OPERATOR SCHEDULE AND DATA PROCESSING ADDENDUM
Date: 02/09/2026
Version: 1.0
1. PARTIES
1.1 AllWage (Pty) Ltd (Registration Number: 2018/531527/07), a private company duly incorporated in accordance with the laws of the Republic of South Africa, having its registered address at 5th Floor Bloukrans Building, Lynnwood Bridge, Pretoria, Gauteng, 0081 ("AllWage"); and
1.2 The person or entity identified as the customer in the Master Agreement (the “Client” or the “Responsible Party”), whose identifying particulars and address are recorded in the Master Agreement.
1.3 AllWage and the Responsible Party are individually referred to as a "Party" and collectively as the "Parties".
2. INTRODUCTION
This Operator Schedule and Data Processing Addendum (the "Addendum") forms part of, and is incorporated by reference into, the master service agreement or other written agreement between AllWage and the Responsible Party pursuant to which the Responsible Party accesses and uses the AllWage platform for payroll processing and related human-resources and remuneration administration services including time, attendance and payroll management, generating payslips, bank files and statutory reporting (the "Master Agreement") with effect from the Effective Date. It sets out the terms on which AllWage processes Personal Information as an Operator under the Protection of Personal Information Act 4 of 2013 ("POPIA") in connection with the Responsible Party's access to and use of the AllWage platform. The parties agree that this Addendum prevails in the event of any conflict with the Master Agreement on matters relating to POPIA processing.
NOW THEREFORE THE PARTIES AGREE AS FOLLOWS:
3. Definitions and interpretation
3.1 In this Addendum, unless the context indicates otherwise, the following expressions shall have the meanings set out below:
3.1.1 "Applicable Law" means the Protection of Personal Information Act 4 of 2013 ("POPIA"), any regulations promulgated thereunder, any applicable codes of conduct issued by the Information Regulator, and any other legislation of the Republic of South Africa applicable to the Processing of Personal Information, in each case as amended, re-enacted or replaced from time to time;
3.1.2 "Data Subject" means the person to whom Personal Information relates, as defined in section 1 of POPIA;
3.1.3 "Effective Date" means the effective date of the Master Agreement into which this Addendum is incorporated, unless the Parties agree a different commencement date for this Addendum in writing;
3.1.4 "Information Regulator" means the Information Regulator established in terms of section 39 of POPIA;
3.1.5 "Operator" means a person who processes Personal Information for a Responsible Party in terms of a contract or mandate, without coming under the direct authority of that party, as defined in section 1 of POPIA. For the purposes of this Addendum, the Operator is AllWage;
3.1.6 "Personal Information" means information relating to an identifiable, living, natural person, and where it is applicable, an identifiable, existing juristic person, as defined in section 1 of POPIA and for the purposes of this Addendum refers to any information Processed by AllWage and/or its sub-processors on behalf of the Responsible Party relating to an identified or identifiable natural person or juristic person, where required;
3.1.7 "POPIA" means the Protection of Personal Information Act 4 of 2013, as amended from time to time, including any regulations promulgated and codes of conduct issued thereunder;
3.1.8 "Master Agreement" means the agreement between the Parties in terms of which the Responsible Party utilises the AllWage platform for payroll processing and related human-resources and remuneration administration services including time, attendance and payroll management, generating payslips, bank files and statutory reporting;
3.1.9 "Processing" means any operation or activity or any set of operations, whether or not by automatic means, concerning Personal Information, including the collection, receipt, recording, organisation, collation, storage, updating or modification, retrieval, alteration, consultation, use, dissemination by means of transmission, distribution or making available in any other form, merging, linking, as well as restriction, degradation, erasure or destruction of information, as defined in section 1 of POPIA; and "Process", "Processes" and "Processed" shall be construed accordingly;
3.1.10 "Responsible Party" means a public or private body or any other person which, alone or in conjunction with others, determines the purpose of and means for processing Personal Information, as defined in section 1 of POPIA. For the purposes of this Addendum, the Responsible Party is identified in the preamble above;
3.1.11 "Security Compromise" means any instance where there are reasonable grounds to believe that the Personal Information of a Data Subject has been accessed or acquired by any unauthorised person, as contemplated in sections 21 and 22 of POPIA;
3.1.12 "Special Personal Information" means Personal Information concerning a Data Subject's religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, or criminal behaviour, as contemplated in sections 26 to 33 of POPIA;
3.1.13 "Sub-Operator" means any third party engaged by the Operator to Process Personal Information on behalf of the Responsible Party in connection with this Addendum.
