This is PRIMA's standard data processing addendum. It applies to every customer of the PRIMA platform without amendment.
This Data Processing Addendum (“DPA”) forms part of, and is incorporated by reference into, the Restaurant Group Agreement, Partner Agreement or other written or electronic agreement between PRIMA VIP INC., a Delaware corporation with its principal place of business at 2045 Biscayne Blvd, Unit #495, Miami, Florida 33137, United States (“PRIMA”), and the customer that has accepted that agreement (the “Customer”) (the “Agreement”).
This DPA takes effect on the Customer’s acceptance of the Agreement, and applies to all processing of Personal Data carried out under the Agreement, including processing carried out before the date of this DPA’s publication or the Customer’s countersignature of it. Where the Agreement contains a data protection clause, this DPA replaces it in full.
A Customer that requires a countersigned instrument may execute the Signature Schedule at the end of this DPA. Execution is optional; it does not alter the terms.
Where this DPA conflicts with the Agreement, this DPA prevails. Where this DPA conflicts with the Standard Contractual Clauses incorporated under Sections 12 and 21, those Clauses prevail.
Personal Data flows between PRIMA and the Customer in two legally distinct streams, which this DPA keeps separate throughout:
Different obligations, retention periods, transfer clauses and rights attach to each stream. Annex I identifies precisely which data falls into which.
Personal Data that PRIMA has collected directly from its own registered users (“PRIMA User Data”) is outside both streams and outside this DPA. Section 14.6 addresses what happens where the same individual appears both as a PRIMA user and in the Customer’s records.
1.1 “Data Protection Law” means all laws applicable to the processing of Personal Data under the Agreement, including Regulation (EU) 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and any national implementing legislation including the French Loi Informatique et Libertés.
1.2 “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing” and “Supervisory Authority” have the meanings given in Article 4 GDPR.
1.3 “Operational Data” (Stream A) means Personal Data that PRIMA processes on the Customer’s behalf in order to operate the Platform, as described in Annex I, Part A.
1.4 “Shared Guest Data” (Stream B) means the categories of Personal Data exhaustively listed in Annex I, Part B, which the Customer discloses to PRIMA for the Permitted Purposes. Shared Guest Data excludes special categories of Personal Data within Article 9 GDPR and excludes free-text staff notes.
1.5 “Permitted Purposes” means the purposes for which PRIMA may process Shared Guest Data as an independent Controller, being: operating, personalising, securing and improving the PRIMA network and its services; identity resolution and the matching of demand to supply across the network; the generation of recommendations, personalised results and ranking, and the development, training, evaluation and improvement of the analytical and machine learning models that produce them; attribution, reconciliation and settlement of transactions; fraud prevention and abuse detection; and the production of aggregate insight and Derived Data. The Permitted Purposes do not include the sale of Shared Guest Data, its disclosure to third parties other than PRIMA’s Sub-processors, or cross-context behavioural advertising.
1.6 “Derived Data” means data created by PRIMA from Operational Data or Shared Guest Data which has been irreversibly altered such that no Data Subject is identifiable, directly or indirectly, by PRIMA or by any other person, taking account of all means reasonably likely to be used, and from which re-identification is not possible by PRIMA using any key, salt, mapping table or other information within its possession or control. Pseudonymised data, including data keyed by hashed or tokenised identifiers that PRIMA is able to resolve to an individual, is not Derived Data and remains Personal Data.
1.7 “Sub-processor” means any third party engaged by PRIMA to process Operational Data.
1.8 “SCCs” means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
1.9 “Customer Establishment” means the EEA Member State in which the Customer is established or, where the Customer is not established in the EEA but the processing is subject to the GDPR, Ireland.
1.10 “PRIMA User Data” means Personal Data relating to a person who has registered with, or otherwise provided their Personal Data directly to, PRIMA. PRIMA is the Controller of PRIMA User Data by virtue of its own collection of it. PRIMA User Data is neither Operational Data nor Shared Guest Data, and this DPA does not apply to it.
2.1 The Customer is Controller and PRIMA is Processor in respect of Operational Data.
2.2 PRIMA shall not process Operational Data for its own purposes. PRIMA’s use of Personal Data originating from the Customer for PRIMA’s own purposes is confined to Shared Guest Data under Part II and to Derived Data under Section 20.
2.3 The Parties acknowledge Article 28(10) GDPR, under which a processor that determines the purposes and means of processing becomes a Controller in respect of that processing. Part II exists so that PRIMA’s own use of Personal Data is lawful, transparent and documented.
