Data processing agreement
Version 1.0 · In force from 28 September 2026 · Last updated 28 September 2026
When your organisation puts the details of staff, members or other people on cards, we handle those details for you. This agreement sets out how, as UK data protection law (UK GDPR Article 28) requires.
1. Who this agreement is between
This agreement is between:
- the organisation that uses Simplecard Business to create or order cards showing other people's personal data (“you”, the controller); and
- Valesta Group LTD, company number 14468408, registered office 60 Tottenham Court Road, Suite 5062a, Fitzrovia, London, W1T 2EW, United Kingdom (“we”, the processor).
It forms part of our terms and conditions of sale and applies from the moment you, or anyone acting for your organisation, first enters or uploads Card Data. It applies whether or not you go on to place an order. If this agreement and the terms of sale conflict on data protection, this agreement wins.
2. Words we use
- Data Protection Law means the UK GDPR, the Data Protection Act 2018 and any other data protection law that applies in the United Kingdom.
- Card Data means the personal data you or your users enter or upload to the service so that it can appear on cards, as described in Annex 1.
- “Controller”, “processor”, “personal data”, “processing”, “data subject”, “personal data breach” and “sub-processor” have the meanings given in Data Protection Law.
3. What this agreement covers
This agreement covers Card Data only. For the details of the people who use the service, such as account holders' names and email addresses, orders and payments, we are the controller. Our privacy notice explains how we use them.
4. Your responsibilities
You confirm that:
- you have a lawful basis under Data Protection Law for giving us the Card Data and for having it printed on cards;
- you have told the people concerned, as Articles 13 and 14 of the UK GDPR require, how their details will be used, including that they are shared with us for card production;
- the Card Data is accurate, and limited to what is needed for the cards;
- you will not give us special category data (such as health information) or criminal offence data unless we have agreed it with you in writing;
- where the cards are for people under 18, you have any permission needed from them or their parents or guardians; and
- the people using your organisation's account are authorised to give us instructions for you.
5. Our responsibilities as your processor
We will:
- Follow your instructions. We process Card Data only on your documented instructions, including about transfers outside the United Kingdom. Your instructions are this agreement, the terms of sale, and what you do in the service: the details you enter, the designs and proofs you approve, the orders you place and the data you delete. If the law requires us to do something else, we will tell you first unless the law forbids it. We will tell you straight away if we think an instruction breaks Data Protection Law.
- Keep it confidential. Everyone we authorise to handle Card Data is bound by confidentiality.
- Keep it secure. We take the technical and organisational measures required by Article 32 of the UK GDPR, described in Annex 2.
- Use sub-processors only as allowed. See section 6.
- Help you with people's rights. The service lets you view, correct and delete Card Data yourself. If someone asks us directly about Card Data, we will pass the request to you without undue delay and will not answer it ourselves unless you ask us to. We will help you answer requests, taking into account what we do and the information we have.
- Help you meet your other duties under Articles 32 to 36 of the UK GDPR: security, notifying breaches, data protection impact assessments and consulting the ICO, taking into account what we do and the information we have.
- Delete Card Data when we no longer need it, as described in section 9.
- Show that we comply. We will give you the information you reasonably need to show that we meet our duties under Article 28, and allow audits as described in section 8.
6. Sub-processors
You give us general permission to use the sub-processors listed on our sub-processors page. We will tell you at least 30 days before we add or replace a sub-processor that handles Card Data, by updating that page and emailing the owners of your organisation account. If you object on reasonable data protection grounds, tell us within that time. We will try to find a solution. If we cannot, you may stop using the service and close your account.
We make every sub-processor that handles Card Data agree in writing to data protection obligations that give the same protection as this agreement. We remain responsible to you for what our sub-processors do.
7. Personal data breaches
If we become aware of a personal data breach affecting Card Data, we will tell you without undue delay, and within 48 hours at the latest. We will give you the information required by Article 33(3) of the UK GDPR as far as we have it, and further information as it becomes available. We will take reasonable steps to limit the breach and its effects, and help you notify the ICO and the people affected where needed.
