Data Processing Agreement
Last updated: 19 September 2026 · Version 1.0
This Data Processing Agreement (the “DPA”) is entered into between you, the organization using idbuddy (the “Customer”, “you” or “your”), and Byte Buddies AB, corporate registration number 559491-4979, with its registered office in Malmö, Sweden (“idbuddy”, “we”, “us” or “our”).
It applies whenever we process personal data on your behalf in connection with the Service, and it is the agreement required by Article 28(3) GDPR. It forms an integral part of the Terms and Conditions of Service available at idbuddy.io/terms, and is accepted when you accept those Terms. You do not need to sign a separate copy.
This document governs the personal data you entrust to us about your members. It does not govern the personal data we process as our own controller, such as your administrators’ account details and our billing records. Those are described in our Privacy Policy at idbuddy.io/privacy.
In a nutshell
Organisations. In short: the six things worth knowing before the rest.
- This is the Article 28 agreement between your organization and us. It is part of the Terms, and you accept it with them.
- You decide what happens to your members' data. We act only on your instructions, never for our own purposes.
- Member data is stored in the EU. Sending email involves a transfer to the United States, on the basis named in Section 9.
- Every vendor that touches the data is named here, with its country and its role, and you hear about a new one before it starts.
- Where a member asks you to show, correct or delete what you hold, you get our help answering.
- When you leave, you choose: the data back, or deleted. Either way we do not keep it.
1. Roles and subject matter
Organisations. In short: You decide what happens to your member data and we carry it out. You are the controller, we are your processor.
For all Customer Data, you act as the data controller and we act as your processor within the meaning of Articles 4(7) and 4(8) GDPR.
“Customer Data” means the personal data you or your members put into your workspace: member records, memberships, membership fee records, stamp and punch cards, offers and their claims, events and attendance, check-in history, uploaded files, and the messages you send through the Service.
The subject matter of the processing is the provision of the Service to you: a membership management platform with an administrator dashboard, a member application, a scanner for counter staff and an email dispatcher.
Where you configure the Service in a way that determines a purpose of your own, you remain the controller for that purpose.
2. Duration
Organisations. In short: For as long as you have a workspace, plus the wind-down period in section 14.
This DPA takes effect when you accept the Terms and continues for as long as we process Customer Data on your behalf.
It survives termination of the Terms for as long as we still hold Customer Data, and the obligations in sections 6, 7, 12 and 14 continue to apply during that period.
3. Nature and purpose of the processing
Organisations. In short: We store your member data, show it back to you and your members, and send the messages you ask us to send.
We process Customer Data only to provide, maintain and secure the Service. In practice that means:
- Storing member records, memberships and the history of what a member has done in your workspace.
- Showing that data back to you in the administrator dashboard and to each member in the member application, subject to the access rules you configure.
- Issuing and reading membership QR codes so counter staff can identify a member and register a check-in, a stamp, a punch or a claimed offer.
- Sending the emails you compose and trigger, and the transactional emails the Service sends on your behalf, such as invitations.
- Counting members and activity so we can show you how your workspace is being used.
- Keeping backups, logs and security records needed to operate the Service.
We do not use Customer Data to train models, to build profiles of your members for our own purposes, or for advertising of any kind.
4. Categories of data subjects and personal data
Organisations. In short: Your members, your administrators, and the people you invite. The data is what you and they put in.
Categories of data subjects:
- Your members and former members.
- Your administrators and other staff with access to your workspace.
- People you have invited who have not yet accepted.
Categories of personal data:
- Identity and contact data: name, email address, profile picture, and any display name you set for a member in your workspace.
- Membership data: which organization a member belongs to, the role held, when the membership started, its renewal and consent state, and any membership fee records.
- Interaction data: stamps collected, punches spent, offers claimed, events attended, check-ins registered, and the scan log entries these produce.
- Content you supply: text, images and files you upload, and the content of the emails you send.
- Technical data generated by use: timestamps, identifiers and log entries tied to the actions above.
Where a membership of your organization itself reveals a special category of personal data under Article 9 GDPR, you remain responsible for identifying your condition under Article 9(2). We do not ask for, and the Service has no field for, special categories of data.