3.2 Words and expressions defined in POPIA and not otherwise defined herein shall bear the same meanings as assigned to them in POPIA.
3.3 References to sections are to POPIA unless context indicates otherwise. The words include and including are not limiting.
3.4 Clause headings are for convenience only and shall not be used in interpretation.
4. Scope and purpose
4.1 This Addendum applies to the Processing of Personal Information by AllWage, who acts as an Operator, on behalf of the Responsible Party in accordance with the categories of Personal Information, Data Subjects and the nature and purposes of Processing described in Annexure A, which is tailored to the Responsible Party's use of the AllWage platform for payroll processing and related human-resources and remuneration administration services including time, attendance and payroll management, generating payslips, bank files and statutory reporting.
4.2 AllWage will Process Personal Information only for the purpose of performing its obligations under the Master Agreement and only in accordance with the documented instructions of the Responsible Party, as set out in this Addendum (including Annexure A), the Master Agreement, the Responsible Party's configurations and in-portal settings and any further written instructions given by the Responsible Party from time to time.
4.3 AllWage shall not Process Personal Information for any purpose (including AllWage’s own marketing, profiling, or sales purposes) other than as set out in this Addendum or as otherwise documented in writing by the Responsible Party, save where required to do so by Applicable Law, in which event AllWage shall (to the extent permitted by such law) inform the Responsible Party of that legal requirement prior to Processing**.**
4.4 AllWage may process de‑identified or aggregated information for service analytics and improvement, provided the data cannot reasonably be re‑identified and no attempts to re‑identify are made.
4.5 AllWage will not sell Personal Information.
4.6 AllWage may suspend Processing on written notice where it reasonably believes that continuing to Process in accordance with a Responsible Party's instruction would contravene POPIA or any other Applicable Law. AllWage shall be entitled to suspend the relevant Processing pending the Responsible Party's clarification or amendment of the instruction, and shall not be liable for any delay or failure to perform resulting from such suspension.
5. Obligations of allwage as operator
5.1 AllWage shall, in respect of all Personal Information Processed on behalf of the Responsible Party:
5.1.1 Process Personal Information only with the knowledge or authorisation of the Responsible Party and only on the Responsible Party's documented instructions, unless required to Process by Applicable Law, in which case AllWage shall inform the Responsible Party of that legal requirement before the relevant Processing unless such law prohibits such information on important grounds of public interest;
5.1.2 treat all Personal Information as confidential and ensure that all persons authorised by AllWage to Process Personal Information have committed themselves to appropriate obligations of confidentiality (whether contractual or statutory);
5.1.3 implement and maintain appropriate, reasonable technical and organisational measures to secure the integrity and confidentiality of Personal Information in its possession or under its control, in accordance with section 19 of POPIA. The measures implemented by AllWage as at the Effective Date are described in Annexure B;
5.1.4 taking into account the nature of the Processing, assist the Responsible Party by appropriate technical and organisational measures, insofar as this is reasonably possible, in fulfilling the Responsible Party's obligations to respond to requests from Data Subjects exercising their rights, in accordance with clause 8;
5.1.5 taking into account the nature of Processing and the information available, provide reasonable assistance to the Responsible Party, on request and at cost where not included in support, with personal information impact assessments, consultations with the Information Regulator, and prior authorisation processes that relate to the services.
5.1.6 assist the Responsible Party in ensuring compliance with its obligations under sections 19 to 22 of POPIA (security of processing and notification of Security Compromises), taking into account the nature of Processing and the information available to AllWage;
5.1.7 at the election of the Responsible Party, return or securely delete or destroy all Personal Information after the end of the provision of services relating to Processing, and delete existing copies unless Applicable Law requires retention of the Personal Information, in accordance with clause 12; and
5.1.8 make available to the Responsible Party all information reasonably necessary to demonstrate compliance with the obligations laid down in section 21 of POPIA and this Addendum, and allow for and contribute to audits, including inspections, conducted by the Responsible Party or an auditor mandated by the Responsible Party.
