GDPR-Compliant Data Processing Agreement
Stack Your Cash and Wix.com Ltd
Effective Date: 23rd February 2026
Last Updated: 23rd February 2026
1. Introduction and Purpose
This document provides a summary of the data processing relationship between Stack Your Cash, acting as Data Controller, and Wix.com Ltd, acting as Data Processor, in accordance with the UK General Data Protection Regulation and the Data Protection Act 2018.
Stack Your Cash operates its website, members dashboard, blog, educational programme, shop and associated digital services using the Wix platform. In doing so, personal data of users, subscribers, customers and members may be processed by Wix strictly on behalf of and in accordance with the documented instructions of Stack Your Cash.
This summary explains the respective roles and responsibilities of the parties, the nature of the processing activities, the categories of personal data involved, and the safeguards implemented to ensure compliance with applicable data protection legislation.
2. Roles and Legal Status
For the purposes of UK data protection law, Stack Your Cash acts as the Data Controller. Stack Your Cash determines the purposes for which personal data is processed and the means by which such processing is carried out in relation to the services it offers.
Wix.com Ltd acts as a Data Processor when providing website hosting, infrastructure, platform functionality, storage services, payment integrations and related technical services. Wix processes personal data solely on documented instructions from Stack Your Cash and does not determine the purposes of processing for Stack Your Cash’s user data.
Where Wix processes data for its own independent purposes, such as account administration between Wix and Stack Your Cash as a customer of Wix, Wix may act as a separate Data Controller for that specific processing activity. However, in relation to the end users of the Stack Your Cash website, Wix acts as a Data Processor.
3. Nature and Purpose of Processing
The processing activities carried out by Wix on behalf of Stack Your Cash include the hosting and storage of personal data submitted through the website, enabling account registration and authentication, facilitating subscription management, processing e-commerce transactions through integrated payment gateways, delivering members-only educational content, maintaining secure login sessions, storing user-generated content within community groups, and supporting analytics integrations.
Processing is undertaken for the sole purpose of enabling Stack Your Cash to operate its financial education platform and deliver services to users in accordance with contractual and legal obligations.
Wix does not process personal data for purposes inconsistent with the documented instructions of Stack Your Cash.
4. Categories of Personal Data Processed
In providing its services, Wix may process personal data categories including identity data such as name and username, contact data such as email address and billing address, account data such as login credentials and subscription status, transaction data relating to purchases and subscription payments, technical data including IP addresses and device identifiers, usage data relating to website interaction, and user-generated content posted within community areas.
Payment card details entered by users are processed through secure third-party payment integrations. Stack Your Cash does not store full payment card numbers, and Wix facilitates encrypted transmission of payment information to authorised payment processors compliant with applicable security standards.
Special category data is not intentionally collected or processed as part of the normal operation of the Stack Your Cash website. Users are instructed not to submit sensitive personal data through the platform.
5. Duration of Processing
Wix processes personal data for the duration of its service agreement with Stack Your Cash and in accordance with Stack Your Cash’s documented instructions. Personal data remains stored within the Wix infrastructure for as long as required to provide website functionality, maintain user accounts and comply with applicable legal retention requirements.
Upon termination of the service agreement, data retention and deletion are governed by the contractual terms between Stack Your Cash and Wix, subject to legal obligations requiring retention.
6. Security Measures
Wix implements appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk, in accordance with Article 32 of UK GDPR. Such measures include encrypted data transmission using Secure Socket Layer (SSL) technology, secure data storage environments, access controls restricting access to authorised personnel, network monitoring systems, firewall protection and intrusion detection mechanisms.
Wix maintains internal security policies and procedures designed to safeguard personal data against accidental loss, unauthorised access, alteration or disclosure.
Stack Your Cash remains responsible for implementing appropriate internal controls, including secure password management, access restrictions and configuration of platform features in accordance with data protection principles.
7. Confidentiality Obligations
Wix ensures that personnel authorised to process personal data are subject to appropriate confidentiality obligations. Access to personal data is restricted to individuals who require access in order to perform their duties in connection with the provision of services.
8. Sub-Processors
Wix may engage sub-processors to provide elements of its infrastructure and services. Where sub-processors are engaged, Wix remains responsible for ensuring that such sub-processors are subject to data protection obligations consistent with UK GDPR requirements.
Sub-processors may include cloud hosting providers, data centre operators, payment gateway providers and technical service providers. Wix maintains oversight of sub-processor arrangements and requires contractual safeguards to ensure compliance with applicable data protection standards.
Stack Your Cash acknowledges that the use of sub-processors is inherent to modern cloud-based website infrastructure and relies upon Wix’s contractual commitments in this regard.
9. International Transfers
Wix operates a global infrastructure and may store or process personal data outside the United Kingdom. Where personal data is transferred internationally, Wix implements appropriate safeguards as required by UK GDPR. Such safeguards may include Standard Contractual Clauses approved under UK law, adequacy regulations or equivalent protective mechanisms.
Stack Your Cash ensures that any international transfers conducted via Wix are supported by lawful transfer mechanisms and that data subjects’ rights remain protected.
10. Assistance with Data Subject Rights
As Data Controller, Stack Your Cash is responsible for responding to requests from individuals exercising their data protection rights. Wix provides technical assistance where necessary to enable Stack Your Cash to fulfil such obligations.
This may include facilitating access to stored data, enabling deletion or correction of information, or exporting data in a structured format where technically feasible.
11. Data Breach Notification
In the event of a personal data breach affecting data processed on behalf of Stack Your Cash, Wix is contractually required to notify Stack Your Cash without undue delay. Wix will provide relevant information necessary to enable Stack Your Cash to assess the breach and fulfil any legal reporting obligations to the Information Commissioner’s Office or affected individuals.
Stack Your Cash remains responsible for determining whether notification to regulators or individuals is required under UK GDPR.
12. Audit and Compliance
Wix maintains documentation demonstrating compliance with data protection obligations and provides assurances through its published security and compliance documentation. Stack Your Cash relies on these contractual and published assurances as part of its due diligence in selecting Wix as a service provider.
Stack Your Cash remains responsible for ensuring that its configuration and use of the Wix platform align with data protection principles, including data minimisation, purpose limitation and storage limitation.
13. Controller Responsibilities
While Wix acts as Data Processor, Stack Your Cash retains overall responsibility for compliance with UK GDPR in relation to personal data processed through its website. This includes ensuring that a lawful basis for processing exists, providing transparent privacy information to users, implementing appropriate retention policies and responding to data subject requests.
Stack Your Cash also ensures that appropriate contractual terms are in place with Wix incorporating mandatory data processing provisions required by Article 28 of UK GDPR.
14. Conclusion
Stack Your Cash uses Wix as a trusted data processing partner to deliver its online financial education platform. The relationship between Stack Your Cash and Wix is governed by contractual data protection terms designed to ensure that personal data is processed lawfully, securely and transparently.
Stack Your Cash remains committed to protecting personal data and ensuring that all third-party processors engaged in delivering its services adhere to high standards of data protection and information security.
​
​
​
​
