Data Processing Addendum

Last updated: 31 August 2026

For DPA questions or a countersigned copy, contact support@referly.so.

Effective Date: 31.08.2026

This Data Processing Addendum (the “DPA”) forms part of the agreement governing Customer's use of the Referly services, including any applicable order form and the Referly Terms of Use (collectively, the “Agreement”). It is entered into between Referly Technologies, LLC, a Delaware limited liability company with an address at 1207 Delaware Ave #3648, Wilmington, DE 19806, United States (“Referly”), and the customer identified in the Agreement or its Referly account (“Customer”). Referly and Customer are each a “Party” and together the “Parties.”

This DPA applies only to Customer Personal Data processed by Referly on behalf of Customer in providing the Services. It does not govern processing for which Referly acts as an independent controller, as described in Schedule 5 and the applicable Referly privacy notice.

1. Scope, incorporation and order of precedence

1.1 This DPA is incorporated into the Agreement and applies where Applicable Data Protection Law requires a written contract between a controller and processor or between a processor and subprocessor.

1.2 If Customer determines the purposes and means of the relevant processing, Customer acts as Controller and Referly acts as Processor. If Customer processes the relevant personal data on behalf of another Controller, Customer acts as Processor and Referly acts as Customer's Subprocessor. References to “Controller” include Customer's controller where the context requires.

1.3 If there is a conflict concerning the processing of Customer Personal Data, the order of precedence is: (a) the applicable Standard Contractual Clauses; (b) this DPA; and (c) the Agreement. Except as amended by this DPA, the Agreement remains in effect.

1.4 This DPA does not reduce any data protection obligation that applies directly to either Party under Applicable Data Protection Law.

2. Definitions

“Applicable Data Protection Law” means the EU GDPR, the UK GDPR, the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection and any other privacy or data-protection law applicable to the processing of Customer Personal Data under the Agreement.

“Customer Personal Data” means Personal Data contained in Customer Data that Referly processes on behalf of Customer in connection with the Services. It excludes data for which Referly acts as an independent Controller.

“EU GDPR” means Regulation (EU) 2016/679.

“Personal Data Breach” has the meaning given by Applicable Data Protection Law and, for this DPA, is limited to a breach affecting Customer Personal Data processed by Referly as Processor.

“Restricted Data” means special-category data under Article 9 EU GDPR, criminal-conviction data under Article 10 EU GDPR, payment-card credentials outside an approved Stripe-hosted collection flow, government identity documents, children's data, or other data subject to heightened legal or industry requirements, except where the Services expressly support that data and the Parties have documented appropriate instructions and safeguards.

“Services” means Referly's affiliate, referral, partner-management, tracking, commission, payout, tax, messaging, integration, API, webhook and related services supplied under the Agreement.

“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914, as completed by Section 11 and Schedule 4 of this DPA.

“Subprocessor” means a third party engaged by Referly to process Customer Personal Data on behalf of Customer in connection with the Services.

Capitalized terms not defined in this DPA have the meaning given in the Agreement or Applicable Data Protection Law. “Controller,” “Processor,” “Data Subject,” “Personal Data,” “Process,” “Processing” and “Supervisory Authority” have the meanings given by the EU GDPR or the applicable equivalent law.

3. Roles and details of processing

3.1 The Parties acknowledge the role allocation in Section 1.2. Referly will process Customer Personal Data only to provide, secure and support the Services in accordance with Customer's documented instructions, unless Applicable Data Protection Law requires otherwise.

3.2 The subject matter, duration, nature, purposes, categories of Data Subjects and categories of Personal Data are described in Schedule 1. Customer may give additional documented instructions through Service configuration, enabled features, support requests, API calls, integration settings, webhooks, order forms and other written communications consistent with the Agreement.

3.3 Referly acts as an independent Controller where it determines its own purposes and essential means of processing, including the activities described in Schedule 5. Nothing in this DPA re-characterizes a Party where Applicable Data Protection Law assigns a different role.

3.4 For Agency Mode, Customer represents that it is authorized by each applicable client Controller to appoint Referly as a Subprocessor and to give the instructions contemplated by this DPA.

4. Customer instructions and obligations

  • Customer is responsible for the lawfulness, fairness and transparency of its processing, including its instructions to Referly; all required privacy notices, cookie or tracking disclosures, consent mechanisms and lawful bases; the accuracy and quality of Customer Personal Data; and responding to Data Subjects except to the extent Referly must assist under this DPA.

  • Customer will not instruct Referly to process Personal Data in violation of Applicable Data Protection Law or the Agreement. Referly will promptly inform Customer if, in Referly's reasonable opinion, an instruction infringes Applicable Data Protection Law, unless prohibited from doing so.

  • Customer will use the Services' access controls and configuration appropriately, protect credentials, limit user permissions, validate customer-selected webhook or integration endpoints, and ensure that its affiliates, staff and contractors are authorized to submit Personal Data.

  • Customer will not submit Restricted Data unless the Services expressly support it and the Parties have agreed documented instructions and safeguards. Tax identifiers and tax forms are permitted only through Referly features designed for that purpose. Raw card or bank credentials must be submitted only through approved payment-provider interfaces.

  • Customer acknowledges that automated or semi-automated fraud rules, approval rules, scoring or commission rules configured by Customer remain Customer's instructions. Customer is responsible for providing human review and safeguards where a decision could produce legal or similarly significant effects for a Data Subject.

5. Referly processing obligations

5.1 Documented instructions. Referly will process Customer Personal Data only on Customer's documented instructions, including transfers, unless required by Union, Member State or other applicable law. Where legally permitted, Referly will inform Customer of that legal requirement before processing.

5.2 Purpose limitation. Referly will not sell Customer Personal Data, use it for targeted advertising, or retain, use or disclose it outside the direct business relationship for purposes other than providing, securing and supporting the Services, except as permitted by Applicable Data Protection Law and expressly disclosed for independent-controller processing.

5.3 Confidentiality. Referly will ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty of confidentiality and access the data only as necessary for their assigned duties.

5.4 Compliance information. Taking into account the nature of processing and information available to Referly, Referly will make available information reasonably necessary to demonstrate compliance with Article 28 EU GDPR and equivalent obligations, subject to Section 13.

5.5 Records and cooperation. Referly will maintain records required of it as Processor and cooperate with competent Supervisory Authorities as required by Applicable Data Protection Law.

6. Security

6.1 Referly will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to the data, taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the risks to Data Subjects. The current measures are described in Schedule 2.

6.2 Referly may update the measures to reflect technological and operational developments, provided the overall level of protection is not materially reduced during the term of the Agreement.

6.3 Customer acknowledges that the Services include configurable features and integrations. Customer is responsible for assessing whether the Services and its configuration meet Customer's security requirements and for implementing security measures within Customer's control.

7. Data Subject requests

7.1 If Referly receives a request from a Data Subject relating to Customer Personal Data, Referly will, where legally permitted, notify Customer and direct the Data Subject to Customer. Referly will not respond substantively except on Customer's documented instructions or as required by law.

7.2 Taking into account the nature of processing, Referly will provide reasonable assistance through available product functionality and, where necessary, proportionate technical or organisational measures so Customer can respond to requests to access, correct, erase, restrict, object to or port Personal Data.

7.3 To the extent permitted by law, assistance that requires material engineering work beyond standard Service functionality may be subject to reasonable fees agreed in advance, unless the assistance is required because Referly breached this DPA.

8. Compliance assistance

Taking into account the nature of processing and information available to Referly, Referly will provide reasonable assistance with Customer's obligations concerning security, breach notifications, data-protection impact assessments and prior consultation under Articles 32 through 36 EU GDPR or equivalent law. Customer remains responsible for determining whether a DPIA or consultation is required and for the content of its submissions.

9. Personal Data Breaches

9.1 Referly will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.

9.2 To the extent available, the notice will describe the nature of the breach, affected categories and approximate number of Data Subjects and records, likely consequences, measures taken or proposed, and a contact for further information. Referly may provide information in phases where it cannot reasonably provide it at the same time.

9.3 Referly will take reasonable steps to contain, investigate and remediate the breach and will reasonably cooperate with Customer. Notification is not an admission of fault or liability.

9.4 Customer is responsible for notifications to Data Subjects, regulators or other third parties unless Applicable Data Protection Law assigns that obligation to Referly.

10. Subprocessors

10.1 General authorization. Customer generally authorizes Referly to engage the Subprocessors listed in Schedule 3 and future Subprocessors in accordance with this Section.

10.2 Flow-down terms. Referly will enter into a written agreement with each Subprocessor that imposes data-protection obligations no less protective in substance than those required by Article 28(3) and (4) EU GDPR for the relevant processing. Referly remains responsible to Customer for the Subprocessor's performance of those obligations to the extent required by Applicable Data Protection Law.

10.3 Changes. Referly will provide at least fifteen (15) days' prior notice of a new or replacement Subprocessor that will process Customer Personal Data, for example by updating its online list and providing notice to subscribers. Emergency substitutions necessary to maintain security or availability may be made on shorter notice, with notice as soon as reasonably practicable.

10.4 Objections. Customer may object during the notice period on reasonable grounds relating to data protection. The Parties will work in good faith to resolve the objection. If no reasonable alternative is available, Referly may suspend or Customer may terminate only the affected Service without penalty, and Referly will refund prepaid fees attributable to the unused affected Service, if any.

10.5 Customer-selected recipients. A third party chosen or configured by Customer, such as Customer's own webhook endpoint, integration, payment account, email platform or business system, is not Referly's Subprocessor merely because the Services transmit data to it on Customer's instruction. Customer is responsible for its relationship and lawful disclosure to that third party.

10.6 Support channels. Customer must not submit Customer Personal Data through public or community support channels, including Discord, and should instead contact support@referly.so. If Customer Personal Data is submitted incidentally through such a channel, Referly will limit its use to addressing the support request and take reasonable steps to redirect the request and remove the data where practicable.

11. International transfers

11.1 Referly will not transfer Customer Personal Data from the EEA, United Kingdom or Switzerland to a country lacking an applicable adequacy decision unless it implements a lawful transfer mechanism and any supplementary measures required by Applicable Data Protection Law.

11.2 Where Customer transfers EEA Personal Data to Referly in the United States and the transfer is not covered by an adequacy decision or another valid mechanism, the SCCs are incorporated by reference and completed as stated in Schedule 4. Module Two applies when Customer is a Controller; Module Three applies when Customer is a Processor.

11.3 For UK Restricted Transfers, the SCCs as completed by this DPA apply together with the then-current mandatory UK Addendum issued by the Information Commissioner, completed as stated in Schedule 4. For Swiss transfers, the adaptations in Schedule 4 apply.

11.4 If Referly lawfully participates in a recognized adequacy framework covering a transfer, Referly may rely on that framework. If it ceases to cover the transfer, Referly will use another valid mechanism.

11.5 Referly will provide information reasonably necessary for Customer's transfer assessment and will use commercially reasonable efforts to notify Customer of legally binding government demands for Customer Personal Data where permitted.

12. Return and deletion

12.1 During the term, Customer may access, export or delete Customer Personal Data using available Service functionality, subject to the Agreement and technical limitations.

12.2 Upon termination or expiration of the Agreement and at Customer's choice, Referly will return or delete Customer Personal Data, unless law requires retention. Unless Customer requests return before termination, Referly will delete Customer Personal Data from active systems and residual backups within thirty (30) days after termination.

12.3 Until deletion is complete, Referly will continue to protect retained Customer Personal Data under this DPA and will process it only as necessary for secure backup restoration, legal compliance or deletion.

13. Information and audits

13.1 Referly will make available relevant compliance materials that it customarily provides to customers, which may include security summaries, policies, certifications, penetration-test summaries or independent audit reports, subject to confidentiality and security restrictions.

13.2 If that information is insufficient to demonstrate compliance, Customer may submit a written questionnaire no more than once in any twelve-month period, except after a Personal Data Breach or where a Supervisory Authority requires more frequent review.

13.3 Where legally required and the measures above are insufficient, Customer may conduct an audit through a qualified independent auditor bound by confidentiality, on at least thirty days' notice, during normal business hours, without accessing other customers' data or unreasonably disrupting Referly's operations. Customer bears its audit costs unless the audit identifies a material breach by Referly.

13.4 Referly may charge reasonable costs for disproportionate audit assistance and may require the Parties to agree scope, timing, duration, security controls and confidentiality before an onsite audit.

