Data Processing Agreement | RevWize

Data Processing Agreement for RevWize dated August 20, 2026. PebbleByte GmbH, Mittelgasse 4/13, 1060 Vienna, Austria.

REVWIZE · LEGAL DOCUMENTS

Data Processing Agreement

Agreement pursuant to Art. 28 GDPR for RevWize

Provider and scope of the agreement
ProviderPebbleByte GmbH, Mittelgasse 4/13, 1060 Vienna, Austria
ScopePersonal data of end customers, prospects, and other contacts of the Business Customer, as well as personal data of the Business Customer and its users, insofar as PebbleByte processes such data on behalf of the Business Customer in connection with RevWize.

As of: August 20, 2026

This DPA is concluded electronically together with the RevWize service agreement. It covers both personal data of end customers and personal data of the Business Customer and its users, insofar as PebbleByte processes such data within RevWize on the documented instructions of the Business Customer.

1. Parties and Incorporation

The Controller is the Business Customer that enters into an agreement with PebbleByte for RevWize. The Processor is PebbleByte GmbH, Mittelgasse 4/13, 1060 Vienna, Austria (“PebbleByte”).

This DPA forms part of the RevWize service agreement. It is concluded by express electronic acceptance during checkout or registration, by acceptance of an offer referring to the DPA, or by separate confirmation in text form. PebbleByte records the version and time of acceptance.

In the event of conflict, the provisions of this DPA take precedence over the General Terms and Conditions for processing carried out on behalf of the Business Customer under data protection law. This DPA covers both end-customer data and personal data of the Business Customer and its users, insofar as PebbleByte processes such data on behalf of the Business Customer. Where PebbleByte processes certain contract, billing, account, website, security, or payment data for its own purposes and under its own responsibility under data protection law, such processing is additionally governed by the public Privacy Policy.

2. Subject Matter, Duration, Nature, and Purpose

PebbleByte provides RevWize as a SaaS platform and, in doing so, processes personal data of end customers, prospects, and other contacts of the Controller, as well as personal data of the Business Customer and its authorized users, insofar as such data is processed on behalf of the Business Customer in connection with the use of RevWize. Processing continues for the term of the main agreement and thereafter only for as long as required for return, deletion, statutory obligations, or documented instructions.

Details of the processing
CharacteristicDescription
Subject matterHosting, storage, organization, display, transmission, and deletion of personal data within the subscribed RevWize functions, including end-customer and Business Customer data, insofar as such data is processed on behalf of the Business Customer.
PurposesContact management; consent and opt-out documentation; review requests; permissible SMS campaigns; QR check-ins; loyalty, stamp, voucher, and reward functions; reporting; support; and technical security
Processing operationsCollection, recording, organization, storage, adaptation, retrieval, consultation, use, transmission, restriction, export, and deletion
Data subjectsEnd customers, prospects, and other contacts of the Controller, as well as contacts, employees, and authorized users of the Business Customer, insofar as their data is processed on behalf of the Business Customer.
Types of dataName or identifier; telephone number; email address; business contact and user data; account and authorization information, insofar as processed on behalf of the Business Customer; consent, withdrawal, and opt-out data; IP and device data, insofar as collected as evidence for forms or security; message content and transmission metadata; delivery status; check-ins; loyalty, stamp, voucher, and reward data; tags, segments, and campaign assignments; and technical usage, event, and log data.

Special categories of personal data within the meaning of Art. 9 GDPR are not part of the intended use. If the Controller intends to process such data, processing may begin only after a separate assessment, documented instructions, and confirmation of appropriate safeguards.

3. Instructions and Responsibility

PebbleByte processes personal data only on documented instructions from the Controller, including transfers to third countries, unless required to do so by law. Configurations and actions performed by authorized users within the platform are deemed documented instructions.

If PebbleByte considers an instruction to violate data protection law, PebbleByte will inform the Controller without undue delay and may suspend execution until the matter is clarified. PebbleByte will inform the Controller in advance of statutory disclosure obligations unless the law prohibits such notice.

The Controller ensures, in particular, lawfulness, transparency, purpose limitation, data minimization, accuracy, and storage limitation. The Controller provides its own privacy notice to data subjects, decides on data-subject rights, and manages consent, withdrawals, objections, and suppression lists.

