SkipDrop · Legal · Schedule 1

Data Processing (Operator) Agreement

Version 2026-07-v1 — effective 19 July 2026

This Schedule is incorporated into, and forms part of, the SkipDrop Terms of Service. Capitalised terms not defined here have the meaning given to them in those Terms. It is the written agreement contemplated by sections 20 and 21 of the Protection of Personal Information Act 4 of 2013("POPIA") between the Operator (as the Responsible Party in respect of End Customer data) and SkipDrop / BotAndBotty (Pty) Ltd (as that Operator's operator under POPIA).

1. Subject matter

SkipDrop processes Personal Information on behalf ofthe Operator strictly to provide the Service. SkipDrop will not process Personal Information for any other purpose, will act only on the Operator's documented instructions (the act of entering data into the tenant being a documented instruction to process it for the relevant operational purpose), and will not disclose Personal Information except as required by these Terms or by law.

2. Categories of data subjects

  • The Operator's End Customers — natural or juristic persons who book skip-hire services from the Operator.
  • The Operator's staff — drivers, dispatchers, office users, and other people the Operator adds to its tenant.

3. Categories of Personal Information

  • Contact details (name, cell, email, billing address).
  • Service-site location data (delivery / collection addresses, GPS pins, site notes).
  • Booking and job history (skip size, waste type, dates, photos).
  • Payment records and invoice history (amounts, payment method references, PayFast transaction identifiers).
  • Job photos or customer signatures captured in the field (which may incidentally capture third-party Personal Information at a site).
  • Operator staff records (display name, cell, email, role flags).
  • Optional marketing preference where an End Customer separately opts in.

SkipDrop does notrequire, and the Operator should not upload, Special Personal Information (POPIA section 26) or children's data (POPIA section 34) without first putting in place its own POPIA-compliant lawful basis. SkipDrop does not store payment-card numbers — those are handled exclusively by PayFast.

4. Confidentiality

SkipDrop will treat Personal Information as confidential. All SkipDrop personnel and contractors with access to Operator Personal Information are bound by written confidentiality obligations that survive the end of their engagement.

5. Security safeguards (POPIA section 19)

SkipDrop will maintain appropriate, reasonable technical and organisational measures for the nature of the Personal Information involved, including:

  • Databases encrypted at rest.
  • All transport encrypted in transit (TLS).
  • Tenant isolation enforced at the database layer.
  • One-time-password authentication only — no shared passwords.
  • Documented backup and restore procedures.
  • Incident response procedures targeting Operator notification within seventy-two (72) hours of becoming aware of a compromise involving Personal Information.
  • Platform-level rate-limiting and abuse controls.
  • Audit logging of sensitive operations (team changes, exports, anonymisations, legal acceptances).

6. Sub-processors

The Operator authorises SkipDrop to engage the following sub-processors:

  • Supabase — managed PostgreSQL database (eu-west-1 / Ireland).
  • Vercel — application hosting and edge network (US region, with global edge caching).
  • Resend — transactional email delivery (US region).
  • SMS Portal — SMS delivery (South Africa).
  • PayFast — payment processing (South Africa).

SkipDrop will give the Operator at least thirty (30) days' notice (by email and/or in-platform) before adding or replacing a sub-processor that processes End Customer Personal Information. If the Operator objects on reasonable POPIA-compliance grounds within that period, its sole remedy is to terminate the Service and export its data under the main Terms.

7. Cross-border transfers (POPIA section 72)

Some sub-processors store or process Personal Information outside South Africa (notably Ireland for the database and the United States for hosting and email). The Operator authorises these transfers. SkipDrop will ensure that each such sub-processor is bound by contractual safeguards providing an adequate level of protection substantially similar to POPIA.

8. Data-subject rights

POPIA gives data subjects rights of access, correction, and (where applicable) deletion. Those rights are exercised against the Responsible Party — i.e. the Operator — for End Customer data.

SkipDrop will assist the Operator in fulfilling these requests within fourteen (14) days of being asked, including through per-customer export and anonymisation tools in the Service. Where SARS or another regulator mandates longer retention (for example five years for tax records), that retention obligation prevails over a deletion request; SkipDrop will anonymise personal fields while retaining the financial record.

9. Breach notification (POPIA section 22)

If SkipDrop becomes aware that any Personal Information belonging to the Operator's tenant has, or is reasonably likely to have been, accessed or acquired by an unauthorised person, SkipDrop will notify the Operator without undue delay and in any event within seventy-two (72) hours of becoming so aware. The notification will include the information reasonably needed for the Operator to comply with its own section 22 obligations to the Information Regulator and affected data subjects.

10. Retention & return

On termination of the main Terms, SkipDrop will retain Operator Personal Information for thirty (30) days to allow export, and will then delete or anonymise it within a further thirty (30) days, subject to legal retention requirements for invoice and tax records (commonly five years). The Operator may request in writing that invoice records be retained for that statutory minimum.

11. Audit

The Operator may request, no more than once in any 12-month period, a written summary of SkipDrop's security posture (architecture, sub-processors, controls, incident history). On-site audits are not offered unless separately agreed in writing.

12. Information Officers

The Operator'sInformation Officer is its CEO, principal, or other person designated under POPIA — by default, the Operator's owner user on the SkipDrop account.

SkipDrop's Information Officer is Charl Lamprecht. Contact: bot@botandbotty.com.

13. Liability & indemnity

Liability and indemnity under this Schedule are governed by the limitation and indemnity clauses of the main Terms. Nothing in this Schedule extends a party's liability beyond the limits set in those clauses.

14. Term & acceptance

This Schedule takes effect when the Operator accepts it (at signup or via the in-app legal acceptance gate) and remains in force for as long as SkipDrop processes Personal Information on the Operator's behalf — including the post-termination retention window in clause 10.

Version 2026-07-v1 — effective 19 July 2026.