Partner Partner

Version 2.1  ·  Effective May 11, 2026

This Data Processing Agreement supersedes all prior versions, including versions dated September 21, 2025 and May 7, 2026.


1. Parties and Scope

This Data Processing Agreement (the “DPA”) is entered into between Prish Partners, Inc., doing business as Partner Partner (“Partner Partner,” “we,” “us,” or “our”), and the customer that has entered into a Terms of Service or written agreement with Partner Partner for use of the Partner Partner platform (the “Services”). The customer is referred to in this DPA as the “Controller” or “you.”

This DPA governs the Processing of Personal Data carried out by Partner Partner on behalf of the Controller in connection with the Services. It forms part of, and is incorporated by reference into, the Controller’s agreement with Partner Partner (the “Principal Agreement”). In the event of any conflict between this DPA and the Principal Agreement with respect to the Processing of Personal Data, this DPA controls.

This DPA reflects the operational reality of the Services as of the Effective Date, including the ingestion of partner program data from third-party platforms (such as PartnerStack, Mantle, and Tapfiliate) and from manual uploads, and the use of that data to surface anomalies, data integrity issues, and reconciliation findings (collectively referred to in the Services as “Receipts,” “Issues,” and related data health features).

2. Definitions

Capitalized terms used in this DPA have the meanings set forth below. Terms not defined here have the meanings given to them in the Principal Agreement or in applicable Data Protection Laws.

  • Applicable Data Protection Laws: all privacy and data protection laws applicable to the Processing of Personal Data under this DPA, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”), the United Kingdom Data Protection Act 2018 and UK GDPR, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), and other comparable U.S. state privacy laws.
  • Controller: the entity that determines the purposes and means of the Processing of Personal Data. For purposes of CCPA/CPRA, the Controller is the “Business.”
  • Customer Data: data that the Controller, or its Authorized Users, submits to or generates within the Services, including data ingested from Partner Sources at the Controller’s direction.
  • Personal Data: Customer Data that constitutes “personal data” or “personal information” under Applicable Data Protection Laws.
  • Partner Source: a third-party platform from which Customer Data is ingested at the Controller’s direction, including (without limitation) PartnerStack, Mantle, Tapfiliate, partner portals, CRMs the Controller has connected, and CSV uploads of partner program data.
  • Processing: any operation performed on Personal Data, whether by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, transmission, restriction, erasure, or destruction.
  • Processor: Partner Partner, when Processing Personal Data on behalf of the Controller. For purposes of CCPA/CPRA, Partner Partner is a “Service Provider.”
  • Subprocessor: a third party engaged by Partner Partner to Process Personal Data on its behalf in connection with the Services. Partner Sources are not Subprocessors of Partner Partner; see Section 5.
  • Security Incident: a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data Processed by Partner Partner.

3. Processing Roles, Purposes, and Data

3.1 Roles

With respect to Personal Data Processed under the Services, the Controller is the controller and Partner Partner is the processor. Each party is responsible for its own compliance with Applicable Data Protection Laws.

3.2 Subject matter and duration

The subject matter of the Processing is the provision of the Services to the Controller. The duration of the Processing is the term of the Principal Agreement, plus any post-termination period during which Partner Partner retains Customer Data in accordance with Section 9.

3.3 Nature and purpose of Processing

Partner Partner Processes Personal Data only for the following purposes:

  • Providing, operating, maintaining, and supporting the Services.
  • Ingesting Customer Data from Partner Sources that the Controller has connected or otherwise authorized.
  • Normalizing, deduplicating, and resolving identities (such as matching customer and partner records) across ingested data.
  • Performing data integrity, anomaly detection, and reconciliation functions, including the detection and management of Receipts, Issues, and related data health findings.
  • Generating notifications, dashboards, and reporting visible to the Controller and its Authorized Users.
  • Maintaining audit trails and logs of Processing activity for security, debugging, and operational purposes.
  • Complying with the Controller’s documented instructions, the Principal Agreement, and Applicable Data Protection Laws.

The Services apply automated logic to Customer Data in order to surface findings, but Partner Partner does not make decisions that produce legal or similarly significant effects on data subjects. Decisions about how to act on Receipts, Issues, or other findings are made by the Controller and its Authorized Users.

