Skip to content

Run Your CRM in Line With South Africa's POPIA

HelloGrowthCRM is a sales CRM built by Soor LLC. If your team sells in South Africa, the Protection of Personal Information Act 4 of 2013 applies to the contact records, call notes and marketing lists you keep in it. This page sets out what POPIA asks of a business, which duties stay with you, and which controls the platform provides. It is written for procurement and security reviewers who want specifics. It is not legal advice, so check your own position with counsel or your information officer.

What POPIA asks of a sales team

POPIA governs the processing of personal information by public and private bodies in South Africa, and it is enforced by the Information Regulator. A CRM sits directly in scope: names, mobile numbers, email addresses, job titles, meeting notes and call summaries are all personal information when they identify someone. The Act also protects the information of juristic persons where it identifies them, so a company contact record is not automatically outside the Act. Most of the duties land on you as the responsible party, not on the software vendor.

The responsible party is the body that decides why and how personal information is processed. An operator is a party that processes it on the responsible party's behalf under a contract, without coming under that party's direct authority. HelloGrowthCRM processes your CRM records on your instructions, so you are the responsible party and we are an operator. You decide what to collect, why, how long to keep it and who inside your business can see it. Our job is to give you controls that make those decisions enforceable and to be clear about how the service is built, where it runs and which third parties we rely on.

The useful question is therefore not whether a CRM is POPIA certified. There is no such certification. The useful questions are narrower and testable. Can you show what personal information is held and export it on demand? Can you restrict who sees which records? Can you delete a person's information when a request arrives? Can you evidence who reached production systems if the Regulator asks? A reviewer can check those inside a trial account, and the rest of this page answers them one at a time. For a comparison with other regimes, see our GDPR-compliant CRM page.

The eight conditions for lawful processing, applied to a CRM

Chapter 3 of POPIA sets out eight conditions that every responsible party must meet. They are best read as a checklist you walk through for your CRM, with the platform supporting some and your own process owning the rest.

Accountability means you are answerable for compliance across the whole lifecycle, which is why an information officer and written policies matter. Processing limitation requires processing to be lawful, minimal and justified, for example by consent, a contract, or a legitimate interest, and requires information to be collected directly from the person in most cases. Purpose specification means you collect for a defined purpose, tell the person what it is, and stop keeping records once the purpose has ended unless a law or contract says otherwise. Further processing limitation asks that any new use is compatible with the original purpose, so a list collected for quotations is not automatically a list for unrelated promotions.

Information quality asks you to keep records complete, accurate and up to date, which is a good argument for deduplication and regular clean-ups of dormant leads. Openness asks you to keep documentation of processing and to notify people when you collect their information, so the wording on web forms and sign-up sheets matters. Security safeguards require appropriate, reasonable technical and organisational measures, including written operator contracts and breach notification. Data subject participation gives people the right to ask what you hold, to see it, and to have it corrected or deleted in the cases the Act provides for.

In practice, the CRM supports these conditions through source fields, consent flags, role-based access, exports and deletion, while the decisions about purpose, retention and notice sit with you. Write down your answers once, apply them consistently, and keep the records. If the Regulator ever asks, a clear, dated process is worth more than any badge.

Direct marketing, consent and opt-out under section 69

Section 69 regulates unsolicited direct marketing by electronic communication, which covers email, SMS and messaging apps such as WhatsApp as well as automatic calling machines. As a rule you may not send such marketing to a person unless they have given consent, or they are an existing customer who meets the Act's conditions. Those conditions are that you obtained their details in the context of a sale of a product or service, that you are marketing your own similar products or services, and that they were given a reasonable opportunity to object when the details were collected and at each communication.

Consent can generally be requested only once if it was not previously refused, and the request has to follow the prescribed approach. Every message must identify the sender and give a contact address or means by which the person can opt out. A sales team that imports a bought list, or that messages every contact in a spreadsheet because it has their number, is the pattern most likely to run into trouble. If you import a list, populate a source field, keep the original file and be ready to show how each contact came to be in your system.