14. Government and third-party demands

Unless prohibited by law, Referly will notify Customer of a legally binding demand from a public authority for Customer Personal Data. Referly will review the legality of the demand and, where reasonable grounds exist, challenge disproportionate or unlawful demands. Referly will disclose only the minimum data legally required and document its response as required by law.

15. Changes, duration and termination

15.1 This DPA becomes effective upon entering into the Agreement by the Parties and remains in force while Referly processes Customer Personal Data on Customer's behalf.

15.2 Referly may update this DPA where reasonably necessary to reflect changes in law, regulatory guidance or the Services, provided an update does not materially reduce Customer's protections during a current paid term without Customer's consent. Material changes will be notified through reasonable means.

15.3 Provisions that by their nature should survive termination, including confidentiality, deletion, audit, transfer, liability and role-allocation terms, survive for as long as Referly retains relevant Personal Data.

16. Liability, governing law and execution

16.1 Each Party's liability arising out of this DPA is subject to the exclusions and limitations of liability in the Agreement, except to the extent those limitations are prohibited by Applicable Data Protection Law or the SCCs.

16.2 The governing law and forum provisions of the Agreement apply to this DPA, except where the SCCs or mandatory law require otherwise.

16.3 This DPA may be accepted electronically, incorporated through an order form or executed in counterparts. Electronic signatures and copies have the same effect as originals.

Schedule 1 - Details of Processing

Part A. Core processing description

FieldDescription
Subject matterProvision, operation, maintenance, security and support of the Referly Services configured by Customer.
DurationFor the term of the Agreement plus the deletion and backup periods in Section 12, unless law requires longer retention.
Nature of processingCollection, recording, organization, structuring, storage, adaptation, retrieval, consultation, matching, comparison, analysis, calculation, classification, transmission, disclosure by transmission, restriction, export, erasure and destruction.
PurposesManaging affiliate and partner programs; referral and conversion attribution; calculating rewards and commissions; fraud and self-referral checks; communications; reporting; payouts and tax workflows; integrations, APIs and webhooks; program support, security and troubleshooting.
FrequencyContinuous or event-driven during Customer's use of the Services, with occasional imports, exports, support access and batch operations.
GeographyPrimarily the United States for the current core hosting configuration stated by Customer, plus other locations used by authorized Subprocessors and customer-selected recipients, subject to Section 11.

Part B. Categories of Data Subjects

  • Customer personnel, administrators, agency personnel, contractors and authorized users;

  • Affiliates, partners, applicants, creators, influencers and their personnel or representatives;

  • Website visitors, prospects, leads, referred customers and end customers;

  • Payout recipients, payees, sole traders, company representatives and beneficial or controlling persons where required by a payment provider;

  • Individuals whose information appears in support requests submitted through authorized channels, uploads, integration payloads, webhook events, tax forms, invoices, payout proofs or Customer-configured fields.

Part C. Categories of Personal Data

CategoryExamples
Identity and contactNames, usernames, email addresses, telephone numbers, postal addresses, country, company, role, profile information and account identifiers.
Program and relationshipProgram membership, application answers, approval status, affiliate groups, campaign assignments, coupon codes, referral codes, notes, custom fields and uploaded files.
Online and deviceIP address, cookie/local-storage identifiers, click and referral identifiers, browser, operating system, device characteristics, screen/viewport, language, timestamps, URLs, referrer, approximate location, ISP or network indicators and proxy/VPN indicators.
Marketing attributionUTM parameters, advertising click identifiers, landing pages, campaigns, sources, media, creatives, click activity and conversion events.
Customer and transactionCustomer identity/contact details, product/order/subscription identifiers, invoice identifiers, sale amount, currency, refund/chargeback status, timestamps and integration metadata.
Performance and commissionClicks, leads, referrals, sales, conversion rates, revenue, commissions, reward status, ranking, scoring and performance reports.
CommunicationsMessages, email content, announcements, support correspondence, delivery status and email open/click events where enabled.
Payout and financialPayment-method tokens or provider identifiers, connected recipient/account identifiers, payout amount, currency, batch status, failure reasons, payout proofs and bank details where Customer uses a supported manual payout workflow. Raw payment credentials are not intended to be stored by Referly when Stripe-hosted collection is used.
Tax and invoiceLegal name, address, entity type, country, tax classification, taxpayer identification number, VAT number, treaty information, signatures, W-9/W-8 information, invoice information and related compliance records.
Security and auditAuthentication, authorization, session, access, API, webhook delivery, change, error and incident logs.
Customer-configured dataOther Personal Data submitted through custom application questions, files, imports, APIs, integrations, support requests or program configuration, subject to the Restricted Data limitations.