3.4 Categories of data subjects

Personal Data Processed under this DPA may relate to:

  • Authorized Users of the Controller (including employees and contractors).
  • The Controller’s partners, including agency partners, technology partners, and brand partners (and individual contacts at those partners).
  • End customers and merchants referenced in partner program data, including referral leads and accounts.
  • Other individuals whose information appears in records the Controller submits or ingests.

3.5 Categories of Personal Data

Personal Data Processed under this DPA may include:

  • Identification and contact data, such as names, business email addresses, phone numbers, and job titles.
  • Account and relationship data, such as company affiliations, partner program membership, partner tier assignments, and connection status.
  • Transactional data, such as referrals, billings, payouts, commissions, currencies, and transaction identifiers.
  • Identifiers and metadata associated with Partner Sources, such as external customer IDs, partner IDs, and source-system record IDs.
  • Usage and log data generated by interaction with the Services.

Partner Partner is not designed to Process special categories of Personal Data (such as health, biometric, or government identifier data) or children’s data. The Controller agrees not to submit such data to the Services and acknowledges that the Services are not configured to handle it.

4. Partner Partner Obligations

Partner Partner will:

  • Process Personal Data only on the Controller’s documented instructions, including those set out in the Principal Agreement, this DPA, and the configuration of the Services. Use of standard product features (including connecting Partner Sources, enabling Receipts and data health features, and triggering ingestion or analysis) constitutes documented instructions.
  • Promptly inform the Controller if, in Partner Partner’s opinion, an instruction infringes Applicable Data Protection Laws (without obligation to provide legal advice).
  • Implement and maintain the technical and organizational measures described in Schedule 2.
  • Ensure that personnel authorized to Process Personal Data are bound by appropriate confidentiality obligations.
  • Assist the Controller, taking into account the nature of the Processing and the information available to Partner Partner, in fulfilling its obligations under Articles 32 to 36 of the GDPR (and equivalent obligations under other Applicable Data Protection Laws), including responding to data subject requests and Security Incidents.
  • Make available to the Controller information reasonably necessary to demonstrate compliance with this DPA and Applicable Data Protection Laws, in the manner described in Section 8.
  • Not “sell” or “share” Personal Data within the meaning of CCPA/CPRA, and not retain, use, or disclose Personal Data outside of the direct business relationship between the parties or for any purpose other than performing the Services and as otherwise permitted by Applicable Data Protection Laws.

5. Subprocessors and Partner Sources

5.1 Authorization to engage Subprocessors

The Controller provides general written authorization for Partner Partner to engage Subprocessors to Process Personal Data in connection with the Services, subject to this Section 5.

5.2 Current Subprocessors

A current list of Partner Partner’s Subprocessors is maintained at https://yourpartnerpartner.com/subprocessors (the “Subprocessor List”). The Subprocessor List identifies each Subprocessor, the Processing activity it supports, and the location of Processing. Examples of categories of Subprocessors include cloud hosting and serverless infrastructure, secrets management, transactional email delivery, and engineering observability.

5.3 Notice of changes

Partner Partner will provide notice of any new or replaced Subprocessor by updating the Subprocessor List. The Controller may object to the engagement of a new Subprocessor on reasonable data protection grounds within fourteen (14) days of the update. If the parties cannot resolve the objection, the Controller’s sole remedy is to terminate the affected Services in accordance with the Principal Agreement.

5.4 Subprocessor obligations

Partner Partner will impose data protection terms on each Subprocessor that are no less protective than those in this DPA, and remains liable to the Controller for the acts and omissions of its Subprocessors to the same extent as if performed by Partner Partner.

5.5 Partner Sources are not Subprocessors

Partner Sources (such as PartnerStack, Mantle, Tapfiliate, partner portals, CRMs, and other systems from which Customer Data is ingested) are not Subprocessors of Partner Partner. Partner Sources operate under their own terms and privacy policies as independent controllers, or as processors of the Controller, with respect to data they generate or hold. The Controller is responsible for:

  • Maintaining its own legal relationship with each Partner Source, including any required terms or data processing arrangements.
  • Having the necessary rights and a valid legal basis to authorize Partner Partner to ingest Customer Data from each Partner Source.
  • Configuring or revoking credentials, API access, or uploads used by Partner Partner to ingest data from Partner Sources.

