hndrdfold
My receiptsLog inBook demo
Log inBook demo

Data Processing Agreement

Version 1.0 · 28 September 2026

In short

  • Your venue is the controller of its guests’ data. Hndrdfold is your processor and acts only on your instructions.
  • Data is stored and processed in the EU, in Frankfurt. We never sell it or use it for our own marketing.
  • We tell you about a breach within 48 hours, and about a new sub-processor 30 days before it starts.
  • When you leave, your data is deleted from live systems within 30 days and from backups within 90.

Get your copy

Fill in your venue’s details and download the agreement as a PDF, ready to sign. Send the signed copy to hello@hndrdfold.com and we return it countersigned. If your pilot or order agreement already refers to this version, it binds us both without a separate signature.

Blank fields print as lines to fill in by hand. What you type goes into the PDF and is not stored.

This Data Processing Agreement ("DPA") is between Hndrdfold, a Danish sole proprietorship (enkeltmandsvirksomhed), CVR 46479262, Amagerbrogade 131, 2300 København S, Denmark ("Hndrdfold", the processor), and the business named as the customer in the order, pilot agreement or signed copy of this DPA ("the Venue", the controller).

It sets out how Hndrdfold processes personal data on the Venue's behalf, as Article 28 of the GDPR requires. Hndrdfold's contact for this DPA, instructions and privacy matters is hello@hndrdfold.com.

1. Scope and acceptance

1.1 This DPA forms part of the agreement under which Hndrdfold provides its digital receipt, loyalty and guest analytics services to the Venue, including any pilot (the "Service Agreement"). It applies to personal data Hndrdfold processes on the Venue's behalf ("Venue Personal Data"). The annexes are part of it.

1.2 This DPA binds the parties when the Venue signs it, or signs a Service Agreement that refers to this version. The person accepting must be authorised to bind the Venue. Processing of Venue Personal Data does not begin before then. Visiting this page is not acceptance.

1.3 Each party keeps a copy of the version it accepted. A later version published on this page does not change an agreement already made.

1.4 On matters concerning Venue Personal Data, this DPA prevails over the Service Agreement. Mandatory data protection law prevails over both.

2. Roles and definitions

2.1 "Data Protection Law" means Regulation (EU) 2016/679 (the "GDPR"), the Danish Data Protection Act (databeskyttelsesloven) and other EU or Danish rules on personal data that apply to the processing. Personal data, processing, controller, processor, data subject and personal data breach have their GDPR meanings.

2.2 The Venue is the controller: it decides why and how its guests' data is processed within the Service. Hndrdfold is its processor. Each party remains responsible for its own obligations under Data Protection Law.

2.3 A "Sub-processor" is a third party Hndrdfold engages to process Venue Personal Data. A "Business Day" is Monday to Friday, except Danish public holidays. Other periods are calendar days.

2.4 Pseudonymous data, including device identifiers, hashed signals, pass identifiers and linked purchase histories, is personal data under this DPA whenever a person can be singled out.

3. Instructions

3.1 Hndrdfold processes Venue Personal Data only on the Venue's documented instructions, including on transfers outside the EU/EEA. The instructions are this DPA, the Service Agreement, the features and settings the Venue enables in the Service, and later written instructions from a person authorised by the Venue (email is enough). Annex 1 sets their limits.

3.2 If EU or Danish law requires Hndrdfold to process the data in another way, Hndrdfold will tell the Venue first, unless that law forbids it on important grounds of public interest.

3.3 Hndrdfold will tell the Venue immediately if it believes an instruction infringes Data Protection Law, and need not carry it out until the Venue confirms or changes it.

3.4 Hndrdfold will not sell Venue Personal Data, use it for its own marketing or advertising, use it to train general-purpose AI models, or combine it with other venues' data for its own purposes.

4. The Venue's responsibilities

4.1 The Venue is responsible for having a lawful basis for the processing, for informing its guests and for obtaining consent where the law requires it. Hndrdfold provides consent screens and privacy text in the Service; the Venue remains responsible for them as controller. Accepting this DPA is not consent from any guest.

4.2 The Venue gives only lawful instructions and has the right to give Hndrdfold access to its point-of-sale data. Its point-of-sale provider is its own supplier, not Hndrdfold's Sub-processor.

4.3 The Venue manages its staff accounts, keeps its credentials safe, and tells Hndrdfold promptly about compromised access and about requests it receives that Hndrdfold must act on.

