Data Processing Agreement
This Data Processing Agreement ("DPA") supplements the Terms of Service between you (the "Customer") and Advanced PrecisionMed Solutions Limited, trading as Loonine ("Loonine", "we"). The DPA governs the processing of personal data by Loonine on your behalf. It applies automatically and without separate signature to any Customer subject to GDPR, the Swiss Federal Data Protection Act, Brazil's LGPD, or any other data protection law that requires a written processor contract.
A signed PDF copy of this DPA is available on request from support@loonine.com. EU Standard Contractual Clauses for international transfers are incorporated by reference into Section 9.
1. Definitions
"Applicable Data Protection Law" means GDPR (Regulation (EU) 2016/679), the Swiss Federal Data Protection Act, Brazil's LGPD (Law 13.709/2018), the UAE Personal Data Protection Law (Federal Decree-Law 45/2021), the California CCPA/CPRA, and any other data protection or privacy law that applies to Customer's processing of personal data.
"Personal Data", "Controller", "Processor", "Sub-processor", "Processing", "Data Subject" have the meanings given in GDPR.
"Customer Personal Data" means personal data that Customer (acting as Controller) submits to or causes to be processed through the Loonine Service, including end-customer phone numbers, names, optional emails, stamp/points/visit history, and rewards.
"Service" means the Loonine platform as defined in the Terms of Service.
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses adopted by the European Commission in Decision 2021/914 of 4 June 2021, Module 3 (processor to processor), as available at eur-lex.europa.eu.
2. Roles of the Parties
For Customer Personal Data processed through the Service:
• Customer is the Controller. Customer determines the purposes and means of processing and is responsible for the legal basis of collection (including consent, where required).
• Loonine is the Processor. Loonine processes Customer Personal Data only on Customer's documented instructions, as set out in the Terms of Service, this DPA, and configuration choices Customer makes within the Service.
For Loonine's own business administration of Customer's account (billing, support, security monitoring, account management), Loonine is the independent Controller. That processing is governed by the Privacy Policy, not by this DPA.
3. Scope, Subject Matter, Duration, and Categories of Processing
Subject matter of the processing: Provision of the Loonine Service to Customer.
Duration: The processing continues for as long as Customer's Loonine account is active, plus the deletion period set out in Section 11.
Nature and purpose of the processing:
• Storing Customer Personal Data submitted via the Service
• Recording stamp / points / visit events on Customer's instruction
• Generating loyalty cards and Apple Wallet passes
• Sending one-time SMS welcome messages to end customers (on Customer's documented instruction and confirmation of consent)
• Issuing reward redemption tokens
• Authenticating Customer and Customer's staff
• Producing aggregated analytics for Customer's own dashboard
Types of personal data processed:
• End-customer name
• End-customer phone number (E.164)
• End-customer email (optional)
• Stamp / points / visit timestamps and counts
• Reward redemption history
• Apple Wallet device push tokens (where the customer has added the pass to Wallet)
• Staff member name, username, hashed password, login timestamps
• Business identifiers and configuration
Categories of data subjects: end customers of Customer's loyalty program; Customer's own staff members.
4. Customer's Instructions
Loonine processes Customer Personal Data only:
• To provide and maintain the Service in accordance with the Terms of Service
• As further documented in this DPA
• Pursuant to additional written instructions from Customer that Loonine has accepted in writing (subject to a reasonable charge for instructions outside the standard Service)
• As required by applicable law, in which case Loonine will inform Customer in advance unless prohibited by law
If Loonine believes a Customer instruction violates Applicable Data Protection Law, Loonine will inform Customer without undue delay and may suspend the relevant processing pending Customer's response.
5. Confidentiality
Loonine ensures that personnel authorised to process Customer Personal Data are bound by written confidentiality obligations of indefinite duration. Loonine restricts access to Customer Personal Data to personnel who need access to perform their duties.
6. Security Measures (Article 32 GDPR)
Loonine implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
Encryption in transit: All data between the Customer's iOS or Android app and the Loonine API is encrypted using TLS 1.2 or higher. Both apps implement SSL certificate pinning (EC P-256 SPKI SHA-256) to defend against MITM attacks.
Encryption at rest and password hashing: Passwords are hashed using bcrypt with per-password salts. Loonine cannot recover plain-text passwords. Apple Wallet authentication tokens are randomly generated per customer card.
Access control: Multi-tenant isolation enforced at the database query level. Production systems restricted to authorised operators on need-to-know basis. JWT access tokens with refresh-token rotation.
Resilience and brute-force protection: Rate limiting on authentication endpoints. Account lockout after 5 failed login attempts within a 15-minute window. Per-business push-notification rate limits.
Monitoring and audit: Tamper-evident audit log of authentication events, account changes, and security-sensitive operations. Server-side errors forwarded to a vetted error monitoring provider with PII stripped.
Backup and recovery: Encrypted database backups on a 30-day rolling cycle.
Loonine reviews and updates these measures regularly. Customer may request a description of current measures at any time by writing to support@loonine.com.
7. Sub-processors
Customer authorises Loonine to engage Sub-processors to provide the Service. Loonine's current Sub-processors are listed at https://loonine.com/subprocessors.
Loonine ensures that each Sub-processor is bound by written contractual terms providing the same data protection obligations as those set out in this DPA, and in particular providing sufficient guarantees to implement appropriate technical and organisational measures meeting GDPR Article 28(3) requirements.
