Legal

Data Processing Addendum

The data processing terms between Rekomi (processor) and you (controller). Updated for GDPR Article 28.

Updated 2026-08-30

1. Roles

You are the data controller for personal data of your customers and affiliates. Rekomi, operated by Uplup Inc., is the data processor. Each party complies with applicable data protection law.

2. Scope of processing

Rekomi processes personal data only on documented instructions from you, except as required by law. Personal data covered: affiliate names, emails, addresses, tax forms, payout history; customer email or hashed identifier when used for attribution; fraud signals on clicks and forms (hashed IP, user agent, device fingerprint, and risk scores); lead data submitted through CPL lead forms; the content of messages exchanged between you and your affiliates on the platform; creator profile text and connected social account statistics shown to you; Shopify protected customer data received through our Shopify app; and historical affiliate, conversion, commission, and customer-attribution records (including customer emails and Stripe customer/subscription identifiers) that you import from a previous affiliate platform. Rekomi is an independent controller, not your processor, for the account data of your own brand users and for affiliates’ direct relationship with Rekomi (their Rekomi account, profile, and payout identity), as described in our Privacy Policy.

3. Sub-processors

Rekomi uses sub-processors listed at /legal/subprocessors. We post additions to /legal/subprocessors with the Updated date and email organization owners at least 30 days before a new sub-processor processes Customer personal data, except where a change is needed urgently for security or continuity, in which case we notify as soon as practicable. You may object to a new sub-processor; if we cannot reasonably accommodate the objection, you may terminate the affected service.

4. Security measures

Multi-tenant row-level security, encryption at rest (AES-256) and in transit (TLS 1.3), signed webhooks, and audit logging. Detailed security model at /security.

5. International transfers

Personal data may be processed in the United States by sub-processors. Where required by EU or UK law, we rely on the Standard Contractual Clauses (SCCs) for EU data and the UK International Data Transfer Addendum for UK data, with sub-processors handling EU or UK personal data.

6. Personal data breach notification

Rekomi notifies you without undue delay and no later than 72 hours after we confirm a personal data breach affecting your personal data, including the nature of the breach, affected categories, likely consequences, and remediation taken.

7. Data subject requests

Rekomi assists you in responding to data subject access, rectification, erasure, and portability requests. You can correct affiliate records and export your program data as CSV directly from the dashboard. For erasure, the affiliate deletes their own account from their Settings, or you forward the request to support@rekomi.com and Rekomi handles it within 30 days. For anything else, contact support@rekomi.com.

8. Audit rights

On-site audit is available for Enterprise customers with reasonable advance notice. Independent third-party audit reports will be made available under NDA when those engagements complete.

9. Data return and deletion

On termination, Rekomi keeps personal data available for export and reactivation, and deletes it at the Customer’s request or when the Customer deletes the account. Backups containing personal data are retained for up to 7 days and overwritten on rotation.

10. Conflict

Where this DPA conflicts with the Terms of Service, this DPA prevails for matters of personal data processing.

We keep this addendum current as the product evolves. Enterprise variants and custom amendments are available on request at support@rekomi.com.