ReferralLinks Data Processing Agreement
Last updated: 4 September 2026
This Data Processing Agreement (“DPA”) forms part of the ReferralLinks Business Terms of Service or other agreement (“Agreement”) between Referral Ventures Limited, company number 13281997 (“Referral Ventures”, “Processor”, “we”) and the business or organisation using ReferralLinks (“Customer”, “Controller”).
This DPA applies to the extent Referral Ventures processes Customer Personal Data on behalf of Customer.
1. Definitions
“Applicable Data Protection Law” means applicable data protection and privacy laws relating to the Processing, including where applicable the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations 2003, EU GDPR, applicable EU or EEA national privacy and ePrivacy legislation, and applicable United States state privacy legislation governing controllers, processors, businesses, contractors or service providers.
“Customer Personal Data” means Personal Data processed by Referral Ventures on behalf of Customer through ReferralLinks.
“Sub-processor” means a third party engaged by Referral Ventures to process Customer Personal Data on behalf of Customer.
Controller, Processor, Personal Data, Processing, Data Subject, Personal Data Breach and Supervisory Authority have the meanings given by Applicable Data Protection Law.
2. Roles
For Customer Personal Data processed to operate a Customer’s referral programme, Customer is Controller and Referral Ventures is Processor.
Processor activities may include creating referral links and identifiers; storing and recognising rl_vid; processing referral events; applying last-click attribution; receiving server-side conversion events; matching conversions with referral identifiers; recording reward eligibility or status; providing analytics; administering referrer accounts; sending Customer-directed communications to referrers; technical support; and fraud or duplicate-referral detection undertaken in providing the Customer’s programme.
Referral Ventures acts as an independent Controller where it determines the relevant purposes and essential means, including Customer user account administration, authentication, billing and subscriptions, financial records, commercial relationship management, legal compliance, legal claims, protection of Referral Ventures’ own infrastructure, and operation of ReferralCodes.com where Referral Ventures independently determines purposes.
Customer Personal Data provided solely for operation of a Customer’s ReferralLinks programme will not be added to the ReferralCodes member database or used for Referral Ventures’ unrelated marketing solely because the Customer uses ReferralLinks.
3. Customer Instructions
Referral Ventures shall Process Customer Personal Data only on Customer’s documented instructions, as necessary to provide the Services requested or configured by Customer, or where required by applicable law.
Documented instructions include the Agreement, this DPA, Customer’s ReferralLinks account and campaign configuration, instructions given through ReferralLinks, documented support requests and other written instructions agreed between the parties.
Referral Ventures shall notify Customer if Referral Ventures reasonably considers an instruction to breach Applicable Data Protection Law.
Where Referral Ventures is required by law to undertake Processing other than on Customer’s instructions, Referral Ventures shall inform Customer before doing so unless prohibited by law.
4. Customer Obligations
Customer is responsible for establishing a lawful basis for its Processing, providing required privacy information, ensuring it has authority to disclose Customer Personal Data to Referral Ventures, determining whether consent is required for referral tracking, implementing and obtaining consent where required, complying with electronic communications and marketing laws, and ensuring its instructions are lawful.
Customer shall not intentionally provide through ReferralLinks special-category Personal Data, criminal-offence data, payment-card credentials, bank-account login details, passwords belonging to Data Subjects, sensitive government identification data or other high-risk Personal Data not reasonably required by ReferralLinks unless separately agreed in writing.
5. Processing Instructions for Attribution
Customer instructs Referral Ventures to process referral attribution information where the relevant Services are enabled.
The standard ReferralLinks attribution system uses a unique referral URL, a referral identifier, a first-party cookie currently named rl_vid, timestamps and server-side conversion information supplied by Customer.
ReferralLinks currently applies last-click attribution. The standard attribution period is 30 days. Where supported, Customer may configure attribution periods between 1 and 365 days. The standard rl_vid browser-cookie duration is currently 30 days.
Referral Ventures shall not use Customer-specific referral identifiers processed solely as Processor to track Data Subjects across unrelated Customer websites for Referral Ventures’ own behavioural advertising or profiling.
6. Referrer Communications
Customer may instruct Referral Ventures to send programme-related emails to its referrers, including verification, account information, referral links, referral activity, conversions, rewards, security information and operational information.
Where these communications are sent solely on Customer’s behalf, Referral Ventures acts as Processor.
