Data Processing Agreement

Last updated on 7 Oct 2026

This Data Processing Agreement (“Agreement”) forms part of the Contract for Services (“Principal Agreement”) between your company (the “Company”) and Jemcode International Limited t/a Leal (the “Data Processor”) (together as the “Parties”).

Whereas

(A) The Company acts as a Data Controller.

(B) The Company wishes to subcontract certain Services, which imply the processing of personal data, to the Data Processor.

(C) The Parties seek to implement a data processing agreement that complies with the requirements of the current legal framework in relation to data processing and with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).

(D) The Parties wish to lay down their rights and obligations.

It is agreed as follows:

1. Definitions and Interpretation

1.1 Unless otherwise defined herein, capitalized terms and expressions used in this Agreement shall have the following meaning:

1.1.1 “Agreement” means this Data Processing Agreement and all Schedules;

1.1.2 “Company Personal Data” means any Personal Data Processed by a Contracted Processor on behalf of Company pursuant to or in connection with the Principal Agreement;

1.1.3 “Contracted Processor” means the Processor or a Subprocessor;

1.1.4 “Data Protection Laws” means EU Data Protection Laws and, to the extent applicable, the data protection or privacy laws of any other country, including the UK GDPR and the UK Data Protection Act 2018;

1.1.5 “EEA” means the European Economic Area;

1.1.6 “EU Data Protection Laws” means the GDPR and laws implementing or supplementing the GDPR, including the Irish Data Protection Acts 1988 to 2018;

1.1.7 “GDPR” means EU General Data Protection Regulation 2016/679;

1.1.8 “Data Transfer” means:

1.1.8.1 a transfer of Company Personal Data from the Company to a Contracted Processor; or

1.1.8.2 an onward transfer of Company Personal Data from a Contracted Processor to a Subcontracted Processor, or between two establishments of a Contracted Processor, in each case, where such transfer would be prohibited by Data Protection Laws (or by the terms of data transfer agreements put in place to address the data transfer restrictions of Data Protection Laws);

1.1.9 “Services” means the Leal digital loyalty programme services the Data Processor provides to the Company under the Principal Agreement, including loyalty cards, Apple Wallet and Google Wallet passes, customer sign-up forms and posters, stamps, rewards and redemptions, customer notifications, analytics, integrations, webhooks and the API;

1.1.10 “Subprocessor” means any person appointed by or on behalf of Processor to process Personal Data on behalf of the Company in connection with the Agreement;

1.1.11 “Processor” means the Data Processor; and

1.1.12 “Applicable Laws” means Data Protection Laws and any other law of the European Union, a Member State or Ireland to which the Processor is subject.

1.2 The terms, “Commission”, “Controller”, “Data Subject”, “Member State”, “Personal Data”, “Personal Data Breach”, “Processing” and “Supervisory Authority” shall have the same meaning as in the GDPR, and their cognate terms shall be construed accordingly.

2. Processing of Company Personal Data

2.1 Processor shall:

2.1.1 comply with all applicable Data Protection Laws in the Processing of Company Personal Data; and

2.1.2 not Process Company Personal Data other than on the relevant Company’s documented instructions.

2.2 The Company instructs Processor to process Company Personal Data to provide the Services, as described in Annex 1, and as the Company otherwise directs through its use of the Services (for example by importing or exporting customers, sending notifications, or connecting an integration or webhook).

2.3 The subject matter, nature, purpose and duration of the Processing, and the types of Personal Data and categories of Data Subjects, are set out in Annex 1.

3. Processor Personnel

Processor shall take reasonable steps to ensure the reliability of any employee, agent or contractor of any Contracted Processor who may have access to the Company Personal Data, ensuring in each case that access is strictly limited to those individuals who need to know / access the relevant Company Personal Data, as strictly necessary for the purposes of the Principal Agreement, and to comply with Applicable Laws in the context of that individual’s duties to the Contracted Processor, ensuring that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality.

4. Security

4.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Processor shall in relation to the Company Personal Data implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk, including, as appropriate, the measures referred to in Article 32(1) of the GDPR.

4.2 In assessing the appropriate level of security, Processor shall take account in particular of the risks that are presented by Processing, in particular from a Personal Data Breach.

5. Subprocessing

5.1 The Company gives Processor general written authorisation to appoint Subprocessors. The Subprocessors in use are listed in Annex 2, and the Company authorises their appointment.

5.2 Processor shall give the Company notice of any intended addition or replacement of a Subprocessor at least 14 days before it begins Processing Company Personal Data, by updating Annex 2 and emailing the Company. The Company may object on reasonable data protection grounds within that period, in which case the Parties will discuss the objection in good faith. If it cannot be resolved, the Company may terminate the Services it affects.

5.3 Processor shall impose data protection obligations on each Subprocessor, by written contract, that are no less protective than those in this Agreement, and remains responsible to the Company for each Subprocessor’s performance of those obligations.

5.4 Services the Company itself connects to Leal, such as its own email or SMS provider, point-of-sale or e-commerce platform, Zapier, or a webhook endpoint, are not Subprocessors of the Processor. Data sent to them is sent on the Company’s instruction.

6. Data Subject Rights

6.1 Taking into account the nature of the Processing, Processor shall assist the Company by implementing appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Company obligations, as reasonably understood by Company, to respond to requests to exercise Data Subject rights under the Data Protection Laws.

6.2 Processor shall:

6.2.1 promptly notify Company if it receives a request from a Data Subject under any Data Protection Law in respect of Company Personal Data; and

6.2.2 ensure that it does not respond to that request except on the documented instructions of Company or as required by Applicable Laws to which the Processor is subject, in which case Processor shall to the extent permitted by Applicable Laws inform Company of that legal requirement before the Contracted Processor responds to the request.

