Data Processing Addendum

Last updated: September 27, 2026

This Data Processing Addendum describes how WalletPassBuilder (Hazelnut Ventures LLC) processes Customer Data as a processor/service provider on behalf of a Customer's own passholders, members, and end users, and takes effect automatically alongside the Terms of Service.

1. Scope & Incorporation

This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the WalletPassBuilder Terms of Service (the "Agreement") between Hazelnut Ventures LLC, d/b/a WalletPassBuilder ("WalletPassBuilder"), and the Customer. It applies whenever WalletPassBuilder processes Personal Information on behalf of and under the instructions of the Customer as part of the Services, and takes effect automatically - alongside the Agreement - the moment the Customer creates an Account, without a separate signature, per the Agreement's own electronic-acceptance terms.

Capitalized terms not defined here have the meaning given in the Privacy Policy or the Agreement. In the event of a conflict between this DPA and the Agreement regarding the processing of Personal Information, this DPA governs.

2. Roles of the Parties

Where WalletPassBuilder processes Personal Information that the Customer submits or makes available through the Services about the Customer's own end users, members, or passholders ("Customer Data"), the Customer is the Controller/Business and WalletPassBuilder is the Processor/Service Provider. Each party will comply with the obligations that apply to its role under applicable Data Protection Law (GDPR, UK GDPR, CCPA/CPRA, and comparable state/federal privacy laws, as applicable).

This DPA does not apply to WalletPassBuilder's own account, billing, and marketing data, for which WalletPassBuilder acts as an independent Controller/Business under its Privacy Policy.

3. Subject Matter, Duration & Details of Processing

  • Subject matter: WalletPassBuilder's provision of the Services - creating, distributing, updating, scanning, and analyzing digital wallet passes on the Customer's behalf.
  • Duration: for the term of the Agreement, plus any post-termination retention period described in Section 8.
  • Nature and purpose: hosting, storage, transmission, display, and processing of Customer Data solely to provide, secure, support, and improve the Services as instructed by the Customer.
  • Categories of data subjects: the Customer's passholders, members, loyalty program participants, employees, or other individuals the Customer issues passes to or collects data about through the Services.
  • Categories of Personal Information: passholder name, email, phone; membership/loyalty identifiers; event/ticket/coupon details; balances; barcodes/QR/serial numbers; custom pass fields and images; enrollment answers; install/update/scan/redemption events; and device/wallet identifiers - limited to what the Customer configures the Services to collect.

4. Customer Instructions

WalletPassBuilder will process Customer Data only: (a) to provide the Services; (b) per the Customer's documented instructions, including those given through the Services' own configuration and features; (c) as described in the Agreement and this DPA; or (d) as required by law, in which case WalletPassBuilder will (where legally permitted) notify the Customer before complying. If an instruction, in WalletPassBuilder's reasonable opinion, would violate Data Protection Law, WalletPassBuilder will inform the Customer before carrying it out.

5. Confidentiality & Personnel

WalletPassBuilder ensures that personnel authorized to process Customer Data are subject to a written confidentiality obligation (or a statutory duty of confidentiality) and only access Customer Data on a need-to-know basis, consistent with their role.

6. Security Measures

WalletPassBuilder implements the technical and organizational measures described in the Privacy Policy (Section 11) and the Trust Center, appropriate to the risk presented by the processing - including encryption in transit and at rest where supported, access controls, multi-factor authentication for privileged systems, monitoring, vulnerability management, and incident response procedures. WalletPassBuilder may update these measures over time provided the update does not materially reduce the overall level of security.

7. Sub-processors

The Customer authorizes WalletPassBuilder to engage the Sub-processors listed in the Privacy Policy (Section 22) and the Trust Center, each bound by a written agreement imposing data protection obligations no less protective than this DPA. WalletPassBuilder remains liable for a Sub-processor's acts and omissions to the same extent WalletPassBuilder would be liable if performing that processing directly.

Where a new Sub-processor will process Customer Data, WalletPassBuilder will update the list and, where the Agreement requires it, give the Customer advance notice and a reasonable window to object on legitimate data-protection grounds. If the parties cannot resolve the objection, either party may terminate the affected Service, without penalty, as its exclusive remedy.

