3. Data Processing Agreement (DPA)
3.1 Scope
This Data Processing Agreement (“DPA”) forms part of the agreement between THYNKR SYSTEMS LTD (“Processor”, “THYNKR”) and the customer using PalletPOS or Pallet Back Office (“Controller”, “Customer”) where THYNKR processes Personal Data on the Customer’s behalf.
This DPA applies to processing subject to the UK GDPR, Data Protection Act 2018 and, where applicable, other data-protection legislation including the EU GDPR.
Capitalised terms not defined here have the meanings given in the main Agreement or applicable Data Protection Law.
3.2 Roles
The Customer is the Controller of Customer Personal Data where it determines the purposes and means of processing.
THYNKR is the Processor when it processes that data solely on the Customer’s documented instructions to provide the Services.
THYNKR may separately act as Controller for limited processing undertaken for its own legitimate purposes, such as account administration, billing, fraud prevention, platform security, legal compliance and establishment or defence of claims. Such controller processing is governed by THYNKR’s Privacy Policy.
3.3 Details of Processing
Subject matter
Provision, operation, maintenance, support and security of PalletPOS, Pallet Back Office and associated business technology services.
Duration
For the duration of the Agreement and any lawful retention or transition period thereafter.
Nature and purpose
Collection, storage, organisation, retrieval, transmission, hosting, analysis, support, deletion and other processing necessary to provide the contracted Services.
Categories of data subjects
May include:
- the Customer’s customers and prospective customers;
- the Customer’s staff and authorised users;
- Customer administrators;
- loyalty or account customers;
- suppliers and business contacts recorded by the Customer; and
- other individuals whose data the Customer lawfully submits.
Types of Personal Data
May include:
- names;
- contact details;
- addresses;
- account identifiers;
- staff details;
- roles and permissions;
- transaction references;
- purchase history;
- invoices and statements;
- balances, credit limits and payment terms;
- customer communications;
- device and technical identifiers;
- IP addresses;
- audit logs;
- loyalty information; and
- other Personal Data submitted through configured fields.
Special-category data
The Services are not designed as a general repository for special-category data. The Customer should not submit such data unless it has a lawful basis and the Services are appropriate for that processing.
3.4 Controller Instructions
THYNKR will process Customer Personal Data only:
- on documented instructions from the Customer, including instructions embodied in the Agreement and use of configured Service features; or
- where processing is required by applicable law.
If law requires processing outside the Customer’s instructions, THYNKR will inform the Customer before processing unless law prohibits that notice.
THYNKR will inform the Customer if, in THYNKR’s reasonable opinion, an instruction infringes applicable Data Protection Law and may suspend the affected processing while the issue is addressed.
3.5 Confidentiality
THYNKR will ensure that personnel authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality.
3.6 Security
Taking into account the state of the art, implementation costs, nature, scope, context and purposes of processing and risks to individuals, THYNKR will maintain appropriate technical and organisational measures.
Measures may include, as appropriate:
- encryption in transit;
- encryption at rest where appropriate;
- access control and least privilege;
- authentication controls;
- logical tenant separation;
- secure development practices;
- logging and monitoring;
- backup and restoration procedures;
- vulnerability and patch management;
- incident-response procedures;
- resilience and recovery controls; and
- periodic review of security effectiveness.
Security controls may evolve as technology and threats change, provided THYNKR does not materially reduce the overall protection of Customer Personal Data.
3.7 Subprocessors
The Customer grants THYNKR general written authorisation to engage subprocessors necessary to provide the Services.
THYNKR will:
- maintain information about material subprocessors;
- impose written data-protection obligations appropriate to the processing and consistent with applicable Article 28 requirements;
- remain responsible to the Customer for performance of applicable subprocessor obligations to the extent required by law; and
- provide reasonable notice of a new material subprocessor through a published notice, account notification, email or another reasonable mechanism.
The Customer may object to a new subprocessor on reasonable data-protection grounds by notifying THYNKR within 14 days of receiving notice.
The parties will work in good faith to address a valid objection. If no commercially reasonable solution is available, either party may terminate the materially affected Service without penalty for the unused prepaid period relating to that Service.
An objection does not create a right to dictate THYNKR’s technology architecture or require THYNKR to provide a materially different service at no additional cost.
3.8 Data Subject Requests
Taking into account the nature of processing, THYNKR will provide reasonable assistance to enable the Customer to respond to requests from Data Subjects exercising rights under applicable Data Protection Law.
