⚠️ VORLAGE / TEMPLATE — vor Veröffentlichung von einer Anwältin/einem Anwalt prüfen lassen. / Have this reviewed by a lawyer before publishing.

This is a non-binding convenience translation — the German version (AVV) prevails.

Data Processing Agreement pursuant to Art. 28 GDPR

between the customer of the Stampbird platform — hereinafter the "Controller" —

and

Nebold, owner Taha Cemal Kaya (sole proprietorship), Wittelsbacherallee 107, 60385 Frankfurt am Main, Germany, represented by Taha Cemal Kaya (owner) — hereinafter the "Processor" —

1. Subject matter and duration of the processing

1.1 The Processor operates the Stampbird SaaS platform for the Controller for the management of digital loyalty cards. The subject matter of this agreement is the associated processing of personal data of the Controller's end customers on behalf of the Controller.

1.2 The duration of this agreement corresponds to the term of the main contract (Stampbird Terms of Service). It ends upon its termination, without prejudice to the obligations under section 9.

2. Nature and purpose of the processing

Nature of the processing: collection, storage, alteration, retrieval, transmission (to wallet platforms at the data subject's instigation), restriction, erasure and anonymisation.

Purpose: management of the Controller's loyalty programme — issuing and updating digital loyalty cards, maintaining stamp/points accounts, redeeming rewards, consent-based messages to end customers, and fulfilment of data subject requests.

3. Categories of personal data

  • name (optional input by the data subject),
  • e-mail address (optional input),
  • birthday — day and month only — exclusively with separate consent for birthday campaigns,
  • visit and stamp/points history of the loyalty card,
  • preferred language,
  • technical pass-delivery data (serial number, wallet registration, push delivery logs) and consent records (type, version, timestamp, IP address, browser identifier).

Special categories of personal data (Art. 9 GDPR) are not the subject of the processing; the Controller ensures that no such data is introduced.

4. Categories of data subjects

End customers of the Controller (holders of the loyalty cards issued by the Controller).

5. Controller's right to issue instructions

5.1 The Processor processes the data exclusively within the framework of the agreements made and on the documented instructions of the Controller (Art. 28 (3)(a) GDPR), unless required to process by Union or Member State law; in such a case, the Processor informs the Controller of that legal requirement before processing, unless that law prohibits such information.

5.2 The Controller's use of the platform features (e.g. creating campaigns, automation rules, exports) constitutes an instruction. Instructions outside the scope of the platform features require text form.

5.3 If the Processor considers an instruction to infringe data protection law, it informs the Controller without undue delay and may suspend execution until the instruction is confirmed or amended.

6. Obligations of the Processor

6.1 The Processor ensures that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28 (3)(b) GDPR).

6.2 The Processor implements the technical and organisational measures pursuant to Art. 32 GDPR as set out in Annex 1 and keeps them in line with the state of the art; the level of protection may not be reduced.

6.3 The Processor assists the Controller, within its means, in fulfilling the obligations under Art. 32 to 36 GDPR (security, breach notification, data protection impact assessment, consultation).

6.4 The Processor notifies the Controller of personal data breaches concerning this engagement without undue delay after becoming aware of them and supports the Controller with its notification and communication obligations (Art. 33, 34 GDPR).

6.5 The Processor has not appointed a data protection officer where no statutory obligation exists; the contact point for data protection matters is office@nebold.com. If an appointment obligation arises, the Processor will communicate the contact details.

6.6 Processing takes place in the European Union (hosting in Germany). Processing in third countries occurs only under the conditions of Art. 44 et seq. GDPR (see Annex 2).

7. Sub-processors

7.1 The Controller grants general authorisation for the engagement of the sub-processors listed in Annex 2.

7.2 The Processor informs the Controller of intended changes (addition or replacement of sub-processors) in text form at least 30 days before they take effect. The Controller may object to the change within this period for important data-protection-related reasons. In the event of an objection, the parties will endeavour to find an amicable solution; if this fails, either party is entitled to terminate the main contract as of the date on which the change takes effect.

7.3 The Processor imposes on sub-processors, by way of contract, in substance the same data protection obligations as set out in this agreement (Art. 28 (4) GDPR). Where a sub-processor fails to fulfil its obligations, the Processor remains liable to the Controller for the performance of that sub-processor's obligations.

