How we process the personal data of merchants, club members and visitors
The controller of personal data is MAMA media s.r.o., with its registered office at Na Hrebienku 1, 811 02 Bratislava, Slovak Republic, Company ID: 36 767 549, registered in the Commercial Register of the Bratislava III Municipal Court, Section: Sro, Insert No. 45585/B, e-mail: support@vexioncards.one (the “Controller” or “we”).
Customers (B2B): merchants and their representatives who order from us and use the VEXiON cards Service to run their own loyalty programme, within the meaning of the VEXiON cards General Terms and Conditions (the “Terms”).
End Customers / Members (B2C): natural persons who register for a loyalty programme run by one of our Customers (merchants). In relation to those persons we are as a rule a processor and not a controller; details are set out below and in the VEXiON cards Consumer Terms.
Buyers and recipients of Gift Vouchers: details of the processing of their data are set out in the Gift Voucher Sales Terms at https://www.vexioncards.one/gift-card-terms.
Website visitors: to the extent of the processing of cookies and analytics tools under Article 8.
We process Customers’ billing and contact details (business name, Company ID, Tax ID, name of the contact person, e-mail, telephone, billing address) for the purposes of concluding and performing the contract (Article 6(1)(b) GDPR), fulfilling accounting and tax obligations (Article 6(1)(c) GDPR) and direct marketing to existing Customers in the scope of offering our own similar products, and towards entrepreneurs who have shown an interest in the Service, on the basis of our legitimate interest (Article 6(1)(f) GDPR), always with the option to opt out or to object at any time. Details of this entitlement, including the use of third party advertising platforms, are set out in clause 15.5 of the Terms and in Article 5 below. In the case of unsolicited electronic communications we proceed in accordance with Section 116 of Act No. 452/2021 Coll. on electronic communications.
A separate group of data subjects are the Customer’s employees and team members who use the merchant application. We process their name, e-mail and records of logins and access to the application, for the purposes of providing the Service to the Customer and of its security, on the basis of our legitimate interest in performing the contract with the Customer and in the security of the Service (Article 6(1)(f) GDPR).
In relation to the personal data of Members of loyalty programmes (name, e-mail, telephone, history of transactions and of programme redemptions including purchase items, that is the name, quantity and price, where the merchant’s POS system or e-shop passes them on) we act as a rule as a processor for the Customer (the merchant), who is the controller in relation to those persons, and we process them on the basis of the DPA concluded with the Customer (Annex 1 to the Terms) and on the Customer’s instruction. For integrations that we have connected technically, the role of controller is determined by the contract with the merchant. Details of your rights as a Member can be found in the VEXiON cards Consumer Terms. Details of the processing of your personal data by the merchant, of the legal bases, of the retention period and of your rights are set out in the Information on the processing of loyalty club members’ personal data, which is available when registering a card and forms Annex 1 to the Consumer Terms at https://www.vexioncards.one/card-terms. To a limited extent we process, as a separate controller, technical and security data on the use of the card (card identifier, technical records of the issue and updating of the card in a digital wallet, device fingerprint in the referral programme), on the basis of our legitimate interest in ensuring the functionality and security of the platform and in preventing abuse (Article 6(1)(f) GDPR).
The Service is not intended for persons under 16 years of age and we do not knowingly process their data. If a Member is a person under 16 years of age, that person may register for the loyalty programme only with the consent of their legal representative; the merchant, as controller, is responsible for verifying this. The merchant, as controller, must not send marketing communications to persons under 16 years of age without the consent of their legal representative; we do not systematically check members’ age.
When a Gift Voucher is purchased we process the name and e-mail of the buyer, the name, telephone and, where applicable, e-mail of the recipient, the personal message that the buyer attaches to the voucher, the language version, the record of consent given and technical data on the order (hash of the IP address, browser identification). We process those data for the purposes of concluding and performing the contract for the purchase and delivery of the voucher (Article 6(1)(b) GDPR), fulfilling accounting and tax obligations (Article 6(1)(c) GDPR) and demonstrating the consent given and preventing abuse (Article 6(1)(f) GDPR). Until the voucher is activated we keep them for 3 years from the purchase. We inform the recipient about the processing of their data and about this Policy in the message by which we deliver the voucher. In the purchase and delivery of a Gift Voucher we act as controller. After the voucher is activated and a loyalty record arises with the merchant, the merchant becomes the controller and we are its processor; details are set out in the Gift Voucher Sales Terms.
