DPA to Yotpo Publisher Agreement

This Data Processing Addendum (“DPA”) is incorporated by reference into Yotpo’s Publisher Agreement available at [LINK TO PUBLISHING AGREEMENT] or other agreement governing the use of Yotpo’s Publishing services (“Agreement”) entered by and between you, the Client (as defined in the Agreement) (collectively, “you”, “your”, “Client”), and Yotpo Ltd. or an Affiliate (“Yotpo”, “us”, “we”, “our”) to reflect the parties’ agreement with regard to the Processing of Personal Data by Yotpo solely on behalf of the Client. Both parties shall be referred to as the “Parties” and each, a “Party”. Capitalized terms not defined herein shall have the meanings assigned to such terms in the Agreement.

By using the Services, Client accepts this DPA and you represent and warrant that you have full authority to bind the Client to this DPA. If you cannot, or do not agree to, comply with and be bound by this DPA, or do not have authority to bind the Client or any other entity, please do not provide Personal Data to us.

In the event of any conflict between certain provisions of this DPA and the provisions of the Agreement, the provisions of this DPA shall prevail over the conflicting provisions of the Agreement solely with respect to the Processing of Personal Data. We may update this DPA at any time with or without notice to you up to the fullest extent permitted by Applicable Law (as defined below). Unless otherwise prohibited by Applicable Law, updated versions of the Agreement take effect immediately.

1. Definitions

1.1Applicable Law” means all data protection and privacy laws of the United States, including but not limited to the CCPA, CPRA, CPA, CTDPA, UCPA, VCDPA, and any successor or implementing legislation, as well as GDPR and UK GDPR where applicable. For clarity, where processing is subject to GDPR, UK GDPR, or Swiss Data Protection Laws, the additional terms set forth in Appendix B (GDPR Addendum) shall apply.

1.2Business” means the entity that determines the purposes and means of processing of Personal Data.

1.3Service Provider” means the entity that processes Personal Data on behalf of a Business.

1.4Publisher Personal Data” means Personal Data disclosed by Publisher to Yotpo in connection with the Services.

1.5Referral Data” means Personal Data disclosed to Yotpo following an individual’s engagement with an offer through the Services. For the sake of clarity, no Referral Data exists in instances where Yotpo does not obtain such information.

1.6Yotpo Data” means data generated, derived, or aggregated from operation of the Yotpo platform or provision of the Services which does not identify an individual, including de-identified, pseudonymized, or anonymized data.

1.7Security Incident” means any confirmed or reasonably suspected unauthorized or unlawful access, disclosure, alteration, loss, or destruction of Personal Data.

1.8 Other capitalized terms not defined herein shall have the meaning set forth in the Agreement.

2. Roles of the Parties

2.1 Publisher is a Business with respect to Publisher Personal Data.

2.2 Yotpo is a Service Provider with respect to Publisher Personal Data.

2.3 Yotpo and Publisher act as separate Businesses regarding Referral Data, and each Party shall be independently liable for its own compliance with Applicable Law.

2.4 Yotpo is a Business with respect to Yotpo Data, which Yotpo may use for its own legitimate business purposes, provided that it does not re-identify any individual.

3. Processing Instructions

3.1 Yotpo shall process Publisher Personal Data only in accordance with Publisher’s documented instructions (including the Publisher Agreement), except where otherwise required by Applicable Law.

3.2 Yotpo shall not sell or share Publisher Personal Data, nor retain, use, or disclose Publisher Personal Data for any purpose other than for the specific business purposes and service provider functions as defined under Applicable Law of providing the Services or described in the Agreement.

3.3 Yotpo shall not combine Publisher Personal Data with Personal Data received from another source, except as permitted by Applicable Law, as defined under the CPRA, and exclusively to execute the commercial objectives within the direct business engagement between the Parties.

