Stripy Fish Networks Limited

Reseller Data Processing Agreement

Reseller platform services — the Article 28 UK GDPR terms governing how we process the Reseller's own data as part of operating the Varde reseller programme. This Agreement does not cover Client Firm compliance data — that is governed separately by the direct Client Firm Data Processing Agreement.

Version v1.9-draft · 15 August 2026 · Questions: privacy@stripyfish.net

Draft — pending solicitor review. This Agreement has not yet had solicitor sign-off. Acceptance is given either by ticking a consent checkbox at your own account setup, or off-platform by signature, e-signature, or written confirmation before your account is approved and activated — see clause 13.

Parties

This Data Processing Agreement ("Agreement") is entered into between:

The Reseller ("Reseller" or "you") — the reseller firm identified in the associated reseller agreement or platform onboarding record. The Reseller is controller only of Reseller's Own Data (clause 1.3); it is neither controller nor processor of Client Firm User Data (clause 1.2) or of Client Firm compliance content (clause 1.2A).

Stripy Fish Networks Limited ("we", "us", or the "Processor") — a company registered in England and Wales, registered address 26 Wellhead Lane, Westbury, Wiltshire, BA13 3PT, ICO registration number ZC148489. Stripy Fish Networks is processor of Reseller's Own Data (clause 1.3); separately controller of Client Firm User Data (clause 1.2); and separately processor, on the Client Firm's own instructions as controller, of Client Firm compliance content (clause 1.2A).

1Background and scope

Background. This section explains the reasoning behind clauses 1.2–1.4; it is context, not itself an operative term.

The Reseller's role in creating a Client Firm's organisation record on the platform is limited to supplying an organisation name and the initial contact's email address. The platform holds no other personal identifier for that individual at account-creation time. That person then completes their own registration directly with Stripy Fish Networks and independently administers their own organisation's users and settings — with no further Reseller involvement, gating, or visibility into compliance content, unless the Client Firm separately and voluntarily grants the Reseller access as a user within their own organisation (a decision the Client Firm controls, not the Reseller or the platform). Stripy Fish Networks alone determines the purposes (delivery of SYSC 10A compliance services) and the essential means (security, retention, and access-control policy, applied uniformly regardless of a Client Firm's origin) of processing Client Firm User Data. On this basis, the parties consider Stripy Fish Networks to be the sole controller of Client Firm User Data, applying the purposes-and-means test in Article 4(7)–(8) UK GDPR.

1.1 The Processor operates the Varde platform, which the Reseller uses to create and administer client organisations ("Client Firms"), provision users on behalf of Client Firms, and track referral-based revenue share.

1.2 Client Firm User Data. Stripy Fish Networks is the controller of Client Firm User Data (defined in clause 2 — account and access data only, not compliance content: see clause 1.2A). The Reseller is neither a controller nor a processor of Client Firm User Data under this Agreement. Stripy Fish Networks' processing of Client Firm User Data as controller is unaffected by this Agreement's status or the state of the reseller relationship.

1.2A Client Firm compliance content is separate, and not Client Firm User Data. Compliance assessment, gap analysis, and policy content generated for or by a Client Firm is not within the scope of this Agreement (see clause 1.5) and is not Client Firm User Data. Stripy Fish Networks processes that content as processor, acting on the instructions of the relevant Client Firm as controller, under the direct data processing agreement between Stripy Fish Networks and that Client Firm. The Reseller is neither controller nor processor of that content, regardless of this Agreement's status or the state of the reseller relationship (see clauses 4.7 and 8.2).

1.3 Reseller's Own Data. The Reseller is the controller of Reseller's Own Data (defined in clause 2). Stripy Fish Networks processes Reseller's Own Data on the Reseller's behalf as processor, in accordance with Article 28 UK GDPR. This is the only personal data for which the Reseller is a controller under this Agreement. The Reseller confirms it has, or will obtain, any ICO registration required for this processing (see clause 5.4).

