Data Processing Agreement

Effective Date: September 24, 2026

This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the CreatorFlow Terms of Service between CreatorFlow ("Processor," "we," "us") and the merchant entity that has registered for the CreatorFlow platform ("Customer," "Controller," "you"). It applies automatically, without a separate signature, whenever Customer's use of the Service involves the Processing of Personal Data subject to the GDPR, the UK GDPR, or the Swiss FADP. If your organization requires a countersigned copy for internal record-keeping, contact legal@gocreatorflow.com.

1. Definitions

  • Applicable Data Protection Law means the EU General Data Protection Regulation (2016/679), the UK GDPR, and the Swiss Federal Act on Data Protection, as applicable to the Processing.
  • Controller, Processor, Data Subject, Personal Data, Processing, and Personal Data Breach have the meanings given in the GDPR.
  • Sub-processor means any third party engaged by CreatorFlow to Process Personal Data on Customer's behalf in order to provide the Service.

2. Roles of the Parties

Customer is the Controller of Personal Data relating to the TikTok creators who apply to Customer's campaigns through the CreatorFlow platform ("Creator Data"). CreatorFlow is the Processor of Creator Data, acting only on Customer's documented instructions — which, for a self-serve SaaS product, are given through Customer's normal configuration and use of the Service (creating campaigns, approving applicants, entering shipping/tracking details, and similar in-product actions). Separately, CreatorFlow is the Controller of Customer's own account and billing data (see the Privacy Policy), which this DPA does not govern.

3. Subject Matter and Details of Processing

  • Subject matter: CreatorFlow's provision of its affiliate-campaign-management SaaS platform to Customer.
  • Duration: For the term of Customer's subscription, plus any period Personal Data is retained afterward per Section 10.
  • Nature and purpose: Collecting and storing creator applications; tracking sample-shipment status; tracking public TikTok video performance metrics for creators Customer has approved; calculating commission/referral attribution; facilitating Customer's communication with its creators.
  • Categories of Data Subjects: TikTok creators who apply to, or are approved for, one of Customer's campaigns.
  • Categories of Personal Data: TikTok username, follower count, contact email, physical shipping address, shipment tracking numbers, referral/commission data, and public TikTok video metrics (views, likes) for tracked videos.

4. Processor Obligations

  • Process Creator Data only on Customer's documented instructions, including regarding international transfers, unless required to do otherwise by law.
  • Ensure personnel authorized to Process Creator Data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational security measures (see Section 5).
  • Assist Customer, insofar as reasonably possible, in responding to Data Subject requests (access, rectification, erasure, portability, objection) submitted to Customer or forwarded to us.
  • Notify Customer without undue delay, and in any event within 72 hours of becoming aware, of any Personal Data Breach affecting Creator Data.
  • Make available to Customer the information reasonably necessary to demonstrate compliance with this DPA.

5. Confidentiality and Security

Creator Data is stored in Supabase (PostgreSQL) with row-level security policies scoping every query to the authenticated Customer's own brand account, so one Customer's data is never queryable by another. Data is encrypted in transit (TLS) and at rest (at the infrastructure-provider level). Access to production data by CreatorFlow personnel is limited to what's needed for support and maintenance.

6. Sub-processors

Customer authorizes CreatorFlow to engage the Sub-processors listed below to Process Creator Data as necessary to provide the Service. CreatorFlow imposes data protection obligations substantially similar to this DPA on each Sub-processor. If CreatorFlow adds or replaces a Sub-processor in a way that materially increases the risk to Creator Data, we'll update this page and, on request, notify Customer at the contact email on file.

  • Supabase, Inc. — database hosting, authentication, and file storage for all application data. Location: Ireland (eu-west-1) — within the EEA.
  • Paddle.com Market Ltd — billing, subscription management, and Merchant of Record for payment processing (Paddle, not CreatorFlow, is the seller of record and handles its own EU/UK VAT and payment-data compliance). Location: United Kingdom.
  • Resend — transactional email delivery (welcome, approval, shipment, and support notifications). Location: United States.
  • TikAPI.io — retrieval of public TikTok video metrics (views, likes) for creators Customer has approved. Location: United States.
  • Vercel Inc. — application hosting and content delivery. Location: United States.
  • Google LLC (Google Analytics) — website usage analytics, loaded only after a visitor grants cookie consent. Location: United States.

7. International Data Transfers

Where a Sub-processor is located outside the EEA, UK, or Switzerland, CreatorFlow relies on that Sub-processor's own GDPR-compliance mechanism for the transfer — typically the EU Standard Contractual Clauses (SCCs) or, where applicable, the UK International Data Transfer Addendum. Copies of the relevant Sub-processor transfer documentation are available on request to legal@gocreatorflow.com.

8. Term and Deletion of Data

This DPA remains in effect for as long as CreatorFlow Processes Creator Data on Customer's behalf. Upon termination of Customer's subscription, Creator Data associated with Customer's account is permanently deleted within 72 hours, consistent with the retention commitment in the Privacy Policy — CreatorFlow does not offer an extended retention or export period after account deletion, so Customer should export any data it needs before deleting its account.

9. Audit Rights

On reasonable written request, no more than once per 12-month period, CreatorFlow will provide Customer with the information reasonably necessary to demonstrate compliance with this DPA (such as a summary of the security measures in Section 5). Given the scale of the Service, on-site audits are not offered, but CreatorFlow will cooperate in good faith with a documentation-based review.

10. Governing Law

This DPA is governed by the same governing law and venue provisions as the CreatorFlow Terms of Service. In the event of a conflict between this DPA and the Terms of Service regarding the Processing of Personal Data, this DPA controls.