Legal

Data Processing Agreement

Last updated: 26 July 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Sketches Int Ltd ("Processor", "we", "us") and the business customer using VoucherMaker ("Controller", "you").

By creating an account, uploading recipient contact data, creating customer groups, or instructing email distribution of vouchers, you appoint us as processor and agree to this DPA. No separate signature is required for standard self-serve use.

1. Subject matter and duration

We process personal data on your behalf to provide list storage, campaign association, and email distribution (and related support) for as long as you use those features and thereafter for limited retention, deletion, and legal compliance as described in the Privacy Policy.

2. Nature and purpose of processing

Processing is limited to: storing recipient contact details you submit; associating contacts with campaigns; sending voucher emails on your documented instructions via the Service; recording delivery status; and providing related customer support and abuse prevention.

3. Types of data and data subjects

  • Data subjects: your customers, prospects, or other recipients whose details you upload or select
  • Personal data: email address; optional name; campaign and send metadata; and any other fields you choose to upload

You shall not instruct us to process special-category data unless expressly agreed in writing and permitted by law.

4. Controller responsibilities

You determine the purposes and means of processing recipient data, ensure you have a lawful basis, provide all necessary notices to data subjects, and ensure your instructions are lawful. You are responsible for the accuracy of data you submit and for the content of messages you instruct us to send.

5. Processor obligations

We shall:

  • process personal data only on documented instructions from you (including via the Service), unless required by law;
  • ensure persons authorised to process the data are bound by confidentiality;
  • implement appropriate technical and organisational security measures;
  • assist you, taking into account the nature of processing, with data-subject requests and with security, breach, and impact-assessment obligations to a reasonable extent;
  • delete or return personal data after end of services related to processing, subject to lawful retention needs; and
  • make available information reasonably necessary to demonstrate compliance with this DPA.

6. Sub-processors

You authorise us to engage sub-processors to deliver the Service. Categories include hosting/infrastructure, email delivery, payment infrastructure (where relevant to account operations), identity providers (where Sign-In is enabled), and print fulfilment partners where you order printed delivery and shipping details must be shared to complete the order.

Create with AI (where enabled) uses a third-party AI provider (currently OpenAI) to process design briefs and brand assets you submit. That processing relates to your campaign design inputs and is described in our Privacy Policy. Recipient contact lists you upload for email distribution are not sent to the AI provider for concept generation.

We remain responsible for sub-processor performance to the extent required by applicable law. We will impose data-protection obligations on sub-processors no less protective than those in this DPA, as appropriate to the service.

7. International transfers

Where personal data is transferred internationally, we will ensure an appropriate transfer mechanism is used where required by applicable law.

8. Security incidents

Upon becoming aware of a personal data breach affecting personal data we process under this DPA, we will notify you without undue delay and provide information reasonably available to help you meet your own notification obligations.

9. Audits

Upon reasonable written request, and no more than once per twelve (12) months unless a competent authority or confirmed breach requires otherwise, we will provide information or summaries reasonably necessary to demonstrate compliance. On-site audits, if required by mandatory law, shall be scheduled to minimise disruption and may be subject to reasonable confidentiality and security controls.

10. Liability

Liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where prohibited by applicable law.

11. Order of precedence

If there is a conflict between this DPA and the Terms regarding processing of Controller personal data under this DPA, this DPA prevails for that subject matter.

12. Contact

Sketches Int Ltd · hello@vouchermaker.io · Contact form

Welcome to Vouchermaker

Forgot password?

No account?

or
Continue with Google