1.4 Joint controllership. The parties do not consider this arrangement to give rise to joint controllership under Article 26 UK GDPR between the Reseller and Stripy Fish Networks in respect of any data referenced in this Agreement — including Client Firm User Data, notwithstanding that the Reseller's revenue share is calculated by reference to a Client Firm's purchase/product status. That is a commercial interest in an outcome derived from the processing, not participation in determining its purposes or means. This is a legal-interpretation position, not a settled fact.

1.5 Scope of services covered by this Agreement:

  • Creation and administration of Client Firm organisation records and user accounts
  • Referral tracking, revenue share calculation, and payout processing for the Reseller's own account

Compliance assessment, gap analysis, and policy documentation services delivered to Client Firms via the platform are described here for context only — they are not within this Agreement's scope. They are governed exclusively by the direct data processing agreement between Stripy Fish Networks and each Client Firm, which this Agreement does not cover or duplicate.

2Definitions

  • "UK GDPR" means the UK General Data Protection Regulation as retained in UK law by the European Union (Withdrawal) Act 2018, as amended.
  • "Personal Data", "Processing", "Data Subject", "Controller", "Processor", and "Supervisory Authority" have the meanings given in UK GDPR.
  • "Client Firm" means a client organisation the Reseller creates or administers on the platform.
  • "Client Firm User Data" means the personal data of a Client Firm's compliance officers and authorised users — their email address, role, and access records. It does not include compliance assessment, gap analysis, or policy content, which is separate and out of this Agreement's scope (see clause 1.2A). Stripy Fish Networks is controller of Client Firm User Data (clause 1.2).
  • "Reseller's Own Data" means the Reseller's own referral and revenue-share records (which Client Firms it has referred or administers, their organisation name and purchase/product status, and the resulting revenue share calculations and payouts) together with the Reseller's own team members' platform account details. The Reseller is controller of Reseller's Own Data (clause 1.3).
  • "Sub-processor" means any third party engaged by the Processor to carry out processing activities on behalf of the Reseller under this Agreement — see clause 6 for which entities meet this definition and which are disclosed for information only.

3Details of processing

This table describes processing carried out on the Reseller's instructions as controller of Reseller's Own Data (clause 1.3). It does not describe Client Firm User Data — that is Stripy Fish Networks' own processing as controller (clause 1.2), detailed in the direct Client Firm DPA instead.

Subject matterPlatform hosting and administration tooling enabling the Reseller to record and manage its own referral relationships, Client Firm organisation references, and revenue share calculations
DurationFor the term of the reseller agreement, plus the retention period specified in clause 8
Nature and purposeProcessing the Reseller's own account and team member data; recording which Client Firms the Reseller has referred or administers (organisation name, purchase/product status) and calculating/paying referral revenue share
Type of personal dataThe Reseller's own team members' account details; Stripe Connect account identifiers used for payout; organisation name and purchase/product status of referred Client Firms, held as the Reseller's own commercial record
Categories of data subjectsThe Reseller's own team members provisioned as platform users

4Processor obligations

These obligations apply to Stripy Fish Networks' processing of Reseller's Own Data (clause 1.3), where the Reseller is controller.

The Processor agrees to:

4.1 Process personal data only on documented instructions from the Reseller, including with regard to transfers of personal data to a third country, unless required to do so by UK law; in such a case, the Processor shall inform the Reseller of that legal requirement before processing, unless prohibited from doing so.

4.2 Ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4.3 Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including as appropriate:

  • Encryption of personal data at rest (AES-256-GCM)
  • Encrypted HTTPS transport for all data in transit
  • Access controls limiting data access to authorised personnel only, scoped so that Resellers and Client Firms cannot access each other's data outside the platform's defined administration relationship
  • Append-only audit logging of all data access and mutation events
  • File-level permissions (0o600) on all stored personal data
  • Systemd process containment limiting filesystem access to defined directories

4.4 Respect the conditions for engaging sub-processors set out in clause 6.

4.5 Taking into account the nature of the processing, assist the Reseller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Reseller's own obligations to respond to requests for exercising data subjects' rights under UK GDPR in respect of Reseller's Own Data. Client Firm users' data subject rights requests are handled under the direct Client Firm DPA, not this Agreement. The Processor's administrative tooling provides the following capabilities on request: data export (Article 15 and 20), erasure (Article 17), and rectification (Article 16).