3.1 PRIMA shall process Operational Data only on the Customer’s documented instructions, including in relation to international transfers, unless required to do otherwise by Union or Member State law to which PRIMA is subject, in which case PRIMA shall inform the Customer of that requirement before processing unless the law prohibits it on important grounds of public interest.
3.2 The Agreement, this DPA and Annex I constitute the Customer’s complete documented instructions. Further instructions shall be given in writing.
3.3 PRIMA shall immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
PRIMA shall ensure that every person authorised to process Operational Data is subject to an appropriate statutory or contractual duty of confidentiality, and that access is limited to those personnel who require it in order to perform PRIMA’s obligations under the Agreement.
5.1 PRIMA shall implement and maintain the technical and organisational measures set out in Annex II, having regard to Article 32 GDPR. Annex II describes both PRIMA’s current production environment and the target environment to which PRIMA is migrating, together with the date of that migration.
5.2 PRIMA may update those measures from time to time provided that the overall level of security is not reduced.
6.1 PRIMA does not ingest, and shall not ingest, special categories of Personal Data within Article 9 GDPR from the Customer’s systems. In particular, PRIMA’s connectors exclude dietary requirements, food allergies and intolerances, and accessibility and mobility requirements, together with free-text staff notes and reservation comments in which such information may appear.
6.2 Exclusion is applied at the point of ingestion, so that such data is not transmitted to, received by, or stored on PRIMA’s systems.
6.3 If PRIMA becomes aware that data within Section 6.1 has been received in error, it shall delete that data without undue delay and shall notify the Customer.
6.4 Should the Parties wish PRIMA to process such data, they shall agree a written amendment to this DPA and to Annex I before any such processing begins.
7.1 The Customer grants PRIMA general written authorisation to engage Sub-processors, subject to this Section.
7.2 The Sub-processors engaged as at the effective date of this DPA are listed in Annex III. The Customer authorises them by accepting the Agreement.
7.3 PRIMA shall notify the Customer of any intended addition or replacement of a Sub-processor at least thirty (30) days before that Sub-processor begins processing Operational Data. Notification is given by email to the Customer’s data protection contact on file, and by publication of the updated list at https://primaapp.com/subprocessors. The Customer may object on reasonable data protection grounds within that period. If the Parties do not resolve an objection within thirty (30) days of it being raised, the Customer may terminate the Agreement in respect of the affected services without penalty and with a pro-rata refund of prepaid fees.
7.4 PRIMA shall impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this Part, and remains fully liable to the Customer for each Sub-processor’s performance.
8.1 Taking into account the nature of the processing, PRIMA shall assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer’s obligation to respond to requests under Chapter III GDPR.
8.2 If PRIMA receives a request directly from a Data Subject relating to Operational Data, it shall not respond substantively but shall forward the request to the Customer without undue delay and in any event within three (3) business days.
8.3 PRIMA shall provide this assistance at no additional charge, save where requests are manifestly excessive in volume.
9.1 PRIMA shall notify the Customer of any Personal Data Breach affecting Operational Data without undue delay and in any event within forty-eight (48) hours of becoming aware of it, so as to enable the Customer to meet its own obligation under Article 33 GDPR.
9.2 The notification shall describe, to the extent known: the nature of the breach and the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed; and a point of contact. Where the information is not all available at once, PRIMA shall provide it in phases without undue delay.
9.3 PRIMA shall not make any public statement identifying the Customer in connection with a Personal Data Breach without the Customer’s prior written consent, save where required by law.
9.4 PRIMA shall provide reasonable assistance to the Customer with data protection impact assessments and prior consultations under Articles 35 and 36 GDPR.
10.1 On termination or expiry of the Agreement, PRIMA shall, at the Customer’s election, delete or return all Operational Data and delete existing copies, within thirty (30) days of the Customer’s instruction, unless Union or Member State law requires storage.
10.2 If the Customer gives no election within thirty (30) days of termination, PRIMA shall delete.
10.3 PRIMA shall provide written certification of deletion within fifteen (15) days of completing it.
10.4 Where deletion from backup media is not immediately practicable, PRIMA shall isolate the data from active processing and delete it on the ordinary backup expiry cycle, which does not exceed ninety (90) days.
10.5 This Section does not apply to Shared Guest Data, which is retained under Section 16, or to Derived Data, which is retained under Section 20. PRIMA shall retain a suppression record sufficient to give effect to Section 17.4 notwithstanding deletion under this Section.
11.1 PRIMA shall make available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR.
11.2 The Customer may audit PRIMA’s compliance once in any twelve-month period, on thirty (30) days’ written notice, during business hours, without unreasonable disruption to PRIMA’s operations and subject to confidentiality undertakings. Additional audits may be conducted following a Personal Data Breach affecting the Customer’s Operational Data, or at the documented direction of a Supervisory Authority.
