Data Processing Agreement
Our commitment to GDPR compliance and data protection for business partners.
1. Introduction
This Data Processing Agreement (“DPA”) forms part of the service agreement between ReceiptBranch and its partners/customers regarding the processing of personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Definitions
For the purposes of this DPA:
- Controller: the partner who determines the purposes and means of processing
- Processor: ReceiptBranch, processing personal data on behalf of the Controller
- Personal data: any information relating to an identified or identifiable person
- Processing: any operation performed on personal data
- Data subject: the individual whose personal data is processed
3. Processing activities
ReceiptBranch processes personal data for the following purposes:
- Providing digital receipt services
- Managing loyalty programs and rewards
- Processing transactions and payments
- Customer support and communication
- Analytics and service improvement
- Compliance with legal obligations
4. Categories of personal data
We may process the following categories of personal data:
- Contact information (name, email, phone number)
- Transaction data (purchase history, receipts)
- Device information (device ID, app usage data)
- Location data, where explicitly consented
- Loyalty programme data (points, rewards, preferences)
5. Security measures
ReceiptBranch implements appropriate technical and organizational measures:
- Encryption of data in transit and at rest
- Regular security assessments and penetration testing
- Access controls and authentication mechanisms
- Staff training on data protection principles
- Incident response and breach notification procedures
- Regular backup and disaster recovery testing
6. Data subject rights
ReceiptBranch will assist the Controller in fulfilling data subject rights:
- Right of access to personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
7. Data transfers
Personal data is processed within the European Economic Area (EEA). Any transfers outside the EEA will be subject to appropriate safeguards, including Standard Contractual Clauses or adequacy decisions by the European Commission.
8. Data retention
Personal data will be retained only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Upon termination of services, data will be securely deleted or returned as instructed by the Controller.
9. Breach notification
ReceiptBranch will notify the Controller without undue delay (within 24 hours where feasible) upon becoming aware of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects.
Contact information
For questions about this agreement or data protection matters:
Data Protection Officer: dpo@receiptbranch.com
Privacy team: privacy@receiptbranch.com
Address: Suite B Fairgate House, 205 Kings Road, Birmingham, B11 2AA
Last updated: January 2024