Back to PropSign

Legal

Legal Documents

These documents explain how PropSign handles billing, privacy, sub-processors, POPIA-facing responsibilities, and information-access requests. They are written to help agencies understand the live platform and the limits of what the product currently provides.

Data Processing Agreement

Version 1.0Effective: 1 June 2026

1. Parties and Background

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between PropSign(“Operator”) and the subscribing agency (“Responsible Party”). Its purpose is to describe how personal information is processed through the service in a manner consistent with POPIA.

2. Scope of Processing

PropSign processes personal information to provide:

  • document creation, routing, and signing workflows;
  • workspace, team, and subscription management;
  • transactional notices and signing-link delivery; and
  • operational and compliance-facing workflow records supported by the product.

3. Categories of Data Subjects and Data

The service may process personal information relating to:

  • agency owners, admins, agents, assistants, and contractors;
  • buyers, sellers, landlords, tenants, guarantors, and witnesses; and
  • other signers or contacts added to an agency workflow.

The information may include:

  • identity and contact information;
  • property and transaction information included in documents;
  • signatures, acknowledgements, and signing timestamps; and
  • supported workflow and account-management data.

4. Operator Obligations

PropSign shall:

  • process personal information only on the documented instructions of the Responsible Party, except where required by law;
  • ensure persons authorized to process personal information are bound by confidentiality obligations;
  • maintain reasonable technical and organizational safeguards appropriate to the live service;
  • assist the Responsible Party with reasonable requests relating to Data Subject rights; and
  • notify the Responsible Party of a material security compromise affecting the data processed through the service.

5. Sub-Processors

The Responsible Party gives general authorization for PropSign to use sub-processors that support hosting, identity, payments, and related operations. The current sub-processor list is published at getpropsign.co.za/legal/sub-processors.

6. Security Measures

PropSign maintains reasonable safeguards for the live service, including encrypted transport, access restrictions, configured authentication tooling, and operational controls implemented through the application and its service providers.

7. International Transfers

Where personal information is processed through providers operating outside South Africa, PropSign relies on appropriate contractual or operational safeguards and the protections required by POPIA.

8. Retention and Deletion

Signed records handled through the current PropSign signing workflow remain available in the platform for up to 72 hours after signing. Agencies should export any records they must retain in their own approved archive.

Other account and operational records may be retained for longer where reasonably required for billing, support, security, or legal obligations.

9. Audit and Cooperation

The Responsible Party may request reasonable information about the safeguards relevant to this DPA. PropSign may satisfy such requests through summaries of service documentation, provider materials, or other reasonable evidence.

10. Governing Law

This DPA is governed by the laws of the Republic of South Africa. Any disputes arising from it are subject to the jurisdiction of the courts of South Africa.

Questions about our legal documents or trust information? Contact PropSign.