Data Processing Agreement
BranStory — a product of Brandmerce, LLC
Effective Date: April 2026 Last Updated: April 2026
This Data Processing Agreement (“DPA”) is entered into between Brandmerce, LLC (“Brandmerce,” “Processor”) and the network operator (“Operator,” “Controller”) that has executed an Operator Agreement for the use of the BranStory platform.
This DPA is incorporated into and forms part of the Operator Agreement. In the event of any conflict between this DPA and the Operator Agreement, this DPA controls with respect to data protection matters.
1. Purpose & Scope
1.1 This DPA governs the processing of Personal Data by Brandmerce on behalf of the Operator in connection with the provision of the BranStory platform and services (the “Services”).
1.2 For the purposes of this DPA:
- The Operator is the “Controller” — the party that determines the purposes and means of processing Personal Data of its network members
- Brandmerce is the “Processor” — the party that processes Personal Data on behalf of the Controller in accordance with this DPA and the Operator’s documented instructions
1.3 This DPA applies to all Personal Data that Brandmerce processes on behalf of the Operator in connection with the Services, including Personal Data of the Operator’s resident members, business members, and sponsors.
2. Definitions
| Term | Meaning |
|---|---|
| Personal Data | Any information relating to an identified or identifiable natural person, as defined under applicable Data Protection Law |
| Data Protection Law | All applicable laws and regulations relating to the processing of Personal Data, including the EU General Data Protection Regulation (GDPR), UK GDPR, the California Consumer Privacy Act (CCPA) as amended by the CPRA, and the Florida Digital Bill of Rights, to the extent applicable |
| Processing | Any operation or set of operations performed on Personal Data, including collection, storage, use, disclosure, and deletion |
| Data Subject | The natural person to whom Personal Data relates (e.g., a resident or business member of the Operator’s network) |
| Sub-processor | Any third party engaged by Brandmerce to process Personal Data on behalf of the Operator |
| Security Incident | Any confirmed unauthorized access to, or accidental loss, disclosure, alteration, or destruction of, Personal Data |
3. Operator’s Responsibilities as Controller
The Operator represents and warrants that:
- It has a valid lawful basis under applicable Data Protection Law for collecting and processing the Personal Data it submits to the Platform (e.g., consent, contract performance, or legitimate interests)
- It has provided adequate notice to its network members about how their Personal Data will be processed, including disclosure of Brandmerce’s role as a sub-processor
- It will comply with all obligations of a data controller under applicable Data Protection Law
- It will ensure that any instructions it gives to Brandmerce for processing Personal Data comply with applicable law
- It will promptly notify Brandmerce if it becomes aware that any processing instruction given to Brandmerce would violate applicable Data Protection Law
4. Brandmerce’s Obligations as Processor
Brandmerce agrees to:
4.1 Process Only as Instructed. Process Personal Data solely on documented instructions from the Operator, as set out in this DPA and the Operator Agreement, except where required to do so by applicable law. In such cases, Brandmerce will inform the Operator of that legal requirement before processing, unless prohibited by law.
4.2 Confidentiality. Ensure that personnel authorized to process Personal Data are subject to confidentiality obligations.
4.3 Security. Implement appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Current measures include:
- Encryption of Personal Data in transit (HTTPS/TLS) and at rest
- Role-based access controls limiting staff access to Personal Data
- Private, access-controlled storage environments for sensitive documents (e.g., KYC verification materials)
- Regular security reviews and infrastructure audits
4.4 Sub-processors. Not engage sub-processors without prior general or specific authorization from the Operator. Current authorized sub-processors are listed in Schedule A of this DPA. Brandmerce will notify the Operator of any intended changes to sub-processors, providing the Operator a reasonable opportunity to object before the change takes effect.
4.5 Data Subject Rights. Assist the Operator in responding to Data Subject rights requests (access, correction, deletion, portability, restriction, objection) to the extent technically feasible, given the nature of the processing. The Operator is primarily responsible for responding to Data Subject requests from its own members.
4.6 Data Protection Impact Assessments. Provide reasonable assistance to the Operator in conducting data protection impact assessments (DPIAs) and prior consultations with supervisory authorities, where required.
4.7 Deletion or Return. Upon termination of the Operator Agreement, delete or return all Personal Data as requested by the Operator, unless applicable law requires retention. Operators may request data export within 30 days of termination.
4.8 Audit Rights. Make available to the Operator all information necessary to demonstrate compliance with this DPA. Upon reasonable written notice (no less than 30 days), permit audits or inspections conducted by the Operator or its authorized representative, subject to reasonable confidentiality protections and at the Operator’s expense.
5. Categories of Personal Data Processed
Brandmerce processes the following categories of Personal Data on behalf of the Operator:
| Category | Examples | Data Subjects |
|---|---|---|
| Identity data | Name, profile photo | Residents, business members, business reps |
| Contact data | Email address | Residents, business members |
| Location data | Neighborhood, business address | Residents, business members |
| Account credentials | Hashed password | All registered users |
| Professional data | Business name, job title, bio | Business members and reps |
| Verification documents | Business license, EIN, proof of address | Business members (KYC process) |
| Transaction data | Subscription plan, payment date, renewal status | Operators, business members |
| Usage data | Login activity, feature usage, session data | All registered users |
| Communications | Inquiries, support messages | All users |
| User-generated content | Reviews, event RSVPs, deal redemptions | Residents, business members |
Brandmerce does not process special categories of sensitive personal data (e.g., health data, biometric data, racial or ethnic origin) on behalf of Operators in connection with the standard Services.
