- § 1
Subject matter, parties and order of precedence
This agreement governs how we process personal data that we process on your behalf (Art. 28 GDPR).
You are the controller: the business that issues the stamp card to its guests. We are the processor: Printproof UG (haftungsbeschränkt), Beim Schlump 15, 20144 Hamburg, Germany, registered in the commercial register of the local court of Hamburg under HRB 199187, represented by its managing director Dennis Achtziger. Contact for anything arising from this agreement: support@treubar.de. Treubar was previously called "Treuly"; the renaming changes neither the parties nor the content of this agreement, and instructions or notifications sent to the previous address support@treuly.de continue to reach us.
Under § 10 of the Terms of Service, this agreement becomes part of the contract for the use of Treubar when that contract is concluded. The version published at https://www.treubar.de/en/dpa — in German at https://www.treubar.de/avv — at the time the contract is concluded is the one that applies; on request to support@treubar.de we provide it to you in text form.
If this agreement and the Terms of Service conflict, this agreement prevails for the processing of personal data.
Not covered by this agreement is the data for which we are the controller ourselves: your account, contract and billing data, and any order for an NFC display stand. Our privacy policy at https://www.treubar.de/en/privacy applies to that.
- § 2
Duration
This agreement starts with the contract for the use of Treubar and ends with it. No separate termination is needed, and none is possible.
The obligations of confidentiality (§ 6) and of erasure or return (§ 12) survive the end of the contract.
- § 3
Nature and purpose of the processing, types of data, categories of data subjects
The nature and purpose of the processing, the types of personal data processed and the categories of data subjects are set out in Annex 1.
We process this data solely in order to run Treubar for you — not for our own purposes. We do not build advertising profiles of our own from your guests’ data, we do not pass it to third parties other than the sub-processors listed in Annex 3, and we do not sell it.
- § 4
Your rights and obligations as controller
You decide on the purposes and means of the processing and are responsible for its lawfulness. You may request information about the processing at any time, issue instructions (§ 5) and verify compliance with this agreement (§ 13).
In particular, it is for you to: inform your guests under Art. 13 and 14 GDPR; obtain and evidence any necessary consents — including for push messages and campaigns under § 7 UWG (German Act against Unfair Competition); define the participation terms of your loyalty programme (§ 9 of the Terms of Service); answer requests from your guests (§ 10); and maintain your own record of processing activities under Art. 30 (1) GDPR.
You alone decide what data you enter into Treubar. That applies in particular to free-text fields such as the note on a guest: whatever is written there, we process without reviewing it. Special categories of personal data under Art. 9 GDPR — health data, for example — do not belong in Treubar; the application is neither intended nor set up for them.
Give us a point of contact for matters arising from this agreement. Unless you name one separately, that is the email address stored in your Treubar account. Keep it current — a notification under § 11 goes to it as well.
- § 5
Processing on documented instructions
We process your guests’ data only on your documented instructions. This also applies to any transfer to a third country (§ 9). It is otherwise only the case where we are required to process by Union or German law; in that event we inform you of the legal requirement before processing, unless the law prohibits that.
Your first instruction is the feature set of the plan you booked, together with the settings you make in Treubar: the design of the card, the reward, your locations, your team’s access, the campaigns and automations you trigger, and the use of an NFC display stand. What you set there, you thereby instruct.
Further or differing instructions are given in text form to support@treubar.de. We document them. Where an instruction goes beyond the scope of service owed under the contract, we may charge the reasonable additional effort; we tell you before that effort arises.
If we consider an instruction to infringe data protection law, we inform you without undue delay. We may suspend execution until you confirm the instruction.
- § 6
Confidentiality of the persons involved
Access to your guests’ data is granted only to those who need it for their task.
Every person who works with that data on our behalf is placed under a written obligation of confidentiality before starting work, unless they are already subject to a statutory duty of secrecy (Art. 28 (3) (b) GDPR). That obligation survives the end of their work for us.
We instruct those persons in the data protection obligations that apply to them.
- § 7
Security of processing (Art. 32 GDPR)
We implement the technical and organisational measures described in Annex 2. Annex 2 describes the state as at the version date given above.
Technology ages, so we are allowed to develop these measures further. The level of protection must not fall below that of Annex 2. Any material change is recorded in a new version of this agreement.
