Data Processing Agreement
Effective Date: July 24, 2026
Download as PDF
Fill in your details, then download a completed copy for your records. Your information stays in your browser and is never sent to Affiliateo.
Stores a visitor ID and the referring affiliate code in the visitor's browser localStorage so we can attribute returning visits and conversions to the correct affiliate. Treated the same as cookies under GDPR / ePrivacy law. The downloaded file reflects the option selected above.
Introduction
This Data Processing Agreement ("DPA") is between NGSMEDIA LLC (trading as "Affiliateo") and the customer entity that has accepted Affiliateo's Terms of Service ("Customer"). This DPA forms part of the Terms of Service and governs how Affiliateo processes personal data on Customer's behalf when Customer installs the Affiliateo tracking script, mobile SDK, or any equivalent integration provided by Affiliateo (the "Service").
By accepting the Terms of Service and using the Service, Customer agrees to this DPA. Capitalized terms not defined here have the meaning given to them in the Terms of Service or in the EU General Data Protection Regulation 2016/679 ("GDPR") and the UK General Data Protection Regulation and Data Protection Act 2018 ("UK GDPR").
Contents
- 1. Key Terms
- 2. Scope of Processing
- 3. Roles and Responsibilities
- 4. Data Retention
- 5. Subprocessors
- 6. International Data Transfers
- 7. Security Measures
- 8. Data Subject Requests
- 9. Data Access and Exports
- 10. Breach Notification
- 11. Audits
- 12. Termination and Deletion
- 13. Governing Law
- 14. Contact
1. Key Terms
Controller
That's Customer. Customer decides what data is collected through the Service and the purposes for which it is processed (Customer's visitors, Customer's website or application).
Processor
That's Affiliateo. Affiliateo processes personal data only to provide Customer with affiliate attribution, analytics, payouts, and related features.
Subprocessor
Third-party vendors that Affiliateo engages to help process personal data on Customer's behalf (for example, infrastructure providers). Affiliateo remains responsible for its subprocessors.
Personal Data
Information relating to an identified or identifiable natural person, as defined in GDPR Article 4(1) and UK GDPR. For the Service, this typically includes IP address, user agent, persistent device identifiers, approximate geolocation, and page activity for Customer's visitors.
2. Scope of Processing
When Customer installs the Affiliateo tracking script or mobile SDK on its websites or applications, Affiliateo collects and processes the following categories of personal data on Customer's behalf:
- •IP address, user agent string, browser family, device type, and operating system.
- •Approximate geolocation derived from IP address (country, region, and city, with latitude and longitude rounded to roughly 1 km).
- •Persistent identifiers stored on the visitor's device (in browser
localStoragefor web, in equivalent on-device storage for mobile apps), including a randomly generated visitor ID, the referring affiliate code, the app ID, and Apple/Google in-app purchase attribution tokens where applicable. - •Page or screen activity, referrer URL, UTM parameters, and session timing.
- •Payment metadata that Customer sends to Affiliateo at conversion time (for example, the affiliate reference embedded in Stripe checkout metadata) so that the correct affiliate can be credited.
Affiliateo processes this data exclusively to:
- •Attribute clicks, signups, and purchases to the affiliate that referred them.
- •Generate analytics, dashboards, funnels, and reports for Customer.
- •Calculate, process, and pay out affiliate commissions on Customer's behalf.
- •Detect and prevent fraud, abuse, and security incidents affecting the Service.
Affiliateo will not use Customer's data for Affiliateo's own marketing or profiling, and will never sell Customer's data. Affiliateo will not disclose Customer's data to any third party except: (a) to the subprocessors listed in Section 5; (b) to the advertising platforms listed in Section 5.1, and then only where Customer has connected an advertising account and only to report Customer's own conversions back to Customer's own advertising account; and (c) as required by law.
Conversion reporting to advertising platforms
Where Customer connects a Meta, TikTok, Google, or Apple advertising account to the Service, Affiliateo reports Customer's recorded sales to that platform from Affiliateo's servers, so that Customer can measure Customer's own advertising. This is processing carried out on Customer's instruction, and connecting the advertising account constitutes that instruction. Each report contains the transaction amount and currency, the product name, the Affiliateo visitor identifier, the visitor user agent, and the advertising click identifier that the platform itself placed in the landing-page URL. For Meta, coarse geographic fields are additionally sent in one-way hashed form.
Affiliateo does not transmit end-user email addresses, names, telephone numbers, postal addresses, or IP addresses to any advertising platform, and does not upload customer lists, contact records, or hashed audience files to any advertising platform. The advertising platforms act as independent controllers of what they receive. Customer is responsible for establishing a lawful basis and, where required, obtaining consent for this reporting, on the same terms as Section 3. Customer may disable it at any time by disconnecting the advertising account.
3. Roles and Responsibilities
Customer Responsibilities (Controller)
- •Establish and document a lawful basis under GDPR Article 6 (or equivalent law) for processing visitor data through the Service.
