Skip to content
Book a demo

Legal

Data Processing Agreement

Data Processing Agreement

Annex 1 to the WalletHero Platform Terms of Service

Version: 1.0 · Date: 28 July 2026

Language note. This English version is provided as a courtesy translation. The Polish version (Umowa powierzenia) is the legally binding text. In case of any discrepancy, the Polish version prevails.

concluded between:

jointly the “Parties”.

This agreement (the “DPA”) constitutes the contract referred to in Art. 28(3) of Regulation (EU) 2016/679 (“GDPR”) and is concluded upon conclusion of the platform service agreement (the “Main Agreement”).

1. Subject matter and duration of processing

  1. The Controller entrusts the Processor with the processing of personal data of end customers and other persons whose data the Controller enters into its workspace on the Platform, within the scope and on the terms set out in this DPA.
  2. Processing takes place for the duration of the Main Agreement and for the period necessary to return or delete the data after its termination, in accordance with Section 10.

2. Nature and purpose of processing

  1. Nature of processing: processing in an IT system (SaaS), including in particular: collection, recording, organization, storage, alteration, retrieval, use, transmission (including delivery of passes and notifications), restriction, erasure, and anonymization of data.
  2. Purpose of processing: provision of the WalletHero Platform services to the Controller, in particular:
    • issuing and updating mobile wallet passes (Apple Wallet, Google Wallet),
    • operating a loyalty program (points, tiers, automations, referral program),
    • running campaigns addressed to audiences defined by the Controller,
    • operating the mobile application for the Controller’s staff,
    • operating integrations enabled by the Controller.

3. Categories of data and data subjects

  1. Categories of personal data:
    • identification data (first name, last name, customer identifiers),
    • contact data (email address, phone number),
    • date of birth,
    • purchase and loyalty activity history (transactions, points, tiers, referrals, campaign participation),
    • device identifiers and push notification tokens (related to the delivery of passes and notifications),
    • custom fields defined by the Controller.
  2. Categories of data subjects: the Controller’s end customers (pass holders, loyalty program members) and — to the extent the Controller enters their data — other persons (e.g., the Controller’s staff, with respect to data handled within the workspace).
  3. The Controller undertakes not to enter special categories of data (Art. 9 GDPR) or data relating to criminal convictions (Art. 10 GDPR) into the Platform, in particular in custom fields, without a valid legal basis and prior arrangement with the Processor.

4. Obligations of the Processor

The Processor undertakes to:

  1. process the data only on the documented instructions of the Controller — the Main Agreement, this DPA, and instructions issued by the Controller via the Platform’s features (including the API) being deemed documented instructions — unless required to process by Union or Member State law; in such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest;
  2. immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions;
  3. ensure that persons authorized to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and process the data only to the extent necessary to provide the services;
  4. implement the technical and organizational measures referred to in Section 5;
  5. respect the conditions for engaging sub-processors set out in Section 6;
  6. assist the Controller in accordance with Sections 7 and 8;
  7. delete or return the data after the end of the provision of services, in accordance with Section 10;
  8. make available to the Controller the information necessary to demonstrate compliance with Art. 28 GDPR and allow for audits in accordance with Section 9.

5. Security measures (Art. 32 GDPR)

  1. The Processor implements and maintains appropriate technical and organizational measures, taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the risk to the rights and freedoms of natural persons, including in particular:
    • logical isolation of each Controller’s data (workspace-level separation; access authorization verified against the workspace),
    • encryption of data in transit (TLS),
    • storage of credentials as cryptographic hashes (passwords, mobile app session and refresh tokens),
    • role-based access control (distinct administrator and staff roles, with role-restricted actions),
    • hosting in the European Union (DigitalOcean infrastructure, Frankfurt region), including the managed database and file storage,
    • backups and mechanisms to restore the availability of data,
    • monitoring of errors and events to detect irregularities,
    • restriction of the Processor’s personnel access to production data to necessary cases (maintenance, support, security).
  2. The Processor regularly reviews and updates the measures applied.

