Legal
Terms of Service
Effective 1 May 2026 · Updated 9 August 2026 · LoyAI Oy (Business ID 3612486-5) · Governing law: Finland
By accessing or using the LOYAI website or platform at loyaistudio.com, you agree to be bound by these Terms of Service. If you do not agree, you must not use the Service.
1Parties
These Terms of Service ("Agreement") govern the relationship between LoyAI Oy, Business ID 3612486-5, Pakilantie 86b C, 00670 Helsinki, Finland ("LOYAI") and any business entity that accesses or uses the LOYAI platform ("Customer"). By accessing the website, registering an account, or using any part of the Service, the Customer confirms that: (i) it is acting as a business or legal entity, not as a consumer; (ii) it has authority to bind that entity to this Agreement; and (iii) it accepts these Terms in full, including the Data Processing Agreement in Section 13. If you are an individual acting outside a business context, you are not permitted to use the Service. LOYAI may require proof of business status at any time.
2The Service
LOYAI is a business-to-business SaaS platform for creating and managing digital loyalty programmes distributed via Apple Wallet and Google Wallet, available at loyaistudio.com. Push notifications to Cardholders are sent by the Customer using the Platform — LOYAI provides infrastructure only and has no editorial control over notification content. No uptime, availability, or performance guarantee is given unless a separate written service level agreement is signed. The Service relies on third-party providers including Google LLC (Firebase, Cloud Functions, Cloud Storage, Google Wallet API, and Google Generative AI), Vercel, Inc. (frontend hosting and Vercel Analytics), Stripe, Inc. (payment processing), Loops Right, Inc. (transactional email), Apple Inc. (Apple Wallet pass delivery and push notifications), and Functional Software, Inc. (Sentry — error tracking). LOYAI may engage additional or replacement providers from time to time. LOYAI is not liable for disruptions caused by those services.
3Free Trial
LOYAI may offer a limited free trial at its discretion. One free trial per legal entity. The trial is provided strictly as-is with no warranties of any kind. If no paid Subscription is activated, access may be downgraded to the free plan or suspended in accordance with the limits shown in the Service. Creating multiple accounts to obtain additional trials is a material breach of this Agreement. LOYAI may modify or end the free trial at any time without liability.
4Payment
Subscriptions renew automatically at the end of each billing cycle at the then-current rate until cancelled. Unless otherwise shown in the Service or by Stripe, cancellation takes effect at the end of the current billing period. By subscribing, the Customer authorises LOYAI to charge the designated payment method on a recurring basis without further action required. The Studio plan is priced by purchased location count; location changes and billing interval changes may be prorated by Stripe. All fees are exclusive of VAT and all applicable taxes, which are the Customer's sole responsibility. All fees are non-refundable except where required by Finnish mandatory law. LOYAI will give at least 30 days' written notice before changing prices for active Subscribers; continued use after the effective date constitutes acceptance. If a payment fails, LOYAI may suspend access immediately and terminate the account if the outstanding balance is not settled within 7 days of written notice.
5Acceptable Use
The Customer must use the Service lawfully and for legitimate business purposes only. The following are prohibited: violating any applicable law or regulation, including GDPR and anti-spam legislation; sending unsolicited commercial communications to Cardholders; engaging in fraud, deception, or misleading practices; uploading unlawful, defamatory, or third-party infringing content; attacking, disabling, or reverse-engineering any part of the Platform; automated scraping of any Service data; and reselling or sublicensing the Service without LOYAI's prior written consent. LOYAI may suspend or terminate access immediately and without notice upon any breach of this section.
6Intellectual Property and Marketing Licence
All intellectual property rights in the Service, Platform, software, and LOYAI branding remain exclusively with LOYAI. The Customer receives a limited, non-exclusive, non-transferable, revocable licence to access and use the Service solely for its internal business purposes during an active Subscription. No other rights are granted.
