Data Processing Agreement

Last updated: 20 July 2026

This Data Processing Agreement (the "DPA") forms part of, and supplements, the Howzit Terms of Service between you (the Shopify merchant, the "Controller") and Mika Dekker, trading as AskMario, the operator of Howzit (the "Processor"). It governs the Processor's processing of personal data on the Controller's behalf when the Controller uses Howzit. Where this DPA conflicts with the Terms of Service on the subject of personal data processing, this DPA prevails.

1. Parties and roles

Howzit is a South-Africa-focused SMS marketing application for Shopify, operated by Mika Dekker (trading as AskMario), website askmario.co.za, contact mika@askmario.co.za.

Each party is responsible for complying with the data protection laws that apply to it. Under this DPA, the applicable frameworks include POPIA (the Protection of Personal Information Act, South Africa), the GDPR (EU and EEA, where relevant), and CPA and WASPA rules governing SMS marketing.

2. Definitions

3. Details of processing

Nature of processing. The Processor sends SMS marketing (campaigns and automations, including abandoned-checkout recovery, welcome, post-purchase, and winback messages); operates a two-way conversational inbox for customer service; captures and manages marketing consent; and produces revenue attribution and reporting.

Purpose of processing. To enable the Controller to run SMS marketing to its own customers, respond to inbound replies, maintain accurate consent records, and measure results. The Processor does not use the Controller's personal data for its own independent purposes.

Duration. Processing continues for as long as the Controller uses Howzit, subject to the automated retention and purge schedule described in section 10 and to deletion on termination.

Categories of data subjects. The Controller's customers and other individuals who receive, reply to, or interact with SMS messages sent through Howzit.

Categories of personal data. The Processor processes:

The Processor does not process payment details or postal addresses. The Processor does not sell personal data and does not carry out automated decision-making that produces legal or similarly significant effects.

4. Processor obligations

The Processor undertakes to:

5. Subprocessors

The Controller authorises the Processor to engage the following subprocessors to deliver the service:

The Processor imposes on each subprocessor data protection obligations consistent with this DPA. If the Processor intends to add or replace a subprocessor, it will inform the Controller, and the Controller may object on reasonable data protection grounds. Where an objection cannot be resolved, the Controller may terminate its use of Howzit as its remedy.

6. Technical and organisational security measures

The Processor maintains the following measures:

7. International transfers and data residency

Personal data processed through Howzit is hosted in the EU (Frankfurt, via Neon on AWS eu-central-1 and Fly.io region "fra") and in South Africa (via the SMSPortal SMS gateway). This data residency is aligned to POPIA and the GDPR. By using Howzit, the Controller instructs and authorises these transfers as necessary to provide the service. Data at rest in the EU is encrypted, including backups, and all transfers occur over encrypted connections as described in section 6.

8. Personal data breach notification

On a suspected personal data breach, the Processor will rotate or revoke affected credentials (Fly secrets, the Neon role, and the Shopify API secret), assess the scope from available logs, and notify affected merchants and the South African Information Regulator within the applicable window. The Processor will provide the Controller with the information reasonably available to it to assist the Controller in meeting its own notification obligations to data subjects and regulators.

9. Audit and information rights

The Processor will make available to the Controller the information reasonably necessary to demonstrate compliance with this DPA, including the details of processing, subprocessors, and security measures set out above. On reasonable prior written request, and no more than once per year unless required by a supervisory authority or following a personal data breach, the Processor will respond to reasonable questions relating to its processing under this DPA. Audit rights are exercised in a manner that respects the confidentiality and security of the Processor's systems and those of its subprocessors.

10. Deletion and return on termination

The Processor operates an automated nightly purge that enforces the following retention rules:

On termination or uninstall, the Processor will delete the Controller's personal data in accordance with the schedule above, and will honour customer and shop redaction requests received through Shopify's privacy webhooks. Where the Controller requires a return of data before deletion, it may request an export while its account remains active. Legal consent records may be retained only as proof of consent and opt-out, and for no longer than necessary.

11. Governing law

This DPA is governed by the laws of South Africa and is to be read consistently with POPIA, and, where applicable, the GDPR and CPA and WASPA rules for SMS. This DPA supplements the Howzit Terms of Service; all other terms of that agreement remain in full force.

Questions? Contact mika@askmario.co.za.