Data Processing Agreement

Agreement on processing of personal data on behalf pursuant to Art. 28 GDPR

This is a courtesy translation. The German version is legally binding.

Draft · Last updated: 15 August 2026

This agreement forms part of the service contract between the business owner and Theky and takes effect upon conclusion of the subscription. It governs the processing of data of the guests who use the business owner's loyalty card. For this data, the business owner is the controller and Theky is the processor. You may save or print this page as a record.

Contents
  1. Parties
  2. Subject matter and duration
  3. Nature, purpose, data types, data subjects
  4. Instructions
  5. Confidentiality
  6. Technical and organisational measures
  7. Sub-processors
  8. Assistance to the controller
  9. Notification of data breaches
  10. Deletion and return
  11. Evidence and audits
  12. Third countries
  13. Liability and final provisions
  14. Annex 1: Sub-processors
  15. Annex 2: Technical and organisational measures

1. Parties

Controller (the "Customer"): the business owner / company that holds a Theky account. The specific details (name, address) follow from the account and the service contract.

Processor: Theky GbR, Batuhan Karadag and Ahmet Kazmacan, Hauptstraße 53, 90537 Feucht, Germany, kontakt@theky.de.

2. Subject matter and duration

The subject matter is the processing of personal data of the Customer's guests by Theky in the course of providing the digital loyalty-card and messaging service. The duration corresponds to the term of the service contract. This agreement ends automatically upon its termination; the obligations under section 10 (deletion) and 5 (confidentiality) survive.

3. Nature, purpose, data types and categories of data subjects

Nature and purpose: providing the wallet loyalty card, counting stamps and redemptions, sending push messages on behalf of the Customer, providing internal metrics and a review flow.

Data types: random card and device identifiers, card serial number, push token, platform (Apple/Google), stamp and redemption events, ratings including optional free text, event metrics. No real names, email addresses or location data of guests are processed.

Categories of data subjects: guests / customers of the Customer who add a loyalty card.

4. Instructions

Theky processes the data only on documented instructions from the Customer, including with regard to transfers to third countries, unless required by law. The Customer's settings and use of the service (e.g. sending a message) constitute instructions. Theky informs the Customer if, in its opinion, an instruction infringes the GDPR.

5. Confidentiality

Theky obliges the persons involved in the processing to confidentiality, unless they are already subject to a statutory duty of confidentiality.

6. Technical and organisational measures

Theky takes appropriate technical and organisational measures pursuant to Art. 32 GDPR; these are described in Annex 2 and are adapted to the state of the art as needed.

7. Sub-processors

The Customer grants general authorisation for the use of sub-processors. The sub-processors currently used are listed in Annex 1. Theky obliges sub-processors to an equivalent level of data protection (Art. 28(4) GDPR). Theky gives timely notice of changes to the list; the Customer may object on reasonable grounds.

8. Assistance to the controller

Theky assists the Customer with appropriate measures in fulfilling data-subject rights (access, rectification, erasure, restriction, portability, objection) and the obligations under Art. 32 to 36 GDPR. Guest requests received directly by Theky are forwarded to the Customer or handled on the Customer's instructions.

9. Notification of data breaches

Theky notifies the Customer of a personal-data breach without undue delay after becoming aware of it and assists with the Customer's notification obligations (Art. 33, 34 GDPR).

10. Deletion and return

After the end of processing, Theky deletes the data or returns it at the Customer's choice, unless there is a statutory retention obligation. Guest data no longer actively used is already deleted automatically after 14 days during ongoing operation.

11. Evidence and audits

Theky makes available to the Customer the information necessary to demonstrate compliance with Art. 28 GDPR and allows for reasonable audits, with reasonable prior notice and without disproportionate disruption to operations.

12. Third countries

Transfers to third countries take place only in accordance with the privacy policy and this agreement, based on the EU Standard Contractual Clauses or the EU-US Data Privacy Framework (see Privacy Policy, section 12).

13. Liability and final provisions

The liability rules of the GDPR (Art. 82) and of the service contract apply. Amendments to this agreement require text form. Should a provision be invalid, the remainder of the agreement remains effective. German law applies.

Annex 1: Sub-processors

Sub-processorServiceLocation
Supabase Inc.Database (storage)EU — Frankfurt/Germany
Render, Inc.Backend hostingEU — Frankfurt
Vercel, Inc.Website/dashboard hosting (CDN)EU / global
AppleApple Wallet and push (APNs)USA / Ireland
GoogleGoogle Wallet and pushUSA / Ireland

Stripe (payment) and Resend (email) process business-owner data, not guest data, and are therefore not part of this processing agreement.

Annex 2: Technical and organisational measures (Art. 32 GDPR)

Draft version: 15 August 2026. Have a lawyer review before use.