1. Scope and parties
This Data Processing Addendum (DPA) is entered into between the Customer accepting the LOYMI Terms of Service (Customer or Controller) and Loymi SRL (LOYMI or Processor). It forms part of the Terms and applies to LOYMI’s processing of Customer Personal Data to provide the Service.
Capitalised terms not defined here have the meaning given in the Terms. “Personal Data”, “Controller”, “Processor”, “Data Subject”, “Processing” and “Personal Data Breach” have the meanings given by applicable data protection law.
2. Roles and instructions
The Customer is the Controller of Customer Personal Data and LOYMI is its Processor. The Customer determines the lawful purposes and means of its loyalty program, customer records, bookings, orders, staff use and communications.
LOYMI will process Customer Personal Data only on documented instructions from the Customer, including the Terms, this DPA, the Customer’s configuration and authorised use of the Service, unless processing is required by law. If legally permitted, LOYMI will inform the Customer before processing required by law.
If LOYMI reasonably believes an instruction violates applicable data protection law, it may suspend the affected processing and inform the Customer while the parties seek a compliant instruction.
3. Customer obligations
The Customer represents that:
- it has a valid legal basis for the Customer Personal Data and each processing instruction;
- it has provided required notices and obtained required consents;
- its instructions are lawful, fair and limited to legitimate business purposes;
- it will not submit data that the Service is not designed or authorised to process;
- it will configure roles, retention, program documents and communications responsibly;
- it will respond to Data Subjects and regulators as the Controller.
4. Processing details
| Subject matter | Operation of the LOYMI loyalty, customer management, booking, order, staff and communication features selected by the Customer. |
|---|---|
| Duration | The term of the Customer’s subscription and the limited period afterwards needed to return or delete data, complete protected backup cycles, resolve security issues or comply with law. |
| Nature | Collection, recording, organisation, storage, retrieval, consultation, transmission, display, modification, restriction, deletion, backup and other processing initiated by authorised use of the Service. |
| Purpose | Providing, securing, maintaining and supporting the Service under the Terms and the Customer’s documented configuration and instructions. |
5. Data Subjects and data categories
Data Subjects
- Customer owners, administrators, staff and authorised contractors;
- loyalty program members and prospective members;
- customers making purchases, bookings, appointments or orders;
- message recipients and individuals contacting the Customer.
Personal Data
- identity and contact data, including name, telephone number and business contact details;
- Telegram identifiers, usernames and authentication metadata;
- account role, location, employee profile and activity records;
- loyalty membership, balance, tier, rewards, consents and preferences;
- purchase, transaction, refund, booking, attendance, order and delivery information;
- communications, campaign status and support-related data;
- security, device, session, IP and audit information.
The Service is not intended for special-category data, government identifiers, payment card data, medical records or criminal-offence data unless the parties expressly agree in writing on appropriate additional safeguards.
6. Confidentiality and personnel
LOYMI ensures that persons authorised to process Customer Personal Data are bound by confidentiality obligations, receive access only where needed for their role and process the data only under applicable instructions. Access may be provided for support, security, maintenance and legal compliance.
7. Security measures
LOYMI maintains technical and organisational measures appropriate to the risk, taking into account the nature of Customer Personal Data and the Service. Measures include, as applicable:
- encrypted network transport and protected administrative connections;
- role-based access, tenant separation and least-privilege administration;
- password hashing and encryption of sensitive integration credentials;
- multi-factor authentication controls for privileged workflows;
- security rate limits, signed provider callbacks and session protections;
- audit records for sensitive business and data changes;
- protected backups and restore procedures;
- restricted object-storage credentials and controlled media access;
- monitoring, patching and incident response procedures.
The Customer is responsible for securely configuring user roles, credentials, connected bots, devices and its own networks.
8. Subprocessors
The Customer gives general written authorisation for LOYMI to use the providers on the current Subprocessors page. LOYMI will impose data protection obligations appropriate to the relevant service and remains responsible for each subprocessor’s performance of its processing obligations to the extent required by law.
LOYMI will publish a material new subprocessor before it begins processing Customer Personal Data where reasonably practicable. A Customer with a reasonable data protection objection may contact us promptly. The parties will work in good faith on a commercially reasonable solution; if none is available, the Customer may stop using the affected feature or terminate the affected Service.
9. Data Subject requests
Taking into account the nature of processing, LOYMI will provide reasonable assistance for the Customer to respond to requests for access, correction, deletion, restriction, objection or portability. If a request concerning Customer Personal Data is sent directly to LOYMI, we will direct the requester to the Customer or notify the Customer, unless law requires a different response.
10. Security incidents
LOYMI will notify the Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. The notice will include available information reasonably needed for the Customer’s legal assessment and notifications. LOYMI may provide information in stages as the investigation progresses.
Notification is not an admission of fault or liability. The Customer is responsible for its notifications to Data Subjects and authorities, with LOYMI’s reasonable assistance where required.
11. Compliance assistance
LOYMI will provide reasonable information needed to demonstrate compliance with this DPA and assist with legally required impact assessments or regulator consultations, taking into account the processing and information available to LOYMI.
On reasonable written notice, not more than once annually unless required following a confirmed incident or by a regulator, the Customer may request relevant compliance information. Audits must avoid exposing other customers’ data, security secrets or confidential information and should first rely on available documentation. The Customer bears extraordinary audit costs unless the audit identifies a material breach by LOYMI.
12. Return and deletion
At the Customer’s choice and subject to available product functionality, LOYMI will return or delete Customer Personal Data following termination, unless applicable law requires retention. Data in protected backups will be isolated from ordinary use and removed through the normal backup lifecycle. Data required for security, dispute or legal records will remain restricted to that purpose and deleted when the requirement ends.
13. International transfers
Where Customer Personal Data is transferred across borders, the parties will use a lawful transfer mechanism required by applicable law. The Customer authorises transfers necessary to the subprocessors listed at /subprocessors, subject to their applicable safeguards.
EEA transfers. Where Regulation (EU) 2016/679 applies and a transfer to LOYMI requires Standard Contractual Clauses, the parties incorporate the controller-to-processor module of the clauses adopted by Commission Implementing Decision (EU) 2021/914. The Customer is the data exporter, Loymi SRL is the data importer, the processing details in Sections 4–7 complete the relevant annex information, and the current Subprocessors page identifies authorised onward processing. The parties will complete additional selections or documentation reasonably required for the Customer’s specific transfer.
14. Liability and conflict
Liability under this DPA is subject to the liability provisions of the Terms, except where applicable data protection law prohibits a limitation. If this DPA conflicts with the Terms on processing Customer Personal Data, this DPA controls. Mandatory Standard Contractual Clauses control over both documents for the transfer they govern.
15. Contact
DPA, security and privacy requests may be sent to admin@loymi.md or addressed to Loymi SRL, Linin 24, Tiraspol, 3300, Moldova.