5.2 With regard to clause 5.1.8:
5.2.1 the Responsible Party shall give AllWage not less than 30 (thirty) business days prior written notice of any proposed audit or inspection;
5.2.2 audits shall be conducted during normal business hours and must not unreasonably interfere with AllWage’s business operations;
5.2.3 auditors must protect AllWage’s and other customers’ confidentiality and security, and audits must be limited to information necessary to assess compliance with this Addendum and POPIA sections 19 - 21;
5.2.4 the Responsible Party bears all audit costs unless the audit reveals a material, uncured breach of this Addendum by AllWage, in which case AllWage shall bear the reasonable costs thereof;
5.2.5 the Responsible Party shall not be entitled to exercise its audit rights more than once in any 12 (twelve) month period, unless a Security Compromise has occurred or the Information Regulator requires an additional audit; and
5.2.6 all auditors shall be bound by obligations of confidentiality no less onerous than those contained in the Master Agreement and shall not be a competitor of AllWage.
6. Obligations of the Responsible Party
6.1 The Responsible Party warrants, represents and undertakes that:
6.1.1 it has a lawful basis under POPIA for the collection and Processing of all Personal Information provided to AllWage, and for the disclosure of such Personal Information to AllWage for Processing under this Addendum, including (where applicable) the consent of the relevant Data Subjects;
6.1.2 all authorisations, consents, registrations and notifications required under Applicable Law have been obtained, given or made (as applicable) prior to providing Personal Information to AllWage, including the provision of notifications to Data Subjects in accordance with section 18;
where Personal Information includes biometrics used for attendance, health records, or trade union membership for deductions, the Responsible Party warrants that section 26 prohibitions are lifted by applicable authorisations under sections 27 - 33, including explicit consent where required, and that any prior authorisation under sections 57 - 58 for transfers of Special Personal Information to foreign countries lacking adequate protection has been obtained before instructing AllWage to Process.
6.1.3 If children’s Personal Information is processed, the Responsible Party warrants that sections 34 - 35 conditions are satisfied and that any prior authorisation under sections 57 - 58 is secured where applicable.
6.1.4 all instructions given to AllWage in respect of the Processing of Personal Information are and shall at all times be lawful and in compliance with POPIA and any other Applicable Law and will be provided in writing through the Master Agreement, this Addendum, and the platform’s documented configuration capabilities; and
6.1.5 it has complied and shall continue to comply with its own obligations as a responsible party under POPIA, including the conditions for the lawful Processing of Personal Information.
6.2 The Responsible Party is solely responsible for the accuracy, quality, and legality of Personal Information uploaded or entered into the platform and for the means by which the Responsible Party acquired such Personal Information.
6.3 The Responsible Party acknowledges that AllWage is entitled to rely on the Responsible Party's instructions and the accuracy of the Responsible Party's warranties, and that AllWage shall not be liable for any loss, claim, cost, fine, penalty or damage arising from or in connection with the Responsible Party's breach of its obligations under this clause 6 or under POPIA.
6.4 The Responsible Party shall promptly inform AllWage of any changes to the Personal Information or to its instructions that may affect AllWage's ability to perform its obligations under this Addendum.
7. Sub‑operators (sub‑processors)
7.1 The Responsible Party authorises AllWage to engage Sub-Operators to carry out any Processing activities on behalf of the Responsible Party provided that AllWage:
7.1.1 carries out adequate due diligence to ensure that the Sub-Operator is capable of providing the level of protection for Personal Information required by this Addendum and Applicable Law;
7.1.2 ensures that the arrangement between AllWage and the Sub-Operator is governed by a written contract which imposes on the Sub-Operator data protection obligations no less onerous than those set out in this Addendum (including, where applicable, equivalent obligations in respect of cross-border transfers under section 72 of POPIA); and
7.1.3 remains responsible to the Responsible Party for the performance of each Sub-Operator's obligations, provided that such liability shall be subject to the limitations and exclusions set out in clause 13 of this Addendum.
