Data Processing and Joint Controller Terms

These terms are part of the Terms of Service for Businesses. They set out, for every kind of personal data that passes between your business and Stampomat, who is responsible for what. Part 1 applies where we process data on your instruction. Part 2 applies where we decide purposes together with you. Parts 3 to 6 apply to both.

1. About these terms

1.1 Who the parties are

"We", "us" and "Stampomat" mean Stampomat, operated by Daniel Ilievski, Ljubljana, Slovenia, SI. Company registration: pending. Until the company exists, the operator named above is personally the contracting party.

"You" means the business that holds an account with us: a shop running a stamp or points programme, an organisation running memberships, or a merchant whose website and pickup ordering we host through Stampomat Sites ("Sites"). A partner that an organisation names for a member benefit is covered as section 6.8 describes.

Privacy contact for both of us: hello@stampomat.com. General contact: hello@stampomat.com. Our data protection officer: none appointed; write to the privacy contact above. Our representative in North Macedonia: none appointed yet; write to the privacy contact above.

1.2 How you accept these terms

You accept these terms, together with the Terms of Service for Businesses, on the acceptance page you see before you first use the dashboard or the merchant portal. A later version does not bring that page back, and section 14 says how a change reaches you. The page shows the full text before you click. We record which document and version you accepted, in which language, the content hash of the text, the surface, the button label, the time, your IP address and browser, and the person who clicked on your behalf.

That record is the written form the data protection laws require for a processor contract and a joint controller arrangement. If you need a countersigned copy, email hello@stampomat.com and we will sign a PDF of this version.

1.3 What these terms cover, in one table

These terms do not cover data we hold about you as a prospect or as our customer contact. The section for business contacts in the Privacy Policy covers that.

1.4 Words we use

"Personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning given in the General Data Protection Regulation (GDPR) and the Macedonian Law on Personal Data Protection (ZZLP). "Customer" means a person who collects stamps or points, holds a membership, or places an order (an "order customer" in the Terms of Service for Businesses). "Sub-processor" means a company we use to process personal data on our behalf. "Sub-processors page" means Sub-processors and recipients.

1.5 The laws behind these terms

Part 1 is written to contain every item that GDPR Article 28(3) and ZZLP Article 32(3) require in a processor contract. Part 2 is written to be the arrangement that GDPR Article 26 and ZZLP Article 30 require between joint controllers. The essence of Part 2 is published in the Privacy Policy so that customers can see it. Nothing in these terms limits the rights a data subject has against either of us under those laws.


Part 1. Processing on your instruction

2. What we process for you

2.1 Description of the processing

2.2 Your duties and rights as controller

You decide why the data in section 2.1 is processed and you are responsible for the lawfulness of that decision. In particular you:

  1. give us only data you may lawfully give us, and collect it with a notice that names Stampomat as your processor where the law requires it;
  2. keep the configuration we act on current: the contact address that receives relayed messages, your legal identity fields, the roster you type in, the partners you name;
  3. answer the requests of people whose data you control, using our help under section 9;
  4. instruct us only in ways that comply with the law;
  5. may ask us at any time what we hold for you, may audit us under section 10, and may end the processing under section 11.

3. Our duties as your processor

3.1 We act only on your instructions

We process the data in section 2.1 only on your documented instructions. Your instructions are: these terms, the Terms of Service for Businesses, the settings you choose in your dashboard or portal or through our API, and written instructions you send to hello@stampomat.com. This includes any transfer of the data to another country. If a law of the European Union, of Slovenia or of North Macedonia requires us to process the data differently, we tell you before we do so, unless that law forbids us to tell you.

We do not use the data in section 2.1 for our own purposes. We do keep aggregate counts that identify nobody, and we keep security and audit records that we control ourselves; the Privacy Policy describes those.

3.2 Confidentiality

Every person we authorise to process personal data is bound by a written confidentiality duty. That covers our staff, any contractor, and any AI assistant session we operate on our own systems. Nobody processes personal data for us without that duty.

3.3 Security

We take the technical and organisational measures in Part 4. They are the measures GDPR Article 32 and ZZLP Article 36 require, sized to the risk of the data we hold for you.

3.4 Sub-processors

We use the sub-processors on the sub-processors page under the conditions in Part 3. We do not add one without the notice and objection right in section 7.2.

3.5 Helping you with people's rights

We help you answer requests of access, rectification, erasure, restriction, portability and objection, as set out in section 9.

3.6 Helping you with security, breaches and impact assessments

We help you meet your duties on security, breach notification to the authority and to the people affected, data protection impact assessments and prior consultation, as set out in section 9. We tell you about a personal data breach that affects your data without undue delay and at the latest within 48 hours of becoming aware of it, with the content in section 6.6.