If THYNKR receives a request relating to Customer Personal Data for which the Customer is Controller, THYNKR may direct the Data Subject to the Customer unless law requires THYNKR to respond directly.
3.9 Compliance Assistance
Taking into account the nature of processing and information available to THYNKR, THYNKR will provide reasonable assistance with:
- security obligations;
- Personal Data breach assessment and notification;
- data-protection impact assessments;
- prior consultation with regulators where required; and
- other obligations under Articles 32–36 or equivalent provisions.
Where assistance materially exceeds standard product functionality or information reasonably available from THYNKR, reasonable professional-services fees may apply where legally permitted and agreed in advance.
3.10 Personal Data Breaches
THYNKR will notify the Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
The notification will provide information reasonably available to THYNKR, which may include:
- the nature of the incident;
- affected data or individuals where known;
- likely consequences where known;
- measures taken or proposed; and
- a contact point for further information.
Information may be provided in phases as an investigation continues.
Notification of an incident is not an admission of fault or liability.
The Customer remains responsible for determining whether it must notify a regulator or affected Data Subjects unless applicable law provides otherwise.
3.11 Deletion and Return
Upon termination or expiry of the affected Service, THYNKR will, at the Customer’s choice and subject to available product functionality, return or delete Customer Personal Data within a reasonable period unless:
- applicable law requires retention;
- the data is contained in secure backups that cannot reasonably be isolated immediately; or
- retention is required for establishment, exercise or defence of legal claims.
Data retained in backup systems will remain protected and will be deleted or overwritten according to ordinary secure backup-retention cycles.
3.12 Audits and Information Rights
THYNKR will make available information reasonably necessary to demonstrate compliance with applicable Article 28 obligations.
Where appropriate, THYNKR may satisfy audit requests by providing current third-party audit reports, certifications, security documentation, questionnaires or other suitable evidence.
If an additional audit is reasonably required:
- the Customer must provide at least 30 days’ written notice unless a regulator or confirmed material incident reasonably requires shorter notice;
- audits must occur during normal business hours;
- audits must not unreasonably disrupt operations;
- the auditor must be independent and bound by confidentiality;
- the audit must avoid access to other customers’ data or THYNKR trade secrets beyond what is reasonably necessary;
- no more than one Customer-requested audit may take place in a twelve-month period unless required by law or following a material breach; and
- the Customer bears its audit costs and THYNKR’s reasonable costs of supporting non-routine audits, except where the audit identifies a material breach by THYNKR.
Nothing in this clause limits a regulator’s lawful powers.
3.13 International Transfers
THYNKR will not make a restricted transfer of Customer Personal Data unless an applicable lawful transfer mechanism is in place.
Where required, the parties will use an appropriate mechanism, which may include:
- the UK International Data Transfer Agreement;
- the UK Addendum to EU Standard Contractual Clauses;
- applicable Standard Contractual Clauses;
- adequacy arrangements; or
- another legally recognised safeguard.
The parties will cooperate with any legally required transfer-risk or supplementary-measures assessment.
3.14 Government Requests
Unless prohibited by law, THYNKR will seek to direct a governmental request for Customer Personal Data to the Customer where appropriate.
Where THYNKR must respond directly, it will disclose only information legally required and may challenge an overbroad or unlawful demand where reasonable and lawful.
3.15 Controller Obligations
The Customer warrants that:
- it has a lawful basis for processing Customer Personal Data;
- it provides required privacy information;
- it obtains required consents where consent is relied upon;
- its instructions comply with Data Protection Law;
- it will not submit Personal Data that the Services are not designed to process without prior agreement;
- it will use appropriate account-security controls; and
- it will respond to Data Subject requests and regulator communications for which it is Controller.
3.16 Liability
Liability under this DPA is subject to the liability provisions of the Agreement except where applicable Data Protection Law prohibits contractual limitation.
Nothing in this DPA relieves either party of direct statutory obligations imposed on it by Data Protection Law.
3.17 Priority
If this DPA conflicts with the Agreement concerning processing of Customer Personal Data, this DPA takes priority for that subject matter.
Where mandatory transfer clauses apply, those clauses take priority to the extent required by law.
3.18 Changes in Data Protection Law
The parties will cooperate in good faith to amend this DPA where reasonably necessary to comply with a material change in applicable Data Protection Law or binding regulatory requirements.