11.3 PRIMA may satisfy an audit request in whole or in part by providing a current independent third-party assessment report covering the relevant controls, where such a report addresses the Customer’s questions.
11.4 Each Party bears its own costs of an audit and the Customer bears PRIMA’s reasonable costs of supporting one, except where the audit identifies a material breach of this DPA by PRIMA, in which case PRIMA bears its own costs.
12.1 Operational Data is transferred to and processed in the locations set out in Annex I, Part D.
12.2 The SCCs are incorporated into this DPA by reference and apply to all transfers of Operational Data from the European Economic Area to PRIMA, as follows:
12.3 For transfers subject to the UK GDPR, the SCCs apply as modified by the UK International Data Transfer Addendum (version B1.0). For transfers subject to Swiss law, references to the GDPR are read as references to the Swiss Federal Act on Data Protection and the competent authority is the Federal Data Protection and Information Commissioner.
12.4 Notwithstanding any governing law or dispute resolution provision in the Agreement, the SCCs and any dispute arising under them are governed by the law of the Customer Establishment and subject to the jurisdiction of its courts. Nothing in the Agreement limits any Data Subject’s rights as a third-party beneficiary under Clause 3 of the SCCs.
12.5 PRIMA shall notify the Customer without undue delay if it becomes unable to comply with the SCCs, or if it receives a legally binding request from a public authority for disclosure of Personal Data originating from the Customer, to the extent permitted by law.
12.6 A transfer impact assessment is provided at Annex IV.
12.7 European data residency. PRIMA commits that,
from 31 October 2026, all Operational Data and all
Shared Guest Data relating to Data Subjects in the European Economic
Area shall be stored and processed at rest in the Amazon Web Services
Europe (Paris) eu-west-3 region. Until that date,
processing takes place in the locations set out in Annex I, Part D,
under the SCCs incorporated above. PRIMA shall publish notice on
completion of the migration and shall issue an updated Annex I, Part D
and Annex III. The SCCs continue to apply after migration in respect of
remote administrative access to European data from outside the European
Economic Area.
PRIMA shall designate a representative in the Union pursuant to Article 27 GDPR by 30 September 2026 and shall publish that representative’s name, address and contact details at https://primaapp.com/privacy. PRIMA’s contact point for data protection matters is prima@primavip.co.
14.1 The Customer discloses Shared Guest Data to PRIMA as one independent Controller to another. PRIMA is not a Processor in respect of Shared Guest Data, and the Parties are not joint Controllers.
14.2 Each Party determines the purposes and means of its own processing of Shared Guest Data and is separately responsible for its own compliance.
14.3 PRIMA shall process Shared Guest Data only for the Permitted Purposes and in accordance with PRIMA’s published privacy notice at https://primaapp.com/privacy.
14.4 The categories of Shared Guest Data are exhaustively listed in Annex I, Part B. PRIMA shall not treat any other Personal Data as Shared Guest Data. Additional categories may be added only by written agreement between the Parties.
14.5 Shared Guest Data does not include, and PRIMA shall not receive into Stream B, any special category of Personal Data within Article 9 GDPR.
14.6 PRIMA users appearing in the Customer’s records. Where PRIMA places a reservation on behalf of one of its own registered users, that user’s Personal Data will ordinarily be recorded in the Customer’s reservation and guest management systems as a consequence of that reservation, and may subsequently be returned to PRIMA through the synchronisation described in Annex I. Such data remains PRIMA User Data. It does not become Shared Guest Data, and does not become subject to this DPA, merely because it also appears in the Customer’s systems or in a feed from them. PRIMA continues to process it as Controller on the basis on which it was originally collected.
14.7 No rights acquired. The Customer acquires no right, licence or interest in PRIMA User Data by reason of a PRIMA user making or fulfilling a reservation at a Participating Restaurant. The Customer becomes an independent Controller of the Personal Data that PRIMA discloses to it in order to place and fulfil that reservation, and processes that data for its own purposes on its own basis; nothing in this DPA restricts either Party’s processing of that data as Controller in its own right.
14.8 Where PRIMA cannot determine whether a record originates from the Customer or from PRIMA’s own collection, PRIMA shall treat it as Shared Guest Data and apply Part II to it.
15.1 The Customer warrants that it has a valid lawful basis under Article 6 GDPR for the disclosure of Shared Guest Data to PRIMA for the Permitted Purposes, and that it will maintain that basis throughout the term.