Once Customer Data is ingested into the Services, Partner Partner Processes that data as a Processor under this DPA.

6. International Data Transfers

Partner Partner is established in the United States and primarily Processes Personal Data in the United States. To the extent the Controller transfers Personal Data subject to GDPR, UK GDPR, or the Swiss Federal Act on Data Protection to Partner Partner in a country that has not been recognized as providing an adequate level of data protection, the parties agree that the following apply by reference to govern the transfer:

  • The European Commission’s Standard Contractual Clauses adopted under Implementing Decision (EU) 2021/914 (the “EU SCCs”), with Module Two (Controller-to-Processor) applying.
  • The UK International Data Transfer Addendum to the EU SCCs (the “UK Addendum”), where the transfer is subject to UK GDPR.
  • The Swiss Federal Data Protection and Information Commissioner’s recognized adaptations of the EU SCCs, where the transfer is subject to Swiss law.

For purposes of the EU SCCs: the Controller is the data exporter; Partner Partner is the data importer; Clause 7 (docking clause) is not adopted; Clause 9(a) Option 2 (general written authorization) is selected, with the time period set out in Section 5.3 of this DPA; Clause 11(a) optional language is not adopted; Clause 17 selects the law of Ireland; Clause 18(b) selects the courts of Ireland; Annex I.A and I.B are populated by the Principal Agreement and Sections 3.4 and 3.5 of this DPA; Annex I.C identifies the supervisory authority of the data exporter; and Annex II is populated by Schedule 2 of this DPA.

7. Security and Security Incidents

7.1 Security measures

Partner Partner will implement and maintain the technical and organizational measures set out in Schedule 2 to protect Personal Data against Security Incidents. Partner Partner may update those measures from time to time, provided that the overall level of protection is not materially reduced.

7.2 Notification of Security Incidents

Partner Partner will notify the Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident affecting the Controller’s Personal Data. The notification will include, to the extent then known, the nature of the Security Incident, the categories and approximate volume of Personal Data and data subjects affected, the likely consequences, and the measures taken or proposed to address the incident and mitigate its effects.

7.3 Cooperation

Partner Partner will reasonably cooperate with the Controller in investigating and responding to any Security Incident, including providing additional information as it becomes available. Partner Partner’s notification of, or response to, a Security Incident under this Section 7 is not an acknowledgment by Partner Partner of any fault or liability with respect to the Security Incident.

8. Information and Audits

Partner Partner will make available to the Controller, on reasonable request and no more than once in any twelve (12)-month period (except where required by a regulator or following a Security Incident), information reasonably necessary to demonstrate Partner Partner’s compliance with this DPA. This information may include:

  • Responses to written security and data protection questionnaires.
  • Summaries of Partner Partner’s security policies, controls, and the technical and organizational measures in Schedule 2.
  • Copies of any third-party audit reports or attestations Partner Partner has obtained, where available.

Where Applicable Data Protection Laws require an on-site audit, Partner Partner and the Controller will agree in advance on the scope, timing, duration, and confidentiality terms of the audit. On-site audits are limited to information and systems used for Processing the Controller’s Personal Data, must be conducted during normal business hours with reasonable advance notice, and must not unreasonably interfere with Partner Partner’s operations.

9. Retention, Return, and Deletion

During the term of the Principal Agreement, Partner Partner will retain Personal Data only for so long as necessary to provide the Services, comply with Applicable Data Protection Laws, and meet its legal and audit obligations. Logs and audit records may be retained for longer periods consistent with Schedule 2.

Within thirty (30) days after termination or expiration of the Principal Agreement, Partner Partner will, at the Controller’s option, return Customer Data in a commonly used machine-readable format or delete Customer Data from active production systems, except where Partner Partner is required by law to retain it. Backup and archival copies will be deleted in the ordinary course of Partner Partner’s backup retention cycles.

10. Data Subject Rights

Taking into account the nature of the Processing, Partner Partner will assist the Controller, by appropriate technical and organizational measures and in so far as practicable, to fulfill the Controller’s obligation to respond to requests by data subjects to exercise rights under Applicable Data Protection Laws (including rights of access, rectification, erasure, restriction, portability, and objection).

