Data Processing Addendum

Version 1.1 — 10 August 2026

Unreviewed draft. Not legal advice. This document has been drafted in-house to describe accurately what our platform actually does. It has not been reviewed by a qualified data protection lawyer. It is published so that advertisers can see our commitments in writing rather than wait for a review to conclude.

A qualified legal review is intended before this document is relied upon in a substantial commercial relationship. If your organisation requires a lawyer-reviewed or negotiated DPA, or your own paper, contact privacy@affilitera.com.

A note on how this is written. We have deliberately avoided standard DPA boilerplate. Every obligation below corresponds to something our platform can actually do today, or to a manual process we can genuinely carry out. Where a common DPA commitment is one we cannot yet meet, we say so instead of promising it. We think a contract we can keep is worth more than one that reads better.

1. Parties and scope

This Addendum forms part of the agreement between Affilitera (“we”, “us”, the processor) and the advertiser using our platform (“you”, the controller). It applies to personal data we process on your behalf in connection with your affiliate programme.

It does not apply to personal data for which we are ourselves the controller — principally the account data of our own users, including your staff who hold logins. That processing is described in our Privacy Policy.

2. Subject matter, duration, nature and purpose

  • Subject matter: attribution of sales made on your storefront to the publishers who referred them, and the calculation of commission arising from those sales.
  • Duration: for as long as you use the platform, and thereafter as set out in section 9.
  • Nature of processing: collection of click and conversion events, storage, matching of conversions to clicks, aggregation into reporting, and transmission to and from affiliate networks where you use one.
  • Purpose: operating your affiliate programme and paying the correct publisher.

3. Categories of data subjects and personal data

Data subjects: visitors to and customers of your storefront who arrive through an affiliate link or use an affiliate discount code.

Categories of personal data. We process the following, and nothing beyond it:

  • A randomly generated click identifier and a randomly generated visitor identifier.
  • A SHA-256 hash of the visitor IP address. This is pseudonymous, not anonymous, and we treat it as personal data.
  • Browser user-agent string and referring URL.
  • Country, derived from IP at our edge network.
  • Order identifier, order value, currency, discount code used, and for single-item orders the product SKU and category.
  • Where you run your programme through a third-party affiliate network, whatever that network returns to us about the sale, which may include a hashed IP, country, device type and new-versus-returning customer status.

We do not process customer names, email addresses, telephone numbers, postal addresses or payment details. Our Shopify integration does not request permission to read Shopify customer records, and we do not store Shopify webhook payloads. No special-category data under Article 9 is processed.

4. Our obligations

  • We process personal data only on your documented instructions. Your configuration of the platform, and this Addendum, constitute those instructions.
  • We will tell you if, in our opinion, an instruction infringes data protection law.
  • Personnel with access to personal data are bound by confidentiality. At present the platform is operated by a very small team, and access is limited to those operating it.
  • We will not sell personal data, and will not use data processed on your behalf to build profiles for our own commercial purposes unconnected with attribution.
  • We will make available the information reasonably necessary to demonstrate compliance with this Addendum, and will contribute to audits by responding to written questions. We do not currently host on-site audits or hold a third-party audit report to offer in place of one.

5. Security measures

The following measures are in place today:

  • Encryption in transit: TLS on all connections.
  • Encryption at rest: provided by our database host for the database as a whole.
  • Application-level encryption: AES-256-GCM, with separated keys, for taxpayer identification numbers, affiliate payout and billing details, platform secrets, and all third-party access tokens including Shopify access tokens.
  • Database access control: row level security is enabled on every table in the production database, which denies direct access using public API keys.
  • Credential handling: tenant API keys are stored only as SHA-256 hashes; administrator passwords only as bcrypt hashes.
  • Audit logging: privileged administrative actions are written to an append-only log which the database itself prevents from being updated or deleted.
  • Webhook authenticity: inbound Shopify webhooks are HMAC-verified before any header is trusted, and replayed deliveries are suppressed.

What we do not claim. We are not SOC 2 or ISO 27001 certified. We have not commissioned an external penetration test. We do not enforce multi-factor authentication on all accounts. Tenant isolation is enforced in application code rather than by database policy, because our server components connect with a privileged database role; row level security therefore protects against direct external database access, not against an application-layer defect. Role-based permission checks are applied to roughly half of tenant API routes; the remainder rely on account scoping derived from the session. We would rather you knew this.

6. Sub-processors

You authorise the following sub-processors. This list is intended to be exhaustive.

Sub-processorFunctionLocation
SupabaseDatabase and file storageIreland (EU)
VercelApplication hostingDublin, Ireland; one edge route global
CloudflareClick-tracking service (aftrk.co)Global edge network
ClerkAuthentication for portal loginsUnited States
StripePayment processingUnited States / EU
ResendTransactional emailUnited States
SentryError monitoringUnited States
Amazon Web ServicesReport export storageEuropean Union
SvixOutbound webhook deliveryUnited States
ShopifyWhere you use our Shopify appGlobal
AnthropicCategory text classification (no customer data sent)United States

Affiliate networks. Where you choose to run your programme through a third-party affiliate network, that network is also a recipient of data relating to your sales. Which networks apply depends entirely on which you have connected. We transmit only a publisher identifier to them; we do not transmit any shopper identifier. Because an affiliate click is a redirect through the network, the visitor browser discloses its own IP address and user-agent to that network directly. The networks our platform can connect to are listed in your integrations settings, and we will confirm in writing which are active on your account on request.