15.2 The Customer warrants that, before or at the time of disclosure, it has provided Data Subjects with the information required by Article 13 GDPR, including: that their data is disclosed to PRIMA; the identity of PRIMA as a recipient and independent controller; the Permitted Purposes; the fact of transfer outside the European Economic Area and the safeguard relied upon; and the retention position under Section 16.
15.3 The Customer shall identify PRIMA in its privacy notice and shall provide PRIMA with a link to that notice on request.
15.4 Where the Customer relies on legitimate interests, it shall conduct and retain a legitimate interests assessment and provide a copy to PRIMA on request.
15.5 The Customer shall notify PRIMA without undue delay if a Data Subject objects to or withdraws consent for the disclosure, or if the Customer’s lawful basis ceases to apply.
15.6 PRIMA shall not be required to accept Shared Guest Data in respect of which the Customer has not satisfied this Section, and may suspend receipt of Stream B without prejudice to the remainder of the Agreement.
16.1 PRIMA shall provide Data Subjects with the information required by Article 14 GDPR in respect of Shared Guest Data, within one month of receipt or at the time of first communication with the Data Subject, whichever is the earlier, save where an exemption under Article 14(5) applies and PRIMA has documented its reliance on it.
16.2 PRIMA shall handle Data Subject requests relating to Shared Guest Data directly and in its own right, and shall respond within the statutory period. PRIMA shall notify the Customer of any request that indicates a failure of the Customer’s obligations under Section 15.
16.3 PRIMA shall apply to Shared Guest Data the technical and organisational measures set out in Annex II.
16.4 PRIMA shall notify the Customer of any Personal Data Breach affecting Shared Guest Data within forty-eight (48) hours, notwithstanding that PRIMA notifies the Supervisory Authority in its own right.
16.5 PRIMA shall not sell Shared Guest Data, shall not use it for cross-context behavioural advertising, and shall not disclose it to any third party other than its Sub-processors and professional advisers, or as required by law.
16.6 Retention. Section 10 does not apply to Shared Guest Data. PRIMA retains Shared Guest Data as Controller for as long as necessary for the Permitted Purposes, and termination or expiry of the Agreement does not of itself require deletion.
16.7 PRIMA shall review the continued necessity of retention at intervals of no more than twenty-four (24) months and shall delete Shared Guest Data that is no longer necessary for the Permitted Purposes.
16.8 Section 16.6 is subject at all times to the rights of Data Subjects under Articles 17 and 21 GDPR, which PRIMA shall honour in its own right.
16.9 On termination the Customer may request that PRIMA cease further processing of Shared Guest Data for the Permitted Purposes. PRIMA shall confirm within thirty (30) days whether it accepts the request. PRIMA is not obliged to accept it, PRIMA’s retention resting on PRIMA’s own lawful basis, and the Customer’s remedy in respect of individual guests lies in the exercise of Data Subject rights under Section 16.8.
17.1 PRIMA shall maintain a mechanism by which a Data Subject may object to PRIMA’s processing of their Shared Guest Data.
17.2 On a valid objection under Article 21 GDPR, PRIMA shall cease processing for the Permitted Purposes unless it demonstrates compelling legitimate grounds which override the interests, rights and freedoms of the Data Subject.
17.3 On a valid erasure request under Article 17 GDPR, PRIMA shall erase the Shared Guest Data of that Data Subject.
17.4 PRIMA shall maintain a suppression record sufficient to ensure that data erased, or in respect of which an objection has been upheld, is not re-ingested from any subsequent feed.
18.1 PRIMA uses automated processing, including profiling within the meaning of Article 4(4) GDPR, to generate recommendations, personalised results and ranking for guests, and to develop and improve the models that produce them. PRIMA discloses this processing in the information it provides under Article 14.
18.2 No decisions with legal or similarly significant effect. This processing determines which offers, venues and availability a Data Subject is shown. It does not produce legal effects concerning any Data Subject, nor does it similarly significantly affect any Data Subject, and it is therefore not a decision within Article 22(1) GDPR. PRIMA shall not use Shared Guest Data to make any decision within Article 22(1) without first agreeing that processing with the Customer in writing and establishing a lawful basis for it.
18.3 No inference of special categories. PRIMA shall not use Shared Guest Data to infer, derive or assign any characteristic within Article 9 GDPR, including health, dietary or religious characteristics, and shall not use any such inferred characteristic in recommendation, ranking or model development. PRIMA shall apply technical controls designed to prevent the reconstruction, from venue or cuisine data, of information excluded under Section 6.
