Effective 29 July 2026

Bronora data processing agreement.

This agreement sets out the Article 28 terms that apply when Donncha O’Toole processes customer personal data through Bronora for a merchant.

1. Parties and scope

This data processing agreement (“DPA”) is between the Merchant that accepts the Bronora merchant service terms, as controller, and Donncha O'Toole, as processor. It applies to personal data the Processor handles on the Merchant’s behalf to provide the Bronora voucher service (“Merchant Personal Data”). It forms part of the merchant service terms. If the documents conflict about Merchant Personal Data, this DPA takes priority.

Each party will comply with the GDPR, the Irish Data Protection Act 2018 and other data-protection law applicable to it. The Merchant is responsible for its lawful basis, customer privacy information, instructions and the accuracy and permitted use of data submitted to Bronora.

2. Documented instructions

The Processor will process Merchant Personal Data only on documented instructions from the Merchant, including these documents, settings, secured imports, support requests and normal authorised use of the service. The Processor may also process it where EU or Irish law requires, in which case the Processor will notify the Merchant before processing unless law prohibits notice.

The Processor will tell the Merchant if, in its reasonable view, an instruction infringes applicable data-protection law and may pause the affected processing while the parties resolve it. The Processor will not sell Merchant Personal Data or use it for its own advertising.

3. Processing details

4. Confidentiality and personnel

The Processor will limit access to people who need Merchant Personal Data to provide, secure or support the service. They will be bound by confidentiality and receive appropriate security and privacy instructions. The Processor remains responsible for their handling of the data.

5. Security measures

Taking account of the state of the art, implementation cost, the processing and the risk to people, the Processor will maintain appropriate technical and organisational measures, including:

The Processor may update these measures as technology and risk change, but will not materially reduce the overall protection during the agreement.

6. Subprocessors

The Merchant gives general authorisation for the subprocessors below. The Processor will impose data-protection terms consistent with this DPA and remains responsible for each subprocessor’s performance of its processing obligations.

Stripe handles card and connected-account payment data under the Merchant’s direct agreement with Stripe and its own legal roles. It is not a subprocessor of Donncha O'Toole for full card data. The Processor handles the payment references and events it receives as part of Merchant Personal Data.

The Processor will give at least 15 days’ notice by account email or on this page before appointing or replacing a material subprocessor, unless an urgent security or legal need prevents advance notice. The Merchant may object within that period on reasonable data-protection grounds. The parties will try in good faith to use a reasonable alternative; if none is available, either may terminate the affected service without penalty.

7. International transfers

The Processor will not transfer Merchant Personal Data outside the European Economic Area unless the transfer is covered by an adequacy decision, the European Commission’s standard contractual clauses, or another lawful safeguard. The Processor will make information about the relevant safeguard available on reasonable request and will require subprocessors to protect onward transfers.

8. Individual rights and compliance assistance

Taking account of the nature of the processing, the Processor will provide reasonable technical and organisational assistance for access, correction, deletion, restriction, portability, objection and consent-withdrawal requests. If the Processor receives a request relating to Merchant Personal Data, it will send it to the Merchant without undue delay and will not answer as controller unless authorised or legally required.

The Processor will also reasonably assist with security risk assessments, breach notifications, data-protection impact assessments, prior consultations and regulator enquiries, taking account of the information available to Bronora.

9. Personal data breaches

The Processor will notify the Merchant without undue delay after becoming aware of a personal data breach affecting Merchant Personal Data. Notice will include, as information becomes available, the nature of the breach, affected data and people, likely consequences, measures taken or proposed and a contact for follow-up. An initial notice may be incomplete and will be supplemented. The Processor will investigate, mitigate and reasonably cooperate, but notice is not an admission of fault.

10. Return, deletion and retention

During the service, the Merchant can export order and reporting data through the available tools. On termination, it may request a reasonable additional export within 30 days. After that period, the Processor will delete or de-identify Merchant Personal Data no longer needed to provide the service, unless EU or Irish law requires retention or the data is needed for an outstanding voucher, payment, dispute, fraud review or legal claim.

Retained data will be isolated to the permitted purpose and deleted when that purpose ends. Database backup copies age out after 14 days in the ordinary cycle. The category-specific rules in the privacy notice apply to processor-controlled records.

11. Information and audits

The Processor will provide information reasonably necessary to demonstrate compliance with this DPA. The Merchant must first use current documentation, certifications and written answers. If those are not sufficient, the Merchant may request one proportionate audit per year, or an additional audit following a confirmed material breach or regulator request.

Audits require reasonable notice, must avoid exposure of another merchant’s data and unnecessary disruption, and are subject to confidentiality and security controls. The Merchant bears its audit costs and the Processor’s reasonable costs unless the audit identifies a material breach by the Processor. Nothing requires disclosure of credentials, another customer’s information or material that would weaken security.

12. End of the DPA

This DPA ends when the Processor has completed the required return or deletion of Merchant Personal Data, but confidentiality, security, audit and liability provisions continue for data lawfully retained. Questions and notices under this DPA should be sent to hello@bronora.com.