Sigmund
Log in Contact us

Data Processing Addendum

Sigmund (Pty) Ltd Version 1.1 · Effective 16 September 2026

This Addendum forms part of the Sigmund Terms of Service and records the written contract required by section 21 of the Protection of Personal Information Act 4 of 2013 ("POPIA") between a responsible party and its operator.

Where you have signed a separate data processing agreement with us, that agreement supersedes this Addendum.


1. Roles

You are the responsible party. Sigmund is your operator. You determine the purpose and means of processing Applicant Data; we process it on your documented instructions.

Where we process personal information for our own purposes, being our website visitors, our mailing list and our own customer contacts, we act as responsible party and our Privacy Policy applies instead.

2. Scope of processing

Subject matter Provision of the Sigmund platform and related services
Duration The term of the Terms of Service, plus the deletion period in clause 9
Nature and purpose Collection, validation, storage, classification, extraction, analysis and presentation of application documents and related information, and any further processing you configure
Categories of data subject The categories you elect to process through the Platform, which typically include applicants for financial, property, insurance and comparable applications, and persons connected to them. This list is descriptive and not exhaustive; it extends to any category you configure the Platform to process.
Categories of personal information The categories you elect to collect, which typically include identity, contact, address, income, employment, banking and tax information, application correspondence, and metadata generated by the Platform. This list is descriptive and not exhaustive.
Special personal information Only where you configure the Platform to collect it, and only on a ground you have established under sections 27 to 35 of POPIA

Your configuration of the Platform from time to time constitutes your documented instruction for the purposes of this clause, without the need to amend this Addendum.

3. Our obligations

In line with sections 20 and 21 of POPIA, we will:

a) process Applicant Data only on your documented instructions, unless the law requires otherwise, in which case we will tell you first unless prohibited from doing so;

b) treat Applicant Data as confidential, and ensure that everyone we authorise to process it is bound by a written confidentiality obligation;

c) maintain the security safeguards described in clause 5;

d) not use Applicant Data for our own purposes, except for the de-identified model improvement described in clause 8 and the service data described in the Terms;

e) notify you of a security compromise in accordance with clause 10;

f) assist you with data subject requests and security compromise notifications, as set out in clauses 9 and 10;

g) delete Applicant Data on termination, as set out in clause 11;

h) make available the information you reasonably need to demonstrate our compliance with this Addendum.

4. Your obligations

You warrant that you have a lawful basis for the processing you instruct, that your instructions are lawful, and that you have given Applicants the notice required by section 18 of POPIA, whether directly or through the applicant notice we display on your behalf.

You are responsible for the accuracy of the configurable content in that notice, for the access rights you grant your own personnel, and for exporting and retaining any records the law requires you to keep.

5. Security safeguards

We apply technical and organisational measures appropriate to the risk, as required by section 19 of POPIA. These currently include:

  • encryption of data in transit using Transport Layer Security, and encryption of data at rest;
  • access to production systems restricted to named individuals on a least-privilege basis, granted and revoked under a documented process;
  • logical separation of each customer's data, with controls preventing cross-customer access;
  • logging of system and access events;
  • encrypted, regularly taken backups;
  • peer review of code changes before release, and secrets held in a managed secrets store rather than in source code;
  • written confidentiality undertakings for all personnel with access to Applicant Data.

Further detail on our current security measures is available on request. We may change them, provided the overall level of protection is not reduced.

6. Sub-operators

You authorise us to appoint sub-operators to process Applicant Data on our behalf. Our current sub-operators, and the purpose for which each is engaged, are listed on the Sub-Operator Page at getsigmund.co/subprocessors.

Each sub-operator is bound in writing to obligations no less protective than those in this Addendum. We remain liable to you for their performance.

We will update the Sub-Operator Page before appointing or replacing a sub-operator that processes Applicant Data, and will notify you where the change is material. Changes to that page do not require an amendment to this Addendum.

7. Where processing takes place

Applicant Data is processed and stored within the Republic of South Africa and the European Union.