5. Instructions
Organisations. In short: We only do what you have told us to do, and we say so if an instruction looks unlawful.
We process Customer Data only on your documented instructions, including as regards transfers to a third country. Your instructions are made up of the Terms, this DPA and your configuration of the Service, and nothing else.
If EU or Swedish law requires us to process Customer Data beyond your instructions, we will tell you of that requirement before processing, unless that law prohibits the notification on important grounds of public interest.
We will inform you if, in our opinion, an instruction infringes the GDPR or another data protection provision. We may suspend the processing concerned until the instruction is withdrawn or amended.
6. Confidentiality
Organisations. In short: Everyone who can see your data is bound to keep it confidential.
We ensure that persons authorized to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
Access is granted on the principle of least privilege, only to the personnel who need it to operate, support and secure the Service, and it is withdrawn when it is no longer needed.
7. Security measures
Organisations. In short: The concrete measures we apply under Article 32, not a promise to be careful.
We implement appropriate technical and organizational measures under Article 32 GDPR, taking into account the state of the art, the costs of implementation, the nature and scope of the processing and the risk to the rights and freedoms of data subjects. They include:
- TLS 1.2 or higher for all traffic in transit, and encryption at rest for the database, file storage and backups.
- Row-level security in the database, so that one organization’s data is reachable only by that organization, enforced by the database itself rather than by application code.
- Every write goes through a checked server-side function rather than a direct database write from the browser.
- Least-privilege access for our own staff, with access logged.
- Separation of the production environment from development environments.
- Regular backups of the database and file storage.
- Staff trained in data protection and bound by confidentiality.
We review these measures periodically and may change them, provided the level of security is not reduced.
8. Sub-processors
Organisations. In short: The vendors we use, what each does, and how you object to a change.
You give us general written authorization to engage sub-processors. The current list is:
- Supabase Inc. (United States), with our project provisioned in an EU region. Database, authentication, file storage and scheduled jobs. This is where your account, membership and interaction data lives.
- Vercel Inc. (United States). Hosting for idbuddy.io, app.idbuddy.io, admin.idbuddy.io and ops.idbuddy.io, plus the aggregated usage measurement and the sign-in bot protection described in our Privacy Policy.
- Resend, Inc. (United States). Delivery of every email the platform sends. Message content and recipient addresses pass through it and its delivery logs and message metadata are held in the United States.
- Google Ireland Limited, with Google LLC (United States) as its sub-processor. Only where a person chooses “Continue with Google” to sign in.
- OpenStreetMap Foundation (United Kingdom). Address lookup and map tiles in the administrator tool. Marker images for those maps are served from a public code distribution network operated by Cloudflare, Inc. (United States).
- A hosted business email service for correspondence with info (at) idbuddy.io and contact (at) idbuddy.io.
Each sub-processor is bound by a written agreement imposing data protection obligations no less protective than those in this DPA.
We will inform you of any intended addition or replacement of a sub-processor at least thirty days before it takes effect, by email to the owner of your workspace. You may object on reasonable data protection grounds within that period by writing to info (at) idbuddy.io. If we cannot resolve the objection, you may terminate the affected part of the Service and receive a pro rata refund of any prepaid fees for the unused period.
We remain fully liable to you for the performance of each sub-processor’s obligations.
9. Transfers outside the EU/EEA
Organisations. In short: Your member data sits in the EU. Where a vendor reaches outside it, each transfer has a named basis.
Customer Data is stored in an EU region and our own staff access it from Sweden. Several of the sub-processors in section 8 are established outside the EU/EEA, so some processing reaches a third country. Where it does, it happens only on one of the following grounds under Articles 44 to 49 GDPR:
- Adequacy decision (Article 45). The United Kingdom is covered by an adequacy decision, which is the basis for the OpenStreetMap processing.
- European Commission Standard Contractual Clauses (Article 46), supplemented with technical and organizational safeguards: encryption in transit and at rest, access controls and transparency undertakings. This is the basis for Supabase, Vercel, Resend and Cloudflare.
