This is a translation. The German version is authoritative.
Preamble
This agreement sets out the obligations under Art. 28 GDPR between the salon as controller and Nguyen Thi Thai Chinh, To 4B Tran Nguyen Han, TP Bac Giang 26110, Vietnam as processor (the “provider”). It applies together with the terms and conditions.
The agreement is concluded electronically upon registration (Art. 28(9) GDPR). The time of consent and the version of the texts are stored with the salon.
1. Subject matter and duration
The subject matter is the processing of personal data carried out by the provider for the salon in the course of providing Lytchie Club Card.
The duration corresponds to the term of the usage contract. When that ends, this agreement ends as well.
2. Nature and purpose of the processing
The provider stores and processes club card data solely in order to run the salon’s loyalty programme: issue and display cards, count stamps, issue and redeem full cards, provide birthday gifts, keep notifications and wallet cards up to date and — where the salon uses it — ask about satisfaction, invite customers on the salon’s behalf to leave a review on Google, reward a friend referral and run a prize draw for the salon and show it live.
There is no processing for the provider’s own purposes. Anonymous counts on platform usage that allow no reference to individuals are excepted.
3. Types of personal data
- Customer master data: first name (required), date of birth (optional, entered by the customer themselves, once, on their card, only at salons on the Pro or Max plan, for the purpose of the birthday gift; the salon can correct or remove it, in which case the time of the last correction is stored), customer number, chosen language; the city is no longer collected for new cards and may only still be stored on older cards
- Loyalty programme usage data: stamps with time, the name on the stamp (with quick scan the name chosen for it) and the salon account through which the stamp was given, corrections, full cards (with an expiry date where the salon set a validity period), redemptions, birthday gifts
- Answers to the satisfaction question (rating and free text) together with the salon’s reply and a note of any invitation to leave a Google review
- Messages from the salon to the customer (broadcasts, personal messages, replies to feedback, invitations to leave a Google review, announcements of gifts, visit reminders and messages about a prize draw) with time and read status
- Gifts from the salon for individual cards: text, time of issue and of redemption and, where the salon set a validity period, the expiry date
- Referrals (“invite friends”): a short, non-secret referral code per card and which card referred a newly created card
- The salon’s prize draw: which card was drawn, with the prize and the point in the draw, together with the prize as a gift that can be redeemed for 30 days; the entries follow from the stamps in the period, and what is stored is the entry count of the drawn card if it wins and, per prize draw, the total number of participants and entries; in the live draw, winners appear on other people’s cards only with their customer number
- A note of the visit day for which a visit reminder was sent (the date only)
- Technical identifiers: card address, wallet pass identifiers, browser push subscriptions
- Data of salon staff, insofar as their names are stored as stamp tiles, and the display names of the salon’s accounts (owner account and scan phones) that appear next to an action in the history
Special categories of personal data under Art. 9 GDPR are not processed. The salon ensures that none are entered into free-text fields.
4. Categories of data subjects
- Customers of the salon who hold a club card
- Staff of the salon, insofar as they are stored in the software as a stamp tile or signed in as a scan phone
- The owner of the salon, insofar as the display name of the owner account appears in the salon’s history
5. Instructions
The provider processes the data solely within the scope of this agreement and on the documented instructions of the salon. Operating the software constitutes an instruction; further instructions are given by the salon in text form.
If the provider considers an instruction unlawful, it says so and may suspend its execution.
Where the provider is legally obliged to process data, it informs the salon beforehand unless the law prohibits this.
6. Confidentiality
The provider only engages persons who are bound to confidentiality and instructs them on their duties under the GDPR.
Access to the data of individual customers exists only where it is unavoidable for operation and troubleshooting. The provider’s platform console shows no customer rows, only totals.
7. Technical and organisational measures (Art. 32 GDPR)
The provider has taken the following measures:
- Transmission exclusively encrypted (TLS/HTTPS); the connection between application and database is encrypted as well
- Passwords and lock PINs are stored only as a scrypt hash, session tokens only as a hash — a database dump yields no usable access
- Separate roles: owner (full salon), scan phone (scan, stamp, redeem, and answer and clear customer feedback) and platform team
- Every database query is bound to the respective salon; cross-salon access is ruled out
- Access for the platform team requires a security key (WebAuthn) or a backup code in addition to the password; the session is time-limited
- Rate limits against automated attacks on login, registration, card creation, data export and deletion
- A log of every platform team intervention (who, when, which salon)
- A strict content security policy, no third-party scripts, no external fonts
- Backups by the database provider
- Deletion functions for the customer herself (“My data”, “Delete card”), for the salon and for the entire salon account
The measures are subject to technical progress. The provider may change them as long as the level of protection is not reduced.