Processing in the European Union is permitted under section 72(1)(a) of POPIA, because it is subject to the General Data Protection Regulation, which upholds principles for the lawful processing of personal information substantially similar to POPIA's, and because our agreements with the relevant providers incorporate the European Commission's Standard Contractual Clauses.

We may change the providers or facilities we use, provided processing continues to take place in a jurisdiction that meets section 72. We will notify you before processing Applicant Data in any jurisdiction outside those named above.

If you require processing to remain wholly within South Africa, or deployment within your own infrastructure, contact us at info@getsigmund.co. That arrangement will be recorded in writing for your account.

8. Model improvement and de-identification

Subject to clause 11 of the Terms of Service, we may use Applicant Data processed through your account to develop, train, evaluate and improve the models, systems and services we operate from time to time, on the following conditions.

De-identification precedes use. Before any Applicant Data enters a development, training or evaluation set, we remove or irreversibly obscure names, identity numbers, account numbers, addresses, contact details, employer identifiers and any other information that could reasonably identify an individual, whether on its own or in combination with other information reasonably available to us. The result is de-identified information as contemplated in section 6(1)(b) of POPIA.

No re-identification. We do not attempt to re-identify de-identified information, and section 6(3) of POPIA prohibits us from doing so.

No leakage of your logic. Your configuration, rules, thresholds and corrections are your intellectual property. Improvements derived from them are not exposed to any other customer except as general model accuracy.

No third-party training. Providers who process Applicant Data on our behalf are contractually prohibited from using it to train their own models.

Opt-out. You may exclude your data at any time by written notice to info@getsigmund.co. The exclusion applies from the date we receive it and is enforced at the ingestion pipeline.

9. Data subject requests

If an Applicant contacts us directly to exercise a right under POPIA, we will not respond substantively, because we are not the responsible party. We will direct them to you and notify you promptly.

We will give you the means, within the Platform where possible, to access, correct, export and delete Applicant Data so that you can meet POPIA's timelines.

10. Security compromises

If we become aware of a security compromise affecting Applicant Data, we will:

  1. notify you without undue delay after becoming aware;
  2. provide the nature of the compromise, the categories and approximate number of records affected, the likely consequences, and the steps taken, to the extent known at the time;
  3. assist you in notifying the Information Regulator and affected Applicants under section 22 of POPIA;
  4. provide a written post-incident report once the investigation is sufficiently advanced.

You remain responsible for making the statutory notifications, as responsible party, unless you instruct us in writing to make them on your behalf.

11. Deletion

Export tools are available in the Platform throughout the life of your account, and exporting before termination is your responsibility. There is no post-termination export period.

On termination, we delete Applicant Data in accordance with clause 15 of the Terms of Service, and from encrypted backups within our normal backup rotation. We are not obliged to return, extract or deliver Applicant Data to you in any form.

We may retain information for longer where the law requires it, in which case we continue to protect it under this Addendum and process it only for that purpose.

De-identified information used for model improvement is not deleted, because it is no longer personal information.

12. Information on request

On written request, and no more than once in any 12-month period, we will provide our then-current security documentation and any third-party audit report or certification we hold, subject to confidentiality.

Nothing in this Addendum entitles you to inspect our systems, premises or records. Where a regulator with jurisdiction over you requires more than the documentation described above, contact us and we will agree what is reasonable and proportionate in the circumstances.

13. Order of precedence

If this Addendum conflicts with the Terms of Service, this Addendum prevails in respect of the processing of personal information.


Contact: info@getsigmund.co · Information Officer: Tapfuma Masunzambwa, info@getsigmund.co

Sigmund

Spaces, 21 Dreyer Street,
Sunclare Building, Claremont, 7708
Cape Town, South Africa

Company

  • Sign in
  • How it works
  • Product tour
  • Founders
  • Pricing
  • Contact
  • LinkedIn

Legal

  • Privacy Policy
  • Terms of Service
  • Data Protection Policy
  • Data Processing Addendum
  • PAIA Manual
  • Sub-Operators
© SIGMUND CAPE TOWN, SOUTH AFRICA