ReferralLinks
Log in · Create account
Business Terms · Data Processing Agreement · Privacy Notice · Cookie & Attribution

ReferralLinks Data Processing Agreement

Last updated: 4 September 2026

This Data Processing Agreement (“DPA”) forms part of the ReferralLinks Business Terms of Service or other agreement (“Agreement”) between Referral Ventures Limited, company number 13281997 (“Referral Ventures”, “Processor”, “we”) and the business or organisation using ReferralLinks (“Customer”, “Controller”).

This DPA applies to the extent Referral Ventures processes Customer Personal Data on behalf of Customer.

1. Definitions

“Applicable Data Protection Law” means applicable data protection and privacy laws relating to the Processing, including where applicable the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations 2003, EU GDPR, applicable EU or EEA national privacy and ePrivacy legislation, and applicable United States state privacy legislation governing controllers, processors, businesses, contractors or service providers.

“Customer Personal Data” means Personal Data processed by Referral Ventures on behalf of Customer through ReferralLinks.

“Sub-processor” means a third party engaged by Referral Ventures to process Customer Personal Data on behalf of Customer.

Controller, Processor, Personal Data, Processing, Data Subject, Personal Data Breach and Supervisory Authority have the meanings given by Applicable Data Protection Law.

2. Roles

For Customer Personal Data processed to operate a Customer’s referral programme, Customer is Controller and Referral Ventures is Processor.

Processor activities may include creating referral links and identifiers; storing and recognising rl_vid; processing referral events; applying last-click attribution; receiving server-side conversion events; matching conversions with referral identifiers; recording reward eligibility or status; providing analytics; administering referrer accounts; sending Customer-directed communications to referrers; technical support; and fraud or duplicate-referral detection undertaken in providing the Customer’s programme.

Referral Ventures acts as an independent Controller where it determines the relevant purposes and essential means, including Customer user account administration, authentication, billing and subscriptions, financial records, commercial relationship management, legal compliance, legal claims, protection of Referral Ventures’ own infrastructure, and operation of ReferralCodes.com where Referral Ventures independently determines purposes.

Customer Personal Data provided solely for operation of a Customer’s ReferralLinks programme will not be added to the ReferralCodes member database or used for Referral Ventures’ unrelated marketing solely because the Customer uses ReferralLinks.

3. Customer Instructions

Referral Ventures shall Process Customer Personal Data only on Customer’s documented instructions, as necessary to provide the Services requested or configured by Customer, or where required by applicable law.

Documented instructions include the Agreement, this DPA, Customer’s ReferralLinks account and campaign configuration, instructions given through ReferralLinks, documented support requests and other written instructions agreed between the parties.

Referral Ventures shall notify Customer if Referral Ventures reasonably considers an instruction to breach Applicable Data Protection Law.

Where Referral Ventures is required by law to undertake Processing other than on Customer’s instructions, Referral Ventures shall inform Customer before doing so unless prohibited by law.

4. Customer Obligations

Customer is responsible for establishing a lawful basis for its Processing, providing required privacy information, ensuring it has authority to disclose Customer Personal Data to Referral Ventures, determining whether consent is required for referral tracking, implementing and obtaining consent where required, complying with electronic communications and marketing laws, and ensuring its instructions are lawful.

Customer shall not intentionally provide through ReferralLinks special-category Personal Data, criminal-offence data, payment-card credentials, bank-account login details, passwords belonging to Data Subjects, sensitive government identification data or other high-risk Personal Data not reasonably required by ReferralLinks unless separately agreed in writing.

5. Processing Instructions for Attribution

Customer instructs Referral Ventures to process referral attribution information where the relevant Services are enabled.

The standard ReferralLinks attribution system uses a unique referral URL, a referral identifier, a first-party cookie currently named rl_vid, timestamps and server-side conversion information supplied by Customer.

ReferralLinks currently applies last-click attribution. The standard attribution period is 30 days. Where supported, Customer may configure attribution periods between 1 and 365 days. The standard rl_vid browser-cookie duration is currently 30 days.

Referral Ventures shall not use Customer-specific referral identifiers processed solely as Processor to track Data Subjects across unrelated Customer websites for Referral Ventures’ own behavioural advertising or profiling.

6. Referrer Communications

Customer may instruct Referral Ventures to send programme-related emails to its referrers, including verification, account information, referral links, referral activity, conversions, rewards, security information and operational information.