We do not carry out profiling or automated decision-making that would have legal effects in relation to you or would similarly significantly affect you within the meaning of Article 22 GDPR. To a limited extent we use automated technical signals (for example a device fingerprint) solely for the purpose of preventing fraudulent behaviour in referrals between members of a loyalty programme; that process does not in itself lead to a decision with legal or similarly significant effects in relation to you; it concerns solely the holding for up to 7 days or the cancellation of an entitlement to a reward from the referral programme, against which you may object at support@vexioncards.one.
We may process data by automated means for the purposes of the operation, security and improvement of the Service, including the personalisation of offers within the Customer’s loyalty programme. For improving the Service across Customers we use exclusively aggregated or anonymised data from which an End Customer cannot be identified. We do not take decisions with legal or similarly significant effects in relation to an End Customer; automated measures against abuse of the referral programme concern solely the entitlement to a reward and an End Customer may object to them. Features that work with identifiable Member data are activated by us solely on the express and revocable instruction of the Customer. Detailed rules are set out in Article 6 of the DPA (Annex 1 to the Terms).
We list processors by category of the recurring shape of the relationship, not by individual company, so that a change of a particular supplier within the same category does not require this document to be amended. The categories are identical to Annex 2 to the Terms:
| Cat. | Category of relationship | Example purpose |
|---|---|---|
| K1 | Core platform infrastructure and services | hosting, database, payments, login, communications, monitoring, digital wallets |
| K2 | POS systems chosen and operated by the Customer | connection to the merchant’s POS system |
| K3 | Booking systems chosen and operated by the Customer | connection to the merchant’s booking system |
| K4 | E-commerce and other platforms that the Customer connects itself | the merchant’s own e-shop or other system |
| K5 | Partner systems with a reversed relationship | the partner is the controller of its end customers, we are its further processor |
| K6 | Tools for automated data processing and enrichment | account set-up assistant, processes only data at the level of the Customer |
| K7 | Professional advisers | accounting, legal and tax advice, audit |
We maintain on an ongoing basis and publish the current named list of sub-processors in each category, stating the legal entity, the purpose of processing, the location of the data and the mechanism for transfers outside the European Economic Area, in Annex A to this Policy at https://www.vexioncards.one/gdpr#sprostredkovatelia. The list contains the date of the last update. We will notify Customers by e-mail at least 30 days in advance of every addition or replacement of a processor, including within the same category; objections and their consequences are governed by Article 8 of the DPA (Annex 1 to the Terms). We will also provide you with the list in another form on request.
The operator of the Google Wallet service acts, when a card is issued and updated, under its own terms as a separate controller and not as our processor, and this is governed by a separate addendum, the “Controller-Controller Data Protection Terms”. We assess the position of the Apple Wallet provider in the same way; Apple does not publish a separate processing addendum for that service. Those companies are separately responsible for the processing of your data within this part, in accordance with their own privacy policies.
Since those digital wallet providers act as separate controllers, no data processing addendum under Article 28 GDPR is required from them, as that provision concerns processors only. The transfer of data passed to them outside the European Economic Area is governed by appropriate safeguards under Chapter V GDPR intended for a relationship between two controllers, in particular standard contractual clauses, where the provider in question offers them.
If any of the processors is established outside the European Economic Area, we secure the transfer of data on the basis of appropriate safeguards under Chapter V GDPR, in particular standard contractual clauses approved by the European Commission, or on the basis of an adequacy decision, where one is in force for that country at the relevant time. The current transfer mechanism for each processor is stated in the list above, since both adequacy decisions and the list of certified companies change over time.
Personal data processed within the Service are stored in the European Union, in the Amazon Web Services environment in the eu-central-1 region (Frankfurt am Main) and in a MongoDB Atlas database operated in the same region. Transfers outside the European Economic Area occur solely in the case of individual sub-processors listed in the list and are covered by the mechanism stated for each of them. We do not offer a choice of another storage region.
Customer data are held in particular by the following tools: Clerk (login to the application), Stripe (payments), SuperFaktura (invoicing), GoHighLevel (CRM), Resend and SMSTools (e-mail and SMS), PostHog (analytics and session recording), BetterStack (operational logs and error reports, data in the European Union), Amazon Web Services and MongoDB Atlas (infrastructure), Vercel (marketing website) and Dub.co (partner programme).
The security measures we apply when processing personal data are set out in Annex 3 to the Terms.
The procedure and the deadline for notifying the Customer of a personal data breach are governed by Article 7 of the DPA (Annex 1 to the Terms).
In order to measure the effectiveness of our own advertising, we pass to advertising platforms (in particular Meta and Google Ads) data on business events on our website and contact lists of prospects and Customers. This concerns exclusively entrepreneurs and persons interested in our service, never Members of loyalty clubs. Our internal service for building advertising lists reads solely the list of business organisations (Customers) and contacts from our CRM, never the Member database.
As a rule we pass data in the form of an irreversible hash. In relation to Meta we act, under Meta’s own terms, as a joint controller under Article 26 GDPR in respect of data on business activity on our website; in relation to Google Ads that platform is our processor in category K1. Details are also set out in clause 15.5 of the Terms. We make the essence of the joint controllership arrangement with the Meta platform under Article 26(2) GDPR available in Annex B to this Policy at https://www.vexioncards.one/gdpr#meta.
When passing data to advertising platforms we observe the following rules: we do not send the IP address or the browser header to the Meta Conversions API, we pass only irreversibly hashed contact identifiers; we build lookalike (derived) audiences exclusively from the list of active Customers and business entities for the purpose of finding new business opportunities, we build no derived audiences from the Member database, and we set uploaded contact lists to expire after 540 days at most, corresponding to the length of a normal business cycle, in both Meta and Google Ads.
To the Google Ads advertising platform we pass, in addition to conversion data, contact lists in the form of an irreversible hash; if a click identifier is missing for a conversion, we pass a hashed e-mail.
We keep personal data only for the period necessary to fulfil the purpose of their processing, at most for the duration of the contractual relationship and then for the period arising from specific legislation (for example accounting and tax legislation) or for the limitation period for bringing claims.
After the contractual relationship with a Customer ends, the Customer’s data and the related data of its Members are subject to the periods under clause 6.3 of the Terms: 30 days for export and then deletion or anonymisation from production systems within 90 days of the end of the contract at the latest. No later than the last day of the export period the Customer may give an explicit documented instruction that, instead of deleting the data, we keep them in an inactive state solely for the purpose of a possible restoration of the service, for no longer than 12 months from the end of the contract; during that time we only store them in separate storage, do not make them available, do not use them for any other purpose, and at the Customer’s request we delete them at the latest within 30 days. If the Customer gives no instruction, no retention takes place. Copies in backups expire within 6 months at the latest and are not used for restoration. For contracts that ended before this Privacy Policy took effect, the periods in this clause do not apply; we keep the data under the previous terms until the Customer asks for it to be returned or deleted.
If your membership of a loyalty programme ends (for example by opting out or by deletion by the merchant), we will delete or anonymise your data on the instruction of the merchant, who is the controller in relation to those data, within 90 days of the end of the membership at the latest; copies in backups expire within 6 months at the latest and are not used for restoration.
We keep records of notifications sent that are not technically linked to a specific Member for a maximum of four years from sending, in accordance with the storage limitation principle under Article 5(1)(e) GDPR.
