Data Processing Agreement
Last updated: August 4, 2026
1. Scope and roles
This DPA forms part of the Terms of Service between RevTouch.io ("Processor") and the customer organization ("Controller"). It applies whenever RevTouch processes personal data on the Controller's behalf and satisfies GDPR Art. 28, UK GDPR Art. 28, and the processor/service-provider contract requirements of CPRA § 1798.100(d), VCDPA § 59.1-579, CPA, CTDPA, TDPSA and the other US state privacy laws.
2. Subject matter and duration
- Subject matter: provision of attribution reporting and affiliate payout services
- Duration: the term of the customer agreement, plus the deletion period in clause 9
- Nature and purpose: collection, storage, identity stitching, computation of attribution credit and payout election, reporting and export
- Data subjects: the Controller's website visitors, customers, affiliates and staff users
- Categories: hashed email and phone, pseudonymous cookie and click identifiers, hashed IP, campaign metadata, conversion values, account contact details
- Special categories: none. The Controller must not submit special category data
3. Processor obligations
- Process only on documented instructions, including for international transfers
- Never sell personal information, never share it for cross-context behavioural or targeted advertising, and never combine it with data from other sources except as permitted by law
- Bind all personnel with access to confidentiality obligations
- Implement the measures in clause 6
- Assist the Controller with data subject requests, DPIAs and regulator consultations
- Notify the Controller if an instruction appears to infringe applicable law
- Make available the information needed to demonstrate compliance and allow audits per clause 8
4. Controller obligations
- Establish and document a lawful basis for the processing
- Obtain any cookie or tracking consent required before the collector fires
- Provide notice to data subjects naming RevTouch as a processor
- Ensure instructions to RevTouch comply with applicable law
5. Sub-processors
The Controller gives general authorisation for the sub-processors below. We give at least 30 days' notice before adding or replacing one, and the Controller may object on reasonable data protection grounds; if the objection cannot be resolved, the Controller may terminate the affected service without penalty. Every sub-processor is bound to terms no less protective than this DPA.
| Sub-processor | Processing | Location |
|---|---|---|
| Supabase | Database, authentication, edge functions | USA / EU |
| Netlify | Front-end hosting and the first-party collector proxy | USA / EU |
| Stripe | Subscription billing and conversion webhooks | USA / EU |
| Whop | Conversion webhooks (only if the customer connects it) | USA |
| Omnisend | Email/SMS campaign metadata (only if connected) | EU |
6. Technical and organisational measures (Annex II)
- Pseudonymisation: email, phone, IP and user agent are SHA-256 hashed at the edge; raw values are never written to storage
- Encryption: TLS 1.2+ in transit, AES-256 at rest, integration credentials encrypted with a separate key
- Tenant isolation: row-level security on every table, keyed to organization membership and role
- Access control: least privilege, role-based, service keys scoped to server-side functions only
- Integrity: append-only audit logs, immutable touch events, signature verification on inbound webhooks, replay protection
- Availability: managed Postgres with point-in-time recovery and daily backups
- Testing: automated RLS role-matrix checks and deterministic engine tests on every change
7. Personal data breach
RevTouch notifies the Controller without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Controller data, with the nature of the breach, categories and approximate numbers affected, likely consequences and remediation. Report suspected issues to privacy@revtouch.io.
8. Audit
On request, and no more than once per year (or after a breach), RevTouch provides its security documentation and answers a reasonable security questionnaire. On-site or third-party audits may be arranged with 30 days' notice, during business hours, under confidentiality, and at the Controller's cost.
9. Return and deletion
On termination the Controller may export its data for 30 days. RevTouch then deletes or de-identifies it within a further 30 days, except where law requires retention, per the schedule below. Backups age out on their normal rotation.
| Data type | Retention |
|---|---|
| Touch events (hashed identity keys only) | 26 months, then aggregated |
| Conversions and attribution credits | Duration of account + 30 days |
| Payout decisions, runs and statements | 7 years (financial record keeping) |
| Billing records | 7 years (legal obligation) |
| Audit log and payout audit | 7 years (append-only, immutable) |
| Account profile data | Duration of account + 30 days |
| Consent records | 5 years (proof of compliance) |
| Data subject requests | 24 months after closure |
10. International transfers
For transfers of EEA personal data to a third country, the European Commission's Standard Contractual Clauses (Decision 2021/914) Module Two (controller to processor) are incorporated, with Annex I populated from clause 2, Annex II from clause 6, and Annex III from clause 5. Docking clause: optional. Governing law: Ireland. For UK data, the UK International Data Transfer Addendum (version B1.0) is incorporated with the SCCs. For Swiss data, references to GDPR are read as references to the FADP and the FDPIC is the competent authority.
11. US state processor terms
RevTouch processes personal information solely to perform the services and for no other commercial purpose, does not sell or share it, does not retain, use or disclose it outside the direct business relationship, and certifies that it understands and will comply with these restrictions. RevTouch will notify the Controller if it can no longer meet its obligations and will cooperate with reasonable steps to stop and remediate unauthorised use.
12. Signature and contact
This DPA is effective automatically on acceptance of the Terms; no signature is required. For a countersigned copy, or to submit sub-processor objections, contact privacy@revtouch.io. Our data protection contact is privacy@revtouch.io.