7.2 AllWage will maintain an up‑to‑date list of material Sub‑operators for the processing services on request and shall inform the Responsible Party in writing of any intended changes concerning the addition or replacement of Sub-Operators, providing the Responsible Party with a reasonable opportunity (being not less than 15 (fifteen) business days from the date of such notice) to object to such changes.
7.3 If the Responsible Party objects under clause 7.2 on reasonable grounds relating to the protection of Personal Information, the Parties shall discuss the objection in good faith, and AllWage shall use reasonable endeavours to make available an alternative solution that does not involve the proposed Sub-Operator. Pending resolution, AllWage shall not engage the proposed Sub-Operator to Process the Responsible Party’s Personal Information, and the Responsible Party may suspend the affected service. If the objection remains unresolved and no reasonable alternative is available, either Party may terminate the affected service on 30 (thirty) days’ written notice without penalty. Such termination shall extend only to services that depend on the proposed Sub-Operator. This Addendum shall continue to apply to any Personal Information that AllWage continues to Process.
8. Data subject rights
8.1 AllWage shall, taking into account the nature of the Processing and AllWage’s features, provide reasonable technical and organisational assistance, on written request by and at the Responsible Party’s cost where not included in support, to enable the Responsible Party to respond to Data Subject requests in exercising their rights under POPIA, including (without limitation) rights of:
8.1.1 access to Personal Information;
8.1.2 correction or deletion of Personal Information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained; and
8.1.3 the destruction or deletion of a record of Personal Information.
8.1.4 The assistance described above applies to Personal Information Processed on the platform and includes assistance with related requests under the Promotion of Access to Information Act 2 of 2000, where applicable.
8.2 Where AllWage receives a request directly from a Data Subject in respect of Personal Information Processed under this Addendum, AllWage will:
8.2.1 promptly notify the Responsible Party of such request;
8.2.2 not respond directly unless required to do so by Applicable Law (in which case AllWage shall, to the extent legally permitted, inform the Responsible Party of that legal requirement before responding) or unless expressly instructed to do so by the Responsible Party in writing**;** and
8.2.3 provide such reasonable co-operation and assistance as the Responsible Party may request to enable the Responsible Party to respond to the Data Subject within the timeframes required by POPIA.
8.3 The Responsible Party remains responsible for making determinations on the lawfulness of requests and for communications with Data Subjects.
9. Security safeguards
9.1 AllWage will implement appropriate, reasonable technical and organisational security measures to protect the integrity and confidentiality of Personal Information against loss, damage, unauthorised destruction, and unlawful access or processing, having regard to generally accepted information security practices and procedures, and will regularly verify and update safeguards as required by section 19(2) - (3).
9.2 Without limiting the generality of clause 9.1, AllWage shall:
9.2.1 identify all reasonably foreseeable internal and external risks to Personal Information in its possession or under its control;
9.2.2 establish and maintain appropriate safeguards against the risks identified;
9.2.3 regularly verify that the safeguards are effectively implemented; and
9.2.4 ensure that the safeguards are continually updated in response to new risks or deficiencies in previously implemented safeguards.
9.3 The technical and organisational measures implemented by AllWage as at the Effective Date are described in Annexure B.
9.4 AllWage will ensure persons authorised to process the Personal Information have committed themselves to confidentiality obligations or are under an appropriate statutory duty of confidentiality, and are trained on data protection responsibilities proportionate to their role.
9.5 The Responsible Party acknowledges that security and privacy outcomes depend in part on its own role‑based access configurations, user management, and device deployment choices, and undertakes to apply least‑privilege access aligned to its policies.
10. Breach notification
10.1 AllWage will notify the Responsible Party without undue delay and in any event within 72 hours of becoming aware of or have reasonable grounds to believe that a Security Compromise affecting Personal Information processed on behalf of the Responsible Party under this Addendum, in compliance with section 21(2) of POPIA.
10.2 Such notification shall include, to the extent reasonably available to AllWage at the time of notification:
10.2.1 a description of the nature of the Security Compromise, including (where possible) the categories and approximate number of Data Subjects affected and the categories and approximate number of Personal Information records concerned;
10.2.2 the name and contact details of AllWage's designated contact person from whom further information may be obtained;
10.2.3 a description of the likely consequences of the Security Compromise; and
10.2.4 a description of the measures taken or proposed to be taken by AllWage to address the Security Compromise, including (where appropriate) measures to mitigate its possible adverse effects.