Customer remains responsible for determining whether requested communications are lawful.
Referral Ventures shall not use an email address supplied solely as Customer Personal Data to send unrelated Referral Ventures marketing unless Referral Ventures has independently established an appropriate lawful basis and provided required privacy information.
7. Confidentiality
Referral Ventures shall ensure that people authorised to Process Customer Personal Data are subject to appropriate confidentiality obligations, receive access only where reasonably required, and process Customer Personal Data only for authorised purposes.
8. Security
Referral Ventures shall implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
Measures shall take account of the nature of the Personal Data, nature and purposes of Processing, available technology, implementation cost and risks to Data Subjects. Current principal measures are described in Schedule 2.
9. Sub-processors
Customer provides general written authorisation for Referral Ventures to engage Sub-processors.
Referral Ventures shall maintain a current list of material Sub-processors and impose appropriate written data protection obligations on them.
Referral Ventures remains responsible for Sub-processor Processing to the extent required by Applicable Data Protection Law.
Referral Ventures shall provide reasonable notice of an intended new material Sub-processor. Customer may object on reasonable, documented data protection grounds. Where the parties cannot reasonably resolve an objection, Customer may stop using the affected Service.
10. International Transfers
Referral Ventures may process Customer Personal Data in the United Kingdom, European Economic Area and other countries in which authorised Sub-processors operate, subject to Applicable Data Protection Law.
Where Personal Data is transferred from the EEA to the United Kingdom while a valid European Commission adequacy decision applies, the parties may rely on that adequacy decision.
Where an international transfer requires additional safeguards, Referral Ventures shall use an appropriate transfer mechanism, which may include an applicable adequacy decision, EU Standard Contractual Clauses, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, an applicable recognised privacy framework or another legally permitted safeguard.
Referral Ventures shall provide reasonable information concerning relevant safeguards on request.
11. Data Subject Rights
Taking into account the nature of the Processing, Referral Ventures shall provide reasonable assistance to Customer in responding to Data Subject rights requests.
Where Referral Ventures receives a request relating to identifiable Customer Personal Data, it may refer the requester to Customer or forward the request to Customer.
Referral Ventures shall not independently determine Customer’s response except on Customer’s instructions, where required by law, or where Referral Ventures separately acts as Controller for the relevant Personal Data.
12. Personal Data Breaches
Referral Ventures shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
To the extent reasonably available, Referral Ventures shall provide information concerning the nature of the breach, relevant categories of Data Subjects and Personal Data, likely consequences, containment and remediation measures, and other information reasonably required for Customer to assess its regulatory obligations.
Referral Ventures shall provide reasonable assistance with Customer’s investigation and notification obligations.
13. Compliance Assistance
Taking account of the nature of the Processing and information available to Referral Ventures, Referral Ventures shall provide reasonable assistance concerning security obligations, Personal Data Breach obligations, Data Protection Impact Assessments, regulatory consultations and reasonable privacy compliance enquiries concerning ReferralLinks.
14. Return and Deletion
Following termination, Referral Ventures shall, at Customer’s choice and subject to reasonable technical capability, return or delete Customer Personal Data.
Referral Ventures may retain Personal Data where required by law, reasonably necessary for legal claims, or temporarily retained in backups pending ordinary backup expiry.
Any retained Customer Personal Data shall remain protected and shall not be used for unrelated purposes.
15. Audits
Referral Ventures shall make available information reasonably necessary to demonstrate compliance with applicable Processor obligations.
Customer should ordinarily use available compliance documentation before requesting an onsite audit.
Where reasonably necessary, Customer or an independent auditor appointed by Customer may audit Referral Ventures’ relevant Processing subject to reasonable advance notice, confidentiality obligations, normal business hours, reasonable measures to avoid disruption, protection of information concerning other Customers, and ordinarily no more than one audit per twelve-month period.
The frequency restriction does not apply where an additional audit is reasonably necessary because of a material Personal Data Breach, evidence of material non-compliance or a lawful requirement of a supervisory authority.
Customer shall bear its own reasonable audit costs unless an audit identifies a material breach of this DPA by Referral Ventures.
16. United States Privacy Requirements
To the extent Referral Ventures acts as a processor, contractor, service provider or equivalent under applicable US privacy legislation, Referral Ventures shall process Customer Personal Data only for purposes permitted by the Agreement.
