← Back to app

Data Processing Addendum

Last updated 15 June 2026

This Addendum forms part of the Terms of Service and applies whenever SkyL4rk (Pty) Ltd (“we”, the operator/processor) processes personal information on your behalf (you being the responsible party/controller) through SkySignal. Terms such as “personal information”, “processing”, “responsible party” and “operator” carry their POPIA meanings; their GDPR equivalents (“controller”, “processor”) apply where the GDPR governs.

1. Roles

You are the responsible party for the campaign data you load into the Service — your recipient audiences and the people identified or depicted in your content. We process that data only as your operator, on your documented instructions, which comprise these terms plus the actions you take in the Service (creating, scheduling and publishing campaigns).

2. Subject-matter, nature & purpose

Nature & purpose: hosting, scheduling, transmitting and reporting on email and social campaigns you configure. Duration: for as long as your workspace is active, subject to the retention terms below. Data subjects: your email recipients and any individuals appearing in your content. Categories: names and email addresses of recipients; and any personal information contained in the copy or images you supply.

3. Our obligations

4. Sub-operators

You authorise us to engage sub-operators to deliver the Service. We remain responsible for their processing. Current sub-operators:

Separately, when you connect and publish to a social platform (e.g. Facebook, LinkedIn), you instruct us to transmit your content and images to that platform. The platform then processes that content as an independent responsible party under its own terms; it is a recipient you direct, not our sub-operator. We will give reasonable notice of any new sub-operator so you may object.

5. Cross-border processing

Where a sub-operator or directed recipient is located outside the Republic of South Africa, the transfer is made under a condition permitted by section 72 of POPIA and, for GDPR data, an appropriate safeguard.

6. Security

We maintain reasonable technical and organisational measures, including: encryption of stored social access tokens and account passwords; per-workspace access scoping; re-encoding of uploaded images to a clean format that strips embedded metadata; and audit logging of publishing events.

7. Retention & deletion

We hold your data only as long as it is needed to provide the Service:

Referenced (externally hosted) images

If you reference an image by URL hosted on your own or your client’s domain, we do not store the image — we retain only the reference and fetch the image from your server at the moment of publishing. The reference persists until you remove it.

Uploaded images

If you upload an image, we store a normalised copy plus a thumbnail. An uploaded image is retained while any scheduled or recently published post still relies on it, and becomes eligible for deletion 30 days after the last post that used it has been delivered — never while a future-dated post still needs it. Uploads that were never attached to a saved post are removed sooner by routine clean-up. We deduplicate identical uploads within a workspace by content hash; if a copy has already expired, re-uploading simply stores it again.

Campaign data & audiences

Retained for the life of your workspace or until you delete them, and on termination as set out in clause 9.

8. Deletion & data-subject requests

You can delete content in the Service at any time. On request we will delete or return specified personal information we hold on your behalf, unless we are required by law to keep it.

Erasure of published content. Because publishing transmits content to third-party platforms that keep their own copy, a complete erasure has two legs: (a) deleting the stored asset and its references in the Service, and (b) deleting the live post(s) from the platform(s) on which it was published. We will action (a) and will, where the platform’s capabilities and your connected permissions allow, assist with (b); content already cached or copied by a platform or its users may persist beyond our control. We keep a minimal erasure record (a content hash, who requested it, and when) as proof of action — it does not retain the deleted image itself.

9. Return or deletion on termination

On termination, and after any wind-down period stated in the Terms, we will delete or, at your election, return the personal information we process on your behalf, except where retention is required by law.

10. Audit

On reasonable written notice and subject to confidentiality, we will provide information reasonably necessary to demonstrate compliance with this Addendum.

11. Liability & precedence

Liability under this Addendum is subject to the limitations in the Terms. If this Addendum conflicts with the Terms on the processing of personal information, this Addendum prevails.

12. Contact

Data-protection matters: privacy@skysignal.co.za · SkyL4rk (Pty) Ltd, Ballito, KwaZulu-Natal, South Africa.