Book a demo

1. Purpose of this register

Ralle Pty Ltd (Ralle) provides digital membership and engagement services to membership organisations. Where Ralle processes personal data on behalf of a customer, Ralle acts as a processor and the customer acts as the controller.

This register lists the third parties Ralle engages to help deliver those services and which may process customer personal data as a result. It is referred to in the data processing terms of Ralle’s Master Supply Agreement and identifies the sub-processors currently engaged by Ralle under the customer’s general authorisation.

This register is the current version. Ralle maintains superseded versions for audit purposes. See section 6.

2. How to read this register

Customer personal data means personal data that Ralle processes on behalf of a customer under a Master Supply Agreement, including personal data relating to that customer’s members.

Primary data location identifies the principal country or region in which the relevant service stores or processes customer personal data. Sub-processor personnel, or the sub-processor’s own sub-processors, may process that data from other locations in accordance with their published terms, which are linked in the More information column. The transfer of personal data from a customer in the United Kingdom or the EEA to Ralle in Australia is governed separately by the transfer mechanism set out in that customer’s agreement with Ralle.

More information links to the sub-processor’s own published security and compliance information, including the transfer safeguards it relies on.

Ralle engages each sub-processor under a written agreement imposing data protection obligations that meet the requirements of applicable data protection law, and remains responsible to its customers for the acts and omissions of its sub-processors.

This register covers organisations that process personal data on Ralle’s behalf as a processor. Ralle also uses tools for its own business operations, such as accounting, task management, code management and customer relationship management, where Ralle acts as a controller in its own right. Those are described in Ralle’s Privacy Policy rather than in this register.

3. Sub-processors that process member personal data

The following sub-processors support Ralle’s core platform and communications services. Whether a particular sub-processor processes a customer’s personal data depends on the services and features that customer uses.

4. Conditional sub-processors

These sub-processors are engaged only where the customer uses the relevant feature or integration. They do not apply to every customer.

5. Systems the Customer contracts directly

Ralle connects to systems that the customer contracts directly with the relevant provider. Those providers are not engaged by Ralle as sub-processors, and their respective data protection roles are governed by their direct agreements with the customer.

Payment providers

Where a customer accepts payments through the Ralle platform, the customer opens and holds its own account with the payment provider.

Ralle does not receive, process or store full payment card numbers. Card details are captured by the provider’s own hosted payment page. Ralle receives transaction records back by API, which include hashed card identifiers but never full card numbers. Provider onboarding, including identity and anti-money laundering checks, is carried out by the provider directly and Ralle has no visibility of it.

Point of sale, membership and ticketing systems

Ralle integrates with point of sale, membership and ticketing systems that the customer contracts directly with the relevant provider. Ralle is not engaged by those providers and does not engage them as sub-processors.

Where an integration is enabled, member personal data may be transmitted from Ralle to that system, and received by Ralle from it, in each case on the customer’s instruction. The customer’s agreement with that provider governs how the provider handles that data, including its retention and deletion.

The systems connected for a particular customer are recorded in that customer’s agreement with Ralle.

6. Changes to this register

Ralle may add or replace sub-processors from time to time. Where Ralle intends to do so, it will give affected customers notice in accordance with the data processing terms of their agreement, and the customer will have the opportunity to object on reasonable data protection grounds.

Ralle will send notices of intended changes to the customer’s nominated data protection contact, or otherwise to its contract representative under the Agreement.

Superseded versions of this register are retained and available on request.

7. Version history

8. Contact

Questions about this register, or about how Ralle processes personal data, should be directed to:

support@ralle.co
Ralle Pty Ltd, Level 18, 324 Queen Street, Brisbane QLD 4000, Australia