Legal
Data processing agreement
Version 1.0, 26 August 2026
In plain English
Your affiliates and your referred customers are your data. You decide what it is for and we hold it for you, which under UK GDPR makes you the controller and us the processor, and a processor needs a written contract. This is that contract, and you already have it: it is part of the terms you accepted, so nothing needs signing. This page is the copy to keep on file, and it prints.
This agreement is between James Barkway trading as AffiliateRail, Office 4382, 182-184 High Street North, London, E6 2JA, United Kingdom ("we", "us", the processor), and the customer named on the AffiliateRail account ("you", the controller).
It forms part of the terms of service and takes effect when you open an account. Where this agreement and the terms disagree about personal data, this agreement wins. It is governed by the law of England and Wales, and by the same courts, as clause 15 of the terms.
1. What this covers
Personal data we process on your behalf when you run a program on AffiliateRail. Annex 1 is the detail: whose data, what kind, and what we do with it.
It does not cover your own account with us, your subscription or your invoices. There we decide why the data is held, so we are the controller and our privacy policy applies instead.
Words like personal data, processing, controller, processor, data subject and personal data breach mean what UK GDPR and the Data Protection Act 2018 say they mean.
2. We act on your instructions and nothing else
- We process the personal data only on your documented instructions, including on transfers out of the UK. Your instructions are: this agreement, the terms, the settings you choose in the product, and anything you ask us to do in writing.
- Using the product is an instruction. Approving a partner, running a payout, sending a campaign, importing a list: each is you telling us to process, and we do not need a separate note for it.
- If the law makes us process your data for some other reason, we tell you before we do it unless that same law forbids the telling.
- If we think an instruction breaks data protection law, we tell you. We do not simply carry it out and we do not simply refuse.
- We never sell your data, never use it to train an AI model, and never use it to build a product of our own. What we learn from running the service is counts and error rates, never anyone's content.
3. Confidentiality
Everyone who can reach your data is bound to keep it confidential, and that duty outlives their involvement. Today that is one person, the proprietor. Where that changes, it changes with a written confidentiality obligation in place first, not afterwards.
4. Security
We take the technical and organisational measures in Annex 2, which are appropriate to the risk. We may change them, and we do not lower them: any change leaves the protection at least as strong.
Our security page is the plain-language version of the same measures, and it says what we do not do as well as what we do.
5. Sub-processors
- You give us general written authorisation to use sub-processors. The current list is published at affiliaterail.com/subprocessors and is part of this agreement.
- We give you 30 days' notice before a new sub-processor starts processing your data. Notice goes to the email on your account and the page is updated the same day.
- You may object, with reasons, during those 30 days. We will try to find another way. If we cannot, you may end your subscription for the affected service and we refund the unused part of what you have paid.
- Every sub-processor is under written terms that carry the same obligations as this agreement, so far as they apply. We stay responsible to you for what they do, exactly as if we had done it.
- Your own payment rails and your own billing provider are not our sub-processors. When a payout goes out we call PayPal, Wise or Payoneer with credentials you connected, on your account. They are your processors and your agreement with them is yours.
6. Helping you answer people
- The product does most of this without us. Settings, then Data requests, exports everything held about one partner or customer, or deletes it. That is the mechanism, and it is available to you at any time.
- If someone contacts us directly about data we hold for you, we do not answer for you. We tell them you are the controller and pass the request to you promptly, and the public page that receives those requests says the same thing.
- Where you still need help, given the nature of the processing and what we can see, we give it. We do not charge for a reasonable amount of it.
- We help you with data protection impact assessments and with consulting the ICO, to the extent the information is ours to give.
7. If there is a breach
- We tell you about a personal data breach affecting your data without undue delay once we know about it, and in any event within 48 hours.
- The notice says what happened, which kinds of data and roughly how many people, what the likely consequences are, what we have done and are doing, and who to talk to. Where we cannot give all of that at once, we send what we have and follow it up rather than waiting.
- Reporting to the ICO and telling the people affected is yours, because you are the controller. We give you what you need to do it.
- We do not notify your regulator or your people on your behalf, and we do not make a public statement naming you without talking to you first.
8. Deletion and return
- You can export at any time while your account is open, per clause 6.1, and the export is machine readable.
- When your account closes you have 30 days to export or to change your mind. After that we delete the program's personal data.
- What survives deletion, and why: money amounts with nobody's name attached, so your own books keep balancing; the audit log; records we are required by law to keep, for as long as that law says. A record kept under a legal obligation is used for that obligation and nothing else.
- Backups are not deleted item by item, because they cannot be. They expire on their own schedule and a restored backup is re-purged. The window is 7 days.
- The full schedule, record by record, is the retention schedule described in Annex 1.
9. Audit and information
- We give you the information you need to show that this agreement is being kept, and this page, the security page and the sub-processor list are most of it.
- We allow and contribute to audits, including inspections, by you or an auditor you appoint. Reasonable notice of at least 30 days, during working hours, no more than once a year unless a breach or a regulator's instruction makes it necessary, subject to confidentiality, and not in a way that puts another customer's data at risk.
- We are not certified to SOC2, ISO 27001 or any other scheme, so there is no report to send instead. We answer questions directly, and the security page says what we actually do.
10. Transfers out of the UK
Personal data processed under this agreement is transferred to the United States, because every sub-processor in the list processes there. No personal data is processed inside the UK or the EEA today. The mechanism relied on for each one is in Annex 3.