- § 8
Sub-processors
You give us general authorisation to engage the sub-processors listed in Annex 3 (Art. 28 (2) sentence 2 GDPR).
If we intend to add a further sub-processor or replace an existing one, we announce it at least 30 days in advance in text form to the email address stored in your account. You may object to the change on data protection grounds within 14 days of receiving the announcement. If you object and the service cannot reasonably be provided without the sub-processor concerned, either party may terminate the contract with effect from the date the change takes effect; fees paid in advance are refunded pro rata for the period not provided.
We bind every sub-processor by contract to data protection obligations substantially equivalent to those in this agreement (Art. 28 (4) GDPR). Where a sub-processor fails to meet its obligations, we remain liable to you for its conduct as for our own.
Ancillary services that have no connection to your guests’ data — telecommunications, postal services or the cleaning of business premises, for example — are not sub-processing within the meaning of this section.
- § 9
Processing outside the EU
Your guests’ data is stored in the European Union (Annex 3 states the location for each sub-processor).
Two transfers go beyond that. First: if a guest saves their card in Google Wallet, we transfer their first and last name, a truncated pass identifier, the stamp balance, the card design and the text of the messages you trigger to Google. Second: if the card is in Apple Wallet, Apple receives the device identifier and a contentless notification that prompts the device to fetch the pass from us again — the name and stamp balance stay on the guest’s device.
For recipients established in the USA we base the transfer on the adequacy decision for the EU–US Data Privacy Framework where the recipient is certified under it, and otherwise on Standard Contractual Clauses under Art. 46 (2) (c) GDPR. On request to support@treubar.de we tell you, for each recipient, what the transfer is based on.
- § 10
Assistance with requests from your guests
You fulfil your guests’ rights under Art. 15 to 22 GDPR; we assist you with appropriate technical and organisational measures (Art. 28 (3) (e) GDPR).
Inside Treubar you can do the following without involving us: view the details stored about a guest together with their stamping and redemption history (access), correct those details, export them as a table (access and portability), and delete a guest entirely — with their card, their stamping and redemption history and the registered wallet devices.
Where that is not enough, we assist you on request to support@treubar.de. For requests going beyond the feature set we may charge the reasonable additional effort; we tell you beforehand.
If a guest contacts us directly, we do not answer their request on the merits. We refer them to you and inform you without undue delay.
There is one limitation you need to know about: if a guest has saved their card in Google Wallet, deleting them in Treubar does not remove the wallet object created at Google. On request to support@treubar.de we set a deleted guest’s Google Wallet object to “inactive” without undue delay, at the latest within 30 days, so that it no longer appears in their wallet; if you delete your account, this happens automatically for every pass of your business. Fully deleting the object from Google’s systems is technically impossible — Google issues immutable object IDs and provides no delete operation. An Apple Wallet pass already issued stays on the guest’s device until they remove it there; after the deletion we no longer update it.
- § 11
Assistance with security, data breaches and impact assessments
We assist you in meeting the obligations under Art. 32 to 36 GDPR — within the scope of the information available to us and taking into account the nature of the processing (Art. 28 (3) (f) GDPR).
If we become aware of a personal data breach affecting your guests’ data, we report it to you without undue delay, and at the latest within 48 hours of becoming aware, in text form to the email address stored in your account. The report contains, as far as known to us: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures we have taken or propose to take. Anything we do not know at first, we supply as soon as we do.
Notifying the supervisory authority under Art. 33 GDPR and communicating with your guests under Art. 34 GDPR are for you to do. The 72-hour period runs for you from your own awareness; that is why we report early, and also where we have not yet fully established what happened.
If you need details of our processing for a data protection impact assessment (Art. 35 GDPR) or a prior consultation with the supervisory authority (Art. 36 GDPR), we provide them on request.
- § 12
Erasure or return after the end of the contract
After the contract ends we either erase your guests’ data or return it to you — your choice. If you tell us nothing else by the end of the export window, we erase it.
How it runs: once the termination takes effect you can export your data for 30 days in a common machine-readable format (§ 7 paragraph 1 of the Terms of Service); if no export function is available to you, we provide the data within that period on request in text form. After that we erase it from the production systems within a further 30 days. If you delete your account yourself, we erase within 30 days of that deletion.
