Data Processing Agreement
Last reviewed: 3 August 2026
This DPA forms part of the Terms of Service between Loyal League Ltd (company no. 17197430), registered office 20 Wenlock Road, London, N1 7GU, England (the "Processor") and the label or business operating a Loyal League workspace (the "Controller"). It applies whenever the Processor processes personal data on the Controller's behalf under UK GDPR, the Data Protection Act 2018, and EU GDPR where applicable.
1. Roles
The Controller determines the purposes and means of processing fan personal data. The Processor processes that data only on the Controller's documented instructions — which include use of the Loyal League service and any configuration made within it — unless required otherwise by law, in which case the Processor will notify the Controller unless legally prohibited.
2. Subject matter, duration, nature and purpose
Subject matter: provision of a fan-data CRM (fan database, capture and link-in-bio pages, broadcasts, memberships, drops and streaming). Duration: for the term of the Controller's subscription plus the deletion window in clause 8. Nature and purpose: storage, organisation, retrieval, analysis (superfan scoring), transmission (email delivery) and deletion.
3. Categories of data subject and personal data
Data subjects: the Controller's fans, customers, members and invited team members. Personal data: name where provided, email address, optional phone number, city, consent status, page of origin, engagement events, purchase and membership records, and download/stream activity. No special category data is intended to be processed; the Controller must not upload it.
4. Processor obligations
- Process only on documented instructions.
- Ensure personnel with access are bound by confidentiality.
- Implement the technical and organisational measures in clause 5.
- Assist the Controller with data subject requests, DPIAs and regulator engagement.
- Notify the Controller without undue delay, and in any case within 48 hours, of a personal data breach affecting their data.
- Make available the information needed to demonstrate compliance and allow audits (see clause 9).
5. Security measures
Encryption in transit (TLS 1.2+) and at rest (AES-256); row-level security so each label can only read rows for its own workspace; private storage buckets served only through short-lived signed URLs; device-bound, expiring streaming sessions; least-privilege administrative access with MFA; automated daily backups; and audit logging of email delivery. Full detail on the Security page.
6. Sub-processors
The Controller gives general authorisation for the sub-processors below. The Processor remains liable for their performance and will give at least 30 days' notice before adding or replacing one, during which the Controller may object on reasonable data-protection grounds and, if unresolved, terminate without penalty.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage and hosting | AWS eu-west-1 (Ireland), EU |
| Resend | Transactional and broadcast email delivery | US / EU |
| Stripe | Subscription billing and fan payments (Stripe Connect) | EU / US |
7. International transfers
Primary storage is in the EU. Where a sub-processor processes personal data outside the UK/EEA, the transfer relies on an adequacy decision or the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum.
8. Return and deletion
The Controller can export all fan data at any time as CSV/JSON. On termination, or on written request, the Processor will delete the Controller's personal data from live systems within 60 days, with backups purged on a rolling schedule of up to 30 days thereafter, except where retention is required by law.
9. Audit
On reasonable written notice, and no more than once per year unless required by a regulator, the Processor will respond to a security questionnaire and provide available documentation about its measures and those of its sub-processors.
10. Signing and contact
A counter-signed copy of this DPA is available on request. Email support@loyalleague.app with your label name and we will return an executed version.
