Data Processing Addendum

Last updated: 21 July 2026

This Data Processing Addendum ("DPA") forms part of the agreement between the business user ("Controller" / "Responsible Party") and DocBridge, operated by BVL Group of Companies ("Processor" / "Operator"), for the provision of the DocBridge Service. It describes how DocBridge processes personal information on the Controller's behalf in compliance with the Protection of Personal Information Act, 2013 (POPIA) and, where applicable, the EU General Data Protection Regulation (GDPR).

DocBridge is a product and trading name of BVL Group of Companies and is not a separate legal or juristic person; the contracting Operator under this DPA is BVL Group of Companies.

1. Roles

The Controller determines the purposes and means of processing the documents and personal information it collects through the Service. DocBridge processes that information only as an Operator on the Controller's documented instructions, which are given through the Controller's use of the Service and these terms.

2. Subject matter and duration

Processing continues for the duration of the Controller's use of the Service and until deletion or return of the relevant personal information as described below.

3. Nature and purpose of processing

Requesting, collecting, verifying, storing, reviewing, packaging and enabling the transfer of documents, and maintaining an audit trail of those activities, for the Controller's document-handover workflows.

4. Categories of data subjects and personal information

  • Data subjects: the Controller's clients, employees, suppliers, brokers and other third parties from whom documents are requested.
  • Personal information: contact details, identity and address documents, financial records, and any other information contained in documents the data subject uploads, which may include special or sensitive categories where the Controller requests them.

5. Operator obligations

  • Process personal information only on the Controller's instructions, unless required otherwise by law.
  • Ensure that persons authorised to process personal information are bound by confidentiality.
  • Implement appropriate technical and organisational security measures (see section 7).
  • Assist the Controller, taking into account the nature of processing, in responding to data-subject requests and in meeting its security, breach-notification and impact-assessment obligations.
  • Not engage another sub-processor without general written authorisation and notice of changes (see section 8).
  • On termination, delete or return personal information as directed by the Controller, subject to legal retention requirements.

6. Storage and access

Uploaded documents are stored in encrypted, private storage that is not publicly accessible. Access to a document occurs only through short-lived, expiring signed links issued to authorised users of the Controller. Each organisation's data is logically isolated by row-level security. Access to a request by a recipient is gated by a secret link and a one-time email verification code.

7. Security measures

  • Encryption of personal information in transit (TLS) and at rest.
  • Private document storage with expiring, signed download links.
  • Row-level isolation of each organisation's data.
  • Recipient verification via secret link and one-time code, with codes stored only in hashed form and rate-limited.
  • Immutable audit logging of actions performed against each request.
  • File-type restrictions and size limits on uploads.
  • Restricted internal access on a need-to-know basis.

8. Sub-processors

The Controller authorises DocBridge to engage the following sub-processors, each bound by data-protection obligations no less protective than this DPA:

  • Supabase / Lovable Cloud — cloud hosting, database and file storage.
  • Resend — transactional email delivery (secure links, verification codes, notifications).

We will give notice of any intended addition or replacement of a sub-processor so the Controller has an opportunity to object on reasonable data-protection grounds.

9. International transfers

Sub-processors may process personal information outside South Africa or the European Economic Area. Any such transfer is subject to appropriate safeguards recognised under POPIA and GDPR.

10. Data-subject requests and breaches

DocBridge will, without undue delay, notify the Controller of any request received directly from a data subject relating to the Controller's data, and of any confirmed personal-information breach affecting that data, and will provide reasonable assistance to enable the Controller to meet its notification and response obligations.

11. Deletion and return

The Controller may delete uploaded documents at any time through the Service. On termination, DocBridge will delete or, at the Controller's request, return remaining personal information within a reasonable period, except for audit-log records and other information we are required to retain by law, which are deleted or anonymised at the end of the applicable retention period.

12. Contact

For data-processing enquiries, contact privacy@thebvl.com.