Last updated: June 17, 2026
This Data Processing Addendum (“DPA”) is incorporated into and forms part of the LockBuzz Terms of Service. It applies where LockBuzz processes personal data of a Brand’s Subscribers on the Brand’s behalf.
LockBuzz processes Subscriber Data as Processor solely for the purpose of delivering wallet pass installation, maintenance, gamification, and push notification services on behalf of the Brand.
| Category | Examples |
|---|---|
| Pseudonymous identifiers | UUID generated at pass install; no PII attached |
| Platform data | Apple Wallet or Google Wallet |
| Acquisition data | Install source (QR scan, referral link) |
| Engagement data | Buzz points, lock streak, last active date |
| Lifecycle data | Install date, uninstall date |
Individuals who install a Brand’s LockBuzz wallet pass (“Subscribers”).
For the term of the Brand’s LockBuzz subscription, plus the retention periods specified in Section 9.
The Brand shall:
LockBuzz shall:
The Brand grants general authorisation for LockBuzz to engage the following sub-processors. LockBuzz will impose data protection obligations on each sub-processor equivalent to those in this DPA.
| Sub-processor | Role | Location |
|---|---|---|
| Supabase, Inc. | Database and authentication infrastructure | USA |
| Vercel, Inc. | Platform hosting and serverless functions | USA / global |
| Stripe, Inc. | Billing and payment processing | USA |
| Apple Inc. | Apple Wallet pass delivery network | USA |
| Google LLC | Google Wallet pass delivery network | USA |
LockBuzz will notify Brands of any intended additions or replacements to sub-processors at least 14 days in advance, giving the Brand opportunity to object on reasonable grounds. If the Brand objects and LockBuzz cannot accommodate the objection, either party may terminate this DPA with 30 days’ notice.
LockBuzz implements the following technical and organisational measures:
Upon receiving a verifiable erasure request from a Subscriber, the Brand shall use LockBuzz’s Subscriber deletion tool (Settings › Danger Zone › Delete Subscriber by ID) to delete the record. LockBuzz will execute the deletion within 24 hours of the Brand’s instruction.
For access and portability requests, the Brand may use the Subscriber data export feature (Settings › Danger Zone › Export Subscriber Data) to provide a portable copy of the relevant data to the requesting Subscriber.
LockBuzz will assist the Brand with data subject requests that cannot be fulfilled by self-serve tools upon written request to privacy@lockbuzz.io.
In the event of a personal data breach affecting Subscriber Data, LockBuzz will notify the Brand without undue delay and within 72 hours where feasible. The notification will include, to the extent available:
The Brand is responsible for any notifications to Subscribers or supervisory authorities required by applicable law, based on information provided by LockBuzz.
The Brand may, with at least 30 days’ written notice and no more than once per calendar year, request that LockBuzz provide documentation demonstrating compliance with this DPA, or engage a mutually agreed qualified third-party auditor to conduct an audit. The Brand shall bear the reasonable cost of any such audit. LockBuzz may object to specific auditor firms that present a conflict of interest.
Subscriber Data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States, in connection with the sub-processors listed in Section 5. Such transfers are made under appropriate safeguards.
For transfers of EEA or UK Subscriber Data to sub-processors in third countries, LockBuzz relies on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 2: Controller to Processor) or the UK International Data Transfer Addendum where applicable. By entering into this DPA, the Brand and LockBuzz agree to be bound by the SCCs for any such transfers.
The SCCs are available at the European Commission’s SCC page or upon request to privacy@lockbuzz.io.
Each party’s liability to the other under this DPA is subject to the limitations of liability set out in the LockBuzz Terms of Service. Where a claim arises under data protection law attributable to both parties’ conduct, liability is allocated in proportion to each party’s responsibility for the damage.
This DPA forms part of the Terms of Service and remains in effect for as long as LockBuzz processes Subscriber Data on behalf of the Brand. It terminates automatically upon final deletion of all Subscriber Data following account termination. Sections 6, 8, 9, and 11 survive termination for the periods specified therein.
This DPA is governed by the same governing law as the Terms of Service, except where a different governing law is mandated by applicable data protection legislation (in which case the relevant data protection law governs with respect to those requirements).
Note: This DPA is a substantive starting draft; we strongly recommend review by a qualified data protection counsel before going live, particularly for GDPR Article 28 compliance verification and the SCC Module 2 selection rationale.