Data Processing Agreement
Version 1.0 · Last updated: May 30, 2026
This Data Processing Agreement (the "DPA") is concluded under Article 28 of Regulation (EU) 2016/679 ("GDPR") and Article 28 of Italian Legislative Decree 196/2003, as amended by Legislative Decree 101/2018 (the Italian Privacy Code), between the Shop, as Controller, and radioBros, as Processor, and governs the processing of personal data of the Shop's customers in the context of the TesserApp service.
The Italian-language version of this DPA is the official version and prevails over translations in case of discrepancy.
1. Parties
1.1 Controller: the natural or legal person who registers on the TesserApp Shop platform and subscribes to the Service (hereinafter the "Shop"). The Shop's identifying details are those entered at signup and editable from the dashboard.
1.2 Processor: radioBros di Alberto Miconi, registered office at Via Ridolfino Venuti 30, 00162 Rome (Italy), Italian VAT registration pending, contact email privacy@tesserapp.eu (hereinafter "radioBros").
The Parties mutually acknowledge the roles above, without prejudice to radioBros' independent role as Controller for its own processing in the performance of the subscription (invoicing, Shop account, security logs of its own systems), which is governed by the Privacy Policy and the Terms of Service.
2. Definitions
The definitions of Article 4 GDPR apply. In addition:
- "Personal Data": any information relating to an identified or identifiable natural person within the meaning of Art. 4 no. 1 GDPR, processed by the Processor on behalf of the Controller in the context of the Service.
- "Data Subject": the Shop's customer who uses the TesserApp mobile app and activates or uses a loyalty card under the Shop's program.
- "Service": the web platform, mobile applications and infrastructure components that radioBros makes available to the Shop for the operation of its loyalty programs.
- "Sub-processor": any third party engaged by the Processor to process Personal Data, under Art. 28(4) GDPR. The list is in Appendix A.
- "Personal Data Breach": as defined in Art. 4 no. 12 GDPR.
3. Subject matter, duration, nature and purposes of the processing
3.1 The Shop, as Controller, instructs radioBros, as Processor, to process the Personal Data of Data Subjects for the purposes necessary to deliver the Service and as set out in this DPA.
3.2 Subject matter: the technical operation of the Shop's loyalty program, including activation of customer cards, recording of transactions (stamps awarded, prizes redeemed, reversals), synchronization of cards to Apple Wallet and Google Wallet, delivery of push notifications related to the loyalty program, exposure of the program in the consumer app catalogue (where the Shop has opted for public visibility), provision of location-based discovery features, and — for private programs — issuance of a personal card to a single named cardholder, delivery of an email installation invitation, and binding of the card to the cardholder's device account.
3.3 Nature of processing: automated processing carried out on the Processor's IT infrastructure and that of its authorized Sub-processors.
3.4 Purposes: performance of the contract between the Shop and its own customers in relation to the loyalty program; compliance with the Shop's legal obligations as Controller; security of information systems and prevention of fraud on stamps and prizes; and, for private programs, delivering personal cards to the specific individuals designated by the Controller and restricting each such card to the cardholder's device account.
3.5 Duration: this DPA is effective for the entire duration of the Shop's subscription to the Service. The obligations under articles 9 (Return and deletion) and 13 (Confidentiality) survive termination.
4. Categories of Data Subjects and Personal Data
4.1 Categories of Data Subjects: customers of the Shop who use the TesserApp consumer app.
4.2 Categories of Personal Data processed (Appendix B):
- anonymous device identifiers (256-bit random tokens, not linked to a person's identity);
- loyalty card identifiers (opaque UUIDs);
- transaction metadata (stamp award events, prize redemptions, reversals; date, time and location of the shop where the operation took place);
- Apple Wallet / Google Wallet pass identifiers and related push tokens;
- IP addresses, processed solely transiently in audit logs for security purposes;
- device system language;
- GPS coordinates, exclusively where the Data Subject has enabled the nearby-shops discovery feature and only for the duration of feature use;
- Data Subject email address, exclusively if voluntarily provided by the Data Subject (GDPR rights requests, support contacts).
4.2 bis — Private (personal) programs only: the cardholder's name and email address, provided by the Controller for the purpose of issuing a personal card and emailing an installation invitation; and a pseudonymous device-account binding reference (an opaque identifier derived from the cardholder's iCloud/Google account), processed solely to enforce that the private card remains on the cardholder's account. The Controller warrants that it has a lawful basis and, where required, the Data Subject's consent to provide this data; the Processor processes it only on the Controller's documented instructions.
