Repark. Legal / DPA

Data Processing · Article 28 UK GDPR

Data Processing Agreement

The terms that govern personal data Repark processes on behalf of a business client — read alongside the service agreement, our Privacy Policy and our Data Protection Policy (available on request).

Version 1.1 Effective 2 August 2026

Agreement record ART. 28
ProcessorRepark LTD (“Repark”, “we”, “us”) · trading as G4GADGET
ControllerThe business client receiving our services (the “Client”, “you”)
Legal basisArticle 28, UK GDPR · Data Protection Act 2018
Governing lawEngland & Wales

01About this agreement

This Data Processing Agreement (“DPA”) applies where Repark LTD (“Repark”) provides order fulfilment, despatch or related services to a business client (the “Client”) and, in doing so, processes personal data on the Client’s behalf. It sets out the terms required by Article 28 of the UK GDPR for that relationship.

This DPA forms part of, and should be read together with, the service agreement between Repark and the Client. If there is a conflict about the processing of personal data, this DPA prevails.

Where Repark sells its own products through online marketplaces, it acts as an independent controller of the order data it receives — that processing is covered by our Privacy Policy, not this DPA.

02Roles and definitions

For the purposes of this DPA, the Client is the controller of the personal data it provides, and Repark is the processor, acting on the Client’s documented instructions. If the Client is itself a processor appointing Repark as a sub‑processor, the Client warrants that it has the controller’s authority to do so on these terms.

Words and phrases defined in the UK GDPR — including “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” — have the same meanings in this DPA. “UK GDPR” means the UK General Data Protection Regulation, read with the Data Protection Act 2018.

03Details of the processing

ItemDescription
Subject matterOrder fulfilment and despatch of physical goods on the Client’s behalf.
DurationThe term of the service agreement, plus the deletion period in section 11.
Nature and purposeReceiving order data; picking, packing, labelling and shipping orders via carriers; tracking, returns and related customer‑service support.
Types of personal dataRecipient name; delivery and, where provided, billing address; phone number; email address; order details (items, values, references); and, for some export destinations, a tax identifier where required by customs.
Categories of data subjectsThe Client’s customers — the recipients of orders.
Special category dataNone. It is not required for the services and must not be sent to us.

04Instructions and confidentiality

We will process the Client’s personal data only on the Client’s documented instructions — being the service agreement, this DPA and the order data the Client transmits to us — including as regards transfers outside the UK, unless we are required to process it by UK law, in which case we will inform the Client of that requirement before processing unless the law prohibits it.

We ensure that every person we authorise to process the Client’s data is committed to confidentiality. We will not use the data for our own purposes, and never for marketing.

05Security of processing

We apply technical and organisational measures appropriate to the risk, as required by Article 32 and as detailed in our Data Protection Policy (available to the Client on request), including:

06Sub‑processors

The Client gives general written authorisation for the sub‑processors listed below. We will give the Client notice of any intended addition or replacement, giving the Client the opportunity to object on reasonable grounds. We impose data‑protection obligations on every sub‑processor equivalent to those in this DPA, and we remain liable to the Client for their performance.

Sub‑processorPurposeLocation
Amazon Web ServicesHosting and database (with encrypted backups in the UK — London)Singapore, with backups in the UK (London) (under the IDTA / UK Addendum to the EU SCCs)
Shipping / courier carriersDelivery of orders (name, address and contact details only)UK and the destination country of each order
Google (Gmail SMTP)Transactional / operational emailUS / EEA, under the UK extension to the EU‑US Data Privacy Framework

07Assisting the Client

Taking into account the nature of the processing, we will assist the Client with appropriate technical and organisational measures, so far as this is possible, in responding to data subject rights requests (access, rectification, erasure, restriction, objection and portability). If a data subject contacts us directly, we will forward the request to the Client without undue delay and will not respond to it except on the Client’s instructions or where the law requires.

We will also assist the Client in meeting its obligations under Articles 32 to 36 of the UK GDPR — security, breach notification, data protection impact assessments and prior consultation — taking into account the nature of the processing and the information available to us.

08Personal data breaches

If we become aware of a personal data breach affecting the Client’s personal data, we will notify the Client without undue delay, and provide the information the Client reasonably requires for its own notification duties under Articles 33 and 34 — the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. We document all breaches and handle them under our Data Breach Notification & Incident Response Plan.

09International transfers

The Client’s personal data is hosted by AWS in its Singapore region. Because this is outside the UK, the transfer is protected by an appropriate safeguard — the International Data Transfer Agreement (IDTA) / UK Addendum to the EU Standard Contractual Clauses that forms part of AWS’s data-processing terms. We also hold encrypted backup copies in AWS Europe (London), within the United Kingdom, so a copy exists outside the live hosting region. In addition, carriers delivering orders internationally receive only the details needed to deliver each order to its destination. We keep a record of these transfers and their safeguards.

10Audits and information

We will make available to the Client the information necessary to demonstrate our compliance with Article 28, and will allow and contribute to audits or inspections conducted by the Client or an auditor it mandates — on reasonable prior notice, during business hours, no more than once in any 12‑month period (unless following a personal data breach or where required by a regulator), and subject to reasonable confidentiality undertakings.

11Return and deletion of data

At the end of the services, at the Client’s choice, we will delete or return all of the Client’s personal data and delete existing copies, unless UK law requires us to store it — for example accounting and transaction records — in which case we will protect and isolate that data from further processing until deletion is possible. We will certify deletion on request. In all cases, buyer personal data (recipient name, delivery and billing address, phone number and email address, and any file rendered from it such as shipping labels, invoices and packing documents) is deleted or irreversibly anonymised within 30 days of confirmed delivery, or from dispatch where no delivery confirmation is available. No buyer personal data is retained beyond 30 days. Transaction and accounting records, which contain no buyer name, address, phone number or email address, are kept for up to 6 years to meet UK tax and company-law obligations.

12General, law and contact

This DPA is governed by the law of England and Wales. Liability between the parties is as set out in the service agreement; nothing in this DPA excludes any liability that cannot be excluded by law.

Questions about this DPA: