Legal

Terms of Service

Effective 1 May 2026 · Updated 9 August 2026 · LoyAI Oy (Business ID 3612486-5) · Governing law: Finland

By accessing or using the LOYAI website or platform at loyaistudio.com, you agree to be bound by these Terms of Service. If you do not agree, you must not use the Service.

Data processing agreement

Incorporated into the Terms of Service above · Effective 1 May 2026 · Updated 9 August 2026 · Pursuant to GDPR Article 28

13Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of and is incorporated into the Terms of Service above. It governs the processing of Cardholder personal data by LoyAI Oy ("Processor") on behalf of the Customer ("Controller") pursuant to Article 28 of Regulation (EU) 2016/679 ("GDPR"). LOYAI processes Cardholder personal data solely and exclusively for the purpose of providing the Service. The Customer's access to and use of the Platform constitutes its complete documented processing instruction. Where LOYAI reasonably considers any instruction to conflict with GDPR or applicable data protection law, it will notify the Customer in writing without undue delay.

As data processor, LOYAI undertakes to: process Cardholder personal data only on the Customer's documented instructions, except where required to do so by applicable law (in which case LOYAI will notify the Customer unless prohibited); ensure that all persons authorised to process Cardholder personal data are subject to binding confidentiality obligations; implement and maintain appropriate technical and organisational security measures including TLS encryption for data in transit, encryption at rest where appropriate, access controls on a strict need-to-know basis, and regular testing and review of security measures; notify the Customer within 72 hours of becoming aware of any personal data breach and provide sufficient information for the Customer to meet its own notification obligations under GDPR Articles 33 and 34; provide reasonable assistance to the Customer in responding to data subject rights requests under GDPR Articles 15 to 22 to the extent technically possible given the nature of the processing; assist the Customer in meeting its obligations under GDPR Articles 32 to 36 to the extent LOYAI holds information relevant to that compliance; maintain a per-Cardholder marketing-consent record and refrain from transmitting any marketing communication through the Platform to a Cardholder whose record does not show an active, un-withdrawn consent (service communications necessary for the operation of the loyalty programme — stamp confirmations, reward availability and expiry notices — are excluded from this restriction); process consent withdrawals received through the Platform's Cardholder-facing management link without undue delay and reflect them in the consent record; and, upon termination of the Agreement, permanently delete all Cardholder personal data within 30 days unless applicable law requires continued retention, except that records demonstrating the giving, refusal, or withdrawal of marketing consent (consent status, timestamps, consent-text version, and pseudonymised technical metadata) may be retained in pseudonymised form for up to 36 months from deletion or withdrawal, solely as necessary for the establishment, exercise, or defence of legal claims (GDPR Articles 17(3)(e) and 7(1)), and are deleted or irreversibly anonymised thereafter.

Allocation of responsibility. The parties acknowledge their respective roles under GDPR Article 82: LOYAI is responsible only for damage caused by processing where it has not complied with its obligations as a processor under GDPR or this DPA, or where it has acted contrary to the Customer's lawful documented instructions. In all other respects, responsibility for the lawfulness of the processing rests with the Customer as sole controller, including without limitation: the existence of a valid legal basis for every processing operation; the content, targeting, timing, and frequency of every marketing communication sent through the Platform; compliance with the ePrivacy Directive and Finnish Act 917/2014 § 200; and the accuracy and completeness of privacy information provided to Cardholders. LOYAI provides, as part of the Service, a consent-collection screen, a consent-enforcement gate, per-Cardholder consent records, and a Cardholder-facing withdrawal mechanism; the Customer acknowledges that these mechanisms, used as provided, constitute the means by which the Customer discharges its own consent obligations, and that LOYAI is entitled to rely on the resulting consent records as the Customer's documented instruction as to which Cardholders may receive marketing. Any marketing communication that reaches a Cardholder as a result of the Customer bypassing, manipulating, or misconfiguring those mechanisms is processing on the Customer's sole responsibility, undertaken against LOYAI's documented design. LOYAI may suspend the Customer's access to marketing features (broadcasts, automations, proximity messaging) with immediate effect where it reasonably suspects that consent mechanisms are being bypassed or that marketing is being sent without a valid consent record, and will notify the Customer of the suspension and its grounds without undue delay; such suspension is not a breach of this Agreement and does not suspend the Customer's payment obligations.

