Data Processing Agreement
Last updated: 19 August 2026
This Data Processing Agreement (“DPA”) forms part of, and is incorporated into, the Brand Terms of Service between the Brand and us. It governs our processing of personal data relating to people who enter prize draws run by the Brand on the Platform.
The Processor: The Prize Draw Company, a sole trader business based in the United Kingdom, ICO registration number ZC219644 (“we”, “us”, “Processor”). The Controller: the Brand that has agreed to the Brand Terms of Service (“you”, “Controller”).
1. Background and roles
1.1 You use the Platform to run prize draws. When people enter your draws, they provide personal data that is collected for you and your purposes. You decide why and how that data is used. You are therefore the controller of that data.
1.2 We host the Platform and store and handle that data on your behalf and on your instructions. We are therefore your processor for that data.
1.3 We do not use entry data for our own purposes. The entry form also offers entrants a separate, optional opt-in to receive updates about new draws from us. Data an entrant gives us through that opt-in is collected by us as a controller, directly from the data subject and with their consent; it is not processed under your instructions, is not a condition of entry, has no effect on entries or odds, and our Privacy Policy applies to it. If we ever otherwise determine the purposes and means of processing any personal data for our own ends, we would be a controller for that data too, and our Privacy Policy would apply to it instead.
1.4 If there is any conflict between this DPA and the rest of the Brand Terms of Service on the subject of data protection, this DPA prevails.
1.5 We may produce anonymised, aggregated statistics from entry data (for example, average entries per draw, or how often each type of action is completed), provided that neither a data subject nor a Brand can be identified from them. Once truly anonymised, such statistics are no longer personal data, and we may use them to improve and promote the Platform.
2. Definitions
Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in UK Data Protection Law, meaning the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003, each as amended (including by the Data (Use and Access) Act 2025) and as replaced from time to time. “Subprocessor” means any third party we engage to process personal data under this DPA.
3. Scope of processing (UK GDPR Article 28(3))
The details required by Article 28(3) are set out in Annex 1. In summary, we process entry data only to provide the Platform to you for the duration of your use of it.
4. Our obligations as processor
We will:
(a) Process only on your instructions. We will process the personal data only on your documented instructions, including on transfers outside the UK, unless we are required to do otherwise by law, in which case we will tell you first unless the law prevents us. Your instructions are this DPA, the Brand Terms of Service, and your use of the Platform’s features. We will tell you if, in our opinion, an instruction breaches UK Data Protection Law.
(b) Ensure confidentiality. We will ensure that the people authorised to process the personal data are bound by confidentiality obligations.
(c) Keep the data secure. We will put in place appropriate technical and organisational measures to protect the personal data, taking account of the state of the art, the costs of implementation, and the nature and risk of the processing. Our current measures are described in Annex 3.
(d) Use subprocessors only on these terms. We may engage subprocessors as set out in Section 5.
(e) Help you respond to data subjects. Taking account of the nature of the processing, we will help you by appropriate technical and organisational measures, so far as possible, to respond to requests from data subjects exercising their rights (for example, access, correction, erasure and objection). The Platform’s own features (such as data export and per entrant erasure) are the main way we provide this help.
(f) Help you meet your wider obligations. Taking account of the nature of the processing and the information available to us, we will help you to meet your obligations on security, breach notification, data protection impact assessments and prior consultation with the regulator (UK GDPR Articles 32 to 36).
(g) Notify breaches. We will tell you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the personal data, and will give you the information you reasonably need to meet your own notification duties.
(h) Delete or return the data. At the end of the provision of the Platform, or on your earlier written request, we will delete or return the personal data and delete existing copies, unless we are required by law to keep it. By default, entry data for a draw is deleted within three months of the draw closing, unless you have a lawful reason to keep it and instruct us accordingly.
(i) Demonstrate compliance and allow audits. We will make available to you the information reasonably necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint. Audits will be at reasonable intervals, on reasonable notice, during business hours, and subject to confidentiality. We may satisfy an audit request by providing relevant documentation or third party certifications where these reasonably address your request.
5. Subprocessors
5.1 You give us general authorisation to engage subprocessors to help provide the Platform. The subprocessors we use at the date of this DPA are listed in Annex 2.
5.2 We will impose on each subprocessor, by contract, data protection obligations that are no less protective than those in this DPA.
5.3 We remain fully liable to you for the performance of each subprocessor’s obligations.
5.4 If we intend to add or replace a subprocessor, we will give you reasonable notice (by updating Annex 2 and notifying account holders, or by another reasonable means) so that you have the chance to object on reasonable data protection grounds. If you object and we cannot reasonably resolve your concern, you may stop using the affected part of the Platform and, if necessary, terminate as set out in the Brand Terms of Service.
6. International transfers
6.1 We will not transfer the personal data outside the United Kingdom except where appropriate safeguards recognised under UK Data Protection Law are in place, such as a UK approved data bridge, the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.
6.2 Where a subprocessor stores or processes data outside the United Kingdom, the safeguards relied on are summarised in Annex 2.
7. Liability
The limitations and exclusions of liability in the Brand Terms of Service apply to claims under this DPA, except where UK Data Protection Law does not allow them to be limited.
8. Term
This DPA applies for as long as we process personal data on your behalf, and the obligations that by their nature should survive (including confidentiality, deletion and audit) continue afterwards.
Annex 1: Details of processing (UK GDPR Article 28(3))
- Subject matter: the provision of the Platform, on which you run prize draws and collect entries.
- Duration: for as long as you use the Platform, and until entry data is deleted or returned in line with this DPA.
- Nature and purpose: collecting, storing, organising, retrieving, displaying, exporting and deleting entry data so that you can run your prize draws, select and contact winners, and (where you have valid consent) market to entrants.
- Type of personal data: entrants’ email addresses; first names; the bonus actions they have declared; answers given to question or vote actions you configure; marketing consent status and timestamp; the source of their entry; referral relationships; and technical data needed for security (such as a hashed form of identifiers used for rate limiting).
- Categories of data subjects: members of the public who enter your prize draws.
- Special category data: none is intended to be processed. You must not configure draws to collect special category data, including through question or vote actions.
Annex 2: Subprocessors
| Subprocessor | Purpose | Location and transfer safeguard |
|---|---|---|
| Cloudflare, Inc. | Hosting, the application database, and content delivery. Entry data is stored here. | The application database is located in the European Union. Cloudflare provides a data processing addendum and the relevant UK transfer safeguards |
| Google LLC | Sending service emails to entrants on your behalf (entry confirmations) from our support address | Google’s infrastructure, under its UK data protection commitments and transfer safeguards |
| Hetzner Online GmbH | Runs the workflow service that relays those service emails | Germany (European Union) |
Annex 3: Technical and organisational security measures
We currently apply the following measures, and keep them under review:
- Encryption in transit: all traffic is served over HTTPS.
- Credential protection: account passwords are stored only as salted, hashed values using a strong key derivation function. Plain passwords are never stored.
- Session security: sessions use random, server side tokens delivered in HttpOnly cookies, marked Secure in production, with a limited lifetime.
- Tenant separation: access to draws and entry data is scoped to the owning Brand, so one Brand cannot read or change another Brand’s data.
- Abuse protection: rate limiting on sign in, sign up and entry, and a honeypot to deter automated entries. Identifiers used for rate limiting are stored only in a one way hashed form.
- Input controls: validation and bounds on data accepted from public forms.
- Hosting: the Platform runs on Cloudflare’s infrastructure, which provides physical and network level security and its own data protection commitments.
- Data minimisation: we collect only what is needed to run a draw, and delete entry data on the schedule described above.