Data Processing Agreement (Annex 1)
Annex 1 to the Selgeo Terms of Use. Version 1.1, effective 12 August 2026 (supersedes Version 1.0, which was effective alongside Terms of Use v1 from 28 April 2026).
What changed in Version 1.1: Section 5 (Data-subject rights) now describes the technical means by which the Processor assists the Controller with Buyer erasure requests and the applicable timing, in line with Articles 17 and 28(3)(e) GDPR.
This Data Processing Agreement (the "DPA") is entered into between the Merchant (the "Controller") and Selgeo (the "Processor") and governs the processing of personal data of Buyers and Partners in connection with the use of the Selgeo platform (the "Platform").
1. Subject matter and roles
1.1. Under this DPA the Merchant determines the purposes and means of processing as the Controller. Selgeo processes personal data solely on behalf of and on the documented instructions of the Merchant, as the Processor.
1.2. Categories of personal data: email addresses, transaction identifiers, payment amounts, Stripe metadata, technical click identifiers.
1.3. Categories of data subjects: the Merchant's Buyers and the Merchant's Partners.
2. Obligations of the Processor
Selgeo undertakes to:
2.1. Process personal data only for the provision of attribution services and the operation of the partner programme.
2.2. Confidentiality. Ensure that personnel authorised to process the personal data are bound by a strict confidentiality undertaking.
2.3. Security (Article 32 GDPR). Implement appropriate technical and organisational measures (encryption, access control) ensuring a level of security appropriate to the risk.
3. Localisation and data transfers
3.1. EEA-only storage. The Processor undertakes to store and process personal data exclusively on servers located within the European Economic Area (EEA). The current data centres and sub-processors are listed atselgeo.com/sub-processors.
3.2. Any transfer of personal data outside the EEA is prohibited without the prior written consent of the Merchant and the implementation of Standard Contractual Clauses (SCC).
4. Sub-processors
4.1. The Merchant grants a general authorisation for the engagement of sub-processors. The current list of sub-processors with names, jurisdictions, and transfer mechanisms is published at selgeo.com/sub-processors and updated at least fourteen days before any addition, removal, or change takes effect.
4.2. Selgeo remains fully responsible for the acts and omissions of its sub-processors and ensures that each sub-processor is bound by data-protection obligations equivalent to those set out in this DPA.
5. Data-subject rights
5.1. The Processor assists the Controller, by appropriate technical and organisational measures and insofar as this is possible taking into account the nature of the processing, in fulfilling the Controller's obligation to respond to requests by Buyers or Partners to exercise their rights under Chapter III of the GDPR (including erasure, access, and portability), in accordance with Article 28(3)(e) GDPR.
5.2. For erasure requests (Article 17 GDPR), the Processor provides the Controller with self-service and operator-assisted tools that erase the relevant data subject's personal datawithout undue delay. Personal data whose retention is required by a legal obligation (in particular accounting and tax records) or that is necessary for the establishment, exercise, or defence of legal claims (Article 17(3) GDPR) are not deleted butpseudonymised: the identifying data are severed while the minimum records required by law are retained.
5.3. The Controller remains responsible for verifying the identity and validity of a data subject's request (Article 12(6) GDPR). The Processor acts solely on the Controller's documented instructions.
5.4. The one-month period for informing the data subject of the action taken on a request (Article 12(3) GDPR, extendable by two further months where justified) is the Controller's obligation. The Processor's assistance is provided in good time to enable the Controller to meet that deadline.
6. Deletion of data
6.1. On termination of the Terms of Use, the Processor undertakes to delete all personal data within thirty days, except for data whose retention is required by EU or member-state law.
7. Technical specification (Privacy by Design)
7.1. Cookieless tracking. The parties confirm that the attribution method used (sessionStorage) is strictly necessary to provide the commission-tracking functionality requested by the user, and does not require consent under the exception in the ePrivacy Directive.
Effective 28 April 2026. Apliteni OÜ, registry code 14296961, Tornimäe tn 3 // 5 // 7, 10145 Tallinn, Estonia. Contact:contact@selgeo.com.