Data Processing Agreement

Version 2026-06-24-gdpr-readiness · Last updated 24 June 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Perkstar Ltd, a company registered in England and Wales with company number 16256732 and registered office at 86-90 Paul Street, London, EC2A 4NE, United Kingdom (the "Processor", "Perkstar", "we", "us") and the operator identified in the subscription (the "Controller", "Operator", "you") for the use of the Perkstar platform (the "Services"). It sets out the terms on which Perkstar processes personal data on the Operator's behalf in accordance with UK GDPR, the Data Protection Act 2018 and, where applicable, the EU GDPR.

We publish this DPA openly so Operators can complete due diligence before signup. It should be read alongside our Terms of Service, Privacy Policy, Cookie Policy, and Sub-processors list.

1. Definitions

Terms not defined here have the meaning given to them in our Terms of Service. The following terms carry the meaning assigned to them under UK GDPR: "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Sub-processor", "Personal Data Breach", "Supervisory Authority", "Pseudonymisation".

"Applicable Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR), and (where the Operator processes personal data of individuals located in the EEA) the EU GDPR.

"Customer Personal Data" means personal data processed by Perkstar on the Operator's behalf in connection with the Services, including personal data relating to the Operator's end customers (the "Cardholders").

2. Roles of the parties

The Operator is the Controller of Customer Personal Data. Perkstar acts as the Operator's Processor in respect of that data and processes it only as described in this DPA and on the Operator's documented instructions, including instructions issued through standard configuration and use of the Services.

The Operator confirms that it has all necessary rights, lawful bases and consents to provide Customer Personal Data to Perkstar for processing under this DPA.

3. Subject matter, duration, nature and purpose

ItemDetail
Subject matterProcessing of Customer Personal Data to operate a digital loyalty programme for the Operator's Cardholders.
DurationThe term of the Operator's subscription, plus the 90-day post-termination grace window described in clause 11, and (in the case of pseudonymised transactional records only) the further retention period in clause 12.
Nature and purposeStoring Cardholder contact details, transaction history, loyalty balances and wallet passes; issuing and updating Apple Wallet and Google Wallet passes; sending Operator-initiated communications (email, SMS, push); running automated programmes (birthday rewards, expiry reminders, win-back campaigns); generating analytics for the Operator.
Types of personal dataName, email, phone number, optional date of birth, optional custom-form values configured by the Operator, loyalty activity and balances, marketing preferences, wallet pass identifiers, IP and User-Agent metadata captured for consent and security audit.
Categories of data subjectsThe Operator's Cardholders enrolled in any loyalty programme created on the Perkstar platform.

Perkstar will not process Customer Personal Data for any other purpose. Perkstar will not sell or rent Customer Personal Data, will not use it to enrich Perkstar's own marketing databases, and will not use it to train any artificial intelligence model.

4. Perkstar's obligations

Perkstar will:

  1. process Customer Personal Data only on the Operator's documented instructions, including with regard to international transfers, unless required to do otherwise by law (in which case Perkstar will notify the Operator first unless the law prohibits this);
  2. ensure that persons authorised to process the data are bound by written confidentiality obligations or appropriate statutory duties of confidence;
  3. implement and maintain the technical and organisational measures set out in Schedule 2 to ensure a level of security appropriate to the risk under Article 32 UK GDPR;
  4. engage Sub-processors only in accordance with clause 5;
  5. assist the Operator, taking into account the nature of the processing and the information available to Perkstar, by appropriate technical and organisational measures, insofar as possible, to fulfil the Operator's obligations to respond to Data Subject rights requests (see clauses 8 and 9);
  6. assist the Operator in ensuring compliance with its obligations under Articles 32 to 36 UK GDPR (security of processing, breach notification, data protection impact assessments, and prior consultation with the Information Commissioner's Office), taking into account the nature of the processing and the information available to Perkstar;
  7. notify the Operator of a Personal Data Breach affecting Customer Personal Data in accordance with clause 10;
  8. on termination of the subscription, return or delete Customer Personal Data in accordance with clauses 11 and 12; and
  9. make available to the Operator all information necessary to demonstrate compliance with this DPA and Article 28 UK GDPR, and allow for audits in accordance with clause 13.

