Data Processing Agreement (DPA)
Last updated: 28 August 2026
This Data Processing Agreement is entered into between each business subscriber (the "Controller") and Garmel (the "Processor", "Garmel") pursuant to Article 28 GDPR. It is accepted at business sign-up and forms part of the Business Subscriber Agreement.
1. Subject matter & duration
The Processor processes personal data on behalf of the Controller to provide the Garmel loyalty platform, for the duration of the subscription plus the 30-day post-cancellation retention window.
2. Nature & purpose of processing
Hosting, storage, and processing of loyalty program data: account management, points and reward tracking, membership billing, consent-based marketing delivery (email/push/SMS), automated program messages (birthday, win-back), analytics shown to the Controller, and security functions.
3. Categories of data & data subjects
- Data subjects: the Controller's customers and staff.
- Personal data: name, email address, phone number (optional), date of birth (optional), hashed credentials, visit and transaction history, points balance, reward redemptions, marketing preferences and consent timestamps, device push tokens.
- No special categories of data are intentionally processed.
4. Processor obligations
- Process personal data only on the Controller's documented instructions (including as configured in the dashboard).
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational measures: TLS in transit, encryption at rest, row-level security isolation per business, audit logging, rate limiting, and access controls.
- Assist the Controller with data subject rights requests (export and deletion tooling is built into the platform).
- Notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data.
- Delete or return all personal data at the end of the engagement (30-day export window, then deletion, save for legally required records).
- Make available information necessary to demonstrate compliance and allow audits as set out in §6.
5. Sub-processors
The Controller gives general authorisation to the following sub-processors. The Processor will give at least 30 days' notice before adding or replacing a sub-processor, during which the Controller may object on reasonable data protection grounds.
| Sub-processor | Function |
|---|---|
| Supabase | Database, authentication, storage |
| Stripe | Payments & payouts (Stripe Connect) |
| Firebase (Google) | Push notifications |
| Resend | Email delivery |
| Inngest | Background job processing |
| OpenAI | AI onboarding extraction |
| Firecrawl | Website content extraction at onboarding |
| Upstash | Rate limiting (Redis) |
| Sentry | Error monitoring |
| Netlify | Hosting |
6. Audit rights
Upon reasonable written notice (no more than once per year, unless required by a supervisory authority or following a breach), the Controller may audit the Processor's compliance with this DPA. The Processor may first satisfy the audit by providing current third-party certifications, sub-processor DPAs, and documentation of its security measures.
7. International transfers
Where a sub-processor processes data outside the EU/EEA, the transfer is protected by EU Standard Contractual Clauses or an adequacy decision.
8. Liability & governing law
Liability under this DPA follows the cap in the Business Subscriber Agreement. Governing law and jurisdiction follow the Terms of Service.
9. Contact
Data protection contact: [email protected] · Garmel