BuzzKiez LogoBuzzKiez

DATA PROCESSING AGREEMENT (AV-VERTRAG)

under Article 28 GDPR

between

Business (Controller)

and

Sriram Jayanthi – BuzzKiez (Processor)

  • Pauline-Staegemann-Strasse 2
  • 10249 Berlin
  • Germany

Last updated: 20/11/2025

This Data Processing Agreement (Agreement) forms part of the main contract between the Controller and Processor for the use of the BuzzKiez loyalty platform.

1. Subject matter and duration

1.1 The Processor processes personal data on behalf of the Controller in connection with the operation of digital loyalty cards through Apple Wallet and Google Wallet.

1.2 The Agreement applies for the duration of the main contract and ends when processing on behalf of the Controller has been fully completed.

2. Nature and purpose of the processing

Processor processes personal data solely for these purposes:

  • generation and updating of digital wallet passes,
  • recording of visits, stamp status and spend values,
  • application of segmentation logic,
  • triggering of loyalty related pass updates,
  • storage and presentation of analytics for the Controller,
  • execution of technical logging, monitoring and security measures required to operate the service.

No other processing takes place unless required by Union or Member State law.

3. Type of personal data and categories of data subjects

3.1 Data subjects

The processing concerns:

  • end customers who use a loyalty card issued by the Controller,
  • authorised staff of the Controller who use the BuzzKiez dashboard.

3.2 Types of data

For end customers:

  • name,
  • wallet pass identifier,
  • anonymised device identifiers,
  • linked business,
  • static geographic coordinates (latitude and longitude) of the business location to enable location based trigger rules,
  • loyalty card type (stamp or value based),
  • visit events and stamp status,
  • spend values for value based loyalty programs,
  • segmentation labels,
  • technical logs such as timestamps and request identifiers.

For the Controller's staff:

  • name and email address,
  • phone number,
  • login credentials (hashed passwords),
  • usage logs and support communications.

Special categories of data within Art. 9 GDPR are not intended to be processed.

4. Instructions

4.1 Processor processes personal data only on documented instructions from the Controller. These instructions are defined in this Agreement and the main contract.

4.2 If the Controller issues additional instructions, they must be in text form.

4.3 If the Processor believes an instruction infringes GDPR or other laws, it will inform the Controller without undue delay and suspend execution until the instruction is confirmed or changed.

5. Confidentiality

5.1 Processor ensures that all persons authorised to process personal data are subject to confidentiality obligations under statutory rules or written agreements.

6. Technical and organisational measures

6.1 Processor implements appropriate technical and organisational measures under Art. 32 GDPR. These include:

  • access control for systems and staff,
  • encrypted transmission of data,
  • separation of production and test environments,
  • regular backups and restore testing,
  • logging and monitoring of system actions,
  • procedures to ensure availability and resilience,
  • incident response processes.

6.2 A current overview of measures (TOMs) is available at:

The Controller acknowledges these measures as appropriate.

7. Sub processors

7.1 Controller grants general authorisation for Processor to appoint sub processors.

7.2 Current sub processors include:

  • DigitalOcean LLC. Hosting and infrastructure provider with data centres located in the European Union.

7.3 Processor will inform the Controller of any intended changes in sub processors and give the Controller the opportunity to object.

7.4 Processor will impose the same data protection obligations on sub processors as set out in this Agreement.

8. Assistance to the Controller

Processor assists the Controller:

  • in responding to data subject requests under Chapter III GDPR,
  • in ensuring compliance with Art. 32 to 36 GDPR (security, breach notification, data protection impact assessments),

taking into account the nature of processing and information available to the Processor.

9. Personal data breaches

9.1 Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting data processed on behalf of the Controller.

9.2 Notifications will contain the information required by Art. 33(3) GDPR as far as known at the time.

10. Deletion and return of data

10.1 After termination of the main contract, and upon request at any time, the Processor will delete or return all personal data processed on behalf of the Controller unless a legal obligation requires continued storage.

10.2 The Processor may retain aggregated or anonymised data that does not relate to an identified or identifiable individual.

11. Audits

11.1 Processor will make available to the Controller all information necessary to demonstrate compliance with this Agreement.

11.2 The Controller may conduct audits or inspections, directly or through a mandated auditor, during regular business hours and with reasonable prior notice.

11.3 The Controller is responsible for its own audit costs and any reasonable costs incurred by the Processor during an audit.

12. Liability

12.1 Each party is liable to data subjects in accordance with Art. 82 GDPR.

12.2 Between Controller and Processor, the allocation of liability follows the main contract.

13. Final provisions

13.1 This Agreement prevails over any conflicting provisions in the main contract relating to data protection.

13.2 This Agreement is governed by the laws of Germany.