Data Processing Addendum

Effective Date: September 1, 2026
Last Updated: August 21, 2026

This Data Processing Addendum ("DPA") forms part of the Affily Terms of Service and Business Terms / Agreement between Affily, Inc. ("Affily") and the business, merchant, brand, seller, or other commercial entity using Affily ("Merchant").

This DPA governs Affily's Processing of Merchant Personal Data on behalf of Merchant in connection with the Affily services.

By accepting Affily's Business Terms / Agreement or otherwise using the Services in a manner subject to those terms, Merchant enters into this DPA with Affily. A separate signature is not required unless the parties agree otherwise in writing.

If there is a conflict between this DPA and the Business Terms / Agreement concerning the Processing of Merchant Personal Data, this DPA controls to the extent of the conflict.

1. Definitions

For purposes of this DPA:

"Applicable Data Protection Law" means any privacy, data-protection, or data-security law applicable to the Processing of Merchant Personal Data under this DPA, including, where applicable, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), the EU General Data Protection Regulation ("GDPR"), the United Kingdom GDPR ("UK GDPR"), and other applicable U.S. state privacy laws.

"Business" has the meaning assigned under the CCPA where applicable.

"Consumer" has the meaning assigned under applicable U.S. privacy law.

"Controller" means the person or entity that determines the purposes and means of Processing Personal Data.

"Data Subject" means an identified or identifiable individual to whom Personal Data relates.

"Merchant Personal Data" means Personal Data that Affily Processes on behalf of Merchant in connection with the Services and for which Merchant acts as Controller, Business, or similar responsible party under Applicable Data Protection Law.

"Personal Data" means personal data, personal information, or similar information relating to an identified or identifiable individual that is protected under Applicable Data Protection Law.

"Process" or "Processing" means any operation performed on Personal Data, including collection, receipt, recording, organization, storage, adaptation, retrieval, consultation, use, transmission, disclosure, analysis, combination, restriction, deletion, or destruction.

"Processor" means a person or entity that Processes Personal Data on behalf of a Controller.

"Security Incident" means a confirmed breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Merchant Personal Data Processed by Affily.

"Service Provider" and "Contractor" have the meanings assigned under the CCPA where applicable.

"Services" means the Affily services described in the Terms of Service and Business Terms / Agreement, including store connection, affiliate attribution, campaign administration, commission and fee calculation, refunds and reversals, product reimbursement, reporting, payment-related operations, fraud prevention, support, and related functionality.

"Subprocessor" means a third party engaged by Affily to Process Merchant Personal Data on Affily's behalf in connection with the Services.

2. Scope and Roles of the Parties

This DPA applies only to Merchant Personal Data that Affily Processes on behalf of Merchant.

For such Processing:

  • Merchant acts as Controller, Business, or equivalent responsible party; and
  • Affily acts as Processor, Service Provider, Contractor, or equivalent service provider.

Merchant determines the purposes for which its customer and store data are made available to Affily through the Services.

Affily may separately act as a Controller or Business for Personal Data it Processes for its own legitimate operational purposes, including Affily user account administration, business and creator relationships, payment and payout administration, fraud prevention, security, tax compliance, legal compliance, enforcement of Affily agreements, and protection of the Affily platform. Such Processing is governed by Affily's Privacy Policy rather than Affily's processor obligations under this DPA.

Nothing in this DPA changes the parties' roles where Applicable Data Protection Law assigns a different role based on the circumstances of particular Processing.

3. Merchant Instructions

Merchant instructs Affily to Process Merchant Personal Data as reasonably necessary to provide the Services described in the Business Terms / Agreement and this DPA.

Those instructions include Processing for:

  • store connection and integration;
  • affiliate-link and click attribution;
  • purchase and conversion tracking;
  • campaign administration;
  • commission calculation;
  • Affily service-fee calculation;
  • commission hold periods;
  • refunds, cancellations, and reversals;
  • product reimbursement;
  • product and variant synchronization;
  • product availability and inventory-related campaign functionality;
  • reporting and analytics;
  • transaction reconciliation;
  • fraud detection, prevention, and investigation;
  • security and abuse prevention;
  • support and troubleshooting;
  • dispute resolution;
  • maintaining the integrity of financial and transaction records; and
  • compliance with applicable legal obligations.

Merchant may provide additional documented instructions that are consistent with the Services and this DPA.

Affily will Process Merchant Personal Data only on documented instructions from Merchant except where Processing is required by applicable law. If applicable law requires Affily to Process Merchant Personal Data contrary to Merchant's instructions, Affily will notify Merchant before such Processing unless the law prohibits that notice.

If Affily reasonably believes a Merchant instruction violates Applicable Data Protection Law, Affily may suspend the affected Processing and notify Merchant.

4. Details of Processing

4.1 Subject Matter

The subject matter of the Processing is the provision of Affily's affiliate marketing, attribution, commission, reimbursement, commerce integration, reporting, refund, security, and related services to Merchant.

4.2 Duration

Processing will continue for the period during which Merchant uses the applicable Services and for any additional period during which Merchant Personal Data is retained in accordance with this DPA, Merchant's instructions, Applicable Data Protection Law, or other lawful retention requirements.

4.3 Nature of Processing

Processing may include:

  • receiving;
  • collecting;
  • recording;
  • organizing;
  • structuring;
  • storing;
  • retrieving;
  • analyzing;
  • comparing;
  • validating;
  • normalizing;
  • using;
  • transmitting;
  • restricting;
  • deleting; and
  • otherwise Processing Merchant Personal Data as necessary to provide the Services.

4.4 Categories of Data Subjects

Data Subjects may include:

  • customers of Merchant;
  • visitors to Merchant's online store;
  • purchasers of Merchant products;
  • individuals whose purchases are attributed to an Affily creator or campaign;
  • Merchant personnel;
  • individuals involved in support, refund, fraud, or dispute matters; and
  • other individuals whose Personal Data appears in commerce records supplied by Merchant or Merchant's commerce platform.

4.5 Categories of Merchant Personal Data

Depending on Merchant's commerce platform, configuration, and the contents of information supplied to Affily, Merchant Personal Data may include:

Commerce and transaction information, such as:

  • external order identifiers;
  • order names or references;
  • transaction timestamps;
  • currencies;
  • order totals and subtotals;
  • product identifiers;
  • variant identifiers;
  • line-item identifiers;
  • product prices;
  • quantities;
  • discount information;
  • post-discount line amounts;
  • refund identifiers;
  • refund amounts;
  • cancellation information;
  • return or reversal information; and
  • related commerce-event information.

Attribution information, such as:

  • Affily link identifiers;
  • click identifiers;
  • campaign identifiers;
  • creator identifiers;
  • visitor or client identifiers;
  • page URLs;
  • referral information;
  • page-view events;
  • checkout events;
  • purchase events;
  • timestamps; and
  • other information used to associate transactions with Affily campaigns.

Technical information, such as:

  • IP addresses where transmitted or recorded;
  • browser information;
  • device information;
  • request metadata;
  • event metadata;
  • log information;
  • authentication or signature-validation information;
  • fraud indicators; and
  • security signals.

Customer information, to the extent included in information supplied by Merchant or Merchant's commerce platform, which may include:

  • customer identifiers;
  • names;
  • email addresses;
  • telephone numbers;
  • billing or shipping information; and
  • other customer information contained in the original commerce-platform event.

Affily's Services are designed primarily to use transaction, product, refund, attribution, and related operational information. Affily does not require Merchant to provide customer information that is unnecessary for the Services.

4.6 Shopify Processing

For Shopify merchants, Affily's current connection uses merchant-configured Shopify Customer Events pixel functionality and merchant-configured signed webhooks.

Merchant may configure Affily to receive events relating to:

  • order creation;
  • order cancellation;
  • refund creation;
  • product updates; and
  • product deletion.

Affily may also receive attribution events through the Affily Customer Events pixel, including page views, checkout activity, purchase events, Affily click identifiers, and related technical information.

Affily verifies applicable signed webhook requests using Merchant-provided authentication information.

Verified Shopify webhook payloads may be temporarily or durably stored as source event records before Affily normalizes relevant information into Affily transaction, order-item, refund, and refund-item records.

