Legal

Data Processing Addendum

Last updated: June 17, 2026

This Data Processing Addendum (“DPA”) is incorporated into and forms part of the LockBuzz Terms of Service. It applies where LockBuzz processes personal data of a Brand’s Subscribers on the Brand’s behalf.

1. Definitions

2. Scope of Processing

Purpose

LockBuzz processes Subscriber Data as Processor solely for the purpose of delivering wallet pass installation, maintenance, gamification, and push notification services on behalf of the Brand.

Categories of Data Processed

CategoryExamples
Pseudonymous identifiersUUID generated at pass install; no PII attached
Platform dataApple Wallet or Google Wallet
Acquisition dataInstall source (QR scan, referral link)
Engagement dataBuzz points, lock streak, last active date
Lifecycle dataInstall date, uninstall date

Data Subjects

Individuals who install a Brand’s LockBuzz wallet pass (“Subscribers”).

Duration

For the term of the Brand’s LockBuzz subscription, plus the retention periods specified in Section 9.

3. Brand Obligations (Controller)

The Brand shall:

4. LockBuzz Obligations (Processor)

LockBuzz shall:

5. Sub-processors

The Brand grants general authorisation for LockBuzz to engage the following sub-processors. LockBuzz will impose data protection obligations on each sub-processor equivalent to those in this DPA.

Sub-processorRoleLocation
Supabase, Inc.Database and authentication infrastructureUSA
Vercel, Inc.Platform hosting and serverless functionsUSA / global
Stripe, Inc.Billing and payment processingUSA
Apple Inc.Apple Wallet pass delivery networkUSA
Google LLCGoogle Wallet pass delivery networkUSA

LockBuzz will notify Brands of any intended additions or replacements to sub-processors at least 14 days in advance, giving the Brand opportunity to object on reasonable grounds. If the Brand objects and LockBuzz cannot accommodate the objection, either party may terminate this DPA with 30 days’ notice.

6. Security Measures

LockBuzz implements the following technical and organisational measures:

7. Data Subject Rights

Upon receiving a verifiable erasure request from a Subscriber, the Brand shall use LockBuzz’s Subscriber deletion tool (Settings › Danger Zone › Delete Subscriber by ID) to delete the record. LockBuzz will execute the deletion within 24 hours of the Brand’s instruction.

For access and portability requests, the Brand may use the Subscriber data export feature (Settings › Danger Zone › Export Subscriber Data) to provide a portable copy of the relevant data to the requesting Subscriber.

LockBuzz will assist the Brand with data subject requests that cannot be fulfilled by self-serve tools upon written request to privacy@lockbuzz.io.

8. Data Breach Notification

In the event of a personal data breach affecting Subscriber Data, LockBuzz will notify the Brand without undue delay and within 72 hours where feasible. The notification will include, to the extent available:

The Brand is responsible for any notifications to Subscribers or supervisory authorities required by applicable law, based on information provided by LockBuzz.

9. Data Retention and Deletion

10. Audit Rights

The Brand may, with at least 30 days’ written notice and no more than once per calendar year, request that LockBuzz provide documentation demonstrating compliance with this DPA, or engage a mutually agreed qualified third-party auditor to conduct an audit. The Brand shall bear the reasonable cost of any such audit. LockBuzz may object to specific auditor firms that present a conflict of interest.

11. International Data Transfers

Subscriber Data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States, in connection with the sub-processors listed in Section 5. Such transfers are made under appropriate safeguards.

For transfers of EEA or UK Subscriber Data to sub-processors in third countries, LockBuzz relies on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 2: Controller to Processor) or the UK International Data Transfer Addendum where applicable. By entering into this DPA, the Brand and LockBuzz agree to be bound by the SCCs for any such transfers.

The SCCs are available at the European Commission’s SCC page or upon request to privacy@lockbuzz.io.

12. Liability

Each party’s liability to the other under this DPA is subject to the limitations of liability set out in the LockBuzz Terms of Service. Where a claim arises under data protection law attributable to both parties’ conduct, liability is allocated in proportion to each party’s responsibility for the damage.

13. Term and Termination

This DPA forms part of the Terms of Service and remains in effect for as long as LockBuzz processes Subscriber Data on behalf of the Brand. It terminates automatically upon final deletion of all Subscriber Data following account termination. Sections 6, 8, 9, and 11 survive termination for the periods specified therein.

14. Governing Law

This DPA is governed by the same governing law as the Terms of Service, except where a different governing law is mandated by applicable data protection legislation (in which case the relevant data protection law governs with respect to those requirements).

Note: This DPA is a substantive starting draft; we strongly recommend review by a qualified data protection counsel before going live, particularly for GDPR Article 28 compliance verification and the SCC Module 2 selection rationale.