- The EU-US Data Privacy Framework, where the vendor is certified under it and the processing falls within its scope.
We carry out a Transfer Impact Assessment before initiating a new third-country transfer. We will not add a transfer without a valid mechanism under Chapter V GDPR.
10. Assistance with data subject rights
Organisations. In short: Your members ask you, not us. Where you need our help to answer, you get it.
Data subject requests are yours to answer. If a member contacts us directly about data in your workspace, we will not respond on your behalf beyond telling them to contact you, and we will forward the request to you without undue delay.
Taking into account the nature of the processing, we assist you by appropriate technical and organizational measures in fulfilling your obligation to respond to requests under Articles 15 to 22 GDPR. In practice:
- The administrator dashboard lets you read, correct and remove the member data in your workspace yourself, which covers most requests without our involvement.
- Where a request cannot be answered from the dashboard, write to info (at) idbuddy.io and we will provide the Customer Data we hold about the data subject, or carry out the correction, restriction or erasure you instruct, within fourteen days of your request.
- We do not charge for this assistance unless a request is manifestly unfounded or excessive.
11. Assistance with Articles 32 to 36
Organisations. In short: We help you meet your own security, breach and impact-assessment duties.
Taking into account the nature of the processing and the information available to us, we assist you in ensuring compliance with your obligations under Articles 32 to 36 GDPR, including security of processing, breach notification and communication, data protection impact assessments, and prior consultation with a supervisory authority.
12. Personal data breaches
Organisations. In short: We tell you without undue delay and give you what you need to notify.
We notify you without undue delay after becoming aware of a personal data breach affecting Customer Data.
The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information. Where we cannot provide all of it at once, we provide it in phases without undue further delay.
Notifying supervisory authorities and data subjects under Articles 33 and 34 GDPR is your responsibility as controller. We do not make that notification on your behalf unless you instruct us to and we agree in writing.
13. Audits and information
Organisations. In short: You can ask us to demonstrate compliance, and you can audit, on reasonable terms.
We make available to you all information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by you or another auditor mandated by you.
An audit may be carried out once per calendar year, on at least thirty days’ written notice, during normal business hours, without unreasonable disruption to our operations, and subject to confidentiality obligations. We may satisfy an audit request by providing a current third-party report or certification where one covers the scope of the request.
Additional audits may be carried out where required by a supervisory authority or following a personal data breach affecting your Customer Data. You bear the reasonable costs of an audit unless it reveals a material breach of this DPA.
14. Return and deletion
Organisations. In short: When you leave, you choose: get the data back or have it deleted. Either way we do not keep it.
On termination of the Service, and at your choice, we delete or return all Customer Data to you, and delete existing copies, unless EU or Swedish law requires us to keep it.
You make that choice by writing to info (at) idbuddy.io before the end of the wind-down period set out in the Terms. If you make no choice, we delete.
Backups containing Customer Data are overwritten on their ordinary rotation and are not restored except to recover the Service.
Aggregated or anonymized data that can no longer be attributed to a data subject is not Customer Data and may be retained.
15. Liability and order of precedence
Organisations. In short: This document wins over the Terms where the two disagree about personal data.
Each party is liable under Article 82 GDPR for the damage caused by processing which infringes the GDPR.
In case of conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails. In case of conflict between this DPA and an Order, this DPA prevails as regards the processing of personal data.
This DPA is governed by Swedish law and disputes are settled as provided in the Terms.
16. Contact
Organisations. In short: One address for everything in this document.
Byte Buddies AB, corporate registration number 559491-4979, Malmö, Sweden.
For any matter under this DPA, including sub-processor objections, audit requests, assistance with data subject rights and your choice under section 14, write to info (at) idbuddy.io.
17. Changes to this DPA
Organisations. In short: Thirty days’ notice before a material change takes effect.
We may update this DPA where a change in law, in the Service or in our sub-processors requires it, provided the change does not reduce the protection given to Customer Data.
We give you at least thirty days’ notice of a material change before it takes effect, by email to the owner of your workspace. The version and date at the top of this document tell you which version is in force.