Subprocessors

Last updated: 2026-07

DRAFT (revamp 2026-07) — for SA attorney review; not legal advice; not for publication.

All statutory references in this draft are indicative and must be verified by counsel against the current text of each Act before any reliance or publication.

1. Overview and legal basis

eRunna (Pty) Ltd (registration number [TBD: company registration number]) ("we", "us", "our") acts as a responsible party under the Protection of Personal Information Act 4 of 2013 ("POPIA") in respect of personal information it collects from customers, runners, merchants, and partners. Where we engage third parties to process personal information on our behalf, those parties are operators within the meaning of POPIA section 1.

POPIA sections 20 and 21 require that:

Where personal information is transferred outside the Republic of South Africa, POPIA section 72 applies. We transfer personal information to a foreign country or international organisation only where:

The Information Regulator of South Africa oversees compliance. Questions or complaints: info@erunna.app.

[ATTORNEY-REQUIRED: Confirm the precise POPIA compliance pathway for each cross-border transfer (s72(1)(a)–(e)) and whether any transfers to US-based Google Cloud, Firebase, or Paystack infrastructure require a formal data-transfer agreement (DTA) or whether reliance on a contractual mechanism is sufficient.]

2. Subprocessor list

The table below lists all third-party operators currently authorised to process personal information on eRunna's behalf. Where a provider is headquartered outside South Africa, the country of processing and the applicable cross-border transfer safeguard are noted. This list is updated when subprocessors are added or removed; material changes will be reflected in the Privacy Policy.

Infrastructure and platform

Subprocessor Services provided Categories of personal information processed Processing location(s) Cross-border safeguard (s72)
Google Cloud Platform (GCP) — Google LLC Cloud Run (containerised API and service hosting), Cloud Logging, Cloud Storage, Vertex AI (where applicable), Secret Manager, Identity and Access Management All personal information transiting or stored on eRunna's backend infrastructure, including account data, order/errand data, location data, and log data Primary: africa-south1 (Johannesburg, South Africa) — post-ADR 0061 migration. Ancillary GCP services may process data in other Google regions. Primary processing in South Africa (no cross-border transfer for africa-south1 workloads). Ancillary services: Google Cloud Data Processing Amendment (contractual safeguard). [ATTORNEY-REQUIRED: Confirm whether Google's standard Data Processing Amendment is accepted as sufficient under s72 for any ancillary workloads processed outside South Africa.]
Firebase — Google LLC Authentication (Firebase Auth), Firestore (real-time database), Cloud Messaging (FCM — push notifications), Crashlytics (crash reporting and diagnostics) Firebase UIDs, authentication tokens, device tokens, order/errand records, crash and diagnostic data Firebase services are globally distributed. Firestore primary region is configured to africa-south1 per ADR 0061; other Firebase services (Auth, FCM, Crashlytics) may process in Google's global infrastructure. Google Cloud Data Processing Amendment (contractual safeguard). [ATTORNEY-REQUIRED: Confirm firebase.google.com DPA coverage extends to all Firebase products in scope, and verify whether Crashlytics data (which may include device identifiers and stack traces) is adequately covered.]
Google Cloud Pub/Sub — Google LLC Asynchronous event messaging between eRunna's microservices (order events, runner-availability events, settlement events, etc.) Event payloads containing order, location, and status data; may include personal identifiers (UIDs, order references) africa-south1 (primary). Cross-region replication not currently enabled. Processing within South Africa (primary). Google Cloud Data Processing Amendment (contractual safeguard) for any ancillary processing.
Google Cloud Memorystore (Redis) — Google LLC In-memory caching (session state, real-time runner-availability state, matching engine transient state) Transient session and state data; may include UIDs and real-time location references africa-south1 (Johannesburg). Data is ephemeral; not persisted to disk in standard configuration. Processing within South Africa. Google Cloud Data Processing Amendment (contractual safeguard).

Payments

Subprocessor Services provided Categories of personal information processed Processing location(s) Cross-border safeguard (s72)
Paystack ([TBD: confirm Paystack's exact registered legal entity name]) Payment authorisation, card tokenisation (saved cards), charge processing, refunds, payouts to runners and merchants. eRunna uses Paystack Inline (in-app WebView) for card capture; full card numbers are NOT transmitted to or stored on eRunna's servers. Payment tokens, authorisation codes, transaction references, payout recipient bank/mobile-money details (runners, merchants). eRunna receives tokens only — not raw card numbers (PCI DSS SAQ-A-EP scope; see ADR 0044 Amendment 2). Paystack processes transactions via its own infrastructure and operates internationally [TBD: confirm Paystack's place of incorporation and corporate group; it is understood to be Nigeria-based]. Servers may be located in [TBD: confirm Paystack's stated data-residency commitments]. [ATTORNEY-REQUIRED: Confirm whether Paystack's standard merchant agreement includes a POPIA-compliant data-processing clause, and whether a separate DTA is required under s72 for personal information transferred to Paystack's non-South-African infrastructure. Also confirm whether payout recipient data (ID numbers / bank details used for runner/merchant verification) triggers heightened obligations as "special personal information" under POPIA s26.]

