Data processing agreement (DPA)
Last updated: October 10, 2026
This DPA is part of the terms of service and governs the processing of customer data by Wafly on behalf of the Merchant, as required by law 18-07 of 10 June 2018.
1. Scope
- Subject: provision of the Wafly service. Duration: the contract plus 30 days for data return.
- Data subjects: the Merchant's customers. Data: first name, email, birthday (day and month), loyalty data, preferences and consents, Wallet identifiers, sign-up IP. No sensitive data.
2. Instructions and confidentiality
Wafly processes data only on the Merchant's instructions (terms, DPA, program configuration). Staff are bound by confidentiality; production access is limited and logged.
3. Security measures
- TLS; per-merchant isolation in the database.
- User authentication, hashed till PINs, paired and revocable till devices.
- Signed, replaceable card tokens; rate limiting; two credits per card per day.
- Audit log, regular backups, security updates, data minimisation.
4. Sub-processors
Hosting: [Nom, forme juridique et adresse de l’hébergeur en Algérie], servers in Algeria. Apple (Apple Wallet), Google (Google Wallet, Sign in with Google), Resend (email); where used, Meta (WhatsApp) and an SMS provider. Changes are announced 30 days in advance; the Merchant may object and terminate without fees.
5. Transfers abroad
Providers established abroad (Apple (Apple Wallet), Google (Google Wallet and Sign in with Google), Resend (email) and, where used, Meta (WhatsApp) and an SMS provider) receive only what their service requires. Transfers abroad require ANPDP authorisation (article 44 of law 18-07); the Merchant requests it and Wafly supplies the necessary information.
6. Assistance, breaches, end of contract
- Data subject rights are self-service; Wafly forwards requests it receives and assists.
- Breaches are notified to the Merchant within 48 hours.
- At the end of the contract: 30 days to export, then deletion or anonymisation.
7. Contact
Data protection contact: dpo@wafly.app.