Data processing agreement
Version 1.0 · Effective 18 August 2026
The operator agreement POPIA requires. It applies automatically, so nobody has to ask for it or sign a separate copy.
This agreement applies automatically to every customer, and forms part of the Terms of Service. Nobody has to ask for it or sign a separate copy. If your legal team needs it executed on paper, write to obakengm@mammrlla.com and we will sign yours.
1. Who is who
Under the Protection of Personal Information Act, your company is the responsible party for the personal information contained in its own mail, and Mammrlla is the operator, processing it only on your documented instruction.
Your instruction is the act of connecting a mailbox and asking questions of it. We process for no other purpose.
2. What we process, and why
- Categories of person: your staff, your clients, your suppliers, and anybody who has corresponded with a connected mailbox.
- Categories of information: names, email addresses, phone numbers, the contents of business correspondence and its attachments, and whatever those attachments contain.
- Purpose: answering questions your people ask about your own documents, and nothing else.
- Duration: for as long as the mailbox is connected and the account is open.
3. Where it goes, and why that is allowed
Some of the companies that help us do this work are outside South Africa. Section 72 of POPIA says personal information may only leave the country on a proper legal basis, so this section says where it goes rather than leaving you to work it out.
- Your mail already lives with Google, under your own Google Workspace agreement, in the countries Google keeps it in. Panorithm reads it where it already is. It does not move your mailbox or copy it anywhere new.
- What we keep is in Johannesburg. Accounts, permissions, the index of what was read and the record of each run are in Google Cloud Firestore, region
africa-south1. - Reading and answering happen with the model providers on the subprocessor list, each with its country named, today in the United States. Every one is bound by written terms to act only on instruction, to protect what it sees, and not to train on it.
- You decide. As responsible party, connecting a mailbox is you permitting this for the people in it, who are your own staff and business contacts. We name every country before it is used, and we never send anything to a country that is not on the list.
4. What we will not do
- Process for any purpose you have not instructed.
- Use your information to train models, build features for other clients, or improve anything outside your own account.
- Sell it, share it with advertisers, or disclose it to anybody except the subprocessors listed.
- Transfer it outside the subprocessors named without telling every account holder first.
5. Security
- Mailbox tokens are encrypted at rest. Nobody at Mammrlla reads them.
- Every record carries the company it belongs to and is refused to any other.
- Access inside your company is what your account holder sets, enforced on every path that can reach a document.
- Sign-in is by single-use link that expires in fifteen minutes. There are no passwords to leak.
- Attachment contents are not stored. They stay in your mailbox and are fetched when opened.
6. When Mammrlla looks at your account
We have no standing access to your data. Nobody at Mammrlla can open your account because they feel like it, and there is no master login.
When we need to look, to fix something or to scope an agent for you:
- We ask, naming what we want to see, why, and for how long. You get an email.
- Nothing happens until your account holder approves it. Declining costs you nothing.
- Access expires on its own, within a week at the outside, without anybody remembering to close it.
- You can withdraw it at any moment, and it stops immediately.
- Two levels exist. Shape only gives counts and how well fields extract, and includes no filenames, senders, suppliers, amounts or document contents. Documents lets us open files, and is asked for only when the work genuinely needs it.
- Every single access is logged and shown to you in Settings, whether or not you are watching at the time.
7. Subprocessors
The current list is at /legal/subprocessors. You authorise those listed. We email every account holder at least three business days before adding a provider or a country, and moving between providers already listed needs no notice. If you object, we go back to the provider used before; if it is gone, we look together for one you accept; and only if none exists may either side end the agreement, with no penalty.
8. If something goes wrong
We will tell you without undue delay and in any case within 24 hours of becoming aware of a compromise affecting your information, with what we know, what we are doing, and what we cannot yet say. Notifying the Information Regulator and the people affected is your obligation as responsible party; we will give you everything you need to do it.
9. Helping you meet your own obligations
If somebody exercises a POPIA right against you and the answer is in Panorithm, tell us and we will help you access, correct, export or delete it. We do not answer such requests directly, because the relationship is with you.
10. Deletion and return
Disconnecting a mailbox deletes its access and every record drawn from it immediately, from inside the product, without involving us. On termination everything belonging to your company is deleted within thirty days; ask before then and we export what we hold. Where your agreement with us gives you a longer window to take an export, nothing is deleted while that window is open, and deletion is complete within thirty days after it closes.
11. Audit
We will answer reasonable written questions about how we process your information, and provide what we have. For anything more than that, ask, and we will agree something proportionate rather than refuse.
12. Governing law
The law of South Africa, and this agreement ends when the Terms of Service do.