Back to the help center
Legal

Data processing agreement

This data processing agreement (DPA) describes how Loyalo processes personal data on behalf of your store, in line with the GDPR. It forms part of the agreement between you and Loyalo.ai, part of Web Builders.

Updated: 2 October 2026
Draft

This is a draft version of this page. The content still needs to be reviewed by a lawyer before publication.

1. Roles

Your store is the controller for its customers' personal data. Loyalo, provided by Loyalo.ai, part of Web Builders, is the processor and processes this data solely to deliver the service and on your instructions.

2. Categories of data and data subjects

  • Data subjects: customers of your store and, where applicable, staff who use Loyalo
  • Data: name, email address, address, customer ID, subscription and order data, and loyalty data such as points, rewards and tier
  • Payment references from Mollie (mandate IDs, payment statuses; no card or bank details)
  • A log of emails sent and, optionally, Klaviyo profile fields and chat messages

3. Instructions

Loyalo processes personal data only on your instructions, as set out in this agreement and the normal operation of the app. Loyalo does not use the data for its own purposes, such as its own marketing.

4. Security measures

  • Separation between shops: the database can only be reached by Loyalo's server functions, which tie each request to one shop
  • Encrypted storage of Mollie keys (AES-GCM)
  • Access for staff of Loyalo.ai, part of Web Builders, based on roles and the least-privilege principle
  • Audit log of administrative actions on accounts and data
  • European hosting of the database and application

5. Subprocessors

Loyalo uses subprocessors such as Shopify, Supabase, Vercel, Mollie, Resend, Klaviyo (optional), Anthropic (AI features) and Stripe. An up-to-date overview with purpose, region and data category is on the subprocessors page. Changes to this list are announced in advance as described on that page.

6. Data breaches

If Loyalo becomes aware of a security incident that may affect personal data processed on your behalf, Loyalo will notify you without undue delay, so that you, as controller, can assess whether notification to the Data Protection Authority or data subjects is required.

7. Return and deletion

After your Loyalo account ends, the personal data processed on your behalf is deleted or anonymised within a reasonable period, unless a legal retention obligation requires otherwise. On request, an export of your data can be offered before deletion.

8. Audits

You can request reasonable information about Loyalo's security measures to demonstrate compliance with this agreement. For further review, we will agree on scope, format and timing together.

9. Transfers outside the EEA

Data is processed within the European Economic Area in principle. Where a subprocessor processes data outside the EEA, this is done only with appropriate safeguards, such as standard contractual clauses.

10. Duration

This data processing agreement applies for as long as you use Loyalo and ends automatically when your Loyalo account is terminated, subject to the provisions on return and deletion.