The Customer retains ownership of its own content and brand assets. By creating any card, programme, or other content on the Platform, the Customer automatically grants LOYAI a perpetual, worldwide, royalty-free, sublicensable licence to use its company name, logo, card designs, and brand assets for commercial marketing purposes — including on LOYAI's website, social media channels, pitch decks, case studies, and investor materials. LOYAI will not misrepresent the Customer's business or products. Following termination of an active Subscription, the Customer may submit a written removal request to info@loyaistudio.com within 60 days; LOYAI will remove the Customer's brand assets from actively promoted materials within 30 days of receipt. This right does not extend to materials already published or archived prior to the request, nor to historical records. No removal request may be submitted while an account remains active. This licence is a right of reference and display only; LOYAI makes no claim of ownership over the Customer's trademarks.
7Data Protection
The processing of Cardholder personal data through the Service is governed exclusively by the Data Processing Agreement set out in Section 13, which is incorporated into and forms part of this Agreement. Acceptance of these Terms constitutes simultaneous acceptance of the DPA. In the event of any conflict between this section and the DPA, the DPA prevails. The Customer warrants, on a continuing basis, that: (i) it holds a valid legal basis under GDPR for all processing of Cardholder personal data through the Service; (ii) it will collect Cardholder marketing consent exclusively through the consent mechanism provided by the Platform and will not circumvent, suppress, or pre-populate that mechanism in any way, including by constructing enrolment URLs that carry a consent outcome the Cardholder was not shown; (iii) it will send marketing communications (including proximity-triggered lock-screen text) only to Cardholders whose Platform consent record is active, and holds the required legal basis under the ePrivacy Directive and Finnish Act 917/2014 § 200 for every communication sent through the Platform; (iv) it will maintain a privacy notice for its Cardholders that describes the loyalty-programme processing, names LoyAI Oy as processor and the sub-processors in Annex 2, states the marketing-consent mechanism and the right to withdraw via the link on the pass, states that the programme is not directed at children under 13, and lists the Cardholder's right to object to direct marketing under GDPR Article 21(2); and (v) it will not upload special category personal data as defined under GDPR Article 9 without LOYAI's prior written agreement. LOYAI will notify the Customer within 72 hours of becoming aware of any personal data breach affecting Cardholder data processed on the Customer's behalf.
8Warranties
LOYAI will use commercially reasonable efforts to provide the Service in accordance with generally accepted B2B SaaS industry standards. Beyond that limited warranty:
THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE". TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, LOYAI DISCLAIMS ALL OTHER WARRANTIES, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, AND UNINTERRUPTED OR ERROR-FREE AVAILABILITY. LOYAI MAKES NO WARRANTY REGARDING NOTIFICATION DELIVERY RATES, ANALYTICS ACCURACY, COMPATIBILITY WITH FUTURE VERSIONS OF APPLE WALLET OR GOOGLE WALLET, OR ANY PARTICULAR BUSINESS OUTCOME FROM USE OF THE SERVICE.
9Limitation of Liability
TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, LOYAI SHALL NOT BE LIABLE TO THE CUSTOMER OR ANY THIRD PARTY FOR: (A) LOSS OF PROFITS, REVENUE, OR ANTICIPATED SAVINGS; (B) LOSS OF BUSINESS, CONTRACTS, OR OPPORTUNITIES; (C) LOSS OR CORRUPTION OF DATA; (D) BUSINESS INTERRUPTION OR WASTED EXPENDITURE; (E) DAMAGE TO REPUTATION OR GOODWILL; (F) COST OF SUBSTITUTE OR REPLACEMENT SERVICES; (G) ANY INDIRECT, CONSEQUENTIAL, SPECIAL, INCIDENTAL, OR PUNITIVE DAMAGES OF ANY KIND; OR (H) ANY CLAIM, DEMAND, OR PROCEEDING BROUGHT AGAINST THE CUSTOMER BY ITS CARDHOLDERS OR END USERS — IN EACH CASE HOWEVER CAUSED AND WHETHER ARISING IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STATUTE, OR OTHERWISE, EVEN IF LOYAI HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH LOSS OR DAMAGE.
LOYAI'S TOTAL AGGREGATE LIABILITY TO THE CUSTOMER FOR ALL CLAIMS ARISING UNDER OR IN CONNECTION WITH THIS AGREEMENT, WHETHER IN CONTRACT, TORT, OR OTHERWISE, SHALL NOT EXCEED THE TOTAL FEES PAID BY THE CUSTOMER TO LOYAI IN THE THREE (3) CALENDAR MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM. WHERE NO FEES HAVE BEEN PAID, INCLUDING DURING A FREE TRIAL, LOYAI'S MAXIMUM LIABILITY IS EUR 100. FOR CLAIMS ARISING SOLELY FROM LOYAI'S DIRECT INFRINGEMENT OF THE CUSTOMER'S INTELLECTUAL PROPERTY RIGHTS, THE CAP IS THE TOTAL FEES PAID IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM.