Part D. Restricted and sensitive data

The Services are not intended for Article 9 special-category data or Article 10 criminal-conviction data unless Referly expressly supports the relevant use and the Parties document appropriate instructions and safeguards. Tax identifiers, payout data and payment-related identifiers are not automatically Article 9 data but are treated as heightened-risk information under this DPA. Customer must not use free-form or file-upload fields to collect Restricted Data without prior written approval and a valid legal basis.

Part E. Feature-level processing activities

ActivityNature and purposeData subjectsPrincipal data
Program and user administrationCreate and operate programs; authenticate users; configure roles, campaigns, commissions and portals.Customer users; affiliatesIdentity, contact, account, program, role and configuration data
Affiliate onboarding and managementCollect applications; store profile/custom responses and files; approve, reject, group and manage participation.Applicants; affiliates; representativesIdentity/contact, profile, program status, custom fields, uploaded documents
Tracking and attributionSet/read referral identifiers; record and match clicks; attribute visits, leads, referrals, sales and conversions.Visitors; prospects; customers; affiliatesOnline identifiers, IP/location, device/browser, referral codes, UTM/ad-click IDs, URLs and timestamps
Sales and integration ingestionReceive transaction, subscription, refund and product data from configured commerce/payment systems.Customers; affiliates; Customer usersIdentity/contact, product/order/subscription, amount, currency, status and timestamps
Commission and reportingCalculate rewards/commissions; produce analytics, rankings, dashboards and reports according to program rules.Affiliates; Customer usersPerformance, revenue, commission, reward status and program data

Schedule 1 - Details of Processing (continued)

ActivityNature and purposeData subjectsPrincipal data
Fraud and self-referral controlsCompare affiliate/customer emails, IPs and related identifiers; flag, hold or reject rewards under Customer-configured rules; support manual review.Affiliates; customersIdentity/contact, IP/network, referral, transaction, rule result and review status
CommunicationsSend Customer-configured messages, announcements and automated emails; record delivery and engagement where enabled.Affiliates; applicants; Customer usersNames, email, message content, templates, delivery/open/click metadata
PayoutsPrepare batches; associate commissions with recipients; collect tokenized funding/recipient identifiers; execute Customer-approved instructions; record results and proofs.Program owners; affiliates; payeesIdentity/contact, provider/account identifiers, payout amounts/status, failure reasons, proofs
Tax and invoicingCollect and structure tax forms and identifiers; calculate or record deductions; create or manage invoice and compliance information according to Customer instructions.Affiliates; payees; company representativesLegal identity, address, entity/tax classification, TIN/VAT, treaty, signature, invoice and payout data
API, webhooks and integrationsReceive, retrieve, transmit, import, export and synchronize program events and objects; retry and log deliveries.All relevant categoriesPayload data selected by Customer, endpoint identifiers, delivery status, timestamps and error logs
Agency ModeEnable Customer to operate programs for client Controllers; segregate and present client program data under Customer branding.Client users, affiliates, visitors and customersAll program-specific categories enabled by the agency and client Controller
Support and troubleshootingInvestigate requests submitted through authorized support channels, diagnose errors, restore service and provide assistance using access limited to what is necessary. Customers are instructed not to submit Customer Personal Data through Discord.Customer users and persons in affected recordsSupport communications, account/configuration data, logs and affected records

Schedule 2 - Technical and Organisational Measures

Security governance

  • Assigned responsibility for security and privacy controls, risk review and incident coordination.

  • Documented policies or procedures for access, incident response, change management, vulnerability handling, retention and vendor management, proportionate to Referly's size and risk.

Access control

  • Role- or need-based access to production and administrative systems, with least-privilege principles and periodic access review.

  • Unique user accounts; prompt removal or adjustment of access when roles change or personnel leave.

  • Administrative access restricted to personnel who need it for operations, security or support.

