Data Processing Agreement
1. Scope and roles
This Data Processing Addendum (“DPA”) forms part of the agreement between Customer (controller/business) and Vissi (processor/encargado) when Vissi processes personal data on Customer's behalf. Each party remains independently responsible for data it controls for its own account, security, billing, legal-compliance or employment purposes. GDPR terms have their GDPR meanings; Mexican terms have the meanings in the applicable LFPDPPP.
2. Instructions and purpose
Customer instructs Vissi to host, organize, retrieve, transmit, update, secure, support, delete and otherwise process Customer Personal Data to provide digital loyalty, membership, coupon and event Services, as configured by Customer and documented in the agreement. Vissi will process only on documented instructions unless law requires otherwise, in which case it will notify Customer where legally permitted. Vissi will promptly inform Customer if an instruction appears unlawful.
3. Processing details
- Duration: the service term plus lawful deletion, backup and return periods.
- Data subjects: Customer owners, staff, members, prospects, pass holders, event attendees and persons communicating with Customer.
- Data: identity/contact, optional birth date/gender/photos, consent evidence, loyalty/member/ticket identifiers, balances, visits, purchases, rewards, scans, locations, messages, device/push tokens and technical/security data. Payment-card data is processed directly by Stripe, not under Vissi's Customer database.
- Sensitive data: prohibited unless expressly approved in writing and documented with additional safeguards.
4. Confidentiality and security
Vissi will bind authorized personnel to confidentiality and maintain risk-appropriate administrative, technical and physical measures. Current measures include access control/least privilege, TLS, provider encryption at rest, selected-field AES-256-GCM encryption for Customer records, password hashing, signed secure sessions, monitoring, backups, vulnerability remediation and incident procedures.
Customer is responsible for access configuration, staff accounts, secure devices, lawful uploads and not placing sensitive data in unrestricted fields. On reasonable request, Vissi will provide a current security summary. No certification is represented unless expressly supplied in writing.
5. Subprocessors
Customer gives general authorization for subprocessors needed to deliver the Services. Current categories/providers include Vercel, Neon/PostgreSQL, Google Cloud/Firebase/Gemini/Maps/Wallet, Apple Wallet/APNs, Stripe, Resend, Sentry, Cloudflare and legacy Cloudinary storage. The Privacy Policy describes their functions.
Vissi will impose materially equivalent data-protection duties, remain responsible for subprocessor performance to the extent required by law, and provide reasonable notice of a material new subprocessor. Customer may object on documented data-protection grounds within 15 days; the parties will seek a reasonable alternative, and Customer may terminate the affected Service if none is feasible.
6. Data-subject requests
Considering the nature of processing, Vissi will reasonably assist Customer with access, correction, deletion/cancellation, objection, restriction, portability and consent-withdrawal requests. If Vissi receives a request concerning Customer-controlled data, it will refer it to Customer and will not respond substantively except on Customer's instruction or as required by law. Customer remains responsible for identity verification, decisions and deadlines.
7. Security incidents
Vissi will notify Customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data and provide available information on nature, likely consequences, affected categories/approximate volume, contact point and mitigation. Notification is not an admission of fault. Vissi will take reasonable containment and remediation steps and cooperate with legally required notices. Customer is responsible for notices where it is controller.
8. International transfers
Where restricted-transfer law applies, the parties will execute and incorporate the applicable European Commission Standard Contractual Clauses (normally Module Two), UK Addendum or other valid mechanism, with Mexico/United States and relevant provider locations listed as destinations. This online summary alone is not a completed SCC annex. Customer must contact privacy@vissi.digital before transferring EEA/UK data so the parties can complete required annexes, transfer assessment and supplementary measures.
9. Compliance assistance and audits
Vissi will reasonably assist with security, breach, DPIA/impact assessment and regulator consultation obligations, taking into account available information and the processing. Once per year, and additionally after a substantiated incident or regulator request, Customer may request relevant documentation. On-site or third-party audits require reasonable notice, confidentiality, no disruption, no access to other customers' data, and reimbursement of reasonable costs unless a material breach is found. Vissi may satisfy requests with current independent reports where appropriate.
10. Return, deletion, priority and contact
At termination and on Customer's written choice, Vissi will return or delete Customer Personal Data within a reasonable period unless law requires retention; isolated backups may remain protected until routine deletion. Vissi may retain restricted evidence needed for legal claims or security. If this DPA conflicts with the Terms on processing, this DPA controls. Mandatory law and completed SCCs control over both. Contact: privacy@vissi.digital. Effective/version: July 16, 2026 / 2026-07-16.
