Data Processing Agreement

GDPR Article 28 DPA for business users and third parties.

Updated May 5, 2026 Version 1.0

This Data Processing Agreement ("DPA") is entered into between Spencer's Website ("Controller") and business users, third-party service providers, or entities accessing data through our Service ("Processor") in compliance with Article 28 of the EU General Data Protection Regulation (GDPR).

Who This Applies To: This DPA applies to business accounts, API access, third-party integrations, and any entity that processes personal data on behalf of Spencer's Website or accesses user data through our Service.

1. Introduction

This DPA governs the processing of personal data by the Processor on behalf of the Controller. It ensures compliance with GDPR requirements for data processing relationships.

By accessing user data through our Service, using our API, or integrating with our platform, you agree to be bound by this DPA.

2. Parties to Agreement

  • Controller: Spencer's Website, operating at thespencerwebsite.com
  • Processor: The business user, third-party service provider, or entity accessing data through our Service

3. Scope of Processing

The Processor shall process personal data only as necessary to provide services to the Controller, including:

  • API access to user data (for authorized business accounts)
  • Integration with third-party services
  • Analytics and reporting services
  • Customer support services
  • Any other processing expressly authorized by the Controller

4. Controller Obligations

The Controller shall:

  • Determine the purposes and means of processing personal data
  • Ensure that processing is lawful, fair, and transparent
  • Provide the Processor with documented instructions for processing
  • Obtain necessary consents from data subjects
  • Maintain records of processing activities
  • Implement appropriate technical and organizational measures

5. Processor Obligations

The Processor shall:

  • Process personal data only on documented instructions from the Controller
  • Ensure that persons authorized to process personal data are committed to confidentiality
  • Implement appropriate technical and organizational measures to ensure security
  • Not engage another processor without prior written authorization from the Controller
  • Assist the Controller with data subject rights requests (access, deletion, portability)
  • Assist the Controller with compliance with GDPR obligations
  • Delete or return all personal data upon termination of this agreement
  • Allow the Controller or an independent auditor to audit compliance

6. Data Subject Rights

The Processor shall assist the Controller in fulfilling its obligations to respond to data subject rights requests, including:

  • Right to access
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object

7. Data Security

The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Pseudonymization and encryption of personal data
  • Confidentiality and integrity of processing systems
  • Ability to restore availability and access to personal data in a timely manner
  • Regular testing of technical and organizational measures

8. Subprocessing

The Processor shall not engage another processor without prior specific or general written authorization from the Controller. The Processor shall provide the Controller with sufficient information to allow the Controller to give prior authorization.

If the Processor engages another processor, it shall impose the same data protection obligations as set out in this DPA.

9. Term and Termination

This DPA shall remain in effect for the duration of the processing relationship and thereafter until all personal data has been deleted or returned.

Upon termination, the Processor shall immediately delete or return all personal data to the Controller and delete existing copies unless required by law to retain the personal data.

10. Governing Law

This DPA shall be governed by the laws of the European Union and the Member State where the Controller is established.

11. Contact

For questions about this DPA or data processing arrangements, contact us:

Email: support@thespencerwebsite.com

Subject line: "Data Processing Agreement Inquiry"