← Loya

Data Processing Agreement (DPA)

Document incorporated by reference into the Loya Service Agreement (§11.18). No separate signature is required — deemed accepted on the Agreement Effective Date (self-serve or enterprise). Version: 1.0 — June 2026

This Data Processing Agreement (the "DPA") is entered into between:

  • the Client (merchant, "Data Controller" or "Controller"); and
  • Hoffman Sacha Max (הופמן סשה מקס), an Osek Patur (עוסק פטור), business ID (מספר עוסק) 337734404, trading as Loya (the "Processor"),

in addition to the Service Agreement (the "Agreement").


1. Purpose and term

1.1 The Processor processes personal data on behalf of the Controller to provide the Loya loyalty platform and related services described in the Agreement.

1.2 This DPA takes effect on the Agreement Effective Date and remains in force for as long as the Processor processes personal data on behalf of the Controller under the Agreement.


2. Roles of the parties

2.1 The Controller determines the purposes and means of processing End-Customer Data in connection with the Client's loyalty program.

2.2 The Processor processes such data only on documented instructions from the Controller, in accordance with the Agreement, the applicable Commercial Appendix, and this DPA, except where required by mandatory law.

2.3 For the limited purposes described in Agreement §11.3 — technical platform security and reliability, fraud and abuse prevention, infrastructure maintenance, legal and regulatory compliance, internal administrative recordkeeping, and the production of anonymised or aggregated statistics — the Processor may act as an independent controller only to the extent necessary and permitted by Applicable Law. Any service improvement or product development is carried out, where reasonably possible, on aggregated, de-identified, or otherwise non-customer-identifiable data. Nothing in this DPA authorises the Processor to use identifiable End-Customer Data for unrelated direct marketing or for the creation of prospect lists.


3. Data categories and data subjects

3.1 Data subjects: end customers of the Controller enrolled in the loyalty program.

3.2 Data categories: as described in Agreement §2.3 and the end-customer privacy policy, including identity, contact, loyalty program data, consents, analytics results, and technical data.

3.3 The Controller must not instruct the Processor to process special categories of data (e.g. health data) unless a valid legal basis exists and the Processor has been informed in writing. The Controller is solely responsible for determining the necessity, legality, and any enhanced notice, consent, or security requirements applicable before any such data is processed through the Services.

3.4 Merchant staff-user data. This DPA governs the processing of End-Customer Data. Personal data relating to the Controller's own staff users (such as names, emails, login credentials, roles, and access logs) that Loya processes to create, secure, and administer the merchant account is not End-Customer Data under this DPA; it is governed by the Service Agreement, and Loya processes it primarily as a controller of that B2B account data for account administration, security, and legal compliance.


4. Instructions and use

4.1 The Processor processes personal data only to:

  • provide the Services;
  • carry out documented instructions from the Controller via the Dashboard, program configuration, and normal service operations;
  • produce anonymised or aggregated statistics and benchmarks (including for service improvement and product development), as described in Section 2.3 and Agreement §11.3, without using identifiable End-Customer Data for unrelated direct marketing or for the creation of prospect lists;
  • comply with Applicable Law.

4.2 The Processor will inform the Controller if an instruction appears to conflict with Applicable Law.

4.3 The Processor does not sell personally identifiable End-Customer Data and does not create identifiable prospect lists without a legal basis and written agreement where required (Agreement §11.15).

4.4 The routine actions taken by the Controller and its authorised staff users in the Dashboard, the Controller's service-configuration choices (including loyalty rules, registration-flow settings, and notification settings), and its customer-record management actions constitute documented instructions from the Controller under this DPA.


5. Sub-processors

5.1 The Controller authorises the Processor to use sub-processors listed in Loya's Sub-processor List. That list is available on written request at contact@loya-pass.com and, where published, at the stable URL stated in that document. The Processor may update the list from time to time.

5.2 The Sub-processor List includes both (a) service providers engaged by the Processor to support the Services and (b) key platform providers used in connection with wallet functionality. As of June 2026 these include Supabase, Render, PassKit, Apple, Google (Google Wallet and Google Maps Platform), and OpenStreetMap/Nominatim as a geocoding fallback where applicable. Certain platform providers (in particular Apple and Google wallet platforms) may operate partly under their own platform terms rather than purely as classic downstream processors.

