POPIA Posture
Vulos processes personal information of South African data subjects as a Responsible Party under the Protection of Personal Information Act 4 of 2013 (POPIA). This document describes our lawful processing basis, data-subject rights, cross-border transfer posture, incident-notification obligations, and POPIA-specific definitions.
Section 1
Lawful Processing Basis
Vulos processes personal information only where at least one of the following conditions under POPIA s11 applies:
Consent (s11(1)(a))
The data subject has consented to the processing for the specific purpose (e.g. account registration, newsletter). Consent is recorded with timestamp and IP address. Withdrawal is supported at any time via the Privacy Dashboard.
Contractual necessity (s11(1)(b))
Processing is necessary to fulfil a contract to which the data subject is party (e.g. provisioning the Vulos service, billing, sending transactional emails).
Legal obligation (s11(1)(c))
Processing is required to comply with a legal obligation (e.g. retaining billing records for 5 years under the SA Tax Administration Act; preserving audit logs for regulatory purposes).
Legitimate interest (s11(1)(f))
Processing is necessary for pursuing a legitimate interest of Vulos or a third party, unless overridden by the data subject's rights (e.g. fraud prevention, security monitoring, aggregate analytics that cannot identify individuals). A Legitimate Interests Assessment (LIA) is on file for each use.
Section 2
Data Subject Rights under POPIA
POPIA confers the following rights on data subjects. Where POPIA and GDPR differ in scope or procedure, this document notes the SA-specific requirements.
Right of Access
Data subjects may request confirmation of whether Vulos holds their personal information, and receive a copy. Requests are fulfilled within 30 days (POPIA s57; extendable to 60 days in complex cases by written notice). Use the Privacy Dashboard for self-service export or email privacy@vulos.org.
Right to Correction or Deletion
Data subjects may request correction, destruction, or deletion of inaccurate, irrelevant, excessive, or unlawfully obtained personal information. SA-specific quirk: POPIA s24 couples correction and deletion in a single right (unlike GDPR Art.16 and Art.17 which are separate). Vulos honours both. The self-service deletion flow is at Privacy Dashboard.
Right to Object
Data subjects may object to the processing of their personal information on grounds relating to their particular situation where Vulos relies on legitimate interest (s11(1)(f)). Vulos will cease processing unless there are compelling legitimate grounds that override the objection, or the processing is necessary for legal claims.
Withdrawal of Consent
Where processing is based on consent, the data subject may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal. Vulos processes withdrawal requests within 5 business days.
Complaint to Information Regulator
Data subjects may lodge a complaint with the Information Regulator (South Africa) if they believe their POPIA rights have been violated. Contact: www.justice.gov.za/inforeg. Vulos encourages direct resolution first via privacy@vulos.org.
Notification of Collection
When collecting personal information, Vulos notifies the data subject of: the identity of the Responsible Party, the purpose of collection, whether collection is mandatory or voluntary, and the consequences of non-disclosure. This is provided via the Privacy Policy at vulos.org/privacy.
To exercise any of the above rights, use the Privacy Dashboard (authenticated) or email privacy@vulos.org with subject line POPIA Data Subject Request. Response time: 30 days for access requests; 5 business days for corrections, deletions, and objections.
Section 3
Information Officer
POPIA s1 requires every private body to designate an Information Officer responsible for POPIA compliance. Vulos's Information Officer is:
Information Officer — [Placeholder]
Name and contact details will be published here once registration with the Information Regulator is complete (POPIA s55). In the interim, all POPIA requests are handled by privacy@vulos.org.
Deputy Information Officer
POPIA s17A permits the designation of a Deputy Information Officer to assist. Designation is in progress.
Section 4
Cross-Border Transfer Posture
Under POPIA s72, personal information may only be transferred outside South Africa if the recipient country ensures an adequate level of protection, or if one of the POPIA s72 conditions is met (consent, contract necessity, public interest, legal claims).
Default: data stays in ZAR/JNB region
By default, customer data is stored in the af-south (Johannesburg) region on Tigris Object Storage. No personal information is transferred to another country without explicit customer configuration.