8. Sub-processors
The salon gives general authorisation to engage the sub-processors named in the privacy policy — currently Railway (operation), Supabase (database), Resend (e-mail to salon owners), the push services of the browser makers, Stripe (payments, only with a paid subscription), OpenStreetMap/Nominatim (geocoding of the salon address) and Cloudflare (name resolution).
Where a customer adds her card to Apple Wallet or Google Wallet, the provider transmits the card contents there. In doing so Apple and Google act as controllers in their own right under their own privacy terms, not as sub-processors; the same applies to Apple where it sells a subscription through the App Store. The list of recipients in the privacy policy names further recipients that receive no card data.
The privacy policy names the sub-processors and the task each of them performs. On request the provider additionally supplies the salon with a summary stating, for each sub-processor, the country of storage, the access paths and the protective measures, so that the salon can carry out any transfer assessment its own law requires.
The provider obliges these service providers to a level of protection corresponding to this agreement.
The provider informs the salon before changing or adding a sub-processor. The salon may object for an important data protection reason; if no agreement is reached, either side may terminate the contract.
9. Transfer to a third country
The provider is based in Vietnam. The body of data is held on servers in the European Union (Amsterdam and Frankfurt am Main); for operation, maintenance and support the provider accesses it remotely from there.
For this transfer the parties hereby agree, by reference, to the standard contractual clauses of the European Commission (Implementing Decision (EU) 2021/914), Module 2 (transfer controller to processor). The salon is the data exporter, the provider the data importer.
The details of the annexes to the standard contractual clauses follow from this agreement:
- Annex I.A (parties): the salon as controller and the provider named above as processor
- Annex I.B (description of the transfer): sections 2 to 4 — nature and purpose, types of personal data, categories of data subjects; the transfer takes place on a continuous basis for the term of the contract
- Annex I.C (competent supervisory authority): the authority competent for the salon as data exporter
- Annex II (technical and organisational measures): section 7
- Annex III (sub-processors): section 8
The options of the clauses apply as follows: the docking clause (clause 7) applies; for sub-processors the general written authorisation under clause 9(a) option 2 applies with 30 days’ prior notice; the law of the Federal Republic of Germany governs the clauses, and the courts of the Federal Republic of Germany have jurisdiction.
Where the standard contractual clauses contradict this agreement, the standard contractual clauses prevail.
As controller, the salon carries out the assessment required for the lawfulness of the transfer; the information the provider supplies for that purpose is set out in section 9a.
9a. The law of the provider’s country and requests from public authorities
This section gives the salon the information it needs for the assessment required by clause 14 of the standard contractual clauses agreed in section 9, and it describes how the provider handles requests from public authorities. It sets out the legal position as the provider understands it; it is not legal advice, and the assessment itself remains the salon’s.
Where the data is and who can reach it: the full body of data is held on servers in the European Union — the application in Amsterdam, the database in Frankfurt am Main; those two systems are run by two of the sub-processors named in section 8. Where a customer allows notifications in her browser, individual card details additionally reach the push service named for that purpose in section 8; where she adds her card to Apple Wallet or Google Wallet, the card contents reach Apple or Google, which under section 8 act as controllers in their own right in doing so. No copy of the database is kept in Vietnam. Those systems are not subject to the jurisdiction of the provider’s country — an authority of that country cannot reach them directly; it would have to order the provider personally to retrieve the data.
Access is remote access over an encrypted connection only and is limited to those persons of the provider who are bound to confidentiality under section 6. Data that has to be downloaded in order to investigate a fault is deleted once the fault is fixed, and the provider holds no separate copy outside those systems.
Which law applies to the provider: the provider is established in Vietnam and is therefore subject to Vietnamese law, in particular the Law on Personal Data Protection (Law No. 91/2025/QH15) with its implementing Decree No. 356/2025/ND-CP, both in force since 1 January 2026, and the Law on Cybersecurity (Law No. 116/2025/QH15, in force since 1 July 2026). Vietnamese law allows public authorities, above all the Ministry of Public Security, to require data from persons subject to Vietnamese law. Data protection is supervised by that Ministry and not by an independent authority of the kind the GDPR provides for; the remedies open to data subjects in Vietnam are not the same as those in the Union.