The retention periods by category of data are as follows: Member data in the loyalty programme for the term of the contract with the Customer, then 30 days for export and deletion or anonymisation within 90 days of the end of the contract at the latest, and, if the Customer gives an explicit documented instruction under clause 6.2, retention in an inactive state for the purpose of restoring the service for no longer than 12 months from the end of the contract; data after membership ends, deletion or anonymisation at the latest within 90 days of it ending; the technical device fingerprint under clause 8.3 for no longer than 90 days from registration through a referral link; Customers’ billing and accounting documents 10 years under Section 35(3) of Act No. 431/2002 Coll.; records of a withdrawal of agreement to marketing communications or of an objection to them, and of their confirmation, 4 years from the withdrawal or the objection, as required by Section 116(5) and (6) of Act No. 452/2021 Coll.; other records of consent given and withdrawn 3 years from the withdrawal of consent or from the end of the membership; analytics data on website traffic 14 months, renewed upon further activity; records of notifications sent with no link to a specific Member 4 years (Section 397 of the Commercial Code); contact lists uploaded to advertising platforms 540 days; buyer and recipient data for a gift voucher, until its activation, 3 years from the purchase; audit records of support access to a Customer’s account permanently; server and security logs of requests 7 days, security firewall logs 14 days, and network and storage level access logs and technical processing logs no more than 30 days. We keep database backups hourly for 1 day, daily for 7 days, weekly for 4 weeks and monthly for 6 months, with point-in-time restoration within a window of one day.
In accordance with the GDPR you have the right of access to your data (Article 15), to rectification (Article 16), to erasure (Article 17), to restriction of processing (Article 18), to data portability (Article 20), the right to object (Article 21) and the right not to be subject to a decision based solely on automated processing (Article 22). You may exercise these rights at support@vexioncards.one. If your request concerns data in respect of which we are a processor, we will pass it on to the relevant controller or provide that controller with cooperation. In matters of personal data protection you may contact us at support@vexioncards.one. You also have the right to lodge a complaint with the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava, www.dataprotection.gov.sk. You also have the right to withdraw consent given at any time, with effect for the future. We will respond to a request within one month. If you reside in another Member State, you may also turn to the supervisory authority of your own state.
Send your request to support@vexioncards.one. If you are a member of a loyalty club, you may also send the request directly to the merchant whose card you use; there is no other interface or login for members, the card in the digital wallet is the only interface. If we cannot identify you reliably, we may ask for additional information; we do not collect other data for that purpose.
A merchant’s marketing messages reach a member as notifications from the loyalty card in the digital wallet. Receiving those messages is part of membership of the loyalty programme. For members who registered on or after the date the Consumer Terms took effect, it rests on the agreement given by accepting those terms on registration. For members who registered before that date, it rests on Section 116(15) of Act No. 452/2021 Coll. on electronic communications, that is on direct marketing of the own similar goods and services of the merchant with whom they joined, with the same free ways to refuse. Every marketing message states the identity of the merchant sending it. A member may stop them at any time and free of charge: by switching the notifications off in their phone settings for Apple Wallet or Google Wallet, or on the card itself, or by e-mail to the merchant or to support@vexioncards.one. Messages the merchant sends from its own booking, point-of-sale or other connected system are governed by that system; we will pass an objection to them on to the merchant, who handles it in its own system, and switching notifications off on the phone also stops those messages. An objection or withdrawal that reaches us by e-mail is recorded, demonstrably confirmed within 30 days at the latest, and the record of it is kept for four years, as required by Section 116(5) and (6) of the same Act. To members who registered before the date the Consumer Terms took effect, the merchant sends marketing messages under Section 116(15) no later than one year after their membership ends, as required by Section 116(16) of the same Act. Stopping the messages has no effect on loyalty club membership or on collecting points.
This Article sets out information on the cookies and similar technologies we use, on their categories and on how to manage your consent settings; we do not issue a separate cookie document. On the vexioncards.one website we use necessary cookies required for the site to work, analytics cookies to measure traffic and marketing cookies to measure the effectiveness of our advertising. Analytics and marketing cookies are loaded only after you have made your choice in the cookie banner; necessary cookies are run on the basis of the statutory exemption under Section 109(8) of Act No. 452/2021 Coll. on electronic communications, since this is technical storage or access strictly necessary for providing the Service you have expressly requested; the related processing of personal data is based on our legitimate interest in the functioning of the site.
