Your data doesn't train Genie's AI
You keep IP ownership of your docs
1. Parties: Identification of the Controller (Responsible Party) and Processor (Operator) with their full legal details
2. Background: Context of the agreement and the processing relationship between the parties
3. Definitions: Definitions of key terms, including those from POPIA and additional agreement-specific terms
4. Scope and Purpose of Processing: Detailed description of the personal information to be processed and the agreed purposes
5. Duration of Processing: Term of the processing activities and agreement duration
6. Obligations of the Processor: Core processor obligations including security measures, confidentiality, and processing limitations
7. Obligations of the Controller: Controller's responsibilities including lawful instructions and compliance with POPIA
8. Sub-processing: Conditions and requirements for engaging sub-processors
9. Data Subject Rights: Procedures for handling data subject requests and assistance requirements
10. Data Security: Security measures and standards required for processing activities
11. Data Breach Notification: Procedures and timeframes for reporting and handling data breaches
12. Audit Rights: Controller's rights to audit and processor's obligations to demonstrate compliance
13. Termination: Conditions for termination and data handling upon termination
14. General Provisions: Standard contractual terms including governing law, jurisdiction, and amendment procedures
1. Cross-border Data Transfers: Required when personal information will be transferred outside South Africa, including safeguards and compliance with POPIA's transfer requirements
2. Special Personal Information: Additional provisions required when processing special personal information as defined in POPIA
3. Children's Personal Information: Special provisions required when processing personal information of children
4. Direct Marketing: Required when processing involves direct marketing activities
5. Business Continuity: Specific provisions for ensuring continuous availability of processing services in critical operations
6. Insurance Requirements: Specific insurance obligations for high-risk processing activities
1. Description of Processing Activities: Detailed description of processing activities, categories of data subjects, types of personal information, and processing purposes
2. Technical and Organizational Security Measures: Specific security measures and controls implemented by the processor
3. Approved Sub-processors: List of approved sub-processors and their processing activities
4. Data Transfer Mechanisms: Details of mechanisms used for international data transfers, if applicable
5. Service Level Agreement: Performance metrics and service levels for processing activities
6. Fee Schedule: Pricing and payment terms for processing services
7. Contact Details and Escalation Procedures: Key contacts and procedures for operational and emergency communications
Find the exact document you need
International Data Transfer Addendum
A South African law-compliant addendum governing international transfers of personal information under POPIA requirements.
Intra Group Data Processing Agreement
A South African law-governed agreement regulating personal information processing between entities within the same corporate group, ensuring POPIA compliance.
Third Party Processing Agreement
A South African law-governed agreement regulating personal information processing between a responsible party and an operator under POPIA.
Data Processing Addendum
A South African law-compliant agreement governing personal information processing between controllers and processors under POPIA.
Intercompany Data Transfer Agreement
South African law-governed agreement regulating intra-group data transfers in compliance with POPIA and local data protection regulations.
Data Management Agreement
A South African law-compliant agreement governing data management and processing activities between organizations, ensuring POPIA compliance and data protection.
Data Controller To Data Controller Agreement
South African POPIA-compliant agreement governing personal information sharing between two data controllers, establishing mutual obligations and responsibilities.
DPA Agreement
A South African law-compliant Data Processing Agreement establishing terms for handling personal information under POPIA regulations.
Third Party Data Processing Agreement
A South African law-compliant agreement governing the processing of personal information by a third-party operator on behalf of a responsible party under POPIA.
Personal Data Transfer Agreement
A POPIA-compliant agreement for transferring personal information between parties under South African law.
Controller Processor Agreement
A South African law-governed agreement between a data controller and processor establishing terms for personal information processing under POPIA.
Affiliate Addendum
A South African law-compliant addendum establishing terms and conditions for affiliate marketing relationships, including commission structures and compliance requirements.
Sub Processing Agreement
A South African-compliant agreement governing the delegation of personal information processing activities to a sub-processor under POPIA requirements.
International Data Transfer Agreement
A South African law-governed agreement for cross-border personal information transfers, ensuring POPIA compliance and data protection standards.
Data Protection Addendum
A South African law-governed addendum establishing POPIA-compliant terms for personal information processing between parties.
ұԾ’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; ұԾ’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

.png)