Version 1.1 — 10 August 2026
Unreviewed draft. Not legal advice. This document has been drafted in-house to describe accurately what our platform actually does. It has not been reviewed by a qualified data protection lawyer. It is published so that advertisers can see our commitments in writing rather than wait for a review to conclude.
A qualified legal review is intended before this document is relied upon in a substantial commercial relationship. If your organisation requires a lawyer-reviewed or negotiated DPA, or your own paper, contact privacy@affilitera.com.
A note on how this is written. We have deliberately avoided standard DPA boilerplate. Every obligation below corresponds to something our platform can actually do today, or to a manual process we can genuinely carry out. Where a common DPA commitment is one we cannot yet meet, we say so instead of promising it. We think a contract we can keep is worth more than one that reads better.
This Addendum forms part of the agreement between Affilitera (“we”, “us”, the processor) and the advertiser using our platform (“you”, the controller). It applies to personal data we process on your behalf in connection with your affiliate programme.
It does not apply to personal data for which we are ourselves the controller — principally the account data of our own users, including your staff who hold logins. That processing is described in our Privacy Policy.
Data subjects: visitors to and customers of your storefront who arrive through an affiliate link or use an affiliate discount code.
Categories of personal data. We process the following, and nothing beyond it:
We do not process customer names, email addresses, telephone numbers, postal addresses or payment details. Our Shopify integration does not request permission to read Shopify customer records, and we do not store Shopify webhook payloads. No special-category data under Article 9 is processed.
The following measures are in place today:
What we do not claim. We are not SOC 2 or ISO 27001 certified. We have not commissioned an external penetration test. We do not enforce multi-factor authentication on all accounts. Tenant isolation is enforced in application code rather than by database policy, because our server components connect with a privileged database role; row level security therefore protects against direct external database access, not against an application-layer defect. Role-based permission checks are applied to roughly half of tenant API routes; the remainder rely on account scoping derived from the session. We would rather you knew this.
You authorise the following sub-processors. This list is intended to be exhaustive.
| Sub-processor | Function | Location |
|---|---|---|
| Supabase | Database and file storage | Ireland (EU) |
| Vercel | Application hosting | Dublin, Ireland; one edge route global |
| Cloudflare | Click-tracking service (aftrk.co) | Global edge network |
| Clerk | Authentication for portal logins | United States |
| Stripe | Payment processing | United States / EU |
| Resend | Transactional email | United States |
| Sentry | Error monitoring | United States |
| Amazon Web Services | Report export storage | European Union |
| Svix | Outbound webhook delivery | United States |
| Shopify | Where you use our Shopify app | Global |
| Anthropic | Category text classification (no customer data sent) | United States |
Affiliate networks. Where you choose to run your programme through a third-party affiliate network, that network is also a recipient of data relating to your sales. Which networks apply depends entirely on which you have connected. We transmit only a publisher identifier to them; we do not transmit any shopper identifier. Because an affiliate click is a redirect through the network, the visitor browser discloses its own IP address and user-agent to that network directly. The networks our platform can connect to are listed in your integrations settings, and we will confirm in writing which are active on your account on request.
Changes. We will give you at least 30 days notice by email, to the address on your account, before adding or replacing a sub-processor that processes data on your behalf. If you object on reasonable data protection grounds within that period, we will work with you to find an alternative, and if none is available you may terminate the affected service. We operate this by email rather than through a subscription feed, because email is something we can reliably do.
Our database and our application servers are located in Ireland. Several sub-processors listed above are United States entities or operate global edge networks. Where personal data is transferred outside the European Economic Area we rely on the Standard Contractual Clauses or equivalent safeguards operated by those sub-processors. We have not yet completed our own transfer impact assessment; this is recorded as outstanding work rather than presented as complete.
Report exports stay in the EU. Exported report files are the one place where data we hold would otherwise leave our EU infrastructure, so we have made the EU a condition of the export running at all rather than a setting we intend to keep correct: our export code refuses to write to storage outside the EU, and an export therefore either stays in the EU or does not happen. We are telling you the mechanism rather than just the outcome because the outcome is only as good as the mechanism behind it.
We will assist you in responding to requests from your customers. We want to set a realistic expectation of how that works, because it is manual.
We will also assist you, taking into account the nature of processing and the information available to us, with data protection impact assessments and prior consultation, by answering written questions.
This section states our actual position, which is not the position a standard DPA would assert.
We will notify you without undue delay after becoming aware of a personal data breach affecting data processed on your behalf, and in any event we will aim to do so within 72 hours of becoming aware. We will provide the information available to us at the time, including the nature of the breach, the categories and approximate volume of records concerned, the likely consequences, and the measures taken. Where we cannot provide all of it at once, we will provide it in phases as it becomes available. Notification will be sent by email to the address on your account.
We commit to “without undue delay” rather than a fixed short deadline, and we should be honest about why: the platform is operated by one person and there is no on-call rota. A guaranteed 24-hour notification is not a commitment we could reliably keep, so we are not making it.
You are responsible for providing any notice to, and obtaining any consent from, your customers required for the storage of and access to information on their devices, and for the processing described here. Our tracking does not currently gate itself on a consent signal, so if your jurisdiction requires consent you must configure your own cookie banner or consent management platform so that our tag is only loaded where consent permits. For our Shopify app pixel, Shopify applies your own consent configuration.
All notices under this Addendum, including erasure requests, sub-processor objections and breach correspondence, should be sent to privacy@affilitera.com.