3.4 Yotpo does not use Publisher Personal Data to build or enhance cross-merchant profiles, audience segments, or targeting models unrelated to the Services provided to the specific Publisher.

4. Yotpo’s Service Provider Obligations

4.1 Purpose Limitation. Yotpo shall process Publisher Personal Data to provide the Services under the Publisher Agreement. For clarity, Yotpo is authorized to process basic, non-sensitive identifiers (including but not limited to, name, email address, hashed email address, IP address, device identifiers, transaction details, and general geolocation) as reasonably necessary to display post-transaction offers, facilitate referral transactions, conduct attribution and campaign measurement, prevent fraud, personalize content within the Publisher’s environment, and improve the Services, as described in the Agreement.

4.2 Confidentiality. Yotpo shall ensure all personnel authorized to process Publisher Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4.3 Subprocessing. Yotpo makes available to Publisher the current list of Sub-Processors used by Yotpo to process Personal Data via https://www.yotpo.com/subprocessors/. Such Sub-processor list includes the identities of those Sub-processors and the entity’s country (“Sub-Processor List”). The Sub-Processor List as of the date of first use of the Service by Publisher is hereby deemed authorized upon first use of the Services. Publisher will have no further claims against Yotpo due to (i) past use of approved Sub-processors prior to the date of the first use of the Services or (ii) the termination of the Agreement (including, without limitation, requesting refunds) and the DPA in the situation described in this paragraph. Yotpo’s webpage, accessible via www.yotpo.com/subprocessors, offers a mechanism to subscribe to notifications of new Sub-processors used to Process Personal Data, to which Publisher shall subscribe, and when Publisher subscribes, Yotpo shall provide notification of any new Sub-processor(s) before authorizing such new Sub-processor(s) to Process Personal Data in connection with the provision of the Services.

4.4 Objection to New Sub-processors. Publisher may reasonably object to Yotpo’s use of a new Sub-processor, for reasons relating to the protection of Personal Data intended to be Processed by such Sub-processor, by notifying Yotpo promptly in writing within seven (7) days after receipt of a Yotpo notification in accordance with the mechanism set out in in this Section. Such written objection shall include the reasons for objecting to Yotpo’s use of such new Sub-processor. Failure to object to such new Sub-processor in writing within seven (7) days following Yotpo’s notice shall be deemed as acceptance of the new Sub-Processor. In the event Publisher reasonably objects to a new Sub-processor, as permitted in the preceding sentences, Yotpo will use reasonable efforts to make available to Publisher a change in the Service or recommend a commercially reasonable change to Publisher’s configuration or use of the Service to avoid Processing of Personal Data by the objected-to new Sub-processor without unreasonably burdening the Publisher. If Yotpo is unable to make available such change within thirty (30) days, Publisher may, as a sole remedy, terminate the applicable Agreement and this DPA with respect only to those Services which cannot be provided by Yotpo without the use of the objected-to new Sub-processor, by providing written notice to Yotpo. Until a decision is made regarding the new Sub-processor, Yotpo may temporarily suspend the Processing of the affected Personal Data and/or suspend access to the Services. Publisher will have no further claims against Yotpo due to the termination of the Agreement (including, without limitation, requesting refunds) and/or the DPA in the situation described in this paragraph.

4.5 Agreements with Sub-processors. Yotpo or a Yotpo Affiliate on behalf of Yotpo has entered into a written agreement with each Sub-processor containing appropriate safeguards to the protection of Personal Data. Where Yotpo engages a Sub-processor for carrying out specific Processing activities on behalf of the Publisher, the same or materially similar data protection obligations as set out in this DPA shall be imposed on such new Sub-processor by way of a contract, in particular obligations to implement appropriate technical and organizational measures in such a manner that the processing will meet the requirements of the GDPR. Where a Sub-processor fails to fulfil its data protection obligations concerning its processing of Personal Data, Yotpo shall remain responsible for the performance of the Sub-processor’s obligations.

