Legal

Data Processing Terms

Last updated: 1 September 2026

1. Roles and scope

For personal data an Operator submits about its own customers, the Operator is controller and Memberra is processor. Memberra is an independent controller for Operator account, security, platform billing and legal-compliance data. These terms form part of the Memberra Terms of Service.

2. Instructions and purpose

Memberra processes end-customer identity, subscription, payment-status, support, provisioning and configured analytics data only to provide, secure and support the service, on the Operator’s documented instructions and as required by law. The Operator is responsible for lawful collection, notices, instructions and its customer-facing policies.

3. Confidentiality and security

Access is limited to authorised personnel and service providers subject to confidentiality duties. Memberra maintains proportionate technical and organisational measures including encryption in transit, access controls, tenant isolation, audit logging, encrypted secrets, backups and incident procedures.

4. Subprocessors and transfers

Memberra may use infrastructure, authentication, payments, communications and support subprocessors described in the Privacy Policy. Appropriate UK transfer safeguards will be used where required. Operators may contact [email protected] for the current list or to raise a reasoned objection to a material new subprocessor.

5. Assistance and incidents

Taking account of the nature of processing, Memberra will reasonably assist with data-subject requests, security, breach assessment, DPIAs and regulator consultations. Memberra will notify the Operator without undue delay after becoming aware of a personal-data breach affecting Operator-controlled data.

6. Return, deletion and audit

On termination or documented instruction, Memberra will delete or return Operator-controlled personal data within a reasonable period unless retention is legally required. Archived billing and audit records may be retained where necessary for legal claims, fraud prevention, tax or accounting. On reasonable request, Memberra will provide information needed to demonstrate compliance; intrusive audits require advance notice, confidentiality and proportionate scope.

7. US privacy laws

Where an applicable US state law treats Memberra as a service provider, processor or contractor, Memberra will not sell or share Operator customer data for cross-context behavioural advertising, will process it only for the contracted business purpose, and will provide assistance reasonably required for applicable consumer requests.