The choice made in the cookie banner on the vexioncards.one website also applies to the login and the merchant environment, because they run on the same domain. On customer-facing pages (card registration, gift vouchers) we use only technically necessary storage for the site to work and our own analytics measurement of site use for improving the Service, which stores no cookies or identifier on the device and does not record the data entered; its legal basis is our legitimate interest in the operation and improvement of the Service and you may object to it. This measurement stores no cookies or other data on your device, does not record the course of your visit, and does not collect characteristics of your device beyond what the browser sends with every request. Server and security logs of requests to our systems, which may contain an IP address and browser data, are kept for 7 days, security firewall logs for 14 days, and network and storage level access logs and technical processing logs for no more than 30 days; they serve solely for security and fault clearing on the basis of legitimate interest.
When you register through a referral link we compute, from the technical characteristics of your device (browser type, language, resolution, time zone and technical device parameters, not the content of your screen), a technical fingerprint which we store field by field in hashed form and compare only with the fingerprints of other people referred by the same member, in order to detect abuse of the referral programme. For the same purpose we may compare the technical identifier of the card installation in Apple Wallet, which we already process in order to deliver card updates. This is access strictly necessary to provide the feature you asked for, under Section 109(8) of Act No. 452/2021 Coll.; the legal basis for the assessment is the legitimate interest of the Merchant and the Provider in protection against fraud. We keep the fingerprint for no longer than 90 days from registration and we do not collect it on an ordinary registration without a referral.
In the merchant application we record the course of the session (cursor movement, clicks, the page content displayed and technical records from the browser console) for the purposes of fixing errors and improving usability. Values entered into form fields are not recorded. We keep the recordings for 30 days and on customer-facing pages recording is switched off.
We may update this Policy from time to time. We will inform you of material changes in an appropriate manner (for example by e-mail or by a notice on the website) before they take effect. Version 1.0, effective from 29 October 2026. We will make previous versions available on request.
List updated: 18 September 2026.
This is the named list of processors and other recipients under Article 4 of this Policy. For each supplier we state the name, the category under Article 4, the purpose of processing, the country of processing and the mechanism for transfers outside the European Economic Area. We update the list on an ongoing basis and will provide it in another form on request.
Category K4: platforms and systems that the merchant connects to the Service itself, for example its e-shop or the systems of developers it has chosen itself. Those platforms are not our processors; their position is determined by the merchant’s contract with them.
Digital wallet providers (Apple Wallet, Google Wallet), including the service by which Apple delivers card updates to devices, act under their own terms as separate controllers and not as our processors, and are therefore not in this list; their position is described in Article 4 of this Policy.
The list contains the date of the last update; the Provider will inform the Customer of changes to it by e-mail in accordance with clause 8.2 of the DPA (Annex 1 to the Terms). The Provider will give notice of both the engagement of a new sub-processor and the replacement of an existing sub-processor by another, including within an existing category, at least 30 days before the new sub-processor begins to process personal data, by publication at this address and at the same time by e-mail sent to the Customer’s contact address stated in the Account.
| Category | Processor | Purpose | Country of processing | Transfer mechanism |
|---|---|---|---|---|
| K1 | Stripe, LLC and Stripe Payments Europe, Ltd. | subscriptions, payments and payouts for gift vouchers | Ireland and the United States of America | EU-US Data Privacy Framework |
| K1 | SuperFaktura s.r.o. | invoicing and accounting documents | Slovak Republic | no transfer outside the European Economic Area takes place |
| K1 | Clerk, Inc. | login and access management for the merchant application | United States of America | EU-US Data Privacy Framework |
| K1 | Resend | sending transactional e-mails | United States of America | EU-US Data Privacy Framework |
| K1 | Com-TRADE (SMSTools) | sending SMS messages, one-time codes and gift voucher notifications | Slovak Republic | no transfer outside the European Economic Area takes place |
| K1 | HighLevel Inc | management of business contacts and marketing communications towards entrepreneurs | United States of America | EU-US Data Privacy Framework |
| K1 | Google LLC (Firebase Cloud Messaging) | delivery of notifications to devices with the Android operating system | United States of America | EU-US Data Privacy Framework |