4.6 Data Subject Rights. Yotpo shall, to the extent legally permitted, promptly notify Publisher of any request received from a Data Subject relating to Publisher Personal Data. Yotpo shall not substantively respond to any Data Subject request relating to Publisher Personal Data without Publisher’s documented instructions, except where required by Applicable Law. Yotpo may inform the requesting individual that Yotpo acts solely as a service provider to Publisher and has forwarded the request to the relevant Publisher. Taking into account the nature of the processing, Yotpo shall provide Publisher with reasonable assistance by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of Publisher’s obligation to respond to verified requests by Data Subjects to exercise their rights under Applicable Law, including rights of access, rectification, deletion, restriction, portability, and opt-out.

4.7 DPIAs and Regulator Cooperation. Yotpo shall provide reasonable assistance, at Publisher’s cost, with Data Protection Impact Assessments and regulatory inquiries relating to Publisher Personal Data.

4.8 Security Incidents. Yotpo shall notify Publisher without undue delay upon becoming aware of a Security Incident and provide all information reasonably required for Publisher to comply with its legal obligations. Yotpo shall not notify any affected Data Subject, supervisory authority, or regulatory body regarding a Security Incident involving Publisher Personal Data without Publisher’s prior written instruction, unless required to do so by Applicable Law and only to the extent legally required, in which case Yotpo shall provide Publisher with advance notice to the extent legally permitted.

4.9 Return or Deletion. Upon termination, Yotpo shall delete or return Publisher Personal Data at Publisher’s option, except where retention is required by law or necessary for the establishment, exercise, or defense of legal claims.

4.10 Audit Rights. Yotpo shall make available to Publisher information reasonably necessary to demonstrate compliance with this Agreement. Any audit shall be conducted no more than once annually (unless required by a regulator or following a Security Incident), during normal business hours, upon reasonable prior written notice, and in a manner that does not unreasonably interfere with Yotpo’s business operations. Where available, Publisher may satisfy its audit rights by reviewing Yotpo’s current third-party security certifications or audit reports (e.g., SOC 2 or equivalent), subject to confidentiality obligations.

5. Publisher’s Obligations

Publisher shall ensure that it has a lawful basis for the collection and disclosure of Publisher Personal Data and shall provide all required notices and obtain all required consents under Applicable Law, including disclosure in its privacy notice of the categories of Personal Data shared with Yotpo, the purposes of such processing (including delivery of post-transaction offers, attribution, analytics, and fraud prevention), and Yotpo’s role as a service provider or processor acting on Publisher’s behalf. Publisher shall independently fulfill its obligations as a Business or Controller under Applicable Law.

6. Referral Data

Regarding Referral Data, Yotpo and Publisher operate as distinct Businesses. Each Party shall independently fulfill its obligations to provide necessary notices, secure required consents, and address Data Subject requests as mandated by Applicable Law. Yotpo is authorized to utilize Referral Data exclusively for the delivery or facilitation of offers, performance measurement, and legal compliance. Each Party shall manage such data in accordance with its respective privacy policies and Applicable Law. Referral Data shall not be merged with Publisher Personal Data for objectives unrelated to the particular referral transaction or the Services rendered to Publisher. No provision herein authorizes the use of Referral Data for re-identification or profiling of individuals beyond the scope essential for the delivery or measurement of the applicable referral offer.

7. Yotpo Data

Yotpo shall be a Business with respect to Yotpo Data. As described in the Agreement, Yotpo may use Yotpo Data for service improvement, analytics, fraud detection, benchmarking, security, research, and product development, provided that Yotpo Data does not identify and cannot reasonably be used to identify an individual. Yotpo shall implement technical and organizational measures designed to ensure that Yotpo Data is de-identified or aggregated in a manner that prevents re-identification and shall not attempt to re-identify any individual from such data.