Where these communications are sent solely on Customer’s behalf, Referral Ventures acts as Processor.

Customer remains responsible for determining whether requested communications are lawful.

Referral Ventures shall not use an email address supplied solely as Customer Personal Data to send unrelated Referral Ventures marketing unless Referral Ventures has independently established an appropriate lawful basis and provided required privacy information.

7. Confidentiality

Referral Ventures shall ensure that people authorised to Process Customer Personal Data are subject to appropriate confidentiality obligations, receive access only where reasonably required, and process Customer Personal Data only for authorised purposes.

8. Security

Referral Ventures shall implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.

Measures shall take account of the nature of the Personal Data, nature and purposes of Processing, available technology, implementation cost and risks to Data Subjects. Current principal measures are described in Schedule 2.

9. Sub-processors

Customer provides general written authorisation for Referral Ventures to engage Sub-processors.

Referral Ventures shall maintain a current list of material Sub-processors and impose appropriate written data protection obligations on them.

Referral Ventures remains responsible for Sub-processor Processing to the extent required by Applicable Data Protection Law.

Referral Ventures shall provide reasonable notice of an intended new material Sub-processor. Customer may object on reasonable, documented data protection grounds. Where the parties cannot reasonably resolve an objection, Customer may stop using the affected Service.

10. International Transfers

Referral Ventures may process Customer Personal Data in the United Kingdom, European Economic Area and other countries in which authorised Sub-processors operate, subject to Applicable Data Protection Law.

Where Personal Data is transferred from the EEA to the United Kingdom while a valid European Commission adequacy decision applies, the parties may rely on that adequacy decision.

Where an international transfer requires additional safeguards, Referral Ventures shall use an appropriate transfer mechanism, which may include an applicable adequacy decision, EU Standard Contractual Clauses, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, an applicable recognised privacy framework or another legally permitted safeguard.

Referral Ventures shall provide reasonable information concerning relevant safeguards on request.

11. Data Subject Rights

Taking into account the nature of the Processing, Referral Ventures shall provide reasonable assistance to Customer in responding to Data Subject rights requests.

Where Referral Ventures receives a request relating to identifiable Customer Personal Data, it may refer the requester to Customer or forward the request to Customer.

Referral Ventures shall not independently determine Customer’s response except on Customer’s instructions, where required by law, or where Referral Ventures separately acts as Controller for the relevant Personal Data.

12. Personal Data Breaches

Referral Ventures shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

To the extent reasonably available, Referral Ventures shall provide information concerning the nature of the breach, relevant categories of Data Subjects and Personal Data, likely consequences, containment and remediation measures, and other information reasonably required for Customer to assess its regulatory obligations.

Referral Ventures shall provide reasonable assistance with Customer’s investigation and notification obligations.

13. Compliance Assistance

Taking account of the nature of the Processing and information available to Referral Ventures, Referral Ventures shall provide reasonable assistance concerning security obligations, Personal Data Breach obligations, Data Protection Impact Assessments, regulatory consultations and reasonable privacy compliance enquiries concerning ReferralLinks.

14. Return and Deletion

Following termination, Referral Ventures shall, at Customer’s choice and subject to reasonable technical capability, return or delete Customer Personal Data.

Referral Ventures may retain Personal Data where required by law, reasonably necessary for legal claims, or temporarily retained in backups pending ordinary backup expiry.

Any retained Customer Personal Data shall remain protected and shall not be used for unrelated purposes.

15. Audits

Referral Ventures shall make available information reasonably necessary to demonstrate compliance with applicable Processor obligations.

Customer should ordinarily use available compliance documentation before requesting an onsite audit.

Where reasonably necessary, Customer or an independent auditor appointed by Customer may audit Referral Ventures’ relevant Processing subject to reasonable advance notice, confidentiality obligations, normal business hours, reasonable measures to avoid disruption, protection of information concerning other Customers, and ordinarily no more than one audit per twelve-month period.

The frequency restriction does not apply where an additional audit is reasonably necessary because of a material Personal Data Breach, evidence of material non-compliance or a lawful requirement of a supervisory authority.

Customer shall bear its own reasonable audit costs unless an audit identifies a material breach of this DPA by Referral Ventures.

16. United States Privacy Requirements

To the extent Referral Ventures acts as a processor, contractor, service provider or equivalent under applicable US privacy legislation, Referral Ventures shall process Customer Personal Data only for purposes permitted by the Agreement.

