H&M Information Management Services (Pty) Ltd DATA PROCESSING ADDENDUM

Last Updated: 23 March 2026

This Data Processing Addendum ("DPA") forms part of the Docwize Terms of Service ("Agreement") between:

  • H&M Information Management Services (Pty) Ltd, trading as Docwize ("Docwize"); and
  • The Customer identified in the Agreement ("Customer").

1. DEFINITIONS

Terms defined in the Agreement apply here. Additional definitions:

1.1 "Applicable Data Protection Laws" means all laws and regulations relating to the processing of Personal Data that apply to the processing activities under this DPA, including the Protection of Personal Information Act 4 of 2013 ("POPIA"), the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK General Data Protection Regulation ("UK GDPR"), and any binding subordinate legislation or guidance issued under them.

1.2 "Personal Data" / "Personal Information" means information relating to an identified or identifiable natural person, as defined under Applicable Data Protection Laws.

1.3 "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure or destruction.

1.4 "Sub-Processor" means a third party engaged by Docwize to process Personal Data in connection with the Service.

1.5 "Security Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data transmitted, stored or otherwise processed by Docwize.

1.6 "Customer Personal Data" means Personal Data contained within Customer Data that Docwize processes on behalf of Customer as Processor / Operator under this DPA.


2. ROLES OF THE PARTIES

2.1 Customer as Controller / Responsible Party. With respect to Customer Personal Data, Customer is the Controller (under GDPR / UK GDPR) or Responsible Party (under POPIA), and Docwize is the Processor (under GDPR / UK GDPR) or Operator (under POPIA). Docwize processes Customer Personal Data only on documented instructions from Customer, except where required by applicable law, in which case Docwize will (to the extent permitted by law) inform Customer of such legal requirement before processing.

2.2 Docwize as independent Controller / Responsible Party. Docwize acts as an independent Controller / Responsible Party with respect to Personal Data that Docwize processes for its own legitimate operational purposes, including: (a) account registration and administration; (b) billing and payment processing; (c) security monitoring, fraud prevention and abuse detection; (d) legal and regulatory compliance; (e) usage analytics for capacity planning and infrastructure management; and (f) communications with Customer's account administrators regarding the Service. Such processing is governed by the Docwize Privacy Policy and is outside the scope of this DPA.


3. NATURE AND PURPOSE OF PROCESSING

Schedule 1 — Processing Details

3.1 Subject matter and purpose of processing:

Docwize processes Customer Personal Data to provide, operate and support the Service, including: eDiscovery, document management, automation, analytics, document review, classification, search, electronic signature workflows, AI-enabled features (where activated by Customer) and related functions as described in the Agreement and Documentation.

3.2 Duration of processing:

From the Effective Date of the Agreement until deletion of all Customer Personal Data in accordance with this DPA, including any post-termination retention and backup retention periods described in Section 11.

3.3 Categories of Personal Data:

The categories of Personal Data processed depend on Customer's use of the Service and may include:

  • Names and contact information (email addresses, phone numbers, physical addresses)
  • Professional and employment information (job titles, employer details)
  • Identification data (identity numbers, employee numbers, account identifiers)
  • Communications content (emails, correspondence, attachments)
  • Document content and metadata
  • Financial and transactional information (where contained in Customer Data)
  • Any other categories of Personal Data that Customer or its Authorised Users submit to the Service

3.4 Categories of Data Subjects:

  • Customer's employees and personnel
  • Customer's clients and their employees or representatives
  • Counterparties and their representatives
  • Suppliers and vendors
  • Any other individuals whose Personal Data is contained in Customer Data

3.5 Processing operations:

Ingestion, parsing, text extraction, OCR, indexing, search, storage, replication, backup, classification, deduplication, analytics, review, annotation, production, export, rendering, thumbnail generation, AI-assisted analysis and transformation (where activated by Customer), electronic signature processing, audit logging and related technical operations.


4. CUSTOMER INSTRUCTIONS

4.1 Docwize processes Customer Personal Data only in accordance with Customer's documented instructions. Customer's instructions include this DPA, the Agreement, applicable Order Forms, and Customer's configuration and use of the Service.

4.2 If Docwize reasonably believes that an instruction from Customer infringes Applicable Data Protection Laws, Docwize will promptly notify Customer and may suspend the relevant processing until the matter is resolved.


5. SECURITY MEASURES

5.1 Docwize will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, damage, theft or disclosure, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing.

5.2 Without limiting the foregoing, Docwize's security measures include the following:

(a) Encryption. Customer Personal Data is encrypted in transit using current industry-standard transport-layer encryption (currently TLS 1.2 or higher) and at rest. Encryption key management follows established key management principles, including the use of dedicated secrets management infrastructure.

(b) Access controls. Role-based access controls are enforced. All Docwize employee and internal accounts with access to production systems require multi-factor authentication. Access is granted on a least-privilege basis and reviewed periodically.

(c) Tenant isolation. Each customer tenant is logically segregated with isolated databases and isolated object storage (e.g. S3 buckets).

