RaffleX
Toggle sidebar

Data Processing Agreement

Data Processing Agreement

Version 1.0. Last updated: 9 July 2026

This Data Processing Agreement (the "DPA") forms part of the agreement between RaffleX and its customers and sets out the terms on which RaffleX processes personal data on the customer's behalf, as required by Article 28 of the UK GDPR.

1. Parties and background

This DPA is entered into between:

(1) GFNI Ltd, a company registered in Northern Ireland (company number NI677326) whose registered office is at 55-59 High Street, Space Antrim, Floor 1, Office 13, Antrim, County Antrim, Northern Ireland, BT41 4AY, trading as "RaffleX" ("RaffleX" or the "Processor"); and

(2) the customer identified in the Principal Agreement (the "Customer" or the "Controller").

Background:

  • RaffleX operates a multi-tenant software-as-a-service platform at rafflex.io that enables the Customer to run competitions, prize draws and raffles.
  • In providing the Services, RaffleX processes personal data on behalf of the Customer. This DPA governs that processing and forms part of the Principal Agreement.

2. Definitions

"Data Protection Laws" means all laws applicable to the processing of personal data under this DPA, including the UK GDPR; the Data Protection Act 2018; the Data (Use and Access) Act 2025 ("DUAA"); the Privacy and Electronic Communications Regulations 2003 ("PECR"); and any associated codes of practice and guidance issued by the Information Commissioner's Office ("ICO"), each as amended or replaced.

"UK GDPR", "controller", "processor", "sub-processor", "personal data", "processing", "data subject", "personal data breach" and "special category data" have the meanings given in Data Protection Laws.

"Principal Agreement" means the agreement for the Services between the parties into which this DPA is incorporated, being the RaffleX DIY Platform Terms and Conditions (or the RaffleX Expert or Pro terms, as applicable), together with the RaffleX Compliance Guidelines.

"Services" means the RaffleX platform and related services provided under the Principal Agreement.

"Customer Personal Data" means personal data that RaffleX processes on behalf of the Customer under the Principal Agreement, as described in Annex 1.

"Sub-Processor List" means the current list of authorised sub-processors published at rafflex.io/sub-processors, as updated from time to time.

"Restricted Transfer" means a transfer of Customer Personal Data to, or access from, a country outside the United Kingdom that is not covered by UK adequacy/data-bridge regulations.

3. Roles of the parties

3.1 In respect of Customer Personal Data, the Customer is the controller and RaffleX is the processor.

3.2 Where RaffleX processes personal data for its own business purposes (including the Customer's own account, billing and relationship data, and platform security, fraud-prevention, audit, and service-improvement data), RaffleX acts as an independent controller and its own Privacy Policy applies to that processing.

3.3 Each party is responsible for its own compliance with Data Protection Laws. Nothing in this DPA relieves the Customer of its obligations as controller, including establishing a lawful basis, providing privacy information to data subjects, obtaining any consent required under PECR for electronic marketing, and handling data subject rights requests.

4. RaffleX's processing obligations

4.1 Processing on documented instructions. RaffleX shall process Customer Personal Data only on the Customer's documented instructions (including those set out in this DPA, Annex 1, the Principal Agreement, and configuration and instructions given by the Customer through the platform), unless required to do otherwise by law, in which case RaffleX shall inform the Customer of that legal requirement before processing, unless the law prohibits it. If RaffleX considers that an instruction infringes Data Protection Laws, it shall inform the Customer without undue delay.

4.2 Confidentiality. RaffleX shall ensure that persons authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality and process the data only as instructed.

4.3 Security. RaffleX shall implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against a personal data breach, as required by Article 32 of the UK GDPR. The measures currently in place are described in Annex 2.

4.4 Assistance with data subject rights. Taking into account the nature of the processing, RaffleX shall assist the Customer by appropriate technical and organisational measures, insofar as possible, to fulfil the Customer's obligations to respond to requests by data subjects exercising their rights under Chapter III of the UK GDPR. RaffleX shall promptly forward to the Customer any such request it receives directly relating to Customer Personal Data, and shall not respond to it itself except on the Customer's instructions or as required by law.

4.5 Assistance with security, breaches and impact assessments. Taking into account the nature of processing and the information available to it, RaffleX shall assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the UK GDPR, including security of processing, personal data breach notification, data protection impact assessments, and prior consultation with the ICO.

4.6 Personal data breach. RaffleX shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and shall provide the Customer with sufficient information to enable it to meet its own breach-reporting obligations under Articles 33 and 34 of the UK GDPR.

5. Sub-processors

5.1 The Customer grants RaffleX general written authorisation to engage sub-processors to process Customer Personal Data, subject to this clause. The sub-processors authorised at the date of this DPA are set out in the Sub-Processor List.

5.2 RaffleX shall enter into a written contract with each sub-processor imposing data protection obligations that are no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each sub-processor's obligations.

5.3 RaffleX shall give the Customer at least 30 days' prior notice of any intended addition or replacement of a sub-processor by updating the Sub-Processor List, which the Customer should check periodically. The Customer may object on reasonable, data-protection-related grounds within 30 days of notice. The parties shall work together in good faith to resolve the objection; if it cannot be resolved, the Customer may terminate the affected part of the Services.

