Partner Partner
Version 2.1 · Effective May 11, 2026
This Data Processing Agreement supersedes all prior versions, including versions dated September 21, 2025 and May 7, 2026.
1. Parties and Scope
This Data Processing Agreement (the “DPA”) is entered into between Prish Partners, Inc., doing business as Partner Partner (“Partner Partner,” “we,” “us,” or “our”), and the customer that has entered into a Terms of Service or written agreement with Partner Partner for use of the Partner Partner platform (the “Services”). The customer is referred to in this DPA as the “Controller” or “you.”
This DPA governs the Processing of Personal Data carried out by Partner Partner on behalf of the Controller in connection with the Services. It forms part of, and is incorporated by reference into, the Controller’s agreement with Partner Partner (the “Principal Agreement”). In the event of any conflict between this DPA and the Principal Agreement with respect to the Processing of Personal Data, this DPA controls.
This DPA reflects the operational reality of the Services as of the Effective Date, including the ingestion of partner program data from third-party platforms (such as PartnerStack, Mantle, and Tapfiliate) and from manual uploads, and the use of that data to surface anomalies, data integrity issues, and reconciliation findings (collectively referred to in the Services as “Receipts,” “Issues,” and related data health features).
2. Definitions
Capitalized terms used in this DPA have the meanings set forth below. Terms not defined here have the meanings given to them in the Principal Agreement or in applicable Data Protection Laws.
- Applicable Data Protection Laws: all privacy and data protection laws applicable to the Processing of Personal Data under this DPA, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”), the United Kingdom Data Protection Act 2018 and UK GDPR, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), and other comparable U.S. state privacy laws.
- Controller: the entity that determines the purposes and means of the Processing of Personal Data. For purposes of CCPA/CPRA, the Controller is the “Business.”
- Customer Data: data that the Controller, or its Authorized Users, submits to or generates within the Services, including data ingested from Partner Sources at the Controller’s direction.
- Personal Data: Customer Data that constitutes “personal data” or “personal information” under Applicable Data Protection Laws.
- Partner Source: a third-party platform from which Customer Data is ingested at the Controller’s direction, including (without limitation) PartnerStack, Mantle, Tapfiliate, partner portals, CRMs the Controller has connected, and CSV uploads of partner program data.
- Processing: any operation performed on Personal Data, whether by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, transmission, restriction, erasure, or destruction.
- Processor: Partner Partner, when Processing Personal Data on behalf of the Controller. For purposes of CCPA/CPRA, Partner Partner is a “Service Provider.”
- Subprocessor: a third party engaged by Partner Partner to Process Personal Data on its behalf in connection with the Services. Partner Sources are not Subprocessors of Partner Partner; see Section 5.
- Security Incident: a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data Processed by Partner Partner.
3. Processing Roles, Purposes, and Data
3.1 Roles
With respect to Personal Data Processed under the Services, the Controller is the controller and Partner Partner is the processor. Each party is responsible for its own compliance with Applicable Data Protection Laws.
3.2 Subject matter and duration
The subject matter of the Processing is the provision of the Services to the Controller. The duration of the Processing is the term of the Principal Agreement, plus any post-termination period during which Partner Partner retains Customer Data in accordance with Section 9.
3.3 Nature and purpose of Processing
Partner Partner Processes Personal Data only for the following purposes:
- Providing, operating, maintaining, and supporting the Services.
- Ingesting Customer Data from Partner Sources that the Controller has connected or otherwise authorized.
- Normalizing, deduplicating, and resolving identities (such as matching customer and partner records) across ingested data.
- Performing data integrity, anomaly detection, and reconciliation functions, including the detection and management of Receipts, Issues, and related data health findings.
- Generating notifications, dashboards, and reporting visible to the Controller and its Authorized Users.
- Maintaining audit trails and logs of Processing activity for security, debugging, and operational purposes.
- Complying with the Controller’s documented instructions, the Principal Agreement, and Applicable Data Protection Laws.
The Services apply automated logic to Customer Data in order to surface findings, but Partner Partner does not make decisions that produce legal or similarly significant effects on data subjects. Decisions about how to act on Receipts, Issues, or other findings are made by the Controller and its Authorized Users.
