Data Processing Agreement
How Partnely processes personal data for a brand as its processor: instructions, sub-processors, security, breach notice and deletion.
1.Parties and roles
This agreement is between the brand that holds a Partnely brand account (the "controller") and SoMe Innovation ApS, Thulevej 12, 3. th, 9210 Aalborg SØ, Denmark (CVR 42673684), which operates Partnely (the "processor"). It is part of the Brand Terms and applies to all personal data the processor handles for the controller in the course of running the controller's program. Where the processor decides the purpose of processing, for example for its own accounts and billing, it acts as controller under the Privacy Policy and this agreement does not apply.
2.Subject matter and details of processing
- Subject matter: running the controller's affiliate and creator program on the service.
- Duration: the term of the Brand Terms, plus the deletion period below.
- Nature and purpose: recording clicks, matching orders, calculating commission and fees, keeping the ledger, sending PayPal payout requests from the controller's own PayPal account when the controller connects it, paying partners where funded payouts are offered and the controller uses them, sending program emails, and keeping signed agreements.
- Data subjects: the controller's partners; shoppers who click the controller's tracked links or place attributed orders; the controller's staff who use the account; where Instagram Replies is offered and the controller connects an account, the people who comment on or message that account.
- Categories: contact and profile data of partners; click records (click id, one-way hash of the IP address, user agent, referrer, country, landing page); order data (order id and number, subtotal, currency, line items, coupon, hashed customer identifier); commission, payout and agreement records, including the IP address and browser recorded when a partner signs; partners' payout details as the controller sees or exports them (bank details, PayPal account data), with the record of each view and export; where Instagram Replies is offered, the commenter's id, username and text and the replies sent.
3.Instructions
The processor processes personal data only on the controller's documented instructions, which are the Brand Terms, this agreement, the settings the controller makes in the application and the actions it takes there, unless the law requires otherwise, in which case the processor will inform the controller before processing where it may. The processor will tell the controller if it believes an instruction breaks data protection law.
4.Sub-processors
The controller authorises the processor to use the following sub-processors:
- A hosting provider: servers, database and backups, in the European Union.
- Stripe: billing and, where funded payouts are offered, those payouts and payout accounts.
- Resend: transactional and program email.
- Meta Platforms, where Instagram Replies is offered and the controller connects an account: receiving comments and sending replies.
The store platforms and social networks the controller itself connects, and PayPal when the controller connects its own PayPal account to pay partners, act under the controller's own agreements with them. The current list with each sub-processor's legal name and location is available from privacy@partnely.app.
The processor will give the controller at least thirty days' notice by email before adding or replacing a sub-processor. The controller may object on reasonable data protection grounds within that period; if the objection cannot be resolved, the controller may close the store and this agreement ends for it. The processor binds each sub-processor to data protection obligations equivalent to these and remains responsible to the controller for their performance.
5.Security measures
The processor maintains technical and organisational measures appropriate to the risk, including:
- Encryption of data in transit; passwords and API keys stored only as hashes; store connection secrets, PayPal credentials and social access tokens encrypted at rest; partners' payout details encrypted at rest, shown in full only to the partner and to a brand that owes the partner approved commission, and masked everywhere else; shoppers' IP addresses stored only as a one-way hash.
- Access to production systems and backups limited to the people who need it, each with their own credentials and strong authentication.
- Signature verification on store platform webhooks, on PayPal's payout notifications and on the social network's events; repeated events handled once.
- Backups of the database taken at least daily and kept apart from the live system, with restores tested regularly.
- Logging of inbound tracking and webhook events and, where Instagram Replies is offered, of every reply an automation sends, with the outcome.
- Everyone with access to the data bound by confidentiality.
6.Confidentiality
The processor keeps the controller's personal data confidential and ensures that everyone it authorises to process it is bound by confidentiality.
7.Assistance to the controller
The processor helps the controller respond to data subjects' requests (access, correction, deletion, portability, objection) by providing the data it holds within ten working days of a request, and by forwarding to the controller any request it receives directly that concerns the controller's program. The processor also assists with data protection impact assessments and consultations with authorities where they concern the service, at reasonable cost where the work goes beyond what the service already provides.
8.Breach notice
The processor notifies the controller without undue delay, and in any case within seventy-two hours of becoming aware, of a personal data breach affecting the controller's data, by email to the address on the controller's account. The notice describes what happened, the data and people affected as far as they are known, the likely consequences, the measures taken, and a contact at privacy@partnely.app, and is followed up as more is known. The processor documents every breach.
9.Audits
On request, not more than once a year unless an authority requires it or a breach has occurred, the processor provides the information needed to show compliance with this agreement, including summaries of its security measures and any independent reports it holds. Where that is not enough, the controller may audit at its own cost, on thirty days' notice, during business hours, without disrupting the service, and under confidentiality.
10.Deletion at the end of the term
When the store or the account closes, the processor provides an export of the controller's data on request within thirty days and then deletes the personal data it holds for the controller, unless the law requires it to be kept, in which case it keeps only what the law requires and processes it for no other purpose. Copies in backups are overwritten within ninety days. Signed agreements are kept as records for both parties for the period stated in the Privacy Policy; commission and payout records are kept as financial records.
11.International transfers
The processor hosts the controller's data in the European Union. It may transfer personal data to a country outside the European Economic Area only through the sub-processors above and with a lawful transfer mechanism in place, such as the EU-US Data Privacy Framework or standard contractual clauses, and will inform the controller of the countries involved on request.
12.Liability and precedence
Each party's liability under this agreement is subject to the limitation of liability in the Terms of Service, except where data protection law does not allow it to be limited. Where this agreement conflicts with the Terms of Service or the Brand Terms on a data protection matter, this agreement applies.
Data Processing Agreement, version 2026-09-17. Questions: hello@partnely.app.