- •Where required by the EU ePrivacy Directive (Article 5(3)), the UK Privacy and Electronic Communications Regulations, or any equivalent law, obtain valid consent from visitors located in the EU, EEA, UK, or other applicable jurisdictions before the tracking script or SDK loads on their device. The Service writes persistent identifiers to the visitor's device and is treated under those laws the same as analytics tools such as Google Analytics or Meta Pixel.
- •Maintain a privacy notice on Customer's own website or application that accurately describes the Service, the categories of personal data collected, and Affiliateo's role as a processor.
- •Handle data-subject access, correction, deletion, restriction, portability, and objection requests received from Customer's visitors. Affiliateo will reasonably assist where the relevant data is held only by Affiliateo.
- •Comply with all applicable data protection laws in Customer's capacity as controller.
Affiliateo Responsibilities (Processor)
- •Process Customer's personal data only on Customer's documented instructions, which are deemed to include the Terms of Service, this DPA, and Customer's configuration of the Service.
- •Ensure personnel authorized to process Customer's personal data are bound by confidentiality obligations.
- •Implement and maintain appropriate technical and organizational security measures (Section 7).
- •Reasonably assist Customer in meeting Customer's obligations under data protection law, including responses to data-subject requests, security incidents, and impact assessments.
- •Not engage subprocessors without prior general authorization, and remain responsible for the performance of subprocessors.
4. Data Retention
Affiliateo retains personal data processed on Customer's behalf only for as long as necessary to provide the Service and to meet legal obligations. Specific retention periods are documented in the Privacy Policy. In summary:
Affiliate click records
90 days, then automatically deleted.
Pageview and session events
90 days, then automatically deleted.
Web visitor profiles
180 days, sized to support the affiliate attribution window plus a safety buffer.
Mobile app visitors
90 days, unless the record has been matched to an affiliate click or carries an advertising source. Records in either of those categories are retained for the life of the app so that a later renewal, refund, or advertising conversion can still be attributed to the correct affiliate.
Checkout views and advertising conversions
Retained for the life of the app, for the same attribution reason.
Aggregate daily click totals
Retained indefinitely for reporting. These contain no device or network identifiers.
Customer account data
Retained until Customer deletes the account or requests deletion, subject to records Affiliateo is required to keep by law (for example, transaction records for tax and accounting).
Customer may request earlier deletion of specific records at any time by contacting support@affiliateo.com.
5. Subprocessors
Affiliateo engages the following subprocessors to provide the Service. The same list is published standalone at affiliateo.com/subprocessors so that changes can be watched without re-reading this agreement.
Supabase
United StatesDatabase, authentication, and storage.
Cloudflare
Global edge networkHosting, CDN, edge compute (Workers), DDoS and bot protection, R2 object storage, Turnstile bot challenge, and transactional email sending.
Stripe
United StatesPayment processing, merchant onboarding (Express accounts), and affiliate payouts. Stripe acts as a separate controller for some payment data.
Apple App Store / Google Play
United StatesIn-app purchase processing and server-to-server notifications for mobile-affiliate apps.
Amazon Web Services
United StatesOptional identity verification only, via Amazon Textract (identity-document reading) and Amazon Rekognition (one-to-one facial comparison). Applies to Affiliateo account holders who choose to verify, not to a customer’s end users. Images are processed transiently and are not retained by Affiliateo.
RevenueCat
United StatesMobile in-app purchase webhook relay, where the customer has connected a mobile-affiliate app to RevenueCat.
Paddle, Polar, Shopify, Whop, and WooCommerce
United States and European Union, by providerAlternative web commerce and payment providers. Each is used only where the customer connects that specific provider to an app, and only to receive the sale notifications needed to attribute a commission.
5.1 Advertising platforms (independent controllers, not subprocessors)
The following receive data from Affiliateo but are not subprocessors, because they process what they receive for their own purposes under their own terms rather than solely on Affiliateo's instructions. They receive Customer data only where Customer has connected the corresponding advertising account, and only as described in Section 2 under "Conversion reporting to advertising platforms."
Meta Platforms, TikTok, and Google
United StatesServer-side conversion reporting into the customer’s own advertising account, so the customer can measure their advertising. Meta additionally receives data about visitors to affiliateo.com for Affiliateo’s own advertising, which is Affiliateo’s processing as a controller and does not involve customer data.
Apple (Apple Search Ads)
United StatesInstall attribution for a customer’s mobile apps, where the customer has connected an Apple Search Ads account.
Affiliateo may engage additional or replacement subprocessors. Material changes to this list will be reflected on this page. Customer may object to a new subprocessor on reasonable data-protection grounds by contacting support@affiliateo.com within 30 days of the change.
6. International Data Transfers
Affiliateo's infrastructure and the majority of its subprocessors are located outside the European Economic Area, primarily in the United States. Personal data of EU, EEA, and UK residents will therefore be transferred internationally.
