Last Updated: April 22, 2025
This Data Processing Agreement ("Agreement") is entered into by and between:
- Customer: the legal entity agreeing to the Endorsely Terms of Service ("Controller")
- Sourced Digital Ltd., 8 High Street, Brentwood, Essex, CM14 4AB, United Kingdom ("Processor")
This Agreement forms part of the Endorsely Terms of Service and governs the processing of Personal Data by Endorsely on behalf of the Customer in connection with the provision of the Services.
1. Definitions
- "Data Protection Laws": All applicable laws regarding privacy and data protection including the GDPR, UK GDPR, CCPA, and related legislation.
- "Personal Data": Any information relating to an identified or identifiable natural person.
- "Subprocessor": Any third-party data processor engaged by Endorsely.
2. Purpose and Scope
Endorsely will process Personal Data on behalf of the Customer for the sole purpose of providing the affiliate marketing platform and related Services in accordance with the Terms of Service.
3. Duration
This Agreement remains in effect for as long as Endorsely processes Personal Data on behalf of the Customer.
4. Nature of Processing
- Data storage, transfer, access, and usage to support affiliate program creation, tracking, billing, and analytics.
- Automated processing of user interactions and partner activity.
5. Types of Personal Data Processed
- Affiliate names, email addresses
- Payment method and payout data
- IP addresses, device/browser metadata
- Account activity, login timestamps
6. Categories of Data Subjects
- Customer employees, representatives
- Customer’s affiliates, partners
7. Obligations of Endorsely (Processor)
Endorsely shall:
- Process Personal Data only on documented instructions from the Customer
- Ensure all personnel authorized to process Personal Data are bound by confidentiality
- Implement appropriate technical and organizational security measures
- Assist the Customer with data subject rights requests (access, deletion, etc.)
- Notify the Customer without undue delay after becoming aware of a Personal Data breach
- Maintain a record of all categories of processing activities carried out on behalf of the Customer
8. Security Measures
Endorsely will implement industry-standard security measures such as:
- Encryption in transit and at rest
- Role-based access control (RBAC)
- Regular security assessments
- Secure infrastructure hosted on compliant cloud services (e.g., AWS)
9. Use of Subprocessors
Endorsely may use Subprocessors to fulfill its contractual obligations. A current list of subprocessors is available at: [Insert URL or link].
Endorsely ensures all Subprocessors:
- Are contractually bound to equivalent data protection obligations
- Have passed appropriate due diligence and security assessments
Customers may subscribe to email notifications for updates to Subprocessor usage.
10. International Data Transfers
Endorsely may transfer Personal Data outside the EEA, UK, or Switzerland. In such cases, Endorsely shall:
- Use Standard Contractual Clauses (SCCs) approved by the European Commission
- Implement additional safeguards where required
11. Audit Rights
Upon written request, Endorsely shall provide relevant documentation demonstrating compliance. If required by law or under a Customer's audit clause, Endorsely will allow for an on-site audit with reasonable notice and safeguards to preserve confidentiality.
12. Data Return or Deletion
Upon Customer request or termination of the Services:
- Endorsely shall delete or return all Personal Data, unless retention is required by applicable law.
- Backups will be deleted according to our standard retention schedule unless otherwise requested.
13. Data Subject Rights
To the extent required by Data Protection Laws, Endorsely will:
- Promptly notify the Customer of any request received from a data subject
- Assist in responding to such requests (e.g., access, correction, deletion, portability)
14. Liability
Each party's liability arising from or related to this DPA shall be subject to the liability limitations set forth in the Terms of Service.
15. Governing Law and Jurisdiction
This Agreement shall be governed by the laws of the State of Washington, USA. Any disputes shall be subject to the exclusive jurisdiction of courts located in King County, Washington, unless otherwise mandated by applicable law.
Appendix A – Current Subprocessors
Subprocessor
Purpose
Location
Amazon AWS
Cloud hosting & storage
USA/EU
Stripe
Payment processing
USA
Paddle
Billing & subscription
UK
OpenAI
AI-based analytics
USA
Resend
Transactional email
USA
Contact Information
Sourced Digital Ltd
8 High Street, Brentwood, Essex, CM14 4AB, United KingdomEmail: support@endorsely.com