Last updated: May 29, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between PromoteKit ("PromoteKit", "we", "us", or "Processor") and the customer ("Customer", "you", or "Controller") that uses the PromoteKit affiliate marketing platform (the "Services"). It reflects the parties' agreement with regard to the Processing of Personal Data in compliance with the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") and other applicable data protection laws.
Capitalized terms not defined here have the meaning given to them in the GDPR. For the purposes of this DPA:
The Customer is the Controller and PromoteKit is the Processor with respect to the Personal Data Processed under the Services. PromoteKit will Process Personal Data only on the documented instructions of the Customer, including as set out in this DPA and the underlying agreement, unless required to do otherwise by applicable law.
The Customer is responsible for ensuring it has a valid legal basis for the Processing and that its instructions to PromoteKit comply with applicable data protection laws.
The subject matter, duration, nature, and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are described in Annex 1 (Details of Processing) below.
PromoteKit will Process Personal Data for the duration of the agreement and only to the extent necessary to provide the Services, including affiliate tracking, referral attribution, commission calculation, and payout processing.
PromoteKit shall:
The Customer provides a general authorization for PromoteKit to engage Sub-processors to Process Personal Data in connection with the Services. A current list of Sub-processors is set out in Annex 3 (Sub-processors).
PromoteKit will impose data protection obligations on its Sub-processors that are no less protective than those set out in this DPA. PromoteKit remains liable to the Customer for the performance of each Sub-processor's obligations.
PromoteKit will inform the Customer of any intended changes concerning the addition or replacement of Sub-processors, giving the Customer the opportunity to object to such changes on reasonable data protection grounds.
PromoteKit will, to the extent legally permitted, promptly notify the Customer if it receives a request from a Data Subject to exercise their rights of access, rectification, erasure, restriction, portability, objection, or the right not to be subject to automated decision-making.
PromoteKit will not respond to such a request itself, except on the documented instructions of the Customer or as required by applicable law. Taking into account the nature of the Processing, PromoteKit will provide reasonable assistance to enable the Customer to respond to such requests.
PromoteKit will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting the Customer's Personal Data. Such notification will include, to the extent available, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach.
PromoteKit will cooperate with the Customer and take reasonable steps to assist in the investigation, mitigation, and remediation of each such breach.
PromoteKit will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.
To the extent permitted, the Customer agrees that audits may be satisfied through the provision of relevant certifications, third-party audit reports, or written responses to a reasonable security questionnaire. Audits will be conducted on reasonable prior notice, during regular business hours, and in a manner that does not unreasonably disrupt PromoteKit's operations.
Upon termination or expiry of the agreement, PromoteKit will, at the Customer's choice, delete or return all Personal Data Processed on behalf of the Customer and delete existing copies, unless applicable law requires storage of the Personal Data.
PromoteKit may retain Personal Data to the extent and for the period required by applicable law, provided that it ensures the confidentiality of such Personal Data and Processes it only as necessary for the purposes specified by that law.
PromoteKit will not transfer Personal Data to a country outside the European Economic Area, the United Kingdom, or Switzerland unless it has taken appropriate safeguards as required by applicable data protection law.
Where required, the parties agree that the Standard Contractual Clauses are incorporated into and form part of this DPA and will apply to transfers of Personal Data from the EEA, UK, or Switzerland to a third country that has not received an adequacy decision.
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the underlying agreement. This DPA will remain in effect for as long as PromoteKit Processes Personal Data on behalf of the Customer.
In the event of a conflict between this DPA and the underlying agreement, this DPA will prevail with respect to the Processing of Personal Data.
PromoteKit implements and maintains appropriate technical and organizational measures designed to protect Personal Data, including:
PromoteKit uses the following Sub-processors to provide the Services. Each Sub-processor is bound by data protection obligations consistent with this DPA.
To request a signed copy of this DPA, raise a data protection question, or notify us of a concern, please contact us at hello@promotekit.com.