data processing agreement.
last updated · 7 april 2026
This Data Processing Agreement ("DPA") forms part of the agreement between PosKit UK Ltd ("PosKit", "we", "us", or "our") and the customer identified in the applicable Order ("Customer", "you") for the provision of the PosKit platform and services (the "Agreement"). It reflects the parties' agreement with regard to the processing of Personal Data by PosKit on behalf of the Customer.
PosKit UK Ltd is a company registered in England and Wales (company number 17076936), with its registered office at Butler House 3rd Floor, 177-178 Tottenham Court Road, London, W1T 7NY.
This DPA is entered into pursuant to Article 28(3) of the UK GDPR. Where the Customer has executed this DPA as instructed in the Agreement, it is incorporated by reference into the Agreement upon execution by both parties and PosKit's receipt of the executed copy.
1. Definitions
- "Data Protection Laws" means all applicable laws relating to the processing of Personal Data, including the UK General Data Protection Regulation as it forms part of the law of England and Wales by virtue of the European Union (Withdrawal) Act 2018 ("UK GDPR"), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and, where applicable, the EU General Data Protection Regulation (EU) 2016/679 ("EU GDPR").
- "Personal Data", "Data Subject", "Controller", "Processor", "processing", and "Personal Data Breach" have the meanings given to them in the UK GDPR.
- "Customer Personal Data" means any Personal Data contained within data provided to, or collected by, PosKit on behalf of the Customer in connection with the Service.
- "Sub-processor" means any third party engaged by PosKit to process Customer Personal Data on behalf of the Customer.
- "Service" means the PosKit platform and services described in the Agreement.
2. Roles of the Parties
The parties acknowledge and agree that, with regard to the processing of Customer Personal Data, the Customer is the Controller and PosKit is the Processor. Each party shall comply with its respective obligations under Data Protection Laws.
For the avoidance of doubt, where PosKit processes Personal Data relating to the Customer's own account with PosKit (such as the names and contact details of the Customer's administrators and billing contacts), PosKit acts as an independent Controller and processes such data in accordance with our Privacy Policy.
3. Details of Processing
- Subject matter: The provision of the Service, including POS device monitoring, alerting, management, and support.
- Duration: The term of the Agreement, plus the retention period set out in Section 10.
- Nature and purpose: Collection, storage, analysis, and display of data from the Customer's connected POS estate in order to provide monitoring and management functionality, and such other processing as instructed by the Customer through its use of the Service.
- Types of Personal Data: User account identifiers (names, email addresses, job titles) of the Customer's personnel; device telemetry and log data that may incidentally contain Personal Data (such as usernames, IP addresses, and device identifiers); support communications; and any other Personal Data the Customer chooses to submit to the Service.
- Categories of Data Subjects: The Customer's employees, contractors, and agents; and, to the extent contained in data submitted to the Service, the Customer's own end users and customers.
- Special category data: The Service is not designed for, and the Customer agrees not to submit, special category data (Article 9 UK GDPR) or criminal offence data (Article 10 UK GDPR).
4. Processor Obligations
PosKit shall:
- process Customer Personal Data only on the Customer's documented instructions (including as set out in the Agreement and this DPA, and as given through the Customer's configuration and use of the Service), unless required to do otherwise by law to which PosKit is subject, in which case PosKit shall inform the Customer of that legal requirement before processing unless the law prohibits such disclosure;
- immediately inform the Customer if, in PosKit's opinion, an instruction infringes Data Protection Laws;
- ensure that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
- implement the technical and organisational measures set out in Annex 2 and Article 32 of the UK GDPR;
- taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests from Data Subjects exercising their rights under Chapter III of the UK GDPR;
- assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the UK GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of processing and the information available to PosKit;
- at the Customer's choice, delete or return Customer Personal Data in accordance with Section 10; and
- make available to the Customer all information necessary to demonstrate compliance with Article 28 of the UK GDPR and allow for and contribute to audits in accordance with Section 9.
5. Customer Obligations
The Customer shall:
- ensure it has a lawful basis for the processing of Customer Personal Data and has provided all notices and obtained all consents required under Data Protection Laws;
- ensure its instructions to PosKit comply with Data Protection Laws; and
- not submit special category data, criminal offence data, or data relating to children to the Service.
