Data processing agreement
Last updated: September 2026. This is a translation; if it differs from the Dutch version, the Dutch version prevails.
This agreement is part of using Knipje and applies between you (the controller) and Hadcode (KvK 82037477), the maker of Knipje (the processor).
Subject
Knipje processes personal data of your customers (first name, stamp history and optionally e-mail address, phone number and birthday) solely to provide the digital stamp card.
Security
- The database is on a server in the EU; all traffic is encrypted (TLS).
- Access only for you and your staff, with a PIN per staff member and a log of all actions.
- Wallet passes contain no phone number or e-mail address, only a random code.
Sub-processors
- Netcup (Germany): hosting and database, on a server in the EU.
- Cloudflare: domain name and security of traffic.
- Resend: e-mails to your customers, only if you send them.
- Meta (WhatsApp): messages to your customers, only if you send them via WhatsApp.
- Apple Wallet and Google Wallet: only the data on the pass (first name, stamps, reward).
Parties outside the EU process data under the EU-US Data Privacy Framework or the standard contractual clauses. We announce new sub-processors by e-mail in advance; you may object to them.
Data breaches
Knipje reports a data breach without undue delay and at the latest within 48 hours of discovering it, so that you can notify the Dutch data protection authority within 72 hours if needed.
Help with requests
If a customer asks for access, correction or deletion, we help you with it. Customers can also delete their card and data themselves. Questions? E-mail [email protected].
End
After cancelling, you can export your customer data. We delete it within 30 days after that.