Data Processing Agreement
Processor commitments for customer-controlled personal data processed through AttributionPath™.
Effective 24 August 2026. This Data Processing Agreement (“DPA”) applies where AttributionPath™ processes personal data on behalf of a business customer in connection with the AttributionPath™ service. It supplements the applicable customer agreement or Terms.
1. Roles and instructions
The customer is controller/business or processor as applicable to its relationship with the data subjects and upstream parties. AttributionPath™ is processor/service provider for customer-controlled service data unless the parties expressly agree otherwise. AttributionPath™ will process such data only on documented customer instructions, including the agreement, configuration and authorised support instructions, unless law requires otherwise.
2. Details of processing
Subject matter: attribution, measurement, deduplication, reporting, proxy/API operations, integrations, security and support. Duration: the service term plus limited deletion, backup and legal-retention periods. Nature: collection, receipt, transmission, organisation, comparison, storage, analysis, retrieval, reporting, deletion and related technical operations. Purpose: providing and securing the services selected by the customer.
3. Data subjects and data types
Data subjects may include website or app visitors, purchasers, leads, publisher or advertiser users, customer personnel and other individuals whose events are lawfully submitted by the customer. Data may include online identifiers, IP addresses, device/browser data, campaign and referral identifiers, timestamps, page and event data, pseudonymous user or order references, conversion values, consent signals, and account/support data. Sensitive or special-category data is not intended for routine attribution processing.
4. Confidentiality
Personnel authorised to process customer personal data are subject to confidentiality obligations and access is limited according to role and operational need.
5. Security
AttributionPath™ will maintain appropriate technical and organisational measures taking account of the nature, scope, context and purposes of processing and relevant risk. Measures may include access controls, authentication, encryption in transit, logging, backup, incident response, environment separation, vulnerability management and supplier controls.
6. Subprocessors
The customer authorises the use of subprocessors necessary to provide the service, subject to equivalent data-protection obligations appropriate to their processing. Where applicable law requires notice of new subprocessors and an opportunity to object, AttributionPath™ will provide a reasonable mechanism for that process. Objections must be based on legitimate data-protection grounds.
7. Data-subject requests
Taking account of the nature of processing, AttributionPath™ will provide reasonable assistance to enable the customer to respond to requests to exercise applicable privacy rights. If AttributionPath™ receives a request relating to customer-controlled data, it may direct the requester to the customer unless legally prohibited.
8. Compliance assistance
Taking account of the information available and nature of processing, AttributionPath™ will reasonably assist the customer with security obligations, breach assessment and notification, data-protection impact assessments, prior consultation and other processor-assistance duties required by applicable law.
9. Personal-data incidents
AttributionPath™ will notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting customer-controlled personal data where notification is required by applicable law, and will provide information reasonably available to support the customer’s response.
10. International transfers
Restricted transfers will use a legally recognised transfer mechanism where required. Depending on the originating jurisdiction this may include adequacy, the European Commission Standard Contractual Clauses, the UK IDTA or UK Addendum, or another approved mechanism. The parties will cooperate on transfer assessments and supplementary safeguards where legally required.
11. Return and deletion
At the end of services involving processing, AttributionPath™ will delete or return customer personal data as required by the customer and applicable agreement, unless law requires retention. Data in backups may remain until overwritten under ordinary retention cycles while remaining protected and unavailable for ordinary use.
12. Audits and information
AttributionPath™ will make information reasonably necessary to demonstrate compliance with applicable processor obligations available to the customer. Audits or inspections must be reasonable, proportionate, protect other customers and security, avoid unnecessary disruption, and may be satisfied through independent reports or documentation where appropriate.
13. Unlawful instructions
If AttributionPath™ reasonably believes a customer instruction infringes applicable data-protection law, it will inform the customer unless prohibited by law and may suspend the affected processing while the parties address the issue.
14. US service-provider / processor restrictions
Where applicable US state privacy law treats AttributionPath™ as a service provider, contractor or processor, AttributionPath™ will process covered personal data for the specified business purposes and documented instructions; will not sell or share it for unrelated purposes; will not retain, use or disclose it outside the permitted relationship except as allowed by law; and will provide the level of privacy protection required of that role.
15. White-label and API deployments
For white-label, proxy and API arrangements, the parties must document which party determines purposes and means, which party presents notices and rights interfaces, which party contracts with end customers, and whether AttributionPath™ acts as processor, subprocessor or independent controller for any limited operational data. Branding does not itself determine legal privacy roles.
16. Priority and governing agreement
If this DPA conflicts with general Terms on processing of personal data, this DPA controls for that processing. A signed customer-specific DPA or mandatory statutory clause controls over this web DPA to the extent of a conflict.
17. Contact
Privacy and DPA enquiries: privacy@attributionpath.com.