Data Processing Agreement

Version 2026-07-13 · Effective July 13, 2026

This Data Processing Agreement ("DPA") forms part of the Merchant Terms of Service between VS Studios AB ("mira", "we", "processor") and the business identified as the merchant account holder ("Merchant", "controller") governing the processing of personal data of the Merchant's end customers ("Data Subjects") through the mira loyalty platform (the "Service"). It reflects the requirements of Article 28 of Regulation (EU) 2016/679 ("GDPR").

1. Subject matter and duration

  • Subject matter. Processing of end-customer personal data as strictly necessary to provide the Service.
  • Duration. For as long as the Merchant maintains an active mira account and for the retention periods described in §9.

2. Nature and purpose of processing

Collection, storage, structuring, retrieval, transmission (to the Merchant and, where the Data Subject requests it, to third-party wallets) and deletion of personal data for the purposes of: issuing and stamping loyalty cards, issuing rewards, providing the Merchant with aggregated analytics, and complying with legal obligations.

3. Categories of Data Subjects

Individuals who scan a Merchant's mira QR code, collect stamps, or claim rewards, whether signed in or using a device-only card.

4. Categories of personal data

  • Identifiers. Device token, loyalty-card public code, and — when the Data Subject signs in — email address, display name, avatar URL, and auth-provider identifier.
  • Loyalty activity. Timestamped stamp events, reward issuances, redemptions, and per-scan location samples where geo-blocking is enabled.
  • Communications. Reward-email tokens and delivery status.
  • Consent records. Cookie preferences and marketing-opt-in state.

We do not process special categories of data (Art. 9 GDPR) or payment-card data (payments are handled by our subprocessor Paddle).

5. Merchant obligations

The Merchant:

  • Warrants a lawful basis for the processing it instructs (Art. 6 GDPR), typically the performance of the loyalty contract with the Data Subject.
  • Provides the Data Subject with any required privacy notice at the point of collection (e.g. next to the QR code).
  • Obtains marketing-communication consent separately before instructing us to send promotional email.
  • Confirms it has authority to bind its business to this DPA.

6. mira obligations

We:

  • Process personal data only on the Merchant's documented instructions, which include configuration in the dashboard and the ordinary use of the Service.
  • Ensure persons authorised to process data are bound by confidentiality.
  • Implement the technical and organisational measures set out in §8.
  • Assist the Merchant, taking into account the nature of processing, to respond to Data Subject requests and to fulfil obligations under Art. 32–36 GDPR.

7. Subprocessors

  • We use the subprocessors listed at https://miraloyalty.com/subprocessors.
  • The Merchant grants general authorisation for these subprocessors.
  • We give at least 14 days' notice by email to the Merchant's account owner before adding or replacing a subprocessor. The Merchant may object in that period by writing to privacy@miraloyalty.com; if we cannot accommodate the objection, either party may terminate the affected part of the Service.

8. Security

Encryption in transit (TLS 1.2+) and at rest, row-level security in the backend database, principle-of-least-privilege access for staff, MFA on administrative accounts, quarterly vendor review, and logging of consent-relevant events.

9. Personal-data breach

We notify the Merchant without undue delay and in any case within 72 hours of becoming aware of a personal-data breach affecting the Merchant's Data Subjects, with the information required by Art. 33(3) GDPR to the extent then known.

10. Data-subject rights

We provide dashboard and API tooling for the Merchant to fulfil access, rectification, erasure, restriction, portability and objection requests. Where a Data Subject contacts mira directly, we forward the request to the Merchant and assist as reasonably requested.

11. Audit

Once per calendar year and on reasonable notice, the Merchant may audit our compliance with this DPA, either through written questionnaire or through an independent auditor bound by confidentiality. We may satisfy audit requests by providing then-current third-party attestations of our subprocessors.

12. International transfers

Where personal data is transferred outside the EEA/UK/Switzerland, we rely on the European Commission's Standard Contractual Clauses (2021/914) and equivalent UK IDTA/Swiss addenda as applicable, and carry out transfer-impact assessments for each subprocessor.

13. Retention and deletion

  • Loyalty activity is retained for the life of the loyalty card plus 24 months to support fraud investigation and dispute resolution.
  • On termination of the Merchant's account, we delete or return all personal data within 90 days, save where retention is required by law.

14. Liability

Liability under this DPA is governed by the limits set out in the Merchant Terms of Service.

15. Governing law

This DPA is governed by the laws of Sweden, without prejudice to mandatory Data Subject rights under the GDPR.

16. Contact

Data protection contact: privacy@miraloyalty.com.