This is a courtesy translation. The legally binding version of this document is the Armenian one. In the event of any discrepancy between this English text and the Armenian original, the Armenian version prevails. Read the Armenian version.
1. DATA CONTROLLER
The controller of the personal data of loyalita's business customers is:
Gurin Dmitrii IE
(individual entrepreneur registered under the laws of the Republic of Armenia)
ΥΥΥΥ (TIN): 1708821015
Address: Yerevan, Republic of Armenia
Website: https://loyalita.am
Contact email: hello@loyalita.am
Phone: +374 55 117479
2. SCOPE
This Policy applies to the processing of the personal data of:
- legal representatives and contact persons of business customers (restaurants, cafΓ©s and other establishments) using the loyalita service;
- the Client's employees and contractors who have access to the admin panel or who deal with us on the Client's behalf;
- people who, on behalf of an organisation, request commercial information, a demonstration or onboarding to the Service.
This Policy does not apply to the data of end users of the loyalty programmes run through loyalita, which are governed by a separate Privacy Policy for users.
3. ALLOCATION OF ROLES
3.1. In respect of the data of the Client's representatives and employees, we act as the controller.
3.2. In respect of the end-customer data the Client transfers to the Platform, the Client is the controller: it independently determines the purposes and legal bases of processing. We process such data solely for the purpose of supplying the Services and in accordance with the Client's instructions β as a processor.
3.3. The Client must ensure there is a lawful basis for collecting its customers' data and transferring it to us, as set out in the Public Offer.
4. CATEGORIES OF DATA WE PROCESS
4.1. Identification and contact data
- First name, surname, position in the organisation.
- Work email address and phone number.
- Organisation name, ΥΥΥΥ and address.
4.2. Account and Platform usage data
- Credentials, roles and access rights in the admin panel.
- History of actions carried out, tariff plan selected and settings.
- IP address, device and browser data, online identifiers.
4.3. Financial and accounting data
- Invoice data, payment history, bank details.
- Data required for tax and accounting records.
4.4. Communications data
- Correspondence with support, enquiries and complaints.
- Requests for a demonstration or a commercial proposal.
5. PURPOSES AND LEGAL BASES FOR PROCESSING
We process the data under the Law of the Republic of Armenia on the Protection of Personal Data, for the following purposes:
- Managing the contractual relationship with the Client: creating the account, granting access to the Platform, servicing the tariff plan β legal basis: performance of a contract.
- Communications and technical support β legal basis: performance of a contract and our legitimate interest.
- Settlements, accounting and compliance with obligations established by law β legal basis: an obligation established by law.
- Informational and commercial messages about the Service (new features, tariff changes, offers) β legal basis: our legitimate interest in respect of existing customers and, for prospective customers, their consent. You may opt out at any time.
- Security and prevention of misuse β legal basis: our legitimate interest.
6. RECIPIENTS OF THE DATA
We may give access to third parties who supply services necessary for the operation of the Service: hosting and technical maintenance, email and notification providers, analytics tools, accounting and payment services. They act solely on our instructions and under the relevant contracts. Data may also be disclosed to state authorities in the cases provided for by law.
7. CROSS-BORDER TRANSFERS
Some of our providers may be located outside the Republic of Armenia. In such cases, transfers are made only to countries recognised by the Personal Data Protection Agency as providing an adequate level of protection, or on the basis of standard contractual clauses approved by the Agency or other mechanisms provided for by law.
8. RETENTION PERIODS
- Account and contract data β for the term of the contract and the applicable limitation period.
- Accounting and tax records β for the periods established by the law of the Republic of Armenia.
- Support correspondence β for a reasonable period after the enquiry is resolved.
- Data for commercial messages β until you opt out.
9. YOUR RIGHTS
Under the Law of the Republic of Armenia on the Protection of Personal Data you have the right to:
- obtain information about the processing of your data and access it;
- request rectification of inaccurate or incomplete data;
- request erasure or blocking of data in the cases provided for by law;
- object to processing, including the receipt of commercial messages;
- withdraw consent at any time.
To exercise these rights, write to hello@loyalita.am or send a letter to Yerevan, Republic of Armenia, marked βPersonal dataβ.
If you consider that your rights have been infringed, you may lodge a complaint with the Personal Data Protection Agency of the Ministry of Justice of the Republic of Armenia.
10. SECURITY
We apply appropriate technical and organisational measures to protect data against destruction, loss, alteration and unauthorised access. In the event of a personal data breach that may pose a risk to rights, we notify the Personal Data Protection Agency within 72 hours of becoming aware of it and inform the Client.
11. CHANGES
We may update this Policy to reflect legislative, technical or business changes. The current version is always available on the website, stating the date of the last update. The Client is separately notified of significant changes.
Related documents: Privacy (users) Β· Terms and Conditions Β· Privacy (business) Β· Public Offer Β· Cookie Policy