Data Processing Agreement
Last updated: 24 July 2026
This Data Processing Agreement ("DPA") is entered into between SkyL4rk PTY LTD, registration number 2018/043553/07, trading as LocalLoyalty ("Operator"), and the Merchant registered on the LocalLoyalty platform ("Responsible Party").
This DPA forms part of the Merchant Services Agreement and governs the processing of personal information as required by the Protection of Personal Information Act 4 of 2013 ("POPIA") and any regulations made thereunder.
1. Definitions
- Personal Information — has the meaning given in section 1 of POPIA, and includes but is not limited to Users' names, email addresses, phone numbers, and transactional data collected through the Platform.
- Responsible Party — the Merchant, who determines the purpose and means of processing Personal Information collected through their Programme(s).
- Operator — LocalLoyalty (SkyL4rk PTY LTD), who processes Personal Information on behalf of the Responsible Party.
- Processing — any operation performed on Personal Information, including collection, storage, use, disclosure, and deletion.
- Data Subject — a User of the LocalLoyalty app whose Personal Information is processed under this DPA.
2. Scope and Purpose of Processing
LocalLoyalty processes Personal Information on behalf of each Merchant solely to provide the loyalty Programme services described in the Merchant Services Agreement. The categories of Personal Information processed include:
- User identity: first name, last name, email address.
- Stamp and card activity: stamp counts, card completion records, redemption events.
- Gift card and credit balance data: top-up amounts, transaction references, balance history (where applicable).
- Device and session identifiers used for push notifications (where the User has consented).
LocalLoyalty does not process Special Personal Information (as defined in POPIA section 26) in connection with the Platform.
3. Obligations of LocalLoyalty as Operator
LocalLoyalty undertakes to:
- Process Personal Information only on documented instructions from the Responsible Party (i.e. the operation of the Merchant's Programme), unless required to do so by law.
- Implement appropriate technical and organisational security measures to protect Personal Information against loss, unauthorised access, destruction, or disclosure — including encryption at rest, access controls, and regular security reviews.
- Ensure that staff with access to Personal Information are bound by confidentiality obligations.
- Assist the Responsible Party in fulfilling its obligations to respond to Data Subject access, correction, and deletion requests received via the Platform.
- Notify the Responsible Party without undue delay — and in any event within 72 hours — of becoming aware of a personal information breach that affects their Users' data, providing sufficient detail to enable the Responsible Party to meet its own notification obligations under POPIA.
- Delete or return all relevant Personal Information upon termination of the Merchant Services Agreement, unless retention is required by law.
- Make available to the Responsible Party all information reasonably necessary to demonstrate compliance with this DPA.
4. Obligations of the Merchant as Responsible Party
The Merchant agrees to:
- Ensure it has a lawful basis for processing the Personal Information of its Programme participants, including obtaining consent from Users where required.
- Provide Users with a clear privacy notice that accurately describes how their data is used in connection with the Merchant's Programme, and to direct Users to LocalLoyalty's Privacy Policy for information about Platform-level processing.
- Not instruct LocalLoyalty to process Personal Information in a manner that would violate POPIA or any other applicable law.
- Promptly forward any Data Subject requests received directly by the Merchant (relating to Platform data) to privacy@localloyalty.co.za.
- Not export, copy, or retain User Personal Information obtained through the Platform for purposes unrelated to the operation of the Programme.
5. Sub-Processors
The Merchant authorises LocalLoyalty to engage the following categories of sub-processors to deliver the Platform services:
- Payment processing — PayFast (a service of PayFast Online (Pty) Ltd), used for gift card top-up transactions where applicable.
- Email delivery — a third-party transactional email provider, used to send top-up links, stamp receipts, and system notifications to Users.
- Cloud hosting — server and database infrastructure used to host the Platform and store data.
LocalLoyalty will notify the Responsible Party of any intended material changes to sub-processors with reasonable advance notice. All sub-processors are contractually bound to process Personal Information only as instructed and to maintain appropriate security standards.
6. Data Retention
- Active User data is retained for as long as the User maintains an account on the Platform.
- Stamp event records are retained for a minimum of 3 years for audit and dispute resolution purposes.
- Gift card transaction records are retained for a minimum of 5 years in compliance with financial record-keeping requirements.
- Upon a User's account deletion request, Personal Information is anonymised or deleted within 30 days, subject to legal retention obligations.
7. Cross-Border Transfers
LocalLoyalty stores and processes all Personal Information on servers located within South Africa or in jurisdictions that the Information Regulator has determined provide an adequate level of protection. Where data is transferred to a sub-processor outside South Africa, LocalLoyalty ensures appropriate safeguards are in place as required by POPIA section 72.
8. Information Regulator
Each party retains the right to lodge a complaint with the Information Regulator of South Africa if it believes the other party has processed Personal Information in violation of POPIA.
Information Regulator contact: inforegulator.org.za
9. Duration and Termination
This DPA remains in force for the duration of the Merchant Services Agreement. Clauses 3 (security and breach notification), 6 (data retention), and 4 (Merchant obligations) survive termination to the extent required by law.
10. Governing Law
This DPA is governed by the laws of the Republic of South Africa and is subject to the jurisdiction of South African courts.
11. Contact
Data-related queries and breach notifications should be directed to:
Information Officer — SkyL4rk PTY LTD · LocalLoyalty
privacy@localloyalty.co.za