1. Overview and legal basis
eRunna (Pty) Ltd (registration number [TBD: company registration number]) ("we", "us", "our") acts as a responsible party under the Protection of Personal Information Act 4 of 2013 ("POPIA") in respect of personal information it collects from customers, runners, merchants, and partners. Where we engage third parties to process personal information on our behalf, those parties are operators within the meaning of POPIA section 1.
POPIA sections 20 and 21 require that:
- Processing by an operator is governed by a written contract that binds the operator to the same obligations that apply to eRunna as responsible party (POPIA s21 [ATTORNEY-REQUIRED: confirm citation — subsection s21(1)]).
- The operator may only process personal information with our knowledge or authorisation and must treat the confidentiality of personal information as obligatory (POPIA s21 [ATTORNEY-REQUIRED: confirm citation — subsection s21(2)]).
- The operator must notify eRunna immediately where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person (POPIA s22, read with s21 [ATTORNEY-REQUIRED: confirm citation — subsection s21(3)]).
Where personal information is transferred outside the Republic of South Africa, POPIA section 72 applies. We transfer personal information to a foreign country or international organisation only where:
- the recipient country or organisation is subject to an adequate level of protection substantially similar to POPIA; or
- the data subject has consented to the transfer; or
- appropriate contractual safeguards are in place; or
- the transfer is necessary for the performance of a contract with the data subject.
The Information Regulator of South Africa oversees compliance. Questions or complaints: info@erunna.app.
[ATTORNEY-REQUIRED: Confirm the precise POPIA compliance pathway for each cross-border transfer (s72(1)(a)–(e)) and whether any transfers to US-based Google Cloud, Firebase, or Paystack infrastructure require a formal data-transfer agreement (DTA) or whether reliance on a contractual mechanism is sufficient.]
2. Subprocessor list
The table below lists all third-party operators currently authorised to process personal information on eRunna's behalf. Where a provider is headquartered outside South Africa, the country of processing and the applicable cross-border transfer safeguard are noted. This list is updated when subprocessors are added or removed; material changes will be reflected in the Privacy Policy.
Infrastructure and platform
| Subprocessor | Services provided | Categories of personal information processed | Processing location(s) | Cross-border safeguard (s72) |
|---|---|---|---|---|
| Google Cloud Platform (GCP) — Google LLC | Cloud Run (containerised API and service hosting), Cloud Logging, Cloud Storage, Vertex AI (where applicable), Secret Manager, Identity and Access Management | All personal information transiting or stored on eRunna's backend infrastructure, including account data, order/errand data, location data, and log data | Primary: africa-south1 (Johannesburg, South Africa) — post-ADR 0061 migration. Ancillary GCP services may process data in other Google regions. |
Primary processing in South Africa (no cross-border transfer for africa-south1 workloads). Ancillary services: Google Cloud Data Processing Amendment (contractual safeguard). [ATTORNEY-REQUIRED: Confirm whether Google's standard Data Processing Amendment is accepted as sufficient under s72 for any ancillary workloads processed outside South Africa.] |
| Firebase — Google LLC | Authentication (Firebase Auth), Firestore (real-time database), Cloud Messaging (FCM — push notifications), Crashlytics (crash reporting and diagnostics) | Firebase UIDs, authentication tokens, device tokens, order/errand records, crash and diagnostic data | Firebase services are globally distributed. Firestore primary region is configured to africa-south1 per ADR 0061; other Firebase services (Auth, FCM, Crashlytics) may process in Google's global infrastructure. |
Google Cloud Data Processing Amendment (contractual safeguard). [ATTORNEY-REQUIRED: Confirm firebase.google.com DPA coverage extends to all Firebase products in scope, and verify whether Crashlytics data (which may include device identifiers and stack traces) is adequately covered.] |
| Google Cloud Pub/Sub — Google LLC | Asynchronous event messaging between eRunna's microservices (order events, runner-availability events, settlement events, etc.) | Event payloads containing order, location, and status data; may include personal identifiers (UIDs, order references) | africa-south1 (primary). Cross-region replication not currently enabled. |
Processing within South Africa (primary). Google Cloud Data Processing Amendment (contractual safeguard) for any ancillary processing. |
| Google Cloud Memorystore (Redis) — Google LLC | In-memory caching (session state, real-time runner-availability state, matching engine transient state) | Transient session and state data; may include UIDs and real-time location references | africa-south1 (Johannesburg). Data is ephemeral; not persisted to disk in standard configuration. |
Processing within South Africa. Google Cloud Data Processing Amendment (contractual safeguard). |
Payments
| Subprocessor | Services provided | Categories of personal information processed | Processing location(s) | Cross-border safeguard (s72) |