Where required, Affiliateo relies on the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, together with the equivalent commitments made by its subprocessors, to safeguard such transfers. By accepting this DPA, Customer authorizes Affiliateo to enter into the SCCs with subprocessors on Customer's behalf where required to enable the Service.
7. Security Measures
Affiliateo implements appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, including:
- •Encryption of data in transit using TLS 1.2 or higher across all public endpoints.
- •Encryption of data at rest via Affiliateo's infrastructure providers (Supabase, Cloudflare R2).
- •Row-level security policies enforced by the database so that Customer data is isolated and only accessible to authorized roles.
- •Role-based access controls limiting administrative access to authorized Affiliateo personnel.
- •Rate limiting, bot detection (Cloudflare Turnstile), and signed webhook verification on financial endpoints.
- •Regular automated backups maintained by the database provider.
- •Hosting with vendors that maintain industry-recognized security certifications (SOC 2, ISO 27001, or equivalent).
8. Data Subject Requests
As controller, Customer is responsible for responding to requests from its visitors to exercise their rights under GDPR Articles 15-22 or equivalent law (access, rectification, erasure, restriction, portability, and objection).
Affiliateo will provide reasonable assistance, taking into account the nature of the processing, by making available to Customer the visitor data held by Affiliateo and by deleting specific records on Customer's instruction. Requests may be sent to support@affiliateo.com.
9. Data Access and Exports
Affiliateo provides Customer with access to the personal data processed on Customer's behalf through its dashboard. Exports reflect the data as stored by the Service. Affiliateo does not provide consolidated archive exports or raw event logs beyond what is retained in the Service.
10. Breach Notification
Affiliateo will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer's data and will provide Customer with the information reasonably necessary to enable Customer to comply with its own notification obligations under GDPR Article 33 or equivalent law.
11. Audits
Affiliateo will, on Customer's reasonable written request and no more than once per twelve-month period (except where required by a supervisory authority), provide Customer with information necessary to demonstrate compliance with this DPA. This may take the form of subprocessor attestations, summaries of security controls, or written responses to a reasonable questionnaire.
12. Termination and Deletion
On termination of the Terms of Service, Affiliateo will, at Customer's choice, return or delete the personal data processed on Customer's behalf, except where retention is required by law (for example, transaction records for tax and accounting). Deletion of app data, analytics, and visitor records follows the retention windows set out in Section 4.
12.1 California Addendum (CCPA/CPRA)
This Section applies where Customer is a "business" and Affiliateo processes "personal information" of California residents on Customer's behalf, each as defined in the California Consumer Privacy Act as amended by the California Privacy Rights Act and its implementing regulations (together, the "CCPA"). Terms used in this Section have the meanings given to them in the CCPA.
Service provider status
Affiliateo acts as a service provider to Customer. Customer discloses personal information to Affiliateo only for the limited and specified business purposes set out in Section 2 of this DPA. Affiliateo certifies that it understands the restrictions in this Section and will comply with them.
Restrictions Affiliateo accepts
- •Affiliateo will not sell or share personal information received from Customer, as "sell" and "share" are defined in the CCPA.
- •Affiliateo will not retain, use, or disclose that personal information for any purpose other than the business purposes specified in this DPA, including outside the direct business relationship between Affiliateo and Customer, except where the CCPA permits it.
- •Affiliateo will not combine that personal information with personal information it receives from, or on behalf of, any other person, or collects from its own interactions with consumers, except as the CCPA permits a service provider to do.
- •Affiliateo will impose these same obligations on any subprocessor it engages, by written contract.
- •Affiliateo will notify Customer promptly if it determines it can no longer meet these obligations, and will cooperate with Customer to remediate unauthorized use.
Conversion reporting is Customer's sharing, not Affiliateo's
The advertising conversion reporting described in Section 2 and Section 5.1 is carried out at Customer's direction, into Customer's own advertising accounts. To the extent that reporting constitutes "sharing" for cross-context behavioral advertising under the CCPA, Customer is the business responsible for it, including for providing any required notice and honoring any opt-out or opt-out preference signal. Customer may stop it at any time by disconnecting the advertising account.
Consumer rights and audit
Affiliateo will assist Customer in responding to verifiable consumer requests to know, delete, correct, opt out, and limit, as described in Section 8. Customer may take reasonable and appropriate steps under Section 11 to confirm that Affiliateo is using the personal information consistently with Customer's obligations under the CCPA.
13. Governing Law
This DPA is governed by the laws of the State of Wyoming, United States, without regard to its conflict-of-law principles, and is incorporated into and subject to the dispute-resolution provisions of the Terms of Service. Where EU or UK data protection law applies, the EU Standard Contractual Clauses and UK International Data Transfer Addendum take precedence to the extent of any conflict in respect of restricted international transfers.
14. Contact
Questions about this DPA or requests related to data protection may be sent to:
NGSMEDIA LLC
312 W 2nd St 4192
Casper, WY 82601
Email: support@affiliateo.com
Website: affiliateo.com
By using the Service, Customer agrees to this DPA.