8. Information and audits
You can ask us questions about how we protect Card Data, and we will answer them. If you reasonably need more, for example because the ICO asks you, you or an independent auditor bound by confidentiality may audit our compliance with this agreement. You must give us at least 30 days' notice, and audits may take place no more than once a year unless there has been a breach. You pay for your own audit costs.
9. How long we keep Card Data and what happens at the end
We keep Card Data in your organisation's account while the account is open, so that you can reorder and add people. You can delete designs and people's details at any time. Some Card Data is deleted automatically, as set out in Annex 1.
A copy of the card details printed for each order is kept with the order records. We keep order records for six years after the end of the financial year of the order, to handle reprints, faults and disputes and to meet our legal obligations.
When you close your organisation's account, we will delete the Card Data in it within 30 days, apart from the order records described above and any data we must keep by law. If you want a copy of your Card Data before then, ask us and we will give it to you in a common format such as CSV.
10. Transfers outside the United Kingdom
We will not transfer Card Data outside the United Kingdom unless the transfer is covered by UK adequacy regulations, or by appropriate safeguards such as the ICO's International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses.
11. Responsibility
Each of us is responsible for complying with Data Protection Law in our own role. Any limits on liability in the terms of sale apply to this agreement, except where the law does not allow them to. Nothing in this agreement limits the rights that people have under Article 82 of the UK GDPR.
12. Changes, duration and law
This agreement lasts for as long as we process Card Data for you. Sections that by their nature should continue, such as deletion and confidentiality, continue after that.
We may update this agreement, for example when the law changes. We will tell organisation owners by email before a change that materially affects you takes effect. The version number and date are shown at the top of this page.
This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Annex 1: Details of the processing
- Subject matter
- Designing, proofing, printing and delivering identification and membership cards for you.
- Duration
- While you use the service, and afterwards for the periods in section 9.
- Nature of the processing
- Receiving Card Data that you type in or import (from spreadsheets and photo files), storing it, showing it in the editor, creating proofs and print files, printing the cards, sending the printed cards to the delivery address you give, keeping order records and deleting data.
- Purpose
- To produce the cards you order and let you manage and reorder them.
- People whose data is processed
- Your employees, contractors, volunteers, members, pupils or students, visitors and other people you choose to issue cards to. Some may be under 18.
- Types of personal data
- Names, job titles or roles, departments, staff, member or student numbers, photos, dates (such as issue, expiry or date of birth, if you add them), information in QR codes or barcodes, emergency contact details if you add them, and any other fields you choose to put on a card.
- Special category data
- None expected. Photos on cards are not used to identify people by biometric means. You must not add health or other special category information unless we have agreed it in writing.
- Automatic deletion
- Designs started without an account and never saved: 14 days. Uploaded photos not used in any design, card or order: 90 days. Uploaded spreadsheets and photo ZIP files: 30 days after the import finishes. Proofs that were never approved: 60 days. Print production files: 120 days. Earlier saved versions of a design: 30 days (the latest 50 are kept).
Annex 2: Security measures
- All connections to the service are encrypted with TLS (HTTPS).
- Session data is encrypted, and passwords are stored only as secure hashes.
- Uploaded files, proofs and print files are held in private storage that is never publicly accessible. Files are only served after checking that the person asking has permission.
- Access inside your organisation is controlled by roles (owner, designer, viewer).
- Our staff reach Card Data only through an admin area that needs two-step sign-in, with roles that limit what each person can do.
- Download links for print files expire after 15 minutes.
- Important actions, such as proof approvals, orders and changes to settings, are recorded in an audit trail.
- Uploaded files are checked for type and size before they are accepted.
- Data is deleted automatically on the schedule in Annex 1.
- Our servers are hosted in professionally managed data centres with physical access controls.
Annex 3: Sub-processors
The sub-processors you authorise are listed on our sub-processors page.