The contents of a raw Shopify webhook payload are determined by Shopify and Merchant's configuration and may contain information that Affily does not use as a normalized field.

4.7 Special Categories and Sensitive Information

Merchant will not intentionally provide Affily with:

  • special-category Personal Data under the GDPR;
  • protected health information subject to HIPAA;
  • government identification numbers;
  • payment-card credentials;
  • account passwords;
  • biometric identifiers; or
  • other highly sensitive information

unless the Processing is expressly supported by the Services and separately agreed by Affily.

5. Merchant Responsibilities

Merchant is responsible for:

  • complying with Applicable Data Protection Law;
  • providing legally required privacy notices to its customers and store visitors;
  • establishing an appropriate legal basis for the collection and disclosure of Merchant Personal Data;
  • obtaining consent where required;
  • ensuring that Merchant's instructions to Affily are lawful;
  • configuring its store, pixels, webhooks, and related commerce systems lawfully;
  • responding to Data Subject or Consumer requests as Controller or Business;
  • ensuring the accuracy and lawfulness of Merchant Personal Data supplied to Affily; and
  • limiting disclosure to information reasonably necessary for the Services.

Merchant represents and warrants that it has all rights, authorizations, notices, and legal bases necessary to instruct Affily to Process Merchant Personal Data under this DPA.

6. Affily Processing Obligations

Affily will:

  • Process Merchant Personal Data only for the purposes and instructions described in this DPA;
  • comply with applicable obligations imposed on Processors, Service Providers, and Contractors under Applicable Data Protection Law;
  • ensure that persons authorized to Process Merchant Personal Data are subject to appropriate confidentiality obligations;
  • implement appropriate technical and organizational measures designed to protect Merchant Personal Data;
  • provide reasonable assistance to Merchant with applicable privacy obligations as described in this DPA;
  • maintain records relating to Processing where required by law; and
  • promptly inform Merchant if Affily determines that it can no longer comply with applicable obligations under this DPA.

Affily will not acquire ownership of Merchant Personal Data merely by Processing it under this DPA.

7. Confidentiality

Affily will limit access to Merchant Personal Data to personnel and service providers who require access for legitimate purposes related to the Services.

Personnel authorized to Process Merchant Personal Data will be subject to confidentiality obligations or appropriate statutory duties of confidentiality.

Affily will not knowingly disclose Merchant Personal Data to unauthorized persons except as required by law.

8. Security

Affily will maintain commercially reasonable technical and organizational safeguards appropriate to the nature of Merchant Personal Data, the Processing performed, and the risks presented by the Processing.

Such safeguards may include, as appropriate:

  • authentication and access controls;
  • least-privilege access practices;
  • logical separation and database access restrictions;
  • secure software-development practices;
  • transport encryption;
  • cryptographic protection of credentials and sensitive integration secrets;
  • signed-webhook verification;
  • restricted administrative access;
  • logging and monitoring;
  • rate limiting and abuse prevention;
  • fraud-detection controls;
  • backup and recovery procedures;
  • vulnerability and dependency management;
  • incident-response procedures; and
  • procedures for reviewing and updating security measures.

Affily currently encrypts merchant-provided webhook signing secrets before storing them and uses those secrets to authenticate supported commerce webhook requests.

No security measure can eliminate all risk, and Affily does not guarantee absolute security.

9. Security Incidents

Affily will notify Merchant without undue delay after becoming aware of a confirmed Security Incident affecting Merchant Personal Data.

To the extent reasonably available, Affily's notice will include information regarding:

  • the nature of the Security Incident;
  • the categories of affected information;
  • the affected systems or Processing;
  • known or reasonably estimated impact;
  • remediation or containment measures; and
  • information reasonably necessary for Merchant to comply with applicable notification obligations.

Affily may provide information in phases as additional facts become available.

Affily's notification of a Security Incident does not constitute an admission of fault or liability.

Merchant is responsible for determining whether notifications to individuals, regulators, or other parties are legally required, except to the extent applicable law places an independent notification obligation directly on Affily.