4.3 Data NOT processed: Data Subject postal address, phone number; Data Subject payment data (the app does not process customer payments to the Shop); special categories of data under Art. 9 GDPR; data on criminal convictions under Art. 10 GDPR; data of minors under 16 (the Service is not directed to that age group). Exception: for private programs, the Data Subject's name and email are processed on the Controller's instruction (see §4.2 bis). For all standard/public programs, name and email remain not processed.
5. Obligations of the Processor
The Processor undertakes to:
5.1 process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or international organization, unless required to do so by Union or Member State law to which the Processor is subject; in such a case the Processor informs the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest;
5.2 ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
5.3 take all measures required pursuant to Art. 32 GDPR, as described in Appendix D of this DPA;
5.4 respect the conditions referred to in paragraphs 2 and 4 of Art. 28 GDPR for engaging Sub-processors, as further specified in art. 6 of this DPA;
5.5 taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the Data Subject's rights under Arts. 15-22 GDPR;
5.6 assist the Controller in ensuring compliance with the obligations pursuant to Arts. 32-36 GDPR, taking into account the nature of processing and the information available to the Processor;
5.7 at the choice of the Controller, delete or return all Personal Data after the end of the provision of services relating to processing, and delete existing copies, unless Union or Member State law requires storage of the data;
5.8 make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller;
5.9 immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.
6. Sub-processors
6.1 The Shop hereby grants the Processor general authorization to engage the Sub-processors listed in Appendix A of this DPA.
6.2 The Processor shall inform the Shop of any intended changes concerning the addition or replacement of other Sub-processors with at least 30 days' prior notice, thereby giving the Shop the opportunity to object to such changes.
6.3 In the event of the Shop's reasoned objection, the Processor shall assess alternative technical solutions. Where it is not possible to avoid the new Sub-processor, the Shop may terminate the subscription without penalty, effective from the date the new Sub-processor becomes operational.
6.4 The Processor enters into a written contract with each Sub-processor containing data protection obligations equivalent to those set out in this DPA, in particular regarding appropriate technical and organizational measures, confidentiality, assistance to the Controller and cooperation with the supervisory authority.
6.5 The Processor remains liable to the Shop for the Sub-processor's actions within the limits provided by Art. 28(4) GDPR.
7. Data Subject rights
7.1 Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the Data Subject's rights under Chapter III of the GDPR (Arts. 12-22), and in particular:
- right of access (Art. 15);
- right to rectification (Art. 16);
- right to erasure (Art. 17), operationalized through the flow described in art. 9 below and in product decision 046 (30-day soft-delete);
- right to restriction of processing (Art. 18);
- right to data portability (Art. 20);
- right to object (Art. 21);
- right not to be subject to a decision based solely on automated processing (Art. 22): the Service does not operate automated profiling with legal effects on the Data Subject.
7.2 Requests received directly by the Processor are forwarded without delay to the Controller, unless the Processor is authorized in writing by the Controller to respond directly.
7.3 The Processor makes available to the Controller technical tools accessible from the dashboard to: (a) export the data of an individual Data Subject; (b) anonymize or delete the data of an individual Data Subject; (c) suspend processing of an individual Data Subject.
8. Personal Data Breach notification
8.1 In the event of a Personal Data Breach of which the Processor becomes aware, the Processor notifies the event to the Controller without undue delay and in any case within 72 hours of becoming aware of it, providing, insofar as possible, the information referred to in Art. 33(3) GDPR and in particular:
- the nature of the breach, the categories and approximate number of Data Subjects concerned;
- the categories and approximate number of personal data records concerned;
- the contact details of the point of contact for the incident;
- the likely consequences of the breach;
- the measures taken or proposed to address it and mitigate its possible adverse effects.
8.2 Where, and to the extent that, it is not possible to provide the information at the same time, the information may be provided in phases without further undue delay.
8.3 It is understood that it is the responsibility of the Controller, under Arts. 33 and 34 GDPR, to decide whether to notify the breach to the supervisory authority and communicate it to the Data Subjects.
9. Return and deletion of Personal Data at termination
9.1 Upon termination of the subscription, and in any case within 30 days of termination, the Shop may request from the Processor the full export of the Personal Data in a structured, commonly used and machine-readable format (JSON, accessible from the dashboard or delivered via signed URL).
9.2 After the expiry of the period above without a request for export, or following completion of the export, the Processor proceeds to delete the Personal Data according to the soft-delete policy of the Service: data is first made inaccessible (30-day soft-delete), after which it is permanently deleted from production systems within 5 days.
9.3 Excluded from deletion, for the strictly necessary time, are Personal Data whose retention is required by legal obligations binding on radioBros (in particular invoice retention for 10 years under Art. 2220 of the Italian Civil Code and applicable tax law). Such data is kept in segregated custody, with restricted and audited access, and is not subject to any further processing other than performance of the obligation.