5.3 The Processor requires, where reasonably possible, that its sub-processors are subject to data protection obligations appropriate to the processing and, in substance, consistent with those set out in this DPA, whether through their own DPAs, terms of service, or applicable law. As noted in Section 5.2, certain platform providers may operate partly under their own platform terms rather than purely as classic downstream processors.

5.4 The Processor will notify the Controller of any material change of sub-processor (addition or replacement) where required by the Agreement or Applicable Law, by email or through the Dashboard. The Controller's remedies in respect of such a change are those set out in the Agreement or this DPA; this Section does not create an implied right to veto a sub-processor.


6. International transfers

6.1 Data may be processed or hosted outside Israel depending on sub-processor infrastructure.

6.2 The Processor implements appropriate safeguards in accordance with Applicable Law, including standard contractual clauses or equivalent mechanisms where required.

6.3 Information about the transfer mechanisms and safeguards relied upon for a given sub-processor is available to the Controller on written request. Where the Controller serves data subjects outside Israel, or is itself subject to a non-Israeli data-transfer framework, the Parties will cooperate reasonably to put in place any additional transfer mechanism required by the Applicable Law governing the Controller's processing.


7. Security

7.1 The Processor implements appropriate technical and organisational measures, including encryption in transit, access controls, authentication, backups, and limitation of internal access (Agreement §11.11).

7.2 The Controller is responsible for securing its staff access, credential confidentiality, and point-of-sale conduct (Agreement §9).


8. Data breaches

8.1 Each Party will inform the other without undue delay after becoming aware of a personal data breach affecting the Service.

8.2 The Parties will cooperate reasonably to mitigate effects and meet applicable legal obligations.

8.3 To the extent available at the time of notification, and supplemented in phases as further information becomes available, the notifying Party will provide: (a) the nature of the incident; (b) the categories and approximate volume of data and data subjects likely affected; (c) the likely consequences of the incident; (d) the measures taken or proposed to address it and mitigate its effects; and (e) a contact point for follow-up.


9. Data subject rights

9.1 The Processor assists the Controller, to the extent reasonably possible and given the nature of processing, in responding to data subject requests under Applicable Law.

9.2 The Controller is the first point of contact for End Customers regarding their data in connection with the program.


10. End of processing

10.1 At the end of the Agreement, the Processor handles End-Customer Data in accordance with Agreement §8.7 and §8.8.

10.2 Subject to payment of amounts due and Applicable Law, the Processor provides the Controller with the export described in Agreement §8.7, then deletes or anonymises identifiable data according to the timelines below.

10.3 Retention periods after termination

Data typeIndicative period
Identifiable End-Customer Data (production)Deletion or anonymisation within 90 days after termination, unless required by law or dispute
CSV export window (Agreement §8.7)30 days after termination
Residual copies in backupsUp to 90 additional days before overwrite
Security and audit logsUp to 12 months
Anonymized or aggregated dataMay be retained indefinitely

11. Audits

11.1 On reasonable request and to the extent required by Applicable Law, the Processor makes available information necessary to demonstrate compliance with this DPA.

11.2 Documentation first. Audit rights are, in the first instance, satisfied through questionnaires, available certifications, policies, and remote documentation review. An on-site audit will be considered only where such measures are insufficient to demonstrate compliance, or where required by Applicable Law or following a major security incident.

11.3 Any on-site audit is subject to reasonable written notice, appropriate confidentiality, and a maximum frequency of once per year, unless required by law or a major security incident.


12. Liability and document hierarchy

12.1 If there is a conflict between this DPA and the Agreement on data protection matters, this DPA prevails.

12.2 For all other matters, the Agreement prevails.

12.3 The limitation of liability in Agreement §15 applies to this DPA, to the extent permitted by Applicable Law.


13. Contact

Processor (Loya): contact@loya-pass.com

Controller: Client contact details in the applicable Commercial Appendix.