10.3 Where and in so far as it is not possible to provide all information at the same time, the information may be provided in phases without undue further delay.
10.4 AllWage shall co-operate with the Responsible Party and take such reasonable steps as the Responsible Party may direct to assist in the investigation, mitigation and remediation of the Security Compromise.
10.5 The Responsible Party acknowledges and agrees that:
10.5.1 the obligation to notify the Information Regulator and affected Data Subjects of a Security Compromise rests with the Responsible Party in accordance with section 22 of POPIA, and AllWage's role is to notify the Responsible Party and assist in discharging that obligation;
10.5.2 AllWage shall not be liable for any delay in notification to the extent that such delay is attributable to the Responsible Party's failure to provide information, instructions or a response reasonably requested by AllWage; and
10.5.3 AllWage's initial notification under clause 10.1 may be provided on the basis of preliminary and incomplete information, and AllWage shall supplement such notification as further information becomes reasonably available.
10.6 Notification is not an admission of fault or liability.
11. Cross‑border transfers
11.1 The Responsible Party acknowledges that certain Sub‑operators or communications platforms may process Personal Information outside South Africa, for example, WhatsApp message delivery infrastructure or cloud hosting providers, which may constitute cross‑border transfers under section 72.
11.2 AllWage shall not transfer Personal Information to a third party in a foreign country or to an international organisation outside the Republic of South Africa without the Responsible Party's knowledge and unless the transfer complies with section 72 of POPIA.
11.3 A transfer of Personal Information to a recipient in a foreign country shall only be permitted where one or more of the following conditions is satisfied:
11.3.1 the recipient of the Personal Information is subject to a law, binding corporate rules or a binding agreement which provides an adequate level of protection that effectively upholds principles for the reasonable Processing of Personal Information that are substantially similar to the conditions for the lawful Processing of Personal Information set out in Chapter 3 of POPIA;
11.3.2 the Data Subject has consented to the transfer;
11.3.3 the transfer is necessary for the performance of a contract between the Data Subject and the Responsible Party, or for the implementation of pre-contractual measures taken in response to the Data Subject's request;
11.3.4 the transfer is necessary for the conclusion or performance of a contract concluded in the interest of the Data Subject between the Responsible Party and a third party; or
11.3.5 the transfer is for the benefit of the Data Subject and it is not reasonably practicable to obtain the consent of the Data Subject to the transfer, and if it were reasonably practicable, the Data Subject would be likely to give such consent.
11.4 Where AllWage engages a Sub-Operator in connection with a cross-border transfer, AllWage shall ensure that the Sub-Operator is bound by equivalent transfer obligations as those set out in this clause 11.
11.5 AllWage shall provide the Responsible Party with such information as may be reasonably required to enable the Responsible Party to satisfy itself that the conditions set out in section 72 of POPIA have been met in respect of any cross-border transfer.
11.6 If the Responsible Party instructs AllWage to transfer Special Personal Information or the Personal Information of children to a third party in a foreign country that does not provide an adequate level of protection, the Responsible Party warrants that any required prior authorisation under section 57(1)(d) has been obtained and notified to the Regulator under section 58 before instructing AllWage, and will provide evidence on request.
12. Term and termination
12.1 This Addendum commences on the Effective Date and continues for as long as AllWage Processes Personal Information on behalf of the Responsible Party under the Master Agreement.
12.2 This Addendum shall automatically terminate upon the later of:
12.2.1 the termination or expiry of the Master Agreement; and
12.2.2 the date on which AllWage ceases to Process all Personal Information on behalf of the Responsible Party.