9.4 Upon written request of the Shop, the Processor issues a formal statement of deletion completed.
10. International data transfers
10.1 The Processor processes Personal Data exclusively on infrastructure located within the European Economic Area, with preference for data centres in Italy or Germany.
10.2 Some Sub-processors listed in Appendix A may have their seat or operations in the United States (in particular Stripe, Apple, Google). Transfers of Personal Data to such parties are carried out on the basis of the Standard Contractual Clauses adopted by the European Commission with Decision 2021/914/EU, supplemented by additional measures where necessary in light of CJEU judgment C-311/18 (Schrems II).
10.3 No transfers are made to third countries outside the Standard Contractual Clauses framework or an adequacy decision of the Commission.
11. Technical and organizational measures
The technical and organizational measures adopted by the Processor under Art. 32 GDPR are described in Appendix D of this DPA, which forms an integral part hereof. Such measures are subject to periodic update to reflect the state of the art; any update may not result in a reduction of the level of security guaranteed.
12. Audit
12.1 The Processor makes available to the Controller, upon written request, the information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and this DPA.
12.2 The Controller may request, once per calendar year, the performance of an audit, to be carried out upon at least 30 days' prior written notice, during business hours, at the Processor's premises, in a manner that does not interfere with the operational continuity of the Service and respects the security measures in force.
12.3 The direct costs of the audit are borne by the Controller, unless the audit reveals significant breaches of this DPA attributable to the Processor, in which case the costs are borne by the Processor.
12.4 In lieu of the on-site audit, the Processor may offer the production of independent third-party auditor reports (e.g. SOC 2, ISO 27001, where available) and equivalent documentation.
13. Confidentiality
13.1 The Parties undertake to treat as strictly confidential all information acquired in the performance of this DPA, except for information in the public domain or whose disclosure is required by law or order of the authority.
13.2 The confidentiality obligation extends to the Parties' employees, collaborators and Sub-processors and survives termination of this DPA.
14. Liability and indemnity
14.1 Each Party is liable for the damage caused by its processing which violates the GDPR, within the limits and in the manner provided by Art. 82 GDPR.
14.2 In the internal relations between the Parties, radioBros' liability to the Shop for the processing of Personal Data is governed by the limitation-of-liability clause in the Terms of Service, save for cases of wilful misconduct or gross negligence and without prejudice to liability to the Data Subject under the GDPR.
14.3 The Shop guarantees and holds radioBros harmless from any claim arising from the Shop's breach of its own obligations as Controller under the GDPR (in particular: proper information to Data Subjects under Arts. 13-14 GDPR; proper legal basis for processing; correctness of instructions issued to the Processor).
15. Duration, amendments and final provisions
15.1 Duration. This DPA is effective from the date of acceptance by the Shop at signup (through a dedicated tick-box) and for the entire duration of the subscription to the Service. The obligations of return/deletion (art. 9) and confidentiality (art. 13) survive termination.
15.2 Amendments. Material amendments to this DPA shall be communicated to the Shop with at least 30 days' prior notice by email to the address registered on the account and through a dedicated banner on the dashboard. The Shop will be required to re-accept the new version at the next login. Failure to accept entails the right to terminate the subscription without penalty.
15.3 Language. The Italian-language version of this DPA is the official version and prevails over translations in case of discrepancy.
15.4 Governing law and jurisdiction. This DPA is governed by Italian law. Any dispute is subject to the exclusive jurisdiction of the Court of Rome.
15.5 Acceptance tracking. Acceptance of the DPA is tracked by the Processor by recording: Shop legal name, email of the user who accepted, IP address, timestamp and DPA version accepted. Such data constitutes proof of acceptance under Arts. 20 and 21 of Italian Legislative Decree 82/2005 (Digital Administration Code).
Appendix A — Authorized Sub-processors
| Sub-processor | Seat | Role | Categories of data | Transfer basis |
|---|---|---|---|---|
| Stripe Payments Europe Ltd. | Ireland (group with US operations) | Processing of Shop subscription payments; invoice issuance | Shop's own payment and tax data (not Data Subject's) | SCC 2021/914/EU |
| Cloudflare, Inc. | USA (R2 storage configured in EU region) | Object storage for backups and assets; CDN for delivery of static resources | Encrypted backups; no PII in clear | SCC 2021/914/EU |
| Resend (resend.com) | EU | Sending of transactional emails | Data Subject's email address (only in the cases provided by art. 4.2 lett. h) of the DPA) | EU processing |
| Apple Inc. | USA | Delivery of Apple Wallet passes via APNs | Push tokens, pass identifiers | SCC 2021/914/EU |
| Google LLC | USA | Delivery of Google Wallet passes via FCM and Google Wallet API | Push tokens, pass identifiers | SCC 2021/914/EU |
| Contabo GmbH | Germany | VPS hosting of production systems | All Personal Data subject to the Service | EU processing |
| FontAwesome, Inc. | USA | Static icon CDN (SVGs, no tracking) | No PII | Site visitor IP addresses, processed transiently |
The updated list is available in the Shop's dashboard under "Privacy → Sub-processors".
