1. Introduction and Scope
This Data Processing Agreement ("DPA") forms part of the Terms and Conditions between Pocket Labs Pty Ltd (ABN 93695191621, ACN 695191621, "Pocket", "Processor", "we", "us", or "our") and you ("Customer", "Controller", "you", or "your").
This DPA governs the processing of Personal Data by Pocket on behalf of Customer in connection with the provision of our wallet pass membership management platform ("Services").
This DPA applies to the extent that Pocket processes Personal Data on behalf of Customer and complies with:
- The Australian Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs)
- The European Union General Data Protection Regulation (GDPR) where applicable
- Other applicable data protection laws and regulations
2. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person that Customer submits to the Services, including customer/member names, email addresses, phone numbers, purchase history, and wallet pass usage data.
- "Data Subject" means the individual to whom Personal Data relates (e.g., Customer's members/customers).
- "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, transfer, or deletion.
- "Controller" means the entity that determines the purposes and means of Processing Personal Data (i.e., Customer).
- "Processor" means the entity that processes Personal Data on behalf of the Controller (i.e., Pocket).
- "Sub-processor" means any third party engaged by Pocket to process Personal Data on behalf of Customer.
- "Data Protection Laws" means all applicable laws and regulations relating to privacy and data protection, including GDPR and the Australian Privacy Act.
3. Roles and Responsibilities
3.1 Controller Responsibilities
Customer, as Controller, is responsible for:
- Determining the purposes and means of Processing Personal Data
- Ensuring compliance with Data Protection Laws in their collection and use of Personal Data
- Obtaining all necessary consents and providing required notices to Data Subjects
- Ensuring the accuracy and lawfulness of Personal Data provided to Pocket
- Responding to Data Subject requests and inquiries
- Instructing Pocket on the Processing of Personal Data
3.2 Processor Responsibilities
Pocket, as Processor, agrees to:
- Process Personal Data only on documented instructions from Customer
- Implement appropriate technical and organizational security measures
- Maintain confidentiality of Personal Data
- Assist Customer in responding to Data Subject requests
- Assist Customer in ensuring compliance with Data Protection Laws
- Delete or return Personal Data upon termination of Services
- Make available all information necessary to demonstrate compliance with this DPA
4. Processing Details
4.1 Nature and Purpose of Processing
Pocket processes Personal Data for the purpose of providing the Services, which include:
- Creating and managing digital wallet passes (Apple Wallet and Google Wallet)
- Storing and managing customer/member information
- Delivering push notifications to wallet pass holders
- Processing rewards, credits, and tier-based benefits
- Integrating with Customer's POS systems and e-commerce platforms
- Providing analytics and reporting on member engagement
- Facilitating communication between Customer and their members
4.2 Types of Personal Data
Personal Data processed may include:
- Identity data: Name, email address, phone number
- Membership data: Member ID, tier status, join date
- Transaction data: Purchase history, rewards balance, points/credit earned
- Technical data: Wallet pass installation status, device type, push notification delivery status
- Location data: Approximate location (if geo-push features are used)
- Engagement data: Wallet pass opens, notification interactions, member activity
4.3 Categories of Data Subjects
- Customer's members/membership program participants
- Customer's customers and end-users
- Recipients of wallet passes
4.4 Duration of Processing
Personal Data will be processed for the duration of the Services agreement and for up to 90 days following termination, unless otherwise instructed by Customer or required by law.
5. Customer Instructions
Pocket will process Personal Data only in accordance with Customer's documented instructions, which include:
- The Terms and Conditions and this DPA
- Instructions provided through the Services dashboard and API
- Written instructions provided via email to support@getpocketpass.com
If Pocket believes an instruction violates Data Protection Laws, Pocket will immediately inform Customer. Pocket may suspend execution of the instruction until Customer confirms or modifies it.
6. Security Measures
6.1 Technical and Organizational Measures
Pocket implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption: Personal Data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Access Controls: Role-based access control (RBAC) and multi-factor authentication (MFA)
- Network Security: Firewalls, intrusion detection, and DDoS protection
- Data Segregation: Logical separation of Customer data in multi-tenant environment
- Monitoring: 24/7 security monitoring and logging
- Incident Response: Security incident response procedures and breach notification protocols
- Employee Training: Regular security and privacy training for personnel
- Background Checks: Pre-employment screening for personnel with access to Personal Data
6.2 Data Breach Notification
In the event of a Personal Data breach, Pocket will:
- Notify Customer without undue delay and in any event within 72 hours of becoming aware of the breach
- Provide details of the nature of the breach, affected Data Subjects, and potential consequences
- Describe measures taken or proposed to address the breach and mitigate its effects
- Cooperate with Customer in investigating and remediating the breach
- Assist Customer in meeting regulatory notification obligations
7. Sub-processors
7.1 Authorization
Customer authorizes Pocket to engage Sub-processors to process Personal Data, subject to the conditions in this Section 7.