5. Sub-processors

The Operator provides general written authorisation for Perkstar to engage Sub-processors to process Customer Personal Data, subject to the conditions below.

The current list of Sub-processors is published at https://dashboard.perkstar.co.uk/dpa/sub-processors and is incorporated into this DPA. Perkstar maintains the list and updates it when Sub-processors are added, removed or replaced.

Before engaging a new Sub-processor or replacing an existing one, Perkstar will give at least 30 days' prior notice by updating the Sub-processors page, publishing an in-app announcement to Operators, and (on prior request to privacy@perkstar.co.uk) sending a copy by email. If the Operator has a reasonable, documented data-protection objection, the Operator may notify Perkstar in writing within 14 days of the notice. Perkstar will work in good faith to propose an alternative arrangement. If no reasonable alternative is available within a further 30 days, the Operator may terminate the affected portion of the Services on written notice, with a pro-rata refund of any prepaid fees for the unused term, without further liability for either party in respect of that termination.

Perkstar will impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, and remains liable to the Operator for each Sub-processor's performance of its data protection obligations.

6. International transfers

The Operator and Cardholder personal data held in Perkstar's database is stored on infrastructure located in the EEA (Ireland, AWS eu-west-1) by Supabase, our database provider. Server-side rendering over Cardholder requests is performed by Vercel in Frankfurt (fra1). Transactional and marketing email is processed by Resend in Ireland. Rate-limiting infrastructure is operated by Upstash in Ireland. The combined effect is that Customer Personal Data at rest, and the primary request-handling layer that processes it, remains inside the EEA.

A limited subset of Sub-processors and operator-enabled integration partners may be located outside the UK and EEA, as identified in Schedule 1 — currently Stripe, Apple, Google, Telnyx, Inngest and certain POS, booking, delivery or marketplace integration partners. Where Customer Personal Data is transferred to a jurisdiction that is not the subject of a UK adequacy decision, Perkstar relies on an appropriate transfer mechanism, including (as applicable) the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another mechanism recognised under Applicable Data Protection Law. The relevant clauses are deemed incorporated into this DPA by reference and, where required, are executed between the parties on the Sub-processor's behalf.

7. Operator's obligations

The Operator will:

  1. ensure that it has a valid lawful basis under Article 6 UK GDPR (and, where applicable, Article 9) for each processing activity it instructs Perkstar to carry out;
  2. provide a privacy notice to its Cardholders that meets the transparency requirements of Articles 12 to 14 UK GDPR. The Operator may reference Perkstar's Cardholder Privacy Policy at https://dashboard.perkstar.co.uk/privacy in addition to, but not as a substitute for, the Operator's own privacy notice;
  3. obtain and maintain any consents required, including for marketing communications under PECR, non-essential cookies or similar technologies, and separate ad/analytics tracking consent where Meta, TikTok or Google Analytics measurement is configured;
  4. only send Customer Personal Data to Perkstar through the API, a point-of-sale integration, a bulk upload, or another external system where the Operator has already captured the required lawful basis and consent evidence;
  5. configure the Services and issue instructions to Perkstar in a way that complies with Applicable Data Protection Law; and
  6. respond to Data Subject rights requests as Controller, with Perkstar's assistance under clause 8.

The Operator is responsible for the accuracy, quality and legality of Customer Personal Data and the means by which it was obtained. The Operator is also responsible for the security of any endpoint to which Perkstar transmits Customer Personal Data — including webhook destinations under the Operator's control — once the data has been delivered.

8. Data Subject rights — general

Perkstar provides self-service tools within the Services to enable the Operator to access, rectify, export, restrict, and erase Customer Personal Data. These tools are designed to allow the Operator to respond to Data Subject rights requests within the timeframes required by UK GDPR.

If a Data Subject contacts Perkstar directly with a rights request relating to Customer Personal Data, Perkstar will, without undue delay, forward the request to the relevant Operator and will not respond substantively except to confirm receipt and direct the Data Subject to the Operator, unless legally required to do otherwise.

Where the self-service tools are insufficient, Perkstar will assist the Operator with reasonable additional support, without undue delay, to enable the Operator to meet its statutory response deadlines.

