Version 1.0 · 28 September 2026
Fill in your venue’s details and download the agreement as a PDF, ready to sign. Send the signed copy to hello@hndrdfold.com and we return it countersigned. If your pilot or order agreement already refers to this version, it binds us both without a separate signature.
This Data Processing Agreement ("DPA") is between Hndrdfold, a Danish sole proprietorship (enkeltmandsvirksomhed), CVR 46479262, Amagerbrogade 131, 2300 København S, Denmark ("Hndrdfold", the processor), and the business named as the customer in the order, pilot agreement or signed copy of this DPA ("the Venue", the controller).
It sets out how Hndrdfold processes personal data on the Venue's behalf, as Article 28 of the GDPR requires. Hndrdfold's contact for this DPA, instructions and privacy matters is hello@hndrdfold.com.
1.1 This DPA forms part of the agreement under which Hndrdfold provides its digital receipt, loyalty and guest analytics services to the Venue, including any pilot (the "Service Agreement"). It applies to personal data Hndrdfold processes on the Venue's behalf ("Venue Personal Data"). The annexes are part of it.
1.2 This DPA binds the parties when the Venue signs it, or signs a Service Agreement that refers to this version. The person accepting must be authorised to bind the Venue. Processing of Venue Personal Data does not begin before then. Visiting this page is not acceptance.
1.3 Each party keeps a copy of the version it accepted. A later version published on this page does not change an agreement already made.
1.4 On matters concerning Venue Personal Data, this DPA prevails over the Service Agreement. Mandatory data protection law prevails over both.
2.1 "Data Protection Law" means Regulation (EU) 2016/679 (the "GDPR"), the Danish Data Protection Act (databeskyttelsesloven) and other EU or Danish rules on personal data that apply to the processing. Personal data, processing, controller, processor, data subject and personal data breach have their GDPR meanings.
2.2 The Venue is the controller: it decides why and how its guests' data is processed within the Service. Hndrdfold is its processor. Each party remains responsible for its own obligations under Data Protection Law.
2.3 A "Sub-processor" is a third party Hndrdfold engages to process Venue Personal Data. A "Business Day" is Monday to Friday, except Danish public holidays. Other periods are calendar days.
2.4 Pseudonymous data, including device identifiers, hashed signals, pass identifiers and linked purchase histories, is personal data under this DPA whenever a person can be singled out.
3.1 Hndrdfold processes Venue Personal Data only on the Venue's documented instructions, including on transfers outside the EU/EEA. The instructions are this DPA, the Service Agreement, the features and settings the Venue enables in the Service, and later written instructions from a person authorised by the Venue (email is enough). Annex 1 sets their limits.
3.2 If EU or Danish law requires Hndrdfold to process the data in another way, Hndrdfold will tell the Venue first, unless that law forbids it on important grounds of public interest.
3.3 Hndrdfold will tell the Venue immediately if it believes an instruction infringes Data Protection Law, and need not carry it out until the Venue confirms or changes it.
3.4 Hndrdfold will not sell Venue Personal Data, use it for its own marketing or advertising, use it to train general-purpose AI models, or combine it with other venues' data for its own purposes.
4.1 The Venue is responsible for having a lawful basis for the processing, for informing its guests and for obtaining consent where the law requires it. Hndrdfold provides consent screens and privacy text in the Service; the Venue remains responsible for them as controller. Accepting this DPA is not consent from any guest.
4.2 The Venue gives only lawful instructions and has the right to give Hndrdfold access to its point-of-sale data. Its point-of-sale provider is its own supplier, not Hndrdfold's Sub-processor.
4.3 The Venue manages its staff accounts, keeps its credentials safe, and tells Hndrdfold promptly about compromised access and about requests it receives that Hndrdfold must act on.
4.4 The Venue must not send special categories of data (Article 9 GDPR), criminal offence data (Article 10), full card numbers or national identification numbers through the Service. Product names on receipts can reveal sensitive facts; the Venue should keep them neutral where that matters.
5.1 Only people who need access to provide the Service get it, and each is bound by a duty of confidentiality that continues after their access ends.
