BuzzKiez LogoBuzzKiez

PRIVACY POLICY FOR BUZZKIEZ

Last updated: 20/11/2025

1. Controller and contact details

The provider of the BuzzKiez platform is:

  • Sriram Jayanthi – BuzzKiez
  • Pauline-Staegemann-Strasse 2
  • 10249 Berlin
  • Germany
  • Email: support@buzzkiez.com

This Privacy Policy explains how we process personal data in connection with the BuzzKiez loyalty platform.

Depending on the situation we act either as

  • a) processor for businesses that use BuzzKiez to run a loyalty program, or
  • b) independent controller (for platform analytics, hosting, logs, billing and support).

2. Contact for data protection

For questions about this Privacy Policy or your rights under GDPR you can contact:

  • support@buzzkiez.com

3. Personal data we process

We process different categories of data depending on how you interact with BuzzKiez.

3.1 Data of businesses and their authorised users

  • Name of business owner or representative
  • Phone number
  • Email address
  • Business name and address
  • Login credentials (hashed password)
  • Billing information
  • Communication and support history
  • Technical logs relating to use of the dashboard

3.2 Data of end customers who hold a BuzzKiez wallet pass

We process the following data when a loyalty card is used:

  • Name as entered by the end customer
  • Wallet pass identifier
  • Anonymised device identifiers
  • Device OS (Android or iOS)
  • Linked business
  • Static geographic coordinates (latitude and longitude) of the business location to enable location based trigger rules. This does not involve tracking the end customer's real time location.
  • Loyalty card type (stamp or value based)
  • Visit events and stamp status
  • Spend values for value based programs
  • Automatic segmentation labels based on visit and spend behaviour
  • Technical logs such as timestamps and request identifiers

We do not intentionally process special categories of personal data within the meaning of Art. 9 GDPR.

4. Purposes and legal bases of processing

4.1 Operation of loyalty programs (processing on behalf of businesses)

For loyalty data relating to end customers, the business is the controller. BuzzKiez acts as processor under Art. 28 GDPR.

The business's legal basis is normally

  • Art. 6(1)(b) GDPR (performance of a loyalty program), or
  • Art. 6(1)(f) GDPR (legitimate interest in customer retention).

4.2 Platform operations and security (BuzzKiez as controller)

We process data independently to

  • operate the platform,
  • secure our infrastructure,
  • detect errors and prevent abuse,
  • provide support,
  • create aggregated, non identifiable statistics about overall platform usage.

We use the business's static geographic coordinates to operate location based wallet updates. BuzzKiez does not collect or process GPS or real time location data of end customers.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating a secure and functional SaaS platform).

4.3 Contract and billing with businesses

We process data of business owners and staff to prepare contracts, provide access and process subscriptions through Stripe.

Legal basis: Art. 6(1)(b) GDPR.

4.4 Legal obligations

We store certain records to comply with commercial and tax retention laws.

Legal basis: Art. 6(1)(c) GDPR.

5. Recipients and data transfers

5.1 Internal access

Access is restricted to staff or contractors who need the data to operate the platform.

5.2 Service providers

We use service providers that process personal data on our behalf. Currently:

DigitalOcean LLC hosting and infrastructure provider. Data is stored exclusively in data centres located in the European Union. A data processing agreement is in place.

We do not use tracking cookies, analytics cookies or third-party analytics tools.

5.3 Businesses using BuzzKiez

Each business receives access only to the loyalty data of its own loyalty program. No business can access data belonging to another business.

5.4 Transfers outside the EEA

We do not transfer personal data outside the EEA. If this becomes necessary, we will do so only where appropriate safeguards under Art. 44 ff. GDPR are in place.

6. Retention periods

We retain data only as long as necessary for the purposes described.

  • Business account, billing and contract data: retained for the duration of the contract and according to statutory retention periods (usually 6 to 10 years).
  • End customer loyalty data: retained for as long as the business uses BuzzKiez or until the business deletes its account or requests deletion of specific data.
  • Technical logs: kept for up to twelve months and then deleted or anonymised unless security or troubleshooting requires different handling.
  • Support and communication data: retained for the duration of the contract and according to legal retention rules.

7. Rights of data subjects

Under GDPR you have the following rights:

  • Right of access (Art. 15)
  • Right to rectification (Art. 16)
  • Right to erasure (Art. 17)
  • Right to restriction of processing (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object (Art. 21)

7.1 End customers (wallet pass holders)

The business that issued the loyalty card is the controller. Requests relating to loyalty data will be forwarded to the relevant business if sent to us.

End customers can request deletion or disable future pass updates by emailing:

  • support@buzzkiez.com

We may ask for the wallet pass ID to identify the data.

7.2 Businesses and authorised users

Businesses can exercise their rights at any time by contacting support@buzzkiez.com.

8. Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority.

The authority responsible for BuzzKiez is:

  • Berliner Beauftragte fΓΌr Datenschutz und Informationsfreiheit
  • Alt Moabit 59–61
  • 10555 Berlin
  • Germany

9. Cookies and website usage

Our website does not use tracking cookies, analytics cookies or advertising cookies.

Only technically necessary cookies may be used for essential functions.

10. Data security

We implement appropriate technical and organisational measures as required by Art. 32 GDPR. These include access controls, encryption in transit, separation of environments, regular backups, monitoring and incident response procedures.

11. Updates to this Privacy Policy

We may update this Privacy Policy to reflect changes in our services or legal requirements. The current version is always available at

  • https://www.buzzkiez.com/privacy