Data Processing Addendum
LoyaltyDog Ltd · Last updated 14 September 2026
Draft — pending legal review. These pages are published so developers can read them before signup. They are not counsel-approved. LoyaltyDog will update them when legal comments land.
Developer = Controller of End Customer Data. LoyaltyDog Ltd = Processor of End Customer Data and Controller of developer account, billing, and security logs. Attaches to the Public API Terms.
1. Subject matter
LoyaltyDog processes End Customer Data to provide the Public API and related services (loyalty programmes, digital passes, gift cards, offers) for the term of the API Terms and until deletion.
2. Nature and purpose
Collection via API, storage, retrieval, transmission to wallet/POS providers at your instruction, security logging, backup, deletion. Solely to provide the documented API. No sale. No LoyaltyDog marketing to End Customers. No training of third-party foundation models on End Customer Data.
3. Data and subjects
Subjects: your customers/members and, where submitted, gift-card holders. Categories as you submit: identifiers, loyalty balances, offer/redemption events, gift-card last4/status/balance, pass serials, locale, store identifiers. Do not send health, biometric, or children’s data without a written addendum.
4. Processor obligations
Process only on documented instructions; confidentiality; security measures below; sub-processors as listed; assist with data-subject requests via API/dashboard; delete or return after the service ends; provide information reasonably necessary to demonstrate compliance.
5. Sub-processors
Hosting/DB, Redis, Cloudflare, S3-compatible storage, Stripe, Apple/Google wallet, Infisical, Sentry, transactional email. We will give notice of material new sub-processors. You may object on reasonable data-protection grounds within 14 days; exclusive remedy is to stop using the Public API and export data.
6. Security
TLS; Cloudflare in front of api.loyalty.dog; public secrets hashed at rest; access control; secrets in Infisical; PII sanitisation on application logs; rate limits on public keys. No ISO 27001 or SOC 2 claim is made in this draft.
7. Deletion
On termination or request: export via existing APIs where available; delete End Customer Data from active systems within 90 days; backups rotate out within a further 90 days, except records we must keep (billing, security logs, legal holds).
8. Transfers and breach
Data may be processed in the UK, EEA, and other sub-processor locations. For restricted transfers we intend to rely on UK adequacy and EU SCCs Module 2 plus UK Addendum — counsel must attach the operative modules before this draft is in force. Breach notice: without undue delay and within 72 hours of confirming a personal-data breach affecting End Customer Data.
9. Order of precedence
This DPA controls over the API Terms on data-protection conflicts. The Privacy Policy describes developer-account data.