| K1 | MongoDB, Inc. | primary database of the Service | European Union, Frankfurt am Main | EU-US Data Privacy Framework |
| K1 | Amazon Web Services, Inc. | cloud infrastructure of the Service including storage, network and backups | European Union, eu-central-1 region | EU-US Data Privacy Framework |
| K1 | Vercel Inc. | hosting of the marketing website | European Union and the United States of America | EU-US Data Privacy Framework |
| K1 | Better Stack | operational logs and error reports | European Union | standard contractual clauses |
| K1 | PostHog Inc | measurement of Service use and session recording in the merchant application | European Union, Frankfurt am Main | EU-US Data Privacy Framework |
| K1 | Google LLC (Google Analytics, Google Tag Manager, Google Ads) | measurement of website traffic and measurement of the effectiveness of our advertising | United States of America | EU-US Data Privacy Framework |
| K1 | Dub Technologies, Inc. | measurement of referrals in the partner programme | United States of America | standard contractual clauses |
| K1 | Meta Platforms Ireland Limited | processing of uploaded contact lists of prospects and Customers for the purpose of building advertising audiences (this operation only - for the measurement of business events on the website Meta acts as a joint controller under Annex B to this Policy) | United States of America | EU-US Data Privacy Framework |
| K2 | systems that the Customer uses and activates in the settings of the Service; the position of the parties is determined in Annex 2 to the Terms; the list of supported systems is on the Integrations page | connection of the loyalty card to the merchant’s POS system | depending on the particular system | depending on the particular system |
| K3 | systems that the Customer uses and activates in the settings of the Service; the position of the parties is determined in Annex 2 to the Terms; the list of supported systems is on the Integrations page | connection of the loyalty card to the merchant’s booking system | depending on the particular system | depending on the particular system |
| K4 | systems that the Customer uses and activates in the settings of the Service; the position of the parties is determined in Annex 2 to the Terms; the list of supported systems is on the Integrations page | the merchant’s own e-shop or other system connected to the Service | depending on the particular system | depending on the particular system |
| K5 | systems that the Customer uses and activates in the settings of the Service; the position of the parties is determined in Annex 2 to the Terms; the list of supported systems is on the Integrations page | connection of the loyalty card to a partner’s system in which the partner is the controller and we are its further processor | depending on the particular system | depending on the particular system |
| K6 | Google LLC (Gemini) | generation of texts and suggestions when setting up a merchant account, processes exclusively data at the level of the Customer | United States of America | EU-US Data Privacy Framework |
| K6 | Anthropic PBC | fallback generation of texts and logo recognition when setting up a merchant account, processes exclusively data at the level of the Customer | United States of America | being verified |
| K6 | Jina AI GmbH | retrieval of the content of the Customer’s website when setting up an account, processes the web address and the content of the page, not Members’ personal data | Federal Republic of Germany | being verified |
| K6 | Logo.dev | retrieval of the Customer’s logo from its web address, does not process Members’ personal data | United States of America | being verified |
| K7 | Professional advisers | accounting, legal and tax advice and audit | Slovak Republic | no transfer outside the European Economic Area takes place |
In respect of data on business activity on our website that we pass server-side to the Meta platform in order to measure the effectiveness of our advertising, we are joint controllers with Meta under Article 26 GDPR. This annex makes available the essence of our arrangement under Article 26(2) GDPR.
What the joint controllership concerns: business events on our website (for example the submission of an enquiry, registration or a subscription order) and the irreversibly hashed contact identifiers that form part of those events. It concerns exclusively entrepreneurs and persons interested in our Service, never Members of loyalty clubs. Contact lists uploaded under Article 5 of this Policy do not fall under the joint controllership.
Allocation of responsibilities: we are responsible for the legal basis for passing the data, for the scope of the data passed and for informing data subjects under Articles 13 and 14 GDPR. Meta is responsible for the processing of the data within the scope of this annex in its own systems, for its security and for meeting its obligations under its own terms for business tools.
Who to contact: you may exercise your rights under Articles 15 to 22 GDPR with either of the joint controllers. We are the first point of contact, at support@vexioncards.one; we will handle the request within one month and will pass on to the Meta platform whatever falls to it. You may also exercise your rights directly with Meta, in accordance with its privacy policy.
Last updated: 27 September 2026. Previous version, effective from 5 November 2024: Privacy Policy (PDF).