The parties acknowledge that these limitations reflect a reasonable and fair allocation of risk between commercially sophisticated parties and form an essential element of the basis of the bargain; LOYAI would not provide the Service at the applicable fees without them. Nothing in this Agreement limits or excludes liability for: death or personal injury caused by negligence; fraud or fraudulent misrepresentation; or any liability that cannot be excluded or limited under Finnish mandatory law. The Customer is solely responsible for its relationship with its Cardholders. LOYAI has no liability for any claim by a Cardholder arising from the Customer's loyalty programme, notification practices, or data handling.
Claims for which the Customer owes LOYAI indemnification under Section 10 are excluded from LOYAI's liability caps and are not LOYAI losses. For the avoidance of doubt, nothing in this Section 9 limits the Customer's own liability toward its Cardholders or supervisory authorities, which the parties allocate to the Customer in accordance with GDPR Article 82(2) except to the extent the damage was caused by LOYAI's breach of its obligations as a processor.
10Indemnification
The Customer shall defend, indemnify, and hold harmless LOYAI and its officers, employees, and agents against all third-party claims, liabilities, damages, losses, and costs (including reasonable legal fees) arising out of or relating to: (i) the Customer's breach of this Agreement; (ii) the Customer's unlawful or unauthorised use of the Service; (iii) the content, targeting, or legal compliance of any notification sent by the Customer through the Platform; (iv) the Customer's loyalty programme and its practices toward Cardholders; (v) any claim by a Cardholder arising from the Customer's acts or omissions; (vi) any infringement of third-party intellectual property rights by content uploaded by the Customer; (vii) any circumvention, manipulation, or misconfiguration by the Customer of the consent mechanisms provided by the Platform, including the construction of enrolment URLs carrying a consent outcome not shown to the Cardholder; or (viii) any claim, complaint, investigation, or proceeding by a data subject or supervisory authority arising from the Customer's marketing practices, lawful-basis failures, or breach of the warranties in Section 7 — in each case including, to the maximum extent permitted by applicable law, administrative fines, regulatory penalties, and the reasonable costs of responding to supervisory-authority inquiries.
11Termination
This Agreement begins on first access to the Service and continues until terminated. The Customer may cancel its Subscription at any time via account settings or by contacting info@loyaistudio.com; cancellation takes effect at the end of the then-current billing period and no fees are refunded. LOYAI may suspend or terminate the Customer's access with immediate effect upon: material breach unremedied within 14 days of written notice; conduct posing a security or reputational risk to the Platform; non-payment of outstanding fees within 7 days of written notice; or legal requirement. LOYAI may discontinue the Service entirely on 60 days' written notice to all active Customers. Upon termination for any reason: all licences granted under this Agreement terminate immediately (subject to the marketing licence terms in Section 6); LOYAI will delete all Cardholder personal data within 30 days in accordance with the DPA, subject to the consent-record retention set out in Section 13; all accrued payment obligations remain due and payable. Sections 6, 9, 10, 12, and 13 survive termination.
12General
These Terms, together with the DPA in Section 13, constitute the entire agreement between the parties and supersede all prior agreements and understandings. Finnish law governs this Agreement. All disputes are subject to the exclusive jurisdiction of the District Court of Helsinki (Helsingin käräjäoikeus); the parties will attempt good-faith resolution for 30 days before initiating formal proceedings. If any provision is found invalid or unenforceable, it shall be modified to the minimum extent necessary and the remainder continues in full force. LOYAI may assign this Agreement in connection with a merger, acquisition, or sale of assets upon 30 days' written notice; the Customer may not assign without LOYAI's prior written consent. Neither party is liable for failure or delay caused by circumstances genuinely beyond its reasonable control. All legal notices to LOYAI must be sent to info@loyaistudio.com or by registered post to Pakilantie 86b C, 00670 Helsinki, Finland.