4.6 Assist the Reseller in ensuring compliance with obligations pursuant to Articles 32 to 36 UK GDPR (security, breach notification, data protection impact assessment, prior consultation), taking into account the nature of processing and the information available to the Processor.

4.7 At the choice of the Reseller, delete or return Reseller's Own Data after the end of the reseller relationship, and delete existing copies unless UK law requires storage of the personal data. Client Firm User Data is not affected by termination of this Agreement — it continues to be governed by the direct Client Firm DPA regardless of whether the reseller relationship ends.

4.8 Make available to the Reseller all information necessary to demonstrate compliance with the obligations laid down in this clause, and allow for and contribute to audits, including inspections, conducted by the Reseller or an auditor mandated by the Reseller. The Processor shall immediately inform the Reseller if, in its opinion, an instruction infringes UK GDPR or other applicable UK data protection provisions.

5Reseller (Controller) obligations

These obligations apply to Reseller's Own Data (clause 1.3). They do not extend to Client Firm User Data, for which Stripy Fish Networks is controller (clause 1.2).

The Reseller warrants that:

5.1 It has a lawful basis for processing Reseller's Own Data.

5.2 It has notified its own team members, as data subjects, as required under Articles 13 and 14 UK GDPR regarding the processing of Reseller's Own Data. Notification to Client Firm users about Stripy Fish Networks' processing of their own data is Stripy Fish Networks' responsibility as controller of that data, not the Reseller's.

5.3 It will not instruct the Processor to process personal data in a manner that would cause the Processor to breach UK GDPR or any other applicable law.

5.4 It is, or will become prior to processing Reseller's Own Data at scale, registered with the ICO as a data controller unless a registration exemption applies, and will provide its ICO registration number to the Processor as a required field before activation. The Processor reserves the right to request evidence of registration.

6Sub-processors

6.1 The Reseller provides general authorisation for the Processor to engage sub-processors. The Processor shall inform the Reseller of any intended changes concerning the addition or replacement of sub-processors, giving the Reseller the opportunity to object to such changes on reasonable data-protection grounds. If the Reseller objects and the parties are unable to resolve the objection, the Reseller's remedy is to terminate the Services affected by that sub-processor's engagement.

6.2 Authorised sub-processors under this Agreement — these process Reseller's Own Data, on the Reseller's instructions as controller (clause 1.3):

Sub-processorLocationPurposeData processed
Stripe Payments Europe, Limited Dublin, Ireland (contracting entity); underlying infrastructure extends to the United States — see clause 7 Stripe Connect Express payout processing for reseller revenue share Reseller's Connect account identifiers and payout records
Fasthosts Internet Limited United Kingdom Outbound SMTP relay for the Reseller's own notification emails (e.g. payout confirmations) Recipient email address; message content
Amazon Web Services (AWS) United Kingdom (London, eu-west-2 region) — confirmed live 2026-08-07; see the data-residency checklist in docs/deploy/ Server hosting and storage Reseller's Own Data as listed in clause 3

6.3 Disclosed for information only — not an authorised sub-processor under this Agreement:

Sub-processorLocationPurposeData processed
Anthropic Ireland Limited Dublin, Ireland (contracting entity); underlying infrastructure extends to the United States AI language model inference (Claude API) Client Firm compliance content, processed by Stripy Fish Networks as processor on the Client Firm's own instructions as controller (clause 1.2A), not on the Reseller's instructions. Governed and disclosed in full under the direct Client Firm DPA, not this Agreement. Listed here so the Reseller has visibility into the platform it distributes.