Communications

Subprocessor Services provided Categories of personal information processed Processing location(s) Cross-border safeguard (s72)
[TBD: Email service provider — e.g., SendGrid / Mailgun / Amazon SES / other] Transactional email delivery (account verification, order confirmations, receipts, support responses, platform notifications) Email addresses, name, order references, message content [TBD: Confirm provider and data-processing location] [TBD: Confirm cross-border transfer safeguard applicable once provider is selected. Likely contractual safeguard (DPA/DTA). Attorney to verify.] [ATTORNEY-REQUIRED: Once provider is selected, confirm POPIA s21 operator contract is in place and s72 pathway is documented.]
[TBD: SMS / OTP provider — e.g., Clickatell / Vonage / Twilio / other] One-time password (OTP) delivery, transactional SMS notifications (order status, runner alerts) Mobile phone numbers, OTP codes (ephemeral), order status data [TBD: Confirm provider and data-processing location] [TBD: Confirm cross-border transfer safeguard once provider is selected.] [ATTORNEY-REQUIRED: Confirm POPIA s21 operator contract and s72 pathway once provider is confirmed.]

Identity verification and KYC

Subprocessor Services provided Categories of personal information processed Processing location(s) Cross-border safeguard (s72)
[TBD: KYC / identity-verification vendor — e.g., Smile Identity / Onfido / Jumio / other] Runner onboarding identity verification: document check (South African ID / passport), selfie / liveness check (biometric), address verification where applicable Government-issued identity documents, facial biometric data (liveness / selfie), date of birth. These constitute special personal information under POPIA s26 (biometric information, possibly race/ethnicity from identity documents). [TBD: Confirm provider and data-processing location] [ATTORNEY-REQUIRED: Processing of biometric data and identity documents is "special personal information" under POPIA s26 and requires explicit consent AND one of the conditions in s27. Attorney must: (a) confirm the applicable s27 condition; (b) confirm whether the KYC vendor's DPA is POPIA-compliant; (c) confirm s72 cross-border safeguard where vendor processes outside South Africa; (d) confirm whether any FICA / FIC Act obligations attach to the runner-verification process given eRunna's emerging accountable-institution status (see also Section 3 below).]

Observability and monitoring

Subprocessor Services provided Categories of personal information processed Processing location(s) Cross-border safeguard (s72)
Grafana Labs (Grafana Cloud) and/or self-hosted Prometheus/Grafana on GCP Metrics collection, alerting, dashboard visualisation, platform health monitoring Aggregated and technical metrics; logs may incidentally contain request identifiers or UIDs. Personally identifiable information in logs should be minimised (see Data Retention Policy). Self-hosted: africa-south1 GCP (no cross-border transfer). If Grafana Cloud is used: [TBD: confirm Grafana Cloud data-region configuration]. Self-hosted: no cross-border transfer. Grafana Cloud: Grafana Labs DPA (contractual safeguard). [TBD: confirm Grafana Cloud region and DPA status if in use.]

3. FICA / AML-CFT obligations — attorney notice

[ATTORNEY-REQUIRED: eRunna operates a payment platform involving the movement of money between customers, runners, merchants, and partners. Attorney must advise on the following:

4. Marketplace integrity — prohibited and counterfeit goods

[ATTORNEY-REQUIRED: eRunna's platform must not facilitate the sale, promotion, or delivery of counterfeit, illicit, or prohibited goods (see ADR 0075). Attorney must advise on:

5. Data-collection surfaces — POPIA collection notices and marketing consent

eRunna operates two live data-collection surfaces outside the main application:

[ATTORNEY-REQUIRED: Confirm (a) whether the current waitlist-form collection notice and consent wording satisfies POPIA s18 and the applicable direct-marketing consent regime; (b) whether any in-person giveaway or promotional competition at mall activations triggers compliance obligations under the Consumer Protection Act 68 of 2008 (CPA) promotional-competition rules [ATTORNEY-REQUIRED: confirm citation — the specific CPA section (indicatively s36) and the applicable promotional-competition Regulations]; and (c) confirm the correct designated Information Officer details for inclusion in collection notices — see [TBD] below.]

6. Information Officer and contact

eRunna's designated Information Officer responsible for POPIA compliance is:

The Information Officer has been or will be registered with the Information Regulator of South Africa as required under POPIA s55. [ATTORNEY-REQUIRED: Confirm registration status with the Information Regulator and whether a deputy Information Officer is required given the scale of processing.]

7. Changes to this list

We review and update this subprocessor list when we add, replace, or remove subprocessors. Material changes — including the addition of any subprocessor that processes special personal information — will be reflected in an updated "Last updated" date and notified to data subjects via the Privacy Policy or, where material, via in-app notice. We aim to provide 30 days' advance notice of material subprocessor changes where operationally feasible.

Related policies