10. Data Subject and Consumer Requests

Merchant is responsible for responding to requests from Data Subjects or Consumers concerning Merchant Personal Data.

If Affily receives a request directly from an individual concerning Merchant Personal Data that Affily Processes solely on behalf of Merchant, Affily may:

  • direct the individual to Merchant;
  • notify Merchant of the request; or
  • take another reasonable action consistent with Applicable Data Protection Law.

Taking into account the nature of the Processing, Affily will provide commercially reasonable assistance to Merchant with requests to:

  • access Personal Data;
  • correct Personal Data;
  • delete Personal Data;
  • restrict Processing;
  • obtain portable information;
  • opt out where applicable; or
  • exercise other rights required under Applicable Data Protection Law,

to the extent the information and functionality necessary to provide such assistance are reasonably available to Affily.

Affily will not independently determine the validity of a Merchant customer's privacy request where Merchant acts as the responsible Controller or Business unless applicable law requires Affily to do so.

11. Assistance With Compliance

Taking into account the nature of the Processing and information available to Affily, Affily will provide reasonable assistance to Merchant as required by Applicable Data Protection Law concerning:

  • security of Processing;
  • Security Incident response;
  • Data Subject requests;
  • data-protection impact assessments;
  • regulatory consultations; and
  • other Processor obligations applicable to the Services.

Merchant will reimburse Affily for extraordinary assistance that materially exceeds the ordinary scope of the Services where permitted by applicable law and agreed in advance.

12. Subprocessors

Merchant provides Affily with general authorization to engage Subprocessors as reasonably necessary to provide the Services.

Subprocessors may include providers of:

  • cloud infrastructure;
  • database and storage services;
  • application hosting;
  • payment and financial infrastructure where applicable;
  • communications infrastructure;
  • security and fraud-prevention services;
  • monitoring and diagnostics; and
  • other technical services necessary to operate Affily.

Affily will require Subprocessors that Process Merchant Personal Data to be subject to contractual data-protection obligations that are materially protective of Merchant Personal Data and appropriate to the Subprocessor's role.

Affily remains responsible for its Subprocessors to the extent required by Applicable Data Protection Law and this DPA.

Where the GDPR or UK GDPR applies, Affily will provide information about current Subprocessors upon reasonable request and will provide reasonable notice of material additions or replacements where legally required.

If Merchant reasonably objects to a new Subprocessor based on documented data-protection concerns, the parties will work in good faith to identify a commercially reasonable solution. If no reasonable solution is available, Affily may permit Merchant to discontinue the affected portion of the Services.

13. CCPA and California Service Provider / Contractor Terms

To the extent the CCPA applies to Merchant Personal Data, the parties agree as follows.

Merchant discloses or makes Merchant Personal Data available to Affily only for the limited and specific business purposes described in this DPA.

Affily will not:

  • sell Merchant Personal Data;
  • share Merchant Personal Data for cross-context behavioral advertising;
  • retain, use, or disclose Merchant Personal Data outside the specific business purposes described in this DPA except as permitted by the CCPA;
  • retain, use, or disclose Merchant Personal Data outside the direct business relationship between Affily and Merchant except as permitted by the CCPA; or
  • combine Merchant Personal Data with Personal Data Affily receives from or on behalf of another person, or collects from its own interaction with a Consumer, except where such combination is expressly permitted by the CCPA.

Affily may Process Merchant Personal Data for permitted internal purposes such as security, fraud prevention, debugging, maintaining or improving the quality of the Services provided to Merchant, and other purposes permitted for Service Providers or Contractors under the CCPA.

Affily will provide the same level of privacy protection required of Service Providers or Contractors by the CCPA.

Affily will notify Merchant if Affily determines it can no longer meet its applicable CCPA obligations.

Merchant has the right, subject to reasonable notice and the limitations in this DPA, to take reasonable and appropriate steps to help ensure that Affily uses Merchant Personal Data consistently with Merchant's CCPA obligations.

Merchant may also take reasonable and appropriate steps to stop and remediate unauthorized use of Merchant Personal Data.

If Affily engages a Subprocessor to Process CCPA-covered Merchant Personal Data, Affily will require the Subprocessor to comply with applicable Service Provider or Contractor restrictions.

