What this is. GDPR requires a written contract whenever one business processes personal data on behalf of another. When you run a loyalty programme on Come Again, you are the data controller for your customers' data and we are your data processor. This agreement sets out what we may and may not do with it. It takes effect automatically when you create an account, and forms part of our Terms of Service.
1. Parties
Controller: the venue holding a Come Again account ("you").
Processor: Creative Media By ST, Business ID / Y-tunnus 3318632-3, Helsinki,
Finland ("we", "us").
2. Scope of the processing
| Subject matter | Operating a customer loyalty programme on your behalf |
| Duration | For as long as your account is open, plus the deletion period in section 9 |
| Nature and purpose | Collecting loyalty sign-ups, recording visits and points, issuing rewards, and sending related notifications by email and SMS |
| Categories of data subject | Members of your loyalty programme — your customers |
| Types of personal data | Name; mobile number; email address; marketing consent and the time it was given; points balance; visit and redemption history, including bill amounts where you award points by spend; a log of messages sent and whether they were delivered |
| Special category data | None. The service is not designed for, and must not be used to record, health data, religious or dietary beliefs, or any other special category data under Art. 9 |
3. Our obligations as processor
We will:
- Process only on your documented instructions — meaning your use of the service and its settings — including for any transfer outside the EEA, unless required otherwise by EU or Finnish law, in which case we will tell you first unless the law forbids it.
- Keep it confidential. Anyone we authorise to access the data is bound by confidentiality obligations.
- Apply the security measures in section 5 (GDPR Art. 32).
- Engage sub-processors only under section 6.
- Help you answer data subject requests. If a customer contacts us directly about access, correction, erasure, portability or objection, we will not act on it ourselves — we will forward it to you, since the decision is yours as controller.
- Help you meet Articles 32–36 — security, breach notification, and data protection impact assessments — to the extent the information is ours to give.
- Delete or return the data when the service ends, per section 9.
- Demonstrate compliance. We will provide the information reasonably needed to show we meet Art. 28, and allow an audit on reasonable notice, at most once a year unless a regulator or an actual breach requires otherwise.
4. Your obligations as controller
- Have a lawful basis. Every customer must opt in themselves through the sign-up form. You must not add, import or upload anyone who did not consent — not from a till system, a booking list, a business card bowl, or anywhere else.
- Give your customers the privacy information GDPR requires, and honour their rights.
- Keep your login credentials secure, and make sure staff using the dashboard understand they are handling customer personal data.
- Only enter data the service is designed for. Do not record special category data in free-text fields.
5. Security measures
The measures actually in place today:
- Encryption in transit — HTTPS/TLS on every connection, with HSTS enforced.
- Encryption at rest for the database and uploaded files.
- Tenant isolation at the database layer — row-level security policies mean one venue cannot read another's records even if application code were flawed.
- Passwords are salted and hashed by our authentication provider and are never stored or visible in readable form.
- Privileged credentials are held server-side only and never sent to a browser.
- Customer points cards are reachable only via a long, randomly generated private link, and those pages are excluded from search engines.
- Access is restricted to the minimum number of people needed to operate the service.
- EU hosting — see section 7.
We state these plainly rather than claiming certifications we do not hold. We are a small company and do not currently hold ISO 27001 or SOC 2 certification.
6. Sub-processors
You authorise the following sub-processors for customer loyalty data:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | EU — Frankfurt, Germany |
| Vercel | Application hosting and serverless processing | EU / global edge |
| Brevo (Sendinblue) | Sending email notifications | EU — France |
| Twilio | Sending SMS notifications, on paid plans | EU / US, under Standard Contractual Clauses |
Our payment provider, Stripe, processes your billing details only. It never receives your customers' personal data, and is therefore not a sub-processor under this agreement.
We will give you at least 30 days' notice by email before adding or replacing a sub-processor. If you object on reasonable data protection grounds, you may terminate your subscription without penalty and receive a pro-rata refund for the unused period.
7. International transfers
Customer loyalty data is stored in Frankfurt, Germany. Where a sub-processor may process data outside the EEA — principally Twilio for SMS delivery — that transfer is covered by the European Commission's Standard Contractual Clauses.
8. Personal data breaches
If we become aware of a personal data breach affecting your customers' data, we will:
- Notify you without undue delay, and in any case within 24 hours of becoming aware, by email to your account address.
- Tell you what we know: what happened, which categories and roughly how many people are affected, the likely consequences, and what we are doing about it.
- Keep you updated as we learn more, and help you meet your own 72-hour notification deadline to the supervisory authority under Art. 33.
The notification duty to the authority and to affected individuals is yours, as controller. We will give you what you need to do it, promptly.
If a breach originates on your side — a shared or stolen login, a device left unattended, data exported and mishandled — you must tell us as soon as you can, so we can help contain it.
9. Deletion and return
- You may export your customer list at any time while your account is open.
- You may delete individual customer records at any time from your dashboard.
- On account closure, data is deleted 90 days afterwards. You may request immediate deletion, or an export, at any point in that window.
- Backups are overwritten on a rolling cycle and are fully purged within a further 30 days.
10. Liability
Each party is responsible for its own compliance failures. Nothing in this agreement limits a data subject's statutory rights under GDPR Art. 82, or the powers of a supervisory authority. Between us, the liability limits in our Terms of Service apply.
11. Governing law
Finnish law, with disputes settled by the District Court of Helsinki. The supervisory authority is the Finnish Data Protection Ombudsman (tietosuoja.fi).
12. Contact
Data protection enquiries: hello@comeagain.fi
Creative Media By ST · Y-tunnus 3318632-3 · Helsinki, Finland