Data Processing Agreement
Off Pixel Ltd · operating Cirqlin
This Data Processing Agreement ("DPA") forms part of the Cirqlin Terms of Service between Off Pixel Ltd (company number 17045733, registered office 124-128 City Road, London, England, EC1V 2NX) as Processor, and the Promoter as Controller. It applies whenever the Processor processes personal data on the Controller's behalf in providing Cirqlin, and is intended to satisfy Article 28 UK GDPR / EU GDPR.
1. Roles and scope
1.1The Controller determines the purposes and means of processing fan data collected through their Cirqlin pages. The Processor processes that data only on the Controller's documented instructions, which are constituted by: these terms, the Controller's configuration of the service (pages published, integrations connected, exports performed), and any further written instructions.
1.2 If the Processor believes an instruction infringes data protection law, it will inform the Controller and may suspend the relevant processing until resolved.
2. Details of processing
Subject matter and duration: provision of the Cirqlin service for the duration of the Controller's account. Nature and purpose: collection, storage, encryption, organisation, transmission to Controller-connected services, matching of Controller-provided ticket records to signup records via non-reversible hashed identifiers, aggregation for analytics, export, and deletion of fan signup data. Categories of data subjects: individuals who sign up on the Controller's pages ("fans"); members of the Controller's organisation. Categories of personal data: email address; phone number (optional); social media handle (optional); approximate location derived from connection (country/region/city); signup source and referral attribution; consent records; age bracket (optional, where the Promoter enables it — a broad range only, never a date of birth); aggregate interaction data; ticket order records provided by the Controller from their ticketing systems (buyer email address, ticket type, price, quantity, order date). No special-category data is intended to be processed; the Controller must not solicit any through the service.
3. Processor obligations
The Processor shall:
- (a) process personal data only on documented instructions, including as regards international transfers, unless required by law (in which case it will inform the Controller unless prohibited);
- (b) ensure persons authorised to process the data are bound by confidentiality;
- (c) implement the technical and organisational measures in Annex II;
- (d) respect the sub-processor conditions in Section 4;
- (e) taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures in responding to data-subject rights requests (access, rectification, erasure, portability, objection) — in practice, the dashboard's export and deletion tools serve most such requests directly;
- (f) assist the Controller with security, breach notification, and (where applicable) impact-assessment obligations, taking into account the information available to the Processor;
- (g) at the end of the provision of services, delete all personal data within 30 days (subject to the Controller's prior export), unless law requires storage;
- (h) make available information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits as set out in Section 7.
4. Sub-processors
4.1 The Controller grants general authorisation for the sub-processors listed in Annex III.
4.2The Processor will give at least 30 days' notice of any intended addition or replacement (via the dashboard or email), during which the Controller may object on reasonable data-protection grounds. If an objection cannot be resolved, the Controller may terminate the affected service without penalty.
4.3 The Processor imposes data-protection obligations on each sub-processor equivalent to those in this DPA and remains liable for their performance.
4.4Controller-directed services are not sub-processors. Where the Controller connects Mailchimp, Bird, Meta, TikTok, or similar services using the Controller's own accounts and credentials, those providers process data as the Controller's own processors (or as independent controllers, per their terms) at the Controller's direction; the Processor merely transmits data as instructed.
5. Personal data breach
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, providing the information reasonably required for the Controller to meet its own notification obligations, and will cooperate in remediation.
6. International transfers
Primary processing and storage occur in the United Kingdom and EEA (database and storage in Ireland). Where the Processor's sub-processors transfer personal data outside the UK/EEA, such transfers are made under appropriate safeguards (UK IDTA / Addendum or EU Standard Contractual Clauses, as applicable). Controller-directed services (Section 4.4) transfer data under their own safeguards, which the Controller accepts by connecting them.
7. Audit
Once per 12-month period and on 30 days' notice, the Controller may request written information reasonably necessary to verify compliance with this DPA (including summaries of security measures and sub-processor arrangements). On-site or technical audits are limited to cases where a supervisory authority requires them or following a breach affecting the Controller's data, are conducted at the Controller's cost, and must not compromise other customers' data or security.
8. Liability and precedence
Liability under this DPA is subject to the limitations in the Terms of Service, save where data protection law provides otherwise. If this DPA conflicts with the Terms of Service on data-protection matters, this DPA prevails.
Annex I — Processing summary
As set out in Section 2.
Annex II — Technical and organisational measures
- Encryption at rest of fan contact fields (email, phone) using symmetric encryption with dedicated keys, separate from application credentials
- Encryption in transit (TLS) on all surfaces
- Tenant isolation enforced at the database layer (row-level security; single audited write path via security-definer functions with no anonymous execution rights)
- Access control: organisation membership checks on every read; owner-role restriction on exports and PII reveal
- Audit logging of every export and every unmasking of contact data
- Bot and abuse protection on public forms (Cloudflare Turnstile, durable rate limiting, honeypots)
- EU data residency for primary storage (Ireland)
- Backups per hosting provider's managed backup regime; deletion propagates on retention schedule
- Adversarial access-control test suite run in continuous integration (cross-tenant denial verified on every build)
- Secrets management: platform credentials encrypted at rest with dedicated keys; no shared or fallback credentials between customers
Annex III — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase, Inc. (on Amazon Web Services) | Database, authentication, file storage | Ireland (EU) |
| Vercel, Inc. | Application hosting, content delivery | EU/global edge |
| Cloudflare, Inc. | Bot protection (Turnstile) | Global |
| Resend (Plus Five Five, Inc.) | Transactional email to Controller accounts | EU sending region |
Controller-directed services (not sub-processors, per §4.4): Intuit Mailchimp; Bird (MessageBird B.V.); Meta Platforms; TikTok.