4. Confidentiality and Personnel

PebbleByte engages only persons who are bound by confidentiality and appropriately trained. Access rights are assigned according to tasks, roles, and the need-to-know principle and are withdrawn when no longer required.

5. Security of Processing

Taking into account the state of the art, implementation costs, the nature, scope, context, and purposes of processing, and the risks involved, PebbleByte implements appropriate technical and organizational measures pursuant to Art. 32 GDPR. The measures applicable when the agreement is concluded are described in Annex 1.

PebbleByte may further develop its security measures provided that the agreed level of protection is not reduced. Changes that materially increase risk will be communicated to the Controller in an appropriate manner.

6. Sub-processors

The Controller grants PebbleByte general written authorization to engage the sub-processors named in Annex 2. PebbleByte contractually binds each sub-processor to substantially the same data protection obligations insofar as its services are concerned and remains responsible for the sub-processor’s performance of those obligations.

New or replacement sub-processors will be announced at least 14 calendar days before their planned engagement, in text form or through an agreed notification channel. The Controller may object within this period for demonstrable data protection reasons. The parties will seek a reasonable alternative. If no solution is possible, the affected part of the services or, if it cannot be separated, the main agreement may be terminated for cause with effect from the date the sub-processor is engaged.

Ancillary services that do not involve access to personal data processed on behalf of the Controller do not constitute sub-processing. Annex 2 provides a consolidated overview of the service providers used for RevWize, including sub-processors and payment service providers. Where a listed service provider processes data for its own legal, regulatory, or contractual purposes, it acts as an independent controller for that processing.

7. Transfers to Third Countries

Data is generally processed within the European Economic Area. A transfer to a third country takes place only on documented instructions or through an authorized sub-processor and only where the requirements of Art. 44 et seq. GDPR are met, in particular on the basis of an adequacy decision or appropriate safeguards such as Standard Contractual Clauses together with any necessary supplementary measures.

8. Assistance to the Controller

Taking into account the nature of the processing and the information available, PebbleByte provides reasonable assistance to the Controller with:

  • access, rectification, erasure, restriction, data portability, objection, and withdrawal;
  • security of processing, notification of personal data breaches, and communication to affected data subjects;
  • data protection impact assessments and, where applicable, prior consultations;
  • evidence relating to instructions, deletion, and technically available consent or opt-out data.

Requests from data subjects received directly by PebbleByte will be forwarded to the Controller without a decision on their substance, insofar as the Controller can be identified. PebbleByte acts only on instructions unless a legal obligation requires otherwise.

9. Personal Data Breaches

PebbleByte informs the Controller without undue delay after becoming aware of a personal data breach affecting personal data processed on behalf of the Controller. To the extent available, the notice includes the nature of the incident, the affected data and persons, the likely consequences, the measures taken or proposed, and a contact point. Missing information will be provided without undue delay.

PebbleByte documents security incidents and provides reasonable assistance to the Controller. The Controller decides whether to notify supervisory authorities or affected persons unless PebbleByte itself is legally required to do so.

10. Return, Export, and Deletion

On instruction or after the end of the main agreement, PebbleByte will, to the extent technically possible, provide the data processed on behalf of the Controller in a structured, commonly used, and machine-readable format or delete it. Standard formats include CSV, JSON, or ZIP with a field description.

No later than the end of the contract, the Controller will state whether it requests return or deletion. If no instruction is given, PebbleByte will make an export available for 30 calendar days after the end of the contract and will then delete production data through its regular deletion runs. Backups will be overwritten according to the documented backup cycle and will remain blocked until then. Mandatory statutory retention obligations remain unaffected.

PebbleByte confirms deletion upon request. Anonymized data that no longer relates to an identifiable person is not subject to these return and deletion obligations.

11. Evidence and Audits

PebbleByte makes available all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and permits audits by the Controller or an auditor bound by confidentiality. Existing reports, certificates, questionnaires, and remote audits should be used first.

On-site audits must be announced at least 14 calendar days in advance, conducted during normal business hours, and limited to the extent necessary. Security interests, the rights of other customers, and trade secrets must be protected. Additional work beyond standard evidence required by law may be charged at reasonable costs agreed in advance; this does not apply where the audit is required because of an incident attributable to PebbleByte.

12. Notification Duties and Contacts

Both parties keep their data protection and security contacts up to date. The Controller promptly reports changes to persons authorized to issue instructions and security-relevant misconfigurations. Data protection notices to PebbleByte must be sent to office@pebblebyte.com.

13. Liability

Liability is governed by Art. 82 GDPR, other mandatory statutory provisions, and, additionally, the main agreement. Internal limitations of liability do not affect claims by data subjects.

14. Term and Final Provisions

This DPA applies from its incorporation into the main agreement and ends after the complete return or deletion of the personal data processed on behalf of the Controller. Amendments must be made in text form unless a stricter form is prescribed.

Austrian law applies. To the extent permitted by law, the place of jurisdiction is Vienna. If any provision is invalid, the remaining provisions remain effective.

The contract language is German. Translations are provided for convenience only. In the event of doubt, discrepancies, or conflict between language versions, the German wording prevails.

Annex 1 – Technical and Organizational Measures

Technical and organizational measures
AreaMeasures
Physical and logical access controlOperation in controlled data-center environments; authentication; role-based permissions; removal of access that is no longer required; protection of administrative accounts
Transmission and transportEncrypted transmission via HTTPS/TLS; protected administrative connections; controlled interfaces and secrets management
Authorization and tenant separationNeed-to-know principle; separation of customer data through appropriate logical measures; restricted support access; regular review of privileged access
LoggingLogging of security-relevant access and changes to the extent required; time-limited retention; evaluation in the event of errors and security incidents
Availability and recoveryAvailability monitoring; backup and recovery procedures according to protection requirements; measures against data loss; documented incident handling
Secure development and maintenanceRegular updates; vulnerability and dependency management; review of security-relevant changes; appropriate separation of development and production access
Incident managementReporting and escalation paths; containment, investigation, remediation, and documentation; prompt notification of the Controller in the event of relevant personal data breaches
Organization and personnelConfidentiality obligations; training; binding internal requirements; selection and monitoring of sub-processors
Data minimization and deletionPurpose-specific fields; configurable retention where available; blocking and deletion routines; controlled deletion after the end of the contract and overwriting of backups in the regular cycle
Effectiveness reviewRegular review and event-driven adjustment of measures, taking technical and organizational risks into account

Annex 2 – Service Providers and Sub-processors Used

The following table lists the service providers used to operate RevWize that may process personal data of end customers or Business Customers. The applicable role under data protection law is described for each service.

Service providers used for RevWize
Service providerRegistered office / locationService, affected data, and role
ONLINECITY.IO ApS (service: GatewayAPI)Buchwaldsgade 50, 5000 Odense C, DenmarkSMS delivery; telephone number, message content, transmission time, and delivery status. Sub-processor pursuant to Art. 28 GDPR.
Hetzner Online GmbHIndustriestr. 25, 91710 Gunzenhausen, GermanyHosting and application operation; databases, storage, and backups; platform, end-customer, and Business Customer data, as well as technical logs. Sub-processor pursuant to Art. 28 GDPR.
PostHog, Inc.2261 Market Street #4008, San Francisco, CA 94114, USA; EU Cloud: Frankfurt, GermanyProduct and usage analytics; technical usage and event data and, where generated during use, pseudonymous end-customer and Business Customer data. Processing in the PostHog EU Cloud. Sub-processor pursuant to Art. 28 GDPR.
Stripe Payments Europe Limited1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, IrelandPayment processing for Business Customers; contract, billing, contact, and payment data, transaction data, and technical payment metadata. Depending on the processing activity, processor or independent controller; in particular, an independent controller for its own legal, regulatory, or payment-processing purposes.
Mollie B.V.Keizersgracht 126, 1015 CW Amsterdam, NetherlandsPayment processing for Business Customers; contract, billing, contact, and payment data, transaction data, and technical payment metadata. Depending on the processing activity, processor or independent controller; in particular, an independent controller for its own legal, regulatory, or payment-processing purposes.

Contact

PebbleByte GmbH

Mittelgasse 4/13, 1060 Vienna, Austria

Email: office@pebblebyte.com

Phone: +43 676 59 40 027

Website: https://revwize.com