8. Assistance with data subject rights

8.1 The Processor assists the Controller by appropriate technical and organisational measures in responding to requests from data subjects (Art. 12 to 23 GDPR).

8.2 To this end, the Processor in particular provides a built-in self-service portal, reachable from every loyalty card, through which data subjects can independently and in an automated manner exercise data access and export (Art. 15, 20 GDPR), erasure/anonymisation (Art. 17 GDPR) and the management of consents (Art. 7 (3) GDPR).

8.3 If a data subject contacts the Processor directly, the Processor forwards the request to the Controller without undue delay, unless the request is fulfilled automatically via the self-service portal.

9. Deletion and return upon termination

9.1 After termination of the main contract, the Controller may retrieve its data for 90 days via the export function in a structured, commonly used and machine-readable format (return).

9.2 After expiry of this period, the Processor deletes or anonymises all personal data processed on behalf of the Controller, unless retention is required by Union or Member State law (Art. 28 (3)(g) GDPR). Upon request, the Processor confirms the deletion in text form.

9.3 The Processor's statutory retention obligations (e.g. for billing data) remain unaffected; the data concerned is blocked for other purposes.

10. Controller's audit rights

10.1 The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR (Art. 28 (3)(h) GDPR), in particular current descriptions of the technical and organisational measures and existing audit reports or certifications.

10.2 The Controller is entitled to conduct audits — including inspections — itself or through an auditor bound to confidentiality. On-site inspections take place after prior notice with a reasonable lead time (as a rule 14 days), during usual business hours, without disproportionate disruption of operations, and at most once per year unless a specific incident warrants a further audit.

10.3 For inspections going beyond the provision of existing evidence, the Processor may charge a reasonable fee, unless the inspection was occasioned by circumstances for which the Processor is responsible.

11. Final provisions

11.1 In the event of conflicts between this agreement and the main contract, this agreement prevails in data protection matters.

11.2 Amendments and supplements require text form. German law applies; the place of jurisdiction is Frankfurt am Main, Germany.

11.3 The invalidity of individual provisions does not affect the validity of the remaining provisions.


Annex 1 — Technical and organisational measures (Art. 32 GDPR)

  1. Encryption: All data transmissions are encrypted via TLS (HTTPS); signed pass and portal links with HMAC tokens against serial-number guessing; access tokens stored as hashes only.
  2. Access control: Role-based authorisation concept in the merchant dashboard (owner/manager/staff), scanner access with additional PIN confirmation and rate limiting, API access via hashed API keys.
  3. Tenant separation: Logical separation of controller data at the database level — every tenant-owned table carries a tenant ID; all access passes through a central, enforced tenant-scoping layer; the separation is continuously verified by automated tests.
  4. Logging: Audit log of security- and privacy-relevant events (including erasures, consent changes, send decisions) with defined retention periods.
  5. Data minimisation and deletion concept: Collection of required fields only (name/e-mail optional, birthday day/month only with consent); automated purge jobs: session artifacts after 30 days, push logs after 180 days, audit logs after 365 days, anonymisation of inactive end-customer profiles after 730 days.
  6. Availability and resilience: Regular database backups, tested restore procedures, operation in EU data centres (Germany) with redundant infrastructure.
  7. Organisational measures: Confidentiality obligations of staff, least-privilege principle for internal access, separate development and production environments, logging of administrative access.

Annex 2 — Approved sub-processors

Company Service Place of processing
Hetzner Online GmbH, Gunzenhausen (DE) Hosting, database and infrastructure operation Germany (Falkenstein/Nuremberg)
Stripe Payments Europe Ltd., Dublin (IE) Payment processing for merchant subscriptions (no loyalty-programme end-customer data) EU/EEA; any third-country transfers with safeguards pursuant to Art. 46 GDPR
{SMTP_ANBIETER} (EU SMTP provider) Dispatch of transactional e-mails EU
Anthropic, PBC, San Francisco (US) Optional AI assistant for campaign copy; processes only text entered by the Controller, no end-customer data USA; EU Standard Contractual Clauses / adequacy mechanisms pursuant to Art. 44 et seq. GDPR

Note: Apple (Apple Wallet/APNs) and Google (Google Wallet) are not sub-processors; they process pass data as independent controllers as soon as the data subject adds the pass to their wallet.