Xee Security

Data Processing Addendum

Version 2026-09 · Last updated September 2026
Template for a South African SaaS. Have it reviewed by a qualified attorney before you rely on it in production.

This Addendum forms part of the Terms and governs our processing of personal information that you (the "Responsible Party") place in the Service, where we (Xee Holdings (Pty) Ltd) act as "Operator" under POPIA.

1. Roles

You determine the purpose and means of processing your customer and ISMS data; we process it only on your documented instructions, which include your configured use of the Service.

2. Our obligations

We will: process personal information only for the purpose of providing the Service; keep it confidential; apply appropriate technical and organisational security measures; and notify you without undue delay after becoming aware of a personal-information breach affecting your data.

3. Sub-operators

You authorise us to appoint sub-operators (hosting, email, payments) under written terms no less protective than this Addendum. A current list is available on request.

4. International transfers

Where personal information is processed outside South Africa, we ensure a lawful basis and adequate protection consistent with POPIA section 72.

5. Assistance

We will provide reasonable assistance with data-subject requests and with your security and breach-notification obligations.

6. Return or deletion

On termination we will, at your choice, return or delete the personal information we process on your behalf, save where retention is required by law.

← Back to sign up