3.7 Deletion and return

At the end of the service we return or delete the data as you choose, within the window in section 11.

3.8 Information and audits

We give you the information you need to show that this processing complies with the law, and we allow and contribute to audits, as set out in section 10.

3.9 If an instruction breaks the law

If we believe an instruction of yours infringes the GDPR, the ZZLP or another data protection law, we tell you at once and we may pause that instruction until it is clarified.

For one instruction we have a technical means and not only a promise: we can place a legal hold on a single membership, and while it is in place your Remove from roster refuses for that member and tells your officer to write to us. We use it while a request or a complaint about that member is open, so that a record we may have to correct, export or answer for is not deleted while we are still working on it. It is ours and it is not the hold you can place on a member's card yourself under Annex A.5, point 7 of the business terms; it does not stop that card working and it does not tell the member anything. It touches nothing else: you can still edit that member's status, level, validity and attendance, you can still put the card on hold and lift it again, and the member can still delete their own Stampomat account. We tell you when we set a legal hold and we lift it as soon as the matter is closed.

3.10 If we decide purposes ourselves

Where we determine the purposes and means of processing, we are a controller for that processing and Part 2 or the Privacy Policy applies, not Part 1.


Part 2. What we decide together

4. Joint controllership

4.1 Loyalty and membership wallet data

A loyalty programme is designed by us and run by you. We decide how stamps, points, rewards, vouchers, passes and anti-fraud checks work; you decide to run the programme, what it rewards, and what happens at your counter. For the following data we are therefore joint controllers:

4.2 Sites order data

We design the checkout, decide how long order data is kept, expose orders to our own administration tools and link orders to a customer's loyalty wallet. You sell the food, accept or decline the order, prepare it and hand it over. We are therefore joint controllers for:

You are the trader and the customer's contractual partner for the sale. We are not a party to the sale.

4.3 What is not joint

We alone control: your account and your staff's accounts, security events and logs, our cookieless analytics and funnel counts, Google Wallet pass objects, our own administration tooling, and our own marketing. The Privacy Policy describes each.

You alone control: every copy of customer data you take outside the platform (exports, screenshots, printouts, your mailbox), and anything you do with customer data in your shop that does not run through Stampomat.

5. Who does what

This is the responsibility matrix required by GDPR Article 26(1) and ZZLP Article 30. Its essence is published in the Privacy Policy.

A customer may exercise every right against either of us, whatever this matrix says. Whoever receives the request passes it to the responsible party and both of us cooperate so that the customer gets one complete answer.

6. Rules both of us follow

6.1 Purpose limitation

You use customer data from the platform only to run your loyalty programme, your membership programme or your pickup ordering on Stampomat. You do not sell it, pass it to a third party, or use it for anything unrelated. If you want to contact customers outside Stampomat, for example from your own mailing tool, you need your own legal basis for that; an export from Stampomat is not consent and does not carry one.

We use the joint data to run the platform, to keep it secure, to answer customers and to produce aggregate counts. We do not use it for our own marketing to customers without their consent.

6.2 Your copies

Every export, screenshot, printout and email you receive from the platform is a copy under your sole control. You keep each copy within your business, share it only with staff who need it, protect it against loss and disclosure, and delete it when the purpose is served. Order and contact emails may stay in your mailbox for as long as you need them to fulfil and account for the order, and no longer than the window for order data in the Privacy Policy retention table unless a tax or accounting law obliges you to keep them. When your account ends you delete every copy within the window in section 11.

The dashboard reminds you of these duties above each export button.

6.3 Customer notes

A note about a customer is content you write, and it is part of the joint data at your shop; we store it and answer for the platform side. Keep it factual and limited to what you need for the programme. Do not record health, religion, ethnicity, political opinion, sexual orientation, criminal matters or other sensitive details. Customers can ask for a copy of the notes about them and we will give it, and they can ask for a note to be deleted.

6.4 Marketing to customers

Broadcast emails are yours: you write them, we send them in your name with a working unsubscribe link in every message and we exclude everyone who opted out. We also exclude members you enrolled from a roster who have never signed in, because they have not been given the opportunity to object. Each send is logged with its basis and time.

The platform offers no way for a partner to write to your members.

You do not run draws, random rewards or other chance-based promotions through the platform. The Terms of Service for Businesses explain why.

6.5 Lawful basis and transparency

For the joint data, the legal basis is the contract each customer has with us and with you, and, for anti-fraud flags and engagement bookkeeping, our legitimate interest in running a fair programme. You do not add a purpose the Privacy Policy does not describe. If you want a new purpose, tell us and we will assess it together and update the policy before it starts.