Authentication and credentials

  • Secure authentication for administrative access and multi-factor authentication for privileged systems where supported.

  • Passwords stored using industry-standard one-way hashing; secrets and API credentials managed separately from source code and access-controlled.

  • Session and credential protections designed to reduce unauthorized reuse or disclosure.

Encryption and payment-data minimization

  • Transport encryption using current TLS for supported external connections and administrative interfaces.

  • Encryption at rest supplied by core infrastructure providers for production databases and object storage, subject to verified vendor configuration.

  • Taxpayer identification numbers encrypted at the application or field level where Referly documentation represents this control.

  • Stripe-hosted setup or onboarding flows used to collect supported funding and recipient credentials so Referly does not intentionally store raw card or bank credentials when those flows are used.

Application and infrastructure security

  • Environment separation and controlled production deployments; code changes reviewed or tested before release proportionate to risk.

  • Security updates and vulnerability remediation prioritized according to severity and operational risk.

  • Input validation, authorization checks and protections appropriate to web applications, APIs and webhook operations.

Logging and monitoring

  • Operational, authentication, API, error, change and webhook-delivery logs generated as appropriate to detect misuse, diagnose incidents and support accountability.

  • Access to logs restricted and retention limited according to operational and security needs.

Availability and recovery

  • Managed hosting and database services designed for resilience and availability.

  • Backups or provider-managed recovery mechanisms appropriate to service risk, with restoration procedures and periodic validation proportionate to Referly's size.

  • Business continuity and incident escalation processes for material service disruption.

Data minimization, segregation and retention

  • Logical separation of program/customer records through application and database authorization controls.

  • Collection and display limited through configured fields, permissions and feature settings.

  • Retention and deletion processes covering live systems, logs, files and backup cycles, including termination workflows.

Personnel and confidentiality

  • Confidentiality obligations for personnel with access to Customer Personal Data.

  • Security and privacy awareness appropriate to role and access.

  • Disciplinary and offboarding processes that address misuse and access revocation.

Incident response

  • Process to identify, assess, contain, investigate, remediate and document suspected security incidents.

  • Escalation to responsible personnel and procedures for Customer notification under Section 9.

  • Post-incident review and corrective measures where appropriate.

Subprocessor and vendor controls

  • Risk-based vendor review before a vendor receives Customer Personal Data.

  • Written data-protection and confidentiality terms with authorized Subprocessors.

  • Review of vendor security, transfer mechanisms, regions and material changes proportionate to risk.

Testing and review

  • Periodic review of the effectiveness of security measures and remediation of identified gaps.

  • Security testing, dependency scanning or penetration testing proportionate to Referly's risk and product maturity.

Schedule 3 - Subprocessor Register

ProviderService/purposeCustomer Personal DataProcessing location / review note
VercelApplication/server hosting, serverless execution, content delivery and related infrastructureProgram, user, visitor, tracking, transaction and operational data processed by hosted applicationGermany.
SupabaseDatabase, authentication if enabled, object/image/file storage and related infrastructureAccount, affiliate, customer, referral, sale, commission, payout, tax, file and log data stored in the configured projectFrankfurt, Germany.
Stripe and applicable Stripe affiliatesPayment-method setup, billing/collection, connected recipient onboarding, payout execution and related payment servicesProgram-owner and payee identity/contact data; tokenized funding/recipient identifiers; transaction, payout and compliance dataUnited States. Stripe may act as independent Controller for KYC, fraud, sanctions and legal compliance.
Mailgun (Sinch)Transactional and program email sending, delivery, suppression and engagement processingRecipient names and email addresses; message content; delivery, bounce, complaint and engagement metadataUnited States region.
PostHogProduct analytics and feature flaggingUser identifiers or pseudonymous IDs; event, device, usage and feature-flag data configured by ReferlyEuropean Union region (Germany).
DigitalOceanInfrastructure hosting for Referly's self-hosted Svix webhook delivery service, including queueing, retries, delivery logging and replayCustomer-configured webhook event payloads; endpoint identifiers; delivery status, timestamps and error logsFrankfurt, Germany.

Subprocessor change notices

The current Subprocessor list is published with Referly's online DPA. Referly will send Subprocessor change notices to the administrative email associated with Customer's Referly account. Questions and objections may be sent to support@referly.so.