18.4 Model development. PRIMA shall use Derived Data for model training wherever the purpose can be achieved with it. Where model training requires Shared Guest Data, PRIMA shall use the minimum data necessary and shall not retain training corpora containing Shared Guest Data for longer than is necessary for the purpose.
18.5 Effect of erasure and objection. Where a Data Subject exercises rights under Section 17, PRIMA shall erase or cease processing that Data Subject’s Shared Guest Data, remove it from any training corpus under PRIMA’s control, and exclude it from subsequent model training. PRIMA does not represent that a model already trained can be reverted in respect of an individual, and shall address any residual effect at the next ordinary retraining cycle.
18.6 The right to object under Section 17 applies to the profiling described in this Section.
19.1 PRIMA may send a Data Subject offers, promotions and other marketing communications relating to the PRIMA network only in accordance with this Section.
19.2 In-application communications. Where a Data Subject is a registered user of a PRIMA application or surface, PRIMA may present offers, recommendations and personalised results to that Data Subject within that surface, as part of the service the Data Subject has requested.
19.3 PRIMA’s own users. This Section does not restrict PRIMA’s electronic marketing to Data Subjects whose contact details constitute PRIMA User Data. Where a Data Subject has provided their contact details to PRIMA directly, in the course of registering for, enquiring about or purchasing a PRIMA service, PRIMA may send them electronic marketing relating to PRIMA’s own similar services on its own lawful basis, subject to a clear and free means of opting out both at the point of collection and in every communication. Section 14.6 applies: such a Data Subject does not cease to be a PRIMA user, and PRIMA does not lose that basis, because they have also dined at a Participating Restaurant.
19.4 Marketing to Data Subjects sourced from the Customer. PRIMA shall not send electronic marketing by email, SMS or other electronic means to a Data Subject whose contact details were obtained from the Customer unless that Data Subject has given prior consent to receive electronic marketing from PRIMA, meeting the standard required by Article 4(11) and Article 7 GDPR and by applicable national law implementing Directive 2002/58/EC.
19.5 How consent is evidenced. Where the Customer collects such consent, it shall:
(a) present the consent request separately from any other terms, in a form that names PRIMA expressly as a recipient and identifies the purpose;
(b) transmit, with each affected record in Stream B, a marketing consent indicator together with the date, time, wording version and capture point of the consent; and
(c) retain evidence of the consent and provide it to PRIMA on request.
19.6 PRIMA shall treat any record not carrying a valid consent indicator as not consented, and shall exclude it from electronic marketing. Absence of the indicator is determinative.
19.7 The Customer shall notify PRIMA without undue delay of any withdrawal of consent, and PRIMA shall give effect to the withdrawal without undue delay and in any event within seventy-two (72) hours.
19.8 PRIMA shall include a functioning opt-out mechanism in every electronic marketing communication and shall maintain a permanent suppression record of opted-out Data Subjects.
19.9 Nothing in this Section permits PRIMA to send electronic marketing on the Customer’s behalf or in the Customer’s name. Any such campaign is separate processing requiring the Parties’ written agreement.
20.1 PRIMA may create Derived Data from Operational Data and from Shared Guest Data, and owns all Derived Data outright. PRIMA may use, retain and commercialise Derived Data for any lawful purpose, without limit of time and notwithstanding termination of the Agreement.
20.2 Derived Data is not Personal Data. Sections 3 to 19 do not apply to it.
20.3 PRIMA shall not attempt, and shall not permit any third party to attempt, to re-identify any Data Subject from Derived Data.
20.4 The Customer acknowledges that Derived Data may be created from data relating to its guests and that the Customer has no proprietary claim to it. PRIMA acknowledges that Derived Data does not include, and shall not be used to reconstitute, the Customer’s guest list.
21.1 The SCCs are incorporated into this DPA by reference and apply to all transfers of Shared Guest Data from the European Economic Area to PRIMA, as follows:
21.2 Sections 12.3 and 12.7 apply equally to Shared Guest Data.
22.1 Each Party’s liability under this DPA is subject to the limitations of liability in the Agreement, save that nothing limits either Party’s liability to a Data Subject or a Supervisory Authority, or any liability that cannot lawfully be limited.
22.2 The Customer shall indemnify PRIMA against claims, fines and reasonable costs arising from the Customer’s breach of Section 15.
22.3 PRIMA shall indemnify the Customer against claims, fines and reasonable costs arising from PRIMA’s breach of Section 16 or Section 17.
22.4 PRIMA may update this DPA from time to time. PRIMA shall give the Customer at least thirty (30) days’ notice of any update that materially reduces the Customer’s rights or PRIMA’s obligations, and the Customer may object in accordance with Section 7.3. Updates required by a change in Data Protection Law take effect on the date required by that law.
