Operator Agreement

LetSignal (Pty) Ltd Website: https://letsignal.co.za

Version: 1.0.0 Effective Date: 27 August 2026

Personal information processing terms between LetSignal and the Agency, concluded in terms of section 21 of the Protection of Personal Information Act.


1. Who this agreement is between and how it is accepted

1.1 This Operator Agreement ("Agreement") is between:

  • LetSignal (Pty) Ltd, registration number 2026/441528/07, of 33 Athens Avenue, Croydon Olive Estate, Somerset West, 7130 ("LetSignal", "we", "us"); and
  • the property practitioner, estate agency, landlord or other business that creates an account on the LetSignal platform ("the Agency", "you").

1.2 You accept this Agreement by ticking the acceptance box during agency verification (or under Settings, Verification), or by using the Platform to collect, request or process any personal information of another person. Acceptance is recorded electronically with your account identifier, the identity of the accepting user, the version of this Agreement, the date and time, the originating IP address, and the browser user agent. That record is proof of acceptance.

1.3 This Agreement is concluded in terms of section 21(3) of POPIA and forms part of, and is subject to, the LetSignal Terms of Service. Where this Agreement and the Terms of Service conflict on the processing of personal information, this Agreement prevails.

1.4 The person accepting this Agreement warrants that they are duly authorised to bind the Agency.

2. Definitions

2.1 "Applicant Data" means personal information relating to prospective tenants, tenants, their dependants, guarantors, references, landlords and property owners, which the Agency collects or causes to be collected through the Platform.

2.2 "POPIA" means the Protection of Personal Information Act, No. 4 of 2013.

2.3 "Platform" means the LetSignal application, website, APIs and related services.

2.4 "Security Compromise" means any unauthorised access to, or acquisition of, personal information processed under this Agreement.

2.5 "Sub-operator" means a third party engaged by LetSignal to process Applicant Data on its behalf.

2.6 "Account Data" means personal information relating to the Agency's own users - names, work contact details, role, authentication data, billing details and Platform usage records.

2.7 "responsible party", "operator", "data subject", "processing", "personal information", "special personal information", "de-identify" and "unique identifier" bear the meanings given to them in POPIA.

2.8 "Information Regulator" means the Information Regulator (South Africa) established under section 39 of POPIA.

3. Roles of the parties

3.1 The Agency is the responsible party in respect of Applicant Data. You determine the purpose of and means for processing it: you decide which properties are listed, which applicants are invited, what is asked of them, which screening checks are run, and what is done with the outcome.

3.2 LetSignal is the operator in respect of Applicant Data. We process it on your behalf, on your instruction, and for no independent purpose of our own except as set out in clause 12.

3.3 LetSignal is the responsible party in respect of Account Data. We process it to provide, secure, support, bill for and improve the Platform, and we do so under our own Privacy Policy rather than this Agreement.

3.4 Nothing in this Agreement makes LetSignal the responsible party for Applicant Data, and nothing obliges LetSignal to decide the purpose or means of processing it on your behalf.

3.5 The parties each remain responsible for appointing and registering their own Information Officer with the Information Regulator.

4. Scope of processing

4.1 LetSignal will process Applicant Data only:

(a) for the purposes, and in the manner, described in Annexure A; (b) on your documented instructions, which the configuration of your account and your use of the Platform constitute; and (c) as otherwise required by law, in which case we will tell you before processing unless the law forbids it.

4.2 If we consider an instruction from you to contravene POPIA or other applicable law, we will tell you and may suspend processing of that instruction until it is resolved.

4.3 We will treat all Applicant Data as confidential and will not disclose it except as permitted by this Agreement or required by law.

5. Your obligations and warranties as responsible party

5.1 You warrant that you have a lawful basis under POPIA for every instance of processing you instruct through the Platform, including the collection of identity documents, proof of income, bank statements and any screening or credit check.

5.2 You warrant that you have given each data subject the notification required by section 18 of POPIA, including the identity of the responsible party (you), the purpose of collection, the recipients of the information, and the data subject's rights.

5.3 You warrant that you have obtained the consents required for any screening, credit bureau or verification check you instruct, and that each such check is for a lawful purpose connected to a genuine letting.

