Data Processing & POPIA
Last updated: June 2026
This is a starting draft maintained by Triligy Systems. Before running paid campaigns, the wording and underlying practices should be reviewed by a qualified privacy and legal professional in your jurisdiction (including South African POPIA counsel).
1. Roles
When operating an assistant for a client, the client is the Responsible Party (POPIA) / Data Controller (GDPR). Triligy is the Operator / Data Processor and acts on the client's documented instructions.
2. Posture
Triligy maintains a GDPR- and POPIA-aligned posture. This page sets out the practices we apply. It is not a substitute for a signed Data Processing Agreement (DPA), which is provided as part of the order form on request.
3. Security measures
- Encryption of data in transit (TLS) and at rest.
- Role-based access controls, with access scoped to those who need it.
- Audit logging on administrative actions.
- Backup, recovery and incident-response procedures.
4. Sub-processors
We use vetted infrastructure and AI providers to deliver the service. A current list, including provider name, role, and hosting region, is provided on request and notified in advance of changes.
5. Retention and deletion
Retention windows for recordings, transcripts and notes are configurable per client. On termination, data is exported on request and then deleted according to the agreed schedule.
6. International transfers
Where personal information is transferred across borders, we rely on recognised lawful mechanisms (e.g. Standard Contractual Clauses or equivalent), and document this in the DPA.
7. Contact
Privacy enquiries: privacy@triligysystems.com