Data Processing Agreement (DPA)
Version 2026-07
This agreement governs the processing of personal data carried out by Graft on behalf of the merchant, in accordance with article 28 of the GDPR (EU regulation 2016/679). It is accepted at account creation and forms an integral part of the terms. This English version is provided for convenience only. In the event of any discrepancy, the French version prevails.
1. Parties and roles
The merchant acts as controller. The publisher, below the processor, acts on the merchant's documented instructions:
- Registered name
- Augustin D. — Entrepreneur individuel
- Legal form
- Entreprise individuelle (EI), régime micro-entreprise
- Share capital
- Sans objet (entreprise individuelle)
- Address
- 14 bis avenue de la République, 87170 Isle, France
- Company number (SIREN)
- 937 506 764
- Trade register (RCS)
- RCS Limoges 937 506 764
- VAT number
- TVA non applicable, art. 293 B du CGI
- Publication director
- Augustin D.
- Contact
- graft.eucontact@gmail.com
- Data protection contact
- graft.eucontact@gmail.com
2. Subject matter, nature and duration
Subject matter: affiliate tracking, commission calculation, affiliate and payout management. Duration: the term of the merchant's subscription, plus statutory retention periods.
Categories of data subjects: the merchant's affiliates, customers and visitors. Categories of data: affiliate identifiers, email addresses, transaction data, IP addresses (hashed before storage), user agent, affiliate payout details.
No special categories of data within the meaning of article 9 of the GDPR are processed.
3. Processor obligations
- Process data only on the controller's documented instructions.
- Ensure the confidentiality of persons authorised to process the data.
- Implement the technical and organisational measures required by article 32 (see section 5).
- Assist the controller in responding to data subject requests.
- Notify any personal data breach without undue delay after becoming aware of it.
- Delete or return the data at the end of the service, at the controller's choice.
- Make available the information needed to demonstrate compliance with article 28 and allow for audits.
4. Sub-processors
The merchant gives general authorisation for the use of the sub-processors listed below. Any addition or replacement is notified to the merchant before it is brought into service, allowing the merchant to object.
| Sub-processor | Purpose | Data location |
|---|---|---|
| Supabase | Database, authentication, storage | European Union (Frankfurt) |
| Vercel Inc. | Application hosting and delivery | European Union |
| Paddle.com Market Ltd | Graft subscription billing (Merchant of Record), VAT handling | United Kingdom (EU adequacy decision) |
| Stripe Payments Europe Ltd | Affiliate commission payouts (Stripe Connect) and merchant payment webhooks | Ireland |
| Resend — only if enabled | Transactional email delivery | European Union |
| Wise / PayPal — only if enabled | Affiliate commission payouts — only if the merchant enables this payout provider | European Union |
5. Security measures (article 32)
- Encryption in transit (TLS) and AES-256-GCM encryption of secrets and payment data at rest.
- Pseudonymisation of IP addresses by salted SHA-256 hashing, before any database write.
- Strict data isolation between merchants (PostgreSQL Row Level Security, multi-tenant partitioning).
- HMAC signature verification of all inbound webhooks.
- Rate limiting on all public endpoints.
- Minimisation: no personal data is written to application logs.
6. Data location and transfers
Data is hosted within the European Union. No transfer outside the European Union is made without an appropriate safeguard under chapter V of the GDPR.
7. Data subject rights
The processor provides the merchant with export (portability, JSON format) and deletion (right to erasure) tools available from account settings, enabling the merchant to respond to data subject requests.
8. Publisher staff access
Cross-tenant administrative access is restricted to authorised personnel, protected by multi-factor authentication, and logged. Affiliate data viewed in that context is aggregated and anonymised: no affiliate personal data is exposed. Such access is recorded in an audit log kept for the purposes of article 30.