5.4 You warrant that you will use the Platform only in connection with real properties that you are lawfully mandated to let or manage, and that you will not use it to collect personal information for any unrelated purpose.

5.5 You warrant that, where required by the Property Practitioners Act, you hold a valid Fidelity Fund Certificate for the current calendar year, and that you will tell us within five business days if it lapses, is withdrawn or is not renewed.

5.6 You are responsible for the accuracy of the data you enter, for the access you grant to your own users, for removing users promptly when they leave, and for the security of the credentials issued to your account.

5.7 You will not upload special personal information or the personal information of children to the Platform except where it is necessary for the letting application and you have a lawful basis to do so.

5.8 You will comply with your own obligations under POPIA, the Property Practitioners Act, the Rental Housing Act, the National Credit Act and the Financial Intelligence Centre Act. We do not discharge any of them on your behalf.

6. Our obligations as operator

6.1 We will process Applicant Data only with your knowledge and authorisation, as required by section 20 of POPIA.

6.2 We will establish and maintain the security measures required by section 19 of POPIA, as described in Annexure B.

6.3 We will ensure that our personnel who have access to Applicant Data are subject to written confidentiality obligations and are granted access only where necessary for their role.

6.4 We will not sell Applicant Data, and we will not use it for direct marketing to data subjects.

6.5 We will assist you, at your reasonable request, with your own POPIA obligations, including responding to data subject requests, notifying Security Compromises, and any personal information impact assessment or engagement with the Information Regulator that relates to the Platform.

7. Security

7.1 We will identify all reasonably foreseeable internal and external risks to Applicant Data in our possession or under our control, establish and maintain appropriate safeguards against those risks, regularly verify that the safeguards are effectively implemented, and update them in response to new risks or identified deficiencies.

7.2 Annexure B describes the technical and organisational measures in place as at the effective date of this Agreement. We may change them from time to time provided the overall level of protection is not reduced.

7.3 You are responsible for the security measures within your own control, including your users' devices, credentials and email accounts, and for enabling any access controls the Platform makes available to you.

8. Sub-operators

8.1 You authorise us to engage Sub-operators to process Applicant Data. The Sub-operators engaged as at the effective date are listed in Annexure C.

8.2 We will impose on each Sub-operator, by written contract, obligations no less protective than those in this Agreement, and we remain liable to you for their processing.

8.3 We will give you at least 30 days' notice before adding or replacing a Sub-operator, by email to your account's notice address or by notice within the Platform. If you reasonably object on data protection grounds within that period, we will work with you in good faith to find an alternative; if none is available, either party may terminate the affected services without penalty.

9. Cross-border transfers

9.1 Applicant Data is processed and stored outside the Republic of South Africa. Annexure C identifies where each Sub-operator processes and stores data.

9.2 Where Applicant Data is transferred outside South Africa, we will ensure the transfer complies with section 72 of POPIA, whether because the recipient is subject to a law, binding corporate rules or a binding agreement providing an adequate level of protection, or on another lawful basis available under that section.

10. Security Compromises

10.1 We will notify you of a Security Compromise affecting Applicant Data without undue delay upon becoming aware of it, and in any event within 72 hours.

10.2 Our notification will describe, so far as known at the time, the nature of the compromise, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. We will provide further information as our investigation progresses.

10.3 As responsible party, the decision to notify the Information Regulator and affected data subjects under section 22 of POPIA is yours. We will provide reasonable assistance and will not make that notification on your behalf unless you instruct us to in writing, or the law requires us to.

10.4 You must notify us immediately of any Security Compromise affecting your account credentials or otherwise affecting Applicant Data held on the Platform.

11. Data subject requests, retention and deletion

11.1 If we receive a request from a data subject to access, correct or delete Applicant Data, we will not respond to it ourselves except to direct the data subject to you. We will forward the request to you within five business days.

11.2 We will provide you with the functionality, or on request the assistance, needed to give effect to a data subject's rights under sections 23 to 25 of POPIA.

11.3 We will retain Applicant Data for the periods set out in Annexure D, or for such shorter or longer period as you instruct in writing where the law permits or requires it.