9. Data Subject rights — implementation specifics

Right of access and portability (UK GDPR Articles 15 and 20). The Services include a self-service data export that generates a ZIP archive containing the Cardholder's profile (in JSON and CSV), cards and balances, full transaction log, consent history (with IP, User-Agent and policy-version hash per channel), marketing-preference snapshots, privacy timeline, outbound communications log, and feedback history. The archive is delivered via a signed download link with a 48-hour time-to-live; the first download access is recorded. Each relation is capped at 10,000 rows, and a cover sheet flags any truncation.

Right to erasure (UK GDPR Article 17). The right to erasure is fulfilled by anonymisation of all identifying fields (name, email, phone, date of birth, custom-form values) and voiding of any active Apple or Google Wallet pass. Transactional records (enrolments, redemptions, balances) are retained in pseudonymised form within the meaning of UK GDPR Article 4(5), linked only by an internal opaque identifier, for the period required by tax law applicable to the Operator — typically 6 years from the end of the relevant accounting period under UK VATA 1994 Schedule 11 paragraph 6 and FA 1998 Schedule 18 paragraph 21 for UK-based Operators. The anonymisation event is logged to the platform's privacy timeline, and a CUSTOMER_ANONYMIZED webhook is fired to the Operator so the Operator's own systems can synchronise.

Right to object and withdraw consent (UK GDPR Article 21). The Services support per-channel consent for marketing communications (email, SMS, push) and separate ad/analytics tracking consent. Operators can record an opt-out at any time and cannot directly opt a Cardholder into marketing — Operator-initiated opt-ins are routed through a double opt-in flow in which the Cardholder confirms via a signed link before the channel is enabled. If a Cardholder objects through the public GDPR form, Perkstar immediately suppresses marketing and ad/analytics tracking consents for matching records while the Operator reviews the request.

Right to restriction (UK GDPR Article 18). Where a Cardholder exercises the right to restriction, the Operator may use the Services' per-channel opt-out controls to stop further marketing communications, combined with the suppression of the Cardholder's profile from active operational use. Perkstar will assist the Operator in implementing a restriction that does not amount to erasure where reasonably required.

Transactional wallet updates. Wallet pass refreshes and service messages needed to operate the loyalty programme, such as balance updates, reward unlocks and pass state changes, are treated separately from marketing. Marketing consent gates do not stop transactional wallet updates that are necessary to keep the Cardholder's pass accurate.

Automated decision-making (UK GDPR Article 22). Perkstar does not carry out solely automated decision-making producing legal effects, or similarly significant effects, on Cardholders. AI features in the Services are limited to assisting the Operator with copywriting and configuration; they do not make decisions about Cardholders.

10. Personal Data Breaches

Perkstar will notify the Operator without undue delay, and in any event within 72 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will include, to the extent then known:

  • the nature of the breach, including the categories and approximate number of Data Subjects and records affected;
  • the likely consequences;
  • the measures taken or proposed to address the breach and to mitigate its possible adverse effects; and
  • a contact point for further information.

Perkstar will provide reasonable assistance to enable the Operator to meet any notification obligations it has to the Information Commissioner's Office or to Cardholders. Routine attempts at unauthorised access that are blocked by Perkstar's security controls (for example, credential-stuffing attempts that do not result in unauthorised access) are not Personal Data Breaches for the purposes of this clause.

11. Return or deletion of data on termination — 90-day grace window

On termination or expiry of the Operator's subscription, Perkstar will retain Customer Personal Data in production systems for a 90-day grace window during which the Operator may:

  • reactivate the subscription with data intact; and
  • request, in writing, either:
    • a machine-readable export of Customer Personal Data (CSV or JSON, including customers, transactions, loyalty balances, consent history, and programme configuration), which Perkstar will deliver within 30 days of the request; or
    • deletion of Customer Personal Data from production systems.

If the Operator does not provide an instruction within the 90-day grace window, Perkstar will delete Customer Personal Data from production systems. Backups containing Customer Personal Data are retained for 7 days on a rolling basis through our database provider; they are not restored except to recover from a disaster, and remain subject to this DPA until they are overwritten in the ordinary course.