Schedule 4 - International Transfer Terms

A. EU Standard Contractual Clauses

SCC itemSelection / completion
Applicable moduleModule Two (Controller to Processor) where Customer is Controller; Module Three (Processor to Processor) where Customer is Processor.
Clause 7Docking clause applies.
Clause 9Option 2 (general written authorization) applies. Notice period: fifteen (15) days, subject to emergency substitutions under Section 10.3.
Clause 11The optional independent dispute-resolution language does not apply.
Clause 13 / Annex I.CThe Supervisory Authority determined under Clause 13 by reference to the data exporter and applicable EU GDPR rules.
Clause 17Option 1 applies. Governing law: Ireland.
Clause 18Courts of Ireland.
Annex I.AData exporter: Customer and, for Module Three, the applicable Controller(s), as identified in the Agreement and this DPA. Data importer: Referly Technologies, LLC, 1207 Delaware Ave #3648, Wilmington, DE 19806, United States. Activities are described in Schedule 1. Signatures and dates are those for the Agreement or this DPA.
Annex I.BCategories of Data Subjects, Personal Data, sensitive data, frequency, nature, purposes and duration are stated in Schedule 1. Transfer frequency is continuous or event-driven during the term. Retention is stated in Section 12.
Annex IISchedule 2.
Annex IIISchedule 3.

B. United Kingdom

For a UK Restricted Transfer, the then-current mandatory addendum to the EU SCCs issued by the UK Information Commissioner (the “UK Addendum”) is incorporated. Table 1 is completed with the Parties and key contacts in the Agreement, this DPA and Schedule 3; Table 2 identifies the approved EU SCCs as completed in Part A above; Table 3 is completed by Schedules 1 through 3; and Table 4 permits either Party to end the UK Addendum as provided by its mandatory clauses. The data exporter may terminate the affected transfer if required following an ICO-approved revision.

C. Switzerland

For transfers subject to the Swiss Federal Act on Data Protection, references in the SCCs to the GDPR include the Swiss law to the extent applicable; references to “EU,” “Union” and “Member State” are interpreted to include Switzerland where necessary; the competent Swiss authority is the Federal Data Protection and Information Commissioner; and Data Subjects in Switzerland may enforce rights available to them under Swiss law. These adaptations do not limit rights under the SCCs or EU GDPR.

D. Transfer assessments and government access

Each Party will provide information reasonably available to it for assessments required by applicable transfer law. Referly will document legally binding public-authority requests affecting transferred Customer Personal Data as required by the SCCs, use reasonable efforts to challenge unlawful or disproportionate requests, and disclose only the minimum amount legally required.

Schedule 5 - Referly Independent-Controller Processing

The following activities are outside Referly's processor obligations under this DPA to the extent Referly determines the purposes and essential means of processing. They remain subject to Applicable Data Protection Law and Referly's applicable privacy notice. The role depends on the facts and may differ for particular features.

ActivityController purpose / boundary
Referly account and relationship administrationCreating and administering Referly customer accounts; authenticating account owners; managing subscriptions, contracts, billing, communications and customer relationships.
Referly-wide affiliate identity and accountMaintaining a common affiliate identity or account that operates across programs, where the functionality is not controlled solely by one program owner.
Marketplace, network and discoveryOperating Referly Marketplace, Influencer Discovery, creator profiles, cross-program discovery, matching, network features and Referly-determined profile presentation.
Cross-program analytics or reputationDeveloping or presenting performance, ranking, fraud, risk, profile or reputation information across programs for Referly-determined purposes, if and to the extent implemented.
Platform security, abuse and legal complianceDetecting and preventing abuse of Referly itself; protecting the platform and users; enforcing terms; establishing, exercising or defending legal claims; responding to lawful requests; maintaining legally required records.
Referly marketing and product relationshipMarketing Referly, managing prospects and events, and measuring Referly's own website or campaign performance.
Payment-provider or legal obligationsProcessing Referly must undertake for its own accounting, tax, sanctions, anti-money-laundering, payment-risk or other independently applicable obligations. Stripe or another provider may separately act as Controller for its compliance purposes.
De-identified or aggregate informationCreating and using information that has been rendered non-personal under applicable law, provided Referly does not attempt to re-identify it except to test de-identification protections.