This agreement is part of our terms for Tap Tile Loyal. It sets out how we handle the personal data of your customers when we run your stamp card for you, as Article 28 of the GDPR requires.
This agreement is between you, the business that subscribes to Tap Tile Loyal, and Jake Zammit, a sole trader trading as Luzzu Labs, 182 Mdina Road, Ħaż-Żebbuġ ZBG 9015, Malta, VAT number MT27302808 ("we" or "us"). You accept it when you accept our terms at sign-up. If this agreement and the rest of our terms disagree about personal data, this agreement wins.
When we run your stamp card, we handle two kinds of personal data, and our role is different for each.
Annex 1 sets out the subject, duration, nature and purpose of the processing, the types of personal data and the people it is about.
We process your customers' data only on your documented instructions. Your instructions are these terms, the settings you choose in your dashboard (such as your messages, campaigns and who they go to), and anything else you ask us in writing by email. We do not use the data for our own purposes, sell it or share it, except as this agreement allows.
If the law requires us to process the data in another way, we tell you first, unless that law forbids it.
If we think an instruction of yours breaks data protection law, we tell you straight away, and we may refuse to follow it until it is resolved.
Today the only person who can access the data is Jake Zammit. Anyone we allow to access it in future will first be bound to keep it confidential, by contract or by law.
We protect the data with the technical and organisational measures in Annex 2. They take into account the risks involved, as Article 32 of the GDPR requires. We may change them over time, but never lower the overall level of protection.
You give us general permission to use the sub-processors listed in Annex 3. Before we add or replace a sub-processor, we email you at least 30 days in advance. You may object in writing within that time, for a reasonable data protection reason. If we cannot meet your objection, you may end your subscription before the change applies, and we refund any fee you paid in advance for the time after the change.
Vercel, Neon and Resend work for us under a written data processing agreement. We use GitHub and Google's email service on the providers' standard terms, which have no separate processing agreement for the plans we use. GitHub holds only the encrypted nightly copy, and our inbox holds the requests you or your customers send us. Apple and Google run their own wallets and receive only what a card needs. We stay responsible to you for the work of every sub-processor.
Your customers can see and delete their own data from their card, and we carry out what they choose straight away. If one of your customers asks us to see or correct their data, or to stop messages, we tell you, unless it concerns only the data we hold as a controller. You instruct us now to carry out a customer's request to delete their card or to stop messages, whether they make it on their card or to us directly. Your Members page shows how many members deleted their card in the last 30 days, and when a customer writes to us we tell you afterwards.
Your dashboard lets you see each member's stamps, stop their messages and set a card back to 0 stamps. For anything the dashboard cannot do, ask us by email and we do it within 7 days.
We give you the information you reasonably need, about the processing we do for you, for your own security, for a data protection impact assessment, and for any consultation with the Information and Data Protection Commissioner (Articles 32 to 36 of the GDPR).
If we become aware of a personal data breach that affects your customers' data, we tell you without undue delay, and where possible within 48 hours, by email to your owner email address. We tell you what happened, which data and roughly how many people it affects, the likely consequences, and what we have done and will do about it. If we do not know everything yet, we tell you what we know and send the rest as soon as we can. We keep a record of every breach.
Your customers' data is stored in the European Union, in Frankfurt, Germany. Some sub-processors in Annex 3 are companies based in the United States. Where data goes to them, the transfer relies on the EU-US Data Privacy Framework or on the European Commission's Standard Contractual Clauses, as Annex 3 shows.
When your subscription ends, we keep your customers' data for 12 months, so everything resumes if you subscribe again. If you ask before then, we send you your customers' data first. During that time you can sign in and export your members, or ask us by email and we send you the list. We email you 30 days before the 12 months end. Then we delete your customers' data, your card settings and your account. Copies in our nightly backups are deleted within 30 days after that. If you delete your account from your dashboard, or ask us to delete everything sooner, we do it straight away. We keep data longer only where the law requires it, such as invoices.
We make available to you the information you need to check that we keep to this agreement. Once a year, or after a breach, you may send us written questions, and we answer within one month. If the answers are not enough, or a supervisory authority asks for it, you or an auditor you choose, bound to keep it confidential, may inspect how we process your customers' data, at a time we agree with at least 30 days' notice. You pay your own costs and the auditor's.
Each of us is responsible for its own duties under data protection law. Between you and us, the limits in section 13 of our terms apply to this agreement too, except where the law does not allow them. This agreement lasts for as long as we process your customers' data for you. If data protection law changes, or a supervisory authority requires it, we may update this agreement. We email you 30 days before a change applies, unless the law requires it sooner.
Stripe is left out on purpose. It handles the business's own payments, where we are the controller, and never your customers' data.