Scarecrow Systems Data Processing Agreement

Last updated: 1 September 2026

This Data Processing Agreement ("DPA") forms part of the agreement between the customer using Scarecrow ("Customer", "you" or "your") and Merch Cast Ltd trading as Scarecrow Systems ("Scarecrow", "we", "us" or "our").

Scarecrow is operated by: Merch Cast Ltd t/a Scarecrow Systems, Company number: 16949588, Britannia Works, Magdalene Road, Torquay, Devon, TQ1 4AF, United Kingdom.

This DPA applies where Scarecrow processes personal data on behalf of the Customer.

1. Purpose and Scope

The Customer and Scarecrow agree that, for personal data processed through Scarecrow on behalf of the Customer:

  • The Customer is generally the Data Controller;
  • Scarecrow is generally the Data Processor.

This DPA sets out the obligations of both parties in relation to that processing. This DPA forms part of the Scarecrow Terms and Conditions.

2. Applicable Data Protection Law

For the purposes of this DPA, "Data Protection Legislation" means applicable data-protection and privacy legislation, including where applicable the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, any legislation replacing, supplementing or amending the above, and other applicable UK data-protection legislation.

Where applicable, references to Controller, Processor, Personal Data, Personal Data Breach and other terms have the meanings given to them under applicable Data Protection Legislation.

3. Customer Responsibilities

The Customer is responsible for ensuring that its use of Scarecrow complies with applicable Data Protection Legislation.

The Customer must:

  • Have a lawful basis for processing personal data;
  • Provide appropriate privacy information to individuals;
  • Ensure that personal data supplied to Scarecrow is processed lawfully;
  • Ensure that personal data is accurate where necessary;
  • Determine appropriate retention periods;
  • Respond to data-subject requests;
  • Ensure that its users are appropriately authorised;
  • Maintain appropriate security of its own systems and accounts.

The Customer must not instruct Scarecrow to process personal data in a manner that would knowingly cause Scarecrow to breach applicable law.

4. Scarecrow's Processing Obligations

Scarecrow will:

  • Process personal data only on documented instructions from the Customer;
  • Process personal data only as necessary to provide the Scarecrow Service;
  • Maintain appropriate technical and organisational security measures;
  • Ensure that persons authorised to process personal data are subject to confidentiality obligations;
  • Provide reasonable assistance to the Customer in relation to applicable data-protection obligations;
  • Notify the Customer of certain personal-data breaches as required by this DPA;
  • Use subprocessors in accordance with this DPA;
  • Delete or return personal data in accordance with this DPA following termination.

Scarecrow will not sell Customer personal data or use it for unrelated advertising purposes.

5. Processing Instructions

The Customer instructs Scarecrow to process personal data as reasonably necessary to:

  • Provide the Scarecrow platform;
  • Store customer and business information;
  • Manage customers and contacts;
  • Create and manage quotations;
  • Manage jobs and orders;
  • Manage products and suppliers;
  • Manage stock information;
  • Produce job and production documentation;
  • Provide integrations requested by the Customer;
  • Provide customer support;
  • Maintain and secure the platform;
  • Perform other functions requested or enabled by the Customer.

Scarecrow may process personal data where necessary to comply with applicable law.

6. Categories of Data Subjects

Depending on how the Customer uses Scarecrow, personal data may relate to:

  • The Customer's customers;
  • Customer contacts;
  • Employees;
  • Contractors;
  • Suppliers;
  • Business contacts;
  • Website or enquiry contacts;
  • Other individuals whose information the Customer enters into Scarecrow.

The Customer remains responsible for ensuring that its use of Scarecrow in relation to these individuals is lawful.

7. Categories of Personal Data

Depending on the Customer's use of Scarecrow, personal data may include:

  • Names;
  • Email addresses;
  • Telephone numbers;
  • Postal addresses;
  • Company information;
  • Job information;
  • Quote information;
  • Order information;
  • Delivery information;
  • Account information;
  • User information;
  • Artwork or files containing personal information;
  • Other information entered by the Customer.

The Customer should not upload special category data or other highly sensitive information unless there is a legitimate and lawful reason to do so and appropriate safeguards are in place.

8. Duration of Processing

Scarecrow will process Customer personal data for the duration of the Customer's use of the Service.

Following cancellation or termination, Scarecrow may retain Customer data for up to 90 days. At the end of this period, Scarecrow may permanently delete the relevant data unless the Customer has requested its return, retention is required by law, retention is necessary to establish, exercise or defend legal claims, or other lawful retention requirements apply.

9. Security Measures

Scarecrow will maintain reasonable technical and organisational measures appropriate to the risks associated with processing personal data.

  • HTTPS encryption in transit;
  • Role-based access controls;
  • Access logging;
  • Administrative access controls;
  • Regular software updates;
  • Infrastructure security;
  • Appropriate authentication controls;
  • Backup and recovery mechanisms;
  • Security monitoring where available.

Security measures may be updated as Scarecrow develops. The Customer acknowledges that no electronic system can guarantee absolute security.

The Customer is responsible for security measures within its own organisation, including user account security, password management, user permissions, device security, staff access and independent backups.

10. Personal Data Breaches

If Scarecrow becomes aware of a Personal Data Breach affecting personal data processed on behalf of the Customer, Scarecrow will notify the Customer without undue delay where required by applicable law.

Where reasonably possible, the notification will include relevant information concerning the nature of the breach, the categories of information affected, the likely consequences, measures taken or proposed to address the breach, and other information reasonably available to Scarecrow.

The Customer remains responsible for determining whether the breach must be reported to the ICO or affected individuals.

11. Data Subject Requests

Where Scarecrow receives a request from an individual relating to personal data processed on behalf of the Customer, Scarecrow will, where appropriate, direct the individual to the Customer.

Scarecrow will provide reasonable assistance to the Customer in responding to data-subject requests where required by applicable law. This may include assistance with access requests, rectification, erasure, restriction, data portability and objections.

The Customer remains responsible for responding to such requests.

12. Data Protection Impact Assessments

Where reasonably required, Scarecrow will provide reasonable information and assistance to the Customer to help the Customer meet its obligations relating to data-protection impact assessments.

The Customer remains responsible for determining whether a DPIA is required for its own processing activities.

13. Subprocessors

The Customer authorises Scarecrow to use third-party subprocessors where reasonably necessary to provide the Service.

Subprocessors may include providers of hosting, database infrastructure, authentication, payment processing, email delivery, file storage, cloud infrastructure, third-party integrations, supplier API connections, and security and monitoring services.

Current or planned subprocessors may include Stripe, Vercel, Supabase, Google and Dropbox. Other subprocessors may be added as Scarecrow develops.

14. Subprocessor Changes

Scarecrow may appoint new subprocessors or replace existing subprocessors where reasonably necessary to operate or improve the Service.

Scarecrow will maintain or publish information regarding relevant subprocessors where reasonably practicable. Where required by applicable law, Scarecrow will provide customers with appropriate notice of material changes to subprocessors.

The Customer may raise reasonable data-protection concerns regarding a proposed subprocessor. Where appropriate, Scarecrow will consider such concerns and seek a commercially reasonable solution.

15. Subprocessor Obligations

Scarecrow will seek to ensure that subprocessors processing personal data on behalf of Scarecrow are subject to appropriate contractual obligations relating to data protection and confidentiality.

Scarecrow remains responsible for the performance of its subprocessors to the extent required by applicable Data Protection Legislation.

16. International Transfers

Some subprocessors may process personal data outside the United Kingdom.

Where personal data is transferred outside the UK, Scarecrow will use appropriate safeguards required under applicable Data Protection Legislation. These may include UK adequacy regulations, International Data Transfer Agreements, UK Addendums, Standard Contractual Clauses where applicable, or other lawful transfer mechanisms.

The Customer authorises Scarecrow to make such transfers where reasonably necessary to provide the Service and where lawful safeguards are in place.

17. Confidentiality

Scarecrow will ensure that persons authorised to process Customer personal data are subject to appropriate confidentiality obligations.

This obligation does not prevent disclosure where required by law.

18. Customer Audits and Information

Where reasonably necessary to demonstrate compliance with applicable Data Protection Legislation, Scarecrow will make available relevant information concerning its processing activities.

The Customer may request reasonable information concerning Scarecrow's compliance with this DPA. Any audit or inspection must be requested on reasonable notice, occur during normal business hours, not unreasonably disrupt Scarecrow's business, respect the confidentiality and security of other customers, not provide access to other customers' data, and be limited to matters reasonably relevant to the Customer's personal data.

Where information or audits would impose disproportionate cost or burden, Scarecrow may provide alternative evidence of compliance where reasonably appropriate.

19. Return and Deletion of Data

Following termination of the Customer's use of Scarecrow, the Customer may request reasonable assistance in exporting its data during the applicable retention period.

Customer data will generally be retained for up to 90 days following termination. Following that period, Scarecrow may permanently delete the data.

Scarecrow may retain information where required by law or where reasonably necessary for legal, accounting, security or dispute-resolution purposes.

20. Customer Backups

The Customer remains responsible for maintaining independent backups of its personal data and business information.

Scarecrow may provide integrations with services such as Google Drive and Dropbox to assist with customer-controlled storage and backups. The Customer is responsible for configuring and maintaining such integrations and ensuring that backups are actually being created successfully.

21. Assistance and Costs

Scarecrow will provide reasonable assistance required under applicable Data Protection Legislation.

Where a request requires substantial additional work outside the ordinary operation of the Service, Scarecrow may charge reasonable costs where permitted by law and where agreed with the Customer in advance.

22. Compliance with Law

Each party will comply with applicable Data Protection Legislation.

The Customer will not instruct Scarecrow to process personal data in a way that would knowingly cause Scarecrow to breach applicable law. If Scarecrow reasonably believes that an instruction breaches applicable Data Protection Legislation, Scarecrow may suspend the relevant processing while the matter is investigated.

23. Liability

The liability provisions contained in the Scarecrow Terms and Conditions apply to this DPA except to the extent that applicable Data Protection Legislation requires otherwise.

Nothing in this DPA is intended to exclude or restrict liability that cannot legally be excluded or restricted.

24. Term

This DPA will remain in effect for as long as Scarecrow processes personal data on behalf of the Customer.

The obligations relating to confidentiality, security, deletion, legal compliance and any other provisions intended to survive termination will continue to apply where appropriate.

25. Changes to this DPA

Scarecrow may update this DPA where reasonably necessary to reflect changes to applicable law, reflect changes to the Scarecrow Service, add or replace subprocessors, improve security provisions, reflect changes in technology, or address regulatory requirements.

Where changes materially affect the Customer's rights or obligations, Scarecrow will endeavour to provide reasonable notice.

26. Governing Law

This DPA is governed by the laws of England and Wales.

The courts of England and Wales shall have exclusive jurisdiction over disputes relating to this DPA, subject to any mandatory legal rights that cannot lawfully be excluded.

27. Contact

Data-protection enquiries should be directed to: Merch Cast Ltd t/a Scarecrow Systems, Britannia Works, Magdalene Road, Torquay, Devon, TQ1 4AF, United Kingdom.

Email: paul@merchcast.co.uk

Company number: 16949588

By using Scarecrow to process personal data on behalf of your business, you confirm that you have read, understood and agreed to this Data Processing Agreement.