Back to Home
Data Processing Agreement
Version 1.0.0, effective 2 June 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you, the business using Habulo, and Habulo. It governs our processing of personal data relating to your end customers, which you collect and control through the Service. It is entered into under Article 28 of the GDPR. Where this DPA conflicts with the Terms of Service on the subject of personal data processing, this DPA prevails.
1. Roles of the Parties
You are the data controller for the personal data of your end customers processed through the Service. You determine the purposes of that processing, the data fields you collect, the communications you send, and the legal basis for each.
We are your data processor for that data. We process it only to provide the Service to you and on your instructions.
Separately, and outside this DPA, we are an independent data controller for the personal data of your own account and team members (name, email, role, billing and usage data). That processing is described in our Privacy Policy and is not governed by this DPA.
Neither party is a joint controller with the other.
2. Subject Matter, Duration, Nature and Purpose
Subject matter: the personal data of your end customers held in the Service.
Duration: for as long as your account is active, and thereafter only for the limited period described in section 11.
Nature and purpose: providing a digital loyalty platform on your behalf. This includes enrolling customers in your loyalty programs, issuing and updating digital wallet passes, recording loyalty activity and rewards, producing analytics and engagement insights for you, and delivering the notifications and communications you configure, in each case as instructed by you through the Service.
3. Types of Personal Data and Categories of Data Subjects
Categories of data subjects: your end customers, meaning individuals who enroll in a loyalty program you operate.
Types of personal data, in each case as you choose to collect them:
- Contact details, such as email address and phone number.
- Identity details, such as first and last name.
- Optional profile details you invite the customer to provide, such as a date of birth or a stated preference.
- Loyalty activity, including balances, transactions, rewards, redemptions, visit timing and, where your program uses spend, purchase amounts.
- Device data relating to a digital wallet pass, being a pass identifier and a notification token supplied by the wallet platform.
- Free-text notes your staff record about a customer.
- Communication preferences, including whether the customer has opted in to marketing.
No special categories of personal data under Article 9 are required by the Service. You must not use the Service to process special category data or data relating to criminal convictions.
4. Processing on Your Instructions
We process end customer personal data only on your documented instructions, including in relation to transfers to a third country, unless required to do otherwise by Union or Member State law. Where such a legal requirement applies, we will inform you before processing, unless that law prohibits us from doing so.
Your instructions are given through your configuration and use of the Service, through this DPA and the Terms of Service, and through any written instruction you send us.
We will inform you if, in our opinion, an instruction infringes the GDPR or other applicable data protection law. We may decline to act on an instruction that would require us to breach the law.
5. Confidentiality
We ensure that persons authorised to process end customer personal data are bound by an appropriate obligation of confidentiality, whether contractual or statutory, and that access is limited to those who need it to provide the Service or to support you.
Where our support staff access your account to investigate a problem, that access is recorded, including who accessed which account and when.
6. Security of Processing
We implement appropriate technical and organisational measures under Article 32, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to individuals. These measures currently include:
- Encryption of personal data in transit using TLS, and encryption at rest on managed database and storage infrastructure.
- Row level security in the database, so that a business account can reach only its own records, enforced by the database rather than by application code alone.
- Separate credentials for user scoped access and for server side operations, with server side credentials held only on the server and never exposed to a browser or a device.
- Authentication and session management provided by our hosting and authentication provider.
- Logging of administrative access to accounts, and of access to personal data through the automated assistance in the dashboard.
- Rate limiting of public endpoints to reduce automated abuse.
- An automated test suite that runs on every deployment, and review of infrastructure changes before release.
We may update these measures over time, provided the level of security is not reduced.
7. Sub-processors
You give us general written authorisation to engage sub-processors for the provision of the Service. The sub-processors engaged at the date of this DPA are:
- Supabase: database, authentication and file storage. Processed in Stockholm, Sweden, inside the EEA. No transfer mechanism required.
- Vercel: application hosting and delivery. Processed in Paris, France, inside the EEA, with operational support access from outside the EEA under Standard Contractual Clauses.
- Stripe: subscription billing and payment processing. Processed inside the EEA and in the United States, under Standard Contractual Clauses.
- Apple: issuing, updating and delivering Apple Wallet passes and their notifications. Processed in the United States, under Standard Contractual Clauses.
- Google: issuing and updating Google Wallet passes, and delivering notifications through Firebase Cloud Messaging. Processed in the United States, under Standard Contractual Clauses.
- Resend: transactional email delivery. Processed in the United States, under Standard Contractual Clauses.
- PostHog: product and usage analytics. Processed on PostHog's EU infrastructure, inside the EEA.
- OpenAI: automated assistance answering a business user's questions about its own loyalty data. Processed in the United States, under Standard Contractual Clauses. Under OpenAI's API terms the data sent is not used to train their models.