6. International transfers

6.1 RaffleX hosts Customer Personal Data in the United Kingdom and/or the European Economic Area (currently on Amazon Web Services in the eu-west-1 region, Ireland). Transfers of personal data from the UK to the EEA are permitted on the basis of the UK's adequacy/data-bridge regulations for the EEA.

6.2 Where RaffleX or any sub-processor makes a Restricted Transfer, it shall ensure that an appropriate transfer mechanism is in place (such as UK adequacy/data-bridge regulations, the ICO International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses), consistent with the data protection test introduced by the DUAA. The transfer mechanism applicable to each sub-processor is stated in the Sub-Processor List.

7. Deletion and return of data

On termination or expiry of the Principal Agreement, the Customer may download its Customer Personal Data as a CSV file for 30 days after termination, extended by a further 7 days where any outstanding fees are paid before the initial 30-day period expires (this download right may not apply where the agreement is terminated for non-payment). After that period, RaffleX will delete the Customer's tenant database and all backups of the Customer's data, and no copies will be kept, save where retention is required by law. Deletion is carried out in accordance with the RaffleX Data Retention & Deletion Policy.

8. Audit and information

RaffleX shall make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR, and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Audits are subject to reasonable prior notice, appropriate confidentiality undertakings, and reasonable limits on frequency and scope. RaffleX may satisfy an audit request in the first instance by providing its policies, security documentation and any available third-party assessments or certifications.

9. Liability

The liability of each party under or in connection with this DPA is subject to the exclusions, limitations and financial caps set out in the Principal Agreement.

10. Term, precedence and governing law

10.1 This DPA takes effect on the effective date of the Principal Agreement and remains in force for as long as RaffleX processes Customer Personal Data.

10.2 If there is a conflict between this DPA and the Principal Agreement in relation to the processing of personal data, this DPA prevails.

10.3 This DPA is governed by the law of Northern Ireland, and the courts of Northern Ireland have exclusive jurisdiction, consistent with the Principal Agreement.


Annex 1: Details of the processing

Item Detail
Subject matter Provision of the RaffleX competitions and prize-draw platform to the Customer.
Duration The term of the Principal Agreement, plus the applicable retention periods in the Data Retention & Deletion Policy.
Nature and purpose Hosting, storage and processing of entrant and customer data to operate competitions, including account registration, entry, facilitation of payment, running draws and selecting winners, sending transactional notifications, and (only where the Customer enables it) sending abandoned-basket marketing emails on the Customer's behalf; and providing customer support.
Categories of data subjects The Customer's site visitors, registered users, competition entrants and prize winners; and the Customer's own staff who use the platform.
Categories of personal data Identity (name); contact details (email address, postal address, telephone number); account credentials; date of birth / age (only where the Customer enables age collection); entry and order history; marketing preferences; a gateway-issued payment token only (card payments are captured off-platform by the tenant's own payment gateway, for example Cashflows or another provider, and RaffleX never receives or stores full card details); technical data (IP address, device and browser data, cookie identifiers).
Special category data None is required or intended. The Customer must not submit special category data through free-text or custom fields.
Children's data The Services are intended for adults (18+). Where the Customer enables date-of-birth or age collection, the Customer is responsible for age-gating and for compliance with children's-data obligations, including UK GDPR Article 25 as amended by the DUAA.

Annex 2: Technical and organisational measures

Measure Description
Encryption in transit All connections to the platform are encrypted using TLS 1.2 or higher; HTTP Strict Transport Security (HSTS) is enforced.
Encryption at rest Databases, object storage and backups are encrypted at rest using industry-standard AES-256 encryption.
Access control Access to systems and data is granted on a least-privilege, need-to-know basis, with multi-factor authentication and unique credentials. Administrative access to the core databases and cloud infrastructure is tightly restricted to authorised personnel only, with periodic access review and credential/key rotation.
Tenant isolation Each tenant's data is stored in its own separate, dedicated database, distinct from every other tenant's. Tenant databases are distributed across multiple database servers, so one Customer's data is kept isolated from another's at the database level rather than only by row-level filtering.
Network and edge security Web application firewall, DDoS mitigation, bot management, rate limiting and IP/ASN-based controls at the edge; segregated production networks; restricted administrative access.
Application security Secure development practices, dependency and patch management, controlled deployment pipeline, and code review.
Logging and monitoring Centralised logging with infrastructure monitoring and automated alerting for anomalous activity.
Backups and resilience Encrypted backups taken at least weekly and retained on a rolling cycle (up to 90 days); high-availability and auto-scaling configuration to support continuity of service.
Payment security Card payments are captured off RaffleX servers by the tenant's own payment gateway; RaffleX stores only a gateway-issued token and holds no cardholder data. PCI DSS compliance for card processing rests with the gateway provider and the merchant, and RaffleX's environment is outside the cardholder-data scope.
Vulnerability management Regular vulnerability scanning (including PCI approved-scanning-vendor scans) and remediation.
Incident response A documented incident-response process, including notification to affected controllers without undue delay.
Personnel Staff are bound by confidentiality obligations and access personal data only on a need-to-know basis.
Secure deletion Data is securely deleted by dropping the tenant database and deleting the tenant's backups, so that no copies are kept after the offboarding window; residual copies of in-life deletions expire as the backup cycle rotates.

Annex 3: Authorised sub-processors

The current list of authorised sub-processors is maintained on our Sub-Processors page.