|---|---|---|---|---|
| Paystack ([TBD: confirm Paystack's exact registered legal entity name]) | Payment authorisation, card tokenisation (saved cards), charge processing, refunds, payouts to runners and merchants. eRunna uses Paystack Inline (in-app WebView) for card capture; full card numbers are NOT transmitted to or stored on eRunna's servers. | Payment tokens, authorisation codes, transaction references, payout recipient bank/mobile-money details (runners, merchants). eRunna receives tokens only — not raw card numbers (PCI DSS SAQ-A-EP scope; see ADR 0044 Amendment 2). | Paystack processes transactions via its own infrastructure and operates internationally [TBD: confirm Paystack's place of incorporation and corporate group; it is understood to be Nigeria-based]. Servers may be located in [TBD: confirm Paystack's stated data-residency commitments]. | [ATTORNEY-REQUIRED: Confirm whether Paystack's standard merchant agreement includes a POPIA-compliant data-processing clause, and whether a separate DTA is required under s72 for personal information transferred to Paystack's non-South-African infrastructure. Also confirm whether payout recipient data (ID numbers / bank details used for runner/merchant verification) triggers heightened obligations as "special personal information" under POPIA s26.] |
Communications
| Subprocessor | Services provided | Categories of personal information processed | Processing location(s) | Cross-border safeguard (s72) |
|---|---|---|---|---|
| [TBD: Email service provider — e.g., SendGrid / Mailgun / Amazon SES / other] | Transactional email delivery (account verification, order confirmations, receipts, support responses, platform notifications) | Email addresses, name, order references, message content | [TBD: Confirm provider and data-processing location] | [TBD: Confirm cross-border transfer safeguard applicable once provider is selected. Likely contractual safeguard (DPA/DTA). Attorney to verify.] [ATTORNEY-REQUIRED: Once provider is selected, confirm POPIA s21 operator contract is in place and s72 pathway is documented.] |
| [TBD: SMS / OTP provider — e.g., Clickatell / Vonage / Twilio / other] | One-time password (OTP) delivery, transactional SMS notifications (order status, runner alerts) | Mobile phone numbers, OTP codes (ephemeral), order status data | [TBD: Confirm provider and data-processing location] | [TBD: Confirm cross-border transfer safeguard once provider is selected.] [ATTORNEY-REQUIRED: Confirm POPIA s21 operator contract and s72 pathway once provider is confirmed.] |
Identity verification and KYC
| Subprocessor | Services provided | Categories of personal information processed | Processing location(s) | Cross-border safeguard (s72) |
|---|---|---|---|---|
| [TBD: KYC / identity-verification vendor — e.g., Smile Identity / Onfido / Jumio / other] | Runner onboarding identity verification: document check (South African ID / passport), selfie / liveness check (biometric), address verification where applicable | Government-issued identity documents, facial biometric data (liveness / selfie), date of birth. These constitute special personal information under POPIA s26 (biometric information, possibly race/ethnicity from identity documents). | [TBD: Confirm provider and data-processing location] | [ATTORNEY-REQUIRED: Processing of biometric data and identity documents is "special personal information" under POPIA s26 and requires explicit consent AND one of the conditions in s27. Attorney must: (a) confirm the applicable s27 condition; (b) confirm whether the KYC vendor's DPA is POPIA-compliant; (c) confirm s72 cross-border safeguard where vendor processes outside South Africa; (d) confirm whether any FICA / FIC Act obligations attach to the runner-verification process given eRunna's emerging accountable-institution status (see also Section 3 below).] |
Observability and monitoring
| Subprocessor | Services provided | Categories of personal information processed | Processing location(s) | Cross-border safeguard (s72) |
|---|---|---|---|---|
| Grafana Labs (Grafana Cloud) and/or self-hosted Prometheus/Grafana on GCP | Metrics collection, alerting, dashboard visualisation, platform health monitoring | Aggregated and technical metrics; logs may incidentally contain request identifiers or UIDs. Personally identifiable information in logs should be minimised (see Data Retention Policy). | Self-hosted: africa-south1 GCP (no cross-border transfer). If Grafana Cloud is used: [TBD: confirm Grafana Cloud data-region configuration]. |
Self-hosted: no cross-border transfer. Grafana Cloud: Grafana Labs DPA (contractual safeguard). [TBD: confirm Grafana Cloud region and DPA status if in use.] |
3. FICA / AML-CFT obligations — attorney notice
[ATTORNEY-REQUIRED: eRunna operates a payment platform involving the movement of money between customers, runners, merchants, and partners. Attorney must advise on the following:
- Whether eRunna constitutes or will constitute an "accountable institution" under Schedule 1 of the Financial Intelligence Centre Act 38 of 2001 ("FICA"), as amended [ATTORNEY-REQUIRED: confirm citation — the specific amending Act and year, and confirm Schedule 1 currently captures the relevant activity], given the nature of its payment flows.
