Santa for Teams · santaai.site

Data Processing Agreement

Last updated September 15, 2026

When your company shares your team’s email addresses with us to deliver Santa gifts, we process them on your behalf. This agreement sets out how, as Article 28 of the GDPR and the UK GDPR require. It is part of our Terms of Sale and applies to every Santa for Teams order.

1. Parties and roles

This Data Processing Agreement (“DPA”) forms part of the Santa for Teams Terms of Sale at santaai.site/en/for-teams/terms. It is between the company named on the invoice (the “Customer”, acting as controller) and the seller named on the same invoice (the “Provider”, acting as processor): A24Z LTD, 128 City Road, London, EC1V 2NX, United Kingdom, or STORIES AR LLC, 30 N Gould St, Sheridan, WY 82801, USA.

It applies to the personal data the Customer shares with the Provider to deliver Santa for Teams gifts, described in Annex 1. “GDPR” means Regulation (EU) 2016/679 and, where applicable, the UK GDPR and the Data Protection Act 2018; terms such as controller, processor, personal data and sub-processor have the meaning given there.

2. Instructions and purpose

The Provider processes the Customer’s data only to deliver gift invitations and reminders to the families the Customer chooses, to let the Customer see the status of each invitation in the dashboard, and to provide support related to the gifts. The Terms of Sale and the actions the Customer’s administrators take in the dashboard (sending, resending, changing or revoking invitations) are the Customer’s documented instructions.

The Provider does not use the Customer’s data for marketing, does not add the addresses to any mailing list, does not sell or rent them and does not share them with anyone except the sub-processors in Annex 3. The only exception is a family that itself ticks the optional box on the gift page asking for news from Santa AI: that consent is the family’s own, given directly to the Provider, and can be withdrawn at any time. If the Provider believes an instruction breaks the law, it will tell the Customer before acting on it.

3. Provider’s obligations

The Provider will:

  • keep the data confidential and make sure that everyone who has access to it is bound by confidentiality and has been told what they may do with it;
  • apply the technical and organisational measures in Annex 2 and keep them up to date;
  • use only the sub-processors listed in Annex 3, stay responsible for their work, and give the Customer at least 14 days’ notice by email before adding or replacing one, so that the Customer can object;
  • help the Customer answer requests from data subjects (access, correction, deletion, objection) within 5 business days of the Customer’s request, and forward any such request it receives directly;
  • help the Customer with data protection impact assessments and consultations with supervisory authorities where they concern this processing;
  • notify the Customer at the contact email in the dashboard without undue delay, and no later than 48 hours after becoming aware of a personal data breach affecting the Customer’s data, with the information the Customer needs for its own notifications;
  • make available the information needed to show compliance with Article 28 GDPR and allow audits by the Customer or an auditor the Customer mandates, once a year or after a breach, on 30 days’ notice, during business hours and at the Customer’s cost;
  • delete the data at the end of the processing as described in section 5.

4. What the Customer is responsible for

The Customer confirms that it has a lawful basis to share the email addresses with the Provider for this purpose and to let the Provider email the families on its behalf, that the addresses are accurate to the best of its knowledge, and that its own privacy notices to employees cover this use. The Customer decides which families receive a gift and can revoke an unused invitation at any time from the dashboard.

5. Duration and deletion

The processing lasts for the gift season: from the first invitation until the date the gifts stop being valid (for the 2026 season, January 7, 2027), plus the period needed to prepare the season summary and refunds. The Provider deletes the email addresses from its systems within 90 days after the gift validity date. Encrypted backups are overwritten in the ordinary rotation within a further 90 days and are never restored for any purpose other than recovering the service.

On the Customer’s request at any time, the Provider deletes the addresses earlier; invitations that have not been used stop working when their address is deleted.

6. Sub-processors and where the data is

The Customer authorises the sub-processors in Annex 3. The Provider’s servers are in the United States. For a Customer in the EU, the EEA or the United Kingdom, the transfer of the data to those servers and to the US sub-processors is covered by the standard contractual clauses adopted by the European Commission in Decision (EU) 2021/914 (module two, controller to processor) and, for the UK, the International Data Transfer Addendum issued by the Information Commissioner, both of which are incorporated into this DPA by reference; the Provider provides signed copies on request.

7. Data that families give us directly

When a parent opens their gift, they enter their child’s details (name, age, city, a few things Santa should mention, and a photo only for formats that use one) and their own email address on the Provider’s website. The parent gives this data to the Provider directly, and the Provider processes it as an independent controller under its privacy policy at santaai.site/en/privacy. The Customer never receives this data: the dashboard shows only whether an invitation was sent, opened and used. This data is not covered by this DPA.

8. Liability, term and law

Liability under this DPA is subject to the limits in the Terms of Sale, except where the law does not allow such limits. This DPA applies for as long as the Provider processes the Customer’s data and is governed by the same law as the Terms of Sale: the laws of England and Wales when the Provider is A24Z LTD, the laws of the State of Wyoming, USA, when the Provider is STORIES AR LLC.

A signed copy of this DPA for the Customer’s records is available on request from the dashboard (Orders & documents → Request) or by email to info@santaai.site.

Annex 1. Details of the processing

Subject matter
Delivery of Santa for Teams gift invitations and reminders to families chosen by the Customer, and showing the Customer the status of each invitation.
Duration
The gift season until the gift validity date (for 2026: January 7, 2027), then deletion within 90 days (section 5).
Nature of processing
Storing the addresses, sending emails to them, recording whether each invitation was sent, opened and used, showing this in the dashboard, deleting.
Personal data
Email addresses of the families the Customer invites; optionally the name of the person who signs the note in the invitation. Names and email addresses of the Customer’s dashboard administrators.
Data subjects
Employees, clients or partners of the Customer and their families; the Customer’s administrators.
Special categories
None. The Provider asks the Customer not to include any.

Annex 2. Technical and organisational measures

  • All connections to the website, the dashboard and the API use TLS. Dashboard sessions use one-time codes sent by email; there are no passwords to leak.
  • The data is stored on a dedicated server managed by the Provider; access is limited to the Provider’s founders over SSH keys. Administrative access to the dashboard data requires a secret key that is never exposed to the browser.
  • Invitation links are personal, random and unguessable; an invitation shows a family only their own gift, never the Customer’s list.
  • The Customer’s dashboard shows statuses only; children’s details and recordings entered by families are kept apart and are never shown to the Customer.
  • Daily encrypted (AES-256) backups stored with a separate provider; the encryption key is kept apart from the backups.
  • Emails to families are sent through a transactional email provider; addresses that bounce permanently are placed on a stop list and not emailed again.
  • Logs and access are reviewed after any incident; a breach is escalated to the founders immediately and to affected Customers within 48 hours.

Annex 3. Sub-processors

CompanyWhat it doesWhere
Contabo Inc.Server hosting for the Provider’s application and databaseUnited States
Vercel Inc.Hosting of the website and the dashboard front endUnited States (edge network worldwide)
Resend Inc.Sending invitation, reminder and dashboard emailsUnited States
Cloudflare, Inc.Storage of encrypted backupsUnited States / EU

The text and voice of each greeting are generated by AI providers (OpenAI, HeyGen, ElevenLabs) from the details the parent enters; those providers never receive the Customer’s list of addresses.

Terms of Sale · Santa for Teams