6. Purpose and Duration of Processing
6.1 Purpose. Brandmerce processes Personal Data solely to provide and maintain the BranStory platform and related Services to the Operator, as described in the Operator Agreement and this DPA.
6.2 Duration. Processing continues for the duration of the Operator Agreement. Upon termination:
- Personal Data is deleted or anonymized within 30 days unless the Operator requests export
- Transaction and billing records are retained for 7 years as required for legal and accounting purposes
- KYC verification documents are retained for the minimum period required by applicable compliance standards, then securely deleted
- Anonymized, aggregated analytics data may be retained indefinitely
7. International Data Transfers
7.1 Brandmerce is based in the United States. Processing of Personal Data under this DPA takes place in the United States and in other countries where Brandmerce’s authorized sub-processors operate.
7.2 Where Personal Data originates from the EEA, UK, or other jurisdictions with data transfer restrictions, Brandmerce will implement appropriate safeguards as required by applicable law, which may include:
- Standard Contractual Clauses (SCCs) as approved by the European Commission
- UK International Data Transfer Agreements (IDTAs)
- Other transfer mechanisms recognized under applicable law
7.3 Operators with EEA or UK-based members should contact privacy@brandmerce.com to execute applicable transfer documentation.
8. Security Incident Notification
8.1 Brandmerce will notify the Operator without undue delay — and in any event within 72 hours of becoming aware — of a confirmed Security Incident affecting Personal Data processed under this DPA.
8.2 Notification will include, to the extent known at the time:
- A description of the nature of the Security Incident
- Categories and approximate number of Data Subjects and records affected
- Likely consequences of the Security Incident
- Measures taken or proposed to address the incident and mitigate its effects
8.3 The Operator is responsible for notifying affected Data Subjects and relevant supervisory authorities as required by applicable Data Protection Law. Brandmerce will provide reasonable assistance in that process.
9. Confidentiality of Processing
Brandmerce will keep all Personal Data processed under this DPA strictly confidential and will not disclose it to any third party except:
- To authorized sub-processors as listed in Schedule A
- As required by applicable law, court order, or regulatory authority
- As expressly instructed in writing by the Operator
10. Governing Law
This DPA is governed by the same governing law as the Operator Agreement (the laws of the State of Florida). For Operators subject to GDPR or UK GDPR, the parties agree to supplement this DPA with applicable Standard Contractual Clauses or equivalent transfer mechanisms upon request.
11. Order of Precedence
In the event of any conflict or inconsistency between this DPA, the Operator Agreement, and Brandmerce’s general Terms of Service:
- This DPA controls for all data protection matters
- The Operator Agreement controls for all other commercial matters
- The Terms of Service apply as a general baseline
Schedule A — Authorized Sub-Processors
The following sub-processors are authorized by Operators upon execution of this DPA. Brandmerce will provide at least 30 days’ notice before adding or replacing sub-processors.
| Sub-Processor | Purpose | Country | Privacy Reference |
|---|---|---|---|
| Supabase, Inc. | Database hosting and user authentication | United States | supabase.com/privacy |
| Stripe, Inc. | Payment processing and subscription management | United States | stripe.com/privacy |
| Resend, Inc. | Transactional and notification email delivery | United States | resend.com/legal/privacy-policy |
| Apple Inc. | iOS app distribution | United States | apple.com/legal/privacy |
| Google LLC | Android app distribution; Google Places API for business profile enrichment | United States | policies.google.com/privacy |
Schedule B — Security Measures Summary
Brandmerce implements the following technical and organizational security measures:
Technical Measures
- HTTPS/TLS encryption for all data in transit
- Encryption at rest for database storage
- Private, access-controlled storage buckets for KYC documents with signed URL expiry
- Multi-factor authentication required for administrative access
- Automated session expiry and token rotation
Organizational Measures
- Role-based access controls — staff access to Personal Data limited to what is necessary for their role
- Confidentiality obligations for all personnel with access to Personal Data
- Regular security reviews of platform infrastructure
- Incident response procedures with documented escalation paths
Infrastructure
- Platform infrastructure hosted on Supabase (PostgreSQL) with row-level security policies
- All data storage within United States-based cloud infrastructure
12. Contact
Data protection inquiries and DPA execution requests: Privacy Officer: privacy@brandmerce.com Brandmerce, LLC · Nocatee, Florida
BranStory is a product of Brandmerce, LLC. © 2026 Brandmerce, LLC. All Rights Reserved.
Note to Operators: This DPA is provided as a standard addendum to all Operator Agreements. If your organization requires a countersigned DPA for your own compliance records, contact privacy@brandmerce.com to request a countersigned copy. If you are subject to GDPR or UK GDPR and require Standard Contractual Clauses, contact us to initiate that process.