Skip to content

Data Processing Agreement

Our commitment to GDPR compliance and data protection for business partners.

1. Introduction

This Data Processing Agreement (“DPA”) forms part of the service agreement between ReceiptBranch and its partners/customers regarding the processing of personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

2. Definitions

For the purposes of this DPA:

  • Controller: the partner who determines the purposes and means of processing
  • Processor: ReceiptBranch, processing personal data on behalf of the Controller
  • Personal data: any information relating to an identified or identifiable person
  • Processing: any operation performed on personal data
  • Data subject: the individual whose personal data is processed

3. Processing activities

ReceiptBranch processes personal data for the following purposes:

  • Providing digital receipt services
  • Managing loyalty programs and rewards
  • Processing transactions and payments
  • Customer support and communication
  • Analytics and service improvement
  • Compliance with legal obligations

4. Categories of personal data

We may process the following categories of personal data:

  • Contact information (name, email, phone number)
  • Transaction data (purchase history, receipts)
  • Device information (device ID, app usage data)
  • Location data, where explicitly consented
  • Loyalty programme data (points, rewards, preferences)

5. Security measures

ReceiptBranch implements appropriate technical and organizational measures:

  • Encryption of data in transit and at rest
  • Regular security assessments and penetration testing
  • Access controls and authentication mechanisms
  • Staff training on data protection principles
  • Incident response and breach notification procedures
  • Regular backup and disaster recovery testing

6. Data subject rights

ReceiptBranch will assist the Controller in fulfilling data subject rights:

  • Right of access to personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing

7. Data transfers

Personal data is processed within the European Economic Area (EEA). Any transfers outside the EEA will be subject to appropriate safeguards, including Standard Contractual Clauses or adequacy decisions by the European Commission.

8. Data retention

Personal data will be retained only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Upon termination of services, data will be securely deleted or returned as instructed by the Controller.

9. Breach notification

ReceiptBranch will notify the Controller without undue delay (within 24 hours where feasible) upon becoming aware of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects.

Contact information

For questions about this agreement or data protection matters:

Data Protection Officer: dpo@receiptbranch.com

Privacy team: privacy@receiptbranch.com

Address: Suite B Fairgate House, 205 Kings Road, Birmingham, B11 2AA

Last updated: January 2024