12.3 Upon termination or expiry of the Master Agreement or an affected service, the Responsible Party shall, within 30 (thirty) days, notify AllWage in writing whether it requires the export or deletion of the Personal Information relating to the terminated services and no longer required for any continuing services. AllWage shall act on that election as soon as reasonably practicable and no later than 30 (thirty) days after receiving it, by either:
12.3.1 make available for secure export to the Responsible Party a copy of Personal Information in a commonly used, machine‑readable format, or
12.3.2 securely delete or de‑identify Personal Information, and will provide written confirmation upon completion. Where deletion is not feasible (e.g., backups or legal holds), AllWage will continue to protect it per this Addendum and will not actively process it except for storage and proof.
12.4 Notwithstanding clause 12.3, AllWage shall be entitled to retain Personal Information to the extent required by Applicable Law (including, without limitation, tax legislation, payroll record-keeping obligations, and the requirements of the Basic Conditions of Employment Act 75 of 1997), in which case:
12.4.1 such retained Personal Information shall remain subject to the confidentiality and security obligations of this Addendum for the duration of its retention;
12.4.2 AllWage shall not Process such retained Personal Information for any purpose other than compliance with the applicable legal obligation; and
12.4.3 AllWage shall securely delete or destroy such Personal Information upon expiry of the applicable retention period.
12.5 If the Responsible Party does not communicate its election within the 30 (thirty) day period specified in clause 12.3, AllWage shall securely delete or destroy the Personal Information concerned as soon as reasonably practicable and no later than 30 (thirty) days after that period expires, subject to the retention provisions in clauses 12.3.2 and 12.4.
12.6 The following provisions shall survive termination or expiry of this Addendum: clause 3 (Definitions and Interpretation), clause 5.1.2 (Confidentiality), clause 6 (Obligations of the Responsible Party), clause 10 (Security Compromise Notification, to the extent of ongoing obligations), clause 11 (Cross-Border Transfers, to the extent Personal Information is retained post-termination), clause 12 (Term and Termination), clause 13 (Liability and Indemnities), clause 14 (Governing Law and Jurisdiction), and clause 15 (General).
13. Liability and Indemnities
13.1 Subject to clause 13.6 AllWage's total aggregate liability under or in connection with this Addendum, whether in contract, delict (tort), under statute or otherwise, shall not exceed an amount equal to the fees actually paid by the Responsible Party to AllWage in terms of the Master Agreement during the 12 (twelve) month period immediately preceding the event giving rise to the claim, or R100,000.00 (whichever is the lesser).
13.2 AllWage shall not be liable for any:
13.2.1 indirect, special, incidental or consequential loss or damage;
13.2.2 loss of profit, loss of revenue, loss of business or loss of anticipated savings;
13.2.3 loss of data (save for AllWage's obligation to implement security measures under this Addendum); or
13.2.4 loss of goodwill or reputation,
however arising, even if AllWage has been advised of the possibility of such loss or damage.
13.3 AllWage shall not be liable for any loss, damage, claim, cost, expense, fine, penalty or liability arising from or in connection with:
13.3.1 AllWage's compliance with the Responsible Party's documented instructions;
13.3.2 the Responsible Party's breach of its warranties, representations or obligations under this Addendum or under POPIA;
13.3.3 the Responsible Party's failure to obtain necessary consents, authorisations or to make required notifications to Data Subjects; or
13.3.4 the inaccuracy, incompleteness or unlawfulness of Personal Information provided by the Responsible Party to AllWage;
13.3.5 the results obtained from the use of the platform by the Responsible Party and for the conclusions drawn from such use.
13.4 The Responsible Party shall indemnify and hold harmless AllWage and its directors, employees, and Sub‑operators from and against all losses, liabilities, penalties, administrative fines, costs, and expenses arising from or in connection with:
13.4.1 any unlawful instruction given by the Responsible Party to AllWage;
13.4.2 any breach by the Responsible Party of its warranties, representations or obligations under clause 6 of this Addendum;
13.4.3 the Responsible Party's failure to obtain necessary consents, authorisations or to make required notifications under POPIA; and
13.4.4 any third-party claim (including a claim by a Data Subject or the Information Regulator) to the extent that such claim arises from the Responsible Party's breach of this Addendum, the Master Agreement or Applicable Law.
13.5 AllWage shall indemnify the Responsible Party against direct damages finally awarded by a court of competent jurisdiction or agreed in settlement (approved in writing by AllWage) to the extent arising from AllWage’s material breach of its obligations under clauses 5, 7, 8 or 9, provided that the Responsible Party mitigates loss and promptly notifies and cooperates with AllWage.