22.5 This DPA continues for as long as PRIMA processes Personal Data originating from the Customer.
22.6 If any provision of this DPA is held invalid, the remainder continues in force. If Section 16.6 is held unenforceable, Sections 16.7 to 17.4 and Section 20 survive.
Categories of Data Subjects. Guests and prospective guests of the Customer who hold a record in the Customer’s reservation and guest management systems; and employees of the Customer who use the Platform or whose identifiers appear in reservation records.
Categories of Personal Data.
| Category | Fields |
|---|---|
| Identity | Given name, family name, salutation |
| Contact | Email address, telephone number |
| Reservation | Date, time, party size, venue, status, source or channel, table assignment |
| Transaction | Check value, payment status, no-show and cancellation history |
| Profile | Guest tags, VIP status, membership status |
| Preferences | Seating and service preferences, excluding any dietary or accessibility information |
| Technical | Device or application identifiers, IP address, timestamps |
Special categories of Personal Data (Article 9 GDPR). None. PRIMA does not ingest dietary, allergen or accessibility information, or free-text staff notes, in accordance with Section 6.
Nature and purpose of processing. Receipt, storage, structuring, matching and retrieval of reservation and guest records for the purposes of operating the Platform; creating, confirming, amending and cancelling reservations; confirming fulfilment of reservations for the calculation and settlement of fees payable under the Agreement; reconciliation and dispute resolution; and provision of the reporting required by the Agreement.
Duration. For the term of the Agreement and thirty (30) days thereafter, subject to Section 10.
Frequency. Continuous, by ongoing synchronisation with the Customer’s reservation and guest management systems, together with an initial historical backfill of the period agreed at onboarding.
This list is exhaustive. Any Personal Data not listed here is Operational Data.
| Category | Fields |
|---|---|
| Pseudonymous identifier | PRIMA-issued guest identifier |
| Identity | Given name, family name |
| Contact | Email address and telephone number, in hashed form where technically feasible |
| Reservation history | Venue, date, time, party size, status, channel |
| Transaction history | Check value band, currency, fulfilment status |
| Derived attributes | Visit frequency, recency, venue category affinity |
| Model-derived attributes | Recommendation, ranking, propensity and affinity scores generated by PRIMA’s analytical and machine learning models |
| Marketing consent record | Consent indicator, together with the date, time, wording version and capture point of the consent, where provided by the Customer under Section 19.5 |
Expressly excluded from Stream B. All special categories of Personal Data within Article 9 GDPR, including dietary, allergen and accessibility information; free-text staff notes and reservation comments; payment instrument data; date of birth; and any field not listed above.
Permitted Purposes. As defined in Section 1.5.
PRIMA’s lawful basis. Legitimate interests under Article 6(1)(f) GDPR, namely PRIMA’s interest in operating, securing and improving a demand-matching network for the benefit of guests, venues and partners, including the generation of recommendations and the development of the models that produce them. PRIMA has conducted and retains a legitimate interests assessment, available to the Customer on request.
Electronic marketing. Legitimate interests is not relied upon for electronic marketing to Data Subjects whose contact details originate from the Customer. That processing rests on the Data Subject’s prior consent, obtained and evidenced in accordance with Section 19.
Retention. As set out in Section 16.
The competent Supervisory Authority of the Customer Establishment.
Current environment, until 31 October 2026
| Component | Provider | Location |
|---|---|---|
| Application | DigitalOcean App Platform | United States — New York (NYC1, NYC3) |
| Primary database (PostgreSQL) | DigitalOcean Managed Databases | United States — New York (NYC1) |
| Secondary database (PostgreSQL) | Supabase, on Amazon Web Services | United States — Northern Virginia (us-east-1) |
| Cache and queue (Valkey) | DigitalOcean Managed Databases | United States — New York (NYC1) |
| Object storage | DigitalOcean Spaces | United States — New York (NYC3) |
| Web front end | Vercel | Global edge network; origin in the United States |
| DNS, WAF and content delivery | Cloudflare | Global edge network |
All storage and processing of Personal Data currently takes place in the United States, in the New York and Northern Virginia regions.
Target environment, from 31 October 2026
| Component | Provider | Location |
|---|---|---|
| All storage and processing of Personal Data relating to Data Subjects in the EEA | Amazon Web Services | Europe (Paris), eu-west-3 |
| Administrative and support access | PRIMA personnel | United States and Canada, under the SCCs |
This Annex describes two environments. Part 1 states the measures in force today, in the environment where Personal Data is processed at the effective date of this DPA. Part 2 states the measures of the target environment, to which PRIMA is migrating on the timetable in Section 12.7. PRIMA warrants that Part 1 is accurate as at the effective date and that Part 2 will be accurate on completion of the migration.