8. International Transfers

Yotpo may transfer Personal Data outside the region in which it was collected only with appropriate safeguards, such as Standard Contractual Clauses or equivalent mechanisms, unless Applicable Law permits otherwise.

9. Costs and Allocation of Responsibility

Each party shall bear its own costs of complying with this Agreement. Yotpo may charge Publisher for reasonable costs incurred in providing assistance not expressly included in the Services, including audits, DPIAs, and regulator consultations.

10. Liability and Indemnification

Liability for breaches of this Agreement shall be governed by the Publisher Agreement. Each party agrees to indemnify the other against losses arising from its own breach of this Agreement or Applicable Law.

11. Term and Termination

This Agreement shall remain in effect for as long as Yotpo processes Publisher Personal Data. Sections relating to confidentiality, Yotpo Data, and limitations of liability shall survive termination.

12. Miscellaneous

12.1 Governing Law. This Agreement shall be governed by the laws specified in the Ad Network Publisher Agreement.

12.2 Order of Precedence. In the event of a conflict, this Agreement shall control with respect to the subject matter herein.

12.3 Severability. If any provision is held invalid, the remainder shall continue in full force and effect.

12.4 Notices. Notices under this Agreement shall be provided in accordance with the Publisher Agreement.

Annex A – Data Processing Schedule

Categories of Data Subjects End users of Publisher’s services.
Types of Personal Data Name, email, mobile number, transaction details, address, device/browser identifiers, location data, usage logs.
Sensitive data Publisher shall not disclose Special Categories of Personal Data (as defined under GDPR) or Sensitive Personal Information (as defined under Applicable Law, including CPRA) to Yotpo unless expressly agreed in writing. Yotpo does not require and does not intentionally collect such data to provide the Services.
Purposes of Processing Delivering offers, analytics, targeting, fraud detection, personalization, campaign measurement, compliance.
Lawful Basis As determined by Publisher; typically consent, performance of contract, or legitimate interest.
Retention For the duration of the Ad Network Publisher Agreement or as required by law; de-identified or anonymized thereafter.
Cross-Border Transfers and Safeguards Standard Contractual Clauses or other lawful mechanisms where required.
Contact points for data protection enquiries privacy@yotpo.com

 

Appendix B

GDPR Addendum

This Appendix B (the “GDPR Addendum”) supplements the Yotpo Data Processing Agreement (the “Agreement”) where and to the extent that Yotpo processes Publisher Personal Data subject to the GDPR, UK GDPR, or Swiss Data Protection Laws. Capitalized terms not defined herein have the meanings set forth in the Agreement.

1. Roles of the Parties

1.1 For purposes of the GDPR and corresponding laws:

  • Publisher acts as “Controller”;
  • Yotpo acts as “Processor” when processing Publisher Personal Data;
  • Where Publisher acts as a Processor for its own customer, Yotpo shall be deemed a “Sub-processor.”

1.2 The parties acknowledge that Yotpo remains an independent Controller with respect to Yotpo Data and Referral Data, as set out in the Agreement.

2. Instructions

Yotpo shall process Publisher Personal Data only on documented instructions from Publisher, unless required by EU, Member State, UK, or Swiss law to do otherwise. Yotpo shall immediately inform Publisher if, in its opinion, any documented instruction infringes GDPR, UK GDPR, Swiss Data Protection Laws, or other applicable data protection provisions.

3. Data Subject Rights

Taking into account the nature of the processing, Yotpo shall assist Publisher by appropriate technical and organizational measures to enable Publisher to respond to Data Subject requests under Articles 15–22 GDPR, including rights of access, rectification, erasure, restriction, portability, and objection. Yotpo shall not respond to Data Subject requests without Publisher’s instructions, unless legally required.

4. Security Measures

4.1 Yotpo shall implement appropriate technical and organizational measures designed to protect Publisher Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

4.2 Such measures are described in Schedule 1 (Technical and Organizational Measures) attached hereto.

5. Security Incidents

Yotpo shall notify Publisher without undue delay after becoming aware of a Security Incident involving Publisher Personal Data and shall provide reasonably available information to assist Publisher in meeting its notification obligations under Articles 33–34 GDPR.

