Cover Page
| Provider | PerkSpring, Inc. |
| Services | Privacy-preserving member verification platform |
| Data Processing | SHA-256 hashed email addresses (pseudonymized personal data) |
| Processing Purpose | Member verification between membership organizations and retailers |
| Data Subjects | Members of partner membership organizations |
| Applicable Law | UK GDPR / EU GDPR / CCPA as applicable |
| Sub-Processors | /legal/sub-processors |
| Erasure SLA | 30 days from request (Article 17) |
| Breach Notification | 72 hours from discovery (Article 33) |
| Data Retention | Hashed data retained until erasure requested or partnership terminated |
| Technical Measures | Per-org salted SHA-256 hashing, TLS in transit, encrypted at rest (Neon), role-based access control |
Standard Terms Incorporation
This DPA incorporates Common Paper's Standard DPA Terms v1.1, including post-Schrems II Standard Contractual Clauses (EU Implementing Decision 2021/914), UK GDPR Addendum, and CCPA service provider language.
Full Standard Terms: commonpaper.com/standards/data-processing-agreement
Contact
For DPA execution, contact legal@perkspring.com