BEYOND OPERATOR AGREEMENT
The written contract required by section 21 of POPIA
Draft prepared for attorney review. Drafted 09/09/2026 against South African law. Risk rating R3, which makes review by a qualified South African attorney required before the first external sale. What to look hardest at is named at the end.
Version 1.0 · Effective 9 September 2026
This agreement forms part of the Beyond Master Software Terms and is accepted at the same time. It applies whenever Beyond processes Personal Information on the Customer's behalf.
WHY THIS DOCUMENT EXISTS
Section 21 of POPIA does not merely encourage this. It requires a Responsible Party to ensure, in terms of a written contract, that any Operator processing Personal Information on its behalf establishes and maintains the security measures required by section 19. Without such a contract the Responsible Party is in breach — so this protects the Customer at least as much as it protects Beyond.
In plain terms:
- You are the Responsible Party. The people whose information goes into the Service are your employees, your contractors and your clients. You decide what goes in, why, and for how long.
- Beyond is the Operator. We hold and process that information on your instruction, to run the Service, and for no purpose of our own.
That division is not a formality. It decides who answers to a data subject, who answers to the Information Regulator, and who must notify a breach.
1. DEFINITIONS AND INTERPRETATION
1.1 Terms defined in the Master Software Terms carry the same meanings here.
1.2 In addition:
1.2.1 "Data Subject", "Operator", "Personal Information", "Processing", "Responsible Party" and "Special Personal Information" bear the meanings given in POPIA.
1.2.2 "Information Regulator" means the Information Regulator established under section 39 of POPIA.
1.2.3 "Personal Information Breach" means any incident where there are reasonable grounds to believe that Personal Information has been accessed or acquired by an unauthorised person.
1.2.4 "Sub-Operator" means a third party engaged by Beyond that processes Personal Information in the course of providing the Service.
1.3 This agreement is read together with the Master Software Terms. Where they conflict on the processing of Personal Information, this agreement governs.
2. THE ROLES
2.1 The Customer is the Responsible Party in respect of all Personal Information contained in Customer Data.
2.2 Beyond is the Operator in respect of that Personal Information.
2.3 Beyond is a Responsible Party in its own right only in respect of the information it holds about the Customer as a business — the contact details of the people who administer the account, billing records, and support correspondence. That processing is governed by the Beyond Privacy Policy, not by this agreement.
2.4 The Customer warrants that it has a lawful basis under section 11 of POPIA for the Personal Information it puts into the Service, and that it has given the notification required by section 18 to the Data Subjects concerned.
2.5 Where the Service records employee activity, Beyond supplies a monitoring notice for the Customer to issue to its own staff. Issuing it, and recording that it was issued, is the Customer's obligation. Beyond cannot discharge it, because these are the Customer's employees and the Customer is the Responsible Party.
3. SCOPE OF PROCESSING
3.1 Subject matter. Provision of the Service described in the applicable Product Schedule.
3.2 Duration. For as long as the Master Software Terms are in force, plus the retention period in clause 10.
3.3 Nature and purpose. Storing, organising, retrieving, displaying and reporting on Customer Data so that the Customer can run its business, and doing so only on the Customer's instruction.
3.4 Categories of Data Subject. The Customer's employees, contractors, clients and the individuals recorded within its client organisations.
3.5 Categories of Personal Information. Typically: names, work email addresses, job roles, employment dates, time and attendance records, leave records, pay-relevant rate information, and — where the Customer enables it — coarse workstation activity totals. The precise list for each product is in Annexure A.
3.6 Special Personal Information. The Service is not designed to hold Special Personal Information as defined in section 26 of POPIA, and the Customer undertakes not to put any into it except where the Product Schedule expressly provides for it and the Customer has a lawful basis under section 27 or an authorisation under section 28.
4. BEYOND'S OBLIGATIONS AS OPERATOR
Beyond undertakes that it will:
4.1 Process only on instruction. Process Personal Information only for the purposes in clause 3 and only on the Customer's documented instruction, which the Master Software Terms and the Customer's use of the Service constitute — except where required to do so by law, in which case Beyond will inform the Customer before processing unless the law forbids it.
4.2 Not process for its own purposes. Not use Customer Personal Information for its own marketing, for profiling, or to train any machine-learning model.
4.3 Maintain section 19 security safeguards. Secure the integrity and confidentiality of Personal Information by taking appropriate, reasonable technical and organisational measures — see clause 5.
4.4 Keep it confidential. Treat all Personal Information as confidential and ensure that every person authorised to process it is bound by a written confidentiality obligation that survives their engagement.
4.5 Restrict access. Limit access to personnel who need it to provide the Service or support, and record every such access — see clause 6.
4.6 Notify breaches immediately. Comply with clause 8.
4.7 Assist the Customer. Provide reasonable assistance, at the Customer's cost where the effort is material, with:
4.7.1 requests from Data Subjects under sections 23, 24 and 11(3) of POPIA; 4.7.2 the Customer's own obligation to notify the Information Regulator and Data Subjects under section 22; and 4.7.3 any assessment, enquiry or investigation by the Information Regulator.
