Data Processing Addendum
Last updated: 31 July 2026
This DPA forms part of the agreement between you (the "Customer" and controller) and Yonto Sales Ltd ("Yonto", the processor) and applies where Yonto processes personal data on your behalf, including under the UK GDPR and EU GDPR. It supplements our Terms of Service and Privacy Policy.
1. Roles
For the personal data processed to attribute sales on your store, you are the controller and Yonto is the processor. Yonto processes that data only on your documented instructions, which include these terms and your use of the Service.
2. Subject matter and duration
The subject matter is the provision of the attribution Service. Processing lasts for the term of your subscription and any wind-down period described below.
3. Nature and purpose of processing
To record clicks on creators' tracked links, match subsequent purchases (by cookie or discount code), and report aggregated attribution figures to you.
4. Types of personal data
- A random click identifier stored in a first-party cookie (an online identifier);
- Order total, currency, and discount code for attributed orders.
Yonto does not process shopper names, emails, addresses, payment details, or product line items.
5. Categories of data subjects
Visitors to your store who arrive via a creator's tracked link, and shoppers who complete an attributed purchase.
6. Our obligations as processor
- Process personal data only on your documented instructions;
- Ensure persons authorised to process it are bound by confidentiality;
- Implement appropriate technical and organisational security measures (clause 7);
- Assist you, taking into account the nature of processing, with data-subject requests and with your security, breach and impact-assessment obligations;
- Make available information needed to demonstrate compliance, and allow for reasonable audits (clause 11).
7. Security
Yonto uses row-level access controls so each business can only reach its own data, encryption in transit, least-privilege access, and reputable infrastructure providers. Because we deliberately avoid collecting shopper contact details or line items, the data at risk is minimal by design.
8. Sub-processors
You authorise Yonto to engage sub-processors to provide the Service — currently our hosting/database provider, our transactional email provider, and our payment provider (as merchant of record). We remain responsible for their performance and will give notice of intended changes so you can object on reasonable data-protection grounds.
9. International transfers
Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards such as the UK International Data Transfer Agreement / Addendum or the EU Standard Contractual Clauses, or an adequacy decision.
10. Data-subject requests and breaches
We will promptly notify you of, and assist with, any data-subject request we receive relating to your data, and we will notify you without undue delay after becoming aware of a personal-data breach affecting your data.
11. Audit
On reasonable written request and no more than once a year (unless required by a supervisory authority), we will provide information reasonably necessary to demonstrate compliance with this DPA.
12. Return and deletion
On termination, we will delete or anonymise the personal data processed on your behalf within a reasonable period, except where we must retain it by law. See the Privacy Policy for retention detail.
13. General
If there is a conflict between this DPA and the Terms of Service on the processing of personal data, this DPA prevails. This DPA is governed by the law of England and Wales.
14. Contact
Data protection contact: privacy@yontosales.com.