6.6 What a breach notice contains

A breach notice between us states: what happened and when we became aware of it; the categories and approximate number of customers and records affected; the likely consequences; what has been done and what is proposed; and a contact for follow-up. If we do not have everything within 48 hours we send what we have and complete it as we learn more.

6.7 Cooperation with authorities

Each of us helps the other with any inquiry from a supervisory authority about the joint data, promptly and in good faith, and neither makes a commitment to an authority on the other's behalf.

6.8 Organisations and partners

If you are an organisation, you are the controller for your roster, attendance, levels, leaderboards and membership status, and we are your processor under Part 1. Once a member signs in, the wallet account is joint under Part 2. You may put a membership you created on hold and lift it again, and you may end it; removing a member from your roster is that ending carried out in full. You may not delete a member's Stampomat account, and we will not execute an instruction to do so, because the account is the person's own relationship with us and with every other business they hold a card at. You are responsible for the partners you name: you name a partner only under a written agreement with it, and you tell your members which partners you have named.

If you are a partner, you receive from the platform only whether a presented membership is valid for the benefit, the name of the benefit, and the counts and times of redemptions. You never receive a member's name, email address or member number. What you learn at the door is under your own control. You accept the Partner Terms for Benefit Providers by pressing Accept on the page your invitation letter opens, we record that acceptance, and this section applies to you in the same way.


Part 3. Sub-processors

7. Sub-processors and recipients

7.1 General authorisation and the list

You authorise us to use the sub-processors listed on the sub-processors page, for the purpose and with the transfer mechanism shown there. The page is rendered from the same configuration as the Privacy Policy, so there is one list. The list at this version:

We have a written contract with each sub-processor that imposes on it the same data protection duties that Part 1 imposes on us. We remain responsible to you for the sub-processor's work.

7.2 Changes

Before a new or replacement sub-processor starts processing your data, or an existing one takes on a new purpose, we email you at least 15 days in advance and update the page. If you have a reasonable data protection ground, you may object in writing within 30 days of our notice. We then look for a solution with you. If none is found, you may end the affected part of the service under the Terms of Service for Businesses without penalty, and we delete or return the data under section 11. Removing a sub-processor is announced on the page and in the changelog without a waiting period.

7.3 Sub-processors that act only on a switched-on feature

One sub-processor acts only when the feature is switched on:

7.4 Recipients that are not sub-processors

The following receive personal data but are not our sub-processors, because they act for their own purposes or at the customer's request: Google for sign-in with a Google account; Google Maps, which loads on your site only after a visitor clicks to load the map and is told that this sends the visitor's IP address to Google; the browser push services that deliver notifications a person opted in to; the mail provider you chose to receive order and contact emails; and your customers' own browsers and devices. The Privacy Policy names each.

Where our own administration of the platform uses an AI assistant, the assistant's provider is listed on the sub-processors page. The assistant sees masked order rows by default; full customer details and notes require a token with a specific ability, and every such read is logged.

7.5 International transfers

Our servers are in the United States with InterServer, Inc., and traffic to a hostname that is routed through Cloudflare, Inc. passes through its edge network. For data of people in the European Union, the transfer relies on the EU-US Data Privacy Framework where the recipient is certified and otherwise on the European Commission's standard contractual clauses; the sub-processors page states which applies to each recipient and the date we last verified it. For data of people in North Macedonia, transfers to the European Union and to NATO member countries are outside the transfer chapter of the ZZLP but must be notified to the Agency for Personal Data Protection; we file that notification for the platform's transfers. You may ask us at hello@stampomat.com for a copy of the safeguards.


Part 4. Security measures

8. Technical and organisational measures

This section describes what the platform does. Where a sentence says "will", the code enforces it.

8.1 Transport

Every request is redirected to HTTPS before the application runs, and in production every secure response carries a Strict-Transport-Security header for one year. Responses carry no-sniff, same-origin framing, strict referrer and frame-ancestors headers. Only proxy addresses we explicitly configure are trusted to state the visitor's address, so the client address we record is the visitor's own, not the proxy's.

8.2 Sign-in and credentials

Customers, your staff, partners and we ourselves sign in with Google using the minimal scopes (identity, name, email). The sign-in flow is stateful and checks that Google has verified the email address before linking an account. The only password on the loyalty platform is your cashier password, and it is stored as a bcrypt hash; our own administration console has no password sign-in. Sign-in cookies are encrypted and flagged HttpOnly, SameSite and, in production, Secure.