6. Sub-processors
The Customer provides general written authorisation for PosKit to engage Sub-processors to process Customer Personal Data, provided that PosKit:
- maintains a current list of Sub-processors (set out in Annex 3) and makes it available to the Customer on request at privacy@poskit.app;
- gives the Customer at least 30 days' prior written notice (which may be by email) of the addition or replacement of any Sub-processor. If the Customer objects on reasonable data protection grounds and the parties cannot resolve the objection within 30 days, the Customer may terminate the affected part of the Service and receive a pro-rata refund of pre-paid fees for the unused portion;
- imposes on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA; and
- remains fully liable to the Customer for the performance of each Sub-processor's obligations.
7. International Transfers
PosKit shall not transfer Customer Personal Data outside the United Kingdom or the European Economic Area unless the transfer is:
- to a country covered by UK adequacy regulations under Article 45 of the UK GDPR (or, for EU GDPR transfers, an EU adequacy decision); or
- subject to appropriate safeguards under Article 46 of the UK GDPR, including the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with any supplementary measures required following a transfer risk assessment.
A copy of the safeguards in place for any given transfer is available on request from privacy@poskit.app.
8. Personal Data Breach
PosKit shall notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification shall, to the extent the information is available, describe the nature of the breach, the categories and approximate numbers of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. PosKit shall provide reasonable cooperation to support the Customer's obligations under Articles 33 and 34 of the UK GDPR, including any notification to the Information Commissioner's Office (ICO) or affected Data Subjects. PosKit's notification of a breach is not an acknowledgement of fault or liability.
9. Audits
PosKit shall make available to the Customer, on request and no more than once per year, information reasonably necessary to demonstrate compliance with this DPA, including summaries of independent security audits and penetration test reports. Where such information is not sufficient to demonstrate compliance, the Customer (or an independent auditor appointed by it that is not a competitor of PosKit) may, on at least 30 days' written notice and subject to reasonable confidentiality obligations, conduct an audit of PosKit's processing of Customer Personal Data during normal business hours, no more than once in any 12-month period unless required by a supervisory authority or following a Personal Data Breach.
10. Return and Deletion of Data
Upon termination or expiry of the Agreement, the Customer may export Customer Personal Data from the Service for a period of 90 days. At the end of that period, PosKit shall delete all Customer Personal Data (including copies held by Sub-processors) unless retention is required by law to which PosKit is subject, in which case PosKit shall protect the retained data in accordance with this DPA and process it only for the purpose required by that law. On written request, PosKit shall confirm deletion in writing.
11. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, and references in the Agreement to a party's liability mean the aggregate liability of that party under the Agreement and this DPA together. Nothing in this DPA limits either party's liability where it cannot be limited under applicable law.
12. General
In the event of any conflict between this DPA and the Agreement with respect to the processing of Customer Personal Data, this DPA shall prevail. This DPA is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales. If any provision of this DPA is held invalid or unenforceable, the remainder shall continue in full force and effect. This DPA terminates automatically upon deletion of all Customer Personal Data in accordance with Section 10.
Annex 1 - Processing Details
The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are as set out in Section 3 of this DPA.
Annex 2 - Technical and Organisational Measures
- Encryption of Customer Personal Data in transit using TLS 1.3 and at rest using AES-256.
- Role-based access controls and multi-factor authentication for all internal systems.
- Logical separation of each customer's data within the Service.
- Regular penetration testing and security audits by independent third parties.
- Intrusion detection and 24/7 security monitoring with audit logs retained for up to 365 days.
- Documented incident response procedures with defined escalation paths.
- Employee security training, confidentiality undertakings, and background checks.
- Regular backups with tested restoration procedures.
- Vulnerability management, including timely application of security patches.
Annex 3 - Sub-processors
PosKit uses third-party Sub-processors for cloud hosting (e.g., AWS, Azure), email delivery, analytics, and customer support tooling. The current list of Sub-processors, including their processing locations, is available on request from privacy@poskit.app.
Contact
- Data Protection Officer: dpo@poskit.app
- Privacy enquiries: privacy@poskit.app
- Postal Address: Data Protection Officer, PosKit UK Ltd, Butler House 3rd Floor, 177-178 Tottenham Court Road, London, W1T 7NY
To execute this DPA, contact eula@poskit.app and we will provide a countersignable copy. You may lodge a complaint with the Information Commissioner's Office at ico.org.uk or 0303 123 1113.