Legal information
Data processing agreement
This operational draft describes how Pulz processes loyalty-customer data for a business. Legal entity details, annexes and signatures must be completed before commercial use.
Last updated: 20 September 2026
Parties and roles
The participating business is the controller for personal data it collects through its loyalty programme. The final registered Pulz operator is the processor. Each party must insert its full legal identity, address and authorised contact before this agreement is signed.
Instructions and purpose
Pulz processes data only on documented instructions needed to host the programme, issue and update Wallet cards, record stamps and rewards, provide metrics, deliver consent-based Wallet messages, provide support, maintain security and return or delete data. Pulz must inform the business if an instruction appears unlawful, unless prohibited by law.
People and data
Data subjects are loyalty customers, business owners and staff. Data may include names and email addresses when supplied, random card identifiers, Wallet object identifiers, consent choices, visit and reward activity, support content, staff identifiers and security logs. Businesses must not submit special-category data, payment-card details, passwords, identity documents or data they do not need.
Confidentiality and security
Authorised personnel must be bound by confidentiality. Current measures include encrypted transport, account authentication, business-level row security, role-based access, staff-attributed audit records, constrained service functions, rate limiting, secret separation and controlled support access. The final technical and organisational measures annex must be reviewed and attached before signature.
Sub-processors and transfers
Expected providers include Supabase for authentication, database and storage; Vercel for hosting; Google for Google Wallet; Apple when Apple Wallet is enabled; Stripe for billing; Resend when transactional email is enabled; and OpenAI only if the optional support assistant is approved and enabled. The final list, processing locations, notice period, objections process, data-processing terms and transfer safeguards must be verified before launch.
Assistance and incidents
Pulz will reasonably assist with data-subject requests, security assessments, breach obligations and regulator enquiries relating to the service. Pulz must notify the business without undue delay after becoming aware of a personal-data breach and provide available information needed for the business's assessment and notification duties.
Return, deletion and audits
Businesses can export their account data. On termination, Pulz will return or delete personal data according to the agreed retention schedule unless law requires continued storage. Security, billing and audit records may be retained only for documented legal or defence needs. Reasonable compliance information and audits must be supported subject to confidentiality and proportionate safeguards.
Completion required
This page is a transparent working draft, not a signed agreement. Before accepting paying businesses, complete the parties, duration, processing annex, retention schedule, sub-processor list, international-transfer mechanism, security annex, contact details and signature process with qualified Polish/EU legal review.