Tokens that grant access without a person present are stored as SHA-256 hashes and shown in plaintext only once: the tokens our Sites product uses to talk to the loyalty API, the tokens of trusted cashier devices, and the tokens our administration tooling uses, which expire after 90 days and carry named abilities. A trusted cashier device stops working the moment you change the cashier password or revoke it from your dashboard. A merchant portal session expires after 30 days at most and you can sign out every device at once.

8.3 Access control and roles

Your loyalty dashboard distinguishes the account holder, admin users, management users and operator users. The account holder and admin users can do everything in your programme. Management users, offered at a membership organisation only, can do everything the account holder can do except rename or act on the account holder. Operator users reach only the attendance routes on an allow-list. A read-only role we no longer offer is refused every write; an account that still carries it can look but not change anything. Team removals take effect immediately, because a team session is revalidated on every request. Exports of customer data are limited to the account holder and admin users, and each export writes an audit row. Management users cannot reach one: the role is offered only at a membership organisation, where these exports do not exist. The security card is not shown to read-only accounts.

Your Sites merchant portal is invitation-only. A merchant user sees only the sites the user is attached to, and our own administration console is limited to an allow-list of our accounts. Orders are read-only for our administration tooling; accepting and declining stay with your staff.

8.4 Separation between businesses

One shop never sees another shop's customers, and a customer's activity at one shop is not shown to another. Every dashboard query is scoped to your account. The customer-facing kiosk shows no personal data. The staff monitor shows the names of today's visitors and, only if you switch it on, their email addresses.

8.5 Audit trails and logs

Our administration console writes an immutable audit trail of administrative actions, with credentials redacted at any depth, and it records our AI assistant as a distinct actor. Security events (failed sign-ins, suspicious stamping, lockouts) are kept for 90 days and then deleted. Audit trail entries are kept for 24 months and are redacted when a person is erased. On Sites, every change made through our API and every order status transition is logged with the actor, and reads of customer details through the API are logged as well. Application log lines carry identifiers, not names or email addresses, and log files are deleted after 14 days.

8.6 Files and photos

Files meant to stay private are stored outside the public web root and served only through access-checked or expiring links; logos, avatars and site images are public by design. Images uploaded to Sites are re-encoded on upload, which drops their metadata, and are deleted when the item or block that used them is removed.

8.7 Backups

The database is backed up nightly. Each backup is compressed, readable only by our hosting account, and deleted after 14 days. Where a backup encryption key is configured, each backup is encrypted with a data key that is itself wrapped with a public key whose private half is kept off the server, and a checksum is stored beside it. Erased data leaves the backups when the last backup that held it is deleted, which is the outer limit of every erasure.

8.8 Retention enforcement

Every retention window in the Privacy Policy is enforced by a scheduled job that reads the same configuration the policy renders, and a test fails when the two disagree. Order data on Sites is pseudonymised 90 days after the order reached a final status: the name is replaced, and the phone number, email address, notes, status link and loyalty reference are blanked, while totals, items and timestamps remain for your statistics. An account a customer asks us to delete is removed within 30 days.

8.9 Abuse prevention

Every web form is protected against cross-site request forgery; the only exceptions are the cookieless analytics beacon and the one-click unsubscribe that mail clients post, neither of which is a form. Public forms on Sites carry honeypots and rate limits, and the loyalty API, the dashboard exports and the sign-in routes are rate limited. Push endpoints are checked against an allow-list of known push services before we send to them. Device cooldowns and manual-code lockouts limit stamp fraud at your counter, and a person can always ask us to review an automatic hold.

8.10 Organisational measures

Deploys are pull-based from a read-only key, configuration is cached so secrets are not read from disk at request time, no production data is used in tests, and dependencies are scanned for known vulnerabilities in continuous integration. We keep a vendor register with the contract and transfer evidence for every sub-processor, a record of processing, a breach runbook with the authorities' filing channels, and a data subject request runbook, and we review them yearly.

8.11 What we do not claim

We do not claim an uptime figure, a certification, or perfect security. We do not encrypt individual database columns. Where a measure above depends on a configuration switch, the Privacy Policy says whether it is on.


Part 5. Assistance, audits and the end of the service

9. How we help you

  1. Rights requests. We answer customers' requests as contact point under section 5. For data you control under Part 1, we find, export, correct and delete on your instruction within ten working days, or faster where the customer's deadline requires it. Customers can also export and delete their own account in the app, and the Privacy Policy's deletion page explains how.
  2. Security. On request we explain the measures in Part 4 and give you our current record of processing.
  3. Breaches. We give you the notice in section 6.6 and the facts you need for your own notification, and we cooperate in containing the breach.
  4. Impact assessments and prior consultation. We give you the description of the processing, the risks we have identified and the measures in place, so that you can complete your own assessment or consultation.
  5. Cost. This help is free where it takes reasonable effort. For work beyond that, for example a bespoke audit or a large bulk export, we may charge our then-current hourly rate after telling you in advance.