6. Return and Deletion

Upon termination of the Services, Yotpo shall, at Publisher’s option, return or delete Publisher Personal Data. Yotpo may retain a copy only as required by law or necessary to establish, exercise, or defend legal claims, subject to ongoing confidentiality and security obligations.

7. International Transfers

7.1 Where Yotpo transfers Publisher Personal Data outside the EEA, UK, or Switzerland, such transfers shall be made pursuant to:

  • The EU Standard Contractual Clauses (Commission Decision (EU) 2021/914), Modules Two (Controller to Processor) and Three (Processor to Processor);
  • The UK Addendum issued by the UK Information Commissioner; and/or
  • The Swiss Addendum issued under Swiss Data Protection Law, as further specified in Schedule 2 (Cross-Border Transfer Terms).

To the extent required by the EU Standard Contractual Clauses or applicable Addenda, the governing law and jurisdiction provisions of such clauses shall prevail solely with respect to matters governed by the Standard Contractual Clauses.

7.2 Yotpo shall provide reasonable cooperation for transfer impact assessments (TIAs) and supplementary measures required under Applicable Law.

8. Assistance with DPIAs and Supervisory Authorities

Yotpo shall provide reasonable assistance to Publisher, at Publisher’s expense, with Data Protection Impact Assessments and consultations with supervisory authorities related to Publisher Personal Data.

9. Order of Precedence

In case of conflict, this GDPR Addendum (including Schedules) prevails over the Agreement, but only with respect to processing subject to GDPR, UK GDPR, or Swiss Data Protection Laws.

Schedule 1 – Technical and Organizational Measures

Yotpo implements, at a minimum:

  • Access Controls: Role-based access, least privilege, strong authentication, revocation on termination.
  • Encryption: Industry-standard encryption of Publisher Personal Data in transit and at rest.
  • Logging & Monitoring: System activity and access logging with routine review.
  • Incident Response: Documented incident response plan with escalation procedures.
  • Physical Security: Restricted access to data centers and secure server environments.
  • Business Continuity: Disaster recovery and backup processes.
  • Vendor Oversight: Regular assessments of Sub-processors’ security practices.

Schedule 2 – Cross-Border Transfer Terms

  1. EU SCCs: The parties incorporate the EU Standard Contractual Clauses, Modules Two and Three, with Yotpo as “data importer” and Publisher as “data exporter.”
  2. UK Addendum: The Approved Addendum (version B.1.0, or successor) issued by the UK ICO applies.
  3. Swiss Addendum: Transfers subject to Swiss law shall be governed by equivalent clauses adapted for Swiss requirements.
  4. Supplementary Measures: Yotpo will implement additional safeguards (e.g. encryption, minimization, internal policies, and transparency commitments) as reasonably necessary to ensure an essentially equivalent level of protection.

 

 

30 min demo
Don't postpone your growth
Let’s schedule a quick demo to get your growth strategy rolling.

Yotpo customers logosYotpo customers logosYotpo customers logos
Laura Doonin, Commercial Director recommendation on yotpo

“Yotpo is a fundamental part of our recommended tech stack.”

Shopify plus logo Laura Doonin, Commercial Director
YOTPO POWERS THE WORLD'S FASTEST-GROWING BRANDS
Yotpo customers logos
Yotpo customers logosYotpo customers logosYotpo customers logos
30 min demo
Don't postpone your growth
Check iconJoin a free demo, personalized to fit your needs
Check iconGet the best pricing plan to maximize your growth
Check iconSee how Yotpo's multi-solutions can boost sales
Check iconWatch our platform in action & the impact it makes
30K+ Growing brands trust Yotpo
Yotpo customers logos