- If eRunna is or becomes an accountable institution: the applicable customer due-diligence ("CDD") obligations, record-keeping obligations, and suspicious-transaction reporting ("STR") obligations under FICA [ATTORNEY-REQUIRED: confirm citation — the specific FICA sections/subsections for each obligation, as the section numbering has changed across amendments].
- Whether the use of Paystack as a regulated payment service provider satisfies, partially satisfies, or is separate from eRunna's own FICA obligations.
- Whether the KYC process used for runner onboarding (see Section 2, Identity verification) meets any applicable CDD standard, or whether additional steps are required.
- Whether eRunna's marketplace facilitation function (in particular, the Johannesburg CBD merchant-onboarding context and the requirement to not facilitate prohibited/counterfeit-goods trade — see ADR 0075) triggers any enhanced due-diligence ("EDD") obligation under FICA in respect of high-risk merchants or product categories.]
4. Marketplace integrity — prohibited and counterfeit goods
[ATTORNEY-REQUIRED: eRunna's platform must not facilitate the sale, promotion, or delivery of counterfeit, illicit, or prohibited goods (see ADR 0075). Attorney must advise on:
- The civil and criminal liability exposure of a platform operator under the Trade Marks Act 194 of 1993, the Counterfeit Goods Act 37 of 1997, and related customs and excise legislation, where the platform knowingly or constructively facilitates the trade in counterfeit goods.
- The platform's obligations (if any) to conduct due diligence on merchants prior to onboarding, particularly for merchants whose inventory categories overlap with goods commonly counterfeited or prohibited in the Johannesburg CBD context.
- Whether eRunna's current merchant-onboarding KYC and category controls (to be implemented per ADR 0075) meet the standard required to avail itself of an "innocent conduit" or "safe harbour" defence.
- Recommended contractual protections (merchant warranties, indemnities, immediate suspension triggers) to be included in merchant terms.]
5. Data-collection surfaces — POPIA collection notices and marketing consent
eRunna operates two live data-collection surfaces outside the main application:
- Waitlist web form ("Join the waitlist") — collects name and email address and/or mobile number. A POPIA-compliant collection notice (s18) and, where applicable, electronic-communications marketing consent (under POPIA and/or the Electronic Communications and Transactions Act 25 of 2002) must accompany this form.
- In-person mall activations — physical sign-up or leaflet distribution at shopping centres in Gauteng. A printed POPIA collection notice must be presented at the point of collection; marketing consent must be specifically and separately obtained.
[ATTORNEY-REQUIRED: Confirm (a) whether the current waitlist-form collection notice and consent wording satisfies POPIA s18 and the applicable direct-marketing consent regime; (b) whether any in-person giveaway or promotional competition at mall activations triggers compliance obligations under the Consumer Protection Act 68 of 2008 (CPA) promotional-competition rules [ATTORNEY-REQUIRED: confirm citation — the specific CPA section (indicatively s36) and the applicable promotional-competition Regulations]; and (c) confirm the correct designated Information Officer details for inclusion in collection notices — see [TBD] below.]
6. Information Officer and contact
eRunna's designated Information Officer responsible for POPIA compliance is:
- Name: [TBD: Information Officer name]
- Title: [TBD: Information Officer title]
- Email: info@erunna.app
- Postal address: [TBD: registered postal address for POPIA purposes]
The Information Officer has been or will be registered with the Information Regulator of South Africa as required under POPIA s55. [ATTORNEY-REQUIRED: Confirm registration status with the Information Regulator and whether a deputy Information Officer is required given the scale of processing.]
7. Changes to this list
We review and update this subprocessor list when we add, replace, or remove subprocessors. Material changes — including the addition of any subprocessor that processes special personal information — will be reflected in an updated "Last updated" date and notified to data subjects via the Privacy Policy or, where material, via in-app notice. We aim to provide 30 days' advance notice of material subprocessor changes where operationally feasible.
Related policies
- Privacy Policy — describes the categories of personal information collected and the purposes and legal bases for processing.
- Data Retention Policy — describes retention periods for each category of personal information.
- Terms of Service — the overarching contract governing use of the eRunna platform.
- Runner Terms — runner-specific terms, including provisions relating to engagement/classification status (unresolved — see that document) and data processing.
- Security Incident Response — describes eRunna's response process for personal-information breaches (POPIA s22 notification obligations).
- Legal index