7.2 Current Sub-processors
Pocket currently uses the following Sub-processors:
| Sub-processor | Service | Location |
|---|---|---|
| Supabase Inc. | Database hosting and authentication | United States (AWS) |
| Stripe, Inc. | Payment processing | United States |
| Apple Inc. | Apple Wallet pass delivery | United States |
| Google LLC | Google Wallet pass delivery | United States |
| Vercel Inc. | Application hosting | United States |
7.3 New Sub-processors
Pocket will provide at least 30 days' notice before engaging a new Sub-processor. Customer may object to the use of a new Sub-processor on reasonable grounds relating to data protection by notifying Pocket within 14 days of receiving notice.
7.4 Sub-processor Obligations
Pocket will ensure that Sub-processors are bound by written agreements imposing data protection obligations no less protective than those in this DPA. Pocket remains liable for Sub-processors' compliance with this DPA.
8. Data Subject Rights
Pocket will assist Customer in fulfilling Data Subject requests, including:
- Access: Provide access to Personal Data held about the Data Subject
- Rectification: Correct inaccurate or incomplete Personal Data
- Erasure: Delete Personal Data ("right to be forgotten")
- Restriction: Restrict processing of Personal Data
- Portability: Export Personal Data in a structured, machine-readable format
- Objection: Object to processing of Personal Data
Upon Customer's request, Pocket will provide reasonable assistance to enable Customer to respond to Data Subject requests within applicable timeframes. Customer is responsible for responding to Data Subjects.
9. International Data Transfers
9.1 Transfer Mechanisms
Personal Data may be transferred to and processed in countries outside Australia and the European Economic Area (EEA). Pocket ensures appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions by the European Commission
- Binding Corporate Rules where applicable
- Other lawful transfer mechanisms under Data Protection Laws
9.2 Standard Contractual Clauses
For transfers subject to GDPR, the parties agree to be bound by the EU Standard Contractual Clauses (Module 2: Controller to Processor), incorporated by reference into this DPA.
10. Data Retention and Deletion
10.1 Retention
Pocket will retain Personal Data for as long as necessary to provide the Services or as instructed by Customer, unless a longer retention period is required or permitted by law.
10.2 Deletion Upon Termination
Upon termination or expiration of the Services:
- Pocket will provide Customer with 90 days to export their Personal Data
- After 90 days (or upon Customer's written request), Pocket will delete or anonymize all Personal Data
- Pocket may retain Personal Data as required by applicable law, provided it remains subject to confidentiality obligations
- Upon Customer's request, Pocket will certify in writing that Personal Data has been deleted
11. Audits and Compliance
11.1 Audit Rights
Upon reasonable written notice and no more than once per year, Customer may:
- Request documentation demonstrating Pocket's compliance with this DPA
- Conduct audits or inspections of Pocket's data processing activities
- Engage a qualified third-party auditor to conduct audits on Customer's behalf
Audits must be conducted during business hours, with minimal disruption to Pocket's operations, and subject to confidentiality obligations.
11.2 Certifications
Pocket maintains relevant security certifications and compliance programs. Upon request, Pocket will provide Customer with copies of applicable certifications and audit reports.
12. Liability and Indemnification
12.1 Liability
Each party's liability under this DPA is subject to the limitations and exclusions set forth in the Terms and Conditions, except where prohibited by applicable Data Protection Laws.
12.2 Indemnification
Customer will indemnify and hold Pocket harmless from claims, fines, or penalties arising from Customer's failure to comply with Data Protection Laws or Customer's instructions that violate Data Protection Laws.
13. Term and Termination
This DPA takes effect on the date Customer first uses the Services and remains in effect until termination of the Services agreement. The obligations in this DPA will survive termination to the extent necessary to ensure proper deletion or return of Personal Data.
14. Modifications
Pocket may update this DPA to reflect changes in Data Protection Laws or our data processing practices. We will notify Customer of material changes at least 30 days in advance. Continued use of the Services after changes constitutes acceptance of the updated DPA.
15. Governing Law and Jurisdiction
This DPA is governed by the laws of New South Wales, Australia. Any disputes arising from this DPA will be subject to the exclusive jurisdiction of the courts of New South Wales, except where Data Protection Laws require otherwise.
16. Contact Information
For questions regarding this DPA or data processing matters:
Pocket Labs Pty Ltd
ABN: 93695191621
ACN: 695191621
Data Protection Officer
Address: 1/84 View St, Gymea, Sydney, NSW 2227, Australia
Email: privacy@getpocketpass.com
DPA Requests: dpa@getpocketpass.com