4.8 Return or delete. Deal with Personal Information at the end of the relationship as clause 10 requires.
4.9 Not process outside the Republic except as clause 9 permits.
5. SECURITY SAFEGUARDS (POPIA SECTION 19)
5.1 Beyond maintains, at minimum:
5.1.1 Isolation between customers. Each Customer's data is confined to its own Workspace. That boundary is enforced in the software itself and is verified by an automated test that fails the build if it ever stops holding.
5.1.2 Access control by role. What a person can see is decided by their role. In particular, confidential figures such as individual cost rates are withheld from those not entitled to see them by the interface that produces them, rather than merely hidden from view.
5.1.3 Encryption in transit, and encryption at rest for stored third-party credentials.
5.1.4 Authentication controls including password minimums, rate limiting on sign-in, and one-time links rather than passwords chosen for people by somebody else.
5.1.5 An append-only audit trail of material changes, readable by the Customer, which cannot be edited or deleted from within the Service.
5.1.6 Backups, verified on creation, with restoration rehearsed rather than assumed.
5.1.7 Automated deletion of data whose retention period has expired, running as a scheduled job rather than as an intention.
5.2 Beyond will not materially reduce these safeguards during the term.
5.3 Beyond identifies and maintains awareness of reasonably foreseeable internal and external risks to Personal Information in its possession, as section 19(2) requires, and verifies that its safeguards are effectively implemented.
6. WHO AT BEYOND CAN SEE THE CUSTOMER'S DATA
6.1 Beyond staff may enter the Customer's Workspace only to provide support, to investigate a fault, or to comply with the law.
6.2 Every such entry is recorded in the Customer's own audit trail, inside the Customer's own Workspace, where the Customer can read it — naming the individual, the time, and the fact that it was Beyond support rather than one of the Customer's own people. It is recorded as a distinct kind of actor so that it can never be mistaken for the Customer's own staff.
6.3 The Customer does not have to ask for this record and Beyond cannot remove it.
7. SUB-OPERATORS
7.1 The Customer gives Beyond general written authorisation to engage Sub-Operators, subject to this clause.
7.2 Beyond will impose on every Sub-Operator, by written contract, obligations no less protective than those in this agreement, and remains fully liable to the Customer for a Sub-Operator's acts and omissions.
7.3 The Sub-Operators engaged as at the effective date of this version are listed in Annexure B.
7.4 Beyond will give the Customer at least 30 (thirty) days' written notice before adding or replacing a Sub-Operator. If the Customer reasonably objects on data-protection grounds within that period, the parties will discuss it in good faith; if it cannot be resolved, the Customer may terminate the Master Software Terms without penalty and receive a pro-rata refund of anything paid in advance.
8. PERSONAL INFORMATION BREACHES
8.1 Beyond will notify the Customer immediately where there are reasonable grounds to believe that Personal Information of a Data Subject has been accessed or acquired by an unauthorised person, as section 21(2) of POPIA requires. "Immediately" means without delay, not within a stated number of days, and Beyond will not wait for a complete investigation before making the first notification.
8.2 The notification will state, so far as known at the time: what happened and when; the categories and approximate volume of Personal Information involved; the likely consequences; what Beyond has done and is doing; and a contact point. Beyond will supplement it as more becomes known.
8.3 Notifying the Information Regulator and the affected Data Subjects under section 22 is the Customer's obligation, because the Customer is the Responsible Party. Beyond will give the Customer every reasonable assistance in doing so.
8.4 Beyond will not notify any third party of a breach affecting the Customer's Personal Information without first consulting the Customer, unless required by law to do so.
8.5 Beyond will keep a record of every Personal Information Breach affecting Customer Data, including the remedial action taken.
9. TRANSFERS OUTSIDE SOUTH AFRICA
9.1 The Service is operated within the Republic of South Africa. Customer Data is stored in the Republic.
9.2 Beyond will not transfer Personal Information outside the Republic unless section 72 of POPIA is satisfied — that is, unless the recipient is subject to a law, binding corporate rules or a binding agreement providing an adequate level of protection, or the Data Subject consents, or one of the other section 72 grounds applies.
9.3 Any Sub-Operator outside the Republic is identified as such in Annexure B, with the section 72 basis relied on stated beside it.
10. RETENTION, RETURN AND DELETION
10.1 The Customer sets its own retention period for activity data within the Service, subject to the minimum and maximum the Product Schedule allows. Beyond deletes data past that period automatically.
10.2 On termination of the Master Software Terms, Beyond retains Customer Data for 90 (ninety) calendar days, during which the Customer may export it or ask Beyond to return it in a machine-readable format.
10.3 After that period Beyond deletes the Customer Data, and procures its deletion by every Sub-Operator, except:
10.3.1 records Beyond is required by law to retain, which are retained only for as long as the law requires and only for that purpose; and
10.3.2 anonymised aggregate statistics from which no Data Subject can be identified.
