Data Processing Agreement

Updated on 05 October 2026.

This Data Processing Agreement (the “DPA”) forms part of the Terms of Service (the “Terms”) between WinWinKit, operated by Osta Ventures ApS (“WinWinKit,” “we,” “us,” or “our”), and the customer that uses the Services (the “Customer,” “you,” or “your”). It applies whenever we process Personal Data on your behalf as part of the Services, and it is accepted automatically when you agree to the Terms. No separate signature is required.

If there is a conflict between this DPA and the Terms, this DPA takes precedence for anything related to the processing of Personal Data.

Definitions

Roles of the parties

For Customer Personal Data, you are the Controller and we are your Processor. You decide which data is sent to WinWinKit (for example, through our SDKs, API, integrations, or affiliate sign-up forms) and why, and we process it only to provide the Services to you.

For the data we collect about you and your team members to run your account, such as names, email addresses, and billing details, we act as an independent Controller. That processing is covered by our Privacy Policy, not by this DPA.

You are responsible for having a lawful basis for the Customer Personal Data you share with us and for giving Data Subjects any notices required by Data Protection Laws.

Details of the processing

Subject matter and purpose. Providing the Services described in the Terms: managing referral programs, affiliate programs, and promo codes for mobile apps, including tracking claims, attributing purchases and subscriptions, granting rewards, calculating affiliate earnings, paying out affiliates, and the related analytics, notifications, and support.

Duration. For as long as you use the Services, plus the deletion period described in Deletion and return of data.

Categories of Data Subjects.

Categories of Personal Data.

Special categories of data. The Services are not designed for special categories of Personal Data or data about criminal convictions, and you agree not to send such data to WinWinKit.

Our obligations

We will:

Subprocessors

You give us general authorization to engage Subprocessors to help provide the Services. We impose data protection obligations on each Subprocessor that are no less protective than those in this DPA, and we remain responsible for their performance.

Customer Personal Data is stored in Ireland (EU). Our current Subprocessors are:

SubprocessorPurposeLocation
Supabase, Inc.Database hosting and authenticationIreland (EU)
Vercel Inc.Web app hosting and background jobsUnited States
Railway CorporationAPI hosting and background job queueUnited States
Functional Software, Inc. (Sentry)Error monitoringGermany (EU)
Resend, Inc.Transactional email deliveryUnited States
Stripe, Inc.Affiliate payouts and billingUnited States
PayPal (Europe) S.à r.l. et Cie, S.C.A.Affiliate payoutsLuxembourg (EU)
Wise Payments LimitedAffiliate payoutsUnited Kingdom
ScrapeCreatorsRetrieving public social media content of affiliatesUnited States
Meta Platforms, Inc.Instagram account connection for affiliatesUnited States

Integrations you connect yourself, such as RevenueCat, App Store Connect, or Google Play, act on your behalf under your own agreements with those providers and are not our Subprocessors.

We will update this list and notify you by email or through the web app at least 14 days before a new Subprocessor begins processing Customer Personal Data. You may object on reasonable data protection grounds within that period. If we cannot reasonably address the objection, you may terminate the affected Services and we will refund any prepaid fees for the remaining period.

International transfers

We are based in Denmark, and Customer Personal Data is stored in our database in Ireland (EU). Some Subprocessors may process Customer Personal Data outside the EU/EEA. When they do, we make sure the transfer is protected by an adequacy decision (including the EU-U.S. Data Privacy Framework where the Subprocessor is certified) or by the Standard Contractual Clauses, together with any supplementary measures that are needed.

For transfers from the United Kingdom or Switzerland, the SCCs apply as amended by the UK International Data Transfer Addendum or as required by Swiss law.

Security measures

We maintain technical and organizational measures appropriate to the risk, including:

We may update these measures over time, as long as the overall level of protection is not reduced.

Personal Data Breaches

If we become aware of a Personal Data Breach affecting Customer Personal Data, we will notify you without undue delay, and in any event within 48 hours. We will give you the information we have about the breach, including its nature, the likely consequences, and the measures taken or proposed, and we will provide updates as more becomes available. We will take reasonable steps to contain the breach and limit its effects.

Data Subject requests

If we receive a request from a Data Subject about Customer Personal Data, we will forward it to you and will not respond directly unless you instruct us to or the law requires it. We will help you fulfill such requests, including access, correction, deletion, and portability, through the Services or, where that is not possible, on request.

Audits

On written request, we will make available the information reasonably needed to demonstrate compliance with this DPA. If that information is not enough, you may carry out an audit, at your own cost, no more than once a year, with at least 30 days’ notice, during normal business hours, and subject to confidentiality. Audits must not disrupt the Services or give access to other customers’ data. A supervisory authority may audit whenever Data Protection Laws require it.

Deletion and return of data

When your account is deleted or your use of the Services ends, we will delete Customer Personal Data within 30 days, unless the law requires us to keep it. Before that, you can export your data through the Services or the API, or ask us for a copy. Data in backups is overwritten in the normal backup cycle.

Liability

Each party’s liability under this DPA is subject to the limitations of liability in the Terms, to the extent permitted by Data Protection Laws.

Term and changes

This DPA stays in effect for as long as we process Customer Personal Data on your behalf. We may update it to reflect changes in our Services, Subprocessors, or legal requirements. If we make significant changes, we will notify you by email or through the web app.

Governing law

This DPA is governed by the laws of Denmark, and the courts of Denmark have jurisdiction over any dispute arising from it, unless Data Protection Laws or the Standard Contractual Clauses require otherwise.

Contact us

If you have any questions about this DPA or need a countersigned copy, you can contact us at:

support@winwinkit.com

Osta Ventures ApS

CVR: 45177270