Data Processing Agreement

Last updated: July 4, 2026

Effective date: July 4, 2026 · Version: v1

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Trizbit Private Limited ("PerksClub", "we", "us"), a company incorporated in India, and you — the business that uses PerksClub Business (together, the "Agreement"). It applies whenever we process personal data about your own customers, end users, or other individuals on your behalf in providing PerksClub Business to you. We serve businesses worldwide, and this DPA is written to meet data-protection laws globally. If this DPA and the rest of the Agreement conflict about how we handle that personal data, this DPA controls.

1. How this DPA works (roles)

  • For personal data about your customers and end users that you collect or process through PerksClub, you are the controller and we are your processor. Where you are yourself a processor acting for someone else, we act as your sub-processor. This DPA governs that processing.
  • For a limited set of data we handle for our own purposes — such as your account and business data, billing, security and fraud prevention, product analytics and improvement, and legal compliance — we act as an independent controller, governed by our Privacy Policy, not this DPA.
  • "Applicable Data Protection Laws" means all data-protection, privacy, and similar laws anywhere in the world that apply to this processing — including the EU/EEA GDPR, the UK GDPR and Data Protection Act, the Swiss FADP, India's Digital Personal Data Protection Act, 2023, the California CCPA/CPRA and other US state privacy laws, and any others now or later in force. Terms such as "personal data", "controller", "processor", "data subject", and "processing" have the meaning given in those laws.

2. Your instructions

We process personal data only on your documented instructions — which include this DPA, the Agreement, your configuration and use of the features, and any further written instructions you give — unless the law requires otherwise (in which case we tell you, unless the law prohibits it). We will let you know if, in our opinion, an instruction breaches Applicable Data Protection Laws. You are responsible for the accuracy and legality of your instructions and of the data you route through the platform.

3. What we process (broad and future-proof)

The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are described in Annex 1. Because the platform is broad and evolving, the processing covers everything reasonably needed to provide, secure, support, and improve PerksClub Business for you, and anything else you instruct or configure — and it may grow as we add features, while staying within the purpose of providing the Services to you.

4. Confidentiality

We ensure that anyone we authorise to process the personal data is bound by an appropriate duty of confidentiality and processes it only as needed to provide the Services.

5. Security

We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, and unauthorised disclosure or access — appropriate to the risk. These include, as relevant, encryption in transit and at rest, access controls and least-privilege, network protections, logging and monitoring, resilience and backups, secure development, and incident response, as summarised in Annex 2. We may update our measures as technology and threats evolve, provided we do not materially reduce the overall level of protection.

6. Sub-processors

You give us general authorisation to engage sub-processors (including our affiliates and third-party providers) to help provide the Services. We:

  • maintain a current list of sub-processors, available on request (and at our published legal pages once available);
  • impose data-protection obligations on each sub-processor essentially equivalent to those in this DPA;
  • remain responsible for our sub-processors' performance of those obligations; and
  • give you reasonable notice of any new or replacement sub-processor before it starts processing, so you can object on reasonable data-protection grounds. If you object and we cannot offer a reasonable alternative, you may stop using the affected feature or end the affected part of the Agreement as your remedy.

7. International data transfers

We and our sub-processors may process personal data in the United States, India, and other countries as we expand or as our providers operate. Where a transfer is a "restricted transfer" under Applicable Data Protection Laws, we ensure an appropriate safeguard applies — such as an adequacy decision, the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, the Swiss addendum, or another lawful transfer mechanism — and, where those clauses are required, they are incorporated into this DPA by reference and completed by the parties' details and Annex 1. If a mechanism is invalidated or changes, we will adopt an alternative lawful mechanism.

8. Assisting you with data-subject requests

Taking into account the nature of the processing, we help you respond to requests from data subjects to exercise their rights (such as access, correction, deletion, restriction, objection, and portability) through appropriate technical and organisational measures and the features of the platform. If we receive a request directly, we will not respond to it except on your instruction or as legally required, and — where permitted — we will forward it to you without undue delay.

9. Assisting you with compliance

Taking into account the nature of the processing and the information available to us, we help you meet your obligations around security, breach notification, data-protection impact assessments, and prior consultation with authorities.

10. Personal-data breaches

If we become aware of a personal-data breach affecting personal data we process for you, we will notify you without undue delay, provide the information reasonably available to help you meet your own notification duties, and take reasonable steps to mitigate and remediate.

11. Return and deletion

On the end of the Services (or earlier at your written request), we will, at your choice, delete or return the personal data we process for you and delete existing copies — except to the extent we are required by law to keep it, in which case we keep it protected and process it only as the law requires.

