Last updated: August 3, 2026
This Data Processing Agreement is provided for transparency about how Tokei handles personal data on your behalf. It is not legal advice, and it has not yet completed specialist UK GDPR legal review. If you need a reviewed or signed copy for your own compliance records, see “Requesting a Signed Copy” below.
This Data Processing Agreement (“DPA”) describes how Tokei processes personal data that a creator collects through, or imports into, their contests, sweepstakes, and giveaways hosted on Tokei (entrant names, email addresses, and similar contact data, together “Entrant Data”). It supplements our Terms and Conditions and Privacy Policy. Where this DPA conflicts with those documents on the specific question of controller/processor roles for Entrant Data, this DPA governs.
For Entrant Data — including contacts a creator imports from a third-party list (for example an export from another giveaway platform, an email service provider, or a spreadsheet) — the creator is the data controller: the creator decides why the data is collected, who is contacted, and how long it is kept. Tokei is the data processor: we process Entrant Data only to provide the contest-hosting service the creator has configured.
Tokei is the controller, not the processor, for data about the creator's own account (billing details, login credentials, account settings) — that relationship is covered by our Privacy Policy, not this DPA.
Tokei processes Entrant Data only on the documented instructions of the controller (the creator), as given through the Tokei dashboard, API, or CLI configuration — for example, which fields to collect, which winners to select, and which connected email service provider (if any) to sync consented entrants to. Tokei will not process Entrant Data for any other purpose unless required to do so by law, in which case Tokei will inform the creator before processing, unless the law prohibits this.
Tokei makes no independent use of Entrant Data, including contacts imported from a third-party list. Specifically, Tokei does not:
Entrant Data is used solely to operate the contest(s) the creator configures: recording entries, detecting fraud and duplicate entries, selecting and notifying winners, and — only where the entrant has given optional marketing consent and the creator has connected an email service provider — syncing that specific entrant to that specific creator's own list.
Tokei ensures that personnel authorized to process Entrant Data are subject to confidentiality obligations, whether contractual or statutory, and access Entrant Data only to the extent necessary to operate, support, or troubleshoot the service.
Tokei implements technical and organizational measures appropriate to the risk, consistent with UK GDPR Article 32, including access controls limiting who can read Entrant Data, encryption of data in transit, and hashing of identifiers such as IP addresses used for fraud detection rather than storing them in plain text. We do not claim any specific third-party security certification (such as SOC 2 or ISO 27001) at this time, and no method of transmission or storage is ever 100% secure.
The creator authorizes Tokei to engage the following sub-processors to provide the service. Tokei remains responsible for each sub-processor's handling of Entrant Data to the extent required by applicable law.
In addition, where a creator chooses to connect their own email service provider — for example Mailchimp, Brevo, Klaviyo, MailerLite, Resend, Kit, or another supported provider — and enables marketing consent syncing, that connection is made at the creator's own election. The connected provider processes synced contacts as the creator's own processor (or controller, depending on that provider's terms), under the creator's direct agreement with them, not as a Tokei sub-processor.
Tokei will provide reasonable notice of any intended change to this sub-processor list, giving the creator an opportunity to object on reasonable grounds relating to data protection.
If Tokei becomes aware of a personal data breach affecting Entrant Data, Tokei will notify the affected creator(s) without undue delay after becoming aware of it, and will provide the information reasonably available at the time to help the creator meet any notification obligations of their own.
Taking into account the nature of the processing, Tokei will provide reasonable assistance to the creator in responding to requests from entrants exercising their data protection rights (such as access, correction, deletion, or objection), including via the account and contest management tools in the dashboard, and by contacting us directly (see “Contact Us” below) for requests the dashboard cannot fulfil directly.
On termination of the creator's use of the service, or on request, Tokei will delete or anonymize Entrant Data in line with the retention position described in our Privacy Policy (see “Contest and Giveaway Data Collection”), unless applicable law requires continued retention. Aggregated data that no longer identifies an individual entrant may be retained.
Entrant Data may be transferred to, and processed in, countries other than the entrant's or the creator's own, including where Tokei's sub-processors operate infrastructure. Where such a transfer is subject to UK GDPR restrictions on international transfers, Tokei intends to rely on an appropriate transfer mechanism available under UK GDPR at the time of transfer. We do not represent that a specific Standard Contractual Clauses addendum or International Data Transfer Agreement has already been executed with every sub-processor; creators with specific transfer-mechanism requirements should contact us before importing data subject to those requirements.
If you have questions about this DPA, or would like to request a signed or countersigned copy for your own records, please contact us: 167-169 Great Portland Street London (W1w 5pf) Office, 5th Floor, London, England, W1W 5PF. Email: team@tokei.io