Data Processing Agreement
Between
Unity Systems Ltd (“Processor”)
and
Merchant / Business Client (“Controller”)
1. Parties & Roles
1.1 Unity Systems Ltd, registered at 4–8 Ludgate Circus, London, EC4M 7LF, United Kingdom, acts as the Data Processor.
1.2 The Merchant that creates an account on the Unity loyalty platform acts as the Data Controller.
1.3 This DPA governs how Unity processes personal data on behalf of the Merchant within the loyalty platform.
2. Definitions
- “UK GDPR” – The retained EU law version of the General Data Protection Regulation.
- “Controller” – The party determining the purpose and means of processing personal data.
- “Processor” – The party processing personal data on behalf of the Controller.
- “Data Subject” – Loyalty customers whose data is processed.
- “Personal Data” – Any information relating to an identified or identifiable natural person.
- “Processing” – Any action performed on data (collection, storage, deletion, etc.).
- “Sub-processor” – A third party engaged by the Processor.
3. Subject Matter of Processing
Unity processes personal data to operate the loyalty card platform for the Merchant, including:
- Registering customer accounts
- Storing and managing loyalty cards
- Point issuance, tracking, and redemption
- Sending account notifications (email/SMS/push)
- Providing a merchant portal with customer insights
- Fraud prevention and lawful operation of the system
4. Types of Data Processed
Unity processes the following Customer Personal Data, as provided by users:
- Full name
- Email address
- Phone number
- Date of birth
- Loyalty card ID
- Points earned, redeemed, and transaction history
- Purchase categories (e.g., coffee, pastry, etc.)
- Time and date of customer visits/purchases
- Marketing preferences (opt-in/out)
- Apple Wallet push delivery status (no GPS data collected)
Unity does not process:
❌ Payment card data
❌ Browser tracking
❌ GPS or real-time location data
5. Duration of Processing
Unity will process the data:
- For as long as the Merchant uses the Unity loyalty platform
- Until the Merchant requests deletion
- Or until the user requests account deletion
Unity may retain minimal audit logs for legal compliance.
6. Processor Obligations (Unity Systems Ltd)
Unity agrees to:
6.1 Process Data Only on Controller Instructions
Unity will only process data based on instructions from the Merchant, including:
- Registering customers
- Allocating or redeeming points
- Sending allowed notifications
- Displaying customer analytics
Unity will never use data for its own purposes.
6.2 Ensure Confidentiality
Unity ensures all employees are subject to appropriate confidentiality obligations.
6.3 Implement Security Measures
Unity maintains technical and organisational measures, such as:
- Encrypted data storage
- Encrypted transmission (TLS/SSL)
- Access control and logging
- Regular security audits
- Password hashing
- Data minimisation by design
6.4 Assist the Controller With Data Subject Rights
Unity will support the Merchant with:
- Access requests
- Correction requests
- Deletion requests
- Data portability
- Objection to processing
- Marketing opt-out controls
A user-facing Delete Account button is provided where requested.
6.5 Notify Data Breaches
Unity will notify the Merchant without undue delay if any personal data breach occurs and provide all necessary details.
7. Controller Obligations (Merchant)
The Merchant agrees to:
- Determine lawful basis for processing (usually consent or legitimate interest)
- Provide legally compliant privacy notices to customers
- Collect and manage marketing consent
- Ensure only authorised staff access the merchant portal
- Respond to user rights requests
- Not upload data they are not legally allowed to process
- Not misuse Unity’s systems for unsolicited marketing
Merchants are responsible for informing their customers about loyalty data usage.
8. Sub-Processors
Unity may use third-party sub-processors for hosting, delivery or support services, such as:
- Cloud hosting providers (UK/EU based)
- Email/SMS delivery services
- Security and analytics infrastructure
Unity will maintain an up-to-date list of sub-processors upon request.
Unity ensures all sub-processors operate under written agreements with GDPR-level protections.
9. International Transfers
Unity stores data primarily within the UK/EU.
If any data is transferred outside the UK, Unity will ensure:
- Adequacy regulations apply, or
- Transfer is protected by approved safeguards (SCCs, IDTAs)
No data will be transferred without appropriate legal protection.
10. Data Retention & Deletion
Unity will:
- Retain customer data as long as the account is active
- Delete or anonymise data upon request by the Merchant or Data Subject
- Provide options for automated expiry if required
- Retain minimal logs only where required by UK law
Upon termination of the Merchant’s agreement:
- Unity will delete all merchant customer data within 30 days, unless otherwise required by law.
11. Audits
Unity will provide:
- Security documentation
- Compliance summaries
- Responses to reasonable audit requests
Formal in-person audits may be requested once per year, subject to reasonable limits.
12. Liability
Each party’s liability is governed by the main Merchant Agreement.
Unity is not liable for:
- Merchant misuse of data
- Merchant marketing sent without user consent
- Incorrect point calculations set by the Merchant
- Merchant-initiated customer communications
13. Termination
This DPA automatically terminates when:
- The Merchant stops using Unity’s services
- All data is deleted
- All outstanding issues are resolved
Unity will certify deletion upon request.
14. Governing Law
This DPA is governed by:
- UK GDPR
- Data Protection Act 2018
- Laws of England and Wales
Any disputes will be handled under English jurisdiction.
15. Contact Information
Data Protection Contact:
📧 security@unity-loyalty.co.uk
Legal Contact:
📧 law@unity-loyalty.co.uk
Postal:
Unity Systems Ltd
4–8 Ludgate Circus, London, EC4M 7LF
Download as Word document