- Processor
- Donncha O'Toole
- Product
- Bronora is a voucher-software product supplied by Donncha O'Toole.
- Address
- Bellevue House, Bellevue Demesne, Delgany, Co. Wicklow, Ireland
- Version
- bronora-dpa-2026-07-29-v2
1. Parties and scope
This data processing agreement (“DPA”) is between the Merchant that accepts the Bronora merchant service terms, as controller, and Donncha O'Toole, as processor. It applies to personal data the Processor handles on the Merchant’s behalf to provide the Bronora voucher service (“Merchant Personal Data”). It forms part of the merchant service terms. If the documents conflict about Merchant Personal Data, this DPA takes priority.
Each party will comply with the GDPR, the Irish Data Protection Act 2018 and other data-protection law applicable to it. The Merchant is responsible for its lawful basis, customer privacy information, instructions and the accuracy and permitted use of data submitted to Bronora.
2. Documented instructions
The Processor will process Merchant Personal Data only on documented instructions from the Merchant, including these documents, settings, secured imports, support requests and normal authorised use of the service. The Processor may also process it where EU or Irish law requires, in which case the Processor will notify the Merchant before processing unless law prohibits notice.
The Processor will tell the Merchant if, in its reasonable view, an instruction infringes applicable data-protection law and may pause the affected processing while the parties resolve it. The Processor will not sell Merchant Personal Data or use it for its own advertising.
3. Processing details
| Subject and purpose | Hosting and operating the Merchant’s digital voucher shop, payment connection, delivery, access, redemption, reporting, import, refund, dispute, support, security, backup and data-return functions |
|---|---|
| Duration | For the agreement and the return, deletion, backup and lawful-retention periods described below |
| Operations | Collection, validation, encryption, organisation, storage, retrieval, display, transmission, delivery, reconciliation, restriction, backup, export, deletion and de-identification |
| Data subjects | Merchant staff and contractors, purchasers, voucher recipients, redeemers and customer-support contacts |
| Personal data | Names, email addresses, gift messages, consent choices, voucher and order details, payment-provider references, delivery and access events, redemption history, refund and dispute records, support material, and authentication, device, security and audit events |
| Sensitive data | No special-category or criminal-offence data is required or intended. The Merchant must not submit it unless the parties first document a lawful need and suitable safeguards |
4. Confidentiality and personnel
The Processor will limit access to people who need Merchant Personal Data to provide, secure or support the service. They will be bound by confidentiality and receive appropriate security and privacy instructions. The Processor remains responsible for their handling of the data.
5. Security measures
Taking account of the state of the art, implementation cost, the processing and the risk to people, the Processor will maintain appropriate technical and organisational measures, including:
- encrypted transport and encryption of sensitive application fields;
- tenant isolation, role-based access and least-privilege service accounts;
- multi-factor authentication for merchant owners and controlled staff-device access;
- protected and rotated application credentials kept outside source code;
- immutable-style financial, voucher and audit records with idempotent payment processing;
- availability monitoring, request controls, security logging and incident procedures;
- daily restricted database backups retained for 14 days and regular restoration checks; and
- change review, dependency checks and production verification proportionate to risk.
The Processor may update these measures as technology and risk change, but will not materially reduce the overall protection during the agreement.
6. Subprocessors
The Merchant gives general authorisation for the subprocessors below. The Processor will impose data-protection terms consistent with this DPA and remains responsible for each subprocessor’s performance of its processing obligations.
| Subprocessor | Service | Primary location and transfer basis |
|---|---|---|
| DigitalOcean, LLC | Application, database and encrypted backup hosting | London, United Kingdom; EU adequacy decision, with DigitalOcean contractual safeguards for any onward transfer |
| Amazon Web Services EMEA SARL | Transactional email through Amazon SES | Ireland (eu-west-1); AWS contractual transfer safeguards for any support or onward transfer where required |
Stripe handles card and connected-account payment data under the Merchant’s direct agreement with Stripe and its own legal roles. It is not a subprocessor of Donncha O'Toole for full card data. The Processor handles the payment references and events it receives as part of Merchant Personal Data.
The Processor will give at least 15 days’ notice by account email or on this page before appointing or replacing a material subprocessor, unless an urgent security or legal need prevents advance notice. The Merchant may object within that period on reasonable data-protection grounds. The parties will try in good faith to use a reasonable alternative; if none is available, either may terminate the affected service without penalty.
7. International transfers
The Processor will not transfer Merchant Personal Data outside the European Economic Area unless the transfer is covered by an adequacy decision, the European Commission’s standard contractual clauses, or another lawful safeguard. The Processor will make information about the relevant safeguard available on reasonable request and will require subprocessors to protect onward transfers.
8. Individual rights and compliance assistance
Taking account of the nature of the processing, the Processor will provide reasonable technical and organisational assistance for access, correction, deletion, restriction, portability, objection and consent-withdrawal requests. If the Processor receives a request relating to Merchant Personal Data, it will send it to the Merchant without undue delay and will not answer as controller unless authorised or legally required.
The Processor will also reasonably assist with security risk assessments, breach notifications, data-protection impact assessments, prior consultations and regulator enquiries, taking account of the information available to Bronora.
9. Personal data breaches
The Processor will notify the Merchant without undue delay after becoming aware of a personal data breach affecting Merchant Personal Data. Notice will include, as information becomes available, the nature of the breach, affected data and people, likely consequences, measures taken or proposed and a contact for follow-up. An initial notice may be incomplete and will be supplemented. The Processor will investigate, mitigate and reasonably cooperate, but notice is not an admission of fault.
10. Return, deletion and retention
During the service, the Merchant can export order and reporting data through the available tools. On termination, it may request a reasonable additional export within 30 days. After that period, the Processor will delete or de-identify Merchant Personal Data no longer needed to provide the service, unless EU or Irish law requires retention or the data is needed for an outstanding voucher, payment, dispute, fraud review or legal claim.
Retained data will be isolated to the permitted purpose and deleted when that purpose ends. Database backup copies age out after 14 days in the ordinary cycle. The category-specific rules in the privacy notice apply to processor-controlled records.
11. Information and audits
The Processor will provide information reasonably necessary to demonstrate compliance with this DPA. The Merchant must first use current documentation, certifications and written answers. If those are not sufficient, the Merchant may request one proportionate audit per year, or an additional audit following a confirmed material breach or regulator request.
Audits require reasonable notice, must avoid exposure of another merchant’s data and unnecessary disruption, and are subject to confidentiality and security controls. The Merchant bears its audit costs and the Processor’s reasonable costs unless the audit identifies a material breach by the Processor. Nothing requires disclosure of credentials, another customer’s information or material that would weaken security.
12. End of the DPA
This DPA ends when the Processor has completed the required return or deletion of Merchant Personal Data, but confidentiality, security, audit and liability provisions continue for data lawfully retained. Questions and notices under this DPA should be sent to hello@bronora.com.