RecruitAffiliates.ai Start free

Legal

Data processing agreement

Version 2.0. Last updated 28 September 2026.

The short version

When you use RecruitAffiliates.ai to email creators, you decide who to contact and why. That makes you the controller of that data, and us the processor: we hold it and act on it for you. It also makes the law on those emails yours to follow (clause 3). UK and EU law says a processor needs a written contract. This is it, and you already have it. It's part of the terms you accepted, so nothing needs signing. This page is the copy to keep on file.

This agreement is between James Barkway, trading as RecruitAffiliates.ai, a sole trader, Office 4382, 182-184 High Street North, London, E6 2JA, United Kingdom ("we", "us", the processor), and the customer named on the RecruitAffiliates.ai account ("you", the controller).

It forms part of the terms of service and takes effect when you open an account. Where this agreement and the terms disagree about personal data, this agreement wins. It's governed by the law of England and Wales, and by the same courts, as section 25 of the terms.

1. What this covers

Personal data we process for you when you recruit affiliates with RecruitAffiliates.ai: the creators you save, the email addresses you reveal, your campaigns, the emails you send and receive, your notes, your deals and your own do-not-contact list. Annex 1 has the detail.

It doesn't cover three things where we're the controller and our privacy policy applies instead: your own account, subscription and invoices; the discovery data our scans gather and rank from public sources, before you save a creator from it; and the do-not-contact list in clause 2.

Words like personal data, processing, controller, processor, data subject and personal data breach mean what UK GDPR, the Data Protection Act 2018 and, where it applies, the EU GDPR say they mean.

2. We act on your instructions and nothing else

We process the personal data only on your documented instructions, including on transfers out of the UK. Your instructions are this agreement, the terms, the settings you choose in the product, and anything you ask us to do in writing.

Using the product is an instruction. Saving a creator, revealing an email, approving a campaign, agreeing a deal: each is you telling us to process.

Accepting the terms also instructs us to do three things on every send, which you can't switch off: add the notice lines to every first email, add an unsubscribe line to every email, and apply the safety rules in section 12 of the terms.

If the law makes us process your data for another reason, we tell you first, unless that law forbids it. If we think an instruction breaks data protection law, we tell you, and we may refuse to carry it out.

We never sell your data, never use it to train an AI model, and never use it to build a product of our own.

One exception, which protects the people you email. When someone unsubscribes from your email or asks to be removed, we keep a scrambled code of their address or channel and block it for every customer. That record is ours, kept to honour their request, and it outlives your account.

3. Your duties as the controller

You're responsible for the outreach you send and the data you give us. In particular, you promise that:

  1. you have a lawful basis for every email you send, under the law where you are and where the recipient is, including any consent the law needs (terms, section 11);
  2. where you rely on legitimate interests, you've done and written down your own assessment;
  3. you give recipients the privacy information the law requires, including who you are and how to reach you. The notice lines we add help with this. They don't replace your own privacy notice;
  4. you honour every objection and opt-out, and never ask us to email an address on the do-not-contact list;
  5. you don't give us special category data, such as health, religion or politics, or data about anyone who appears to be under 18;
  6. your instructions to us are lawful.

4. Confidentiality

Everyone who can reach your data is bound to keep it confidential, and that duty outlives their involvement. Access is granted only where the work needs it.

5. Security

We take the measures in Annex 2. We may change them, but never to leave the protection weaker. The security page is the plain-language version.

6. Sub-processors

You give us general written authorisation to use sub-processors. The current list is on the sub-processors page, which is part of this agreement.

We give you 30 days' notice before a new sub-processor starts processing your data. Notice goes to the email on your account, and the page is updated the same day.

You may object, with reasons, during those 30 days. We'll try to find another way. If we can't, you may end your subscription and we refund the unused part of what you've paid.

Every sub-processor is under written terms carrying the same obligations as this agreement, so far as they apply. We stay responsible to you for what they do.

Your own mailbox provider (Google, Microsoft, Yahoo or your mail host) isn't our sub-processor. You chose it, and your agreement with it is yours.

7. Helping you answer people

You can export your saved creators on a paid plan. To delete one creator's data from your account for good, email support and we do it within 7 days.

If someone contacts us about data we hold for you, we tell them you're the controller, tell them it's your business they're dealing with, and pass the request to you promptly. If they ask us to stop emailing them, we block their address at once, as clause 2 says, and tell you.

A person you emailed can see what's held about them, and where it came from, through the link in the notice lines. They can also remove themselves at app.recruitaffiliates.ai/creators/remove.

Where you need more help, we give it. We don't charge for a reasonable amount. We help with data protection impact assessments and with consulting the ICO, to the extent the information is ours to give.

8. If there's a breach

We tell you about a personal data breach affecting your data without undue delay, and within 48 hours of finding out.

The notice says what happened, which kinds of data and roughly how many people, the likely consequences, what we've done, and who to talk to. If we can't give all of it at once, we send what we have and follow up.

