Data Processing Agreement (DPA)
Language. This document may be made available in other languages for convenience. In the event of any conflict or inconsistency between the English version and any translation, the English version shall prevail.
Contractual annexes that govern the processing of personal data entrusted to Voilatier in connection with the Services.
Contents
1. Purpose and scope
This Data Processing Agreement (hereinafter the "DPA") supplements the Terms of Service between Voilatier Inc. and the Customer, and governs the processing of personal data entrusted to Voilatier in connection with the Services. This DPA is intended to support the Customer's compliance with applicable data protection laws and reflects internationally recognized privacy and security principles for the processing of personal data.
2. Parties and roles
- Data Controller: the Customer.
- Data Processor: Voilatier Inc.
The Customer determines the purposes and means of processing the data of its end customers. Voilatier acts exclusively under the Customer's documented instructions.
3. Documented instructions
Voilatier processes Customer Data only to: (a) provide the Service in accordance with the Terms; (b) follow reasonable Customer instructions communicated through the panel or in writing; (c) comply with legal obligations to which it is subject. Any instruction that, in Voilatier's judgment, violates applicable law will be reported to the Customer without being carried out.
4. Confidentiality
Voilatier ensures that persons authorized to process Customer Data are bound by an equivalent contractual or legal duty of confidentiality. Access to production data is restricted to authorized engineering staff, with each access logged.
5. Technical and organizational measures
Voilatier implements measures appropriate to the risk, including:
- Encryption in transit (TLS 1.2+) and at rest (disk-level encryption for all storage, column-level encryption for identifiable PII).
- Mandatory two-factor authentication for administrative roles.
- Append-only audit log of significant actions and accounting movements.
- Strict logical tenant isolation: all data access is scoped to each tenant, so no query can cross tenant boundaries.
- Encrypted backups of production data with restricted access, maintained according to documented backup and recovery procedures.
- Documented incident management policy with playbooks by category.
- Mandatory code reviews for changes that touch security surfaces or PII.
- Periodic review of security controls; independent security assessments may be engaged based on risk and business requirements.
6. Subprocessors
Voilatier may engage subprocessors to provide parts of the Service. The current list is in Annex B. Before adding a new subprocessor, Voilatier will notify the Customer at least 30 days in advance. The Customer has the right to object on reasonable grounds; if the objection cannot be resolved, the Customer may terminate the contract without penalty.
Voilatier imposes on each subprocessor contractual obligations equivalent to those of this DPA regarding confidentiality, security and breach notification.
7. Assistance with data subject rights
Voilatier reasonably assists the Customer in responding to data subject requests (access, rectification, erasure, portability, objection). If a data subject contacts Voilatier directly, Voilatier will redirect them to the Customer without processing the request unilaterally, unless legally obligated otherwise.
The panel offers self-service tools to export (CSV), anonymize (preserving aggregates without PII) and delete end-customer records.
8. Breach notification
If Voilatier becomes aware of a security breach affecting Customer Data, it will notify the Customer without undue delay and, in any case, within 72 hours of detection. The notification will include: a description of the nature of the breach, the categories and approximate volume of affected data subjects and data, likely consequences, and measures taken or proposed to mitigate it.
9. Audit
The Customer has the right to verify compliance with this DPA up to once a year (plus one additional time after a confirmed breach) under the following conditions:
- 30 days' advance notice.
- A confidentiality undertaking by the designated auditor, under the confidentiality provisions of the applicable agreement.
- An audit conducted during business hours, without disrupting the Service.
- Costs borne by the Customer, unless material non-compliance is found, in which case Voilatier covers the direct costs.
Instead of an on-site audit, Voilatier may satisfy audit requests by providing available independent security assessments, audit reports, or responses to a recognized security questionnaire, subject to appropriate confidentiality restrictions.
10. International transfers
When Customer Data is transferred outside the jurisdiction of origin, Voilatier implements appropriate safeguards where required by applicable law, such as recognized contractual transfer mechanisms. The processing jurisdictions are listed in Annex B.
11. Duration and return
This DPA remains in effect as long as Voilatier processes Customer Data. Upon termination of the contract, the Customer has 60 days to export its data via the panel or API. After that period, Voilatier will delete or anonymize the data, unless legally required to retain it. At the Customer's request, Voilatier will issue a certificate of deletion.
Annex A — Processing details
Categories of data subjects
- End customers of the Merchant (people who receive loyalty communications).
- Merchant staff who operate the panel.
Categories of personal data
- Identification: first name, last name, optional external identifiers (DNI, RFC, NIT, RUC).
- Contact: mobile phone, email (both encrypted at the column level).
- Demographics: date of birth (optional), preferred language, country.
- Behavior: transaction history, accumulated points, RFM segment, loyalty tier, channel subscriptions.
- Consents: opt-in / opt-out per channel (email, WhatsApp), associated timestamps.
Purposes of processing
- Operation of the loyalty program (accumulation, redemption, tiers).
- Communication with end customers through authorized channels.
- Analytics and segmentation for the Merchant's internal use.
- Compliance with the Merchant's legal obligations.
Duration of processing
As long as the Merchant's Account is active, plus 60 days after termination for export, unless the Merchant instructs early deletion.
Annex B — Authorized subprocessors
List current as of 2026-07-22:
- DigitalOcean — United States · Application hosting and database storage
- Cloudflare — United States · CDN, DNS, CAPTCHA, and DDoS protection
- Brevo — European Union (France) · Transactional and marketing email delivery
- Meta Platforms (WhatsApp Cloud API) — United States / Ireland · WhatsApp message delivery
- Stripe — United States · Merchant subscription billing; does not process end-customer data
- Anthropic — United States · AI-powered language processing for optional platform features, subject to Voilatier's privacy, security, and data-processing controls
- Google (Google Wallet API) — United States · Digital loyalty passes for Google Wallet
- Apple (Apple Push Notification service) — United States · Push notifications for Apple Wallet pass updates
For questions about subprocessors or to subscribe to change notifications, write to [email protected].