12. Retention of pseudonymised transactional records

Separately from clause 11, transactional records (enrolments, redemptions, balances) that have been pseudonymised in accordance with clause 9 are retained for the period required by tax law applicable to the Operator. For UK-based Operators this is typically 6 years from the end of the relevant accounting period (UK VATA 1994 Schedule 11 paragraph 6; FA 1998 Schedule 18 paragraph 21). Operators in other jurisdictions are responsible for confirming the applicable statutory retention period; Perkstar will retain the pseudonymised records for that period or for 6 years, whichever is shorter, unless the Operator instructs otherwise in writing.

These records contain no directly identifying information; they are linked only by an internal opaque identifier and are not re-identifiable by Perkstar without additional information held separately by the Operator.

13. Audit

Perkstar will make available to the Operator the information necessary to demonstrate compliance with Article 28 UK GDPR and this DPA. On reasonable written notice, and no more than once per calendar year (unless required more frequently by a Supervisory Authority or following a Personal Data Breach affecting the Operator), the Operator may request:

  1. completion of a reasonable security questionnaire;
  2. a copy of Perkstar's current Sub-processor list, technical and organisational measures, and any third-party audit reports or certifications Perkstar holds; and
  3. where the information made available under (1) and (2) is insufficient, and on at least 30 days' notice, an on-site or remote audit conducted during business hours, in a manner that does not unreasonably interfere with Perkstar's operations and that respects the confidentiality of other Perkstar customers.

Each party bears its own costs in connection with an audit, except that the Operator will reimburse Perkstar's reasonable costs for any audit beyond the standard annual cadence.

Audit requests should be sent to privacy@perkstar.co.uk.

14. Liability

Each party's liability arising out of or in connection with this DPA is subject to and forms part of the limitations and exclusions of liability set out in our Terms of Service. Nothing in this DPA excludes or limits liability where it cannot be excluded or limited by law.

15. Order of precedence

In the event of a conflict between this DPA and any other agreement between the parties, the following order of precedence applies in respect of the subject matter of this DPA: (1) any applicable UK International Data Transfer Agreement or EU Standard Contractual Clauses with UK Addendum; (2) this DPA; (3) the Terms of Service; (4) any other agreement.

16. Governing law and jurisdiction

This DPA is governed by the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales, except that the Operator may bring proceedings in any jurisdiction where it is required to do so by Applicable Data Protection Law.

17. Changes to this DPA

Perkstar may update this DPA from time to time to reflect changes in Applicable Data Protection Law or in the Services. Material changes will be notified to the Operator at least 30 days in advance by email and through an in-app announcement, and the Operator will be required to accept the updated version on next sign-in. Non-material changes (clarifications, formatting, link updates) take effect on publication.

18. Contact

For any matter relating to this DPA, including audit requests, Data Subject assistance, breach notification follow-up, or sub-processor change notifications by email, contact us at privacy@perkstar.co.uk.


Schedule 1 — Sub-processors

The current Sub-processor list is maintained at https://dashboard.perkstar.co.uk/dpa/sub-processors and is incorporated into this DPA. As at the effective date, the Sub-processors of Customer Personal Data are:

EEA-resident — no cross-border transfer mechanism required

  • Supabase (Supabase Inc.) — database, authentication — Ireland (AWS eu-west-1)
  • Vercel (Vercel Inc.) — platform hosting, SSR — Frankfurt (fra1)
  • Resend (Resend, Inc.) — email delivery — Ireland
  • Upstash (Upstash Inc.) — Redis rate limiting — Ireland

Outside the UK and EEA — covered by UK IDTA or EU SCCs + UK Addendum where required

  • Stripe (Stripe, Inc.) — subscription billing, Stripe Connect, identity verification, checkout and payment metadata — United States / global infrastructure
  • Apple (Apple Inc.) — Apple Wallet pass distribution and wallet push services — United States / global infrastructure
  • Google (Google LLC) — Google Wallet pass distribution, Google Places address lookup where enabled, and Google Analytics measurement only where the Operator configures it and the Cardholder consents — United States / global infrastructure
  • Telnyx (Telnyx LLC) — SMS delivery — United States / global telecom routing
  • Inngest (Inngest Inc.) — background job queue — United States
  • Operator-enabled POS, booking, delivery and marketplace integration partners — varies by partner and only applies where the Operator connects that integration. Current or active integration surfaces include Square, Shopify, Toast, Lightspeed, Clover, Acuity Scheduling, Mindbody, Deliveroo, Dojo, EPOS Now, Access EPoS, MX POS, Poynt and NCR Aloha Cloud.