7. Personal Data Breach

7.1 Processor shall notify Company without undue delay upon Processor becoming aware of a Personal Data Breach affecting Company Personal Data, providing Company with sufficient information to allow the Company to meet any obligations to report or inform Data Subjects of the Personal Data Breach under the Data Protection Laws.

7.2 Processor shall co-operate with the Company and take reasonable commercial steps as are directed by Company to assist in the investigation, mitigation and remediation of each such Personal Data Breach.

8. Data Protection Impact Assessment and Prior Consultation

8.1 Processor shall provide reasonable assistance to the Company with any data protection impact assessments, and prior consultations with Supervising Authorities or other competent data privacy authorities, which Company reasonably considers to be required by article 35 or 36 of the GDPR or equivalent provisions of any other Data Protection Law, in each case solely in relation to Processing of Company Personal Data by, and taking into account the nature of the Processing and information available to, the Contracted Processors.

9. Deletion or return of Company Personal Data

9.1 The Company can export its customers, with their stamps and rewards, from the Services at any time, including before closing its account. On request, Processor shall provide a copy of Company Personal Data in a commonly used, machine-readable format.

9.2 Cancelling a paid plan does not by itself delete Company Personal Data. The Services end, for the purposes of this section, when the Company deletes its Leal account (the “Cessation Date”).

9.3 Subject to this section 9, Processor shall promptly and in any event within 10 business days of the Cessation Date delete and procure the deletion of all copies of those Company Personal Data from its live systems and those of its Subprocessors.

9.4 Copies held in encrypted backups are deleted as those backups expire, within 30 days of the Cessation Date. Until then they are kept secure and are not used for any other Processing.

9.5 Processor may retain Company Personal Data only to the extent and for as long as Applicable Laws require, and shall keep it confidential and Process it only for the purpose for which those laws require it to be kept.

9.6 Individual customer records the Company deletes while its account remains open are deleted from live systems straight away and from backups within 30 days.

10. Audit rights

10.1 Subject to this section 10, Processor shall make available to the Company on request all information necessary to demonstrate compliance with this Agreement, and shall allow for and contribute to audits, including inspections, by the Company or an auditor mandated by the Company in relation to the Processing of the Company Personal Data by the Contracted Processors.

10.2 Information and audit rights of the Company only arise under section 10.1 to the extent that the Agreement does not otherwise give them information and audit rights meeting the relevant requirements of Data Protection Law.

11. Data Transfer

11.1 Company Personal Data is hosted in the EEA. Some Subprocessors listed in Annex 2 may process it outside the EEA, and the Company authorises those transfers.

11.2 Processor shall only transfer Company Personal Data outside the EEA, or authorise such a transfer, where it is protected by an adequacy decision of the European Commission (including the EU-US Data Privacy Framework, where the recipient is certified) or by the European Commission’s standard contractual clauses or another safeguard permitted by Article 46 of the GDPR.

12. General Terms

12.1 Confidentiality. Each Party must keep this Agreement and information it receives about the other Party and its business in connection with this Agreement (“Confidential Information”) confidential and must not use or disclose that Confidential Information without the prior written consent of the other Party except to the extent that: (a) disclosure is required by law; (b) the relevant information is already in the public domain.

12.2 Notices. All notices and communications given under this Agreement must be in writing and will be sent by email. Controller shall be notified by email sent to the address related to its use of the Service under the Principal Agreement. Processor shall be notified by email sent to the address: [email protected].

13. Governing Law and Jurisdiction

13.1 This Agreement is governed by the laws of Ireland.

13.2 Any dispute arising in connection with this Agreement, which the Parties will not be able to resolve amicably, will be submitted to the exclusive jurisdiction of the courts of Ireland.

Annex 1: Details of Processing

Subject matter and purpose. Providing the Services to the Company: running its loyalty programme, issuing and updating wallet passes, recording stamps, rewards and redemptions, sending the notifications the Company sets up, and providing analytics, exports, integrations and support.

Nature of Processing. Collection through sign-up forms, imports and integrations; storage; organisation; retrieval; transmission to wallet providers and the Company’s chosen integrations; and deletion.

Duration. For as long as the Company has a Leal account, then as set out in section 9.

Categories of Data Subjects. The Company’s customers who join its loyalty programme, and the Company’s staff who use the Services.

Types of Personal Data. As the Company’s sign-up form and imports require: name, email address, phone number and birthday; loyalty card, stamp, reward and redemption history; wallet pass and device identifiers needed to deliver pass updates; marketing and SMS opt-out status; external customer references from connected platforms; and, for staff, name and email address. No special categories of Personal Data are intended to be Processed.

Annex 2: Subprocessors

SubprocessorPurposeLocation
Hetzner Online GmbHApplication serversEU
PlanetScale, Inc.Database hostingEU region
Cloudflare, Inc.Image storage, custom domains and network securityGlobal network
Resend (Plus Five Five, Inc.)Sending emails to customers, such as card linksUnited States
Apple Inc.Apple Wallet pass delivery and update notificationsUnited States
Google LLCGoogle Wallet pass deliveryUnited States
Honeybadger Industries LLCError monitoringUnited States
New Relic, Inc.Performance monitoringUnited States

Leal also uses providers that do not receive Company Personal Data, such as Stripe for billing the Company and analytics on tryleal.dev. Those are described in the Privacy Policy.

If your company requires this DPA signed by Leal or have any questions, please contact us at [email protected].