Data Processing Agreement
Agreement on processing of personal data on behalf pursuant to Art. 28 GDPR
This is a courtesy translation. The German version is legally binding.
Draft · Last updated: 15 August 2026
This agreement forms part of the service contract between the business owner and Theky and takes effect upon conclusion of the subscription. It governs the processing of data of the guests who use the business owner's loyalty card. For this data, the business owner is the controller and Theky is the processor. You may save or print this page as a record.
- Parties
- Subject matter and duration
- Nature, purpose, data types, data subjects
- Instructions
- Confidentiality
- Technical and organisational measures
- Sub-processors
- Assistance to the controller
- Notification of data breaches
- Deletion and return
- Evidence and audits
- Third countries
- Liability and final provisions
- Annex 1: Sub-processors
- Annex 2: Technical and organisational measures
1. Parties
Controller (the "Customer"): the business owner / company that holds a Theky account. The specific details (name, address) follow from the account and the service contract.
Processor: Theky GbR, Batuhan Karadag and Ahmet Kazmacan, Hauptstraße 53, 90537 Feucht, Germany, kontakt@theky.de.
2. Subject matter and duration
The subject matter is the processing of personal data of the Customer's guests by Theky in the course of providing the digital loyalty-card and messaging service. The duration corresponds to the term of the service contract. This agreement ends automatically upon its termination; the obligations under section 10 (deletion) and 5 (confidentiality) survive.
3. Nature, purpose, data types and categories of data subjects
Nature and purpose: providing the wallet loyalty card, counting stamps and redemptions, sending push messages on behalf of the Customer, providing internal metrics and a review flow.
Data types: random card and device identifiers, card serial number, push token, platform (Apple/Google), stamp and redemption events, ratings including optional free text, event metrics. No real names, email addresses or location data of guests are processed.
Categories of data subjects: guests / customers of the Customer who add a loyalty card.
4. Instructions
Theky processes the data only on documented instructions from the Customer, including with regard to transfers to third countries, unless required by law. The Customer's settings and use of the service (e.g. sending a message) constitute instructions. Theky informs the Customer if, in its opinion, an instruction infringes the GDPR.
5. Confidentiality
Theky obliges the persons involved in the processing to confidentiality, unless they are already subject to a statutory duty of confidentiality.
6. Technical and organisational measures
Theky takes appropriate technical and organisational measures pursuant to Art. 32 GDPR; these are described in Annex 2 and are adapted to the state of the art as needed.
7. Sub-processors
The Customer grants general authorisation for the use of sub-processors. The sub-processors currently used are listed in Annex 1. Theky obliges sub-processors to an equivalent level of data protection (Art. 28(4) GDPR). Theky gives timely notice of changes to the list; the Customer may object on reasonable grounds.
8. Assistance to the controller
Theky assists the Customer with appropriate measures in fulfilling data-subject rights (access, rectification, erasure, restriction, portability, objection) and the obligations under Art. 32 to 36 GDPR. Guest requests received directly by Theky are forwarded to the Customer or handled on the Customer's instructions.
9. Notification of data breaches
Theky notifies the Customer of a personal-data breach without undue delay after becoming aware of it and assists with the Customer's notification obligations (Art. 33, 34 GDPR).
10. Deletion and return
After the end of processing, Theky deletes the data or returns it at the Customer's choice, unless there is a statutory retention obligation. Guest data no longer actively used is already deleted automatically after 14 days during ongoing operation.
11. Evidence and audits
Theky makes available to the Customer the information necessary to demonstrate compliance with Art. 28 GDPR and allows for reasonable audits, with reasonable prior notice and without disproportionate disruption to operations.
12. Third countries
Transfers to third countries take place only in accordance with the privacy policy and this agreement, based on the EU Standard Contractual Clauses or the EU-US Data Privacy Framework (see Privacy Policy, section 12).
13. Liability and final provisions
The liability rules of the GDPR (Art. 82) and of the service contract apply. Amendments to this agreement require text form. Should a provision be invalid, the remainder of the agreement remains effective. German law applies.
Annex 1: Sub-processors
| Sub-processor | Service | Location |
|---|---|---|
| Supabase Inc. | Database (storage) | EU — Frankfurt/Germany |
| Render, Inc. | Backend hosting | EU — Frankfurt |
| Vercel, Inc. | Website/dashboard hosting (CDN) | EU / global |
| Apple | Apple Wallet and push (APNs) | USA / Ireland |
| Google Wallet and push | USA / Ireland |
Stripe (payment) and Resend (email) process business-owner data, not guest data, and are therefore not part of this processing agreement.
Annex 2: Technical and organisational measures (Art. 32 GDPR)
- Encryption: transport encryption (HTTPS/TLS) for all connections; passwords and PINs stored only as hashes.
- Access control: access only for authorised persons, token-based authentication; separated roles (operator/merchant/staff).
- Data minimisation: no real names, email addresses or location data of guests; only technically necessary identifiers.
- Data location: database and backend in the EU (Frankfurt).
- Resilience & recoverability: managed, secured database hosting with provider backups.
- Deletion concept: automatic deletion of unused guest data after 14 days; full deletion upon account termination.
- Logging: event and access logs for traceability.
- Separation: tenant separation per business owner via unique identifiers.
Draft version: 15 August 2026. Have a lawyer review before use.