Legal · Effective 17 May 2026
Data Processing Agreement (DPA)
This Agreement is between you (the Controller) and DDM Technology (Pty) Ltd (the Processor), trading as Flow Invoicer.
How to request a signed DPA
For business customers required to maintain a signed DPA for POPIA, GDPR, or vendor-due-diligence reasons, email dpa@ddmtech.co.za with:
- Your registered company name + VAT number
- The signatory's name, role, and contact email
- Any jurisdiction-specific clauses you require
We turn signed DPAs around within 5 business days.
What our DPA covers
- Categories of personal data processed (invoice, client, payment, bank)
- Purposes of processing (issuing + collecting invoices)
- Sub-processors (Supabase, Vercel, Resend, Paystack, Yoco, Anthropic, Sentry, PostHog)
- Security measures (encryption, RLS, 2FA, audit logging)
- Data subject rights handling (export, deletion within 30 days of request)
- Breach notification (72 hours)
- International transfers (none — data stays in af-south-1)
Sub-processors
We engage the following sub-processors. Each has its own equivalent DPA in place with us:
- Supabase — database, auth, storage (hosted on AWS af-south-1)
- Vercel — hosting + serverless functions
- Resend — transactional email delivery
- Paystack + Yoco — payment processing
- Anthropic — AI assistant (zero-data-retention via Vercel AI Gateway)
- Sentry — error monitoring
- PostHog — product analytics
Need something specific?
Email dpa@ddmtech.co.za or read more on our Trust page.