Last updated: 2026-10-01 · Version 2026-10-01.v5
This agreement governs how Kadoro processes personal data on your behalf, as required by Article 28 GDPR. It forms part of your contract and takes precedence over the terms and conditions wherever the two differ on personal data.
You are the controller. You decide to run a loyalty programme and decide what happens with your customers' data. Grewolls, Peer & Madeira Amorim, Joao Pedro eGbR, Voigtstraße 9, 09116 Chemnitz, Germany ("Kadoro") is the processor and acts only on your instructions.
This agreement lasts as long as your Kadoro contract. Ending that contract ends this one, subject to the deletion obligations in section 10.
Purpose: operating the loyalty programme you run, and nothing else.
| Category | Data |
|---|---|
| Loyalty card | An unguessable card serial, the points or stamps balance, lifetime totals, which shop and card programme, when the card was created and last used. |
| Customer identity (optional) | Name and email address — only where a customer chooses to give them, and only with their consent. Most cards stay anonymous. |
| Consent record | Whether privacy consent was given and when; whether marketing consent was given. |
| Wallet usage | Whether the card was added to Apple or Google Wallet, and device registrations used to update the pass. |
| Transactions | Stamps or points added and rewards redeemed, with timestamps. |
Categories of data subjects: the customers of your business who add a loyalty card.
No special categories of data (Art. 9 GDPR) are processed, and Kadoro does not process payment data of your customers at any point.
Kadoro processes personal data only on your documented instructions. Using the service as intended — issuing cards, adding stamps, redeeming rewards, viewing your dashboard — constitutes those instructions. Further instructions may be given in text form to support@kadoro.app.
Kadoro will tell you if it believes an instruction breaches data protection law, and may suspend that instruction until it is confirmed or withdrawn.
Kadoro does not sell your customers' data, does not use it to advertise, and does not use it to train machine-learning models.
Everyone at Kadoro authorised to process personal data is bound to confidentiality and instructed on their obligations. Access to production data is limited to the two founders and only for support, maintenance and fault diagnosis.
These measures may be updated as the state of the art develops; the level of protection will not be reduced.
You consent to Kadoro using the following subprocessors:
| Subprocessor | Purpose | What it receives |
|---|---|---|
| Railway (hosting and database) | Runs the application and stores its data | All data listed in section 2 |
| Vercel (frontend hosting) | Serves the web interface | Technical access data such as IP address and browser |
| Apple Inc. (Wallet / PassKit) | Delivers and updates Apple Wallet passes | Pass contents — balance, shop, serial — and device registrations. No name, no email |
| Google LLC (Google Wallet) | Delivers and updates Google Wallet passes | As above. No name, no email |
Kadoro will inform you before adding or replacing a subprocessor and you may object on reasonable data protection grounds; if the objection cannot be resolved, either party may terminate.
Our payment provider is not listed here because it processes your own billing data, not your customers'.
Apple and Google are established in the United States. Transfers to them are covered by the EU Standard Contractual Clauses and by their own certifications. The hosting region for the application and database is stated in the privacy policy.
Where a customer exercises a right — access, correction, deletion, portability — you answer them, and Kadoro supports you. The product does much of this directly: a customer can delete their own card and data from their card page, and you can delete a customer from your dashboard. If a request reaches us instead of you, we forward it rather than answering it.
Kadoro will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need for your own notification under Art. 33 GDPR. Reporting to the supervisory authority is your obligation as controller; Kadoro will support it.
When the contract ends, Kadoro deletes the personal data it processes for you within 90 days, unless it is required by law to keep it. On request before then, Kadoro provides an export.
Records that a shop must keep for accounting — the fact and amount of a transaction — may be retained in a form that no longer identifies a person.
Kadoro will provide the information you reasonably need to demonstrate compliance with Art. 28. Audits may be carried out on reasonable notice, during business hours, without disrupting operations, and no more than once a year unless there is specific cause.
Where this agreement and the terms and conditions differ on the handling of personal data, this agreement prevails. German law applies. If any provision is invalid the remainder stays in force.