1. Parties and purpose
This Data Processing Agreement (the “DPA”) is entered into between the merchant using the Kartalik platform (you) and NOVASTACK SARL, with a share capital of 100 000 MAD, registered in the Marrakech Commercial Register under No. 185521, with its registered office at APPT N 7 ETG 2 LOT AL MASAR N 643, Marrakech (the “Publisher” — we). It applies to all personal data of your end customers processed on the Service, and takes effect as soon as you use the Service.
2. Roles
You and we are jointly responsible for your end customers' personal data (Law 09-08, art. 1-5). You decide to offer a loyalty card, run your programme and see only your own customers. We operate the platform: we set the forms, the retention periods and the security, deliver the cards to Apple Wallet and Google Wallet, and declare the processing and its transfers to the CNDP. For your own merchant account data, we are the controller — as described in the Privacy Policy.
The same split applies to your digital business cards: you decide to publish a card and to invite the people who scan it to leave their contact; we operate the platform and declare the processing.
3. What processing this DPA covers
- Subject matter: operating digital loyalty cards and digital business cards in Apple Wallet and Google Wallet, for your customers and for the people who scan your card.
- Duration: as long as you use the Service, plus the deletion period below.
- Data subjects: your end customers holding a loyalty card, the visitors who choose to leave their contact on one of your digital business cards, and the members of your staff for whom you create a scan-manager account.
- Data categories: identity and contact details (first name, last name, phone, optional email and birthday), card data (wallet chosen, points balance, install state), visit history (date, points, amount paid, optional note, the point of sale where the scan happened), consent records, and for your staff their account details plus the record of which account performed each scan.
- Data categories for a digital business card: the name, the phone number or email address and the optional company a visitor chose to leave, their consent record, and the chain of shares showing how your card travelled from one person to the next — a point in that chain carries no identity of its own until someone attaches one by leaving a contact.
- Purposes: creating and delivering the card, recording visits and points, sending card push messages, handing back the contacts left on a digital business card together with the record of how it was passed on, and the security of the Service.
4. Our commitments
- We use your customers' data only to operate the Service — never for our own marketing. We never sell it, rent it, or use it for advertising.
- We keep it confidential: access is limited to what operating the Service requires, protected by authentication and role-based access, and each establishment only ever sees its own customers.
- We secure it: encrypted transport (HTTPS/TLS), sensitive card secrets encrypted at rest, hashed passwords, tenant isolation enforced in the database, and forgery-protected scan codes.
- We assist you with data subject requests: your dashboard lets you erase a customer's personal details on the spot, and we answer any request you escalate to us within the legal timeframe.
- We notify you of a breach affecting your customers' data without undue delay, and in any case within 72 hours of becoming aware of it, with what we know: the nature of the breach, the categories and approximate number of customers concerned, the likely consequences, and the measures taken. Where we cannot give all of it at once, we send it in stages without further delay, so you can meet your own notification duties.
- We delete on request: erasing a customer from your dashboard removes their identity details immediately, and a card left unused is erased automatically 36 months after its last visit; the visit records themselves stay, stripped of everything that names the customer.
- For a digital business card, you erase a single contact from the card's contact list, and deleting the card removes every contact left on it; the person can also write to contact@kartalik.com. Erasure leaves the anonymous point in the sharing chain standing, so that no one else's chain breaks.
- Our staff and anyone we authorise to process your customers' data is bound by a duty of confidentiality that survives the end of their engagement.
- We assist you, taking into account the nature of the processing and the information available to us, in keeping the processing secure, in notifying breaches to the CNDP and to the customers concerned, and in any prior consultation with the CNDP.
- We do not delete anything when a subscription ends. Ending a subscription only takes the loyalty card offline, so that renewing puts it back exactly as it was — the data stays until you ask for it to go. To close your account, write to contact@kartalik.com from the email address on the account; we delete or anonymize your customers' data within 30 days of that request and confirm when it is done, unless the law requires keeping some of it longer.
- We inform you before adding or replacing a provider that receives your customers' data, so you can object before the change applies to your data.
5. Your commitments
- You file nothing with the CNDP for the Service: we declare the platform's processing and its transfers, and the enrollment page cites our receipt number. Any processing you run outside the Service — a customer file of your own, exports — remains yours to declare.
- You inform your customers and collect their consent — the enrollment form does this for you and records when each customer accepted.
- You use the data only for legitimate loyalty purposes, honour opt-outs, and answer your customers' access, correction and deletion requests — the dashboard gives you the tools.
- You keep your account credentials safe and manage your staff's access responsibly. Because every scan is recorded against the account that performed it, you tell the staff member concerned before creating their account, and you deactivate accounts of people who have left.
6. Providers and recipients
The Service relies on the following providers, strictly to deliver it:
- Apple Inc. (United States) — delivers and updates Apple Wallet passes for customers who chose Apple Wallet;
- Google LLC (United States) — delivers and updates Google Wallet passes for customers who chose Google Wallet;
- Hostinger International Ltd. — hosting AND email delivery, on servers located in the European Union; it sends the transactional emails described in the Privacy Policy.
- OpenStreetMap Foundation (United Kingdom) — its map tiles and address search are loaded by YOUR browser on the dashboard's store-location picker; it sees your browser's address, never your customers' data;
Beyond these, we use no other provider. There is no analytics provider, no advertising network and no customer-data enrichment service in the Service.
7. International transfers
Hosting stays in the European Union, on the CNDP's list of countries ensuring an adequate level of protection. Delivering a pass to Apple Wallet or Google Wallet transfers the pass data to the United States, which is not on that list: the transfer rests on the customer's express consent given at enrollment (art. 44); we file the transfer requests with the CNDP ourselves, so you have nothing to file.
8. Marketing messages
The platform enforces article 10 of Law 09-08 for you: marketing pushes only ever reach customers who separately opted in at enrollment, and balance updates after a visit are service messages, not marketing. You remain responsible for the content of the campaigns you send.
9. Audit and information
On written request, we provide the information reasonably necessary to demonstrate compliance with this DPA — including our security measures and provider list — we allow and contribute to audits and inspections you or an auditor you mandate carry out, and we cooperate with any control by the CNDP concerning this processing.
10. Liability and precedence
Each party is responsible for its own obligations under Law 09-08. In case of conflict between this DPA and the Terms of Use & Sale, this DPA prevails for everything concerning your customers' personal data. The liability limits of the Terms apply.
11. Contact
For any question about this agreement or about your customers' data: contact@kartalik.com — APPT N 7 ETG 2 LOT AL MASAR N 643, Marrakech.