Data Processing Agreement
Version 1.0, 1 September 2026
This Data Processing Agreement (“DPA”) is entered into between:
- Proof of Stake SRL, a company registered in Romania, Trade Registry No. J35/638/2018, sole registration code / VAT RO38943299 (“WalletWallet”, the “Processor”), and
- the customer identified in the signature block below (the “Customer”, the “Controller”).
It supplements the WalletWallet Terms & Conditions (the “Agreement”) and applies whenever WalletWallet processes personal data on the Customer’s behalf in providing the WalletWallet API, dashboard, and related services (the “Service”). Per Section 8.2.2 of the Agreement, this signed DPA prevails over Section 8 of the Agreement on data protection matters in case of conflict.
1. Definitions
- “GDPR” means Regulation (EU) 2016/679. “Controller”, “processor”, “personal data”, “processing”, “personal data breach”, and “data subject” have the meanings given in the GDPR.
- “Customer Personal Data” means personal data contained in Customer Content (the data the Customer submits to generate or update Passes) and in End-User device data (device identifiers, push tokens, and pass install state) that WalletWallet processes on the Customer’s behalf.
- Other capitalised terms have the meaning given in the Agreement.
2. Roles and scope
2.1 For Customer Personal Data, the Customer is the controller and WalletWallet is the processor. Where the Customer acts as a processor for another controller, the Customer warrants that its instructions to WalletWallet are authorised by that controller, and references to the Customer’s obligations as controller are read accordingly.
2.2 For the Customer’s own account data, billing records, and website analytics, WalletWallet is an independent controller as described in the Privacy Policy. That data is outside the scope of this DPA.
3. Duration
This DPA applies for the term of the Agreement and until WalletWallet has deleted or returned all Customer Personal Data under Section 13.
4. Processing on instructions
4.1 WalletWallet processes Customer Personal Data only on the Customer’s documented instructions, which consist of this DPA, the Agreement, and the Customer’s use of the Service’s features and APIs, and as required by applicable law. If law requires other processing, WalletWallet informs the Customer before processing unless that law prohibits it.
4.2 WalletWallet notifies the Customer without undue delay if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.
4.3 The Customer must not submit special-category data under Article 9 GDPR, payment card numbers, or government-issued identification numbers (Section 5.1 of the Agreement).
5. Confidentiality
WalletWallet ensures that persons authorised to process Customer Personal Data are bound by confidentiality obligations, contractual or statutory.
6. Security
WalletWallet implements and maintains the technical and organisational measures described in Annex 2, in accordance with Article 32 GDPR. WalletWallet may update those measures over time provided the overall level of protection is not reduced.
7. Sub-processors
7.1 The Customer gives general written authorisation for the sub-processors listed in Annex 3, which mirrors the live list at walletwallet.dev/trust/subprocessors/.
7.2 WalletWallet gives at least 30 days’ advance notice of any intended addition or replacement of a sub-processor, by updating that page and its dated changelog and, for customers who have requested it by email, by email notice.
7.3 The Customer may object within the notice period on reasonable data-protection grounds. The parties will discuss the objection in good faith; if it cannot be resolved, the Customer may terminate the affected part of the Service in accordance with the Agreement.
7.4 WalletWallet imposes on each sub-processor data-protection obligations no less protective than those in this DPA and remains fully liable to the Customer for the sub-processor’s performance.
8. Data subject requests
Taking into account the nature of the processing, WalletWallet assists the Customer with appropriate technical and organisational measures in fulfilling the Customer’s obligation to respond to data-subject requests under Chapter III GDPR. If a data subject contacts WalletWallet directly about processing under this DPA, WalletWallet refers the request to the Customer without undue delay.
9. Personal data breach
WalletWallet notifies the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification includes, to the extent available, the information listed in Article 33(3) GDPR, and WalletWallet provides reasonable assistance with the Customer’s notification obligations under Articles 33 and 34.
10. Assistance
Taking into account the nature of the processing and the information available to it, WalletWallet assists the Customer with the Customer’s obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, and prior consultation).
11. Audits
WalletWallet makes available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 GDPR, including the documents published at walletwallet.dev/trust/, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor the Customer mandates. Audits require at least 30 days’ notice, take place at most once in any 12-month period unless a supervisory authority requires otherwise or a personal data breach has occurred, must not unreasonably disrupt WalletWallet’s operations, and are subject to confidentiality. Each party bears its own costs.
12. International transfers
12.1 Customer Personal Data is stored at rest in Cloudflare’s European Union region: the primary database and the pass object store both run in Cloudflare’s EU location, with no replicas outside it. Request processing runs on Cloudflare’s global edge network, so compute is not EU only, and traffic is encrypted in transit throughout.