The specific business purposes for which Affily Processes CCPA-covered Merchant Personal Data are:

  • providing affiliate attribution;
  • processing commerce events;
  • calculating and administering commissions and Affily fees;
  • processing refunds, reversals, and product reimbursement;
  • maintaining product and inventory synchronization;
  • reporting and analytics for Merchant;
  • security and fraud prevention;
  • support and troubleshooting;
  • transaction reconciliation; and
  • operating other Services expressly requested by Merchant.

Nothing in this Section permits Affily to Process Merchant Personal Data in a manner prohibited by the CCPA.

14. Other U.S. State Privacy Laws

Where another U.S. state privacy law requires contractual provisions between a Controller and Processor, this DPA will be interpreted to satisfy those requirements to the extent applicable.

Affily will:

  • Process covered Personal Data according to Merchant's instructions;
  • maintain confidentiality;
  • implement appropriate security measures;
  • use Subprocessors subject to appropriate contractual protections;
  • assist Merchant with applicable Consumer rights where required; and
  • provide information reasonably necessary for Merchant to demonstrate compliance.

If a mandatory state-law requirement applicable to the parties is not expressly addressed in this DPA, that requirement is incorporated to the minimum extent necessary for compliance.

15. GDPR and UK GDPR Processor Terms

To the extent the GDPR or UK GDPR applies to Merchant Personal Data, Affily will:

  • Process Personal Data only on documented instructions from Merchant;
  • ensure persons authorized to Process Personal Data are subject to confidentiality obligations;
  • implement appropriate technical and organizational security measures;
  • comply with applicable requirements concerning engagement of Subprocessors;
  • assist Merchant, taking into account the nature of Processing, with fulfillment of Data Subject rights;
  • assist Merchant with security, breach notification, impact-assessment, and regulatory-consultation obligations where required;
  • delete or return Personal Data after the end of the Services as described in this DPA;
  • make information reasonably necessary to demonstrate compliance available to Merchant; and
  • permit audits as required and subject to Section 18 of this DPA.

If Merchant's instruction would violate the GDPR, UK GDPR, or other applicable European data-protection law, Affily will inform Merchant unless prohibited by law.

16. International Data Transfers

Merchant acknowledges that Affily and its Subprocessors may Process Merchant Personal Data in the United States or other jurisdictions.

If Applicable Data Protection Law restricts an international transfer of Merchant Personal Data, the parties will use a lawful transfer mechanism applicable to that transfer.

Where required, such mechanisms may include:

  • an adequacy decision;
  • the European Commission's Standard Contractual Clauses;
  • the United Kingdom International Data Transfer Addendum or International Data Transfer Agreement; or
  • another legally recognized transfer mechanism.

The parties will reasonably cooperate to execute or incorporate additional transfer documentation where legally required.

17. Deletion and Return of Merchant Personal Data

Upon termination of the Services, and subject to Merchant's written request where required, Affily will delete or return Merchant Personal Data within a commercially reasonable period except where:

  • applicable law requires retention;
  • Merchant instructs Affily to retain the information;
  • information must temporarily remain in secure backups pending ordinary deletion cycles; or
  • Affily has another lawful basis to retain information outside its role as Merchant's Processor.

Where Affily retains Merchant Personal Data solely because applicable law requires retention, Affily will continue to protect the information and will not Process it for unrelated purposes.

Certain transaction, accounting, fraud, dispute, tax, payment, or legal records may be retained where Affily has independent legal obligations or legitimate purposes for retaining those records. To the extent Affily acts as an independent Controller for that limited Processing, such Processing is governed by Affily's Privacy Policy and applicable law.

Deletion of an Affily account, removal of a pixel, deletion of webhooks, or disconnection of a commerce integration does not necessarily result in immediate deletion of all historical information.

Backup copies may remain until overwritten or deleted through Affily's ordinary backup-retention cycle.

18. Audits and Compliance Information

Affily will make information reasonably necessary to demonstrate its compliance with this DPA available to Merchant upon reasonable request.