Loonine remains liable to Customer for the acts and omissions of its Sub-processors as if they were Loonine's own.
Notice of changes: Loonine will publish any new Sub-processor on the Sub-processor page at least 30 days before the new Sub-processor begins processing Customer Personal Data. Customer may object to the new Sub-processor during the 30-day notice window by writing to support@loonine.com with a reasoned objection. If Loonine cannot accommodate Customer's objection, Customer may terminate the affected portion of the Service without penalty.
8. Data Subject Requests and Cooperation
Customer is responsible for responding to data subject rights requests (access, rectification, erasure, restriction, portability, objection, withdrawal of consent) directly. Loonine provides functionality within the Service to assist Customer with these requests, including the ability to view, edit, export, and delete customer records.
If a data subject contacts Loonine directly with a rights request, Loonine will refer them to Customer without acting on the request, except where Loonine is legally required to act.
Loonine will assist Customer, taking into account the nature of the processing and the information available to Loonine, in fulfilling Customer's obligations under Articles 32-36 GDPR (security, breach notification, impact assessments, prior consultation).
9. International Transfers
Loonine processes Customer Personal Data on infrastructure located primarily in the United States. Sub-processors are located in the United States, Lebanon, and at the edge in EU member states (see Sub-processor list).
Where Customer Personal Data originating in the EU/EEA or Switzerland is transferred to a country without an adequacy decision, the parties agree to be bound by the following transfer mechanisms:
EU/EEA → third country: The EU Standard Contractual Clauses (Decision 2021/914), Module 3 (processor to processor), are hereby incorporated by reference and form part of this DPA. The optional clauses are completed as follows: Clause 7 (docking clause) - applicable; Clause 9 (sub-processors) - Option 2 (general written authorisation, 30-day notice as set out in Section 7); Clause 11 (redress) - independent dispute resolution body - not applicable; Clause 17 (governing law) - Ireland; Clause 18 (forum) - courts of Ireland.
Swiss → third country: The SCCs apply, modified as required by Swiss law (references to "GDPR" include the Swiss FADP; the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority for Swiss-only data flows).
A copy of the executed SCCs and the relevant Transfer Impact Assessment can be requested at support@loonine.com.
10. Personal Data Breach Notification
Loonine notifies Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data, and in any event within 72 hours. The notification will include, to the extent known at the time:
• Description of the breach, including categories and approximate number of data subjects and records affected
• Likely consequences
• Measures taken or proposed to address the breach and mitigate its effects
• Contact point for further information
Loonine will provide updates as further information becomes available. Loonine is not responsible for notifying data subjects directly; that obligation, where it arises, falls on Customer as Controller (GDPR Article 34).
11. Deletion and Return of Customer Personal Data
On termination of the Service, Customer may export Customer Personal Data via the iOS app (customer list export). Customer must complete any export before the effective date of termination.
After the effective date of termination - or earlier if Customer deletes their account from within the iOS app - Loonine deletes all Customer Personal Data from primary databases immediately. Backups containing Customer Personal Data are overwritten on the rolling 30-day backup cycle. Loonine confirms deletion in writing on request.
Limited records (audit logs, billing records, anonymised aggregate metrics) may be retained as required by Applicable Data Protection Law or for the limited purposes set out in the Privacy Policy.
12. Audit Rights
Customer (or an independent third-party auditor selected by Customer and reasonably acceptable to Loonine, bound by appropriate confidentiality obligations) may audit Loonine's compliance with this DPA, no more than once per calendar year, on at least 30 days' written notice, during normal business hours, in a manner that does not unreasonably disrupt the Service. Loonine may charge a reasonable fee for the resources required for an audit beyond the routine documentation Loonine makes available.
To minimise the need for on-site audits, Loonine makes available on request: descriptions of security measures, the latest summary of any independent third-party security assessment, and copies of executed SCCs.
13. Liability
Each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service. Notwithstanding any other provision, nothing in this DPA limits or excludes:
• Liability for direct damages arising from a party's breach of its obligations under this DPA where mandatory law prohibits such limitation
• Each party's joint and several liability under Article 82 GDPR vis-à-vis a data subject - Loonine remains directly liable to data subjects to the extent provided by GDPR
• Liability for fraud, gross negligence (faute lourde), or willful misconduct (dol)
14. Order of Precedence
If there is a conflict between this DPA, the Terms of Service, and the Standard Contractual Clauses, the order of precedence is:
1. The Standard Contractual Clauses (where they apply)
2. This DPA
3. The Terms of Service
15. Term and Changes
This DPA enters into force when Customer accepts the Terms of Service or starts using the Service, whichever is earlier. It continues in force for the duration of the Service plus the deletion and audit periods.
Loonine may update this DPA where required by Applicable Data Protection Law or where amendments do not materially reduce Customer's rights. Material changes (other than those required by law) will be notified at least 30 days in advance via email and via the in-app notification system.
16. Contact
For matters relating to this DPA, including SCC documentation, audit cooperation, or breach notification:
Advanced PrecisionMed Solutions Limited, trading as Loonine
Aspect Tower, Zone B, Suite 1206, Executive Tower
P.O. Box 118212, Dubai, United Arab Emirates
Email: support@loonine.com