Data processing agreement
Incorporated into the Terms of Service above · Effective 1 May 2026 · Updated 9 August 2026 · Pursuant to GDPR Article 28
13Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of and is incorporated into the Terms of Service above. It governs the processing of Cardholder personal data by LoyAI Oy ("Processor") on behalf of the Customer ("Controller") pursuant to Article 28 of Regulation (EU) 2016/679 ("GDPR"). LOYAI processes Cardholder personal data solely and exclusively for the purpose of providing the Service. The Customer's access to and use of the Platform constitutes its complete documented processing instruction. Where LOYAI reasonably considers any instruction to conflict with GDPR or applicable data protection law, it will notify the Customer in writing without undue delay.
As data processor, LOYAI undertakes to: process Cardholder personal data only on the Customer's documented instructions, except where required to do so by applicable law (in which case LOYAI will notify the Customer unless prohibited); ensure that all persons authorised to process Cardholder personal data are subject to binding confidentiality obligations; implement and maintain appropriate technical and organisational security measures including TLS encryption for data in transit, encryption at rest where appropriate, access controls on a strict need-to-know basis, and regular testing and review of security measures; notify the Customer within 72 hours of becoming aware of any personal data breach and provide sufficient information for the Customer to meet its own notification obligations under GDPR Articles 33 and 34; provide reasonable assistance to the Customer in responding to data subject rights requests under GDPR Articles 15 to 22 to the extent technically possible given the nature of the processing; assist the Customer in meeting its obligations under GDPR Articles 32 to 36 to the extent LOYAI holds information relevant to that compliance; maintain a per-Cardholder marketing-consent record and refrain from transmitting any marketing communication through the Platform to a Cardholder whose record does not show an active, un-withdrawn consent (service communications necessary for the operation of the loyalty programme — stamp confirmations, reward availability and expiry notices — are excluded from this restriction); process consent withdrawals received through the Platform's Cardholder-facing management link without undue delay and reflect them in the consent record; and, upon termination of the Agreement, permanently delete all Cardholder personal data within 30 days unless applicable law requires continued retention, except that records demonstrating the giving, refusal, or withdrawal of marketing consent (consent status, timestamps, consent-text version, and pseudonymised technical metadata) may be retained in pseudonymised form for up to 36 months from deletion or withdrawal, solely as necessary for the establishment, exercise, or defence of legal claims (GDPR Articles 17(3)(e) and 7(1)), and are deleted or irreversibly anonymised thereafter.
Allocation of responsibility. The parties acknowledge their respective roles under GDPR Article 82: LOYAI is responsible only for damage caused by processing where it has not complied with its obligations as a processor under GDPR or this DPA, or where it has acted contrary to the Customer's lawful documented instructions. In all other respects, responsibility for the lawfulness of the processing rests with the Customer as sole controller, including without limitation: the existence of a valid legal basis for every processing operation; the content, targeting, timing, and frequency of every marketing communication sent through the Platform; compliance with the ePrivacy Directive and Finnish Act 917/2014 § 200; and the accuracy and completeness of privacy information provided to Cardholders. LOYAI provides, as part of the Service, a consent-collection screen, a consent-enforcement gate, per-Cardholder consent records, and a Cardholder-facing withdrawal mechanism; the Customer acknowledges that these mechanisms, used as provided, constitute the means by which the Customer discharges its own consent obligations, and that LOYAI is entitled to rely on the resulting consent records as the Customer's documented instruction as to which Cardholders may receive marketing. Any marketing communication that reaches a Cardholder as a result of the Customer bypassing, manipulating, or misconfiguring those mechanisms is processing on the Customer's sole responsibility, undertaken against LOYAI's documented design. LOYAI may suspend the Customer's access to marketing features (broadcasts, automations, proximity messaging) with immediate effect where it reasonably suspects that consent mechanisms are being bypassed or that marketing is being sent without a valid consent record, and will notify the Customer of the suspension and its grounds without undue delay; such suspension is not a breach of this Agreement and does not suspend the Customer's payment obligations.
Where the Customer's business or loyalty programme is transferred to another legal entity, the Customer remains responsible for ensuring a lawful basis for the continued processing of Cardholder personal data and consent records by the transferee; LOYAI may require evidence of that basis before transferring the account and will otherwise treat the consent records as non-transferable.