5.2 Hndrdfold implements and maintains the technical and organisational measures in Annex 2, as Article 32 GDPR requires, and keeps them appropriate to the risk. They include pseudonymisation and encryption; the ongoing confidentiality, integrity, availability and resilience of the systems; the ability to restore data promptly after an incident; and regular testing of their effectiveness. Hndrdfold may improve them over time but will not reduce the overall level of protection.
6.1 The Venue gives general written authorisation for the Sub-processors listed in Annex 3, for the activities listed there.
6.2 Hndrdfold will notify the Venue by email at least 30 days before adding or replacing a Sub-processor, or materially expanding what one does or where. The notice names the provider, its activity, the data concerned, its locations and the transfer safeguard. Updating this page alone is not notice.
6.3 The Venue may object on reasonable data protection grounds within that period. The parties will look for a solution, and the new provider will not process the Venue's data while the objection is unresolved. If no solution is found, the Venue may terminate the affected Service without penalty and receive a refund of prepaid fees for the unused period.
6.4 Each Sub-processor is bound by a written contract with data protection obligations equivalent to this DPA, including on security and deletion. Hndrdfold reviews each Sub-processor's safeguards before engaging it and at least once a year, and remains fully liable to the Venue for its Sub-processors.
7.1 Venue Personal Data is stored and processed in the EU, in Frankfurt, Germany. Some Sub-processors in Annex 3 are established outside the EU/EEA and may process or access data from there, for example to deliver email or provide support.
7.2 Hndrdfold transfers Venue Personal Data outside the EU/EEA only as Chapter V GDPR allows: to a recipient covered by an EU adequacy decision, including the EU-U.S. Data Privacy Framework where the recipient is certified, or under the European Commission's Standard Contractual Clauses with any supplementary measures needed. Annex 3 names the safeguard for each provider.
7.3 If a safeguard stops being valid, Hndrdfold will tell the Venue and suspend the affected transfer until lawful protection is restored.
7.4 If a public authority requests Venue Personal Data, Hndrdfold will check that the request is legally binding, disclose no more than required, and tell the Venue unless the law forbids it.
8.1 Hndrdfold helps the Venue respond to guests exercising their rights: access, rectification, erasure, restriction, portability and objection. Guests can withdraw their permissions in the Service themselves and can ask Hndrdfold directly to erase their data; the Venue authorises Hndrdfold to carry out those withdrawals and erasure requests and to tell the Venue when it has.
8.2 Hndrdfold forwards other requests about the Venue's data to the Venue within two Business Days and does not answer them itself unless the Venue asks it to.
8.3 With the information available to it, Hndrdfold helps the Venue with security, breach notification, data protection impact assessments and prior consultation (Articles 32 to 36 GDPR).
8.4 Routine assistance is included in the Service. Hndrdfold may charge for exceptional work agreed in advance, but never for help needed because of its own failure, and a question of fees never delays help the law requires.
9.1 Hndrdfold will notify the Venue without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Venue Personal Data. It will not wait for its investigation to be complete.
9.2 The notice goes to the Venue's contact on record and gives what is known: what happened, the categories and approximate number of guests and records affected, the likely consequences, and what has been done to contain it. Further information follows as it becomes available.
9.3 The Venue decides whether to notify Datatilsynet and the guests affected. Hndrdfold helps it do so and does not notify them on the Venue's behalf unless instructed or required by law.
10.1 Hndrdfold makes available all information needed to demonstrate compliance with Article 28 GDPR and this DPA, and keeps the record of processing Article 30(2) requires.
10.2 Hndrdfold allows and contributes to audits, including inspections, by the Venue or an independent auditor it mandates who is bound by confidentiality. Written information and documentation are used first where they answer the question.
10.3 Audits are announced at least 15 Business Days ahead, take place in business hours and must not expose other venues' data or the security of the Service. Shorter notice applies after a breach, where there are concrete signs of non-compliance, or where a supervisory authority requires it.
10.4 Each party bears its own audit costs. Hndrdfold fixes confirmed shortcomings at its own cost.
11.1 Hndrdfold keeps Venue Personal Data only for the periods in Annex 1, or for less time where a guest's erasure request, the Venue's instruction or the law requires it.
