Back to Home

Data Processing Agreement (DPA)

Last updated: July 24, 2026

1. Definitions

"Customer" refers to the entity that has entered into an agreement with GCNhub for API services.

"Processor" refers to GCNhub, which processes personal data on behalf of the Customer.

"Personal Data" has the meaning given in the GDPR and other applicable data protection laws.

"Sub-processor" means any third party engaged by GCNhub to assist in processing personal data on behalf of the Customer.

2. Roles and Responsibilities

The Customer acts as the data controller and GCNhub acts as the data processor.

GCNhub processes personal data only on documented instructions from the Customer, including with regard to transfers of personal data to a third country, unless required by applicable law.

The Customer is responsible for ensuring that it has a valid legal basis for the processing and for complying with its obligations as a controller under applicable data protection laws, including providing necessary privacy notices and obtaining consents from data subjects.

3. Processing Activities

GCNhub processes personal data for the following purposes on behalf of the Customer:

  • Operating the API platform and fulfilling gift card orders initiated by the Customer's end users.
  • Maintaining API access logs and transaction records for security, billing, and compliance.
  • Providing support and technical maintenance of the Service.

4. Sub-processors

GCNhub engages sub-processors to support the delivery of the Service (e.g., cloud hosting, email delivery, payment processing).

GCNhub remains liable for the performance of its sub-processors to the same extent as if it were performing the services itself.

A current list of sub-processors is available upon request. GCNhub will notify the Customer of any intended changes to sub-processors, giving the Customer the opportunity to object.

5. Security Measures

GCNhub implements and maintains appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256).
  • SOC 2 Type II certified infrastructure with annual third-party audits.
  • Regular vulnerability assessments and penetration testing.
  • Role-based access controls with least-privilege enforcement and multi-factor authentication.
  • Incident response procedures with documented escalation paths.
  • Employee training on data protection and security awareness.

6. Data Subject Rights

GCNhub will assist the Customer in responding to data subject requests (e.g., access, rectification, erasure, restriction, portability) by providing the necessary information and tools within a reasonable timeframe.

If GCNhub receives a data subject request directly, it will forward it to the Customer without responding, unless required by law.

7. Personal Data Breach Notification

GCNhub will notify the Customer without undue delay (and in any case within 72 hours) upon becoming aware of a personal data breach affecting the Customer's data.

The notification will include the nature of the breach, the likely consequences, and the measures taken or proposed to address it and mitigate its effects.

GCNhub will cooperate with the Customer in fulfilling any breach notification obligations to supervisory authorities and data subjects.

8. Audit Rights

GCNhub will make available to the Customer all information necessary to demonstrate compliance with this DPA.

The Customer may, at its own cost, conduct an audit or instruct a qualified third-party auditor to do so, subject to reasonable confidentiality obligations and at least 30 days' prior notice.

GCNhub's SOC 2 Type II report is available annually and may satisfy audit requirements without the need for on-site audits.

9. Data Return and Deletion

Upon termination of the Service or at the Customer's request, GCNhub will return or delete all personal data processed on behalf of the Customer, except where storage is required by applicable law.

Any data retained for legal compliance will be held securely and processed only for the purpose of complying with the applicable legal obligation, then deleted upon expiration of the retention period.

10. International Data Transfers

If personal data is transferred outside the EEA, UK, or Switzerland, GCNhub will ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or other valid transfer mechanisms approved by the relevant supervisory authority.

11. Governing Law

This DPA is governed by the same governing law as the underlying agreement between the Customer and GCNhub.

12. Contact

For questions about this DPA or to request the list of sub-processors, please contact our Data Protection Officer at dpo@gcnhub.com.