1. Parties and purpose
This Data Processing Agreement (the “DPA”) is entered into between the merchant using the KartaPass platform (the “Controller” — you) and [COMPANY NAME], registered in the [CITY] Commercial Register under No. [RC], ICE [ICE], with its registered office at [ADDRESS] (the “Processor” — we). It applies to all personal data of your end customers that we process on your behalf to operate the Service, and takes effect as soon as you use the Service.
Law 09-08 requires the relationship between a data controller and its processor to be governed by a written agreement recording that the processor acts only on the controller's instructions and provides sufficient security guarantees. This DPA is that agreement.
2. Roles
You are the data controller of your end customers' personal data: you decide to offer a loyalty card, and enrollment happens under your name. We are your data processor: we host and process that data solely to provide the Service. For your own merchant account data, we are the controller — as described in the Privacy Policy.
3. What processing this DPA covers
- Subject matter: operating digital loyalty cards in Apple Wallet and Google Wallet for your customers.
- Duration: as long as you use the Service, plus the deletion period below.
- Data subjects: your end customers holding a loyalty card.
- Data categories: identity and contact details (first name, last name, phone, optional email and birthday), card data (wallet chosen, points balance, install state), visit history (date, points, amount paid, optional note, the point of sale where the scan happened), and consent records.
- Purposes: creating and delivering the card, recording visits and points, sending card push messages, and the security of the Service.
4. Our obligations as processor
- We process your customers' data only to operate the Service and on your documented instructions — never for our own purposes. We never sell it, rent it, or use it for advertising.
- We keep it confidential: access is limited to what operating the Service requires, protected by authentication and role-based access, and each establishment only ever sees its own customers.
- We secure it: encrypted transport (HTTPS/TLS), sensitive card secrets encrypted at rest, hashed passwords, tenant isolation enforced in the database, and forgery-protected scan codes.
- We assist you with data subject requests: your dashboard lets you erase a customer's personal details on the spot, and we answer any request you escalate to us within the legal timeframe.
- We notify you without undue delay if we become aware of a breach affecting your customers' data, with the information you need to meet your own obligations.
- We delete: erasing a customer removes their identity details immediately, visit history is purged automatically after 24 months, and when your account closes we delete or anonymize your customers' data within 90 days, unless the law requires keeping it longer.
- We inform you before adding or replacing a sub-processor, so you can object before the change applies to your data.
5. Your obligations as controller
- You declare the processing to the CNDP before enrolling customers (déclaration préalable), naming us as your processor, and you file the foreign-transfer notification for the wallet delivery described below. Our CNDP compliance kit walks you through both filings.
- You inform your customers and collect their consent — the enrollment form does this for you and records when each customer accepted.
- You use the data only for legitimate loyalty purposes, honour opt-outs, and answer your customers' access, correction and deletion requests — the dashboard gives you the tools.
- You keep your account credentials safe and manage your staff's access responsibly.
6. Sub-processors and recipients
We use the following sub-processors, strictly to deliver the Service:
- Apple Inc. (United States) — delivers and updates Apple Wallet passes for customers who chose Apple Wallet;
- Google LLC (United States) — delivers and updates Google Wallet passes for customers who chose Google Wallet;
- Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus — hosting, on servers located in the European Union;
- our email provider — sends the transactional emails described in the Privacy Policy.
7. International transfers
Hosting stays in the European Union, on the CNDP's list of countries ensuring an adequate level of protection. Delivering a pass to Apple Wallet or Google Wallet transfers the pass data to the United States, which is not on that list: the transfer rests on the customer's express consent given at enrollment (art. 44) and must be notified to the CNDP with your declaration — the compliance kit includes the pre-filled transfer request.
8. Marketing messages
The platform enforces article 10 of Law 09-08 for you: marketing pushes only ever reach customers who separately opted in at enrollment, and balance updates after a visit are service messages, not marketing. You remain responsible for the content of the campaigns you send.
9. Audit and information
On written request, we provide the information reasonably necessary to demonstrate compliance with this DPA — including our security measures and sub-processor list — and we cooperate with any control by the CNDP concerning your processing.
10. Liability and precedence
Each party is responsible for its own obligations under Law 09-08. In case of conflict between this DPA and the Terms of Use & Sale, this DPA prevails for everything concerning your customers' personal data. The liability limits of the Terms apply.
11. Contact
For any question about this DPA or to exercise an instruction: [EMAIL] — [ADDRESS].
Terms of Use & Sale · Política de privacidad · CNDP Compliance Kit