Where documentation is insufficient and Applicable Data Protection Law provides Merchant with an audit right, Merchant may conduct an audit subject to the following conditions:

  • no more than once in any twelve-month period unless a Security Incident, regulator, or applicable law reasonably requires an additional audit;
  • reasonable advance written notice;
  • mutually agreed timing and scope;
  • confidentiality obligations;
  • no unreasonable interference with Affily's operations;
  • no access to information relating to other Affily customers;
  • no access to source code, credentials, or information that would create a material security risk except where legally required and subject to appropriate safeguards; and
  • Merchant bears its own audit costs and, where permitted by law, Affily's reasonable costs of supporting an extraordinary audit.

Affily may satisfy an audit request in whole or in part through current third-party security reports, certifications, questionnaires, summaries, or other appropriate compliance documentation where those materials reasonably address Merchant's request.

If Affily receives a legally binding request from a government authority for Merchant Personal Data, Affily may disclose information as required by law.

Where legally permitted, Affily will notify Merchant before disclosure and provide reasonable information concerning the request.

Affily will not knowingly disclose more Merchant Personal Data than reasonably required by the applicable legal process.

20. Limitation of Liability

The liability limitations, exclusions, disclaimers, and remedies contained in the Terms of Service and Business Terms / Agreement apply to this DPA to the fullest extent permitted by law.

Nothing in this DPA limits liability where Applicable Data Protection Law prohibits such limitation.

21. Order of Precedence

If there is a conflict involving the Processing of Merchant Personal Data, the order of precedence is:

  1. any mandatory terms of Applicable Data Protection Law that cannot be varied by contract;
  2. any executed international data-transfer mechanism applicable to the Processing;
  3. this DPA; and
  4. the Business Terms / Agreement.

The remainder of the Terms of Service continues to govern all matters not specifically addressed by this DPA.

22. Changes to This DPA

Affily may update this DPA where reasonably necessary to:

  • reflect changes to the Services;
  • address changes to Applicable Data Protection Law;
  • improve privacy or security protections;
  • update Processing activities; or
  • maintain consistency with Affily's legal agreements.

Affily will provide reasonable notice of material changes where required by law or the Business Terms / Agreement.

Affily will not materially reduce the protections applicable to Merchant Personal Data during an active contractual relationship without an appropriate legal basis.

23. Contact

Questions, requests, or notices concerning this DPA may be sent to:

Affily, Inc.
43313 Woodward Ave #1152

Bloomfield Hills, MI 48302

United States

Email: admin@affilyapp.com

Schedule A: Processing Summary

Controller / Business: Merchant

Processor / Service Provider / Contractor: Affily, Inc.

Subject Matter: Merchant commerce, customer transaction, attribution, campaign, refund, reimbursement, product, technical, and related Personal Data Processed to provide the Affily Services.

Duration: For the duration of Merchant's use of the Services and any lawful retention period described in this DPA.

Purposes: Affiliate attribution, commission administration, Affily fee administration, refunds, reversals, product reimbursement, product synchronization, availability handling, reporting, fraud prevention, security, support, reconciliation, and related operations.

Data Subjects: Merchant customers, store visitors, purchasers, Merchant personnel, and individuals represented in applicable support or transaction records.

Data Categories: Commerce transaction information, order identifiers, product and variant information, prices, discounts, quantities, refund information, attribution identifiers, click and event information, IP/device/log information, and customer identifiers or contact information to the extent included in commerce-platform payloads.

Special Categories: Not intentionally required by the Services.

Schedule B: Minimum Security Measures

Affily will maintain safeguards reasonably appropriate to the Services, including as applicable:

  1. access controls and least-privilege principles;
  2. authentication controls;
  3. protection of credentials and secrets;
  4. transport encryption;
  5. signed-webhook authentication;
  6. database authorization and access restrictions;
  7. security logging and monitoring;
  8. fraud and abuse controls;
  9. rate limiting where appropriate;
  10. backup and recovery procedures;
  11. dependency and vulnerability management;
  12. secure software-development and change-management practices;
  13. incident-response procedures;
  14. confidentiality requirements for authorized personnel; and
  15. periodic review of security measures based on risk and changes to the Services.