Sprout Affiliate ← Back to site

Legal

Data Processing Agreement

Version 1.0 · Last updated: September 3, 2026

This Data Processing Agreement ("DPA") applies where a merchant ("Controller") installs Sprout Affiliate and, in doing so, has us process personal data on their behalf. It forms part of the Terms of Service between the Controller and O10 Media LLC, a California limited liability company trading as Sprout Affiliate ("Processor," "we," "us").

It is already in force. You do not have to ask for it. Installing Sprout Affiliate accepts this DPA, so a merchant in the EU, the UK or Switzerland has a signed Article 28 agreement and transfer safeguards from the moment they install. If your organisation needs a countersigned PDF for its records, email support@sproutaffiliate.com with your legal entity name and address and we will return one, normally within two business days.

1. Roles

For personal data about shoppers and affiliates in a merchant's program, the merchant is the Controller and Sprout Affiliate is the Processor. The merchant decides who joins their program, what commission is owed and when payouts happen. We act only on the merchant's instructions.

Where we process data about the merchant's own account (billing, support, security logs) we act as a Controller, and our Privacy Policy governs that.

2. Subject matter, duration, nature and purpose

Categories of data subjects

Types of personal data

We do not process payment card data. We do not ask for and do not want special category data under Article 9.

3. Our obligations

We will:

4. Sub-processors

The Controller gives general authorisation for the sub-processors listed at sproutaffiliate.com/subprocessors.html. We will post any intended addition or replacement there at least 30 days in advance. A Controller who objects on reasonable data protection grounds within those 30 days may tell us, and if we cannot offer a reasonable alternative the Controller may terminate the affected part of the service without penalty.

Each sub-processor is engaged under a written contract imposing data protection obligations no less protective than this DPA. We remain fully liable to the Controller for a sub-processor's performance.

5. International transfers

Sprout Affiliate is operated from the United States, and the application and database run in Ashburn, Virginia. Personal data from the European Economic Area, the United Kingdom or Switzerland is therefore transferred to the United States.

For those transfers the parties adopt, and this DPA incorporates by reference:

Where the SCCs conflict with the rest of this DPA, the SCCs prevail.

6. Government access requests

We have received no national security orders or government requests for the personal data we process for merchants. If we receive one we will, unless legally prohibited, notify the affected Controller, challenge requests that appear unlawful or overbroad, and disclose only the minimum required. We will publish any change to the first sentence of this paragraph on this page.

7. Data subject requests

If a data subject contacts us directly about a merchant's program, we will not respond substantively ourselves. We will tell them to contact the merchant and, unless prohibited, tell the merchant promptly.

The app is built so a merchant can answer these requests without us: affiliate records can be viewed, corrected, exported and deleted from the admin, and every affiliate can export or delete their own data from their portal. Where a merchant still needs help, we will assist at no charge.

8. Personal data breaches

We will notify the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting their data. The notice will describe what happened, the categories and approximate number of data subjects and records involved, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once, we will provide it in phases without undue further delay.

9. Audits

We will make available to the Controller the information reasonably necessary to demonstrate compliance with Article 28, including answering a written security questionnaire. Where that is not sufficient, the Controller may audit once in any twelve-month period on 30 days' written notice, during business hours, without unreasonably disrupting the service, and subject to confidentiality. A supervisory authority may audit at any time as the law allows.

10. Deletion and return

When the app is uninstalled or the agreement ends, we delete the merchant's personal data. Uninstalling triggers Shopify's shop/redact webhook, which purges the store's data across every table that holds it. Deletion completes within 30 days of that request. A merchant may ask for an export before deletion, and may ask for immediate deletion at support@sproutaffiliate.com or via sproutaffiliate.com/delete-data.html.

Database snapshots are retained for 5 days and then expire, so deleted data is gone from backups within that window as well.

11. Liability and governing law

Liability under this DPA is subject to the limitations in the Terms of Service, except that nothing limits liability that cannot be limited by law, and except that the SCCs govern liability for the transfers they cover.

Annexes

Annex I

A. List of parties

Data exporter (Controller): the merchant that installed Sprout Affiliate. Name, address and contact are those on the merchant's Shopify account and, where a countersigned copy is requested, those the merchant provides. Activities: operating an affiliate marketing program for its own store. Signature and date: given by installing the app, or by the countersigned copy.

Data importer (Processor): O10 Media LLC, trading as Sprout Affiliate, California, United States. Contact: support@sproutaffiliate.com. Activities: providing the Sprout Affiliate service. Role: Processor.

B. Description of transfer

C. Competent supervisory authority

The supervisory authority of the EEA member state in which the Controller is established. Where the Controller is not established in the EEA but has an Article 27 representative, the authority of the representative's member state. For UK transfers, the Information Commissioner's Office. For Swiss transfers, the FDPIC.

Annex II · Technical and organisational measures

These are the measures actually in place, not aspirations.

Encryption

Access control

Separation and integrity

Resilience and logging

Data minimisation

Annex III · List of sub-processors

The Controller has authorised the sub-processors listed at sproutaffiliate.com/subprocessors.html, which forms part of this Annex and states each one's name, purpose, the data it receives and its location.

Contact

Questions about this DPA, or a request for a countersigned copy: support@sproutaffiliate.com.