Data Processing Addendum
Last updated 15 June 2026
This Addendum forms part of the Terms of Service and applies whenever SkyL4rk (Pty) Ltd (“we”, the operator/processor) processes personal information on your behalf (you being the responsible party/controller) through SkySignal. Terms such as “personal information”, “processing”, “responsible party” and “operator” carry their POPIA meanings; their GDPR equivalents (“controller”, “processor”) apply where the GDPR governs.
1. Roles
You are the responsible party for the campaign data you load into the Service — your recipient audiences and the people identified or depicted in your content. We process that data only as your operator, on your documented instructions, which comprise these terms plus the actions you take in the Service (creating, scheduling and publishing campaigns).
2. Subject-matter, nature & purpose
Nature & purpose: hosting, scheduling, transmitting and reporting on email and social campaigns you configure. Duration: for as long as your workspace is active, subject to the retention terms below. Data subjects: your email recipients and any individuals appearing in your content. Categories: names and email addresses of recipients; and any personal information contained in the copy or images you supply.
3. Our obligations
- process personal information only on your instructions, and tell you if an instruction appears to breach data-protection law;
- ensure people authorised to process it are bound by confidentiality;
- apply appropriate security measures (clause 6);
- assist you, so far as reasonable, with data-subject requests and with your own security, breach and impact-assessment obligations;
- notify you without undue delay after becoming aware of a security compromise affecting your data; and
- make available the information reasonably needed to show compliance with this Addendum.
4. Sub-operators
You authorise us to engage sub-operators to deliver the Service. We remain responsible for their processing. Current sub-operators:
- Hosting & storage — UK, where the application and uploaded media reside.
- Email delivery relay — our sending infrastructure, used to dispatch your campaign emails.
Separately, when you connect and publish to a social platform (e.g. Facebook, LinkedIn), you instruct us to transmit your content and images to that platform. The platform then processes that content as an independent responsible party under its own terms; it is a recipient you direct, not our sub-operator. We will give reasonable notice of any new sub-operator so you may object.
5. Cross-border processing
Where a sub-operator or directed recipient is located outside the Republic of South Africa, the transfer is made under a condition permitted by section 72 of POPIA and, for GDPR data, an appropriate safeguard.
6. Security
We maintain reasonable technical and organisational measures, including: encryption of stored social access tokens and account passwords; per-workspace access scoping; re-encoding of uploaded images to a clean format that strips embedded metadata; and audit logging of publishing events.
7. Retention & deletion
We hold your data only as long as it is needed to provide the Service:
Referenced (externally hosted) images
If you reference an image by URL hosted on your own or your client’s domain, we do not store the image — we retain only the reference and fetch the image from your server at the moment of publishing. The reference persists until you remove it.
Uploaded images
If you upload an image, we store a normalised copy plus a thumbnail. An uploaded image is retained while any scheduled or recently published post still relies on it, and becomes eligible for deletion 30 days after the last post that used it has been delivered — never while a future-dated post still needs it. Uploads that were never attached to a saved post are removed sooner by routine clean-up. We deduplicate identical uploads within a workspace by content hash; if a copy has already expired, re-uploading simply stores it again.
Campaign data & audiences
Retained for the life of your workspace or until you delete them, and on termination as set out in clause 9.
8. Deletion & data-subject requests
You can delete content in the Service at any time. On request we will delete or return specified personal information we hold on your behalf, unless we are required by law to keep it.
Erasure of published content. Because publishing transmits content to third-party platforms that keep their own copy, a complete erasure has two legs: (a) deleting the stored asset and its references in the Service, and (b) deleting the live post(s) from the platform(s) on which it was published. We will action (a) and will, where the platform’s capabilities and your connected permissions allow, assist with (b); content already cached or copied by a platform or its users may persist beyond our control. We keep a minimal erasure record (a content hash, who requested it, and when) as proof of action — it does not retain the deleted image itself.
9. Return or deletion on termination
On termination, and after any wind-down period stated in the Terms, we will delete or, at your election, return the personal information we process on your behalf, except where retention is required by law.
10. Audit
On reasonable written notice and subject to confidentiality, we will provide information reasonably necessary to demonstrate compliance with this Addendum.
11. Liability & precedence
Liability under this Addendum is subject to the limitations in the Terms. If this Addendum conflicts with the Terms on the processing of personal information, this Addendum prevails.
12. Contact
Data-protection matters: privacy@skysignal.co.za · SkyL4rk (Pty) Ltd, Ballito, KwaZulu-Natal, South Africa.