A. Access control. Access to production infrastructure and to production databases is limited to two named individuals: PRIMA’s Chief Technology Officer and its Head of Engineering. Multi-factor authentication is enforced on all administrative consoles, including the cloud platform, database, hosting, edge and source code repository consoles. Access is by named account; shared accounts are not used.
B. Network. The application is served over TLS 1.2 or higher behind the Cloudflare Web Application Firewall, with IP-based rate limiting and bot mitigation. The managed database cluster is restricted to trusted sources and is not addressable from the public internet.
C. Encryption. All data is encrypted in transit using TLS. All data is encrypted at rest by the managed database, object storage and platform services, using AES-256. Credentials are held as platform-managed environment variables, scoped per environment.
D. Payment data. PRIMA does not store payment card data. Card data is handled entirely by Stripe, and PRIMA’s systems never receive a primary account number. PCI DSS scope rests with Stripe.
E. Secure development and change management. All commits are cryptographically signed. Automated malware scanning runs on every push. Automated code review is applied to every pull request. Two-person review is mandatory before any change reaches production; direct-to-production deployment is disabled. Internal penetration testing is conducted on a regular cycle.
F. Independent validation. PRIMA does not hold SOC 2 Type II or ISO/IEC 27001 certification. PRIMA has not to date commissioned an independent third-party penetration test; one is scheduled for 30 November 2026, following completion of the migration described in Part 2, so that it assesses the environment in which Customer data will reside. PRIMA will provide the resulting report, or an executive summary of it, to Customers on request.
G. Logging and monitoring. Application errors and exceptions are captured centrally. Platform system and audit logs are retained for ninety (90) days.
H. Resilience. The managed database is backed up automatically with point-in-time recovery. Backups are retained for between thirty (30) and ninety (90) days. Recovery point objective: twenty-four (24) hours. Recovery time objective: four (4) to eight (8) hours for full application and database recovery. Documented business continuity and disaster recovery plans are maintained and available on request.
I. Organisational measures. All personnel are subject to written confidentiality obligations. PRIMA maintains documented policies covering access control and privileged access management, secure software development and change management, vulnerability management, data loss prevention, vendor risk management, incident response, business continuity and disaster recovery. Security awareness training is provided to all personnel every six (6) months, commencing August 2026. Copies of policies are available to Customers on request.
A. Access control and identity. Federated single sign-on via SAML 2.0 to AWS Identity Center; no service handles passwords directly. Privileged access to production infrastructure and data remains limited to two named individuals. Application interfaces are authorised per route by a custom authorizer that resolves opaque bearer tokens to a verified identity; tokens are stored only as hashes, in a store encrypted with a customer-managed key. Authorisation is group-based, with an access-domain axis enforced at query level.
B. Network and infrastructure. The primary database is an Amazon Aurora PostgreSQL cluster reachable exclusively through the RDS Data API over TLS. It has no inbound security-group rule, no open socket and no reachable network surface; access is mediated by IAM and AWS Secrets Manager. A Web Application Firewall is attached to the public interface, applying IP-based rate limiting and the AWS managed common rule set in enforcing mode. Object storage has all public access blocked and versioning enabled.
C. Encryption and key management. TLS for all external and internal service communication. Customer-managed KMS keys with automatic rotation protect the database, object storage and audit logs. Credentials are held in AWS Secrets Manager. Signing keys for third-party service integrations are generated inside KMS and never exist outside it. No long-lived cloud credentials exist in the deployment pipeline: continuous integration authenticates by GitHub OIDC to a role scoped to a single action on a single resource prefix.
D. Logging and monitoring. Full API-level audit logging across all cloud accounts, written to a dedicated store encrypted with a customer-managed key and protected against deletion.
E. Independent validation. An independent third-party penetration test of the target environment is scheduled for 30 November 2026.
F. Data residency. All Personal Data relating to
Data Subjects in the European Economic Area is stored and processed at
rest in the Europe (Paris) eu-west-3 region.