Changes. We will give you at least 30 days notice by email, to the address on your account, before adding or replacing a sub-processor that processes data on your behalf. If you object on reasonable data protection grounds within that period, we will work with you to find an alternative, and if none is available you may terminate the affected service. We operate this by email rather than through a subscription feed, because email is something we can reliably do.

7. International transfers

Our database and our application servers are located in Ireland. Several sub-processors listed above are United States entities or operate global edge networks. Where personal data is transferred outside the European Economic Area we rely on the Standard Contractual Clauses or equivalent safeguards operated by those sub-processors. We have not yet completed our own transfer impact assessment; this is recorded as outstanding work rather than presented as complete.

Report exports stay in the EU. Exported report files are the one place where data we hold would otherwise leave our EU infrastructure, so we have made the EU a condition of the export running at all rather than a setting we intend to keep correct: our export code refuses to write to storage outside the EU, and an export therefore either stays in the EU or does not happen. We are telling you the mechanism rather than just the outcome because the outcome is only as good as the mechanism behind it.

8. Assistance with data subject requests

We will assist you in responding to requests from your customers. We want to set a realistic expectation of how that works, because it is manual.

  • We cannot identify a shopper from the data we hold. We hold no customer name or email address. To locate records we need an identifier we do hold — an order identifier, a discount code plus date range, or our click identifier. Please include one when you contact us.
  • Given such an identifier, we will locate, export or delete the corresponding click and conversion records. Our operator does this from an internal console that shows what would be affected before anything is removed and records what was done. There is no self-service tool for you and no endpoint you can call; the request comes to us and a person carries it out.
  • Timescale: we will acknowledge within 5 working days and complete the action within 30 days of receiving a request containing a usable identifier. We commit to 30 days rather than a shorter period because this is manual work performed by a very small team.
  • Shopify privacy webhooks. We expose the three mandatory endpoints — customer data request, customer redaction and shop redaction — and they verify authenticity and act on the request. A customer redaction deletes the unconfirmed conversion records for the order identifiers given, removes the shopper-derived fields from confirmed ones, follows our click identifier onward and clears the visitor fields on the corresponding click record, and deletes any related discount-code signal. A shop redaction does the same for the whole shop and additionally erases our stored access token for it. A customer data request is recorded as a dated task and answered within the 30 days stated above, rather than answered automatically, because we hold no address to send a shopper’s data to.
  • What a redaction does not remove. Order identifiers and click identifiers survive on commission, invoice and payout records. Those records are the account of what was earned and paid, they are subject to tax retention, and other people’s earnings are calculated from them, so they are deliberately excluded from erasure — see section 9. The identifiers that remain there are not linked to any name, email address or other contact detail, because we hold none.

We will also assist you, taking into account the nature of processing and the information available to us, with data protection impact assessments and prior consultation, by answering written questions.

9. Deletion and return on termination

This section states our actual position, which is not the position a standard DPA would assert.

  • On termination, we will delete the click and conversion records we hold on your behalf within 90 days of your written request. We commit to 90 days, and to it being triggered by your request, because the deletion is performed manually. We do not currently operate any automated retention or expiry mechanism, and we are not going to write a clause implying that we do.
  • You may request an export of the records we hold on your behalf at any time, including on termination, and we will provide it in a machine-readable format within 30 days.
  • What we retain regardless. Commission, invoice and payout records are retained indefinitely and are deliberately excluded from deletion. They are the record of what was earned and paid between you, us and publishers, and both tax law and the integrity of publisher earnings require them. Where these contain personal data it is limited to identifiers already described.
  • Uninstalling our Shopify app immediately revokes and erases our stored access token for your shop. It does not by itself delete the order records described above; use the request route in the first bullet.
  • Backups. Deleted data may persist in our hosting provider backups until those backups expire on the provider schedule. We do not selectively edit backups.

10. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting data processed on your behalf, and in any event we will aim to do so within 72 hours of becoming aware. We will provide the information available to us at the time, including the nature of the breach, the categories and approximate volume of records concerned, the likely consequences, and the measures taken. Where we cannot provide all of it at once, we will provide it in phases as it becomes available. Notification will be sent by email to the address on your account.

We commit to “without undue delay” rather than a fixed short deadline, and we should be honest about why: the platform is operated by one person and there is no on-call rota. A guaranteed 24-hour notification is not a commitment we could reliably keep, so we are not making it.

11. Consent and your responsibilities

You are responsible for providing any notice to, and obtaining any consent from, your customers required for the storage of and access to information on their devices, and for the processing described here. Our tracking does not currently gate itself on a consent signal, so if your jurisdiction requires consent you must configure your own cookie banner or consent management platform so that our tag is only loaded where consent permits. For our Shopify app pixel, Shopify applies your own consent configuration.

12. Contact

All notices under this Addendum, including erasure requests, sub-processor objections and breach correspondence, should be sent to privacy@affilitera.com.