HomeLegalData Processing Agreement

Data Processing Agreement

Data Processing Agreement

BranStory — a product of Brandmerce, LLC

 

Effective Date: April 2026 Last Updated: April 2026

 

This Data Processing Agreement (“DPA”) is entered into between Brandmerce, LLC (“Brandmerce,” “Processor”) and the network operator (“Operator,” “Controller”) that has executed an Operator Agreement for the use of the BranStory platform.

 

This DPA is incorporated into and forms part of the Operator Agreement. In the event of any conflict between this DPA and the Operator Agreement, this DPA controls with respect to data protection matters.

 

1. Purpose & Scope

1.1 This DPA governs the processing of Personal Data by Brandmerce on behalf of the Operator in connection with the provision of the BranStory platform and services (the “Services”).

 

1.2 For the purposes of this DPA:

 

  • The Operator is the “Controller” — the party that determines the purposes and means of processing Personal Data of its network members
  • Brandmerce is the “Processor” — the party that processes Personal Data on behalf of the Controller in accordance with this DPA and the Operator’s documented instructions

 

1.3 This DPA applies to all Personal Data that Brandmerce processes on behalf of the Operator in connection with the Services, including Personal Data of the Operator’s resident members, business members, and sponsors.

 

2. Definitions

TermMeaning
Personal DataAny information relating to an identified or identifiable natural person, as defined under applicable Data Protection Law
Data Protection LawAll applicable laws and regulations relating to the processing of Personal Data, including the EU General Data Protection Regulation (GDPR), UK GDPR, the California Consumer Privacy Act (CCPA) as amended by the CPRA, and the Florida Digital Bill of Rights, to the extent applicable
ProcessingAny operation or set of operations performed on Personal Data, including collection, storage, use, disclosure, and deletion
Data SubjectThe natural person to whom Personal Data relates (e.g., a resident or business member of the Operator’s network)
Sub-processorAny third party engaged by Brandmerce to process Personal Data on behalf of the Operator
Security IncidentAny confirmed unauthorized access to, or accidental loss, disclosure, alteration, or destruction of, Personal Data

 

3. Operator’s Responsibilities as Controller

The Operator represents and warrants that:

 

  • It has a valid lawful basis under applicable Data Protection Law for collecting and processing the Personal Data it submits to the Platform (e.g., consent, contract performance, or legitimate interests)
  • It has provided adequate notice to its network members about how their Personal Data will be processed, including disclosure of Brandmerce’s role as a sub-processor
  • It will comply with all obligations of a data controller under applicable Data Protection Law
  • It will ensure that any instructions it gives to Brandmerce for processing Personal Data comply with applicable law
  • It will promptly notify Brandmerce if it becomes aware that any processing instruction given to Brandmerce would violate applicable Data Protection Law

 

4. Brandmerce’s Obligations as Processor

Brandmerce agrees to:

 

4.1 Process Only as Instructed. Process Personal Data solely on documented instructions from the Operator, as set out in this DPA and the Operator Agreement, except where required to do so by applicable law. In such cases, Brandmerce will inform the Operator of that legal requirement before processing, unless prohibited by law.

 

4.2 Confidentiality. Ensure that personnel authorized to process Personal Data are subject to confidentiality obligations.

 

4.3 Security. Implement appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Current measures include:

 

  • Encryption of Personal Data in transit (HTTPS/TLS) and at rest
  • Role-based access controls limiting staff access to Personal Data
  • Private, access-controlled storage environments for sensitive documents (e.g., KYC verification materials)
  • Regular security reviews and infrastructure audits

 

4.4 Sub-processors. Not engage sub-processors without prior general or specific authorization from the Operator. Current authorized sub-processors are listed in Schedule A of this DPA. Brandmerce will notify the Operator of any intended changes to sub-processors, providing the Operator a reasonable opportunity to object before the change takes effect.

 

4.5 Data Subject Rights. Assist the Operator in responding to Data Subject rights requests (access, correction, deletion, portability, restriction, objection) to the extent technically feasible, given the nature of the processing. The Operator is primarily responsible for responding to Data Subject requests from its own members.

 

4.6 Data Protection Impact Assessments. Provide reasonable assistance to the Operator in conducting data protection impact assessments (DPIAs) and prior consultations with supervisory authorities, where required.

 

4.7 Deletion or Return. Upon termination of the Operator Agreement, delete or return all Personal Data as requested by the Operator, unless applicable law requires retention. Operators may request data export within 30 days of termination.

 

4.8 Audit Rights. Make available to the Operator all information necessary to demonstrate compliance with this DPA. Upon reasonable written notice (no less than 30 days), permit audits or inspections conducted by the Operator or its authorized representative, subject to reasonable confidentiality protections and at the Operator’s expense.

 

5. Categories of Personal Data Processed

Brandmerce processes the following categories of Personal Data on behalf of the Operator:

 

CategoryExamplesData Subjects
Identity dataName, profile photoResidents, business members, business reps
Contact dataEmail addressResidents, business members
Location dataNeighborhood, business addressResidents, business members
Account credentialsHashed passwordAll registered users
Professional dataBusiness name, job title, bioBusiness members and reps
Verification documentsBusiness license, EIN, proof of addressBusiness members (KYC process)
Transaction dataSubscription plan, payment date, renewal statusOperators, business members
Usage dataLogin activity, feature usage, session dataAll registered users
CommunicationsInquiries, support messagesAll users
User-generated contentReviews, event RSVPs, deal redemptionsResidents, business members

 

Brandmerce does not process special categories of sensitive personal data (e.g., health data, biometric data, racial or ethnic origin) on behalf of Operators in connection with the standard Services.

