← Back to site

Data Processing Addendum

Last Updated: July 16, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between REFINE Performance Marketing ("Processor," "we," "us," or "our") and the business entity using our Services ("Controller," "you," or "your") and applies where we process personal information on your behalf in connection with the Services. This DPA supplements your agreement with us and our Privacy Policy.

1. Definitions

2. Roles and Scope

You are the business or controller of Personal Information you submit to the Services about your customers, leads, or personnel. We act as your service provider or processor and will Process that Personal Information only on your documented instructions and as described in this DPA and our agreement, unless otherwise required by law.

3. Processing Instructions and Restrictions

4. Confidentiality and Personnel

We ensure that persons authorized to Process Personal Information are subject to appropriate confidentiality obligations (contractual or statutory). We provide training on data protection appropriate to their role.

5. Sub-processors

You authorize us to engage the sub-processors listed below to Process Personal Information on your behalf. We remain responsible for each sub-processor's performance of its obligations in accordance with this DPA.

We will provide you at least 30 days' advance notice of a new sub-processor or a material change to a sub-processor arrangement, unless we cannot do so due to legal or security reasons (in which case we will notify you as soon as reasonably practicable). If you object on reasonable data-protection grounds, we will work with you in good faith to resolve the objection.

6. Security

We implement and maintain appropriate technical and organizational measures designed to protect Personal Information against unauthorized access, loss, or alteration, taking into account the nature of processing and the risks involved. Measures may include access controls, encryption in transit, logging, vendor reviews, and incident response procedures.

7. Consumer Requests and Assistance

Taking into account the nature of the Processing, we will assist you by appropriate technical and organizational measures, insofar as possible, to fulfill your obligation to respond to consumer rights requests under Applicable Privacy Laws. Where a request is submitted directly to us, we will instruct the requester to contact you unless we are legally required to respond directly.

8. Data Retention and Deletion

We retain Personal Information only as long as necessary to provide the Services and as described in our Privacy Policy. Upon termination of the Services or upon your written request (subject to legal retention requirements), we will delete or return Personal Information in our possession, unless retention is required by law.

9. Audits

Upon reasonable written request, we will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of our security practices or completed questionnaires. Where an on-site audit is required by Applicable Privacy Laws, such audit will be conducted during business hours, with reasonable advance notice, and subject to confidentiality and security controls.

10. International Transfers

Personal Information may be processed in the United States. If we transfer Personal Information across borders where required by law, we will implement appropriate safeguards described in our agreement or as otherwise required by Applicable Privacy Laws.

11. Liability

Liability arising from our Processing of Personal Information under this DPA is subject to the limitations and exclusions in your agreement with us, except where prohibited by Applicable Privacy Laws.

12. Contact

For questions about this DPA or our Processing of Personal Information on your behalf, contact info@refinepm.com.