3.4 Categories of data subjects
Personal Data Processed under this DPA may relate to:
- Authorized Users of the Controller (including employees and contractors).
- The Controller’s partners, including agency partners, technology partners, and brand partners (and individual contacts at those partners).
- End customers and merchants referenced in partner program data, including referral leads and accounts.
- Other individuals whose information appears in records the Controller submits or ingests.
3.5 Categories of Personal Data
Personal Data Processed under this DPA may include:
- Identification and contact data, such as names, business email addresses, phone numbers, and job titles.
- Account and relationship data, such as company affiliations, partner program membership, partner tier assignments, and connection status.
- Transactional data, such as referrals, billings, payouts, commissions, currencies, and transaction identifiers.
- Identifiers and metadata associated with Partner Sources, such as external customer IDs, partner IDs, and source-system record IDs.
- Usage and log data generated by interaction with the Services.
Partner Partner is not designed to Process special categories of Personal Data (such as health, biometric, or government identifier data) or children’s data. The Controller agrees not to submit such data to the Services and acknowledges that the Services are not configured to handle it.
4. Partner Partner Obligations
Partner Partner will:
- Process Personal Data only on the Controller’s documented instructions, including those set out in the Principal Agreement, this DPA, and the configuration of the Services. Use of standard product features (including connecting Partner Sources, enabling Receipts and data health features, and triggering ingestion or analysis) constitutes documented instructions.
- Promptly inform the Controller if, in Partner Partner’s opinion, an instruction infringes Applicable Data Protection Laws (without obligation to provide legal advice).
- Implement and maintain the technical and organizational measures described in Schedule 2.
- Ensure that personnel authorized to Process Personal Data are bound by appropriate confidentiality obligations.
- Assist the Controller, taking into account the nature of the Processing and the information available to Partner Partner, in fulfilling its obligations under Articles 32 to 36 of the GDPR (and equivalent obligations under other Applicable Data Protection Laws), including responding to data subject requests and Security Incidents.
- Make available to the Controller information reasonably necessary to demonstrate compliance with this DPA and Applicable Data Protection Laws, in the manner described in Section 8.
- Not “sell” or “share” Personal Data within the meaning of CCPA/CPRA, and not retain, use, or disclose Personal Data outside of the direct business relationship between the parties or for any purpose other than performing the Services and as otherwise permitted by Applicable Data Protection Laws.
5. Subprocessors and Partner Sources
5.1 Authorization to engage Subprocessors
The Controller provides general written authorization for Partner Partner to engage Subprocessors to Process Personal Data in connection with the Services, subject to this Section 5.
5.2 Current Subprocessors
A current list of Partner Partner’s Subprocessors is maintained at https://yourpartnerpartner.com/subprocessors (the “Subprocessor List”). The Subprocessor List identifies each Subprocessor, the Processing activity it supports, and the location of Processing. Examples of categories of Subprocessors include cloud hosting and serverless infrastructure, secrets management, transactional email delivery, and engineering observability.
5.3 Notice of changes
Partner Partner will provide notice of any new or replaced Subprocessor by updating the Subprocessor List. The Controller may object to the engagement of a new Subprocessor on reasonable data protection grounds within fourteen (14) days of the update. If the parties cannot resolve the objection, the Controller’s sole remedy is to terminate the affected Services in accordance with the Principal Agreement.
5.4 Subprocessor obligations
Partner Partner will impose data protection terms on each Subprocessor that are no less protective than those in this DPA, and remains liable to the Controller for the acts and omissions of its Subprocessors to the same extent as if performed by Partner Partner.
5.5 Partner Sources are not Subprocessors
Partner Sources (such as PartnerStack, Mantle, Tapfiliate, partner portals, CRMs, and other systems from which Customer Data is ingested) are not Subprocessors of Partner Partner. Partner Sources operate under their own terms and privacy policies as independent controllers, or as processors of the Controller, with respect to data they generate or hold. The Controller is responsible for:
- Maintaining its own legal relationship with each Partner Source, including any required terms or data processing arrangements.
- Having the necessary rights and a valid legal basis to authorize Partner Partner to ingest Customer Data from each Partner Source.
- Configuring or revoking credentials, API access, or uploads used by Partner Partner to ingest data from Partner Sources.
