Data Processing Agreement
Last updated: 1 June 2026 · Version: 2026-06-01
This Data Processing Agreement ("DPA") forms part of the Gast Terms of Service and governs the processing of personal data carried out by Gast (BetterVue, Oliver Birringer, Sobieskigasse 25/24, 1090 Vienna, Austria; "Processor") on behalf of the registered business ("Controller") in connection with the Gast platform. By accepting the Terms of Service, the Controller also accepts this DPA.
1. Subject and duration
The Processor processes personal data on behalf of the Controller for the purpose of providing the Gast platform (wallet-based loyalty programmes for hospitality and retail businesses). This DPA applies for as long as the Controller uses the Gast platform.
2. Nature and purpose of processing
- Operating digital loyalty programmes (stamp cards and points cards)
- Issuing and updating wallet passes (Apple Wallet, Google Wallet)
- Recording loyalty scans (stamps, points, redemptions)
- Sending transactional and — with guest consent — promotional push notifications
- Providing the Controller with statistics and administration tools
- Fulfilling data subject rights (export, deletion) on behalf of the Controller
3. Categories of data subjects
- Guests of the Controller who enrol in a loyalty programme
- The Controller's staff who use the scanner or administration interface
4. Categories of personal data
- Guests: pass identifier, wallet platform, optional first name, optional email, consent flags and timestamps, loyalty balance, scan history (time, location, staff), wallet device identifiers and push tokens.
- Staff: email, name, role, location assignment, scan activity, audit log entries.
5. Obligations of the Controller
The Controller:
- determines the purposes and means of processing within the scope of the Gast platform;
- obtains all required consents from guests (Art. 6, 7 GDPR), in particular for marketing push notifications and any future location/geofencing features;
- informs guests about data processing in accordance with Art. 13 GDPR (own privacy notice or reference to Gast's privacy policy);
- is responsible for the lawfulness of any data uploaded to the Gast platform (logos, hero images, campaign content);
- responds to data subject requests addressed directly to the Controller within the legal deadlines;
- notifies the Processor without undue delay of any data protection issues that affect processing by the Processor.
6. Obligations of the Processor
The Processor:
- processes personal data only on documented instructions from the Controller (acceptance of these Terms and use of the platform constitute such instructions for the agreed scope);
- ensures that persons authorised to process personal data are bound by confidentiality;
- implements appropriate technical and organisational measures (Art. 32 GDPR) — see § 11 and Annex I;
- assists the Controller, taking into account the nature of processing, in fulfilling obligations to respond to data subject requests (Art. 12-22 GDPR) — including the GDPR request form, the in-pass data download / deletion links, and the export and deletion workers described in the Gast documentation;
- assists the Controller in ensuring compliance with Art. 32-36 GDPR (security, breach notification, impact assessments, prior consultation);
- at the choice of the Controller, deletes or returns all personal data after the end of the provision of services (see § 14);
- makes available to the Controller all information necessary to demonstrate compliance with Art. 28 GDPR.
7. Sub-processors
The Controller grants the Processor a general authorisation to engage sub-processors. The current list of sub-processors is published in the privacy policy. The Processor will inform the Controller of any intended changes (addition or replacement of sub-processors) at least 30 days in advance. The Controller may object within 14 days for important reasons related to data protection; in that case the parties will look for a solution in good faith, failing which the Controller may terminate this DPA and the underlying contract.
The Processor concludes a contract with each sub-processor that imposes data protection obligations equivalent to those in this DPA, in particular sufficient guarantees regarding appropriate technical and organisational measures under Art. 28(3) and Art. 32 GDPR.
8. Transfers to third countries
Primary processing takes place in the European Union (Google Cloud Platform region europe-west3, Frankfurt). Some sub-processors (Apple, Google, Firebase) may process data in the United States or other third countries. Such transfers are based on adequacy decisions where available (EU-US Data Privacy Framework), and otherwise on the EU Standard Contractual Clauses (Module 3 — Processor to Sub-processor) together with appropriate supplementary measures.