The Customer grants LOYAI general written authorisation to engage the Sub-processors listed in Annex 2. LOYAI will impose data protection obligations on each Sub-processor equivalent to those in this DPA and remains fully liable to the Customer for each Sub-processor's performance. LOYAI will provide at least 14 days' prior written notice of any intended change to the Sub-processor list. The Customer may object in writing within 14 days of such notice on reasonable and documented data protection grounds; the parties will engage in good faith to resolve the objection. Cardholder personal data is hosted primarily on infrastructure located within the European Economic Area. Where Sub-processors located outside the EEA process Cardholder personal data, LOYAI ensures that such transfers are subject to appropriate safeguards, including the EU-U.S. Data Privacy Framework where the Sub-processor holds an active certification, and otherwise Standard Contractual Clauses adopted by the European Commission (Decision 2021/914), incorporated into the relevant Sub-processor agreements.
Annex 1 — Details of Processing
Data Controller: the Customer, as identified at account registration. Data Processor: LoyAI Oy, Business ID 3612486-5, Pakilantie 86b C, 00670 Helsinki, Finland. Subject matter and purpose: the operation of digital loyalty and stamp card programmes on behalf of the Customer via the LOYAI Platform. Nature of processing: collection, storage, use, transmission, and deletion of personal data. Duration: the term of the Agreement, plus a 30-day deletion window following termination. Data subjects: the Customer's Cardholders (end consumers enrolled in the Customer's loyalty programme). Special category data: none — not permitted to be processed without prior written agreement between the parties.
Categories of personal data processed may include, depending on Customer configuration and Wallet platform capabilities: full name, email address, and telephone number (where collected at enrolment); device type, operating system, and Wallet Pass installation, update, and open events; push notification receipt and interaction status; loyalty stamp counts and reward redemption events; store location, nearby Wallet relevance, and scanner-location events where enabled by the Customer; device push notification tokens, pass serial numbers, and pseudonymous analytics identifiers; marketing-consent records (consent status, grant/withdrawal timestamps, the identifier of the consent wording displayed, page language, truncated hash of the network address, browser user-agent string, and the history of superseded consent records) and per-pass consent-management link tokens; and any additional data fields configured by the Customer at the point of Cardholder enrolment. LOYAI does not control what data Apple Inc. or Google LLC collect independently through their Wallet platforms; the Customer must review Apple's and Google's own privacy documentation.
Annex 2 — Approved Sub-processors
The following Sub-processors are approved as of the effective date of this Agreement. LOYAI maintains an up-to-date list at loyaistudio.com.
- Google LLC — Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Google Wallet API, App Check, and Google Generative AI used for in-product card design assistance. Servers: EEA and US. Transfer mechanism: EU-U.S. Data Privacy Framework; Standard Contractual Clauses as fallback.
- Vercel, Inc. — frontend hosting, deployment, and cookieless Vercel Analytics. Servers: EEA and US. Transfer mechanism: EU-U.S. Data Privacy Framework; Standard Contractual Clauses as fallback.
- Stripe, Inc. — payment processing (Customer billing data only; no Cardholder loyalty data). Servers: EEA and US. Transfer mechanism: EU-U.S. Data Privacy Framework; Standard Contractual Clauses as fallback.
- Loops Right, Inc. (Loops) — transactional email delivery and waitlist communications. Servers: United States. Transfer mechanism: Standard Contractual Clauses.
- Apple Inc. — Apple Wallet pass delivery, pass updates, and Apple Push Notification service for Cardholders who add a pass to Apple Wallet. Servers: United States. Transfer mechanism: EU-U.S. Data Privacy Framework; Standard Contractual Clauses as fallback.
- Functional Software, Inc. (Sentry) — frontend and backend error tracking, exception reporting, and performance diagnostics. Personal data is minimised: error stack traces and request metadata only; user identifiers and request payloads are not transmitted. Servers: Germany (EU). Transfer mechanism: Standard Contractual Clauses where applicable.
Apple Wallet and Google Wallet are independent platforms operating under their own terms and privacy policies. Personal data processed directly and solely by those platforms is outside the scope of this DPA and LOYAI's control.
LoyAI Oy · Pakilantie 86b C, 00670 Helsinki, Finland · info@loyaistudio.com · loyaistudio.com