How SyncChat meets the Protection of Personal Information Act, and what that means for you and your customers.
LAST UPDATED: JULY 2026
SyncChat, operated by Leadsync, is committed to processing personal information lawfully and responsibly in line with the Protection of Personal Information Act (POPIA) of South Africa. This notice explains how we uphold POPIA's eight conditions for lawful processing.
Where you use SyncChat to message your own customers, you are the responsible party for that personal information and SyncChat acts as your operator, processing it only on your instructions. For your own account information, SyncChat is the responsible party.
We process personal information only for the legitimate purpose of operating the messaging platform — delivering and logging WhatsApp messages, generating AI replies, providing support, and billing. We collect the minimum information needed for these purposes.
As the responsible party for your customers' data, you are responsible for having a lawful basis (such as consent) to message them and to store their contact details. SyncChat provides tools — consent capture against each contact, opt-out handling, and Terms acceptance prompts — to help you meet this obligation, but the opt-in itself must be obtained by you.
WhatsApp adds its own requirement on top of POPIA: before you send someone a business-initiated message, they must have opted in through a clear action, knowing your business name and that they will be contacted on WhatsApp. Keep a record of how and when each opt-in was given. Contacts who decline or reply STOP are marked as opted out and are automatically excluded from bulk and scheduled campaigns.
Data subjects may request access to, correction of, or deletion of their personal information, and may object to processing. Requests relating to your account can be sent to us directly; requests relating to your customers should be directed to you as the responsible party, and we will assist you in fulfilling them.
We maintain appropriate, reasonable technical and organisational measures to secure personal information against loss, damage, and unauthorised access — including encryption in transit, access controls, and per-organisation data isolation.
Some of our sub-processors (for hosting, messaging, and AI) may process data outside South Africa. Where this happens, we take steps to ensure the recipient is subject to adequate data-protection safeguards, as permitted under POPIA.
If a security compromise affecting personal information occurs, we will notify the affected parties and the Information Regulator as required by POPIA, as soon as reasonably possible after becoming aware of it.
Our Information Officer oversees POPIA compliance and handles data-related queries and complaints. You may also lodge a complaint with the Information Regulator of South Africa (inforegulator.org.za).