Garmel
How it worksPricingContactSign inStart free

Data Processing Agreement (DPA)

Last updated: 28 August 2026

This Data Processing Agreement is entered into between each business subscriber (the "Controller") and Garmel (the "Processor", "Garmel") pursuant to Article 28 GDPR. It is accepted at business sign-up and forms part of the Business Subscriber Agreement.

1. Subject matter & duration

The Processor processes personal data on behalf of the Controller to provide the Garmel loyalty platform, for the duration of the subscription plus the 30-day post-cancellation retention window.

2. Nature & purpose of processing

Hosting, storage, and processing of loyalty program data: account management, points and reward tracking, membership billing, consent-based marketing delivery (email/push/SMS), automated program messages (birthday, win-back), analytics shown to the Controller, and security functions.

3. Categories of data & data subjects

  • Data subjects: the Controller's customers and staff.
  • Personal data: name, email address, phone number (optional), date of birth (optional), hashed credentials, visit and transaction history, points balance, reward redemptions, marketing preferences and consent timestamps, device push tokens.
  • No special categories of data are intentionally processed.

4. Processor obligations

  • Process personal data only on the Controller's documented instructions (including as configured in the dashboard).
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Implement appropriate technical and organisational measures: TLS in transit, encryption at rest, row-level security isolation per business, audit logging, rate limiting, and access controls.
  • Assist the Controller with data subject rights requests (export and deletion tooling is built into the platform).
  • Notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data.
  • Delete or return all personal data at the end of the engagement (30-day export window, then deletion, save for legally required records).
  • Make available information necessary to demonstrate compliance and allow audits as set out in §6.

5. Sub-processors

The Controller gives general authorisation to the following sub-processors. The Processor will give at least 30 days' notice before adding or replacing a sub-processor, during which the Controller may object on reasonable data protection grounds.

Sub-processorFunction
SupabaseDatabase, authentication, storage
StripePayments & payouts (Stripe Connect)
Firebase (Google)Push notifications
ResendEmail delivery
InngestBackground job processing
OpenAIAI onboarding extraction
FirecrawlWebsite content extraction at onboarding
UpstashRate limiting (Redis)
SentryError monitoring
NetlifyHosting

6. Audit rights

Upon reasonable written notice (no more than once per year, unless required by a supervisory authority or following a breach), the Controller may audit the Processor's compliance with this DPA. The Processor may first satisfy the audit by providing current third-party certifications, sub-processor DPAs, and documentation of its security measures.

7. International transfers

Where a sub-processor processes data outside the EU/EEA, the transfer is protected by EU Standard Contractual Clauses or an adequacy decision.

8. Liability & governing law

Liability under this DPA follows the cap in the Business Subscriber Agreement. Governing law and jurisdiction follow the Terms of Service.

9. Contact

Data protection contact: [email protected] · Garmel

Garmel

Your shop, your app, your name. White-label loyalty for barbers, salons, gyms & small shops.

Product

  • How it works
  • Pricing
  • Contact
  • Sign in
  • Start free trial

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Refund Policy
  • Subscriber Agreement
  • Data Processing Agreement
  • Acceptable Use Policy
© 2026 Garmel · Your shop, your app, your name.