Where a mechanism stops being valid, we move to another lawful one or stop using that sub-processor. You authorise us to enter into transfer terms with a sub-processor on your behalf where a mechanism requires it.
11. Liability
Liability under this agreement is subject to the limits in clause 12 of the terms. Nothing here limits either side's own liability to a data subject or to a regulator, which is not ours to limit.
12. Changing this agreement
We may update this agreement. Where a change materially reduces your protection we email you at least 30 days before it takes effect, and you may end your subscription in that period if you do not accept it. Sub-processor changes follow clause 5 instead.
Annex 1: what is processed
Subject matter and duration
Running your affiliate program: tracking referrals, calculating commissions, paying partners from your own account, and the communication around all of it. It lasts as long as your account, plus the 30 days and the retained records in clause 8.
Whose data
- Your affiliates, and people who applied to be one.
- Your customers, where a referral is tracked to a sale, and where automatic enrolment is switched on, which turns a customer into an affiliate.
- Visitors who click an affiliate link, before they are anyone.
- Your own team, where you invite colleagues into the program.
What kind of data
| Category | What that means |
|---|---|
| Identity and contact | Name, email, handle, company, website, country, language |
| Application answers | Whatever your own custom fields ask for |
| Financial | Payout method details, encrypted. Commission, payout and invoice amounts |
| Tax | W-9, W-8BEN and W-8BEN-E: legal name, address and taxpayer identification number, encrypted |
| Behavioural | Clicks, with a hashed IP address, browser, referring site and landing page. Referrals, leads and sales |
| Communication | Emails and messages sent through the program, and whether they were opened |
| Customer | Email, name, your own identifier, and the billing provider's ids for them |
No special category data is asked for, and none of it is needed. If a custom field of yours collects it, that is your decision and your lawful basis, not ours.
What we do with it
Store it, track referrals, work out commissions, apply your rules, show your affiliates their own performance, instruct payouts on your own rails, collect and store tax forms, send the emails your program sends, back it up, and give you the exports and deletions in clause 6.
How long
Per clause 8. The full schedule, record by record, with the reason for each period and what wins where two rules disagree, is kept in the repository as the retention schedule and is available on request from support@affiliaterail.com.
Annex 2: security measures
| Measure | What we do |
|---|---|
| Encryption in transit | TLS on every surface, including the tracker and the short-link redirector |
| Encryption at rest | The whole database, at the provider. Payout credentials and tax form payloads are encrypted a second time in the application, under a per-deployment key with a key id so a key can be rotated without re-encrypting everything at once. That key is not in the database |
| Access control | Two-factor authentication on accounts. API keys stored as a hash and shown once, with scopes enforced on the server. Plan limits enforced on the server, never only in the interface |
| Separation | One tenancy check on every query, tested with two customers seeded side by side rather than asserted |
| Money handling | Payouts are non-custodial. We hold no funds and no payment credential of our own. Every write that moves money is idempotent on a unique index, so a repeat cannot pay twice |
| Integrity | An audit log of every consequential action, including the record of a deletion. Webhooks are signed, and a rotated secret keeps working for 24 hours |
| Availability | Managed Postgres with a 7 day point-in-time history. A restore drill is run and its result logged with the numbers |
| Testing | An automated suite of several thousand tests runs before anything ships, including tests that prove one customer's data cannot be read from another's session |
| Vulnerability reports | security@affiliaterail.com, human reply within two working days and a fix timeline within five |
Annex 3: transfers
Every sub-processor processes in the United States. The mechanism relied on for each, checked against that provider's own published terms on 26 August 2026:
| Sub-processor | Mechanism |
|---|---|
| Neon (Databricks) | EU-US Data Privacy Framework with the UK Extension, certified with the US Department of Commerce, backed by the 2021 Standard Contractual Clauses and the UK International Data Transfer Addendum |
| Vercel, including Vercel Blob | 2021 Standard Contractual Clauses with the UK International Data Transfer Addendum. No Data Privacy Framework certification is claimed |
| Stripe | Standard Contractual Clauses, the UK International Data Transfer Addendum, and Data Privacy Framework self-certification, through Stripe's data transfers addendum |
| Resend | EU-US Data Privacy Framework with the UK Extension, certified, plus the EU Standard Contractual Clauses and the UK Addendum |
| Upstash | EU-US Data Privacy Framework with the UK Extension, plus Standard Contractual Clauses |
| Sentry | Data Privacy Framework, with Standard Contractual Clauses and the UK Addendum as the fallback |
| PostHog | EU-US Data Privacy Framework with the UK Extension, plus Standard Contractual Clauses and the UK International Data Transfer Addendum |
| Inngest | Not confirmed. No published addendum was found and one is being requested. Only our own record ids reach it, never personal data |
| Firecrawl | Not confirmed. A published addendum is being requested. It receives the public website address an applicant gives us and nothing else about them |
Two rows say "not confirmed" rather than naming a mechanism we have not seen. That is the honest state of it on the date above, and both are being chased. Neither one receives personal data, which is why the service still runs while we sort the paperwork out.
Getting a copy
This page prints. Use your browser's print or save-as-PDF and the navigation drops away.
If your procurement process needs a signed copy rather than one accepted by reference, email support@affiliaterail.com and we will send one.