13.6 Nothing in this Addendum shall exclude or limit liability for fraud, wilful misconduct or gross negligence, or any liability which cannot be excluded or limited by Applicable Law.
14. Governing law and jurisdiction
This Addendum and any dispute or claim arising out of or in connection with it are governed by the laws of the Republic of South Africa. The parties submit to the non-exclusive jurisdiction of the High Court of South Africa, Gauteng Division, Pretoria in relation to any such dispute, without prejudice to any statutory right to lodge a complaint with the Information Regulator.
15. General
15.1 Relationship with the Master Agreement. This Addendum supplements and forms part of the Master Agreement. Except as expressly modified by this Addendum, all terms and conditions of the Master Agreement remain in full force and effect. In the event of any conflict or inconsistency between this Addendum and the Master Agreement in respect of the protection of Personal Information or the Processing thereof, the provisions of this Addendum shall prevail.
15.2 Entire agreement. This Addendum (together with the Master Agreement and Annexures A and B) constitutes the entire agreement between the Parties in relation to its subject matter and supersedes all prior agreements, understandings, negotiations and discussions (whether oral or written) between the Parties in relation thereto.
15.3 Variation. No amendment, modification or variation of this Addendum shall be binding on either Party unless reduced to writing and signed by or on behalf of each Party.
15.4 Severability. If any provision of this Addendum is held by any court or competent authority to be invalid, unlawful or unenforceable to any extent, such provision shall to that extent be severed from the remaining provisions, which shall continue to be valid and enforceable to the fullest extent permitted by law. The Parties shall negotiate in good faith to agree a replacement provision that, to the greatest extent possible, achieves the intended commercial result of the severed provision.
15.5 No waiver. No failure or delay by a Party in exercising any right, power or remedy under this Addendum shall operate as a waiver of that right, power or remedy, nor shall any single or partial exercise of any such right, power or remedy preclude any other or further exercise thereof or the exercise of any other right, power or remedy.
15.6 Notices. Any notice required or permitted to be given under this Addendum shall be in writing and delivered to the relevant Party at the address or email address set out below (or such other address as that Party may designate by written notice from time to time):
To AllWage: 5th Floor Bloukrans Building Lynnwood Bridge
Pretoria
Gauteng, 0081
Email: info@allwage.com / cilliers@allwage.com
To Responsible Party: The physical address and email address designated by the Client for notices in the Master Agreement.
16. EXECUTION
This Addendum, including Annexures A and B, is accepted by the Parties through execution of the Master Agreement into which it is incorporated and does not require separate signature.
1. : Description of processing (AllWage services)
The categories and activities below apply to the extent relevant to the services used by the Responsible Party and its documented instructions and configurations.
1. Categories of Data Subjects
1.1 Employees, wage earners, contractors, and temporary or seasonal workers whose time, attendance, activities, documents, and payroll are administered by the Responsible Party on AllWage.
1.2 Responsible Party administrators, managers, and supervisors with portal access.
2. Categories of Personal Information
2.1 Identity and contact information: names, employee numbers, South African ID or passport numbers, mobile numbers, email addresses.
2.2 Employment and attendance information: worksite allocations, clock‑in/out timestamps, shifts, overtime and short time, leave requests and approvals, daily activities, project/task data, supervisor assignments, notes and overrides.
2.3 Biometric and clocking information: fingerprint or facial recognition templates or images where enabled; RFID wristband identifiers; facial clocking validation outcomes; device and event metadata.
2.4 Location information: location recorded when employees clock using AllWage hardware devices or WhatsApp clocking, where enabled.
2.5 HR documentation: contracts, licences, training certificates, safety certificates, medical or fitness‑to‑work records, document expiry alerts.
2.6 Payroll and financial information: earnings, deductions, benefits, overtime and piece‑rates, pay run templates, payslips, bank account details, SARS tax numbers, UIF/SDL items, provident fund and union deductions where applicable, bank file outputs.
2.7 Statutory reporting data: EMP201, EMP501, UIF declarations, IRP5/IT3(a), bargaining council outputs (e.g., BIBC) where configured.
