Last updated: 1 October 2026
This Data Processing Agreement ("DPA") forms part of the Passtastic Terms & Conditions and applies automatically to every customer who uses Passtastic to run a loyalty programme. You do not need to sign or request a separate copy: by accepting the Terms, this DPA is in force between you and us.
It sets out how we handle the personal data of your customers — the people who add one of your loyalty cards — as required by Article 28 of the General Data Protection Regulation (GDPR). It supplements our Privacy Policy, which explains our data practices more generally.
Where this DPA conflicts with the Terms & Conditions on the subject of processing your customers' personal data, this DPA prevails.
The particulars required by Article 28(3) GDPR. Where this DPA says "your customers' data", it means the personal data described here.
| Subject matter | Our provision of the Passtastic digital loyalty platform to you. |
|---|---|
| Duration | For as long as your account is active, and afterwards until you ask us to delete the data (see section 12). |
| Nature and purpose | Hosting, storing, processing and transmitting your customers' data in order to run your loyalty programme: issuing and updating wallet cards, recording visits, stamps, points and balances, delivering push notifications and SMS at your instruction, producing analytics for you, and exchanging data with any system you choose to connect (see section 8). |
| Types of personal data | Name, email address, phone number, loyalty activity (visits, stamps, points, balances, rewards claimed), wallet push tokens issued by Apple and Google, and any additional fields you choose to collect in your own sign-up form. |
| Categories of data subjects | Your customers — the people who add one of your loyalty cards to their mobile wallet, and anyone you invite or import into your programme. |
| Special category data | The Service is not designed for special category data (Article 9 GDPR) such as health, biometric or religious information, and you must not configure your sign-up form to collect it. |
Which of us is responsible for what depends on whose data is involved.
| Data | Our role | Who is the controller |
|---|---|---|
| Your customers' data (people who add your loyalty card) | Processor | You |
| Your own account data (registration, billing, platform usage) | Controller | Passtastic |
We process your customers' data only on your instructions. Your instructions are: this DPA, the Terms & Conditions, and the actions you take in the platform — the programme you set up, the messages you send, the integrations you connect, and any support request you make to us in writing.
We will not use your customers' data for our own purposes. We do not sell it, and we do not share it with other merchants.
If we believe an instruction from you would breach data protection law, we will tell you and may decline to carry it out until the point is resolved.
As the controller, you decide why and how your customers' data is processed, and some duties are yours alone. By using the Service you confirm that:
Access to your customers' data is limited to the people who need it to operate and support the Service, and everyone with such access is bound by written confidentiality obligations that survive the end of their engagement with us.
We keep each organisation's data logically separated, and every person on your own account holds a role that determines what they can see and do.
We protect your customers' data with encryption in transit (HTTPS/TLS) and at rest, role-based access control, per-organisation data isolation, and encryption at rest for the credentials of any system you connect. Our database and application hosting run on providers certified to ISO 27001 and SOC 2.
No system is completely secure and we cannot guarantee absolute security, but we keep these measures under review and will not reduce the overall level of protection during your subscription.
You give us general authorisation to engage the sub-processors listed under Sub-processors in our Privacy Policy. Each one processes only the minimum data needed for its function, and each is bound by data protection terms no less protective than this DPA.
We keep that list current and publish any addition or replacement there at least 30 days before it takes effect. Changes are announced by publication on that page rather than by individual email, so please check it if you wish to track changes.
Where we have to replace a sub-processor at short notice — because of an outage, a security concern, or because the provider stops serving us — we may do so immediately and will publish the change as soon as we can.
If you reasonably object to a new sub-processor on data protection grounds, tell us before the change takes effect. If we cannot offer you a practical alternative, you may terminate the affected part of the Service without penalty for the remainder of your paid term.
You can connect Passtastic to other systems you already use, such as a point-of-sale or accounting system. Those systems belong to you, not to us: they are not our sub-processors, and what happens to data inside them is governed by your own agreement with that provider.
When you connect one, data moves in both directions. We read the information needed to run your programme — sales, products, categories, and the contact details of the customer on a sale — and, where you enable it, we write into that system: the loyalty programme, its rules and rewards, and contact records for your members so your staff can find them at the counter.
To do this we store the access credentials you provide, encrypted at rest. You can disconnect an integration at any time, which stops all further exchange of data. Records we have already written into your own system remain yours and stay there.
Your customers exercise their rights with you, as the controller. The platform is built so that you can answer most requests yourself, immediately:
If one of your customers approaches us directly about their data, we will not answer for you: we will tell them to contact you as the controller, and let you know so that you can respond within your own deadline.
If a court, regulator or law enforcement body demands your customers' data from us, we will tell you before we disclose anything, so that you can respond or object — unless we are legally forbidden from telling you. We will disclose only what we are actually required to disclose.
If we become aware of a personal data breach affecting your customers' data, we will notify you without undue delay at the email address on your account.
We will tell you what we know: what happened, which categories and roughly how many records are affected, the likely consequences, and what we are doing about it. Where we do not have the full picture at once, we will send what we have and follow up.
You are responsible for notifying your supervisory authority and, where required, the affected individuals — the GDPR gives you 72 hours from becoming aware. We will give you the information reasonably available to us so you can meet that deadline, and will not withhold it pending our own investigation.
You can export your customer data from the dashboard at any time while your account is active, so you always have your own copy.
You can delete your customers' data yourself at any time using the erasure function described in section 9. If you would rather we did it, email us at hello@passtastic.io from an address on your account and we will action it without undue delay.
We do not currently delete your customers' data automatically when a subscription ends — it remains available so that you can reactivate or export it. If you want it removed, ask us and we will remove it. We may retain data where law requires, and anonymised or aggregated statistics that cannot identify anyone may be kept.
When we delete a loyalty card holder, we keep a minimal non-identifying record so the same wallet pass cannot be silently re-created, and that record expires automatically.
On request we will make available the information reasonably necessary to demonstrate our compliance with this DPA. In practice that means this DPA, our Privacy Policy, our current sub-processor list and a description of our security measures, together with the ISO 27001 and SOC 2 certifications held by our infrastructure providers.
Where an audit beyond that documentation is required by data protection law, it will be limited to once in any twelve-month period, carried out at your cost, on at least 30 days' written notice, during normal business hours, without disrupting the Service, and subject to confidentiality. We may satisfy such a request with the documentation above where it reasonably answers the question.
Our database and application hosting are located in the European Union. Some of the sub-processors listed in our Privacy Policy process limited data outside the European Economic Area; where they do, the transfer is covered by the European Commission's Standard Contractual Clauses or by an adequacy decision.
We will not move your customers' data outside the EEA on any other basis without telling you first.
Nothing in this DPA changes how liability works between us. The limitations and exclusions of liability in section 7 of the Terms & Conditions apply to claims under this DPA as they do to any other claim, and apply to the two of us together rather than once per document.
This does not limit any right a data subject has directly against either of us under the GDPR, or anything that cannot lawfully be limited.
We may update this DPA, for example to reflect a change in law or in how the Service works. The current version is always on this page with the date it took effect, and we will give notice of any material change in the same way we give notice of changes to the Terms.
We will not make a change that materially reduces the protection given to your customers' data during your paid term.
For anything about this DPA, about a data subject request, or to ask us to delete your customers' data, contact us at: