Data Processing Agreement | RevWize
Data Processing Agreement for RevWize dated August 20, 2026. PebbleByte GmbH, Mittelgasse 4/13, 1060 Vienna, Austria.
REVWIZE · LEGAL DOCUMENTS
Data Processing Agreement
Agreement pursuant to Art. 28 GDPR for RevWize
| Provider | PebbleByte GmbH, Mittelgasse 4/13, 1060 Vienna, Austria |
|---|---|
| Scope | Personal data of end customers, prospects, and other contacts of the Business Customer, as well as personal data of the Business Customer and its users, insofar as PebbleByte processes such data on behalf of the Business Customer in connection with RevWize. |
As of: August 20, 2026
This DPA is concluded electronically together with the RevWize service agreement. It covers both personal data of end customers and personal data of the Business Customer and its users, insofar as PebbleByte processes such data within RevWize on the documented instructions of the Business Customer.
1. Parties and Incorporation
The Controller is the Business Customer that enters into an agreement with PebbleByte for RevWize. The Processor is PebbleByte GmbH, Mittelgasse 4/13, 1060 Vienna, Austria (“PebbleByte”).
This DPA forms part of the RevWize service agreement. It is concluded by express electronic acceptance during checkout or registration, by acceptance of an offer referring to the DPA, or by separate confirmation in text form. PebbleByte records the version and time of acceptance.
In the event of conflict, the provisions of this DPA take precedence over the General Terms and Conditions for processing carried out on behalf of the Business Customer under data protection law. This DPA covers both end-customer data and personal data of the Business Customer and its users, insofar as PebbleByte processes such data on behalf of the Business Customer. Where PebbleByte processes certain contract, billing, account, website, security, or payment data for its own purposes and under its own responsibility under data protection law, such processing is additionally governed by the public Privacy Policy.
2. Subject Matter, Duration, Nature, and Purpose
PebbleByte provides RevWize as a SaaS platform and, in doing so, processes personal data of end customers, prospects, and other contacts of the Controller, as well as personal data of the Business Customer and its authorized users, insofar as such data is processed on behalf of the Business Customer in connection with the use of RevWize. Processing continues for the term of the main agreement and thereafter only for as long as required for return, deletion, statutory obligations, or documented instructions.
| Characteristic | Description |
|---|---|
| Subject matter | Hosting, storage, organization, display, transmission, and deletion of personal data within the subscribed RevWize functions, including end-customer and Business Customer data, insofar as such data is processed on behalf of the Business Customer. |
| Purposes | Contact management; consent and opt-out documentation; review requests; permissible SMS campaigns; QR check-ins; loyalty, stamp, voucher, and reward functions; reporting; support; and technical security |
| Processing operations | Collection, recording, organization, storage, adaptation, retrieval, consultation, use, transmission, restriction, export, and deletion |
| Data subjects | End customers, prospects, and other contacts of the Controller, as well as contacts, employees, and authorized users of the Business Customer, insofar as their data is processed on behalf of the Business Customer. |
| Types of data | Name or identifier; telephone number; email address; business contact and user data; account and authorization information, insofar as processed on behalf of the Business Customer; consent, withdrawal, and opt-out data; IP and device data, insofar as collected as evidence for forms or security; message content and transmission metadata; delivery status; check-ins; loyalty, stamp, voucher, and reward data; tags, segments, and campaign assignments; and technical usage, event, and log data. |
Special categories of personal data within the meaning of Art. 9 GDPR are not part of the intended use. If the Controller intends to process such data, processing may begin only after a separate assessment, documented instructions, and confirmation of appropriate safeguards.
3. Instructions and Responsibility
PebbleByte processes personal data only on documented instructions from the Controller, including transfers to third countries, unless required to do so by law. Configurations and actions performed by authorized users within the platform are deemed documented instructions.
If PebbleByte considers an instruction to violate data protection law, PebbleByte will inform the Controller without undue delay and may suspend execution until the matter is clarified. PebbleByte will inform the Controller in advance of statutory disclosure obligations unless the law prohibits such notice.
The Controller ensures, in particular, lawfulness, transparency, purpose limitation, data minimization, accuracy, and storage limitation. The Controller provides its own privacy notice to data subjects, decides on data-subject rights, and manages consent, withdrawals, objections, and suppression lists.
4. Confidentiality and Personnel
PebbleByte engages only persons who are bound by confidentiality and appropriately trained. Access rights are assigned according to tasks, roles, and the need-to-know principle and are withdrawn when no longer required.
5. Security of Processing
Taking into account the state of the art, implementation costs, the nature, scope, context, and purposes of processing, and the risks involved, PebbleByte implements appropriate technical and organizational measures pursuant to Art. 32 GDPR. The measures applicable when the agreement is concluded are described in Annex 1.
PebbleByte may further develop its security measures provided that the agreed level of protection is not reduced. Changes that materially increase risk will be communicated to the Controller in an appropriate manner.
6. Sub-processors
The Controller grants PebbleByte general written authorization to engage the sub-processors named in Annex 2. PebbleByte contractually binds each sub-processor to substantially the same data protection obligations insofar as its services are concerned and remains responsible for the sub-processor’s performance of those obligations.
New or replacement sub-processors will be announced at least 14 calendar days before their planned engagement, in text form or through an agreed notification channel. The Controller may object within this period for demonstrable data protection reasons. The parties will seek a reasonable alternative. If no solution is possible, the affected part of the services or, if it cannot be separated, the main agreement may be terminated for cause with effect from the date the sub-processor is engaged.
Ancillary services that do not involve access to personal data processed on behalf of the Controller do not constitute sub-processing. Annex 2 provides a consolidated overview of the service providers used for RevWize, including sub-processors and payment service providers. Where a listed service provider processes data for its own legal, regulatory, or contractual purposes, it acts as an independent controller for that processing.
7. Transfers to Third Countries
Data is generally processed within the European Economic Area. A transfer to a third country takes place only on documented instructions or through an authorized sub-processor and only where the requirements of Art. 44 et seq. GDPR are met, in particular on the basis of an adequacy decision or appropriate safeguards such as Standard Contractual Clauses together with any necessary supplementary measures.
8. Assistance to the Controller
Taking into account the nature of the processing and the information available, PebbleByte provides reasonable assistance to the Controller with:
- access, rectification, erasure, restriction, data portability, objection, and withdrawal;
- security of processing, notification of personal data breaches, and communication to affected data subjects;
- data protection impact assessments and, where applicable, prior consultations;
- evidence relating to instructions, deletion, and technically available consent or opt-out data.
Requests from data subjects received directly by PebbleByte will be forwarded to the Controller without a decision on their substance, insofar as the Controller can be identified. PebbleByte acts only on instructions unless a legal obligation requires otherwise.
9. Personal Data Breaches
PebbleByte informs the Controller without undue delay after becoming aware of a personal data breach affecting personal data processed on behalf of the Controller. To the extent available, the notice includes the nature of the incident, the affected data and persons, the likely consequences, the measures taken or proposed, and a contact point. Missing information will be provided without undue delay.
PebbleByte documents security incidents and provides reasonable assistance to the Controller. The Controller decides whether to notify supervisory authorities or affected persons unless PebbleByte itself is legally required to do so.
10. Return, Export, and Deletion
On instruction or after the end of the main agreement, PebbleByte will, to the extent technically possible, provide the data processed on behalf of the Controller in a structured, commonly used, and machine-readable format or delete it. Standard formats include CSV, JSON, or ZIP with a field description.
No later than the end of the contract, the Controller will state whether it requests return or deletion. If no instruction is given, PebbleByte will make an export available for 30 calendar days after the end of the contract and will then delete production data through its regular deletion runs. Backups will be overwritten according to the documented backup cycle and will remain blocked until then. Mandatory statutory retention obligations remain unaffected.
PebbleByte confirms deletion upon request. Anonymized data that no longer relates to an identifiable person is not subject to these return and deletion obligations.
11. Evidence and Audits
PebbleByte makes available all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and permits audits by the Controller or an auditor bound by confidentiality. Existing reports, certificates, questionnaires, and remote audits should be used first.
On-site audits must be announced at least 14 calendar days in advance, conducted during normal business hours, and limited to the extent necessary. Security interests, the rights of other customers, and trade secrets must be protected. Additional work beyond standard evidence required by law may be charged at reasonable costs agreed in advance; this does not apply where the audit is required because of an incident attributable to PebbleByte.
12. Notification Duties and Contacts
Both parties keep their data protection and security contacts up to date. The Controller promptly reports changes to persons authorized to issue instructions and security-relevant misconfigurations. Data protection notices to PebbleByte must be sent to office@pebblebyte.com.
13. Liability
Liability is governed by Art. 82 GDPR, other mandatory statutory provisions, and, additionally, the main agreement. Internal limitations of liability do not affect claims by data subjects.
14. Term and Final Provisions
This DPA applies from its incorporation into the main agreement and ends after the complete return or deletion of the personal data processed on behalf of the Controller. Amendments must be made in text form unless a stricter form is prescribed.
Austrian law applies. To the extent permitted by law, the place of jurisdiction is Vienna. If any provision is invalid, the remaining provisions remain effective.
The contract language is German. Translations are provided for convenience only. In the event of doubt, discrepancies, or conflict between language versions, the German wording prevails.
Annex 1 – Technical and Organizational Measures
| Area | Measures |
|---|---|
| Physical and logical access control | Operation in controlled data-center environments; authentication; role-based permissions; removal of access that is no longer required; protection of administrative accounts |
| Transmission and transport | Encrypted transmission via HTTPS/TLS; protected administrative connections; controlled interfaces and secrets management |
| Authorization and tenant separation | Need-to-know principle; separation of customer data through appropriate logical measures; restricted support access; regular review of privileged access |
| Logging | Logging of security-relevant access and changes to the extent required; time-limited retention; evaluation in the event of errors and security incidents |
| Availability and recovery | Availability monitoring; backup and recovery procedures according to protection requirements; measures against data loss; documented incident handling |
| Secure development and maintenance | Regular updates; vulnerability and dependency management; review of security-relevant changes; appropriate separation of development and production access |
| Incident management | Reporting and escalation paths; containment, investigation, remediation, and documentation; prompt notification of the Controller in the event of relevant personal data breaches |
| Organization and personnel | Confidentiality obligations; training; binding internal requirements; selection and monitoring of sub-processors |
| Data minimization and deletion | Purpose-specific fields; configurable retention where available; blocking and deletion routines; controlled deletion after the end of the contract and overwriting of backups in the regular cycle |
| Effectiveness review | Regular review and event-driven adjustment of measures, taking technical and organizational risks into account |
Annex 2 – Service Providers and Sub-processors Used
The following table lists the service providers used to operate RevWize that may process personal data of end customers or Business Customers. The applicable role under data protection law is described for each service.
| Service provider | Registered office / location | Service, affected data, and role |
|---|---|---|
| ONLINECITY.IO ApS (service: GatewayAPI) | Buchwaldsgade 50, 5000 Odense C, Denmark | SMS delivery; telephone number, message content, transmission time, and delivery status. Sub-processor pursuant to Art. 28 GDPR. |
| Hetzner Online GmbH | Industriestr. 25, 91710 Gunzenhausen, Germany | Hosting and application operation; databases, storage, and backups; platform, end-customer, and Business Customer data, as well as technical logs. Sub-processor pursuant to Art. 28 GDPR. |
| PostHog, Inc. | 2261 Market Street #4008, San Francisco, CA 94114, USA; EU Cloud: Frankfurt, Germany | Product and usage analytics; technical usage and event data and, where generated during use, pseudonymous end-customer and Business Customer data. Processing in the PostHog EU Cloud. Sub-processor pursuant to Art. 28 GDPR. |
| Stripe Payments Europe Limited | 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland | Payment processing for Business Customers; contract, billing, contact, and payment data, transaction data, and technical payment metadata. Depending on the processing activity, processor or independent controller; in particular, an independent controller for its own legal, regulatory, or payment-processing purposes. |
| Mollie B.V. | Keizersgracht 126, 1015 CW Amsterdam, Netherlands | Payment processing for Business Customers; contract, billing, contact, and payment data, transaction data, and technical payment metadata. Depending on the processing activity, processor or independent controller; in particular, an independent controller for its own legal, regulatory, or payment-processing purposes. |
Contact
PebbleByte GmbH
Mittelgasse 4/13, 1060 Vienna, Austria
Email: office@pebblebyte.com
Phone: +43 676 59 40 027
Website: https://revwize.com