10. Audits and information

You may ask us, once in any twelve months, to demonstrate compliance with Part 1. We answer first in writing with a completed questionnaire, our record of processing, our vendor register and the results of our own tests. If that does not satisfy a reasonable concern, you or an independent auditor you appoint, bound by confidentiality and not a competitor of ours, may audit the processing on 30 days' written notice, during business hours, remotely where possible, without disrupting the service and at your cost. Audit findings are confidential between us. A supervisory authority may audit at any time, and we cooperate with it.

11. When the service ends

  1. Export first. You may ask for an export of your programme data or your site data at any time while your account is active and up to 30 days after it ends. We deliver it within 30 days of the request in a common machine-readable format.
  2. Then deletion. We delete the data you control under Part 1 and the joint data at your shop within 90 days after the end of the service, unless you asked for an export that we have not yet delivered, in which case the window runs from delivery. For a Sites site this covers the site, its domains, pages, menu, images, orders, contact submissions, newsletter sign-ups and staff attachments, and the detachment of any custom hostname from our edge network. For a loyalty account this covers your card, customers' stamps, points, rewards, feedback, notes and memberships at your shop, your team accounts, your trusted devices and your fiscal devices, and expires any Google Wallet pass issued for your programme.
  3. What customers keep. Customer accounts belong to the customers and survive your departure. A customer keeps the wallet; your card stops working in it and the customer's history at your shop is deleted with your account, as the Terms of Service for Customers explain.
  4. What remains. We keep: the record that you accepted these terms, with your identifier removed and the content hash retained, as evidence that the contract existed; audit trail entries for 24 months, redacted; security events for 90 days; invoices and accounting records for as long as tax law requires; and backups until they roll off after 14 days.
  5. Your copies. You delete every export and every copy of customer data in your systems within the same 90 days, unless a law obliges you to keep it, and you confirm the deletion to us in writing if we ask.
  6. Legal holds. If a law of the European Union, Slovenia or North Macedonia requires us to keep specific data longer, we keep only that data, only for that reason, and only for as long as the law requires.

Part 6. Liability, precedence and versions

12. Liability

Each of us is liable for the damage it causes by breaching these terms or the data protection laws that apply to its role. The liability cap, the carve-outs and the exclusion of consequential loss in the Terms of Service for Businesses apply to claims under these terms, with the carve-outs for data protection breaches, intent and gross negligence that the Terms state. Between us, a claim by a data subject or a fine is borne by the party whose breach caused it; where both contributed, in proportion to responsibility; and a party that has paid a data subject in full may recover the other party's share. Nothing in this section limits a data subject's right to claim full compensation from either of us.

13. Precedence and form

  1. These terms prevail over the Terms of Service for Businesses on any question of personal data.
  2. On request, we sign with you the standard contractual clauses for processors adopted by the Agency for Personal Data Protection of North Macedonia (Official Gazette 280/21) or those adopted by the European Commission (Implementing Decision (EU) 2021/915). Once signed, those clauses prevail over Part 1 in case of conflict, and these terms fill in what they leave open.
  3. The Privacy Policy is information for data subjects, not a contract between us; where it describes the platform in more detail than these terms, that description is accurate on its effective date.
  4. If a provision of these terms is invalid, the rest stands and the invalid provision is replaced by the valid rule closest to its purpose.

14. Changes and versions

The version and effective date at the top identify these terms. Every published version is listed on the document versions page.

We change these terms only by direct notice to you, never by publication alone. For a material change we email you at least 30 days before it applies; for any other change at least 15 days; and longer where you need time to adapt your systems. A change never applies to the past. If you do not agree, you may end the service before the change applies. You do not need to accept a new version anywhere, and the dashboard and the portal do not ask you to: if you keep using the service after the notice period, the new version applies. The acceptance page you see before first use never blocks the legal pages, sign-out or the deletion routes.

Changes to the sub-processor list follow section 7.2, not this section.

15. Language, law and contact

These terms are published in English, Macedonian and Slovenian. A German-language business sees the English text with a notice that no German version exists. The English version prevails between us.

These terms are governed by the law of the Republic of Slovenia, and the courts of Ljubljana have jurisdiction, as the Terms of Service for Businesses provide. Mandatory data protection law of the country where a customer lives applies to that customer regardless.

Questions about these terms: hello@stampomat.com.