Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the agreement between Loyaltify OÜ ("Processor") and the customer ("Controller") under the GDPR. It applies when Loyaltify processes personal data on behalf of the Controller in connection with the Services.

1. Roles and Scope

The Controller determines the purposes and means of processing personal data. Loyaltify processes personal data solely on the Controller’s documented instructions and as necessary to provide the Services.

2. Processing Details

  • Purpose: Providing loyalty and customer engagement services
  • Data subjects: End customers of the Controller
  • Categories of data: Identifiers, contact details, transaction activity, loyalty activity, and communications metadata
  • Duration: For the term of the Services and as otherwise agreed

3. Confidentiality

Loyaltify ensures that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4. Security Measures

Loyaltify implements appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, in accordance with GDPR Article 32.

5. Sub-processors

The Controller authorizes Loyaltify to engage sub-processors to help provide the Services. Sub-processors may include:

  • AWS (Frankfurt, EU – eu-central-1): hosting and primary data storage
  • Stripe: payment processing
  • SendGrid: transactional email delivery
  • Intercom: customer support communications

Loyaltify remains responsible for the performance of its sub-processors’ obligations to the extent required by applicable law.

6. Assistance with Data Subject Requests

Loyaltify will assist the Controller, where technically feasible, in fulfilling data subject requests (such as access, deletion, or correction) and in complying with related GDPR obligations.

7. International Transfers

Personal data is primarily processed within the EU. Where personal data is processed outside the EU/EEA, Loyaltify will implement appropriate safeguards such as Standard Contractual Clauses or adequacy decisions, in accordance with GDPR requirements.

8. Deletion or Return of Data

Upon termination of the Services, Loyaltify will delete or return personal data to the Controller, unless retention is required by applicable law.

9. Contact

For DPA-related inquiries, contact dpo@loyaltify.io.

Last updated: 2025-12-12 · Version: 46109ce56519