4.4 The Venue must not send special categories of data (Article 9 GDPR), criminal offence data (Article 10), full card numbers or national identification numbers through the Service. Product names on receipts can reveal sensitive facts; the Venue should keep them neutral where that matters.

5. Confidentiality and security

5.1 Only people who need access to provide the Service get it, and each is bound by a duty of confidentiality that continues after their access ends.

5.2 Hndrdfold implements and maintains the technical and organisational measures in Annex 2, as Article 32 GDPR requires, and keeps them appropriate to the risk. They include pseudonymisation and encryption; the ongoing confidentiality, integrity, availability and resilience of the systems; the ability to restore data promptly after an incident; and regular testing of their effectiveness. Hndrdfold may improve them over time but will not reduce the overall level of protection.

6. Sub-processors

6.1 The Venue gives general written authorisation for the Sub-processors listed in Annex 3, for the activities listed there.

6.2 Hndrdfold will notify the Venue by email at least 30 days before adding or replacing a Sub-processor, or materially expanding what one does or where. The notice names the provider, its activity, the data concerned, its locations and the transfer safeguard. Updating this page alone is not notice.

6.3 The Venue may object on reasonable data protection grounds within that period. The parties will look for a solution, and the new provider will not process the Venue's data while the objection is unresolved. If no solution is found, the Venue may terminate the affected Service without penalty and receive a refund of prepaid fees for the unused period.

6.4 Each Sub-processor is bound by a written contract with data protection obligations equivalent to this DPA, including on security and deletion. Hndrdfold reviews each Sub-processor's safeguards before engaging it and at least once a year, and remains fully liable to the Venue for its Sub-processors.

7. Transfers outside the EU/EEA

7.1 Venue Personal Data is stored and processed in the EU, in Frankfurt, Germany. Some Sub-processors in Annex 3 are established outside the EU/EEA and may process or access data from there, for example to deliver email or provide support.

7.2 Hndrdfold transfers Venue Personal Data outside the EU/EEA only as Chapter V GDPR allows: to a recipient covered by an EU adequacy decision, including the EU-U.S. Data Privacy Framework where the recipient is certified, or under the European Commission's Standard Contractual Clauses with any supplementary measures needed. Annex 3 names the safeguard for each provider.

7.3 If a safeguard stops being valid, Hndrdfold will tell the Venue and suspend the affected transfer until lawful protection is restored.

7.4 If a public authority requests Venue Personal Data, Hndrdfold will check that the request is legally binding, disclose no more than required, and tell the Venue unless the law forbids it.

8. Assistance

8.1 Hndrdfold helps the Venue respond to guests exercising their rights: access, rectification, erasure, restriction, portability and objection. Guests can withdraw their permissions in the Service themselves and can ask Hndrdfold directly to erase their data; the Venue authorises Hndrdfold to carry out those withdrawals and erasure requests and to tell the Venue when it has.

8.2 Hndrdfold forwards other requests about the Venue's data to the Venue within two Business Days and does not answer them itself unless the Venue asks it to.

8.3 With the information available to it, Hndrdfold helps the Venue with security, breach notification, data protection impact assessments and prior consultation (Articles 32 to 36 GDPR).

8.4 Routine assistance is included in the Service. Hndrdfold may charge for exceptional work agreed in advance, but never for help needed because of its own failure, and a question of fees never delays help the law requires.

9. Personal data breaches

9.1 Hndrdfold will notify the Venue without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Venue Personal Data. It will not wait for its investigation to be complete.

9.2 The notice goes to the Venue's contact on record and gives what is known: what happened, the categories and approximate number of guests and records affected, the likely consequences, and what has been done to contain it. Further information follows as it becomes available.

9.3 The Venue decides whether to notify Datatilsynet and the guests affected. Hndrdfold helps it do so and does not notify them on the Venue's behalf unless instructed or required by law.

10. Records and audits

10.1 Hndrdfold makes available all information needed to demonstrate compliance with Article 28 GDPR and this DPA, and keeps the record of processing Article 30(2) requires.

10.2 Hndrdfold allows and contributes to audits, including inspections, by the Venue or an independent auditor it mandates who is bound by confidentiality. Written information and documentation are used first where they answer the question.

10.3 Audits are announced at least 15 Business Days ahead, take place in business hours and must not expose other venues' data or the security of the Service. Shorter notice applies after a breach, where there are concrete signs of non-compliance, or where a supervisory authority requires it.