G. Retained measures. The measures in Part 1, Sections D, E, H and I continue to apply.
| Sub-processor | Purpose | Contracting entity and location | Transfer mechanism |
|---|---|---|---|
| DigitalOcean, LLC | Application hosting, managed PostgreSQL, managed Valkey, object storage | United States (New York) | SCCs |
| Supabase, Inc. | Secondary PostgreSQL database and authentication | United States (Northern Virginia) | SCCs |
| Amazon Web Services, Inc. | Cloud platform (target environment) and model inference via Amazon Bedrock | United States; Europe (Paris) from 31 October 2026 | SCCs |
| Vercel Inc. | Front-end hosting and edge delivery | United States and global edge | SCCs |
| Cloudflare, Inc. | DNS, Web Application Firewall, content delivery | Global edge | SCCs |
| Stripe, Inc. and Stripe Payments Europe Ltd | Payment processing and payouts | United States and Ireland | SCCs; Ireland adequate |
| Twilio Inc. | Transactional SMS | United States | SCCs |
| SimpleTexting, LLC | Transactional SMS, regional routing | United States | SCCs |
| ClickSend Pty Ltd (Sinch group) | Transactional SMS, regional routing | Level 8, 150 Lonsdale Street, Melbourne, Victoria 3000, Australia | SCCs |
| Mailgun Technologies, Inc. (Sinch group) | Transactional email | 112 E Pecan St, Suite 1135, San Antonio, TX 78205, United States | SCCs |
| Functional Software, Inc. (Sentry) | Error and exception monitoring | United States | SCCs |
Customer reservation systems. Where PRIMA accesses a reservation or guest management system operated by the Customer, that system’s provider is the Customer’s processor and not a Sub-processor of PRIMA. PRIMA accesses the Customer’s tenancy under credentials that the Customer provides and may revoke at any time.
Model inference. Where PRIMA uses large language models, inference is executed through Amazon Bedrock within PRIMA’s own Amazon Web Services account, under IAM-scoped and audit-logged access. Prompt and completion content is not retained by, nor used to train the models of, the model provider. Amazon Web Services is the Sub-processor for this activity; the model provider is not, and no Personal Data originating from the Customer is transmitted to any model provider’s own application programming interface.
1. The transfers. Personal Data is transferred from the European Economic Area to the United States. Stream A is a Controller-to-Processor transfer; Stream B is a Controller-to-Controller transfer. The categories of data and Data Subjects are as set out in Annex I. No special categories of Personal Data are transferred.
2. The mechanisms relied upon. The SCCs, Module Two for Stream A and Module One for Stream B, in each case under the law of the Customer Establishment. From 31 October 2026, Personal Data relating to Data Subjects in the European Economic Area is stored and processed at rest within the European Economic Area, so that the transfer is confined to remote administrative access.
3. Assessment of United States law. PRIMA is a reservations and demand-matching platform. It does not provide electronic communications services to the public and does not consider itself an “electronic communication service provider” within the meaning of 50 U.S.C. § 1881(a), and therefore does not consider itself subject to directives under Section 702 of the Foreign Intelligence Surveillance Act. PRIMA has assessed the potential application of Executive Order 12333 and of the Clarifying Lawful Overseas Use of Data Act and considers the risk to the categories of data transferred to be low, having regard to the nature of that data, which is commercial reservation information containing no special category data.
4. Onward access from third countries. Privileged administrative access to production systems is held by two named individuals, located in the United States and in Canada. Canada benefits from a European Commission adequacy decision in respect of commercial organisations subject to PIPEDA, so access from Canada does not constitute a transfer requiring an additional safeguard.
5. Practical experience. PRIMA has never received a request from any government authority for access to Personal Data originating from a Customer, and has never disclosed such data to any government authority.
6. Supplementary measures. Encryption in transit and at rest, with keys under PRIMA’s sole control. Access to production data limited to two named individuals subject to multi-factor authentication. A documented policy of challenging any government access request that appears unlawful or overbroad, and of notifying the Customer to the fullest extent permitted by law. Migration of European Personal Data to the Europe (Paris) region by 31 October 2026.
7. Conclusion. Taking the mechanisms and supplementary measures together, PRIMA considers that the transfers afford a level of protection essentially equivalent to that guaranteed within the European Economic Area. PRIMA reviews this assessment annually and on any material change in law or circumstances.
Execution of this Schedule is not required for this DPA to apply. It is provided for Customers whose internal policies require a countersigned instrument.
For the purposes of Annex I.A of the Standard Contractual Clauses.
| Field | Detail |
|---|---|
| Registered legal entity name | |
| Legal form | |
| Company registration number | |
| Registered office address | |
| Customer Establishment (Member State) | |
| Data protection contact | |
| Reservation or guest management system(s) in scope | |
| Historical backfill period |
Signed for and on behalf of
PRIMA VIP INC.
Signed for and on behalf of
the Customer
End of PRIMA Data Processing Addendum, Version 1.0.
© 2026 PRIMA · Members-only access