11.2 When the Service ends, including at the end of a pilot, the Venue may ask within 15 days for a copy of its data, delivered securely in a common, machine-readable format. Hndrdfold then deletes Venue Personal Data from its own and its Sub-processors' active systems within 30 days after the Service ends. If the Venue makes no choice, the data is deleted without a copy.
11.3 Backup copies are kept only for disaster recovery, are never restored for ordinary use and expire on a fixed schedule. The last copy is deleted no later than 90 days after the Service ends. Annex 2 describes how backups are protected meanwhile and how deleted data is kept from returning if a backup is restored.
11.4 Hndrdfold keeps data longer only where EU or Danish law requires it, and then only that data, only for that purpose, and it tells the Venue what is kept and why.
11.5 On request, Hndrdfold confirms deletion in writing, stating separately when the data left its active systems and when the last backup copy expired.
11.6 Copies outside Hndrdfold's control are not covered: a receipt a guest downloaded, or a pass a guest saved in Google Wallet, which Google holds under its own terms (Annex 3). Hndrdfold still deletes its own copies and invalidates the passes it can.
12.1 Hndrdfold is a controller, not a processor, for its own business contacts, contracts, billing and administration of the Service, and for its optional market-insights product. Those activities are described in its privacy policy and are not covered by this DPA.
12.2 Hndrdfold will not move Venue Personal Data into those activities. Market insights use only records a guest has separately agreed to share with Hndrdfold.
13.1 This DPA applies for as long as Hndrdfold or its Sub-processors hold Venue Personal Data, including during return, deletion and backup expiry.
13.2 Changes need the agreement of both parties, except Sub-processor changes under section 6 and security improvements under section 5.2. Hndrdfold keeps earlier versions available on request.
13.3 If Hndrdfold cannot comply with this DPA, the Venue may suspend the affected processing and, if compliance is not restored within 30 days, terminate the affected Service.
14.1 Each party is liable for its own breaches of this DPA. A limitation of liability agreed in the Service Agreement applies to claims between the parties to the extent the law allows. Nothing in this DPA limits guests' rights under Article 82 GDPR or the powers of a supervisory authority.
14.2 This DPA is governed by Danish law. Disputes go to the Copenhagen City Court (Københavns Byret).
Subject matter and purpose. Hndrdfold provides digital receipts and the related features the Venue enables. It reads transactions from the Venue's point-of-sale system, matches a sale to a guest's tap on the NFC marker, shows the receipt on the guest's phone and, on request, emails it. Where enabled and permitted, it runs the Venue's loyalty passport and offers, issues Google Wallet passes at the guest's request, and gives the Venue reporting on visits, repeat rate and revenue for its own guests.
Nature of the processing. Collection, matching, storage, display, transmission, analysis for the Venue's reporting, export and deletion. There is no automated decision-making with legal or similarly significant effects (Article 22 GDPR).
Duration. The term of the Service, then return and deletion under section 11.
| Data subjects | Personal data | Purpose |
|---|---|---|
| Guests receiving a receipt | Line items, quantities, prices, VAT, totals, payment method, sale and order numbers, terminal, time of sale, the raw point-of-sale record | Show and deliver the receipt |
| Guests tapping the marker | Time of tap, venue, terminal, device type, browser language, short-lived matching signals, receipt-access token | Match the sale to the guest, secure access, prevent abuse |
| Guests who allow visit analytics | Pseudonymous device and guest identifiers, linked visits and purchases, derived measures such as visit count, spend, favourite items and visit rhythm | The Venue's reporting on its own guests |
| Loyalty passport members | Email address, passport identifier, language, stamps, rewards, offers and redemptions, delivery status of requested emails | Run the passport, confirm the email address, send requested emails |
| Guests making privacy choices | Consent and withdrawal records, with wording version and time | Respect and evidence the choice |
| Guests saving a Wallet pass | Pass identifier, venue, stamp progress and next reward; for a receipt pass, date, items and total | Issue and update the pass |
| Venue staff | Name, work email, role, venue access, sign-in and activity records | Access to the Service and support |
Not processed: phone numbers, names of guests (unless a guest types one into an email address), card numbers, special categories of data. The loyalty passport is for adults aged 18 or over.