2.8 System and security data: role‑based permissions, full audit logs of changes, support tickets.
3. Special Personal Information processed (as configured by the Responsible Party)
3.1 Biometric information (fingerprint, facial recognition).
3.2 Health information contained in medical or fitness‑to‑work documentation.
3.3 Trade union membership information where used for payroll deductions**.**
4. Nature and purpose of processing
4.1 Capturing and verifying attendance and activities; managing shifts, breaks, and leave; preventing ghost workers (e.g., biometric and facial validation; RFID clocking).
4.2 Consolidating time data into payroll; generating payslips and bank files; delivering payslips and operational notices via WhatsApp; supporting dispute resolution through audit logs.
4.3 Maintaining a central HR repository; tracking document expiries and compliance alerts; supporting industrial and statutory reporting.
5. Processing operations
Collection, recording, organisation, collation, storage, retrieval, consultation, use, transmission, distribution or making available, merging, linking, restriction, and deletion or destruction, as necessary to provide the services.
6. Duration of processing
Personal Information is Processed for the duration specified in clause 12 of this Addendum. Its return, deletion, de-identification and any continued retention are governed by that clause.
7. Sub‑operators and cross‑border elements
Material categories may include: cloud hosting and infrastructure; secure messaging and payslip delivery (including WhatsApp); device vendors or managed services; analytics and monitoring tools. Some Sub-Operators may Process Personal Information outside South Africa. Such transfers shall comply with section 72 of POPIA and clause 11 of this Addendum.
8. Security measures (summary)
Role‑based access; multi‑factor authentication for all access to systems processing Personal Information; transport encryption (TLS 1.2 or higher); encryption at rest (AES‑256 or equivalent industry‑standard encryption); least‑privilege access; complete audit logging; secure payslip access and delivery; hardened device configurations; operator contractual controls.
9. Data export and deletion procedures
Standard export formats for payroll and attendance data; secure export of document repositories on request; deletion routines including cryptographic erasure for applicable stores; backup retention and eventual expiry with no active processing.
2. - TECHNICAL AND ORGANISATIONAL SECURITY MEASURES
AllWage has implemented and maintains the following technical and organisational security measures in accordance with section 19 of POPIA, having due regard to generally accepted information security practices and procedures (as updated from time to time in accordance with clause 5.1.3 of this Addendum, provided that such updates do not materially diminish the overall level of security):
1. Access Controls
Role-based access controls restricting access to Personal Information to authorised personnel on a need-to-know basis; multi-factor authentication for access to systems Processing Personal Information; unique user credentials; automatic session timeouts; and procedures for timely de-provisioning upon termination of employment or engagement.
2. Encryption
Encryption of Personal Information in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent industry-standard encryption); encrypted backup storage.
3. Network and Systems Security
Firewalls; intrusion detection and prevention systems; network segmentation; regular vulnerability assessments and penetration testing; malware protection; and timely application of security patches and updates.
4. Physical Security
Data centre facilities with physical access controls (biometric or card-based entry), CCTV monitoring, environmental controls (fire suppression, climate control), and redundant power supply.
5. Business Continuity and Disaster Recovery
Regular data backups (with tested restoration procedures); documented disaster recovery plan; redundant infrastructure; and defined recovery time and recovery point objectives.
6. Personnel Security
Pre-employment screening (background checks) for personnel with access to Personal Information; written confidentiality obligations; regular information security awareness training; and disciplinary procedures for breach of security policies.
7. Incident Detection and Response
Documented incident response plan; designated incident response team; procedures for detection, escalation, containment, investigation, remediation and post-incident review of Security Compromises.
8. Audit, Logging and Monitoring
Centralised logging and monitoring of access to systems Processing Personal Information; retention of audit logs for the periods specified in AllWage’s documented retention schedules, subject to Applicable Law and clause 12 of this Addendum; regular internal security audits; and periodic independent third-party security assessments.
9. Data Minimisation and Retention
Processing limited to Personal Information that is adequate, relevant and not excessive for the stated purposes; documented retention schedules aligned with Applicable Law; and secure disposal (overwriting or physical destruction) upon expiry of retention periods.
Back to top ↑