11.4 On termination of your account, we will, at your election, return Applicant Data to you in a structured, commonly used format, or delete it. Absent an election, we will retain it for 30 days to allow for retrieval and then delete it, except where we are required by law to retain it, where an evidence record is protected against deletion as described in Annexure B, or where it has been de-identified in a way that cannot be reversed.

11.5 Deletion under this clause extends to backups on the ordinary backup expiry cycle described in Annexure D, rather than by immediate extraction from backup media.

12. Aggregated and de-identified information

12.1 We may de-identify Applicant Data and use the resulting information to operate, secure, benchmark and improve the Platform, and to produce aggregated statistics and market insights.

12.2 We will de-identify such information in a manner that cannot be reversed, as contemplated by POPIA, and we will not attempt to re-identify it or permit any Sub-operator to do so.

12.3 We will not publish or disclose aggregated statistics in a form that identifies you, any data subject, or any individual property.

12.4 Nothing in this clause permits us to reuse Applicant Data relating to an identified or identifiable person for a purpose other than providing the Platform to you. Any such reuse would require a separate lawful basis obtained from the data subject directly.

13. Assurance

13.1 On written request, no more than once in any 12-month period, we will provide you with reasonable information about our compliance with this Agreement, including a completed security questionnaire and copies of any current third-party audit reports or certifications we hold.

13.2 Where clause 13.1 does not give you information reasonably required to demonstrate compliance, and a regulator or your own compliance obligations require more, the parties will agree a proportionate alternative in good faith. Any inspection will be at your cost, on at least 20 business days' written notice, during business hours, subject to confidentiality, and conducted so as not to disrupt the Platform or compromise the confidentiality of other customers' data.

14. Liability

14.1 Each party's liability under this Agreement is subject to the limitations and exclusions in the Terms of Service, except that neither party limits liability for its own wilful misconduct or gross negligence, or for anything that cannot be limited by law.

14.2 You indemnify us against any claim, fine or loss arising from your breach of clause 5, including any processing you instructed without a lawful basis.

14.3 We indemnify you against any claim, fine or loss arising from our processing of Applicant Data in breach of clause 4.1 or clause 6, to the extent of our own fault.

14.4 Neither party is liable for the other's failure to appoint or register an Information Officer, or for the other's own compliance obligations under POPIA.

15. Term and termination

15.1 This Agreement takes effect on acceptance and continues for as long as we process Applicant Data on your behalf.

15.2 Clauses 4.3, 11, 12, 14 and 16 survive termination.

16. General

16.1 Amendment. We may amend this Agreement on 30 days' notice where the change is required by law, by a regulator, or by a change to the Platform. If an amendment materially reduces your protections, you may terminate your subscription without penalty before it takes effect. Continued use of the Platform after the effective date constitutes acceptance.

16.2 Notices. Notices to you are sent to the email address on your account. Notices to us are sent to stuart@letsignal.co.za, marked for the attention of the Information Officer.

16.3 Information Officer. LetSignal's Information Officer can be contacted at stuart@letsignal.co.za.

16.4 Governing law. This Agreement is governed by the laws of the Republic of South Africa. The parties consent to the jurisdiction of the Magistrate's Court in terms of section 45 of the Magistrates' Courts Act, No. 32 of 1944.

16.5 Severability. Any provision found unenforceable is treated as removed and the remainder stays in force.

16.6 Whole agreement. This Agreement, together with the Terms of Service and its annexures, is the whole agreement between the parties on the processing of personal information through the Platform.


Annexure A - Description of processing

Subject matter Provision of the LetSignal tenant application, FICA verification and rental documentation platform
Duration For the term of the Agency's account, plus the retention periods in Annexure D
Nature of processing Collection, recording, storage, organisation, retrieval, transmission to the payment provider for application-fee payment, generation of reports and letting documentation, and erasure. No Applicant Data is submitted to any artificial-intelligence or machine-learning service, and the Platform performs no credit bureau, TPN, or Department of Home Affairs check of its own - screening remains a hand-off performed by the Agency.
Purpose Enabling the Agency to receive, verify, assess and record rental applications, to run FICA on the parties to a letting, and to generate and manage letting documentation
Categories of data subject Prospective tenants and tenants; their dependants, spouses and co-applicants; guarantors and sureties; employer and personal references; landlords and property owners; the Agency's own users
Categories of personal information Name, identity or passport number, date of birth, contact details, physical address, marital status, employment details, income and affordability information, bank account details and bank statement contents, rental history, identity documents and supporting uploads, communications with the Agency, and application status records
Special personal information Not required by the Platform. Where present in uploaded documents (for example, information appearing incidentally in a bank statement), it is stored as part of the document only and is not extracted, indexed or used as a screening criterion.
Children's information Names and ages of dependants where the Agency's application form requests household composition