Opt-in replication to EU (latency)
Customers may opt in to replication to the eu-west region for lower latency in European markets. This opt-in constitutes explicit consent under POPIA s72(1)(a) and is covered by GDPR-grade SCCs under the DPA for EU data subjects.
Control-plane metadata (Fly.io iad/lhr/fra)
Account credentials and billing records are processed by the Vulos control plane on Fly.io (operated by Fly.io, Inc., United States). The control plane may be deployed in regions outside South Africa (iad, lhr, fra). This processing is covered by the Vulos DPA and is justified under POPIA s72(1)(b) (contractual necessity) and s72(1)(c) (recipient bound by substantially similar laws or binding agreement).
Section 5
Incident Notification
POPIA s22 requires a Responsible Party to notify the Information Regulator and affected data subjects "as soon as reasonably possible" after discovering a security compromise. The Act does not specify a precise timeframe; Vulos adopts the GDPR standard of 72 hours as its internal SLA, which satisfies both POPIA's reasonableness test and GDPR Art.33 simultaneously.
T+0 — Detection and containment
Immediate isolation of affected systems. Incident commander assigned; internal incident log opened.
T+72 h — Regulator + Controller notification (internal SLA)
Notification to the Information Regulator (SA) and affected data subjects / Controllers within 72 hours of Vulos becoming aware. Notification includes: nature of the compromise, categories of personal information involved, estimated number of data subjects, measures taken, and a contact for follow-up.
T+14 days — Full incident report
Detailed post-incident report covering root cause, full scope, remediation, and preventive measures. Delivered to affected parties and the Information Regulator.
Information Regulator (SA): www.justice.gov.za/inforeg · inforeg@justice.gov.za
Section 6
POPIA-Specific Definitions
Key terms as defined in POPIA that differ from or extend GDPR terminology:
| POPIA Term | Definition & Vulos context |
|---|---|
| Personal information | Information relating to an identifiable, living, natural person or an identifiable, existing juristic person (s1). SA-specific: juristic persons (companies) are covered — broader than GDPR which covers natural persons only. Vulos treats business customer data with the same care as individual personal data. |
| Special personal information (s26) | Information concerning religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health, sex life, biometric information, or criminal behaviour. Vulos does not intentionally collect or process special personal information. Users must not upload special PI to Vulos without prior written consent from Vulos. |
| Children's information (s34) | Personal information of persons under 18. POPIA s34 prohibits processing children's information without parental consent except in limited circumstances. Vulos services are not directed at persons under 18. Account registration requires acknowledgment of minimum age 18 (or legal majority in the user's jurisdiction). |
| Responsible Party | The entity that determines the purpose and means of processing personal information. Equivalent to GDPR "Controller." Vulos acts as Responsible Party for control-plane data and as Operator (below) for customer-bucket data. |
| Operator | A person who processes personal information for a Responsible Party under a mandate. Equivalent to GDPR "Processor." For data stored in customer buckets, Vulos acts as Operator on behalf of the customer (Responsible Party). The Vulos DPA constitutes the written mandate required by POPIA s20 and s21. |
| Processing | Any operation on personal information — collection, receipt, recording, organisation, collation, storage, updating, modification, retrieval, alteration, consultation, use, dissemination, distribution, merging, linking, blocking, degradation, erasure, or destruction (s1). Broader than colloquial usage. |
| De-identification | Removing or altering information so it cannot be linked to a specific data subject without additional information kept separately. Vulos uses de-identification (not full deletion) for billing records to satisfy both POPIA s14 (minimal processing) and SA Tax Administration Act retention obligations. |
Exercise your rights
Export or delete your data directly from the self-service Privacy Dashboard.
Open Privacy Dashboard →Data Processing Agreement
The Vulos standard DPA incorporates POPIA Operator obligations and cross-border transfer clauses.
Read the DPA →Full compliance posture
Data residency, encryption, SOC 2 status, sub-processors, and breach SLA.
Compliance posture →