Except where applicable law expressly permits otherwise, Referral Ventures shall not sell Customer Personal Data; share Customer Personal Data for cross-context behavioural advertising; retain, use or disclose Customer Personal Data for purposes outside the direct business relationship with Customer; combine Customer Personal Data with Personal Data received from another customer for Referral Ventures’ unrelated purposes; or use Customer Personal Data for Referral Ventures’ own targeted advertising.

Referral Ventures shall provide the level of privacy protection required of a processor, contractor or service provider under applicable law and shall notify Customer if it determines that it can no longer meet its relevant legal obligations.

Customer may take reasonable and appropriate steps to verify that Customer Personal Data is being processed consistently with applicable requirements.

17. Liability

Liability arising under this DPA is subject to the liability provisions in the Agreement to the maximum extent legally permitted.

18. Precedence

Where provisions conflict concerning Customer Personal Data, the following order applies: any mandatory international transfer mechanism; this DPA; the main Agreement.

Schedule 1 — Processing Details

Subject Matter

Operation of Customer referral programmes using ReferralLinks.

Duration

For the duration of Customer’s use of ReferralLinks and such limited period afterwards as reasonably necessary for data export, termination processing, deletion, backups, legal compliance or legal claims.

Nature and Purpose

Processing may include creating referral links and identifiers; recognising referral visits; recording rl_vid; processing referral source and campaign information; recording timestamps; last-click attribution; receiving server-side conversion events; matching conversions with referral identifiers; recording order/conversion identifiers; recording transaction values where supplied; calculating reward eligibility; recording reward status; programme analytics; referrer account administration; sending programme communications; preventing duplicate referral attribution; fraud detection relating to Customer’s programme; and technical support.

Categories of Data Subjects

Referrers, advocates, Customer customers, prospective customers, purchasers, referral recipients, visitors to Customer websites and Customer account users.

Types of Personal Data

Name, email address, ReferralLinks account identifier, referral identifier, rl_vid, referral URL, campaign identifier, IP address, HTTP request information, basic device and browser information, timestamps, conversion identifier, order identifier, transaction value where supplied, conversion status, reward amount, reward status, programme communications and relevant support information.

Special Category Data

ReferralLinks is not intended to process special-category Personal Data or criminal-offence data.

Frequency

Continuous or as triggered by use of Customer’s referral programme.

Schedule 2 — Technical and Organisational Measures

Hosting and Infrastructure

Amazon Web Services infrastructure; principal application/data hosting using AWS Ireland; MySQL database technology; Cloudflare network/security infrastructure.

Network and Transmission

HTTPS/TLS for supported web and API communications; appropriate encrypted network connections; network and security controls provided by relevant infrastructure.

Access Controls

Authenticated administrative access; restriction of production access to authorised personnel; access based on operational need; revocation of access where no longer required.

Application Security

Server-side validation; authentication and authorisation controls; measures against common web vulnerabilities; controlled deployment processes; software and dependency updates.

Data Protection

Restricted access to Customer programme data; encryption at infrastructure level where appropriate; database and infrastructure security measures; backup arrangements.

Monitoring

Operational logging; security logging where appropriate; infrastructure monitoring; incident investigation capability.

Personnel

Confidentiality obligations; access restricted according to role and need.

Incident Management

Investigation procedures; containment; remediation; escalation of Personal Data Breaches; Customer notification processes.

Supplier Management

Use of established infrastructure providers; contractual data protection obligations; international transfer safeguards where required.

Recovery

Backups; infrastructure recovery capability; reasonable business continuity measures appropriate to the Services.

Schedule 3 — Material Sub-processors

Provider Purpose Processing
Amazon Web Services (AWS) Hosting and infrastructure ReferralLinks application, database, logs, backups and infrastructure
Cloudflare Security, network and content delivery IP addresses, HTTP/network information and security data
Mailgun Transactional email delivery Recipient email addresses, message contents and email delivery metadata

Referral Ventures may update this list in accordance with this DPA.

MySQL is the database technology used by Referral Ventures and is not itself treated as a separate Sub-processor unless provided through a separately operated third-party service.

Contact

Referral Ventures Limited
300 Vauxhall Bridge Road
London SW1V 1AA
United Kingdom
Company number: 13281997
Email: info@referrallinks.com

SDK · Business Terms · DPA · Privacy · Cookies