Data processing agreement
This agreement supplements the business terms when a business uses Retapio to manage customer data in its own loyalty programme.
Last updated:
1. Parties and roles
The business that activates a Retapio tenant is the data controller for its own loyalty programme. RUSEI MS COMPANY SRL is the processor for processing carried out on behalf of the business through the platform.
For Retapio account authentication, general service security, billing and its own legal obligations, RUSEI MS COMPANY SRL acts separately as a controller under the Privacy Policy.
2. Subject matter, duration, nature and purpose
Processing covers hosting and organising the loyalty programme, associating the customer with the business, recording NFC visits, calculating points, presenting offers, activating rewards, completing the receipt, statistics and technical support.
Processing continues while the business uses the service and for the limited period required for export, deletion, security or legal obligations after termination.
3. Data subjects and data categories
- Data subjects: loyalty programme customers and authorised business users.
- Identification data: UID, name, email, role and tenant.
- Loyalty data: visits, points, rewards, campaigns, transactions, receipt value and associated history.
- Analytics data: segments, recency, frequency, estimated value and inactivity probability.
- Technical data: sessions, NFC stations, audit logs, errors and anti-fraud signals.
The current version does not process the Google profile photo, receipt product lists, card data or personal data in the NFC tag.
4. Controller instructions
Retapio processes data only to deliver the features configured by the business and under the Terms, this agreement and documented instructions submitted through service settings or support. If an instruction appears to breach the law, we will inform the business before carrying it out unless prohibited by law.
The business is responsible for the legal basis of its programme, customer notices, the correctness of its rules and authorisation of its staff.
5. Confidentiality and security
Staff access is limited to operational need and subject to confidentiality obligations. Measures include verified authentication, role- and tenant-based authorisation, restrictive Firestore rules, privileged server-side operations, atomic transactions, opaque NFC tokens, separation of the retention ledger and limited operational logs.
The business must protect its own accounts, devices and access rights and notify us promptly of unauthorised use.
6. Sub-processors
The business authorises the providers required to operate the service:
- Google LLC and its relevant entities — Firebase Authentication, Firestore and Google Cloud for identity, storage and backend execution;
- Stripe — payments and business subscription management, within the limits of billing data.
We will impose appropriate data-protection obligations and provide reasonable notice of material changes to the list, allowing the business to raise justified objections before the change where possible.
7. Assistance and incidents
Within the available information and features, we assist the business with data-subject requests, processing security, incident notifications, impact assessments and consultations with authorities. We will inform the business without undue delay after confirming an incident that affects its data.
8. Deletion, return and audit
When the service ends or following a valid instruction, we delete or return business data, as applicable, except for data that must be retained by law or for the defence of legal rights. Technical copies are removed gradually according to the backup cycle.
We provide information reasonably required to demonstrate compliance and permit proportionate, planned and confidential audits. The business bears the costs of a special audit unless it identifies a material breach attributable to Retapio.
9. Transfers and precedence
International transfers rely on mechanisms recognised by the GDPR, including adequacy decisions and standard contractual clauses, as applicable. If there is a conflict concerning data protection, this agreement prevails over the general Terms for that issue.
Contact for instructions and requests: [email protected].