9. Data subject rights
The Processor supports the Controller in responding to requests from data subjects exercising their rights under Chapter III GDPR. In particular, the Processor:
- provides a public GDPR request form at mygast.com/en/gdpr-request;
- includes in-pass "Download my data" and "Delete my data" links on every wallet pass;
- processes confirmed export requests by generating a signed-URL data archive within the legal deadline (Art. 12(3): 30 days, extendable by two months for complex requests);
- processes confirmed deletion requests by removing or anonymising all linked personal data, voiding the wallet pass, and notifying Apple/Google to remove the pass from the device;
- forwards requests that require the Controller's involvement (e.g. context-specific questions, complaints) to the responsible Controller.
10. Personal data breach
The Processor notifies the Controller without undue delay, and in any event within 24 hours of becoming aware, of any personal data breach affecting the Controller's data. The notification contains the information required by Art. 33(3) GDPR to the extent known. The Processor assists the Controller in fulfilling its notification obligations to the supervisory authority and to affected data subjects.
11. Technical and organisational measures (Art. 32 GDPR)
The Processor implements at least the following measures (current state — may be updated provided the level of protection is not reduced):
- Confidentiality: role-based access controls; multi-factor authentication via Firebase for staff with elevated privileges; encryption in transit (TLS 1.2+); encryption at rest for the production database (GCP Cloud SQL default encryption); separation of production and development environments.
- Integrity: code review for all production changes; audit logs for administrative actions; database backups with point-in-time recovery (GCP Cloud SQL).
- Availability: regular backups; managed cloud infrastructure (Cloud Run, Cloud SQL) with documented redundancy; basic monitoring and alerting.
- Resilience: stateless application services that can be redeployed automatically; immutable container images.
- Procedures: documented incident response procedure; periodic review of access rights; secrets stored in GCP Secret Manager, not in source code; subprocessors selected on the basis of documented compliance.
- Data minimisation: only first name and optional email are collected from guests; no payment data is processed; no sensitive categories of data within the meaning of Art. 9 GDPR are processed by default.
An updated technical and organisational measures statement is available on request.
12. Records of processing
The Processor maintains records of processing activities carried out on behalf of the Controller in accordance with Art. 30(2) GDPR. The records are made available to the Controller and, on request, to supervisory authorities.
13. Audit rights
The Controller is entitled to verify the Processor's compliance with this DPA, either by way of written documentation, by inspection in coordination with the Processor (no more than once per calendar year, except in case of suspected breach), or via third-party audit reports (e.g. ISO 27001 if available). Audit costs are borne by the Controller unless the audit reveals material non-compliance by the Processor.
14. Deletion or return of data
On termination of the contract, the Processor — at the Controller's choice — returns or deletes all personal data processed on behalf of the Controller, unless EU or Member State law requires storage. By default, the Processor deletes data within 90 days of contract end. Wallet passes already issued to guests are voided and removed from devices on next update; the Controller is responsible for informing its guests of the end of the loyalty programme.
15. Liability
Liability under this DPA is governed by the liability provisions of the underlying Terms of Service. Liability under Art. 82 GDPR towards data subjects is not affected.
16. Term and termination
This DPA applies for as long as the Processor processes personal data on behalf of the Controller. It ends automatically when the underlying contract ends. Provisions that are intended to survive termination (in particular § 14) remain in force.
17. Choice of law and jurisdiction
Austrian law applies, excluding the UN Convention on Contracts for the International Sale of Goods (CISG) and conflict-of-law rules. The exclusive place of jurisdiction is — to the extent permitted by law — the Commercial Court of Vienna (Handelsgericht Wien).
18. Final provisions
In case of conflict between this DPA and the Terms of Service or any other agreement between the parties, this DPA prevails for matters of data protection. If individual provisions of this DPA are invalid, the validity of the remaining provisions is unaffected.
For data protection questions: privacy@mygast.com.