| Data | Kept for at most |
|---|---|
| Receipt content, including the raw point-of-sale record | 90 days after it is received |
| Email address entered but never confirmed | 7 days |
| Matching signals | Until the receipt is matched, unless the guest allowed visit analytics |
| Tap, visit and analytics records | 2 years (730 days); analytics links end earlier if the guest withdraws |
| Loyalty passport, stamps and rewards | Until the guest deletes the passport or the Service ends (section 11) |
| Consent and withdrawal records | As long as the data they concern, then with the Venue's data when the Service ends |
| Email delivery records held by the email provider | As needed for delivery and troubleshooting, and no longer than 90 days |
| Venue staff accounts | Until access is removed or the Service ends |
| Server and security logs | 30 days |
| Backups | A fixed expiry; the last copy no later than 90 days after the Service ends (section 11.3) |
| Area | Measures |
|---|---|
| Access | Individual accounts; multi-factor authentication for production systems and provider consoles; least privilege; access removed when no longer needed and reviewed every quarter |
| Separation between venues | Access checked on the server; database row-level security; staff see only the venues they are assigned to; guest profiles are computed from the Venue's own visits only |
| Receipt and account access | A receipt opens only with the guest's own access token or a signed, expiring link; a passport exists only after its email address is confirmed; verification and session tokens are stored only as hashes; repeated and abusive requests are rate-limited |
| Encryption | TLS for all traffic; the database is encrypted at rest; point-of-sale credentials are encrypted separately with a key kept outside the database; secrets are kept out of the browser and out of logs |
| Minimisation | No guest names or phone numbers; pseudonymous identifiers; matching signals are short-lived; no persistent visit history without the guest's permission; personal data kept out of logs |
| Hosting | EU hosting in Frankfurt with providers that maintain their own physical and infrastructure security |
| Backups | Encrypted, access-restricted and used only for disaster recovery; each copy has a fixed expiry that copying or migration does not restart; a minimal, protected record of deletions survives restoration and is reapplied before restored data becomes available; deletion covers database rows, email content and attachments, files, logs, exports, test copies and Sub-processors; completion is recorded separately for active systems and for backups; the restore-and-redelete procedure is tested at least once a year |
| Retention | Automated daily deletion jobs for the periods in Annex 1; a failed job raises an alert |
| Incidents | Service and job monitoring with alerts; a documented incident procedure able to meet section 9 |
| Development | Changes affecting access or privacy are reviewed and tested; dependencies are kept supported; testing and demonstrations use synthetic data, never production data |
| Review | Measures evaluated at least once a year and after any incident or material change |
Hndrdfold does not claim ISO 27001, SOC 2 or any other certification.
A. Sub-processors authorised under section 6.
| Provider and address | Activity | Location | Transfer safeguard |
|---|---|---|---|
| Supabase Pte. Ltd, 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513 | Database and authentication: all Venue Personal Data | EU (Frankfurt, Germany); support access may occur outside the EU | Standard Contractual Clauses in Supabase's data processing agreement |
| Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA | Application hosting: requests, responses and short-lived operational logs | Functions in the EU (Frankfurt); global edge network | Standard Contractual Clauses in Vercel's data processing agreement |
| Plus Five Five, Inc. (Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA | Sending requested receipt and confirmation emails: recipient address, message content, delivery status | United States | EU-U.S. Data Privacy Framework and Standard Contractual Clauses in Resend's data processing agreement |
B. Google Wallet. When a guest chooses to save a pass, Hndrdfold sends Google the pass content described in Annex 1 so Google can show it in the guest's Wallet. No name or email address is included. Google provides Wallet to the guest under its own terms and privacy policy and is responsible for that service itself; it is a recipient, not a Sub-processor. Google LLC participates in the EU-U.S. Data Privacy Framework. Pass data goes to Google only for venues that enable Wallet, and only when a guest asks.
C. The Venue's point-of-sale provider is the Venue's own supplier. Hndrdfold reads transactions from it with credentials the Venue provides and sends it no guest data.