We impose on each sub-processor data protection obligations equivalent to those set out in this DPA, and we remain fully liable to you for the performance of that sub-processor's obligations.
We will inform you of any intended addition or replacement of a sub-processor at least 30 days before it begins processing, and you may object on reasonable data protection grounds within those 30 days. If you object and we cannot offer a reasonable alternative, you may terminate the affected part of the Service without penalty for the remainder of the subscription term.
8. Assistance with Data Subject Rights
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests from your end customers exercising their rights under Chapter III of the GDPR.
The Service provides functions that allow you to respond to most requests directly and without our involvement, including viewing and correcting a customer's details, exporting a customer's personal data in a structured, machine readable format, and erasing a customer's personal data.
If an end customer contacts us directly about data you control, we will not respond to the substance of the request ourselves. We will inform them to contact you and, where we can identify you as the relevant business, refer the request to you without undue delay.
9. Personal Data Breaches and Assistance with Articles 32 to 36
We notify you without undue delay after becoming aware of a personal data breach affecting end customer personal data we process for you. Our notification will describe, to the extent known to us, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.
You are responsible for assessing whether the breach must be notified to a supervisory authority or communicated to affected individuals, and for making any such notification, since you are the controller.
We assist you, taking into account the nature of processing and the information available to us, in ensuring compliance with your obligations under Articles 32 to 36, including data protection impact assessments and prior consultation where required.
10. International Transfers
Our primary infrastructure is located inside the European Economic Area: the database and file storage holding end customer personal data run in Stockholm, Sweden, and the application runs in Paris, France. End customer personal data is therefore stored within the EEA.
Certain sub-processors engaged under section 7 may process personal data on infrastructure located outside the EEA, including in the United States. Where personal data leaves the EEA we rely on a transfer mechanism approved under Chapter V of the GDPR, such as the European Commission's Standard Contractual Clauses or the EU to U.S. Data Privacy Framework where applicable.
Where we enter into Standard Contractual Clauses with a sub-processor that acts as a further processor of end customer personal data, we do so on Module Three (processor to processor) terms, as your processor and on your behalf.
We do not transfer end customer personal data outside the EEA other than through a sub-processor engaged under section 7.
11. Deletion or Return of Data
At your choice, we delete or return all end customer personal data to you at the end of the provision of the Service, and delete existing copies, unless Union or Member State law requires us to store it.
In practice: while your account is active you may export your customer data from the dashboard at any time. When your account or subscription ends, you have the opportunity to export that data before it is removed. Unless you ask us in writing within that period to return or retain it, the data is deleted within 90 days of the account ending.
Backups are overwritten in the ordinary course of their retention cycle. Accountability records that evidence who accessed personal data and when are retained for that purpose only, as described in our Privacy Policy.
12. Information and Audits
We make available to you all information necessary to demonstrate compliance with the obligations in Article 28 and this DPA, and we allow for and contribute to audits, including inspections, conducted by you or another auditor mandated by you.
In the first instance we will respond to your reasonable written questions and provide relevant documentation about our processing and security measures. Where that is not sufficient to demonstrate compliance, we will cooperate with an audit on reasonable prior notice, during business hours, no more than once in any twelve month period unless required by a supervisory authority or following a personal data breach, and subject to confidentiality. Audits must not unreasonably disrupt the Service or compromise the data of other customers.
13. Your Obligations as Controller
You warrant that:
- You have a lawful basis for each purpose for which you use the Service, including loyalty analytics, customer segmentation and marketing campaigns.
- You have given your end customers an appropriate privacy notice covering the processing carried out through the Service, and that you will keep it accurate as your use of the Service changes.
- You have obtained any consent required for the data fields you choose to collect and for any promotional communications you send, and that you honour withdrawals of consent and objections to direct marketing.
- You use the audience, segmentation and campaign features only to reach customers who are eligible to receive the communication in question under applicable data protection and electronic communications law.
- You do not enter special categories of personal data under Article 9, or data relating to criminal convictions, into any free-text field of the Service, including staff notes about a customer and any preference a customer is invited to type.
- Your instructions to us comply with applicable data protection law.
Where you export end customer personal data from the Service and use it in your own systems, you do so as controller and this DPA does not apply to that use.
14. Term, Changes and Contact
This DPA takes effect when you accept the Terms of Service and remains in force for as long as we process end customer personal data on your behalf.
We may update this DPA where required by law, by a change in our sub-processors, or to reflect a change in the Service. Material changes are notified under the changes section of our Privacy Policy before they take effect.
This DPA is published in English and in Greek and both versions are authentic. If there is a discrepancy between them, the Greek version prevails for customers established in Greece and the English version prevails for everyone else.
For any question about this DPA, or to send us a written instruction under it, contact Habulo, operated by Evangelos Spathonis, Leof. Kefallinon 39, 28100 Argostoli, Kefalonia, Greece, at info@habulo.com.