10.4 Each party bears its own audit costs. Hndrdfold fixes confirmed shortcomings at its own cost.

11. Retention, return and deletion

11.1 Hndrdfold keeps Venue Personal Data only for the periods in Annex 1, or for less time where a guest's erasure request, the Venue's instruction or the law requires it.

11.2 When the Service ends, including at the end of a pilot, the Venue may ask within 15 days for a copy of its data, delivered securely in a common, machine-readable format. Hndrdfold then deletes Venue Personal Data from its own and its Sub-processors' active systems within 30 days after the Service ends. If the Venue makes no choice, the data is deleted without a copy.

11.3 Backup copies are kept only for disaster recovery, are never restored for ordinary use and expire on a fixed schedule. The last copy is deleted no later than 90 days after the Service ends. Annex 2 describes how backups are protected meanwhile and how deleted data is kept from returning if a backup is restored.

11.4 Hndrdfold keeps data longer only where EU or Danish law requires it, and then only that data, only for that purpose, and it tells the Venue what is kept and why.

11.5 On request, Hndrdfold confirms deletion in writing, stating separately when the data left its active systems and when the last backup copy expired.

11.6 Copies outside Hndrdfold's control are not covered: a receipt a guest downloaded, or a pass a guest saved in Google Wallet, which Google holds under its own terms (Annex 3). Hndrdfold still deletes its own copies and invalidates the passes it can.

12. Hndrdfold's own activities

12.1 Hndrdfold is a controller, not a processor, for its own business contacts, contracts, billing and administration of the Service, and for its optional market-insights product. Those activities are described in its privacy policy and are not covered by this DPA.

12.2 Hndrdfold will not move Venue Personal Data into those activities. Market insights use only records a guest has separately agreed to share with Hndrdfold.

13. Duration, changes and termination

13.1 This DPA applies for as long as Hndrdfold or its Sub-processors hold Venue Personal Data, including during return, deletion and backup expiry.

13.2 Changes need the agreement of both parties, except Sub-processor changes under section 6 and security improvements under section 5.2. Hndrdfold keeps earlier versions available on request.

13.3 If Hndrdfold cannot comply with this DPA, the Venue may suspend the affected processing and, if compliance is not restored within 30 days, terminate the affected Service.

14. Liability, law and disputes

14.1 Each party is liable for its own breaches of this DPA. A limitation of liability agreed in the Service Agreement applies to claims between the parties to the extent the law allows. Nothing in this DPA limits guests' rights under Article 82 GDPR or the powers of a supervisory authority.

14.2 This DPA is governed by Danish law. Disputes go to the Copenhagen City Court (Københavns Byret).

Annex 1. Details of the processing

Subject matter and purpose. Hndrdfold provides digital receipts and the related features the Venue enables. It reads transactions from the Venue's point-of-sale system, matches a sale to a guest's tap on the NFC marker, shows the receipt on the guest's phone and, on request, emails it. Where enabled and permitted, it runs the Venue's loyalty passport and offers, issues Google Wallet passes at the guest's request, and gives the Venue reporting on visits, repeat rate and revenue for its own guests.

Nature of the processing. Collection, matching, storage, display, transmission, analysis for the Venue's reporting, export and deletion. There is no automated decision-making with legal or similarly significant effects (Article 22 GDPR).

Duration. The term of the Service, then return and deletion under section 11.

Data subjectsPersonal dataPurpose
Guests receiving a receiptLine items, quantities, prices, VAT, totals, payment method, sale and order numbers, terminal, time of sale, the raw point-of-sale recordShow and deliver the receipt
Guests tapping the markerTime of tap, venue, terminal, device type, browser language, short-lived matching signals, receipt-access tokenMatch the sale to the guest, secure access, prevent abuse
Guests who allow visit analyticsPseudonymous device and guest identifiers, linked visits and purchases, derived measures such as visit count, spend, favourite items and visit rhythmThe Venue's reporting on its own guests
Loyalty passport membersEmail address, passport identifier, language, stamps, rewards, offers and redemptions, delivery status of requested emailsRun the passport, confirm the email address, send requested emails
Guests making privacy choicesConsent and withdrawal records, with wording version and timeRespect and evidence the choice
Guests saving a Wallet passPass identifier, venue, stamp progress and next reward; for a receipt pass, date, items and totalIssue and update the pass
Venue staffName, work email, role, venue access, sign-in and activity recordsAccess to the Service and support

Not processed: phone numbers, names of guests (unless a guest types one into an email address), card numbers, special categories of data. The loyalty passport is for adults aged 18 or over.