10.4 Backups containing Customer Data are overwritten on the ordinary backup cycle. Beyond will not restore deleted Customer Data from a backup other than to recover from a fault.
10.5 Beyond will confirm deletion in writing on request.
11. AUDIT
11.1 Beyond will, on reasonable written request and no more than once in any 12 (twelve) month period unless there has been a Personal Information Breach, make available the information reasonably necessary to demonstrate compliance with this agreement.
11.2 The Customer may, at its own cost, on 30 (thirty) days' written notice and subject to reasonable confidentiality undertakings, audit Beyond's compliance — or appoint an independent auditor to do so, provided that auditor is not a competitor of Beyond.
11.3 An audit must not compromise the security or confidentiality of any other customer's data, and Beyond may refuse access to anything that would.
11.4 Where a Personal Information Breach has occurred, the once-a-year limit in clause 11.1 does not apply.
12. LIABILITY
12.1 The liability provisions of the Master Software Terms apply to this agreement, save that nothing here limits either party's liability to a Data Subject or to the Information Regulator, which is determined by POPIA and not by contract.
12.2 Each party is responsible for its own compliance with POPIA in its own role.
13. GENERAL
13.1 This agreement takes effect on the date the Customer accepts it and continues for as long as Beyond processes Personal Information on the Customer's behalf.
13.2 It may be varied only by a new published version which the Customer accepts, in the manner set out in clause 18 of the Master Software Terms.
13.3 The dispute resolution, domicilium, governing law and section 45 provisions of the Master Software Terms apply to this agreement.
13.4 If any provision of this agreement is inconsistent with POPIA, POPIA prevails and the provision is read down to the minimum extent necessary.
ANNEXURE A — WHAT IS PROCESSED
This is Annexure A referred to in the Beyond Operator Agreement, version 1.0.
For Beyond Pulse:
| Category | What | Source |
|---|---|---|
| Identity | Name, work email address, role, time zone, active/inactive status | Entered by the Customer |
| Work records | Time entries with project, task, description, duration and date; timesheet submissions and approvals | Entered by Users, or imported by the Customer |
| Leave | Leave type, dates, duration, reason where given, approval decisions | Entered by Users and approvers |
| Financial | Per-person cost and charge rates; project budgets; invoices and expenses | Entered by the Customer |
| Activity (only where enabled) | Per day and per machine: active minutes, idle minutes, and coarse category totals | The activity agent, installed by the User |
| Coding activity (opt-in per person) | Per-day coding totals from the person's own WakaTime-compatible account | Connected by the User themselves |
| Access records | Sign-in events, audit trail entries, support access | Generated by the Service |
What the activity signal never collects, and cannot be configured to collect: window titles, document names, URLs, screenshots, keystrokes, or individual application names. That is enforced by automated checks that fail the build, not only by policy. The full statement is in the monitoring notice.
For other Beyond products, the equivalent table is in that product's Schedule.
ANNEXURE B — SUB-OPERATORS
This is Annexure B referred to in the Beyond Operator Agreement, version 1.0.
| Sub-Operator | What it does | Location | Section 72 basis |
|---|---|---|---|
| To be completed before the first external sale |
⚠️ This annexure is deliberately not filled in with guesses. For an on-premises deployment on the Customer's own infrastructure the list may be empty. For a Beyond-hosted deployment it must name every party that touches Customer Data — the hosting provider, the mail provider, and any integration the Customer enables — with the location of each and, for anything outside the Republic, the section 72 ground relied on. Naming a Sub-Operator that does not exist is as bad as omitting one that does, so this is completed from the deployment's actual configuration and not from an assumption.
For the attorney reviewing this
- Clause 8.1, "immediately". POPIA section 21(2) says "immediately" and this agreement repeats it rather than converting it into a number of hours, which would be a weaker undertaking than the statute. Please confirm that is right and that clause 8.3 correctly places the section 22 obligation on the Customer.
- Clause 7, general authorisation for Sub-Operators. POPIA is less prescriptive than the GDPR here. Please confirm that general authorisation plus 30 days' notice and an objection right is adequate, and whether specific authorisation should be required instead.
- Annexure B is empty by design and must be completed from the real deployment before anybody signs. Please advise whether an empty annexure invalidates the agreement or merely limits it to no sub-processing.
- Clause 2.4 and 2.5, the warranties placed on the Customer. These put the lawful basis and the section 18 notification on the Customer. That is correct in law, but please confirm the wording does not overreach in a way a court would read against the drafter.
- Clause 9, cross-border. Currently drafted for a South African deployment. If Beyond ever hosts outside the Republic, this clause and Annexure B both change materially.
- Clause 12.1. Liability to a Data Subject and to the Regulator is expressly not capped, because it cannot be. Please confirm the carve-out is drawn widely enough.
operator-agreement · v1.0 · sha256 4fceda8e2007995dfad5ff6214df2a77b76480284980427b41f47501f14219a2