Reporting to the ICO and telling the people affected is yours, because you're the controller. We give you what you need to do it.

9. Deletion and return

Ask us to delete your account's data, from the owner's address, and we delete the personal data we hold for you within 30 days. Export your saved creators first if you want them. A finished trial or a cancelled plan isn't a deletion: the account stays read-only until you ask.

Some data goes sooner on its own: the subject and body of synced emails after 30 days, and your mailbox connection 7 days after your plan ends.

What survives deletion: the do-not-contact record in clause 2, and records we're required by law to keep, for as long as that law says. Backups expire on their own schedule, within 7 days, and a restored backup is purged again.

10. Audit and information

We give you the information you need to show this agreement is being kept. This page, the security page and the sub-processor list are most of it.

We allow audits, including inspections, by you or an auditor you appoint. We need at least 30 days' notice, during working hours, no more than once a year unless a breach or a regulator makes it necessary, under confidentiality, and never in a way that puts another customer's data at risk.

We aren't certified to SOC 2, ISO 27001 or any other scheme, so there's no report to send instead. We answer questions directly.

11. Transfers out of the UK

Most of our sub-processors process in the United States, and some in the EU. The mechanism for each is on the sub-processors page, which is Annex 3 of this agreement.

We use OpenRouter to send requests to Qwen models run by Alibaba Cloud International, which may process them in Singapore or mainland China. Neither country has a UK or EU adequacy decision. Alibaba states it does not use this data to train models. We rely on OpenRouter's contractual data-protection commitments; we do not currently hold a signed data processing agreement with Standard Contractual Clauses for this transfer. We send it only public web text, channel descriptions, video titles and your own website's text. We never send it email addresses, email bodies, replies or payment data.

Where a mechanism stops being valid, we move to another lawful one or stop using that sub-processor. You authorise us to enter into transfer terms with a sub-processor on your behalf where a mechanism requires it.

If you're in the EU or EEA, the EU Standard Contractual Clauses (module two, controller to processor, or module three, processor to processor, as the case needs) are incorporated into this agreement by reference, with the governing law and courts of Ireland for those clauses only.

12. Liability

Liability under this agreement is subject to section 22 of the terms, and your promise to cover us in section 21 of the terms applies to a breach of clause 3. Nothing here limits either side's own liability to a data subject or a regulator.

13. Changing this agreement

Where a change materially reduces your protection, we email you at least 30 days before it takes effect. You may end your subscription in that time if you don't accept it. Sub-processor changes follow clause 6 instead.

Annex 1: what is processed

Subject matter and duration

Recruiting affiliates for your business: the creators you save, the emails you send them and the terms you agree. It lasts as long as your account, plus the 30 days in clause 9.

Whose data

What kind of data

CategoryWhat that means
Identity and contactName, email address and where it came from, site, channel or show, handle, country, language
Public profileAudience size, traffic estimate, the pages, videos or episodes that matched, the affiliate links on them
CommunicationThe emails you send and the replies you receive, in threads RecruitAffiliates.ai started or you linked. Subjects and bodies are deleted after 30 days
DealThe terms you offer and agree: commission rate, how long it's paid, currency, every version
Notes and listsWhatever you write about a creator, and your own do-not-contact list with its reasons

No special category data is asked for or needed. You must not add it (clause 3).

What we do with it

Store it, find and verify email addresses, build draft emails for you to approve, send the emails you approved from your connected inbox with the notice and unsubscribe lines, read replies in those threads, sort replies by rules, stop sequences on a reply, bounce or unsubscribe, move creators through your pipeline, back it up, and give you the exports and deletions in clauses 7 and 9.

Annex 2: security measures

MeasureWhat we do
Encryption in transitTLS on every surface
Encryption at restThe whole database, at the provider. Email bodies are encrypted again in our own database. Mailbox connection secrets are held by Unipile, not in our database
Mailbox boundaryNo import of old mail. Only threads RecruitAffiliates.ai started, or that you linked, are synced
Access controlRoles: owner, admin, member. Only the owner connects an inbox or changes billing. Plan limits enforced on the server
SeparationA tenancy check on every query, tested with two customers side by side
Sending safetyHuman approval before a campaign's first send. A daily cap per inbox, lower for a new inbox. Automatic stop on reply, bounce or unsubscribe. A do-not-contact list shared by every customer. No open or click tracking
AvailabilityManaged Postgres with a 7-day point-in-time history
TestingAn automated test suite runs before anything ships, including tests that one customer's data can't be read from another's session
Vulnerability reportssecurity@recruitaffiliates.ai, a human reply within two working days

Annex 3: transfers

The provider-by-provider list of locations and transfer mechanisms is on the sub-processors page, and forms this annex.

Getting a copy

If your procurement process needs a signed copy rather than the accepted-by-reference version, email support@recruitaffiliates.ai and we'll send one.