DataKept for at most
Receipt content, including the raw point-of-sale record90 days after it is received
Email address entered but never confirmed7 days
Matching signalsUntil the receipt is matched, unless the guest allowed visit analytics
Tap, visit and analytics records2 years (730 days); analytics links end earlier if the guest withdraws
Loyalty passport, stamps and rewardsUntil the guest deletes the passport or the Service ends (section 11)
Consent and withdrawal recordsAs long as the data they concern, then with the Venue's data when the Service ends
Email delivery records held by the email providerAs needed for delivery and troubleshooting, and no longer than 90 days
Venue staff accountsUntil access is removed or the Service ends
Server and security logs30 days
BackupsA fixed expiry; the last copy no later than 90 days after the Service ends (section 11.3)

Annex 2. Technical and organisational measures

AreaMeasures
AccessIndividual accounts; multi-factor authentication for production systems and provider consoles; least privilege; access removed when no longer needed and reviewed every quarter
Separation between venuesAccess checked on the server; database row-level security; staff see only the venues they are assigned to; guest profiles are computed from the Venue's own visits only
Receipt and account accessA receipt opens only with the guest's own access token or a signed, expiring link; a passport exists only after its email address is confirmed; verification and session tokens are stored only as hashes; repeated and abusive requests are rate-limited
EncryptionTLS for all traffic; the database is encrypted at rest; point-of-sale credentials are encrypted separately with a key kept outside the database; secrets are kept out of the browser and out of logs
MinimisationNo guest names or phone numbers; pseudonymous identifiers; matching signals are short-lived; no persistent visit history without the guest's permission; personal data kept out of logs
HostingEU hosting in Frankfurt with providers that maintain their own physical and infrastructure security
BackupsEncrypted, access-restricted and used only for disaster recovery; each copy has a fixed expiry that copying or migration does not restart; a minimal, protected record of deletions survives restoration and is reapplied before restored data becomes available; deletion covers database rows, email content and attachments, files, logs, exports, test copies and Sub-processors; completion is recorded separately for active systems and for backups; the restore-and-redelete procedure is tested at least once a year
RetentionAutomated daily deletion jobs for the periods in Annex 1; a failed job raises an alert
IncidentsService and job monitoring with alerts; a documented incident procedure able to meet section 9
DevelopmentChanges affecting access or privacy are reviewed and tested; dependencies are kept supported; testing and demonstrations use synthetic data, never production data
ReviewMeasures evaluated at least once a year and after any incident or material change

Hndrdfold does not claim ISO 27001, SOC 2 or any other certification.

Annex 3. Sub-processors and other recipients

A. Sub-processors authorised under section 6.

Provider and addressActivityLocationTransfer safeguard
Supabase Pte. Ltd, 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513Database and authentication: all Venue Personal DataEU (Frankfurt, Germany); support access may occur outside the EUStandard Contractual Clauses in Supabase's data processing agreement
Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USAApplication hosting: requests, responses and short-lived operational logsFunctions in the EU (Frankfurt); global edge networkStandard Contractual Clauses in Vercel's data processing agreement
Plus Five Five, Inc. (Resend), 2261 Market Street #5039, San Francisco, CA 94114, USASending requested receipt and confirmation emails: recipient address, message content, delivery statusUnited StatesEU-U.S. Data Privacy Framework and Standard Contractual Clauses in Resend's data processing agreement

B. Google Wallet. When a guest chooses to save a pass, Hndrdfold sends Google the pass content described in Annex 1 so Google can show it in the guest's Wallet. No name or email address is included. Google provides Wallet to the guest under its own terms and privacy policy and is responsible for that service itself; it is a recipient, not a Sub-processor. Google LLC participates in the EU-U.S. Data Privacy Framework. Pass data goes to Google only for venues that enable Wallet, and only when a guest asks.

C. The Venue's point-of-sale provider is the Venue's own supplier. Hndrdfold reads transactions from it with credentials the Venue provides and sends it no guest data.

Hndrdfold
Amagerbrogade 131
2300 København S
CVR 46479262
hello@hndrdfold.com

Product

  • Digital receipts
  • Guestbook

About

  • Support
  • Data Processing Agreement

Made with 🧡 in Denmark

PrivacyTerms
© 2026 Hndrdfold