Data Processing Agreement

Last updated 31 July 2026 · Version 2026-07-31

This agreement is published in draft while Wivly completes company registration and legal review. It describes how the service actually handles personal data today, but the registered entity and governing-law details are not yet final.

This agreement governs how Wivly processes personal data about your customers on your behalf. It applies automatically to every merchant using Wivly and forms part of the Terms of Service. You do not need to sign or return anything: accepting the Terms when you create your account accepts this agreement, and the version you accepted is recorded and shown in your dashboard settings.

The processor is Wivly. Data-protection contact: privacy@wivly.me.

1.Roles

  1. 1.1You are the controller of personal data about your customers and staff. You decide to run a loyalty program, what it collects, and what you do with it.
  2. 1.2Wivly is your processor. We process that data only to provide the service to you, on your instructions.
  3. 1.3Where we decide things for ourselves — your own account details, billing records, security logs, aggregate platform statistics — we act as a controller, and our Privacy notice explains that separately.
  4. 1.4Neither party is a joint controller with the other in respect of your customers' data.

2.What is processed, and for how long

Subject matter and purpose: running the loyalty, prepaid or membership program you have configured, including issuing wallet passes, recording visits and rewards, sending offers to the pass, and reporting on the program to you.

Duration: for as long as your account is open, plus the 30-day export window described in the Terms.

Data subjectsCategories of personal data
Your customers (program members)Name (optional), email (optional), birthday (optional, only if you ask for it), visit and reward history with time and venue, pass serial number, wallet device token, referral relationships, and a signed functional cookie identifying their card.
Your staffName, role, salted PIN hash, and attribution of the stamps and redemptions they record.
Your teamEmail address used to sign in, and the actions taken in the dashboard.

No special categories of personal data (Art. 9) are required by the service, and you must not use it to store them.

3.Our instructions

  1. 3.1We process personal data only on your documented instructions. Your configuration of the service, and this agreement, are those instructions.
  2. 3.2We will tell you if, in our opinion, an instruction infringes data-protection law, and may pause that processing until it is resolved.
  3. 3.3If we are legally required to process data beyond your instructions, we will tell you before doing so unless the law forbids that notification.
  4. 3.4We never sell your customers' data, never use it for our own advertising, never use one merchant's data to benefit another, and never use it to train models.

4.Confidentiality

Everyone we allow to process your data is bound by confidentiality obligations, is trained on their responsibilities, and gets access only where their job requires it. Access to merchant accounts by our support engineers is time-limited, read-only by default, and written to an audit log.

5.Security

We take appropriate technical and organisational measures under Art. 32. Today these include:

  • Data stored in the European Union, with the application and its database hosted in Ireland and Dublin.
  • Encryption in transit for all traffic, and encryption at rest at the database layer.
  • Strict tenant isolation: every query is scoped to one organization, and cross-organization reads are confined to a single audited module used only by platform administration.
  • Staff and venue PINs stored as salted scrypt hashes, never in plain text.
  • Customer identity carried in a signed, httpOnly token that is never exposed to page JavaScript.
  • No advertising or cross-site tracking anywhere. The only measurement is a cookieless page-view count on our own marketing pages; it never runs on any surface where your customers' data is present.
  • Least-privilege access for our own team, with support access to merchant accounts audit-logged as described above.
  • Regular dependency updates, and automated tests covering authentication, plan limits and pass integrity.

Security measures evolve. We may change them, but not in a way that materially reduces the protection of your customers' data.

6.Sub-processors

You give general authorisation for us to engage sub-processors. We impose data-protection obligations on each of them no less protective than those in this agreement, and we remain fully responsible to you for their performance.

The current list:

ProviderPurposeRegion
SupabaseDatabase & merchant authenticationEU (Ireland, eu-west-1)
VercelApplication hosting & serverless functionsEU (Dublin, dub1); US company
AppleApple Wallet passes & push notificationsUS (EU-US DPF)
GoogleGoogle Wallet passesUS (EU-US DPF)
ResendTransactional email: merchant sign-in and account notices, plus card recovery and prepaid card records for customers who gave an address. Never marketing to customers.US (SCCs)
StripeMerchant subscription billingUS (EU-US DPF)
Vercel Web AnalyticsAggregate page-view counts for our own marketing site (cookieless, no cross-site profiling)EU (Dublin, dub1); US company

We publish additions and removals on our sub-processor page at least 30 days before the change takes effect. If you object to a new sub-processor on reasonable data-protection grounds within that period, tell us at privacy@wivly.me; if we cannot resolve it, you may terminate the affected part of the service without penalty.

7.International transfers

Your customers' data is stored in the EU. Some sub-processors are US companies. Where data reaches them, transfers are covered by an adequacy decision (the EU-US Data Privacy Framework) or by the European Commission's Standard Contractual Clauses together with supplementary measures. The region column above states which applies to each provider.

8.Helping you answer your customers

  1. 8.1Your customers exercise their rights with you, not with us, because you are their controller.
  2. 8.2The dashboard already lets you action the common requests yourself: view everything held about one member, export it in a machine-readable format, correct it, and delete it permanently.
  3. 8.3If a request reaches us directly, we will not answer it on your behalf. We will pass it to you promptly, and help you respond, taking into account the nature of the processing.

9.Personal data breaches

  1. 9.1If we become aware of a personal data breach affecting your customers' data, we will notify you without undue delay, and in any case within 48 hours of becoming aware.
  2. 9.2Our notice will describe what happened, the categories and approximate number of people and records affected, the likely consequences, and the measures we have taken or propose to take.
  3. 9.3We will help you meet your own notification duties to your supervisory authority and, where required, to your customers. Reporting to the authority is your decision as controller.

10.Impact assessments

Taking into account the nature of the processing and the information available to us, we will give you reasonable assistance with data-protection impact assessments and any prior consultation with a supervisory authority (Arts. 35 and 36).

11.Deletion and return

  1. 11.1You can export your data at any time from your dashboard, and for 30 days after your account closes.
  2. 11.2At the end of that window we delete your customers' personal data. Deletion is real: removing a member cascades to their passes, visit history, notifications and device registrations rather than flagging a row as hidden.
  3. 11.3Independently of your account, personal data expires on a published schedule: individual visit records after 24 months, the aggregate analytics behind your dashboard after 14 months, message delivery records after 6 months, and a device push token for a removed card within 30 days. A daily job enforces it — this is a running process, not a policy statement.
  4. 11.4We may retain data for longer only where law requires it (for example, billing records for tax purposes), and only for that purpose.
  5. 11.5Backups are retained on a rolling schedule and overwritten in the ordinary course. Data in a backup remains protected by this agreement until it is overwritten.

12.Audits and information

  1. 12.1We will make available the information you reasonably need to demonstrate compliance with Art. 28, on request to privacy@wivly.me.
  2. 12.2You may audit our processing, or appoint an independent auditor to do so, no more than once a year unless a breach or a supervisory authority requires otherwise. Give us reasonable notice, keep findings confidential, and avoid disrupting the service or other merchants' data.
  3. 12.3Where we hold an appropriate third-party certification or report, we may offer that first to satisfy an audit request.

13.Changes to this agreement

We will update this agreement as the service and the law change. Substantive changes carry a new version number and are notified in the dashboard, where you will be asked to accept the new version. The version you accepted, and the date, are recorded on your account and shown in your settings.

This agreement supplements the Terms of Service. For what your customers should know, see the Privacy notice; for the current sub-processor list and its change log, see the sub-processor page.

← Wivly

Data Processing Agreement · Wivly