Data Processing Agreement
Last updated 2026-07-31
Data Processing Agreement
Version 2026-07-31 — in force from 31 July 2026
This agreement is made between you, the business holding a Fidei account (the Controller), and Weslley David Botelho Santos (the Processor), Avenue Coghen 23, 1180 Uccle, Brussels, Belgium, company number BE1032.434.445.
It forms part of the Terms of Service and satisfies Article 28(3) of the GDPR and Articles 39 and 42 of the LGPD. It applies whenever Fidei processes personal data on your behalf.
Why you are being asked to sign this. When your customers join your loyalty card, you decide why their data is collected and what happens to it — so the law treats you as the controller and Fidei as your processor. Article 28(3) requires that relationship to be governed by a written contract. Without one, every enrolment you run is unlawful, regardless of how carefully Fidei is built.
1. Subject matter, duration, nature and purpose
Subject matter. Processing of personal data of your loyalty programme members, so that Fidei can provide the loyalty card service described in the Terms of Service.
Duration. For as long as your account is open, plus the deletion period in section 10.
Nature and purpose. Collection, storage, organisation, retrieval, transmission to wallet providers at the member's request, and deletion — all for the purpose of issuing and running loyalty cards, recording stamps and redemptions, and reporting on programme performance.
2. Categories of data subjects and personal data
Data subjects: your loyalty programme members (your customers).
Categories of personal data:
- identity data: first name;
- contact data: email address or mobile number;
- programme data: stamp count, tier, visit and redemption history, location visited, serving staff member;
- technical data: pass serial number, pass authentication token, wallet device identifier and push token, chosen language;
- consent evidence: document version accepted, locale, wording shown, timestamp, IP address, browser description, and a keyed hash of the contact detail.
No special category data (GDPR Art. 9) and no sensitive personal data (LGPD Art. 5(II)) is processed. Do not enter any.
3. Processing only on your instructions
Fidei processes personal data only on your documented instructions, including for transfers, unless required otherwise by law — in which case Fidei will tell you before processing, unless that law forbids it.
Your instructions are: these terms, this agreement, and the configuration choices you make in the product. Fidei will tell you if, in its opinion, an instruction infringes data protection law.
4. Confidentiality
Fidei ensures that everyone authorised to process the personal data is bound by an appropriate duty of confidentiality, and limits access to those who need it to perform their role.
5. Security measures (GDPR Art. 32 / LGPD Art. 46)
Fidei implements and maintains:
- encryption of personal data in transit;
- hashing of account passwords using scrypt with per-user salts;
- unguessable, randomly generated pass serial numbers and authentication tokens;
- strict tenant isolation, so one business cannot read another's data;
- role-based access control across owner, staff and administrator roles;
- rate limiting on authentication and public enrolment endpoints;
- a strict Content Security Policy and standard security headers on the web application;
- managed, backed-up database infrastructure with restore procedures;
- logging sufficient to investigate an incident.
These measures are reviewed periodically and may be improved, but will not be reduced below the level of protection described here.
Known limitations, stated honestly. Session tokens are held in browser local storage rather than in HttpOnly cookies; pass authentication tokens are stored unencrypted at rest. Both are documented so you can make an informed assessment rather than assume otherwise.
6. Sub-processors
You give general authorisation for Fidei to engage sub-processors. Current sub-processors:
- Vercel Inc. (application hosting) and Neon, Inc. (PostgreSQL database) — hosting, database and application delivery.
- Apple Inc. — Apple Wallet pass delivery and updates, where a member chooses to add a card to Apple Wallet.
- Google LLC — Google Wallet pass delivery and updates, on the same basis.
Fidei imposes on each sub-processor data protection obligations no less protective than those in this agreement, and remains fully liable to you for their performance.
Fidei will give you at least 30 days' notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, you may terminate the affected service without penalty.
7. Assisting you with data subject rights
Fidei will, taking into account the nature of the processing, assist you by appropriate technical and organisational measures in responding to requests to exercise rights under GDPR Chapter III and LGPD Art. 18.
If a member contacts Fidei directly, Fidei will not respond substantively but will forward the request to you without undue delay.
8. Assisting you with security, breaches and impact assessments
Fidei will assist you in complying with GDPR Articles 32 to 36 and the equivalent LGPD obligations, taking into account the nature of the processing and the information available to it.
Breach notification. Fidei will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your data. The notification will describe the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Fidei will provide further information as it becomes available so that you can meet your own 72-hour deadline to your supervisory authority.
9. Audits
Fidei will make available to you all information necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
Audits are limited to once per twelve months unless a breach has occurred or a supervisory authority requires more, must be on at least 30 days' written notice, during business hours, and conducted so as not to disrupt Fidei's operations or compromise other customers' confidentiality.
10. Deletion or return on termination
On termination, and at your choice, Fidei will delete or return all personal data processed on your behalf, and delete existing copies, unless law requires it to be retained.
Absent a contrary instruction, Fidei will delete the data 30 days after termination, so that you have a window to export it first.
Consent evidence is retained for 5 years, stripped of IP address and browser description, in reliance on GDPR Art. 17(3)(e) — establishment, exercise or defence of legal claims. What remains is a keyed hash of the contact detail, from which the contact detail itself cannot be recovered.
11. International transfers
Fidei processes data in the European Union and Brazil, and its sub-processors may process it elsewhere. Transfers out of the EEA are made under the European Commission's Standard Contractual Clauses (Decision 2021/914), which are incorporated into this agreement by reference, with supplementary measures where a transfer impact assessment requires them. Transfers out of Brazil are made under LGPD Art. 33, relying on standard contractual clauses or an adequacy recognition as applicable.
12. LGPD-specific operator obligations
Where the LGPD applies, Fidei acts as operador and you as controlador within the meaning of Article 5. Fidei will process data strictly per your instructions (Art. 39), maintain records of processing (Art. 37), adopt the security measures in Article 46, and communicate incidents to you under Article 48 within the timescale in section 8. Fidei's data protection contact, acting as encarregado for its own processing, is Weslley David Botelho Santos (contact@botelho.solutions) — no separate DPO appointed.
13. Order of precedence
Where this agreement conflicts with the Terms of Service, this agreement prevails in respect of data processing. Where it conflicts with the Standard Contractual Clauses, the Clauses prevail.
Questions: contact@botelho.solutions.