Storage in Vietnam: Vietnamese cybersecurity law requires certain providers to keep data in Vietnam. That duty is tied to services offered in cyberspace in Vietnam and to the data of users in Vietnam. Where the salon does not direct its club cards at users in Vietnam, the duty does not apply on the provider’s reading, and no copy of the data is kept in Vietnam. Should that change, the last paragraph of this section applies.
Requests from public authorities (clause 15 of the standard contractual clauses): the provider notifies the salon of any legally binding request without undue delay and tells it which data is affected. Where notification is prohibited, the provider uses all reasonable efforts to obtain a waiver of the prohibition and documents those efforts. The provider reviews the lawfulness of every request, challenges and appeals against requests it considers unlawful, and discloses the minimum amount of data permissible. The provider keeps a record of the requests it receives and makes it available to the salon on request. Nothing in this agreement limits clauses 14 and 15 of the standard contractual clauses.
Circumstances relevant to the assessment: the data is the club card data described in section 3. It contains no special categories of data within the meaning of Art. 9 GDPR, and no e-mail addresses, telephone numbers or payment data of card holders. The provider grants no authority of any country standing, direct or bulk access to the systems.
Change of circumstances: if the law or the practice of the authorities in the provider’s country changes in a way that prevents the provider from complying with this agreement or with the standard contractual clauses, the provider informs the salon without delay (clause 14(e) and clause 16 of the clauses). The salon may then suspend the transfer or terminate the contract; the provider deletes the data in accordance with section 12.
10. Support for the controller
The provider supports the salon with data subject rights. For this the software offers the self-service export “My data” and the self-deletion “Delete card” on every customer card, as well as deletion of a customer by the salon.
If a data subject approaches the provider directly, the provider forwards the request to the salon without delay and does not answer it itself.
The provider states one limit plainly: the first name on an active card cannot be edited in the software; a correction there is only possible by deleting the card and creating a new one, which does not carry the stamps across. Since 29 September 2026 the salon can, on the Pro and Max plans, correct or remove in the customer account a date of birth that the customer entered on an active card, without losing any stamps; only the customer can enter it in the first place. The software records the time of the last correction. The provider will tell the salon if this limit changes.
The provider also supports the salon with a data protection impact assessment and with reporting personal data breaches, insofar as the necessary information is available only to the provider.
11. Personal data breaches
If the provider becomes aware of a personal data breach, it notifies the salon without undue delay, with all the information the salon needs for its own notification — under Art. 33 GDPR or under whichever law applies to the salon.
Notification to the supervisory authority and communication to the data subjects are the salon’s responsibility.
The provider may itself be subject to a statutory duty to report personal data breaches to an authority in its own country within 72 hours. Should such a report become legally unavoidable, the provider will inform the salon beforehand — or, where it is forbidden to do so, as soon as that prohibition allows — will report no more than the law requires, and will not disclose customer data of the salon unless legally compelled to do so.
12. Deletion after the contract ends
After the contract ends the provider deletes all of the salon’s data. If the salon deletes its account itself in the app, the deletion takes effect at once. If it instead requests a switch to another provider, the retrieval period under § 9a of the terms and conditions applies first; deletion follows after that. Statutory retention duties remain unaffected.
Until then the salon can view and save its customer data through the software.
After deletion, the provider’s platform log keeps only a record of the deletion without customer data: the salon name, the plan, the time, counts and a checksum of the contact e-mail address, not the address itself. The provider is itself responsible for that record; the privacy policy has the details.
13. Evidence and audits
On request the provider demonstrates compliance with this agreement in text form, in particular by describing the measures under section 7.
The salon may satisfy itself of compliance after prior notice and during normal business hours. On-site audits remain limited to what is necessary and must not impair operations or the security of other salons.
14. Final provisions
In the event of contradictions between this agreement and the terms and conditions, this agreement prevails in matters of data protection.
The law of the Federal Republic of Germany applies.
Version 2026-10-06.1, as of 6 October 2026.
15. The processor’s representative in the Union
The provider has designated a representative in the Union under Article 27 GDPR. The designation covers the provider’s role as a processor under this agreement.