HelloGrowthCRM carries consent and opt-out flags on each contact, broadcast templates include opt-out handling, and an opt-out removes the contact from future sends. Message history is dated, so you can show what was sent and when. This supports a documented process, but whether a particular campaign is lawful is a judgment for you and your adviser. If you run WhatsApp conversations at scale, our WhatsApp CRM for South Africa page explains the shared inbox, and Meta's own conversation rules and fees apply on top.

Access, correction, deletion and your information officer

Data subjects can ask whether you hold information about them, ask for a copy, and ask for it to be corrected or deleted where the Act provides. A CRM makes this manageable or painful depending on how its search and export behave. Administrators in HelloGrowthCRM can search contact records, open the full activity history and export account data at any time, so assembling a response does not depend on a support ticket. Decide in advance whether free-text notes are in scope of your answers, because notes often contain opinions that are still personal information.

We do not publish a fixed retention period, because the right one depends on your industry, contracts and statutory obligations rather than ours. What we provide is the mechanism: deletion requests are honoured, administrators can remove records, and the process is documented on our data rights page. Set a retention schedule, write it down and review lapsed leads on a cycle instead of letting dormant records pile up.

Each responsible party must have an information officer, registered with the Information Regulator, who encourages compliance, deals with requests and works with the Regulator. In a private business that role generally sits with the head of the organisation unless it is formally delegated, and deputies can be appointed. Give the information officer visibility of your CRM configuration, retention schedule and integrations, and keep a record of staff training on what the sales team may and may not do with contact data.

Security safeguards, compromise notification and the operator relationship

The security safeguards condition asks for appropriate, reasonable technical and organisational measures against loss, damage and unauthorised access. Where an operator is involved, the responsible party must have a written contract requiring the operator to maintain those measures, and the operator must tell the responsible party immediately if it has reasonable grounds to believe information has been accessed by an unauthorised person. HelloGrowthCRM protects data in transit with TLS and encrypts data at rest. Customer data sits in Supabase-managed Postgres running on AWS, with row-level security enforcing tenant isolation at the database layer.

Inside your account, role-based access control decides which users see which records, so a new representative does not need the same reach as an administrator. On our side, production access is least-privilege, gated behind multi-factor authentication, logged and reviewed periodically. Automated backups run with point-in-time recovery, so a database can be restored to a chosen moment. Soor LLC also completed a SOC 2 Type II examination covering a February to June 2025 observation window; the report is available under NDA by writing to sales@hellogrowthcrm.com.

Section 22 requires the responsible party to notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovering that personal information has been accessed or acquired by an unauthorised person. For that chain to work you need to know how you will hear from us and who you will tell next. Our incident-response workflow includes customer notification, and the Data Processing Agreement sets out the commitments in writing. Security researchers can report issues through our vulnerability disclosure process.

Cross-border transfers under section 72 and subprocessors

Section 72 limits the transfer of personal information to a third party in another country. In general you may transfer it if the recipient is subject to a law, binding corporate rules or a binding agreement that provides substantially similar protection, or if the person consents, or if the transfer is necessary for a contract or for the person's benefit in the circumstances the section lists. Most cloud CRMs, ours included, involve infrastructure that may be outside South Africa, which makes this section one to address in writing rather than assume.

The documents that support your assessment are the Data Processing Agreement, the subprocessor list and written confirmation of the hosting region that applies to your account, which we provide during onboarding or a security review. If a particular location is a hard requirement for your organisation, raise it before signing rather than after migration. Do not infer a hosting location from a South African phone number, a domain suffix or a regional sales presence.

For a wider view of how the platform is built and monitored, see the security overview and the trust center.

