Data Processing Agreement

This DPA was last updated on 17 June 2026.

Parties to this DPA

This Data Processing Addendum (“DPA”) is made by and between the parties to the Terms incorporating this DPA by reference (the Customer as defined in the Terms, and Alia), and this DPA shall be in addition to any obligations set out in the Terms.

The parties agree that in relation to Protected Data (as it may be applicable to the parties under Data Protection Laws), the Customer shall be the Data Controller and Alia shall be the Data Processor.

This DPA is incorporated into and forms part of the agreement between the parties concerning the provision of Alia’s Services.

1. Definitions

All capitalised terms in this DPA shall have the meaning as prescribed by Alia’s Terms of Service (“Terms”) or as otherwise agreed between the parties, unless otherwise specified below.

Applicable Law means as applicable and binding on the Controller, the Processor and/or the Services:

  1. Any law, statute, regulation, byelaw or subordinate legislation in force from time to time to which a party is subject and/or in any jurisdiction that the Services are provided to or in respect of, as may be specified in the Terms;
  2. The common law and law of equity as applicable to the parties from time to time;
  3. Any binding court order, judgment or decree; or
  4. Any applicable direction, policy, rule or order that is binding on a party and that is made or given by any regulatory body having jurisdiction over a party or any of that party’s assets, resources or business;

Associated Company means a company belonging to the same group as either party;

Applicable Data Protection Laws (or Data Protection Laws) means all laws and regulations relating to the privacy, protection, or processing of Personal Data applicable to a party in the performance of its obligations under this DPA, including:

  1. in the United States: the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (together, the “CCPA”), and any other comparable U.S. federal or state privacy or data protection law as may be in force from time to time;
  2. in the European Economic Area, the United Kingdom and Switzerland: Regulation (EU) 2016/679 (the “GDPR”); the United Kingdom General Data Protection Regulation as defined in section 3(10) of the Data Protection Act 2018, supplemented by section 205(4) (the “UK GDPR”); the Data Protection Act 2018; the Privacy and Electronic Communications (EC Directive) Regulations 2003; and the Swiss Federal Act on Data Protection;
  3. in relation to the Customer, all other data protection and/or privacy laws applicable in any jurisdiction where Data Subjects contacted through the Services are located; and
  4. any laws or regulations replacing, amending, extending, re-enacting or consolidating any of the above from time to time;

Data Protection Losses means:

  1. Administrative fines, penalties, sanctions, liabilities or other remedies imposed by a Supervisory Authority; and/or
  2. Compensation which is ordered by a Supervisory Authority to be paid to a Data Subject;

Data Subject, Process, Data Controller and Data Processor shall have the meanings ascribed to them under Applicable Data Protection Laws;

EU SCCs means the standard contractual clauses for the transfer of personal data to third countries set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as may be amended, superseded or replaced from time to time;

Personal Data has the meaning given to that term in Applicable Data Protection Laws, or where that term is not identically defined in the relevant Applicable Data Protection Law, the meaning given to the equivalent defined term in that Applicable Data Protection Law;

Personal Data Breach means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, any Protected Data;

Protected Data means Personal Data received from or on behalf of the Data Controller in connection with the performance of the Data Processor’s obligations under this DPA and/or in connection with the Services;

Sub-Processor means another Data Processor engaged by Alia or any Associated Company of Alia for carrying out processing activities in respect of the Protected Data on behalf of the Customer;

Supervisory Authority means any local, national or multinational agency, department, official, parliament, public or statutory person or any government or professional body, regulatory or supervisory authority, board or other body responsible for administering Data Protection Laws;

UK SCCs means the Information Commissioner’s Office’s (“ICO”) International Data Transfer Agreement (“IDTA”) for the transfer of personal data from the UK and/or the ICO’s International Data Transfer Addendum to EU Commission Standard Contractual Clauses, or such alternative clauses as may be approved by the UK from time to time.

2. Data Processor and Data Controller

2.1. Alia shall process Protected Data in compliance with:

2.1.1 the obligations of Data Processors under Data Protection Laws in respect of the performance of its obligations herein; and

2.1.2 the terms of this DPA, the Terms and the agreement between the parties which set out the Data Controller’s instructions in relation to such processing activities.

2.2 The Data Controller shall comply with:

2.2.1 all Data Protection Laws in connection with the processing of Protected Data, use of the Services and the exercise and performance of its respective rights and obligations under this DPA, including maintaining all relevant regulatory registrations and notifications as required under Data Protection Laws; and

2.2.2 the terms of this DPA; and

2.2.3 ensuring that all Personal Data sourced by the Data Controller for use in connection with the Services has been collected, stored and processed in compliance with Data Protection Laws, including the provision of all required fair processing information to, and the obtaining of all necessary consents from, Data Subjects.

2.3 The Data Controller warrants, represents and undertakes that all instructions given by it to the Data Processor in respect of Personal Data shall at all times be in accordance with Data Protection Laws.

2.4 The Data Controller shall not unreasonably withhold, delay or condition its agreement to any change or amendment requested by the Data Processor in order to ensure the Services and the Data Processor (and each Sub-Processor) can comply with Data Protection Laws.