(d) Infrastructure security. Hosting environments are secured with network segmentation, firewalls, intrusion detection and monitoring systems, and regular vulnerability management.

(e) Backup and recovery. Backups are maintained and tested periodically to support data recovery. Backup data remains subject to the confidentiality and security obligations of this DPA.

(f) Personnel. All Docwize personnel with access to Customer Personal Data are subject to written confidentiality obligations and receive appropriate data protection and security awareness training.

(g) Secure development. Docwize follows secure software development practices, including code review and testing.

5.3 Docwize will not materially reduce the overall level of security during the Subscription Term.


6. SUB-PROCESSORS

6.1 General authorisation. Customer grants Docwize general authorisation to engage Sub-Processors to process Customer Personal Data in connection with the provision of the Service. The current list of Sub-Processors is available at the Docwize Sub-Processors page and may be updated from time to time.

6.2 Contractual safeguards. Docwize ensures that each Sub-Processor is bound by a written agreement imposing data protection obligations equivalent in substance to those set out in this DPA.

6.3 Notification and objection. Docwize will notify Customer at least fifteen (15) days before authorising a new non-optional Sub-Processor to process Customer Personal Data. Customer may object on reasonable data protection grounds by written notice to Docwize within that fifteen (15) day period. If Customer objects, the parties will discuss the objection in good faith. If the parties are unable to resolve the objection within thirty (30) days of Customer's notice, Customer may terminate the affected Service or Order Form and receive a pro-rata refund of any prepaid fees for the unused portion of the Subscription Term.

6.4 Liability. Docwize remains responsible for the acts and omissions of its Sub-Processors to the same extent as if it were performing the processing itself.

6.5 Optional Sub-Processors. Certain Sub-Processors are engaged only when Customer activates or uses specific features of the Service (for example, AI-enabled features or specific signing channels). The Sub-Processors page identifies which Sub-Processors are feature-dependent.


7. INTERNATIONAL TRANSFERS

7.1 Customer Personal Data may be transferred to and processed in countries outside the jurisdiction where Customer is located. Where such transfers occur, Docwize will ensure that an appropriate lawful transfer mechanism is in place, which may include:

(a) an adequacy decision by the relevant authority (e.g. European Commission, UK Secretary of State, or equivalent); (b) Standard Contractual Clauses approved by the European Commission (including the UK International Data Transfer Addendum where applicable); (c) other transfer mechanisms permitted under Applicable Data Protection Laws, including POPIA-compliant safeguards.

7.2 Docwize will not knowingly transfer Customer Personal Data to any country or territory in contravention of Applicable Data Protection Laws.

7.3 On request, Docwize will provide Customer with reasonable information regarding the transfer mechanisms relied upon for specific transfers.


8. SECURITY INCIDENTS

8.1 Notification. Docwize will notify Customer without undue delay and in no event later than forty-eight (48) hours after becoming aware of a confirmed Security Incident affecting Customer Personal Data. Docwize will direct such notification to Customer's designated security or account contact.

8.2 Content of notification. Docwize's notification will include, to the extent reasonably available at the time, the following information (which may be provided in phases as information becomes available): (a) the nature of the Security Incident, including where possible the categories and approximate number of data subjects and Personal Data records concerned; (b) the likely consequences of the Security Incident; (c) the measures taken or proposed to address the Security Incident, including measures to mitigate its possible adverse effects; and (d) a contact point for further information.

8.3 Mitigation and cooperation. Docwize will take reasonable steps to contain and mitigate the effects of any Security Incident and will cooperate with Customer's reasonable requests in connection with Customer's investigation, notification and remediation obligations.

8.4 Regulatory notifications. Customer is responsible for determining whether any regulatory or data subject notification is required under Applicable Data Protection Laws and for making such notifications.

8.5 Evidence preservation. Docwize will preserve relevant records and evidence relating to a Security Incident to the extent reasonably necessary for investigation, remediation and compliance with Applicable Data Protection Laws.

8.6 Limitations. Nothing in this DPA requires Docwize to disclose information that would compromise the security of its systems, the confidentiality of other customers' data, or any ongoing investigation (whether internal or by a law enforcement authority).


9. CONFIDENTIALITY

All personnel processing Customer Personal Data on behalf of Docwize are subject to written confidentiality obligations. Docwize ensures that access to Customer Personal Data is limited to personnel who require such access for the performance of their duties.


10. DATA SUBJECT RIGHTS

10.1 Docwize will provide Customer with reasonable assistance, taking into account the nature of the processing, to enable Customer to respond to requests from data subjects exercising their rights under Applicable Data Protection Laws, including rights of access, rectification, erasure, restriction, data portability and objection.

10.2 If Docwize receives a request directly from a data subject relating to Customer Personal Data, Docwize will promptly redirect the data subject to Customer and notify Customer, unless Docwize is legally required to respond directly.