6.4 Where the Processor engages a sub-processor under clause 6.2, it shall impose the same data protection obligations as set out in this Agreement on that sub-processor by way of a contract.

6.5 The Processor shall remain fully liable to the Reseller for the performance of a clause 6.2 sub-processor's obligations.

7International transfers

7.1 Stripe Payments Europe, Limited is the contracting entity relevant to this Agreement's scope (clause 1.3, clause 6.2). Its infrastructure extends outside the European Economic Area (including to the United States), so this transfer is not covered by UK adequacy alone.

7.2 Stripe's processing is governed by its Data Processing Addendum, incorporated into its commercial terms of service. This instrument incorporates the EU Standard Contractual Clauses (Module Two/Three) together with the UK International Data Transfer Addendum (Addendum B.1.0, issued by the ICO under s.119A of the Data Protection Act 2018), which extends the SCCs to satisfy the UK's separate transfer regime. The Processor has reviewed and accepts these terms.

7.3 Anthropic's processing of Client Firm compliance content (clause 6.3) is outside this Agreement's scope. It is disclosed and governed under the direct Client Firm DPA, which covers its own transfer mechanism and data-minimisation approach for that content.

7.4 The Processor's hosting infrastructure (clause 6.2) is located within the United Kingdom. Hosting and storage of Reseller's Own Data does not itself involve any international transfer.

7.5 No other international transfers of personal data are made under this Agreement.

7.6 The Data (Use and Access) Act 2025 reformed the UK GDPR Chapter V transfer framework with effect from 5 February 2026: Article 44 ("general principle for transfers") was omitted, and the governing standard for appropriate-safeguards transfers is now the "data protection test" (Article 46(1A) UK GDPR, inserted by the 2025 Act) rather than the previous adequacy-based framing referred to in clause 7.1. Section 119A of the Data Protection Act 2018 — the Commissioner's power to issue transfer safeguard documents, including the UK International Data Transfer Addendum referred to in clause 7.2 — remains in force, amended to reference the new test, not repealed. The safeguard mechanism described in clauses 7.1–7.2 (EU Standard Contractual Clauses plus the UK International Data Transfer Addendum) continues to be available and relied upon under the reformed Article 46; this clause records that the legal test it is assessed against changed on 5 February 2026, without asserting any change to the mechanism itself.

8Retention and deletion

8.1 Reseller's Own Data (clause 1.3) is retained for the term of the reseller relationship, plus any period required by UK law (e.g. financial record-keeping).

8.2 On termination of the reseller relationship, the Reseller may request deletion of Reseller's Own Data before any applicable retention period expires. The Processor will action such requests within 5 business days and provide written confirmation of deletion. This has no effect on Client Firm User Data, which is governed by the direct Client Firm DPA regardless of the reseller relationship's status.

8.3 The Processor's audit log — a platform-wide security and forensic record covering all users' actions, not limited to Reseller's Own Data — retains event type, timestamp, a hashed token identifier, and, in plaintext, IP address and user agent, for up to 6 years from the date of the event, aligned with the six-year Corporation Tax record-keeping requirement under Schedule 18, paragraph 21 of the Finance Act 1998 (this is the Processor's own company record, not a client obligation), independent of the Reseller's own retention choices under clauses 8.1–8.2. IP address and user agent are personal data. This 6-year ceiling is the Processor's storage-limitation commitment under Article 5(1)(e) UK GDPR; the Processor retains the log for that period under its own legitimate interest in platform security (Article 6(1)(f) UK GDPR). Enforcement of this ceiling is automatic: entries older than 6 years are deleted on a scheduled and startup purge, and the deletion itself is recorded as an audit event.

9Security breach notification

9.1 In the event of a personal data breach affecting Reseller's Own Data, the Processor will notify the Reseller without undue delay and, where feasible, not later than 48 hours after becoming aware of the breach. This window is deliberately shorter than the Reseller's own 72-hour notification deadline to the ICO under Article 33 UK GDPR, so the Reseller has runway to investigate and report within its own regulatory clock — it is not intended to be aligned to 72 hours.

