OrgSpace logoOrgSpaceby Pixels
OPERATOR TERMS

Data Processing Terms

POPIA terms for organisation data processed through OrgSpace.

Effective 21 August 2026

1. Roles and scope

These terms apply where an organisation uses OrgSpace to process personal information for its workplace operations. The organisation is the responsible party and Pixels is its operator, except where Pixels independently determines a processing purpose as explained in the Privacy Policy.

Pixels processes organisation data only to provide, secure, support and maintain OrgSpace, to follow documented configuration and workflow instructions, and to meet applicable law. The organisation remains responsible for lawful collection, notices, data quality, user authority, retention instructions and responding to data subjects.

2. Confidentiality and security

Pixels restricts access to authorised personnel and service providers who require access for their duties and are bound by confidentiality obligations. Pixels maintains reasonable technical and organisational measures, including authentication, role and active-membership controls, tenant checks, server-side workflow validation, private evidence storage, short-lived file access, audit records, monitoring, backups and incident procedures.

3. Sub-processors

The organisation authorises Pixels to use sub-processors needed to provide the service. Current categories include Google Firebase and Google Cloud; Expo and mobile platform providers; Paystack where billing is enabled; and the configured transactional-email provider. Pixels remains responsible for selecting providers with appropriate privacy and security obligations and will update the public Privacy Policy when a material category changes.

4. International transfers

Some sub-processors may process information outside South Africa. Pixels will use a recipient subject to applicable law, binding corporate rules, a binding agreement or another lawful safeguard providing an adequate level of protection as contemplated by POPIA section 72, and will limit transfers to what is necessary for the service.

5. Security compromises

Pixels will notify the organisation without undue delay after becoming aware of a security compromise affecting organisation data and will provide reasonably available details about the nature of the incident, affected data, containment and remediation. The organisation decides and performs notifications required of it as responsible party. Pixels will not notify a data subject on the organisation’s behalf unless instructed or legally required.

6. Data-subject and regulator assistance

Taking account of the nature of the processing, Pixels will provide reasonable assistance for access, correction, deletion, restriction, objection, impact assessment, security and regulator enquiries. Organisation administrators can export or correct many records directly; authenticated personal account deletion is available in the app.

7. Return, deletion and retention

On termination, the organisation should export records it must keep. Pixels will delete or de-identify organisation data when instructed and when no legal, security, dispute or backup-retention reason remains. Protected backup copies expire according to the configured retention cycle and remain unavailable for ordinary use. Legitimate immutable audit or financial records may be retained only for the lawful period that applies.

8. Audit information

Pixels will provide reasonable information about its security and privacy controls, relevant incident records and sub-processor categories. Any additional audit must protect other customers, confidential information and service security, be proportionate, and be agreed in advance.

9. Contact and precedence

Privacy and Information Officer enquiries: hello@orgspace.co.za or 071 548 1945. These terms supplement the service terms and Privacy Policy. A signed customer agreement may add stricter terms and prevails to the extent of a direct conflict.