3. Data Processing Details

3.1. The subject matter and details of the processing of Protected Data to be carried out by the Data Processor under this DPA shall comprise the processing set out in Schedule 1 (Data Processing Details), as may be updated from time to time as agreed between the parties.

4. Obligations of the Data Processor

The Data Processor agrees to:

4.1. Process Personal Data only on documented instructions from the Data Controller.

4.2. Ensure that persons authorized to process the Personal Data are subject to appropriate confidentiality obligations.

4.3. Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption, access controls, and data minimization practices.

4.4. Assist the Data Controller in ensuring compliance with its obligations regarding data security, Personal Data Breach notifications, data protection impact assessments, and consultations with Supervisory Authorities.

4.5. At the choice of the Data Controller, delete or return all Personal Data at the end of the Term, unless retention is required by law.

4.6. Make available to the Data Controller all information necessary to demonstrate compliance and allow for audits (subject to reasonable notice and confidentiality obligations).

5. Technical and organisational measures

5.1 The Data Processor shall implement and maintain, at its cost and expense, appropriate technical and organisational measures in relation to the processing of Protected Data by the Data Processor, taking into account the nature of the processing, to assist the Data Controller insofar as is possible in the fulfilment of the Data Controller’s obligations. These measures are outlined in the Alia Technical and Security Measures.

6. Sub-Processors

6.1 The Data Controller hereby authorizes the engagement of the Data Processor’s existing and future Associated Companies as Sub-Processors and also authorizes the appointment of any of the Sub-Processors listed in the Alia Sub-Processors page. During the Term, the Data Processor shall provide the Data Controller with 30 days’ prior notice of the appointment of any new third-party Sub-Processor, including details of the Processing to be undertaken by the Sub-Processor, via email.

6.2 The Data Controller may object (on reasonable grounds and only relating to Data Protection Laws) to the use of a new or replacement Sub-Processor appointed per the clause above within fourteen (14) days of the Data Processor’s notice. If the Data Controller notifies the Data Processor in writing of any objections to the proposed appointment, both parties shall work in good faith toward a resolution. If a solution cannot be found, the Data Controller may, by written notice to the Data Processor with immediate effect terminate the agreement between the parties to the extent that it relates to the Services which require the use of the proposed Sub-Processor. This termination right is the Data Controller’s sole and exclusive remedy to object to any Sub-Processor appointed by the Data Processor during the Term.

6.3 The Data Processor shall ensure:

6.3.1 via a written contract that each Sub-Processor only accesses and processes Protected Data to perform the obligations subcontracted to it and does so in accordance with the measures contained in this DPA that is enforceable by the Data Processor; and

6.3.2 that it shall remain fully liable for all the acts and omissions of each Sub-Processor as if they were its own.

7. International Data Transfers

7.1. European Transfers. The Data Controller agrees that the Data Processor may transfer any Protected Data to Sub-Processors located in countries outside the European Economic Area (EEA), provided all transfers by the Data Processor of Protected Data to an EEA international recipient shall (to the extent required under Data Protection Laws) be subject to and in compliance with the EU SCCs and other requirements of Data Protection Laws, including, but not limited to, data transfer impact assessments, third country assessments and agreeing additional safeguards as necessary.

7.2. UK Transfers. The Data Controller agrees that the Data Processor may transfer any Protected Data to Sub-Processors located in countries outside the United Kingdom (UK), provided all transfers by the Data Processor of Protected Data to a UK international recipient shall (to the extent required under Data Protection Laws) be subject to and in compliance with the UK SCCs and other requirements of Data Protection Laws including, but not limited to, data transfer impact assessments, third country assessments and agreeing additional safeguards as necessary.

7.3 US Transfers. If the Data Processor Processes Protected Data outside the United States, it shall ensure appropriate safeguards are implemented in accordance with applicable US Data Protection Laws, including, where relevant, the use of valid cross-border transfer mechanisms recognised under applicable US Data Protection Laws.

8. Data Subject Rights

8.1 The Data Processor shall promptly notify the Data Controller of any request received directly from a Data Subject and shall not respond to such a request without the Data Controller’s prior written consent unless required by law.

8.2 Further to the above and notwithstanding anything to the contrary in the Terms, the Data Processor reserves the right to disclose the identity of the Data Controller to any relevant Data Subject following any such request.

9. Security Incidents

In the event of a Personal Data Breach, the Data Processor shall:

9.1. Notify the Data Controller without undue delay after becoming aware of the Personal Data Breach.

9.2. Provide the Data Controller with such information as is reasonably available to the Data Processor regarding the Personal Data Breach, including (to the extent then known) the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it; and provide reasonable cooperation and assistance to enable the Data Controller to meet its own breach notification obligations.

10. Deletion or Return of Data

10.1. The Data Processor shall upon written request from the Data Controller, delete or return of Protected Data. Any return of Protected Data shall be in such form as the Data Controller reasonably requests, within a reasonable time after the earlier:

10.1.1. the end of the provision of the relevant Services related to processing; or

10.1.2. once processing by the Data Processor of any Protected Data is no longer required for the purpose of the Data Processor’s performance of its relevant obligations under the Agreement, and delete existing copies (unless storage of any data is required by Applicable Law and, if so, the Data Processor shall inform the Data Controller of any such requirement).