Data held in backups is overwritten as part of the ordinary backup cycle. Until then we block it from any further processing; it is restored only in an emergency, and never in order to bring erased data back.
What we are legally required to retain is reserved: where Union or German law obliges us to retain records — in particular § 147 AO (German Fiscal Code) and § 257 HGB (German Commercial Code) — we keep the records concerned for the duration of the period and otherwise block them from further processing. That concerns invoice, accounting and order data from our own contractual relationship with you, not your guests’ stamp cards.
Wallet passes already issued stay on your guests’ devices until they remove them themselves. After the end of the contract we no longer update them and no longer accept stamps.
We confirm the erasure in text form on request to support@treubar.de.
- § 13
Evidence and audits
We make available to you all information needed to demonstrate compliance with the obligations under Art. 28 GDPR (Art. 28 (3) (h) GDPR) — in particular the current version of Annexes 2 and 3, and information on them in text form.
We maintain a record of the categories of processing activities carried out on behalf of controllers (Art. 30 (2) GDPR) and make it available to you on request.
You may satisfy yourself on site that we comply with this agreement, or have an auditor appointed by you do so. An audit requires specific grounds and must be announced at least 14 days in advance; it takes place during normal business hours, must not unreasonably disrupt operations, and may take place at most once per calendar year. The auditor must not be a competitor of ours and is bound to secrecy. We may charge the reasonable effort of an on-site audit where we have told you so beforehand.
Audits that a supervisory authority is empowered to carry out remain unaffected.
- § 14
Liability, amendments and final provisions
§ 12 of the Terms of Service applies accordingly to liability, unless Art. 82 GDPR mandatorily provides otherwise.
Amendments to this agreement must be made in text form. § 7 applies to Annex 2 and § 8 to Annex 3; otherwise § 14 of the Terms of Service applies.
The law of the Federal Republic of Germany applies. The exclusive place of jurisdiction is Hamburg, provided you are a merchant, a legal entity under public law or a special fund under public law.
Should any provision of this agreement be or become invalid, the validity of the remaining provisions is unaffected.
- A1
Annex 1 — Nature and purpose of the processing, types of data, data subjects
Nature and purpose of the processing: running a digital stamp and loyalty card on your behalf. This covers: issuing wallet passes to your guests (Apple Wallet, Google Wallet); counting stamps by QR scan, by NFC display stand or by manual entry from your team; redeeming rewards; recovering a card after a device change; sending push messages and campaigns in your name; providing insights in your business dashboard; and storing and backing up that data.
Categories of data subjects: • your guests, who receive a stamp card • the staff for whom you create access to Treubar
Your guests’ data: • first name, last name and date of birth — the three mandatory fields of the card’s enrolment form • a note your team can add about a guest (free text) • an email address only for cards enrolled before 26 August 2026, while the form still asked for one; it is no longer collected for new cards • pass identifiers: the serial number of the pass and the credential with which the guest’s device identifies itself to the wallet service • stamping and redemption data: the time of each stamp, the route used (QR scan, NFC display stand, manual), the location, the member of your team who issued it, the current stamp balance, and the time and subject of each redemption • wallet device identifiers: the device identifier assigned by Apple and the push credential of each device holding the pass; for Google Wallet the identifier of the object created there • messages: the text of the message you address to an individual pass, and the time it was delivered • for the NFC display stand: a random, signed identifier of your guest’s browser (the treuly_bid cookie) and its assignment to the card on our server; the time and outcome of each tap; and, while a stamp is briefly parked, a checksum of the IP address computed with a secret key, which prevents another browser from picking up the parked stamp
Your staff’s data: name, email address, role in the business (Admin, Manager, Scanner), the credentials they sign in with, and the link to the stamps and redemptions they issued.
No special categories of personal data under Art. 9 GDPR are processed. Treubar is not intended for them (§ 4).
Duration of the processing: for the term of the contract. After that, § 12 applies.
- A2
Annex 2 — Technical and organisational measures (Art. 32 GDPR)
This annex describes the measures actually in place as at the version date. It deliberately also states what we do not promise.
