Privacy Policy

Privacy Policy
Loyalty Engage B.V. ("Loyalty Engage", "we", "us", or"our") values the protection of personal data. We process personaldata carefully, transparently, and in accordance with the General DataProtection Regulation (GDPR) and other applicable privacy laws.

This Privacy Policyexplains what personal data we process, why we process it, how we protect it,and what rights individuals have regarding their personal data.

1. Who We Are
Loyalty Engage B.V.is a provider of a Software-as-a-Service (SaaS) platform that enablesorganizations to build and manage customer loyalty through loyalty programs,rewards, campaigns, customer segmentation, and marketing automation.

Depending on thecircumstances, Loyalty Engage acts as either:
• Data Controller for personal data that we collect ourselves, for     example through our website, contact forms, customer support, sales     activities, and invoicing.
• Data Processor for personal data processed by our customers within the Loyalty Engage Platform.

When acting as a Data Processor, we process personal data solely on behalf of our customers and inaccordance with the applicable Data Processing Agreement.

2. What Personal Data Do We Process?
Personal Data WeProcess Ourselves
When you contact usor use our services, we may process the following personal data:
Name
Company
name
Email address
Telephone number
Billing information
Communications with our support team
We use this information solely for the operation of our own business.

Personal Data Processed by Our Customers
Our customersdetermine which personal data they process within the Loyalty Engage Platform.
Depending on how theplatform is configured, the following types of personal data may be processed:
Name
Email address
Customer ID
Loyalty points
Purchase history
Preferences
Marketing preferences
Any other personal data that our customer chooses to process within the platform
Loyalty Engage doesnot determine which personal data is processed and processes such data solely on behalf of its customers.

3. Purposes of Processing
We process personaldata only for legitimate purposes.
When We Act as Data Controller
We process personal data for the following purposes:
Responding to inquiries
Providing our services
Managing customer relationships
Providing customer support
Billing and invoicing
Securing our systems
Improving our services
Complying with legal obligations

When We Act as Data Processor
Within the LoyaltyEngage Platform, we process personal data exclusively in accordance with our customers' instructions.
Examples ofprocessing purposes include:
Managing loyalty programs
Analyzing customer behavior
Personalizing offers
Sending messages
Customer segmentation
Reporting and analytics
Marketing automation
Our customersdetermine which platform features are used.

4. Legal Basis for Processing
We process personaldata only when there is a valid legal basis, including:
Performance of a contract
Consent Compliance with a legal obligation
Legitimate interests

Where Loyalty Engage acts solely as a Data Processor, personal data is processed only on the instructions of the Data Controller.

5. Sharing Personal Data
We never sell personal data.
Personal data is shared only when necessary for providing our services or when required by law. We work with carefully selected subprocessors for services including:
Cloud hosting
Network security
System monitoring
Error detection
Transactional email delivery

All subprocessors are contractually required to implement appropriate technical and organizational security measures. Where personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safe guards are in place, including the European Commission's Standard Contractual Clauses (SCCs).

6. Subprocessors
To provide ourservices, we work with several trusted subprocessors, including:
Hetzner (Hosting)
Cloudflare
Better Stack
Sentry
SendGrid
These parties processpersonal data only to the extent necessary for providing services to Loyalty Engage.
An up-to-date list ofsubprocessors is available upon request.

7. Security
Protecting personal data is a top priority for Loyalty Engage.
We implement a range of technical and organizational security measures, including:
HTTPS/TLS encryption
Encryption of stored data
Daily backups
Web Application Firewall (WAF)
DDoS protection
API authentication
Segregated customer data storage
Comprehensive logging
24/7 system monitoring
Regular security updates
Role-based access control
Confidentiality obligations for employees
Periodic reviews of our security procedures
Our infrastructure isdesigned to ensure the confidentiality, integrity, and availability of personal data.

8. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by applicable law.
When Loyalty Engage acts as a Data Processor, our customers determine the applicable retention periods. Upon termination of the agreement, personal data will be deleted in accordance with the applicable agreements and legal requirements.

9. Data Breaches
Loyalty Engage maintains procedures for detecting, investigating, and responding to security incidents.
In the event of apersonal data breach, we will:
Investigate the cause immediately
Mitigate the impact
Notify our customer without undue delay
Assist our customer in meeting any applicable legal notification obligations
Where Loyalty Engageacts solely as a Data Processor, we do not notify data subjects or supervisory authorities directly unless legally required to do so.

10. Data Subject Rights
Under the GDPR, individuals have various rights, including the right to:
Access their personal data
Rectify inaccurate data
Request deletion
Restrict processing
Data portability
Object to processing
Where personal datais processed by one of our customers within the Loyalty Engage Platform, requests should be directed to the relevant organization. Loyalty Engage will assist its customers in handling such requests where required.
Where Loyalty Engageacts as the Data Controller, requests may be submitted using the contactdetails below.

11. Cookies
Our website usesfunctional cookies and may also use analytical and marketing cookies.
Where required by law, we will obtain your consent before placing non-essential cookies on your device.

12. International Data Transfers
We aim to process personal data within the European Economic Area (EEA). Where personal data is transferred outside the EEA, we ensure an adequate level of protection inaccordance with the GDPR, for example through the use of the European ommission's Standard Contractual Clauses (SCCs).

13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The most recent version will always be published on our website.
We encourage you to review this page periodically.

14. Contact
If you have any questions about this Privacy Policy or the processing of personal data, please contact us:
Loyalty Engage B.V.
Email:
security@loyaltyengage.tech