9.2 The notification shall include, to the extent known at the time: the nature of the breach, the categories and approximate number of data subjects concerned, the likely consequences, and the measures taken or proposed to address the breach.

9.3 The Reseller is responsible for notifying the ICO and affected data subjects as required by Articles 33 and 34 UK GDPR, in respect of personal data for which it is controller.

10Audit rights

10.1 The Reseller may request written evidence of compliance with this Agreement no more than once per calendar year without cause. The Processor shall respond within 20 business days.

10.2 The Reseller may conduct or commission an on-site audit on reasonable notice (minimum 30 days) and at the Reseller's cost, no more than once per calendar year unless a breach has occurred.

11Term and termination

11.1 This Agreement takes effect on the date the Reseller's account is approved and activated on the platform and remains in force for the duration of the reseller relationship.

11.2 Either party may terminate this Agreement on written notice if the other party commits a material breach of this Agreement and fails to remedy it within 30 days of written notice.

11.3 Obligations under clauses 4, 8, and 9 survive termination of this Agreement.

12Governing law

This Agreement is governed by the laws of England and Wales. Any dispute arising under it shall be subject to the exclusive jurisdiction of the courts of England and Wales.

13Execution

13.1 Acceptance of this Agreement is given either (a) by an authorised individual at the Reseller actively ticking a consent checkbox confirming they are authorised to accept this Agreement on the Reseller's behalf, presented at completion of the Reseller's own account setup on the platform, or (b) confirmed in writing (signature, e-signature, or written confirmation) by the Reseller before its account is approved and activated, where acceptance has not already been given under (a).

13.2 The Processor records the version of this Agreement accepted, the date and time of acceptance, and — where given under 13.1(a) — the individual who gave consent, against the Reseller's account record. Where acceptance is instead confirmed under 13.1(b), this record is set by the Processor's platform owner at the point of approval.

14Assignment

14.1 The Processor may assign, novate, or transfer its rights and obligations under this Agreement, in whole or in part, including in connection with a sale, merger, reorganisation, or transfer of all or substantially all of its business, provided the assignee agrees to be bound by this Agreement.

14.2 The Reseller may not assign or transfer its rights or obligations under this Agreement without the Processor's prior written consent.

15General

15.1 Entire agreement. This Agreement constitutes the entire agreement between the parties relating to its subject matter, and supersedes all prior discussions, negotiations, and agreements between them relating to that subject matter. Nothing in this clause excludes liability for fraud or fraudulent misrepresentation.

15.2 Severability. If any provision of this Agreement is found unenforceable or invalid, that provision is limited or eliminated to the minimum extent necessary, and the remaining provisions continue in full force.

15.3 Waiver. No failure or delay by either party in exercising a right under this Agreement operates as a waiver of that right, and no single or partial exercise of a right prevents further exercise of that or any other right.

15.4 Notices. A notice under this Agreement must be given in writing and is validly given if sent to the email address the Reseller registered with the Processor, or to legal@stripyfish.net for notices to the Processor (or such other address as either party notifies to the other), and is deemed received 24 hours after sending unless the sender receives a delivery-failure notification.

15.5 Third-party rights. A person who is not a party to this Agreement has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce any term of this Agreement. This includes, for the avoidance of doubt, any Client Firm referred by the Reseller — this Agreement governs the Reseller/Processor relationship only and does not alter the direct Client Firm DPA.

16Variation

16.1 The Processor may update this Agreement from time to time. It will give at least 30 days' notice of any material change to active Resellers by email; a change required to reflect a change in applicable data protection law may take effect immediately on notice instead. A change takes effect for the Reseller's account from its stated effective date and does not apply retrospectively to processing already carried out under an earlier version. The version of this Agreement in force at any given time is recorded against the Reseller's account per clause 13.

← Back