Confidentiality • Sign-in: access to Treubar runs through our authentication provider (Annex 3). Passwords are stored and checked there; we never see them. Every request to our API must carry a valid, time-limited sign-in credential. • Roles: each account carries exactly one role with a fixed set of rights (Admin, Manager, Scanner). A Scanner account can stamp, redeem and view the customer list, but can neither manage accounts nor send campaigns. • Separation of businesses: every database query is scoped to your business identifier; an account belonging to another business is refused access to your data. This separation is enforced in the application — the account the application uses to reach the database bypasses the database’s own access rules. Row Level Security is additionally enabled on the tables; it takes effect for access that does not go through our application. • Pseudonymisation: we show your team only a few characters of the pass identifier, never the pass’s full credential. • Encrypted keys: the cryptographic keys of the NFC display stands are held in the database in encrypted form only (AES-128-GCM).
Integrity • Transport encryption: all connections between the app, the web application, the pages your guests see and our API run exclusively over HTTPS. • Separate file store: images and logos are held in a separate store and are served exclusively through our API; the address of the storage service is not reachable from outside. • Input control: changes to master data and security-relevant operations — including the deletion of a guest — are logged with the time and the person acting. • Abuse protection: a configurable minimum interval between two stamps per card, a lock against accidental double scans, and, for NFC display stands, verification of the chip’s signature and counter, which detects a cloned or replayed tap.
Availability • Operations: the API runs in Frankfurt am Main, the database in the EU (Annex 3). • Backups: backups of the database are created by our database provider. Backups are created and kept automatically by our database provider, Supabase; frequency and retention follow the service tier booked there. What we do NOT promise here: a contractually assured recovery time, or a documented, regularly repeated restore test. As long as neither is evidenced, we do not claim it.
Organisation • Every person with access to your guests’ data is placed under an obligation of confidentiality before starting work (§ 6). • We engage sub-processors only as set out in Annex 3 and only under contract (§ 8).
What we do not promise • We are not certified to ISO/IEC 27001 or a comparable standard, and we do not have a regular external security audit carried out. • We do not additionally encrypt individual data fields; date of birth and name are held in the database in the clear. What is encrypted is the transport and the storage at the level of our providers. • We do not owe a particular availability quota (§ 11 of the Terms of Service).
- A3
Annex 3 — Sub-processors
This list is current as at 11 September 2026. Changes are announced under § 8.
• Supabase, Inc. (established in the USA) — database and file storage. Place of processing: European Union. Scope: all data listed in Annex 1. • Render Services, Inc. (established in the USA) — operation of our API and web application. Place of processing: Frankfurt am Main, Germany. Scope: all data passing through the application, plus technical logs. • Clerk, Inc. (USA) — sign-in and management of the accounts you create for yourself and your team. Scope: the name, email address and sign-in credentials of those accounts. Clerk does not receive your guests’ data. • Apple Distribution International Ltd. (Ireland) — delivery and updating of the card in Apple Wallet. Scope: the guest’s device identifier and a contentless notification. The name and stamp balance stay on the guest’s device. • Google Ireland Limited (Ireland), with Google LLC (USA) for technical operation — saving the card in Google Wallet. Scope: the guest’s first and last name, a truncated pass identifier, the stamp balance, the card design and the text of the messages you trigger. Only if the guest saves the card in Google Wallet. • Google Ireland Limited (Ireland), “Google Fonts” service — the enrolment and display-stand pages your guests see load their font directly from a Google server. In doing so, your guest’s browser transmits its IP address and technical details about the browser and operating system to Google. • Resend, Inc. (USA) — sending emails to you and your team, such as order confirmations and status notifications for the NFC display stand. Resend does not receive your guests’ data.
Not sub-processors within the meaning of this agreement: • Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (USA) — they process our payments, are controllers in their own right for that, and receive none of your guests’ data. • the print and shipping providers for the NFC display stand — they receive your order and delivery data, for which we are the controller ourselves (§ 5 of the privacy policy). • the OpenStreetMap Foundation (United Kingdom) — the address lookup when entering a location or delivery address concerns only the address text you typed.
Third-country transfers: for the above recipients established in the USA we base the transfer on the adequacy decision for the EU–US Data Privacy Framework where the recipient is certified under it, and otherwise on Standard Contractual Clauses under Art. 46 (2) (c) GDPR (§ 9).