Appendix B — Categories of data and retention periods
| Category | Retention | Legal basis |
|---|---|---|
| Loyalty card identifiers (UUIDs) | Until the Customer deletes them or until termination of the Shop's subscription, plus 30 days of soft-delete, plus deletion within 5 days | Performance of the loyalty program contract |
| Transaction metadata (stamps, prizes, reversals) | 24 months active for reconciliation and fraud prevention; afterwards archived with pseudonymized references | Legitimate interest of the Controller in program security |
| Apple/Google Wallet pass identifiers | Until removal of the pass by the Data Subject from the native wallet | Performance of the loyalty program contract |
| GPS coordinates (use of discovery feature) | Not retained beyond the session of feature use | Data Subject consent (Art. 6.1.a GDPR) |
| IP addresses in audit logs | Nulled upon permanent deletion of the Data Subject's card | Legitimate interest in security |
| Data Subject email (if provided) | 30 days from the conclusion of the proceeding for which it was provided | Performance of a Data Subject request |
| Shop subscription invoices | 10 years | Legal obligation (Art. 2220 Italian Civil Code and applicable tax law) |
Appendix C — Data Subject rights and methods of exercise
The Shop is the first recipient of GDPR rights requests from its own customers. radioBros assists the Shop by providing:
- a rights-management console integrated into the Shop's dashboard, for export and deletion of individual Data Subject data;
- the option to request directly from radioBros, at privacy@tesserapp.eu, the exercise of rights, which will be forwarded without delay to the Shop;
- an audit-trail system, accessible at any time by the Shop, recording the date of the request, the type of right exercised, the date of response and the actions taken.
Indicative response times (maximum under Art. 12 GDPR): 30 days from the request, extendable by a further 60 days in case of complexity, with notice to the Data Subject.
Appendix D — Technical and organizational measures (Art. 32 GDPR)
D.1 Confidentiality
- Encryption in transit via TLS 1.2 or higher on all exposed endpoints.
- Encryption at rest with AES-256 of database backups and Cloudflare R2 objects (SSE).
- Hashing of authentication tokens with argon2id algorithm, parameters compatible with OWASP guidelines.
- Hashing of Shop account passwords with argon2id; no password ever stored in plaintext.
- Segregation of environments (production, staging, development) with distinct credentials and no access to production data from non-production environments.
D.2 Integrity
- Role-based access control (RBAC) on production infrastructure.
- Audit log of every administrative operation, kept in append-only storage.
- Versioning of database schema migrations with a verifiable hash chain.
D.3 Availability and resilience
- Automatic daily database backups with Point-In-Time Recovery (PITR) via WAL streaming (pgBackRest).
- Documented restore drills, at least annually.
- Real-time infrastructure monitoring, with alarms on security and availability anomalies.
- Rate limiting on public endpoints, perimeter anti-DDoS via Cloudflare.
D.4 Verification procedures
- Annual external penetration test.
- Six-monthly internal review of security configurations.
- Vulnerability management with defined SLAs for remediation (critical: 7 days; high: 30 days; medium: 90 days).
D.5 Processing continuity
- Documented disaster recovery and incident management procedures.
- Substitutability of infrastructure Sub-processors within reasonable timeframes, where necessary.
D.6 Incident handling
- Internal Personal Data Breach handling procedure with a dedicated officer, activatable 24/7.
- Predefined notification chain to ensure compliance with the 72-hour deadline referred to in art. 8 of this DPA.
Contacts
- Processor: radioBros di Alberto Miconi, Via Ridolfino Venuti 30, 00162 Rome (Italy), Italian VAT registration pending.
- Email for any matter relating to this DPA: privacy@tesserapp.eu.
- Lead supervisory authority for radioBros: Italian Data Protection Authority (Garante) — gpdp.it. Shops established in other EU Member States may also contact their local supervisory authority.
Version 1.0 — adopted on May 30, 2026. Historical versions, where available, are archived in PDF format at URLs https://tesserapp.eu/legal/dpa/v{version}.pdf.