1. Parties and roles
The client is the controller: you determine the purposes and means of the processing. DIKKE KASSA is the processor: we process personal data solely on your documented instructions.
This agreement applies to all services in which we have access to personal data in your systems, such as your affiliate software, network account or store analytics.
2. Subject matter and duration
The processing concerns the setup, management and optimisation of affiliate programs in European markets, including publisher management, transaction validation and reporting.
This agreement runs for the duration of the main agreement and ends once we no longer process personal data for you, subject to clause 11.
3. Nature and purpose of the processing
We process personal data solely to manage your affiliate program: vetting and managing publishers, validating transactions, compiling reports and resolving tracking issues.
We never use the data for our own purposes, such as profiling, selling it to third parties or approaching your publishers for other brands.
4. Categories of data and data subjects
The processing may cover the following categories, depending on how your program is configured.
- Data subjects: publishers, website visitors and customers of the client.
- Publishers: name, email address, website, payment details and performance statistics.
- Transaction data: order references, order values, commissions and click IDs, whether or not linked to an online identifier.
- Technical data: IP addresses and device data insofar as they appear in tracking and reporting systems.
5. Our obligations as processor
We commit to:
- Processing personal data only on your documented instructions, including this agreement.
- Ensuring that staff and engaged third parties are bound by confidentiality.
- Implementing appropriate technical and organisational measures (clause 6).
- Assisting you with data subject requests and with your obligations under Articles 32 to 36 GDPR, such as breach notification and impact assessments.
- Deleting or returning all data after the end of the services, at your choice.
6. Security measures
We take at least the following measures:
- Encrypted connections (HTTPS/TLS) for all data transfers.
- Access on a need-to-know basis, with individual accounts and strong authentication.
- Storage within the European Union with providers carrying their own EU processing responsibility.
- Regular updates and security patches of the systems in use.
- Logical separation of client data per client.
7. Sub-processors
You grant us general authorisation to engage sub-processors for hosting, email, analytics and affiliate platforms. We inform you in advance of intended changes; you then have two weeks to object.
We impose obligations on each sub-processor no lighter than this agreement and remain fully liable for their performance.
8. Transfers outside the EU
In principle we process personal data within the European Union. Transfers to a third country only take place where an appropriate safeguard applies, such as an adequacy decision or the European Commission's standard contractual clauses, and only to the extent necessary for the agreed service.
9. Data breaches
We notify you as the controller of any personal data breach affecting the data we process without undue delay, and no later than 48 hours after becoming aware of it. The notification describes the nature of the breach, the likely consequences and the measures taken or proposed, so you can meet your own notification duty towards the supervisory authority.
10. Audits and information
We provide all information reasonably necessary to demonstrate compliance with this agreement. Once a year, at your own expense and with prior notice, you may have an audit performed by an independent expert bound by confidentiality.
11. End of services
After the collaboration ends, we delete all personal data processed on your behalf within 60 days, unless you request return in writing or a statutory retention obligation requires us to keep certain data longer.
12. Liability and precedence
Liability under this agreement is subject to the same limitations as our general terms and conditions. In case of conflict between this data processing agreement and the general terms, this agreement prevails with regard to the processing of personal data.
This agreement is governed by Dutch law.