Legal
Data Processing Addendum
Effective the date first published
This addendum forms part of, and is incorporated into, the Merchant Agreement. It governs Fidella’s processing of customer data on a Merchant’s behalf.
Between the Merchant (controller of the customer data it collects through its loyalty programme) and Kiwana Labs Limited (NZBN 9429050289325), trading as Fidella (the processor). Capitalised terms not defined here have the meaning in the Merchant Agreement.
1. Roles and scope
- The Merchant is the controller and Fidella is the processor of the customer data processed to provide the Services. For Fidella’s own platform-operation purposes (security, billing, platform improvement), Fidella acts as a controller under its Privacy Policy.
- This DPA is drafted to meet the Privacy Act 2020 (New Zealand) and the Privacy Act 1988 and Australian Privacy Principles (Australia). On data-protection matters it prevails over the Merchant Agreement.
2. Subject matter, data, and duration
- Processing covers customer data for loyalty, vouchers, wallet passes, and related support, for the term of the Merchant Agreement plus applicable retention windows.
- Data subjects: customers, and the Merchant’s staff/site admins and support contacts. Personal information: identifiers (a unique account identifier, email, profile data, country/region), loyalty activity, transaction records, wallet-pass metadata, support communications, and device/session data (with personal data scrubbed from logs where applicable).
- Sensitive information is not intentionally processed; any such data the Merchant supplies is at the Merchant’s risk and responsibility.
3. Processing instructions
- Fidella processes customer data only on the Merchant’s documented instructions (which include this DPA, the Merchant Agreement, and use of the Services’ configuration), unless required by law, in which case Fidella will inform the Merchant where lawful to do so.
- Fidella will tell the Merchant if, in its opinion, an instruction breaches applicable privacy law.
4. Fidella’s obligations
Fidella will: implement the security measures below; ensure personnel authorised to process customer data are subject to confidentiality; assist the Merchant, taking into account the nature of processing, to respond to data-subject requests and to meet its breach-notification and security obligations; and make available information reasonably necessary to demonstrate compliance with this DPA.
5. Data-subject requests
Fidella will, taking into account the nature of the processing, provide the in-app export, access, correction, and deletion tools and reasonable assistance to enable the Merchant to fulfil requests under IPP 6 & 7 (NZ) and APP 12 & 13 (Australia). Where a customer contacts Fidella directly about Merchant-controlled data, Fidella will refer them to the Merchant or assist as instructed.
6. Sub-processors
- The Merchant authorises Fidella to engage sub-processors to provide the Services. Sub-processor categories include an identity/authentication provider, a payment processor, hosting/database/storage and CDN providers, analytics and error-monitoring providers (subject to consent), and email/SMS providers.
- Fidella imposes data-protection obligations on each sub-processor substantially equivalent to this DPA and remains responsible for its sub-processors’ performance. Fidella will give the Merchant a means to learn of intended changes and a reasonable opportunity to object on reasonable data-protection grounds.
7. Security measures
Fidella maintains technical and organisational measures appropriate to the risk, including: encryption in transit; role-based access control and least-privilege; multi-tenant data separation keyed by site; rate limiting and abuse controls; audit logging; scrubbing of personal data from logs and observability; backup with masked-restore controls; and a documented incident-response process.
8. Personal-data breaches
- Fidella will notify the Merchant without undue delay after becoming aware of a breach affecting the Merchant’s customer data, with the information reasonably available (nature and scope, categories and approximate number of data subjects affected, likely consequences, and remediation steps).
- The parties acknowledge their own statutory notification duties: the Merchant’s duty to notify the Office of the Privacy Commissioner (NZ) of a notifiable privacy breach causing or likely to cause serious harm, as soon as practicable; and, for Australian data, the Notifiable Data Breaches scheme duty to notify the OAIC and affected individuals of an eligible data breach. Fidella will provide reasonable assistance to enable the Merchant to meet these duties.
9. International transfers
Where customer data is processed outside New Zealand or Australia, Fidella will apply appropriate safeguards consistent with IPP 12 (NZ) and APP 8 (Australia), and take reasonable steps so overseas recipients handle the data consistently with the applicable principles.
10. Audit, return, and precedence
- On reasonable notice, subject to confidentiality and no more than once per 12 months (except where required by a regulator or following a breach), Fidella will provide evidence of its controls to enable the Merchant to verify compliance.
- On termination or written request, Fidella will delete or return customer data, subject to lawful retention obligations (including financial/tax record-keeping).
- Liability under this DPA is subject to the limitation-of-liability provisions of the Merchant Agreement, except where the law provides otherwise. In case of conflict, this DPA prevails over the Merchant Agreement on data-protection matters.