The live page also lists service providers that are not Sub-processors of Customer Personal Data (Anthropic for operator-facing AI copywriting features, Sentry for error monitoring with PII scrubbing, and operator-configured advertising recipients such as Meta or TikTok where they act on the Operator's own instructions).

Schedule 2 — Technical and organisational measures

Perkstar maintains the following measures, reviewed at least annually.

Encryption

  • All Customer Personal Data is encrypted at rest. The database provider applies PostgreSQL transparent disk encryption; OAuth tokens and integration secrets are additionally encrypted at the application layer using AES-256-GCM.
  • All data in transit is protected by TLS 1.2 or higher, with weak ciphers disabled.

Access control

  • Role-based access controls within the Services across three roles (Owner, Manager, Staff), with per-action permission gates applied at every write site.
  • Multi-factor authentication is available to every Operator on every plan via time-based one-time password (TOTP) enrolment. Mandatory MFA enforcement may be enabled by Perkstar on individual high-risk Operator accounts as a tightening measure in response to a security incident or risk finding; in that case, Operator users without an enrolled factor are blocked from the dashboard until they enrol one.
  • Multi-factor authentication is required for all Perkstar staff with access to production systems.
  • All administrative actions on Operator accounts are recorded in an operator-facing audit log; all Perkstar staff actions are recorded in a separate platform audit log.

Token security

  • Claim, opt-in, and data-export tokens are stored as SHA-256 hashes in the database; the raw token travels only through the Cardholder's signed link.
  • API keys and OAuth access tokens are hashed at rest.
  • Wallet pass back-of-card links use HMAC-SHA256 signatures verified statelessly on every request, with a 90-day rolling time-to-live and re-mint on every pass refresh.

Tenant isolation

  • Per-organisation tenant isolation is enforced at every query boundary; no shared data collections between Operators.

Resilience and backups

  • Daily automated backups of production data, retained on a rolling 7-day basis through our database provider (Supabase Pro).
  • Documented disaster recovery procedure with backup recovery exercised at least quarterly.

Operational security

  • Vulnerability monitoring on dependencies; security patches applied on a risk-based schedule.
  • Production access limited to a defined group of authorised personnel, with access reviewed at least quarterly.
  • Background checks on personnel with access to production systems, where permitted by law.
  • PII scrubbing in error monitoring: a Sentry beforeSend hook strips email, phone, IP, postcode, date of birth, names, and Stripe identifiers, recursively sweeps event extras and contexts, and redacts breadcrumbs before any event reaches the monitoring ingest.
  • Rate limiting on public endpoints via Upstash Redis; API-key idempotency cache.

Communications integrity

  • Every outbound and inbound email is recorded with direction, category (transactional, marketing, operational), provider message ID, and delivery status.
  • Bounce and complaint handling: provider webhooks automatically suppress the affected address, recorded in the platform's privacy timeline. Suppressed addresses are skipped on subsequent sends.
  • A List-Unsubscribe header is included on every marketing email, pointing to the platform's unsubscribe endpoint.
  • Transactional messages bypass marketing-consent checks on a legitimate-interest basis; marketing messages require explicit consent on the relevant channel.

Webhook delivery audit

  • Every signed outbound webhook is recorded with attempt count, response status, and response body hash. Retries follow a 1-minute / 5-minute / 30-minute schedule, then move to an exhausted state.

Incident response

  • Documented Personal Data Breach response procedure.
  • Notification to the Operator within 72 hours of awareness in accordance with clause 10.

Governance

  • Annual review of this Schedule and of the wider information security programme.
  • Sub-processors assessed for adequate data protection commitments before engagement.

Test mode

  • Operators may flag any transaction or enrolment as test data. Test data is excluded by default from every dashboard chart, customer export, and audit timeline.

Questions, audit requests or due-diligence requests: privacy@perkstar.co.uk. Operators can also use the Compliance area in the admin dashboard to review evidence links, vendor records and data-protection controls maintained by Perkstar.

Questions? Email hello@perkstar.co.uk.