Registra
Registra.
RegistrationEthicsTermsPrivacyPOPIACookiesRefundsDisciplineVeterinary
RegistrationEthicsTermsPrivacy
Return
Registra.Official Legal Dossier

POPIA Notice & Operator Agreement

This notice outlines our respective obligations under the South African Protection of Personal Information Act (POPIA) and constitutes our Data Processing Agreement.

Effective Date: July 1, 2026
•
Last Updated: June 1, 2026
Questions?

1. Dual Legal Roles: Operator vs. Responsible Party

TL;DR Summary
Registra acts as Responsible Party for your account data and the public registry. For your client data, Registra is the Operator and you are the Responsible Party.

Under POPIA, a clear distinction is made between the entity that controls the data and the entity that processes it. Registra operates in a dual capacity depending on the context of the data.

  • Registra as Responsible Party: For your personal account details, billing information, and the overarching public genealogical registry of dogs, Registra acts as the Responsible Party.
  • Registra as Operator: For the client management tools, waitlist applications, and puppy buyer data that you collect and store on our platform, Registra acts strictly as an Operator. You (the Breeder) are the Responsible Party. You determine the purpose of this data collection and are ultimately responsible to the Information Regulator and your clients.

2. Automatic Data Processing Agreement (DPA)

TL;DR Summary
Creating an account and using Registra constitutes the required written Data Processing Agreement under POPIA.

POPIA mandates that a Responsible Party must conclude a written agreement with their Operator. By creating an account and utilizing the Registra platform, you are agreeing to our Terms of Service, which legally constitutes the required Data Processing Agreement between your kennel and Registra.

3. Section 19 Security Obligations

TL;DR Summary
Cryptographic isolation via RLS, encryption in transit and at rest, strict access control with MFA and audit logs.

As your Operator, we are legally bound to establish and maintain the security measures outlined in Section 19 of POPIA.

  • Architectural Security:Each kennel's records are cryptographically isolated via database row-level security (RLS). All traffic is encrypted in transit and database backups are encrypted at rest.
  • Access Control: Only a small, audited group of Registra engineers hold administrative access, which is protected by mandatory multi-factor authentication and strict access logs.

4. Confidentiality and Processing Instructions

TL;DR Summary
We process data only per your instructions. Personnel bound by confidentiality. Individual audits prohibited to protect multi-tenant security.

As your Operator, Registra complies strictly with POPIA Sections 20 and 21 regarding the processing of your data.

  • Documented Instructions: We will process your localized client data solely in accordance with your documented instructions. Your use of the Registra platform, including interacting with the interface and utilizing our APIs, constitutes your complete and final documented instructions. Registra will not process your client data for any secondary purposes outside of providing the software service.
  • Duty of Confidentiality: All Registra personnel and engineers who have authorized access to our infrastructure are bound by strict contractual confidentiality obligations. We will never sell, disclose, or distribute your private client management data unless formally compelled by a South African court of law.
  • Compliance Verification: To satisfy your regulatory requirement to verify our security posture, Registra relies on continuous internal security auditing. Due to the multi-tenant nature of our cloud architecture, physical or technical audits of our infrastructure by individual users are strictly prohibited to protect the security of all kennels on the platform.

5. Public Application Forms & Cryptographic Consent

TL;DR Summary
Three-layer consent enforcement: form checkbox, RPC check, database trigger. Tamper-proof timestamp provides auditable proof of consent.

When members of the public submit waitlist applications via your Registra-hosted public profile, they must provide explicit, informed consent for their data to be stored. We enforce that consent at three architectural layers to protect you legally:

  • A required consent tickbox on the public-facing form.
  • An RPC-level action check on our backend servers.
  • A final database trigger that raises an exception and refuses insertion if consent was not granted.

When consent is given, a tamper-proof timestamp is recorded. This timestamp serves as your auditable proof of consent should a client ever submit a POPIA inquiry to your kennel.

6. Sub-Operators and Cloud Infrastructure

TL;DR Summary
We use AWS, Vercel, Stripe etc. All Sub-Operators bound by DPAs with POPIA-equivalent protection including Section 72 cross-border compliance.

To provide a globally available SaaS platform, Registra utilizes industry-leading third-party cloud infrastructure providers (such as AWS, Vercel, or Stripe).

  • By accepting this agreement, you grant Registra general authorization to engage these Sub-Operators to process your client data.
  • Registra ensures that all Sub-Operators are bound by strict data processing agreements that guarantee a level of data protection equivalent to or greater than POPIA standards, including strict compliance with Section 72 regarding cross-border data transfers.

7. Assistance with Data Subject Requests

TL;DR Summary
Dashboard tools provided to modify, export, or delete client data to help you fulfill POPIA obligations.

As the Responsible Party for your clients, you are legally obligated to fulfill Data Subject requests (such as a client asking for their data to be deleted or updated). Registra provides you with the necessary digital tools within your dashboard to modify, export, or permanently delete your clients' personal information to satisfy your POPIA obligations.

8. Operator Incident Reporting

TL;DR Summary
We notify you immediately of any breach affecting your client data so you can fulfill your notification duties to clients and the Information Regulator.

Should we identify any unauthorized access or data breach impacting your kennel's localized client data, we are legally bound as an Operator to notify you as soon as reasonably possible. This ensures you can fulfill your duties as the Responsible Party to notify your affected clients and the Information Regulator.

9. Data Deletion Upon Termination

TL;DR Summary
Client management data deleted on termination. Public registry data (pedigrees, lineage) retained permanently for genealogical integrity.

Upon the termination of your Registra subscription or the deletion of your account, Registra will securely delete your client management data (waitlists, buyer CRM data) from our active servers. Note that public registry data, including dog pedigrees and lineage records linked to your kennel affix, will be retained permanently by Registra in its capacity as the Responsible Party to maintain the integrity of the genealogical database.

Generated via registra.co.zaPrinted on request
Registra.

© 2026 Registra. All rights reserved.

Proudly designed and built in Cape Town.