8. Deletion & Return of Data

On termination or expiration of the Agreement, and subject to the exceptions below, WalletPassBuilder will delete or, at the Customer's written request made within 30 days of termination, make available for export, the Customer Data still in its possession. WalletPassBuilder may retain Customer Data (a) in encrypted backups until they age out through the standard backup lifecycle, (b) as required by law, or (c) to the extent needed to resolve a dispute, enforce the Agreement, or investigate fraud or a security incident - in each case protected under this DPA's confidentiality and security obligations until deleted.

The self-service export and erasure tools described in the Privacy Policy (Section 7.3) let the Customer independently export or delete an individual passholder's own record at any time during the Agreement's term, without waiting for termination.

9. Assistance With Data Subject Requests

Taking into account the nature of the processing, WalletPassBuilder will provide reasonable assistance to the Customer, by appropriate technical and organizational measures, to fulfil the Customer's obligation to respond to requests from data subjects exercising their rights under Data Protection Law. Where WalletPassBuilder itself receives such a request concerning Customer Data, it will, without undue delay, redirect the requester to the Customer per Privacy Policy Section 7.3.

10. Personal Data Breach Notification

WalletPassBuilder will notify the Customer without undue delay after becoming aware of a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Data, and will provide the information reasonably available at the time - the nature of the incident, the categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed to address it - updating the Customer as more information becomes available. A notification is not an admission of fault.

11. Data Protection Impact Assessments

WalletPassBuilder will provide reasonable assistance to the Customer with any data protection impact assessment, and any prior consultation with a supervisory authority, that Data Protection Law requires in connection with the Customer's use of the Services, taking into account the information reasonably available to WalletPassBuilder.

12. International Transfers

Where Customer Data originating in the EEA, UK, or Switzerland is transferred to a country without an applicable adequacy decision, the transfer is governed by the Standard Contractual Clauses adopted by the European Commission (Module Two: Controller-to-Processor, or Module Three: Processor-to-Processor, as applicable to the parties' roles for that transfer) and, for UK transfers, the UK International Data Transfer Addendum to those Clauses - each incorporated into this DPA by reference to its official published text, with WalletPassBuilder as "data importer" and the Customer as "data exporter," without needing to be separately signed. Annex information for these Clauses (parties, description of transfers, technical/organizational measures, competent supervisory authority) is as set out in Sections 3, 6, and this Section of this DPA, and in the Privacy Policy (Sections 9 and 22).

13. Audit Rights

No more than once per 12-month period (or promptly following a confirmed security incident affecting Customer Data, or if required by a supervisory authority), and on at least 30 days' written notice, WalletPassBuilder will make available the information reasonably necessary to demonstrate compliance with this DPA - which may take the form of a summary of a recent third-party audit, security certification, or completed security questionnaire, at WalletPassBuilder's reasonable discretion, before allowing an on-site audit. Any audit is conducted during business hours, doesn't unreasonably interfere with WalletPassBuilder's operations, and is subject to confidentiality obligations at least as protective as those in the Agreement. The Customer bears its own audit costs.

14. Liability

Each party's liability arising out of or related to this DPA, whether in contract, tort, or otherwise, is subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA relieves either party of any obligation or liability imposed by applicable Data Protection Law that cannot be limited by contract.

15. Term & Survival

This DPA remains in effect for as long as WalletPassBuilder processes Customer Data on the Customer's behalf. Sections 5, 8 (as to retained copies), 10, 13, and 14 survive termination to the extent necessary to give them effect.

16. Governing Law & Order of Precedence

This DPA is governed by the same governing law and venue as the Agreement (Terms of Service, Section 20), except that the Standard Contractual Clauses incorporated in Section 12 are governed by the law specified in those Clauses where they so require. Where this DPA conflicts with the Agreement on the processing of Personal Information, this DPA controls for that subject matter; the Standard Contractual Clauses control over this DPA to the extent of any conflict directly concerning an international transfer they cover.

17. Electronic Acceptance & Updates

Creating an Account, and each subsequent use of the Services, constitutes the Customer's electronic acceptance of this DPA, equivalent to a handwritten signature - the same mechanism described in the Terms of Service, Section 1.5. WalletPassBuilder may update this DPA to reflect changes to the Services, its Sub-processors, or applicable Data Protection Law, updating the "Last Updated" date and, for material changes, providing notice consistent with the Terms of Service, Section 1.6.

A Customer needing a separately signed, negotiated version of this DPA (e.g. for procurement purposes) may request one at [email protected]; where a signed version is executed, it controls over this self-service DPA for that Customer.