Annexure B - Technical and organisational security measures

Access control

  • Role-based access control within the Platform; each agency's users can access only their own agency's data, enforced in the application layer with database row-level security policies as defence in depth
  • Agency user authentication by email and password through the Platform's managed authentication provider
  • Emailed one-time-code identity verification for document signers, with codes stored only as hashes
  • Least-privilege access for LetSignal personnel, with production data access limited to what operating the Platform requires

Encryption

  • All data encrypted in transit using TLS, with HTTP Strict Transport Security enforced for two years including subdomains
  • Data and document uploads encrypted at rest on the hosting Sub-operator's infrastructure
  • Application-level integrity measures: SHA-256 hashes recorded for uploaded documents and signed PDFs, HMAC-signed identity cookies, and HMAC-verified inbound webhooks

Storage

  • All documents held in private storage buckets with file-type and size restrictions; no public access
  • Document access only through authenticated routes or short-lived signed URLs, with access recorded in the audit trail

Logging and monitoring

  • Append-only audit logs of authentication, document access, export and review events, protected by database-level privilege revocation so they cannot be altered or deleted through the Platform, and retained indefinitely
  • A per-record SHA-256 hash chain over signing events, so any insertion, deletion or reordering of the record is detectable
  • Application error monitoring with automatic filtering that removes South African identity numbers, embedded image data, cookies and authorisation headers from error reports before transmission
  • Request rate limiting on sensitive endpoints

Infrastructure

  • Hosting and data storage in the European Union (Frankfurt, Germany) - see Annexure C
  • Separation between production and non-production environments; no production personal information is used in development or testing
  • Automated platform backups managed by the hosting Sub-operator, expiring on its ordinary backup cycle

People

  • Confidentiality obligations for personnel and contractors with access to personal information

Incident management

  • Monitoring and alerting on application errors in production, with Security Compromises handled and notified as described in clause 10

Annexure C - Sub-operators

Sub-operator Purpose Processing location Section 72 basis
Supabase Database, document storage and authentication Frankfurt, Germany (EU) Data processing agreement; provider subject to the GDPR
Vercel Application hosting, web analytics and performance monitoring Frankfurt, Germany (EU) primary; United States (support services) Data processing agreement incorporating GDPR standard contractual clauses
Paystack Card payment processing (also an independent responsible party for payment data under its own privacy policy) Ireland (EU) Binding corporate rules; provider subject to the GDPR
Resend Transactional email, including signed-document, mandate and invoice PDF attachments United States Data processing agreement
Sentry Application error monitoring (reports filtered as described in Annexure B) United States Data processing agreement
Upstash Request rate-limiting cache (holds client IP addresses only) United States Data processing agreement
Google Address autocomplete on address fields (typed input passes from the browser directly to Google Places) and website analytics United States and global infrastructure Data processing terms incorporating GDPR standard contractual clauses

Annexure D - Retention

Category Retention period Trigger
Application drafts never submitted Deleted automatically, including uploaded documents, once the applicant's resume link has expired and the draft has been inactive for 7 days Resume-link expiry plus inactivity
Lease drafts Deleted automatically after 30 days of inactivity, and immediately when the lease is sent Last edit date
Submitted applications and their documents Retained while the Agency requires them; deleted or de-identified on the Agency's written instruction, and on data subject requests routed through the Agency The Agency's written instruction
Signed leases and mandates 5 years from the lease or mandate end date, recorded per record at signature time; destruction is actioned on instruction rather than automatically End date
Audit and signing-event logs Retained indefinitely; append-only and not deletable through the Platform Date of event
Backups Expire on the hosting Sub-operator's ordinary backup cycle Backup creation date

End of Operator Agreement