12.2 For the transfers this involves, WalletWallet relies on Cloudflare’s data processing addendum incorporating the EU Standard Contractual Clauses; Cloudflare additionally holds an EU Cloud Code of Conduct verification. Any other transfer of Customer Personal Data outside the EEA is governed by the Standard Contractual Clauses or another lawful transfer mechanism identified in Annex 3.
12.3 The EU storage location is WalletWallet’s operational configuration rather than a contractually pinned jurisdiction. A contractual residency commitment, if required, must be agreed separately in writing.
13. Return and deletion
On termination of the Service, at the Customer’s choice, WalletWallet deletes or returns Customer Personal Data and deletes existing copies within 30 days, unless applicable law requires retention. Return is provided in a commonly used, machine-readable format (JSON via the API). By design of the wallet platforms, a Pass already installed on an End-User device cannot be removed by WalletWallet; revocation voids the Pass, and the voided Pass may remain accessible to that device (Section 14.3 of the Agreement).
14. Liability
The liability of each party under this DPA is subject to the exclusions and limitations of liability in the Agreement.
15. Governing law
This DPA is governed by the laws of Romania, and the courts competent for the registered seat of Proof of Stake SRL have exclusive jurisdiction, as set out in the Agreement.
16. Execution
To execute this DPA, complete the Customer signature block, sign, and email a copy to [email protected]. WalletWallet countersigns and returns the executed copy within a few business days.
| WalletWallet (Processor) | Customer (Controller) | |
|---|---|---|
| Legal entity | Proof of Stake SRL | |
| Registration | J35/638/2018, RO38943299 | |
| Name | ||
| Title | ||
| Date | ||
| Signature |
Annex 1: Details of processing
- Subject matter: provision of the Service (generating, signing, hosting, updating, revoking, and delivering Apple Wallet and Google Wallet passes and related notifications).
- Duration: the term of the Agreement, plus the deletion period in Section 13.
- Nature and purpose: hosting, storage, transmission, and delivery of pass content and pass update notifications on the Customer’s behalf.
- Types of personal data: pass content the Customer submits, which may include names, member or customer identifiers, barcode values, field labels and values, and images; End-User device data (Apple device library identifiers and push tokens, Google pass install state); Apple Wallet error logs sent by devices, retained briefly.
- Categories of data subjects: the Customer’s End Users and personnel.
- Excluded data: special-category data, payment card numbers, and government-issued identification numbers must not be submitted.
Annex 2: Technical and organisational measures
- Hosting. The Service runs entirely on Cloudflare’s managed platform (Workers, D1, R2, Queues); WalletWallet operates no servers of its own.
- Encryption in transit. All API, dashboard, and website traffic is served over TLS. Connections to Apple Push Notification service and the Google Wallet API use TLS.
- Encryption at rest. Cloudflare encrypts stored data at rest across the platform. Customer-supplied signing credentials on Bring Your Own Cert plans (Apple certificates and keys, Google service-account credentials) are additionally encrypted at the application layer with AES-256-GCM under a master key held as a deployment secret, with each ciphertext cryptographically bound to the owning account.
- Data residency. The primary database (Cloudflare D1) and the pass object store (Cloudflare R2) run in Cloudflare’s EU region with no replicas outside it; request processing runs on the global edge.
- Access control. Production access is limited to authorised personnel. Operational tooling uses scoped, least-privilege API tokens.
- Credentials. Customer API keys are randomly generated 128-bit bearer tokens, unique per account and rotatable on request. Installed passes authenticate update requests with a per-pass randomly generated token owned by the server and never settable by callers.
- Customer authentication. Dashboard sign-in is passwordless: a one-time code sent by email, or Google sign-in. WalletWallet stores no passwords.
- Tenant separation. Every stored record and object is keyed to the owning account, and authorisation checks run on every request.
- Abuse controls. Unauthenticated endpoints are rate limited per IP at the edge; authenticated usage is metered per plan.
- Availability and recovery. The primary database supports point-in-time recovery covering the previous 30 days. An independent scheduled health check monitors the API.
- Retention and deletion. As set out in Section 7 of the Privacy Policy: account deletion within 30 days of request, Apple Wallet error logs kept at most 7 days, verification codes expiring within minutes.
Annex 3: Authorised sub-processors
The authoritative, dated list is published at walletwallet.dev/trust/subprocessors/. As of the version date of this DPA, the sole sub-processor of Customer Personal Data is:
| Sub-processor | Activity | Location | Transfer mechanism |
|---|---|---|---|
| Hosting, database (D1), object storage (R2), delivery | EU storage, global edge processing | EU SCCs (Cloudflare DPA); EU Cloud Code of Conduct verification |
Apple Inc. and Google LLC receive pass identifiers, device push tokens, and pass object data as independent wallet platforms chosen by the Customer’s End Users; they act under their own terms and are not sub-processors of WalletWallet. Providers that process only WalletWallet’s controller-side data (Polar, Loops, PostHog) are listed in the Privacy Policy and are outside the scope of this DPA.