POPIA Compliance Statement

1. Our Role Under POPIA

LegalDominio operates in two capacities depending on context:

Our full obligations as a data processor are set out in our Data Processing Agreement, which is entered into with every subscriber.

2. Lawfulness of Processing

We process personal information under the following lawful bases:

3. Purpose Specification

Personal information is collected only for specific, explicitly defined purposes. Data collected through the website and bot is used to:

Data collected through the platform (subscriber use) is used solely to provide the case management, lead capture, document management, and AI features that subscribers have contracted for.

We do not use data for purposes beyond those specified at collection without obtaining fresh consent.

4. Data Minimisation

We collect only what is necessary for the stated purpose:

5. Security Safeguards (POPIA Section 19)

Technical Safeguards

Organisational Safeguards

6. Data Breach Notification

In the event of a personal information breach:

  1. Internal assessment within 24 hours of detection
  2. Notification to the Information Regulator within 72 hours (where required)
  3. Immediate notification to affected individuals if there is a high risk to their rights
  4. Immediate containment and corrective action

7. Data Retention

Data CategoryRetention PeriodBasis
Lead contact information3 years from last interactionLegitimate interest
Subscriber account dataDuration of contract + 5 yearsTax and legal requirements
Conversation logs2 years from conversation dateService improvement, compliance
Audit logs7 yearsLegal and regulatory requirements

Data is securely deleted after its retention period using cryptographic erasure. Backup copies are purged within 90 days of deletion.

8. Cross-Border Data Transfers (POPIA Section 72)

Primary data storage uses Microsoft Azure cloud infrastructure. Some processing involves transfers outside South Africa:

ProviderPurposeLocationSafeguards
Microsoft AzureCloud hosting & databaseSouth AfricaDPA, ISO 27001, SOC 2
OpenAIAI language model processingUnited StatesDPA, Standard Contractual Clauses
TwilioWhatsApp & SMS notificationsUnited StatesDPA, GDPR-compliant

All international transfers are conducted under appropriate safeguards including Data Processing Agreements and Standard Contractual Clauses.

9. Automated Decision-Making

The platform uses AI-assisted processing in the following areas:

No solely automated decisions with legal or significant effects are made. Human review is available for all AI-assisted outputs.

10. Data Subject Rights

Individuals whose personal information we process have the following rights under POPIA:

To exercise any right: privacy@legaldominio.com

11. Information Officer

Email: privacy@legaldominio.com
Organisation: LegalDominio

12. Complaints

If you are dissatisfied with how we handle your personal information, you may contact the Information Regulator:

Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Email: inforeg@justice.gov.za
Phone: +27 (0)10 023 5200
inforegulator.org.za