Data Processing Agreement

Version 1.0 · Effective 23 September 2026 · Required by GDPR Article 28

What this is. GDPR requires a written contract whenever one business processes personal data on behalf of another. When you run a loyalty programme on Come Again, you are the data controller for your customers' data and we are your data processor. This agreement sets out what we may and may not do with it. It takes effect automatically when you create an account, and forms part of our Terms of Service.

1. Parties

Controller: the venue holding a Come Again account ("you").
Processor: Creative Media By ST, Business ID / Y-tunnus 3318632-3, Helsinki, Finland ("we", "us").

2. Scope of the processing

Subject matterOperating a customer loyalty programme on your behalf
DurationFor as long as your account is open, plus the deletion period in section 9
Nature and purposeCollecting loyalty sign-ups, recording visits and points, issuing rewards, and sending related notifications by email and SMS
Categories of data subjectMembers of your loyalty programme — your customers
Types of personal dataName; mobile number; email address; marketing consent and the time it was given; points balance; visit and redemption history, including bill amounts where you award points by spend; a log of messages sent and whether they were delivered
Special category dataNone. The service is not designed for, and must not be used to record, health data, religious or dietary beliefs, or any other special category data under Art. 9

3. Our obligations as processor

We will:

  1. Process only on your documented instructions — meaning your use of the service and its settings — including for any transfer outside the EEA, unless required otherwise by EU or Finnish law, in which case we will tell you first unless the law forbids it.
  2. Keep it confidential. Anyone we authorise to access the data is bound by confidentiality obligations.
  3. Apply the security measures in section 5 (GDPR Art. 32).
  4. Engage sub-processors only under section 6.
  5. Help you answer data subject requests. If a customer contacts us directly about access, correction, erasure, portability or objection, we will not act on it ourselves — we will forward it to you, since the decision is yours as controller.
  6. Help you meet Articles 32–36 — security, breach notification, and data protection impact assessments — to the extent the information is ours to give.
  7. Delete or return the data when the service ends, per section 9.
  8. Demonstrate compliance. We will provide the information reasonably needed to show we meet Art. 28, and allow an audit on reasonable notice, at most once a year unless a regulator or an actual breach requires otherwise.

4. Your obligations as controller

5. Security measures

The measures actually in place today:

We state these plainly rather than claiming certifications we do not hold. We are a small company and do not currently hold ISO 27001 or SOC 2 certification.

6. Sub-processors

You authorise the following sub-processors for customer loyalty data:

Sub-processorPurposeLocation
SupabaseDatabase, authentication, file storageEU — Frankfurt, Germany
VercelApplication hosting and serverless processingEU / global edge
Brevo (Sendinblue)Sending email notificationsEU — France
TwilioSending SMS notifications, on paid plansEU / US, under Standard Contractual Clauses

Our payment provider, Stripe, processes your billing details only. It never receives your customers' personal data, and is therefore not a sub-processor under this agreement.

We will give you at least 30 days' notice by email before adding or replacing a sub-processor. If you object on reasonable data protection grounds, you may terminate your subscription without penalty and receive a pro-rata refund for the unused period.

7. International transfers

Customer loyalty data is stored in Frankfurt, Germany. Where a sub-processor may process data outside the EEA — principally Twilio for SMS delivery — that transfer is covered by the European Commission's Standard Contractual Clauses.

8. Personal data breaches

If we become aware of a personal data breach affecting your customers' data, we will:

  1. Notify you without undue delay, and in any case within 24 hours of becoming aware, by email to your account address.
  2. Tell you what we know: what happened, which categories and roughly how many people are affected, the likely consequences, and what we are doing about it.
  3. Keep you updated as we learn more, and help you meet your own 72-hour notification deadline to the supervisory authority under Art. 33.

The notification duty to the authority and to affected individuals is yours, as controller. We will give you what you need to do it, promptly.

If a breach originates on your side — a shared or stolen login, a device left unattended, data exported and mishandled — you must tell us as soon as you can, so we can help contain it.

9. Deletion and return

10. Liability

Each party is responsible for its own compliance failures. Nothing in this agreement limits a data subject's statutory rights under GDPR Art. 82, or the powers of a supervisory authority. Between us, the liability limits in our Terms of Service apply.

11. Governing law

Finnish law, with disputes settled by the District Court of Helsinki. The supervisory authority is the Finnish Data Protection Ombudsman (tietosuoja.fi).

12. Contact

Data protection enquiries: hello@comeagain.fi
Creative Media By ST · Y-tunnus 3318632-3 · Helsinki, Finland