Once Customer Data is ingested into the Services, Partner Partner Processes that data as a Processor under this DPA.
6. International Data Transfers
Partner Partner is established in the United States and primarily Processes Personal Data in the United States. To the extent the Controller transfers Personal Data subject to GDPR, UK GDPR, or the Swiss Federal Act on Data Protection to Partner Partner in a country that has not been recognized as providing an adequate level of data protection, the parties agree that the following apply by reference to govern the transfer:
- The European Commission’s Standard Contractual Clauses adopted under Implementing Decision (EU) 2021/914 (the “EU SCCs”), with Module Two (Controller-to-Processor) applying.
- The UK International Data Transfer Addendum to the EU SCCs (the “UK Addendum”), where the transfer is subject to UK GDPR.
- The Swiss Federal Data Protection and Information Commissioner’s recognized adaptations of the EU SCCs, where the transfer is subject to Swiss law.
For purposes of the EU SCCs: the Controller is the data exporter; Partner Partner is the data importer; Clause 7 (docking clause) is not adopted; Clause 9(a) Option 2 (general written authorization) is selected, with the time period set out in Section 5.3 of this DPA; Clause 11(a) optional language is not adopted; Clause 17 selects the law of Ireland; Clause 18(b) selects the courts of Ireland; Annex I.A and I.B are populated by the Principal Agreement and Sections 3.4 and 3.5 of this DPA; Annex I.C identifies the supervisory authority of the data exporter; and Annex II is populated by Schedule 2 of this DPA.
7. Security and Security Incidents
7.1 Security measures
Partner Partner will implement and maintain the technical and organizational measures set out in Schedule 2 to protect Personal Data against Security Incidents. Partner Partner may update those measures from time to time, provided that the overall level of protection is not materially reduced.
7.2 Notification of Security Incidents
Partner Partner will notify the Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident affecting the Controller’s Personal Data. The notification will include, to the extent then known, the nature of the Security Incident, the categories and approximate volume of Personal Data and data subjects affected, the likely consequences, and the measures taken or proposed to address the incident and mitigate its effects.
7.3 Cooperation
Partner Partner will reasonably cooperate with the Controller in investigating and responding to any Security Incident, including providing additional information as it becomes available. Partner Partner’s notification of, or response to, a Security Incident under this Section 7 is not an acknowledgment by Partner Partner of any fault or liability with respect to the Security Incident.
8. Information and Audits
Partner Partner will make available to the Controller, on reasonable request and no more than once in any twelve (12)-month period (except where required by a regulator or following a Security Incident), information reasonably necessary to demonstrate Partner Partner’s compliance with this DPA. This information may include:
- Responses to written security and data protection questionnaires.
- Summaries of Partner Partner’s security policies, controls, and the technical and organizational measures in Schedule 2.
- Copies of any third-party audit reports or attestations Partner Partner has obtained, where available.
Where Applicable Data Protection Laws require an on-site audit, Partner Partner and the Controller will agree in advance on the scope, timing, duration, and confidentiality terms of the audit. On-site audits are limited to information and systems used for Processing the Controller’s Personal Data, must be conducted during normal business hours with reasonable advance notice, and must not unreasonably interfere with Partner Partner’s operations.
9. Retention, Return, and Deletion
During the term of the Principal Agreement, Partner Partner will retain Personal Data only for so long as necessary to provide the Services, comply with Applicable Data Protection Laws, and meet its legal and audit obligations. Logs and audit records may be retained for longer periods consistent with Schedule 2.
Within thirty (30) days after termination or expiration of the Principal Agreement, Partner Partner will, at the Controller’s option, return Customer Data in a commonly used machine-readable format or delete Customer Data from active production systems, except where Partner Partner is required by law to retain it. Backup and archival copies will be deleted in the ordinary course of Partner Partner’s backup retention cycles.
10. Data Subject Rights
Taking into account the nature of the Processing, Partner Partner will assist the Controller, by appropriate technical and organizational measures and in so far as practicable, to fulfill the Controller’s obligation to respond to requests by data subjects to exercise rights under Applicable Data Protection Laws (including rights of access, rectification, erasure, restriction, portability, and objection).
