Data Processing Agreement (DPA)

Version 2026-07

This agreement governs the processing of personal data carried out by Graft on behalf of the merchant, in accordance with article 28 of the GDPR (EU regulation 2016/679). It is accepted at account creation and forms an integral part of the terms. This English version is provided for convenience only. In the event of any discrepancy, the French version prevails.

1. Parties and roles

The merchant acts as controller. The publisher, below the processor, acts on the merchant's documented instructions:

Registered name
Augustin D. — Entrepreneur individuel
Legal form
Entreprise individuelle (EI), régime micro-entreprise
Share capital
Sans objet (entreprise individuelle)
Address
14 bis avenue de la République, 87170 Isle, France
Company number (SIREN)
937 506 764
Trade register (RCS)
RCS Limoges 937 506 764
VAT number
TVA non applicable, art. 293 B du CGI
Publication director
Augustin D.
Contact
graft.eucontact@gmail.com
Data protection contact
graft.eucontact@gmail.com

2. Subject matter, nature and duration

Subject matter: affiliate tracking, commission calculation, affiliate and payout management. Duration: the term of the merchant's subscription, plus statutory retention periods.

Categories of data subjects: the merchant's affiliates, customers and visitors. Categories of data: affiliate identifiers, email addresses, transaction data, IP addresses (hashed before storage), user agent, affiliate payout details.

No special categories of data within the meaning of article 9 of the GDPR are processed.

3. Processor obligations

  • Process data only on the controller's documented instructions.
  • Ensure the confidentiality of persons authorised to process the data.
  • Implement the technical and organisational measures required by article 32 (see section 5).
  • Assist the controller in responding to data subject requests.
  • Notify any personal data breach without undue delay after becoming aware of it.
  • Delete or return the data at the end of the service, at the controller's choice.
  • Make available the information needed to demonstrate compliance with article 28 and allow for audits.

4. Sub-processors

The merchant gives general authorisation for the use of the sub-processors listed below. Any addition or replacement is notified to the merchant before it is brought into service, allowing the merchant to object.

Sub-processorPurposeData location
SupabaseDatabase, authentication, storageEuropean Union (Frankfurt)
Vercel Inc.Application hosting and deliveryEuropean Union
Paddle.com Market LtdGraft subscription billing (Merchant of Record), VAT handlingUnited Kingdom (EU adequacy decision)
Stripe Payments Europe LtdAffiliate commission payouts (Stripe Connect) and merchant payment webhooksIreland
Resend — only if enabledTransactional email deliveryEuropean Union
Wise / PayPal — only if enabledAffiliate commission payouts — only if the merchant enables this payout providerEuropean Union

5. Security measures (article 32)

  • Encryption in transit (TLS) and AES-256-GCM encryption of secrets and payment data at rest.
  • Pseudonymisation of IP addresses by salted SHA-256 hashing, before any database write.
  • Strict data isolation between merchants (PostgreSQL Row Level Security, multi-tenant partitioning).
  • HMAC signature verification of all inbound webhooks.
  • Rate limiting on all public endpoints.
  • Minimisation: no personal data is written to application logs.

6. Data location and transfers

Data is hosted within the European Union. No transfer outside the European Union is made without an appropriate safeguard under chapter V of the GDPR.

7. Data subject rights

The processor provides the merchant with export (portability, JSON format) and deletion (right to erasure) tools available from account settings, enabling the merchant to respond to data subject requests.

8. Publisher staff access

Cross-tenant administrative access is restricted to authorised personnel, protected by multi-factor authentication, and logged. Affiliate data viewed in that context is aggregated and anonymised: no affiliate personal data is exposed. Such access is recorded in an audit log kept for the purposes of article 30.