions relating to privacy, security, and compliance.

6. Subprocessors

The provider must not appoint another processor to handle See the Good’s personal information without prior written authorisation or another agreed authorisation process.

A subprocessor must be bound by obligations that provide at least the same level of protection required by this Agreement. The provider remains responsible for the work it gives to a subprocessor.

7. Security

The provider must protect the integrity and confidentiality of personal information against loss, damage, unauthorised destruction, unlawful access, and unlawful processing.

Measures should be appropriate to the risk and may include access controls, authentication, encryption where appropriate, secure transmission, logging, backups, resilience, testing, and secure deletion.

The provider must ensure that its staff and systems receive only the access necessary to perform the agreed services.

8. Assistance and rights

The provider must reasonably assist See the Good in responding to requests to access, correct, delete, restrict, or otherwise exercise rights over personal information.

The provider must promptly forward any request, complaint, or enquiry it receives from a person about See the Good’s processing, unless it is authorised to respond directly. It must not respond on See the Good’s behalf without instructions.

9. Security incidents

The provider must notify See the Good without undue delay after becoming aware of a security compromise involving personal information processed for See the Good.

The notice should include, where known, the nature of the compromise, the information affected, the people potentially affected, likely consequences, and the measures taken or proposed to contain and resolve it.

The provider must cooperate with See the Good’s investigation, mitigation, record-keeping, and notification obligations.

10. International transfers

The provider must not transfer personal information outside South Africa, or allow it to be accessed from another country, unless the transfer is authorised and the required protection is in place.

Before a transfer begins, the provider must give See the Good enough information to understand the destination, the receiving party, the purpose of the transfer, and the safeguards used.

11. Retention and deletion

The provider must keep personal information only for as long as needed to provide the agreed services or meet a legal, financial, security, or dispute-related obligation.

When the service ends, or when See the Good instructs the provider to do so, the provider must return or securely delete the personal information and existing copies, unless a law requires continued storage. Information retained for that reason must remain protected and must not be used for another purpose.

12. Records and audits

The provider must make available the information reasonably needed for See the Good to demonstrate compliance with this Agreement and applicable privacy law.

See the Good may request reasonable information, attestations, or audit assistance relating to the provider’s processing. Any audit must respect confidentiality, security, and the provider’s other customers.

13. Contact

Questions about this Agreement or a provider’s processing should be sent to:

hello@seethegood.co.za