Last updated 13 September 2026
This addendum forms part of the Bee Loyal Terms of Service. It applies automatically when the business named on a Bee Loyal account (the "Customer") uses the service to process personal data. The Customer is the controller and Bits Matter Ltd is the processor. Together, the Terms and this addendum are the parties' binding data-processing contract under Article 28 of the UK GDPR.
Subject matter and purpose. We process personal data to provide, secure and support Bee Loyal: creating, storing, delivering, displaying, updating and retiring digital business, loyalty, recognition and prize-draw passes; recording activity on those passes; and sending a card email or wallet update when the Customer asks us to.
Duration. Processing lasts while the Customer uses the service and for the short deletion period described in section 9 below.
People covered. The data may relate to the Customer's staff, workers, representatives, customers, card holders, prize-draw entrants and any other people whose data the Customer chooses to put into the service.
Types of data. The data may include names, job titles, phone numbers, email and postal addresses, websites, social links, descriptions and photographs; company, user, card, pass, entry and wallet-device identifiers; push tokens; stamps, points, award reasons, offers, transaction or event history; and prize-draw entries and results.
The service is not intended for special-category data or criminal-offence data. The Customer must not provide either unless we have first agreed suitable extra safeguards in writing.
We will process this data only on the Customer's documented instructions, including instructions about transfers outside the UK, unless UK law requires otherwise. The Terms, the Customer's use and configuration of the service, and written support requests are documented instructions. If the law requires other processing, we will tell the Customer before it happens unless the law prohibits us from doing so. We will tell the Customer immediately if we believe an instruction breaks data-protection law.
The Customer decides why the data is processed and is responsible for having a lawful basis, giving any required privacy information, responding to people who exercise their rights, and making sure its instructions comply with data-protection law. The Customer may give us lawful written instructions, ask for the assistance and compliance information described below, object to a new sub-processor, audit our compliance, and choose return or deletion when the service ends.
We will limit access to people who need the data to provide or support the service. Anyone we authorise to process it must be bound by confidentiality and receive appropriate data-protection and security guidance.
Taking account of the available technology, cost, risks and nature of the data, we will maintain appropriate technical and organisational measures under Article 32 of the UK GDPR. These measures include access controls, protection for credentials and tokens, measures to preserve the confidentiality, integrity and availability of the service, the ability to restore access after an incident, and regular review of the measures we use. We will provide more detail reasonably needed for the Customer's compliance checks.
The Customer gives general written authorisation for us to use the sub-processors listed below to provide Bee Loyal:
We will give the Customer at least 14 days' written notice before adding or replacing a sub-processor so the Customer can object on genuine data-protection grounds. If we cannot resolve a reasonable objection, we may stop the affected feature or the Customer may end the affected service.
Before a sub-processor handles the data, we will put a written contract in place that gives the data at least the same protection as this addendum. We remain responsible to the Customer for the sub-processor's performance.
We will not transfer the data outside the UK except on the Customer's documented instructions and in compliance with UK data-protection law. Where a restricted transfer is not covered by UK adequacy regulations, we will use an approved safeguard such as the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, and carry out any required transfer risk assessment.
Taking account of the nature of our processing, we will give the Customer reasonable technical and organisational help to respond to requests to access, correct, delete, restrict, object to or move personal data. If a request comes to us directly, we will pass it to the Customer promptly and will not answer it ourselves unless the Customer authorises us or the law requires us to.
We will tell the Customer without undue delay after becoming aware of a personal-data breach affecting its data. We will provide the information we have about what happened, the data and people affected, likely consequences and steps taken, and will update it as more becomes known.
Taking account of the nature of the processing and the information available to us, we will also reasonably help the Customer with security obligations, breach notifications, data-protection impact assessments and any required consultation with the Information Commissioner's Office.
At the end of the service, the Customer may choose to have its personal data returned or deleted. It must ask for a return before the account is closed; otherwise its instruction is to delete the data. We will then delete existing copies unless UK law requires us to keep them, in which case we will isolate and protect them and use them only for that legal requirement. A retired card record may be kept for up to 30 days so the wallet can be told that the pass is void, then it is deleted.
We will provide information reasonably needed to show that we meet this addendum and Article 28, and contribute to reasonable audits and inspections by the Customer or an independent auditor it appoints. Unless there is a breach, regulator request or other urgent reason, the Customer will give reasonable notice, avoid disrupting the service, keep our confidential information secure, and audit no more than once a year.
Nothing in this addendum reduces either party's duties or liabilities under data-protection law. If it conflicts with the Terms on the processing of personal data, this addendum takes priority. The law and courts clause in the Terms also applies here.
Questions or instructions about this addendum: privacy@bitsmatter.co.uk.