12. Audits and information

We will make available the information reasonably necessary to demonstrate our compliance with this DPA, and allow and contribute to audits, including inspections, by you or an auditor you mandate. To respect confidentiality, security, and scale, audits happen on reasonable prior notice, no more than once a year (unless required by an authority or following a breach), during business hours, without unreasonable disruption, and we may satisfy audit requests by providing third-party certifications or reports (such as SOC 2 or ISO 27001) where available.

13. United States — service-provider terms

Where the CCPA/CPRA or another US state privacy law applies, we act as your "service provider" / "processor". We will not "sell" or "share" the personal data, will not retain, use, or disclose it except to provide the Services (or as those laws otherwise permit), will not combine it with data from other sources except as permitted, and we certify that we understand and will comply with these restrictions. These terms apply equally under other US state privacy laws (for example Virginia, Colorado, Connecticut, Utah, and Texas) and any that come into force later.

14. India — processor terms

Where India's Digital Personal Data Protection Act, 2023 applies, we process personal data as a Data Processor engaged by you under this valid contract, only for providing the Services, and we assist you with data-principal rights and grievance redressal and with security safeguards and breach intimation.

15. Your responsibilities

You represent and warrant that: you have a lawful basis and have given all required notices and obtained all required consents for the personal data you route through PerksClub; your instructions comply with Applicable Data Protection Laws; and you will meet your own obligations as controller. You are responsible for the personal data you choose to collect and for how you configure the platform.

16. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement (including the liability cap), and the DPA and the Agreement are treated as one for that purpose. Nothing in this DPA limits any liability that cannot be limited under Applicable Data Protection Laws, or affects data subjects' rights.

17. Term

This DPA applies for as long as we process personal data for you under the Agreement. Provisions that by their nature should survive termination (including confidentiality, transfers, deletion, audits, and liability) survive.

18. Governing law and disputes

This DPA is governed by, and disputes are resolved under, the governing-law and dispute-resolution terms of the Agreement (the laws of India; arbitration seated in India, administered by the MCIA under the MCIA Rules) — except where Applicable Data Protection Laws or an incorporated transfer mechanism (such as the Standard Contractual Clauses) require a different governing law or forum, in which case that requirement prevails for what it covers, and data subjects keep the rights those mechanisms give them.

19. Changes and precedence

If there is a conflict about the processing of personal data, this DPA prevails over the rest of the Agreement, and any incorporated Standard Contractual Clauses (or other transfer mechanism) prevail over this DPA for restricted transfers. We may update this DPA where reasonably needed to keep it aligned with Applicable Data Protection Laws or our Services, without materially reducing your protections. Notices about this DPA: legal@perksclub.tech.

Annex 1 — Details of processing

  • Controller: you (the business using PerksClub Business). Processor: Trizbit Private Limited (PerksClub).
  • Subject matter: our processing of personal data on your behalf to provide PerksClub Business.
  • Duration: the term of the Agreement, plus any legally required retention.
  • Nature and purpose: hosting and storing data; operating your engagement activities, coupons, offers, and campaigns; issuing and validating codes; delivering communications you initiate; providing analytics and reporting to you; support; security and fraud prevention; and other processing needed to provide, maintain, and improve the Services for you, or that you instruct or configure.
  • Types of personal data (broad, as applicable to your use): identifiers and contact details (name, email, phone, username); customer/loyalty profile and preferences; coupons, rewards, transactions, and redemption records; device, technical, and usage data (including IP address and identifiers); approximate or precise location where enabled; images or content submitted (such as QR scans or uploads); communications and support content; marketing and analytics identifiers; and any other personal data you choose to process through the platform.
  • Categories of data subjects (broad): your customers, members, and end users; prospective customers and contacts; your staff or authorised users; and other individuals whose personal data you process through PerksClub.
  • Special categories: not intended — do not submit special-category data unless a feature expressly supports it and the law permits.

Annex 2 — Security measures (summary)

Encryption of personal data in transit and at rest; access controls, authentication, and least-privilege; separation and stricter controls for sensitive records; network and application security; logging, monitoring, and alerting; resilience, backup, and recovery; secure software development and change management; vendor and sub-processor security diligence; personnel confidentiality and training; and incident detection and response. We may enhance these measures over time without materially reducing protection.

Annex 3 — Sub-processors

We use sub-processors in categories including cloud hosting and infrastructure, communications delivery (email/SMS), authentication, payments (if enabled), analytics and monitoring, support tooling, and our affiliates. A current list is available on request at legal@perksclub.tech (and at our published legal pages once available). We give reasonable notice of changes as described in §6.

Related agreements: Terms of Service · Privacy Policy · Early Access Agreement.

Operated by Trizbit Private Limited

support@perksclub.tech
Powered by PerksClub