 

6. Purpose and Duration of Processing

6.1 Purpose. Brandmerce processes Personal Data solely to provide and maintain the BranStory platform and related Services to the Operator, as described in the Operator Agreement and this DPA.

 

6.2 Duration. Processing continues for the duration of the Operator Agreement. Upon termination:

 

  • Personal Data is deleted or anonymized within 30 days unless the Operator requests export
  • Transaction and billing records are retained for 7 years as required for legal and accounting purposes
  • KYC verification documents are retained for the minimum period required by applicable compliance standards, then securely deleted
  • Anonymized, aggregated analytics data may be retained indefinitely

 

7. International Data Transfers

7.1 Brandmerce is based in the United States. Processing of Personal Data under this DPA takes place in the United States and in other countries where Brandmerce’s authorized sub-processors operate.

 

7.2 Where Personal Data originates from the EEA, UK, or other jurisdictions with data transfer restrictions, Brandmerce will implement appropriate safeguards as required by applicable law, which may include:

 

  • Standard Contractual Clauses (SCCs) as approved by the European Commission
  • UK International Data Transfer Agreements (IDTAs)
  • Other transfer mechanisms recognized under applicable law

 

7.3 Operators with EEA or UK-based members should contact privacy@brandmerce.com to execute applicable transfer documentation.

 

8. Security Incident Notification

8.1 Brandmerce will notify the Operator without undue delay — and in any event within 72 hours of becoming aware — of a confirmed Security Incident affecting Personal Data processed under this DPA.

 

8.2 Notification will include, to the extent known at the time:

 

  • A description of the nature of the Security Incident
  • Categories and approximate number of Data Subjects and records affected
  • Likely consequences of the Security Incident
  • Measures taken or proposed to address the incident and mitigate its effects

 

8.3 The Operator is responsible for notifying affected Data Subjects and relevant supervisory authorities as required by applicable Data Protection Law. Brandmerce will provide reasonable assistance in that process.

 

9. Confidentiality of Processing

Brandmerce will keep all Personal Data processed under this DPA strictly confidential and will not disclose it to any third party except:

 

  • To authorized sub-processors as listed in Schedule A
  • As required by applicable law, court order, or regulatory authority
  • As expressly instructed in writing by the Operator

 

10. Governing Law

This DPA is governed by the same governing law as the Operator Agreement (the laws of the State of Florida). For Operators subject to GDPR or UK GDPR, the parties agree to supplement this DPA with applicable Standard Contractual Clauses or equivalent transfer mechanisms upon request.

 

11. Order of Precedence

In the event of any conflict or inconsistency between this DPA, the Operator Agreement, and Brandmerce’s general Terms of Service:

 

  1. This DPA controls for all data protection matters
  2. The Operator Agreement controls for all other commercial matters
  3. The Terms of Service apply as a general baseline

 

Schedule A — Authorized Sub-Processors

The following sub-processors are authorized by Operators upon execution of this DPA. Brandmerce will provide at least 30 days’ notice before adding or replacing sub-processors.

 

Sub-ProcessorPurposeCountryPrivacy Reference
Supabase, Inc.Database hosting and user authenticationUnited Statessupabase.com/privacy
Stripe, Inc.Payment processing and subscription managementUnited Statesstripe.com/privacy
Resend, Inc.Transactional and notification email deliveryUnited Statesresend.com/legal/privacy-policy
Apple Inc.iOS app distributionUnited Statesapple.com/legal/privacy
Google LLCAndroid app distribution; Google Places API for business profile enrichmentUnited Statespolicies.google.com/privacy

 

Schedule B — Security Measures Summary

Brandmerce implements the following technical and organizational security measures:

 

Technical Measures

 

  • HTTPS/TLS encryption for all data in transit
  • Encryption at rest for database storage
  • Private, access-controlled storage buckets for KYC documents with signed URL expiry
  • Multi-factor authentication required for administrative access
  • Automated session expiry and token rotation

 

Organizational Measures

 

  • Role-based access controls — staff access to Personal Data limited to what is necessary for their role
  • Confidentiality obligations for all personnel with access to Personal Data
  • Regular security reviews of platform infrastructure
  • Incident response procedures with documented escalation paths

 

Infrastructure

 

  • Platform infrastructure hosted on Supabase (PostgreSQL) with row-level security policies
  • All data storage within United States-based cloud infrastructure

 

12. Contact

Data protection inquiries and DPA execution requests: Privacy Officer: privacy@brandmerce.com Brandmerce, LLC · Nocatee, Florida

BranStory is a product of Brandmerce, LLC. © 2026 Brandmerce, LLC. All Rights Reserved.

 

Note to Operators: This DPA is provided as a standard addendum to all Operator Agreements. If your organization requires a countersigned DPA for your own compliance records, contact privacy@brandmerce.com to request a countersigned copy. If you are subject to GDPR or UK GDPR and require Standard Contractual Clauses, contact us to initiate that process.

 

We'd love to give you a live demo– just reach out.

Kindly complete the form in this section. Please note that we engage with network operators that are established with a minimum of 250+ members in their network/community.

We appreciate you taking the time to inquire about launching your own branded operating system– powered by

  • info@brandmerce.com

  • Nocatee-Ponte Vedra, FL

Contact Form (New)