10.3 Docwize may charge Customer a reasonable fee for assistance with data subject requests that are manifestly unfounded, excessive or that require significant manual effort beyond standard Service functionality.


11. RETURN AND DELETION OF DATA

11.1 Export period. Upon termination or expiry of the Agreement, Docwize will make Customer Data available for export during the Export Period described in the Agreement (default: thirty (30) days).

11.2 Deletion from active systems. After the Export Period, Docwize will delete Customer files from active production systems within approximately thirty (30) days.

11.3 Logs and audit data. Logs and audit data relating to Customer Personal Data may be retained for up to twelve (12) months after termination where reasonably necessary for security monitoring, incident investigation and compliance with Applicable Data Protection Laws. Such data remains subject to the confidentiality and security obligations of this DPA.

11.4 Metadata and operational records. File metadata and related operational records (such as index records, system identifiers and billing records) may be retained for up to twelve (12) months after termination where reasonably necessary for system integrity, auditability, billing reconciliation, fraud or security investigation, legal compliance or backup administration. Such records remain subject to the confidentiality and security obligations of this DPA.

11.5 Backup retention. Automated backup systems retain historical copies of Customer Personal Data in accordance with the applicable backup retention schedule (which may include daily, monthly and annual backup cycles). Backup copies are overwritten or deleted in the ordinary course of the retention cycle. Docwize will not actively restore Customer Personal Data from backups after deletion from active systems except as necessary to comply with a legal obligation or as agreed with Customer.

11.6 Certification. Upon Customer's written request, Docwize will confirm in writing that deletion has been completed in accordance with this Section, subject to the exceptions stated above.


12. AUDITS

12.1 Information. Docwize will make available to Customer information reasonably necessary to demonstrate compliance with this DPA.

12.2 Audit right. Customer (or a qualified independent third-party auditor appointed by Customer and acceptable to Docwize) may conduct an audit of Docwize's processing activities under this DPA, subject to the following conditions:

(a) Customer must provide at least thirty (30) days' prior written notice of any audit; (b) audits are limited to once per twelve (12) month period, unless a Security Incident has occurred or a supervisory authority requires or requests an additional audit; (c) Docwize may satisfy Customer's audit request by providing relevant independent third-party audit reports, certifications or compliance documentation where reasonably available and appropriate; (d) where an on-site or remote audit is conducted, it must be carried out during normal business hours, with minimal disruption to Docwize's operations, and in a manner that protects the confidentiality of other customers' data and Docwize's proprietary information; (e) Customer bears its own costs in connection with any audit, unless otherwise agreed in writing; and (f) the auditor must enter into a confidentiality agreement with Docwize before receiving any confidential or proprietary information.


13. CUSTOMER RESPONSIBILITIES

Customer is responsible for:

(a) lawful collection and submission of Personal Data to the Service; (b) obtaining and maintaining all necessary consents, authorisations or legal bases for the processing of Customer Personal Data; (c) ensuring the accuracy and relevance of Personal Data submitted; (d) configuring the Service and access controls in accordance with Customer's security and data protection requirements; (e) providing documented lawful instructions to Docwize; (f) ensuring that its use of AI Features complies with all applicable laws and regulations; (g) not enabling or permitting any use of AI Features that is prohibited under applicable law; and (h) meeting any additional obligations that apply where Customer deploys AI Features in high-risk or regulated contexts.


14. AUTOMATION AND AI FEATURES

14.1 Where Customer activates or uses AI Features, Docwize may process Customer Personal Data using automated means, including third-party AI sub-processors, to provide the requested functionality.

14.2 AI outputs are probabilistic and must be validated by Customer before use or reliance.

14.3 AI outputs do not constitute professional, legal or business advice.

14.4 No training of third-party or general-purpose models. Neither Customer Data nor aggregated or de-identified data derived from it may be used by Docwize or its Sub-Processors to train third-party models or general-purpose AI or machine-learning models. AI Sub-Processors may process Customer Data only to the extent necessary to provide the AI-enabled functionality activated by Customer's use of the applicable feature. Docwize may use aggregated or de-identified data (from which Customer and individuals cannot reasonably be identified) for analytics, reliability, security, abuse prevention and general service improvement, but not for training third-party or general-purpose AI or machine-learning models.

14.5 Where AI-generated or AI-modified content may materially affect individuals and applicable law requires transparency, Customer must ensure that the involvement of AI is appropriately disclosed.

14.6 Where Customer uses AI Features in contexts that are classified as high-risk or subject to specific AI regulatory regimes, Customer is solely responsible for compliance with those regimes.


15. LIABILITY

Liability under this DPA is governed by the limitation provisions in the Agreement.


16. TERM

This DPA remains in force for as long as Docwize processes Customer Personal Data on behalf of Customer, including any post-termination retention period described in Section 11.


17. CONFLICT

In case of conflict between this DPA and the Agreement, this DPA prevails with respect to the processing and protection of Customer Personal Data.


18. ACCEPTANCE

This DPA becomes binding upon Customer's acceptance of the Agreement.