Except where applicable law expressly permits otherwise, Referral Ventures shall not sell Customer Personal Data; share Customer Personal Data for cross-context behavioural advertising; retain, use or disclose Customer Personal Data for purposes outside the direct business relationship with Customer; combine Customer Personal Data with Personal Data received from another customer for Referral Ventures’ unrelated purposes; or use Customer Personal Data for Referral Ventures’ own targeted advertising.
Referral Ventures shall provide the level of privacy protection required of a processor, contractor or service provider under applicable law and shall notify Customer if it determines that it can no longer meet its relevant legal obligations.
Customer may take reasonable and appropriate steps to verify that Customer Personal Data is being processed consistently with applicable requirements.
17. Liability
Liability arising under this DPA is subject to the liability provisions in the Agreement to the maximum extent legally permitted.
18. Precedence
Where provisions conflict concerning Customer Personal Data, the following order applies: any mandatory international transfer mechanism; this DPA; the main Agreement.
Schedule 1 — Processing Details
Subject Matter
Operation of Customer referral programmes using ReferralLinks.
Duration
For the duration of Customer’s use of ReferralLinks and such limited period afterwards as reasonably necessary for data export, termination processing, deletion, backups, legal compliance or legal claims.
Nature and Purpose
Processing may include creating referral links and identifiers; recognising referral visits; recording rl_vid; processing referral source and campaign information; recording timestamps; last-click attribution; receiving server-side conversion events; matching conversions with referral identifiers; recording order/conversion identifiers; recording transaction values where supplied; calculating reward eligibility; recording reward status; programme analytics; referrer account administration; sending programme communications; preventing duplicate referral attribution; fraud detection relating to Customer’s programme; and technical support.
Categories of Data Subjects
Referrers, advocates, Customer customers, prospective customers, purchasers, referral recipients, visitors to Customer websites and Customer account users.
Types of Personal Data
Name, email address, ReferralLinks account identifier, referral identifier, rl_vid, referral URL, campaign identifier, IP address, HTTP request information, basic device and browser information, timestamps, conversion identifier, order identifier, transaction value where supplied, conversion status, reward amount, reward status, programme communications and relevant support information.
Special Category Data
ReferralLinks is not intended to process special-category Personal Data or criminal-offence data.
Frequency
Continuous or as triggered by use of Customer’s referral programme.
Schedule 2 — Technical and Organisational Measures
Hosting and Infrastructure
Amazon Web Services infrastructure; principal application/data hosting using AWS Ireland; MySQL database technology; Cloudflare network/security infrastructure.
Network and Transmission
HTTPS/TLS for supported web and API communications; appropriate encrypted network connections; network and security controls provided by relevant infrastructure.
Access Controls
Authenticated administrative access; restriction of production access to authorised personnel; access based on operational need; revocation of access where no longer required.
Application Security
Server-side validation; authentication and authorisation controls; measures against common web vulnerabilities; controlled deployment processes; software and dependency updates.
Data Protection
Restricted access to Customer programme data; encryption at infrastructure level where appropriate; database and infrastructure security measures; backup arrangements.
Monitoring
Operational logging; security logging where appropriate; infrastructure monitoring; incident investigation capability.
Personnel
Confidentiality obligations; access restricted according to role and need.
Incident Management
Investigation procedures; containment; remediation; escalation of Personal Data Breaches; Customer notification processes.
Supplier Management
Use of established infrastructure providers; contractual data protection obligations; international transfer safeguards where required.
Recovery
Backups; infrastructure recovery capability; reasonable business continuity measures appropriate to the Services.
Schedule 3 — Material Sub-processors
| Provider | Purpose | Processing |
|---|---|---|
| Amazon Web Services (AWS) | Hosting and infrastructure | ReferralLinks application, database, logs, backups and infrastructure |
| Cloudflare | Security, network and content delivery | IP addresses, HTTP/network information and security data |
| Mailgun | Transactional email delivery | Recipient email addresses, message contents and email delivery metadata |
Referral Ventures may update this list in accordance with this DPA.
MySQL is the database technology used by Referral Ventures and is not itself treated as a separate Sub-processor unless provided through a separately operated third-party service.
Contact
Referral Ventures Limited
300 Vauxhall Bridge Road
London SW1V 1AA
United Kingdom
Company number: 13281997
Email: info@referrallinks.com