The representative in the Union is:
theQ GmbH, Kurt-Schumacher-Str. 22, 30159 Hannover, Germany · Managing director: Van Cuong Vu · Email: info@lytchie.com
Supervisory authorities and data subjects may address the representative. Doing so does not affect the provider’s own obligations under this agreement or under the standard contractual clauses referred to in section 9. For Annex I.A of those clauses, the provider’s contact details are those given in the legal notice; the representative may be addressed in addition.
On request the salon receives a copy of the standard contractual clauses together with their annexes.
Annex: United States state privacy laws
Where a salon is subject to a US state privacy law — for example the California Consumer Privacy Act — this annex applies in addition to the sections above, which remain unchanged. The salon is the business or controller; the provider is its service provider, contractor or processor.
The salon discloses personal information to the provider, or has the provider collect it on its behalf, only for the limited and specified purposes set out in section 2 of this agreement.
The provider will not sell or share that personal information. It will not retain, use or disclose it for any purpose other than performing the services, and not outside its direct business relationship with the salon, except where the law allows. It will not combine it with personal information from any other source, except as the law allows.
The provider complies with the obligations the applicable law places on a service provider, contractor or processor and gives the personal information the same level of protection that law requires. The provider will tell the salon if it concludes that it can no longer meet these obligations. The salon may take reasonable and appropriate steps — including the evidence and audits under section 13 — to check how the provider uses the information and to stop and remedy any unauthorised use.
The provider engages sub-processors only under a written contract with the same duties (section 8). It helps the salon answer requests from its customers to know, to access, to delete and to opt out — among other things through “My data” and “Delete card”, which sit on every card — and it tells the salon without undue delay if it learns of a breach of security affecting the salon’s data (section 11). For a request to correct, the limit set out in section 10 applies: a first name on an active card cannot be edited, and the only route is to delete the card and create a new one.
The salon stays responsible for its own notices to its customers, including any notice a state requires before a customer joins a loyalty programme.
Annex: Australia
This annex applies where the salon’s business is in Australia. It applies in addition to the sections above and replaces none of them. Australian law does not divide the roles into “controller” and “processor”. Where the salon is covered by the Privacy Act 1988 (Cth), the salon generally remains accountable under Australian Privacy Principle 8 and section 16C for personal information once it has been handed to the provider. This agreement is what the provider promises about that handling, and what the salon can rely on.
The body of data is held on servers in the European Union — the application in the Netherlands, the database in Germany — and the provider accesses it remotely from its own country. Sub-processors may hold card data in the United States and in Ireland, as listed in the privacy policy; the one-off look-up of the salon’s address reaches a service in the United Kingdom and involves no customer data. The provider discloses card data to no one else, uses it for no purpose of its own, and passes it to no one for their own advertising or marketing.
For access requests (Australian Privacy Principle 12) the software provides the self-service export “My data” on every card, as set out in the section on support for the controller. The provider notifies the salon of a personal data breach as set out in the section on personal data breaches, so that the salon can meet the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act where that scheme applies to it. On request the provider states in writing which countries hold the data and what security measures are in place.
Correction (Australian Privacy Principle 13) has a limit the salon should know about before it answers a request: the first name on an active card cannot be edited — the only route is to delete the card and create a new one, which does not carry the stamps across. The date of birth, by contrast, the salon can correct or remove in the customer account on the Pro and Max plans without losing any stamps, once the customer has entered it; only the customer can enter it in the first place. The provider will tell the salon if this limit changes.
The section on transfer to a third country carries out European Union law. It remains in place for every salon, but an Australian salon’s own duties come from the Privacy Act, not from those clauses.
Annex: Canada
Where the salon is subject to Canadian law, this agreement is also the written service-provider contract that Canadian law requires before personal information is entrusted to a service provider. It applies in addition to the sections above and replaces none of them. The provider keeps the information confidential (section 6), uses it only to perform this agreement and on the salon’s instructions (sections 2 and 5), does not keep it once this agreement has ended — the salon can delete its account together with all cards itself in the app at any time, once a subscription taken out on the provider’s website has been cancelled, and the provider deletes what remains when the agreement ends, subject to statutory retention duties (section 12) — and informs the salon of any personal data breach without undue delay (section 11).
Under Canadian law the salon remains the organisation accountable for the information. Before personal information leaves Quebec the salon carries out the assessment its law requires; on request the provider supplies the storage locations, the access paths, the sub-processors together with their countries, and the protective measures that the assessment needs.