Data Processing Addendum
Last updated: 23 July 2026
1. Introduction and scope
This Data Processing Addendum ("DPA") forms part of the agreement between you ("Customer") and Robert Brown trading as Browns Digital ("Browns Digital", "Operator", "we", "us") when you use Studio hosting and related services to process personal information of third parties (for example visitors to sites you publish).
This DPA supplements the Privacy Policy and Terms of Service. It applies only to personal information we process on your behalf as an operator under POPIA. It does not cover processing for which Browns Digital is the responsible party (account, billing, and platform administration).
2. Roles under POPIA
- Customer: typically the responsible party for personal information collected through forms, analytics, cookies, or other tooling on sites you publish.
- Browns Digital: the operator for personal information stored or transmitted on our hosting infrastructure as part of providing Studio publish and hosting services.
- You remain responsible for your own privacy notice to visitors and for ensuring your instructions are lawful.
3. Subject matter and duration
The subject matter is hosting, storage, transmission, backup, and related technical processing of content and data on Customer sites. Processing continues for the duration of the services and thereafter only as needed for deletion, backup roll-off, legal retention, or dispute resolution as described in the Privacy Policy.
4. Nature and purpose of processing
We process personal information only to provide the services: storing published content, serving pages and assets, disaster-recovery backups, security monitoring, abuse prevention, and support when you ask us to investigate a specific issue. We do not sell hosted-site personal information or use it for unrelated advertising.
5. Customer instructions
We will process personal information only on documented instructions from you, which include: (a) use of Studio and hosting features as configured by you; (b) the Terms, this DPA, and the Privacy Policy; and (c) reasonable written instructions you send us that are consistent with the services.
You warrant that your instructions are lawful and that you have a lawful basis under POPIA (or other applicable law) for the processing you ask us to perform. We will inform you if, in our opinion, an instruction infringes POPIA, unless law prohibits that notice.
6. Security measures
Taking into account the nature of a small shared hosting environment, we implement appropriate technical and organisational measures, including:
- access controls and least-privilege administrative access;
- transport encryption where supported (for example HTTPS);
- isolation of customer sites where architecture permits;
- logging of relevant administrative and security events;
- backup processes for disaster recovery.
Details and limitations are summarised in the Privacy Policy security section. You are responsible for application-level security on your site (forms, plugins, credentials you introduce, and third-party scripts you embed).
7. Subprocessors
You authorise us to engage infrastructure and service subprocessors reasonably necessary to deliver hosting (for example web hosting, DNS, database, email, or edge providers). Material subprocessors are listed or described in the Privacy Policy.
We remain responsible for subprocessors' performance insofar as they process personal information for us as operators. We will update the Privacy Policy subprocessor table for material changes and, where practicable, give notice before a change that materially affects hosted personal information.
8. Assistance with data subject requests
Taking into account the nature of processing, we will reasonably assist you with data-subject requests under POPIA that relate to hosting systems under our control, when you cannot fulfil them yourself from Studio, exports, or your own site tooling.
You remain primarily responsible for responding to your visitors. If a data subject contacts us directly about your site, we may redirect them to you and, where appropriate, notify you.
9. Personal information breach assistance
We will notify you without undue delay after becoming aware of a personal information breach affecting your hosted-site data, and provide information reasonably available to us to help you meet your notification duties under POPIA (including to the Information Regulator and affected data subjects where required).
Our notice will describe, to the extent known: the nature of the incident, categories of data involved, likely consequences, and measures taken or proposed.
10. Return and deletion
When you delete a site or your account, or when the services end, we will delete or de-identify hosted personal information according to the retention schedule in the Privacy Policy (including backup roll-off), unless law requires longer retention.
You should export any content you need before deletion. On written request made before deletion completes, we will make commercially reasonable efforts to provide a copy of hosted content then available to us in a common format.
11. Information and audits
On written request, we will provide information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality and security. Formal audits are available by mutual agreement, limited to once per 12-month period (unless a breach or regulatory requirement justifies more), conducted in a manner that does not compromise other customers or our infrastructure.
12. Liability and term
Liability under this DPA is subject to the limitations and exclusions in the Terms of Service, including the aggregate liability floor of the greater of fees paid in the relevant period or R500, except where liability cannot lawfully be limited.
This DPA remains in effect for as long as we process personal information on your behalf as an operator. Provisions that by nature should survive (including confidentiality, liability, and deletion) continue after termination.
13. Contact
- Email: legal@brownsdigital.org
- Help: https://help.brownsdigital.org
- Privacy Policy: /policies/privacy/
- Policies hub: /policies/
This DPA is a practical statement of our operator practices for a small South African SaaS. Customers with complex compliance needs (sector regulators, extensive cross-border programmes, or enterprise contracts) should obtain advice for their situation; we can discuss a signed addendum where required.