10.2. The Data Processor retains user data for up to one (1) year unless earlier deletion is triggered by merchant uninstall (within 48 hours). The Data Processor may retain certain data (such as SMS consent records) for up to ten (10) years to comply with legal and regulatory obligations.

11. Liability

11.1. Any claims brought under or in connection with this DPA shall be subject to the terms and conditions, including, but not limited to, the exclusions and limitations set out in the Terms.

12. Miscellaneous

12.1. This DPA is governed by the laws set forth in the Terms.

12.2. In the event of conflict between this DPA and the Terms, the terms of this DPA shall prevail with respect to data protection matters.

13. Cooperation

13.1. If a party receives a compensation claim from an individual or Supervisory Authority relating to processing of Protected Data, it shall promptly provide the other party with notice and full details of such claim. The party with conduct of the action shall:

13.1.1. make no admission of liability nor agree to any settlement or compromise of the relevant claim without the prior written consent of the other party (which shall not be unreasonably withheld or delayed); and

13.1.2. consult fully with the other party in relation to such action.

14. Audits and Records

14.1. The Data Processor shall maintain, in accordance with Data Protection Laws binding on the Data Processor, written records of all categories of processing activities carried out on behalf of the Data Controller.

14.2. The Data Processor shall, in accordance with Data Protection Laws, make available to the Data Controller such information as is reasonably necessary to demonstrate the Data Processor’s compliance with the obligations of Data Processors under Data Protection Laws and allow for and contribute to audits, including inspections by the Data Controller (or another auditor mandated by the Data Controller) for this purpose, subject to the Data Controller:

14.2.1. giving the Data Processor reasonable prior notice of such information request, audit and/or inspection being required by the Data Controller;

14.2.2. ensuring that all information obtained or generated by the Data Controller or its auditor(s) in connection with such information requests, inspections and audits is kept strictly confidential (save for disclosure to the supervisory authority or as otherwise required by Applicable Law);

14.2.3 ensuring that such audit or inspection is undertaken during normal business hours, with minimal disruption to the Data Processor’s business and the business of other customers of the Data Processor; and

14.2.4 paying the Data Processor’s reasonable costs for assisting with the provision of information and allowing for and contributing to inspections and audits on-site, calculated on a time and materials basis.

15. Government Requests

15.1. The Data Processor does not, as a matter of course, voluntarily supply government authorities, agencies or law enforcement access to or information relating to the Data Processor’s customer accounts or Protected Data. If the Data Processor receives a compulsory request (whether via court order, warrant, or other valid legal process) from any government authority, agency or law enforcement for access to or information relating to a customer account (including Protected Data) belonging to the Data Controller (a “Government Request”), the Data Processor shall use reasonable efforts to confirm the validity and scope of such request before responding.

15.2 In the event that the Data Processor satisfies itself that a Government Request is valid, the Data Processor shall:

15.2.1 inform the government authority, agency or law enforcement that the Data Processor is a processor of the Protected Data;

15.2.2 attempt to redirect the government authority, agency or law enforcement to request the data directly from the Data Controller; and

15.2.3 notify the Data Controller via email of the Government Request to allow the Data Controller to seek their own appropriate remedy, whereby the Data Processor may provide the Data Controller’s contact information.

15.3 The Data Processor shall not be required to comply with the provision of clauses 15.1 or 15.2 above if:

15.3.1 the Data Processor is legally prohibited from doing so; or

15.3.2 the Data Processor has a reasonable and good-faith belief that urgent access is necessary to prevent an imminent risk of serious harm to any individual, the safety of the public, or the Data Processor’s Services or property.

SCHEDULE 1 – DATA PROCESSING DETAILS

1. Subject-matter of processing:

Protected Data collected via forms integrated on the Customer’s website(s) in relation to the Data Processor’s provision of the Services to the Data Controller.

2. Duration of the processing:

For the duration of the Term until deletion of all Protected Data by the Processor in accordance with the DPA, unless otherwise agreed or required by law.

3. Nature and purpose of the processing:

The Data Processor will process Protected Data for the purposes of providing the Services to the Data Controller in accordance with the DPA and the Terms and as initiated by the Data Controller in its use of the Services, including but not limited to collecting, transmitting, and storing Personal Data submitted through website pop-up forms to facilitate marketing, lead generation, and communication on behalf of the Customer.

4. Type of Personal Data:

Types of Personal Data provided to the Data Processor via the provision of the Services by or at the direction of the Data Controller, including but not limited to contact data (such as email address, contact number, name or other contact details), marketing preferences, IP address and usage information (including online navigation data, location data and browser data).

5. Categories of Data Subjects:

Data Subjects include the individuals about whom Personal Data is provided to the Data Processor via the Services by or at the direction of the Data Controller or end-users of the Data Controller, including but not limited to website visitors and users of the Customer’s services.