Where Partner Partner receives a data subject request that relates to Personal Data Processed on behalf of the Controller, Partner Partner will, unless legally prohibited, refer the data subject to the Controller and notify the Controller of the request without undue delay. Partner Partner will not respond to such a request directly except as instructed by the Controller or as required by Applicable Data Protection Laws.
11. Liability
Each party’s liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement. Nothing in this DPA limits or excludes liability that cannot be limited or excluded under Applicable Data Protection Laws.
12. Governing Law and Jurisdiction
This DPA is governed by the laws of the State of Washington, without regard to its conflict of laws principles. The parties consent to the exclusive jurisdiction of the state and federal courts located in King County, Washington for any dispute arising out of or in connection with this DPA, except where the EU SCCs or the UK Addendum specify otherwise for transfers governed by those instruments.
13. Changes to this DPA
Partner Partner may update this DPA from time to time to reflect changes in Applicable Data Protection Laws, the Services, or industry practice. Material changes will be notified to the Controller by email or through the Services at least thirty (30) days before they take effect, and the updated DPA will be posted at https://yourpartnerpartner.com/data-processing-agreement/.
14. Contact
Questions about this DPA, or requests related to it (including audit requests, subprocessor objections, or data subject requests), may be sent to:
Email: support@yourpartnerpartner.com
Website: https://yourpartnerpartner.com
Entity: Prish Partners, Inc., d/b/a Partner Partner
Schedule 1 — Processing Summary
The following table summarizes the Processing carried out under this DPA. Capitalized terms have the meanings set out in this DPA.
| Topic | Description |
|---|---|
| Subject matter | Provision of the Partner Partner Services to the Controller, including ingestion of partner program data, normalization, identity resolution, anomaly detection, reconciliation, and reporting. |
| Duration | Term of the Principal Agreement, plus any post-termination period described in Section 9. |
| Nature and purpose | See Section 3.3. |
| Categories of data subjects | See Section 3.4. |
| Categories of Personal Data | See Section 3.5. |
| Special categories of Personal Data | Not intended to be Processed. Controller agrees not to submit such data to the Services. |
| Frequency of transfer | Continuous, including scheduled and on-demand ingestion from Partner Sources and uploads by Authorized Users. |
| Retention period | See Section 9. |
Schedule 2 — Technical and Organizational Measures
Partner Partner implements and maintains the following technical and organizational measures designed to protect Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, or damage. These measures are reviewed and updated from time to time. Specific implementations may evolve, but the overall level of protection will not be materially reduced.
| Measure | Description |
|---|---|
| Encryption | Personal Data is encrypted in transit using TLS 1.2 or higher. Data at rest in production databases and object storage is encrypted using industry-standard algorithms. |
| Access control | Access to production systems is limited to authorized personnel based on least-privilege principles. Administrative access requires multi-factor authentication. Access is reviewed periodically and revoked promptly upon role change or departure. |
| Secrets management | Credentials and API tokens used to ingest data from Partner Sources are stored in AWS Secrets Manager and accessed only by services and personnel with a documented operational need. |
| Network security | Production services are hosted on managed cloud infrastructure (Vercel and AWS) with vendor-managed network controls, including isolation between environments and rate limiting at the edge. |
| Logical isolation | Customer Data is logically segregated by Controller using account-scoped identifiers and access controls within the Services. |
| Audit logging | Operational events, including ingestion runs, anomaly detection runs, and Security Incidents, are logged. Logs are retained for periods consistent with operational, security, and compliance needs. |
| Backup and recovery | Production data stores are backed up by the underlying platform providers in accordance with their published practices. Restore procedures are exercised on a periodic basis. |
| Personnel | Personnel with access to Personal Data are bound by written confidentiality obligations and receive guidance on data protection responsibilities appropriate to their role. |
| Subprocessor management | Subprocessors are subject to written contractual obligations no less protective than those in this DPA. The list of Subprocessors is maintained at https://yourpartnerpartner.com/subprocessors. |
| Incident response | Partner Partner maintains an internal procedure for identifying, investigating, and notifying the Controller of Security Incidents in accordance with Section 7. |
| Vendor and platform reliance | Partner Partner relies on the security controls and certifications of its underlying infrastructure providers (including Vercel, AWS, and Bubble) and inherits relevant controls from those providers. |
© Prish Partners, Inc. d/b/a Partner Partner. All rights reserved.