Last updated: Aug 1, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between wiCreate Media Tech (“Winza”, the “Processor”) and the customer (“you”, the “Controller”). It applies whenever we process personal data on your behalf in the course of providing the Service, and it is incorporated automatically - no separate signature is required, though we are happy to countersign a copy on request.
Terms not defined here have the meaning given in the EU General Data Protection Regulation (“GDPR”), the UK GDPR, or equivalent applicable data protection law.
1. Roles of the parties
You are the Controller of the personal data you and your campaign participants submit to the Service. You determine the purposes and means of processing, decide what fields your campaign forms collect, and are responsible for having a lawful basis and for providing participants with the required privacy notices. Winza is the Processor and acts only on your documented instructions. Where we determine our own purposes - for example account administration, billing, and platform security - we act as an independent Controller under our Privacy Policy.
2. Subject matter and details of processing
| Element | Detail |
|---|---|
| Subject matter | Provision of the Winza gamified campaign platform and related support |
| Duration | The term of your subscription, plus the deletion window in section 9 |
| Nature and purpose | Hosting, storing, structuring, retrieving, analysing, and deleting campaign and participant data to deliver the Service |
| Categories of data subjects | Campaign participants, your employees and authorised users, and your agency partners |
| Categories of personal data | Identifiers (name, email, phone), campaign activity (entries, scores, prize claims), device and connection data (IP, user agent), and any additional fields you configure |
| Special category data | None. You must not configure the Service to collect special category or criminal offence data |
3. Processing instructions
We process personal data only on your documented instructions, which are given through the Terms, this DPA, your configuration of the Service, and any written instructions you send us. We will notify you if, in our opinion, an instruction infringes applicable data protection law, and may pause the affected processing until it is resolved. If we are required by law to process data beyond your instructions, we will inform you first unless the law prohibits that notice.
4. Confidentiality and personnel
Access to personal data is limited to personnel who need it to deliver or support the Service. Every person with access is bound by written confidentiality obligations that survive the end of their engagement, receives annual data protection and security training, and passes background screening where local law permits. Access is granted on a least-privilege basis, reviewed quarterly, and revoked within 24 hours of a role change or departure.
5. Security measures
We implement the technical and organisational measures required by Article 32 GDPR, including:
- Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256).
- Logical tenant isolation so one customer's campaign data is never readable by another.
- Multi-factor authentication, single sign-on, and role-based access control for administrative access.
- Continuous monitoring, centralised audit logging, and automated alerting on anomalous access.
- Encrypted, geographically redundant backups with documented restore testing.
- Annual penetration testing by an independent third party and a documented vulnerability management process.
- A business continuity and disaster recovery plan reviewed at least annually.
A fuller description, including our certifications and incident response process, is published on our Security page. We may update these measures over time provided the overall level of protection is not reduced.
6. Sub-processors
You give general authorisation for us to engage sub-processors. Each is bound by a written contract imposing data protection obligations no less protective than this DPA, and we remain fully liable for their performance.
We will give at least 30 days’ notice by email and on this page before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period; if we cannot offer a workaround, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees. To receive change notifications, subscribe at hello@winza.cc.
7. Assistance with data subject rights
The Service provides self-service tools to search, export, correct, and delete participant records so you can respond to access, rectification, erasure, restriction, portability, and objection requests yourself. If a data subject contacts us directly, we will not respond substantively but will forward the request to you within 5 business days. Where you need additional help, we will provide reasonable assistance taking into account the nature of the processing. We also assist with data protection impact assessments and prior consultations with supervisory authorities.
8. Return and deletion of data
You may export Customer Data at any time during your subscription. On termination, we make the data available for export for 30 days, then delete it from production systems within a further 30 days and from encrypted backups within 90 days as backup cycles expire. We will certify deletion in writing on request. We retain data beyond these periods only where required by law, and where we do, it remains protected by this DPA.
9. Personal data breach notification
We will notify you without undue delay, and in any case within 48 hours, of becoming aware of a personal data breach affecting your data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where full details are not immediately available, we provide them in phases as the investigation progresses. Notification is not an acknowledgement of fault.
10. Audits and evidence of compliance
On request, and no more than once per year, we provide our current third-party audit reports, penetration test summaries, and completed security questionnaires to demonstrate compliance. Where those are insufficient to satisfy a regulator or your own audit obligations, you may conduct an audit on 30 days’ written notice, during business hours, subject to confidentiality and to reasonable measures that avoid disrupting other customers. You bear the cost of an on-site audit unless it uncovers a material breach of this DPA.
11. Liability and precedence
Each party’s liability under this DPA is subject to the limitations set out in the Terms of Service. In the event of a conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms of Service, in each case only to the extent of the conflict and only for matters of data protection.
Contact us
Need a countersigned DPA, the SCCs, or our sub-processor change notifications? Email hello@winza.cc or write to wiCreate Media Tech, Legal Team, and we will respond within 30 days.
Related documents