Controls and capabilities at a glance

  • TLS protects data in transit and stored data is encrypted at rest across the HelloGrowthCRM platform and its managed database.
  • Row-level security in Supabase-managed Postgres on AWS enforces tenant isolation, so one account cannot reach another account's records.
  • Role-based access control limits which users see which contacts, deals and activity history, supporting the security safeguards condition.
  • Production access at Soor LLC is least-privilege, multi-factor gated, logged and reviewed periodically rather than granted permanently.
  • Soor LLC completed a SOC 2 Type II examination covering a February to June 2025 observation window; the report is available under NDA.
  • Consent and opt-out flags on every contact, so a marketing send can be segmented on recorded consent and an opt-out removes the contact from future sends.
  • Administrators can export account data at any time, which supports data subject access requests without depending on a vendor support ticket.
  • Deletion requests are honoured, and the process for individuals and customers is documented publicly on the data rights page.
  • A documented incident-response workflow covers triage, containment and customer notification so you can act within POPIA's section 22 expectations.
  • Automated backups with point-in-time recovery let a database be restored to a chosen moment, not only to the last nightly snapshot.
  • The subprocessor list and an available Data Processing Agreement support your operator contract and cross-border transfer assessment.

Questions reviewers ask

Is HelloGrowthCRM POPIA certified?
No, and neither is any other CRM. POPIA is a law you comply with, not a certification scheme, so there is no POPIA certificate to hold or display. What we offer instead is evidence. Soor LLC completed a SOC 2 Type II examination covering a February to June 2025 observation window, available under NDA from sales@hellogrowthcrm.com, plus a Data Processing Agreement, a published subprocessor list and a documented data rights process. Treat any vendor advertising POPIA certification with caution.
Are we the responsible party and is HelloGrowthCRM the operator?
For the customer and lead records you load into your account, you are the responsible party and we process them on your instructions as an operator. You decide why personal information is collected, what is kept and for how long, and who in your business can see it. Our duties centre on processing only on your instructions, keeping the information confidential, maintaining security measures and telling you promptly about a compromise. Your obligations as the responsible party are not transferred to us by signing up.
Will you sign an operator or Data Processing Agreement?
Yes. A Data Processing Agreement is available covering processing instructions, confidentiality, security measures, subprocessor handling, assistance with data subject requests and incident notification. POPIA expects a written contract between a responsible party and an operator, so ask for the agreement during evaluation rather than after go-live. Our subprocessor list names the third parties involved in running the service, so you can see who is in the chain before you sign.
Where is my CRM data hosted, and is that a cross-border transfer?
HelloGrowthCRM runs on Supabase-managed Postgres hosted on AWS. The specific region that applies to your account is confirmed during onboarding or a security review, so ask for it in writing. If the data is stored or accessed outside South Africa, section 72 of POPIA is relevant: you need one of its grounds, such as a binding agreement providing substantially similar protection, or the data subject's consent. Record the hosting answer and your chosen ground in your own transfer assessment, and take legal advice if the position is not clear.
Can I send WhatsApp or email marketing to my CRM contacts under POPIA?
Section 69 restricts unsolicited electronic direct marketing. In general you need the person's consent, or they must be an existing customer whose details you obtained in the course of a sale and whom you are marketing similar products to, with a clear chance to object at collection and in every message. Each message must also say how to opt out. HelloGrowthCRM stores consent and opt-out flags per contact, so you can segment on them and record the evidence, but deciding whether a given send is lawful remains your responsibility.
What happens if there is a security incident?
Soor LLC maintains a documented incident-response workflow covering triage, containment, remediation and customer notification. Under section 22 of POPIA the responsible party must notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovering a compromise, so define internally who receives our notification and what they do first. A notice sitting unread in a shared inbox is the common failure. Researchers can also report issues through our published vulnerability disclosure process.
Do we still need an information officer if the CRM is secure?
Yes. POPIA requires each responsible party to have an information officer, who has to be registered with the Information Regulator. In a private company that role generally falls to the head of the business unless it is formally delegated. Vendor security controls reduce risk but do not transfer the obligation. Give your information officer visibility of the CRM configuration, retention schedule and integration list so the role has something concrete to oversee.

Get the security pack before you commit

Ask sales@hellogrowthcrm.com for the SOC 2 Type II report under NDA, the Data Processing Agreement and confirmation of the hosting region for your account. If a question here is not answered, put it in the security review and we will respond in writing. This page is general information, not legal advice. Looking for a CRM built around the South African market? See CRM for South Africa or the free CRM for South Africa, and compare Salesforce alternatives for South African teams.