Where the Customer's business or loyalty programme is transferred to another legal entity, the Customer remains responsible for ensuring a lawful basis for the continued processing of Cardholder personal data and consent records by the transferee; LOYAI may require evidence of that basis before transferring the account and will otherwise treat the consent records as non-transferable.

The Customer grants LOYAI general written authorisation to engage the Sub-processors listed in Annex 2. LOYAI will impose data protection obligations on each Sub-processor equivalent to those in this DPA and remains fully liable to the Customer for each Sub-processor's performance. LOYAI will provide at least 14 days' prior written notice of any intended change to the Sub-processor list. The Customer may object in writing within 14 days of such notice on reasonable and documented data protection grounds; the parties will engage in good faith to resolve the objection. Cardholder personal data is hosted primarily on infrastructure located within the European Economic Area. Where Sub-processors located outside the EEA process Cardholder personal data, LOYAI ensures that such transfers are subject to appropriate safeguards, including the EU-U.S. Data Privacy Framework where the Sub-processor holds an active certification, and otherwise Standard Contractual Clauses adopted by the European Commission (Decision 2021/914), incorporated into the relevant Sub-processor agreements.

Annex 1 — Details of Processing

Data Controller: the Customer, as identified at account registration. Data Processor: LoyAI Oy, Business ID 3612486-5, Pakilantie 86b C, 00670 Helsinki, Finland. Subject matter and purpose: the operation of digital loyalty and stamp card programmes on behalf of the Customer via the LOYAI Platform. Nature of processing: collection, storage, use, transmission, and deletion of personal data. Duration: the term of the Agreement, plus a 30-day deletion window following termination. Data subjects: the Customer's Cardholders (end consumers enrolled in the Customer's loyalty programme). Special category data: none — not permitted to be processed without prior written agreement between the parties.

Categories of personal data processed may include, depending on Customer configuration and Wallet platform capabilities: full name, email address, and telephone number (where collected at enrolment); device type, operating system, and Wallet Pass installation, update, and open events; push notification receipt and interaction status; loyalty stamp counts and reward redemption events; store location, nearby Wallet relevance, and scanner-location events where enabled by the Customer; device push notification tokens, pass serial numbers, and pseudonymous analytics identifiers; marketing-consent records (consent status, grant/withdrawal timestamps, the identifier of the consent wording displayed, page language, truncated hash of the network address, browser user-agent string, and the history of superseded consent records) and per-pass consent-management link tokens; and any additional data fields configured by the Customer at the point of Cardholder enrolment. LOYAI does not control what data Apple Inc. or Google LLC collect independently through their Wallet platforms; the Customer must review Apple's and Google's own privacy documentation.

Annex 2 — Approved Sub-processors

The following Sub-processors are approved as of the effective date of this Agreement. LOYAI maintains an up-to-date list at loyaistudio.com.

  • Google LLC — Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Google Wallet API, App Check, and Google Generative AI used for in-product card design assistance. Servers: EEA and US. Transfer mechanism: EU-U.S. Data Privacy Framework; Standard Contractual Clauses as fallback.
  • Vercel, Inc. — frontend hosting, deployment, and cookieless Vercel Analytics. Servers: EEA and US. Transfer mechanism: EU-U.S. Data Privacy Framework; Standard Contractual Clauses as fallback.
  • Stripe, Inc. — payment processing (Customer billing data only; no Cardholder loyalty data). Servers: EEA and US. Transfer mechanism: EU-U.S. Data Privacy Framework; Standard Contractual Clauses as fallback.
  • Loops Right, Inc. (Loops) — transactional email delivery and waitlist communications. Servers: United States. Transfer mechanism: Standard Contractual Clauses.
  • Apple Inc. — Apple Wallet pass delivery, pass updates, and Apple Push Notification service for Cardholders who add a pass to Apple Wallet. Servers: United States. Transfer mechanism: EU-U.S. Data Privacy Framework; Standard Contractual Clauses as fallback.
  • Functional Software, Inc. (Sentry) — frontend and backend error tracking, exception reporting, and performance diagnostics. Personal data is minimised: error stack traces and request metadata only; user identifiers and request payloads are not transmitted. Servers: Germany (EU). Transfer mechanism: Standard Contractual Clauses where applicable.

Apple Wallet and Google Wallet are independent platforms operating under their own terms and privacy policies. Personal data processed directly and solely by those platforms is outside the scope of this DPA and LOYAI's control.

LoyAI Oy · Pakilantie 86b C, 00670 Helsinki, Finland · info@loyaistudio.com · loyaistudio.com