Data Processing Agreement

Last updated: May 29, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between PromoteKit ("PromoteKit", "we", "us", or "Processor") and the customer ("Customer", "you", or "Controller") that uses the PromoteKit affiliate marketing platform (the "Services"). It reflects the parties' agreement with regard to the Processing of Personal Data in compliance with the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") and other applicable data protection laws.

1. Definitions

Capitalized terms not defined here have the meaning given to them in the GDPR. For the purposes of this DPA:

  • "Personal Data" means any information relating to an identified or identifiable natural person that is Processed by PromoteKit on behalf of the Customer in connection with the Services.
  • "Data Subject" means the individual to whom Personal Data relates, including affiliates, referred users, and end customers.
  • "Processing" means any operation performed on Personal Data, such as collection, storage, use, disclosure, or deletion.
  • "Controller", "Processor", "Sub-processor", and "Supervisory Authority" have the meanings given in the GDPR.
  • "Standard Contractual Clauses" or "SCCs" means the clauses adopted by the European Commission for the transfer of Personal Data to third countries.

2. Roles of the Parties

The Customer is the Controller and PromoteKit is the Processor with respect to the Personal Data Processed under the Services. PromoteKit will Process Personal Data only on the documented instructions of the Customer, including as set out in this DPA and the underlying agreement, unless required to do otherwise by applicable law.

The Customer is responsible for ensuring it has a valid legal basis for the Processing and that its instructions to PromoteKit comply with applicable data protection laws.

3. Scope and Details of Processing

The subject matter, duration, nature, and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are described in Annex 1 (Details of Processing) below.

PromoteKit will Process Personal Data for the duration of the agreement and only to the extent necessary to provide the Services, including affiliate tracking, referral attribution, commission calculation, and payout processing.

4. Obligations of PromoteKit

PromoteKit shall:

  • Process Personal Data only on documented instructions from the Customer, including with regard to transfers of Personal Data to a third country, unless required to do so by law (in which case PromoteKit shall inform the Customer of that legal requirement before Processing, unless prohibited by law).
  • Ensure that persons authorized to Process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex 2 (Security Measures).
  • Respect the conditions for engaging Sub-processors set out in Section 5.
  • Taking into account the nature of the Processing, assist the Customer by appropriate technical and organizational measures, insofar as possible, in responding to requests from Data Subjects exercising their rights under the GDPR.
  • Assist the Customer in ensuring compliance with its obligations regarding security, breach notification, data protection impact assessments, and prior consultation with Supervisory Authorities.
  • At the choice of the Customer, delete or return all Personal Data after the end of the provision of the Services, as set out in Section 9.
  • Make available to the Customer all information necessary to demonstrate compliance with the obligations set out in Article 28 of the GDPR and allow for and contribute to audits as set out in Section 8.

5. Sub-processors

The Customer provides a general authorization for PromoteKit to engage Sub-processors to Process Personal Data in connection with the Services. A current list of Sub-processors is set out in Annex 3 (Sub-processors).

PromoteKit will impose data protection obligations on its Sub-processors that are no less protective than those set out in this DPA. PromoteKit remains liable to the Customer for the performance of each Sub-processor's obligations.

PromoteKit will inform the Customer of any intended changes concerning the addition or replacement of Sub-processors, giving the Customer the opportunity to object to such changes on reasonable data protection grounds.

6. Data Subject Rights

PromoteKit will, to the extent legally permitted, promptly notify the Customer if it receives a request from a Data Subject to exercise their rights of access, rectification, erasure, restriction, portability, objection, or the right not to be subject to automated decision-making.

PromoteKit will not respond to such a request itself, except on the documented instructions of the Customer or as required by applicable law. Taking into account the nature of the Processing, PromoteKit will provide reasonable assistance to enable the Customer to respond to such requests.

7. Personal Data Breach

PromoteKit will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting the Customer's Personal Data. Such notification will include, to the extent available, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach.

PromoteKit will cooperate with the Customer and take reasonable steps to assist in the investigation, mitigation, and remediation of each such breach.

8. Audits

PromoteKit will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.

To the extent permitted, the Customer agrees that audits may be satisfied through the provision of relevant certifications, third-party audit reports, or written responses to a reasonable security questionnaire. Audits will be conducted on reasonable prior notice, during regular business hours, and in a manner that does not unreasonably disrupt PromoteKit's operations.

9. Return and Deletion of Personal Data

Upon termination or expiry of the agreement, PromoteKit will, at the Customer's choice, delete or return all Personal Data Processed on behalf of the Customer and delete existing copies, unless applicable law requires storage of the Personal Data.

PromoteKit may retain Personal Data to the extent and for the period required by applicable law, provided that it ensures the confidentiality of such Personal Data and Processes it only as necessary for the purposes specified by that law.

10. International Transfers

PromoteKit will not transfer Personal Data to a country outside the European Economic Area, the United Kingdom, or Switzerland unless it has taken appropriate safeguards as required by applicable data protection law.

Where required, the parties agree that the Standard Contractual Clauses are incorporated into and form part of this DPA and will apply to transfers of Personal Data from the EEA, UK, or Switzerland to a third country that has not received an adequacy decision.

11. Liability and Term

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the underlying agreement. This DPA will remain in effect for as long as PromoteKit Processes Personal Data on behalf of the Customer.

In the event of a conflict between this DPA and the underlying agreement, this DPA will prevail with respect to the Processing of Personal Data.

Annex 1 — Details of Processing

  • Subject matter of Processing: Provision of the PromoteKit affiliate marketing platform to the Customer.
  • Duration of Processing: For the term of the agreement and until deletion or return of Personal Data in accordance with this DPA.
  • Nature and purpose of Processing: Affiliate registration and management, referral tracking and attribution, commission calculation, payout processing, analytics, and related support.
  • Categories of Data Subjects: The Customer's affiliates, referred users, and end customers.
  • Types of Personal Data: Names, email addresses, account identifiers, payout details (e.g. PayPal or Wise account information), referral and conversion data, IP addresses, and transaction metadata received from Stripe.
  • Special categories of data: PromoteKit does not intentionally Process special categories of Personal Data.

Annex 2 — Security Measures

PromoteKit implements and maintains appropriate technical and organizational measures designed to protect Personal Data, including:

  • Encryption of Personal Data in transit (TLS) and at rest.
  • Access controls and the principle of least privilege for personnel and systems.
  • Row-level security and organization-scoped data isolation within the platform.
  • Authentication controls, including support for secure sign-in methods.
  • Logging and monitoring of access to production systems.
  • Regular review of security practices and use of reputable infrastructure and Sub-processors.
  • Measures to ensure the ongoing confidentiality, integrity, availability, and resilience of Processing systems.

Annex 3 — Sub-processors

PromoteKit uses the following Sub-processors to provide the Services. Each Sub-processor is bound by data protection obligations consistent with this DPA.

  • Stripe — payment processing and subscription/transaction data.
  • Supabase — database hosting and authentication.
  • Vercel — application hosting and content delivery.
  • PayPal and Wise — affiliate payout processing.
  • Postmark — transactional email and notification delivery.
  • Intercom — customer chat support.

Contact

To request a signed copy of this DPA, raise a data protection question, or notify us of a concern, please contact us at hello@promotekit.com.