Where Partner Partner receives a data subject request that relates to Personal Data Processed on behalf of the Controller, Partner Partner will, unless legally prohibited, refer the data subject to the Controller and notify the Controller of the request without undue delay. Partner Partner will not respond to such a request directly except as instructed by the Controller or as required by Applicable Data Protection Laws.

11. Liability

Each party’s liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement. Nothing in this DPA limits or excludes liability that cannot be limited or excluded under Applicable Data Protection Laws.

12. Governing Law and Jurisdiction

This DPA is governed by the laws of the State of Washington, without regard to its conflict of laws principles. The parties consent to the exclusive jurisdiction of the state and federal courts located in King County, Washington for any dispute arising out of or in connection with this DPA, except where the EU SCCs or the UK Addendum specify otherwise for transfers governed by those instruments.

13. Changes to this DPA

Partner Partner may update this DPA from time to time to reflect changes in Applicable Data Protection Laws, the Services, or industry practice. Material changes will be notified to the Controller by email or through the Services at least thirty (30) days before they take effect, and the updated DPA will be posted at https://yourpartnerpartner.com/data-processing-agreement/.

14. Contact

Questions about this DPA, or requests related to it (including audit requests, subprocessor objections, or data subject requests), may be sent to:

Email: support@yourpartnerpartner.com

Website: https://yourpartnerpartner.com

Entity: Prish Partners, Inc., d/b/a Partner Partner

Schedule 1 — Processing Summary

The following table summarizes the Processing carried out under this DPA. Capitalized terms have the meanings set out in this DPA.

Topic Description
Subject matterProvision of the Partner Partner Services to the Controller, including ingestion of partner program data, normalization, identity resolution, anomaly detection, reconciliation, and reporting.
DurationTerm of the Principal Agreement, plus any post-termination period described in Section 9.
Nature and purposeSee Section 3.3.
Categories of data subjectsSee Section 3.4.
Categories of Personal DataSee Section 3.5.
Special categories of Personal DataNot intended to be Processed. Controller agrees not to submit such data to the Services.
Frequency of transferContinuous, including scheduled and on-demand ingestion from Partner Sources and uploads by Authorized Users.
Retention periodSee Section 9.

Schedule 2 — Technical and Organizational Measures

Partner Partner implements and maintains the following technical and organizational measures designed to protect Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, or damage. These measures are reviewed and updated from time to time. Specific implementations may evolve, but the overall level of protection will not be materially reduced.

Measure Description
EncryptionPersonal Data is encrypted in transit using TLS 1.2 or higher. Data at rest in production databases and object storage is encrypted using industry-standard algorithms.
Access controlAccess to production systems is limited to authorized personnel based on least-privilege principles. Administrative access requires multi-factor authentication. Access is reviewed periodically and revoked promptly upon role change or departure.
Secrets managementCredentials and API tokens used to ingest data from Partner Sources are stored in AWS Secrets Manager and accessed only by services and personnel with a documented operational need.
Network securityProduction services are hosted on managed cloud infrastructure (Vercel and AWS) with vendor-managed network controls, including isolation between environments and rate limiting at the edge.
Logical isolationCustomer Data is logically segregated by Controller using account-scoped identifiers and access controls within the Services.
Audit loggingOperational events, including ingestion runs, anomaly detection runs, and Security Incidents, are logged. Logs are retained for periods consistent with operational, security, and compliance needs.
Backup and recoveryProduction data stores are backed up by the underlying platform providers in accordance with their published practices. Restore procedures are exercised on a periodic basis.
PersonnelPersonnel with access to Personal Data are bound by written confidentiality obligations and receive guidance on data protection responsibilities appropriate to their role.
Subprocessor managementSubprocessors are subject to written contractual obligations no less protective than those in this DPA. The list of Subprocessors is maintained at https://yourpartnerpartner.com/subprocessors.
Incident responsePartner Partner maintains an internal procedure for identifying, investigating, and notifying the Controller of Security Incidents in accordance with Section 7.
Vendor and platform reliancePartner Partner relies on the security controls and certifications of its underlying infrastructure providers (including Vercel, AWS, and Bubble) and inherits relevant controls from those providers.

© Prish Partners, Inc. d/b/a Partner Partner. All rights reserved.