Operator agreement
Processing of personal information on an organisation’s behalf — sections 20 and 21 of the Protection of Personal Information Act, 2013
Between
admin made simple Pty Ltd, trading as admin made simple
(the Operator)
- Registered name
- admin made simple Pty Ltd
- Registration number
- 2022/835591/07
- Address
- 10 Remhoogte Road, Somerset West, 7130, South Africa
- Telephone
- +27 76 439 8222
- michael@adminmadesimple.co.za
and the organisation named below
(the Organisation)
What this agreement records
The Organisation uses the admin made simple platform to hold and work with information about the people it serves and employs. Under the Protection of Personal Information Act, the Organisation is the responsible party for that information, and the Operator processes it on the Organisation's behalf.
Sections 20 and 21 of the Act govern that arrangement, and section 21 asks for it in writing. This document is that writing, for the Organisation's own compliance file. It records what the Operator's Terms of Use already provide; where the two differ, whichever protects personal information more strictly applies.
The information concerned
Whatever the Organisation and its staff put into their workspace on the platform: records about the people the Organisation serves — clients, learners and their families, owners, members, customers — and about its own staff. The Organisation decides what goes in. The Operator collects nothing about those people itself.
What the Operator does with it, and what it never does
The Operator processes the information only to run the Organisation's workspace, and only on the Organisation's instruction. In particular:
- It is not sold, not used for advertising, not used to improve anything of the Operator's, and not shared with anybody the Organisation did not send it to.
- It never reaches another organisation on the platform. One access rule in one place decides every read, and the organisation is the boundary it draws.
- When the Organisation publishes something to the people it serves, each person is shown only their own records, filtered on the Operator's servers before anything reaches their device.
- A request from a person the information is about — show me what you hold, correct it, delete it — is the Organisation's to answer. The Operator acts on the Organisation's instruction and does not answer for it.
Confidentiality
The Operator treats the Organisation's information as confidential, as section 20 requires. Nobody working on the platform touches it except so far as running or supporting the service requires, and the Operator does not disclose it unless the law requires disclosure — in which case the Organisation is told first, where the law allows.
Security safeguards
The Operator keeps administrative and technical safeguards appropriate to the harm that unauthorised access, loss or damage could do, as sections 19 and 21 require: every read is decided on the Operator's servers by one access rule, connections are encrypted, card numbers never reach the platform at all, and credentials are held apart from the information they unlock. The security section of the Operator's privacy policy sets the measures out in more detail, and this agreement holds the Operator to them.
If something goes wrong
If the Operator has reason to believe personal information the Organisation holds here has been accessed or acquired by somebody unauthorised, the Operator notifies the Organisation as soon as practicable after becoming aware of it, shares what it knows so the Organisation can establish what happened and whose information was affected, and acts at its own cost to contain the event and prevent it recurring.
Where it is processed
The information lives on the hosting infrastructure the Operator's privacy policy names, and it does not cross a border except as that policy sets out. The one deliberate case is the AI: rows are sent to an AI provider only when somebody asks a question in words, the countries on offer are disclosed before anybody chooses, and the Organisation's administrators may restrict that choice for everybody in the Organisation.
When it ends
The Organisation may take its information out at any time, and may instruct the Operator to delete what it holds: removing a data source or an app deletes its stored records immediately, with no archived copy — and a connected Google Sheet was never copied at all, because the Operator reads it live and holds read-only access. When the Organisation stops using the platform, the Operator deletes what remains on the Organisation's instruction and confirms when it is done.
Term
This agreement applies from the date signed below, for as long as the Organisation uses the platform. The confidentiality and deletion obligations survive the end of that use.
For admin made simple Pty Ltd, trading as admin made simple
who warrants their authority to sign for the party named above
For the Organisation named above
who warrants their authority to sign for the party named above
Signed copies go to michael@adminmadesimple.co.za — we counter-sign and return yours. An organisation with its own version of this document can send that instead, and we will sign it.
Transferring personal data from the EU, the EEA or Switzerland? The transfer annex completes this agreement with the EU Standard Contractual Clauses — print the two together and sign once. Open the transfer annex.