6. Sub-processing

  1. The Controller grants the Processor a general authorization to engage the sub-processors listed in the Subprocessor List, which forms an integral part of this DPA.
  2. The Processor shall inform the Controller of intended additions or replacements of sub-processors at least 30 days in advance (by email or in-panel notice), giving the Controller the opportunity to object. In the event of a justified objection, the Parties shall discuss in good faith to find a solution; if no solution is found, the Controller may terminate the Main Agreement with respect to the services affected by the change.
  3. The Processor imposes on each sub-processor — by contract — the same data protection obligations as set out in this DPA, in particular the obligation to implement appropriate security measures. The Processor remains fully liable to the Controller for the performance of the sub-processors’ obligations.
  4. Transfers of data to sub-processors established outside the European Economic Area take place only in compliance with Chapter V GDPR (in particular Standard Contractual Clauses or an adequacy decision, including the EU–U.S. Data Privacy Framework for certified providers), per the mechanisms indicated in the Subprocessor List.

7. Assistance with data subject rights

  1. Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organizational measures in fulfilling the Controller’s obligation to respond to data subject requests (Art. 15–22 GDPR).
  2. To this end, the Platform provides, among others: access to and export of an end customer’s data, rectification (editing), and deletion or anonymization of an end customer’s data on the Controller’s instruction.
  3. If a data subject addresses a request directly to the Processor, the Processor will promptly forward it to the Controller and will not respond to it on the merits itself, unless the Controller instructs otherwise or a response is required by law.

8. Assistance with security and personal data breaches

  1. The Processor assists the Controller in ensuring compliance with the obligations under Art. 32–36 GDPR (security, breach notification, data protection impact assessments, prior consultation), taking into account the nature of the processing and the information available to it.
  2. After becoming aware of a personal data breach concerning the entrusted data, the Processor shall notify the Controller without undue delay and no later than within 72 hours of becoming aware of the breach, providing — as available — the information referred to in Art. 33(3) GDPR (nature of the breach, categories and approximate number of data subjects and records, likely consequences, measures taken and proposed).
  3. The Processor documents breaches and cooperates with the Controller in handling them. Notifications to the supervisory authority and communications to data subjects are made by the Controller as the data controller.

9. Audits

  1. The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
  2. An audit shall be conducted upon prior notice of at least 14 business days, during business hours, in a manner that does not unreasonably disrupt the Processor’s operations, and no more than once every 12 months — unless an audit is required by a supervisory authority or follows a confirmed breach.
  3. The auditor may not be a direct competitor of the Processor and is subject to a confidentiality undertaking.
  4. The Processor may in the first instance satisfy the audit obligation by providing current documentation, internal audit results, or certifications it holds.

10. End of processing — return and deletion of data

  1. After the end of the Main Agreement, the Processor — at the choice of the Controller — returns all the entrusted data to the Controller (export in a commonly used, machine-readable format) or deletes it, and deletes existing copies, unless Union or Member State law requires storage of the data.
  2. The Controller may request the return of the data within 30 days of the end of the Main Agreement. After the unsuccessful expiry of that period, the Processor deletes or irreversibly anonymizes the entrusted data.
  3. Deletion also covers data in backups — at the latest upon expiry of the backup rotation cycle; until then, data in backups is not used for any other purposes.
  4. At the Controller’s request, the Processor will confirm the deletion of the data in writing or in electronic form.

11. Liability

  1. Each Party is liable for damage caused by its processing infringing the GDPR, on the terms set out in Art. 82 GDPR.
  2. The limitations of liability provided for in the Main Agreement apply to this DPA to the fullest extent permitted by law; they do not limit liability towards data subjects or liability arising from mandatory provisions of law.

12. Final provisions

  1. This DPA remains in force for the duration of the Main Agreement and until completion of the activities referred to in Section 10.
  2. Matters not regulated herein are governed by the Main Agreement, the GDPR, and Polish law.
  3. In the event of a conflict between this DPA and the Main Agreement with respect to personal data protection, this DPA prevails.
  4. The binding version is the Polish version; the English translation is for information only.

Annex: Subprocessor List