Data Processing Addendum

LoyaltyDog Ltd · Last updated 14 September 2026

Draft — pending legal review. These pages are published so developers can read them before signup. They are not counsel-approved. LoyaltyDog will update them when legal comments land.

Developer = Controller of End Customer Data. LoyaltyDog Ltd = Processor of End Customer Data and Controller of developer account, billing, and security logs. Attaches to the Public API Terms.

1. Subject matter

LoyaltyDog processes End Customer Data to provide the Public API and related services (loyalty programmes, digital passes, gift cards, offers) for the term of the API Terms and until deletion.

2. Nature and purpose

Collection via API, storage, retrieval, transmission to wallet/POS providers at your instruction, security logging, backup, deletion. Solely to provide the documented API. No sale. No LoyaltyDog marketing to End Customers. No training of third-party foundation models on End Customer Data.

3. Data and subjects

Subjects: your customers/members and, where submitted, gift-card holders. Categories as you submit: identifiers, loyalty balances, offer/redemption events, gift-card last4/status/balance, pass serials, locale, store identifiers. Do not send health, biometric, or children’s data without a written addendum.

4. Processor obligations

Process only on documented instructions; confidentiality; security measures below; sub-processors as listed; assist with data-subject requests via API/dashboard; delete or return after the service ends; provide information reasonably necessary to demonstrate compliance.

5. Sub-processors

Hosting/DB, Redis, Cloudflare, S3-compatible storage, Stripe, Apple/Google wallet, Infisical, Sentry, transactional email. We will give notice of material new sub-processors. You may object on reasonable data-protection grounds within 14 days; exclusive remedy is to stop using the Public API and export data.

6. Security

TLS; Cloudflare in front of api.loyalty.dog; public secrets hashed at rest; access control; secrets in Infisical; PII sanitisation on application logs; rate limits on public keys. No ISO 27001 or SOC 2 claim is made in this draft.

7. Deletion

On termination or request: export via existing APIs where available; delete End Customer Data from active systems within 90 days; backups rotate out within a further 90 days, except records we must keep (billing, security logs, legal holds).

8. Transfers and breach

Data may be processed in the UK, EEA, and other sub-processor locations. For restricted transfers we intend to rely on UK adequacy and EU SCCs Module 2 plus UK Addendum — counsel must attach the operative modules before this draft is in force. Breach notice: without undue delay and within 72 hours of confirming a personal-data breach affecting End Customer Data.

9. Order of precedence

This DPA controls over the API Terms on data-protection conflicts. The Privacy Policy describes developer-account data.