Legal

Data Processing & Joint Controller Agreement (DPA)

How Klatsa, advertisers and publishers process personal data.

Version: 1.2 Effective date: 18 September 2026

Language. This is a translation of the Dutch original. In the event of any discrepancy between this English version and the Dutch version, the Dutch text prevails.

This Data Processing and Joint Controller Agreement (hereinafter: the "DPA") forms an integral part of the Advertiser Terms and Conditions and the Publisher Terms and Conditions of Jaspers Media (trading as "Klatsa"), established in Limmen, the Netherlands, Chamber of Commerce 02093573, VAT NL002155155B89, hereinafter "Klatsa".

This DPA governs the processing of personal data within the Klatsa Network (app.klatsa.nl and to.klatsa.nl) between Klatsa on the one hand and the Advertiser or Publisher on the other (hereinafter: the "Counterparty").


1. Definitions and framework

1.1. Capitalised terms not defined here have the meaning given to them in the GDPR (Regulation (EU) 2016/679) and/or the Terms and Conditions of Klatsa.

1.2. Applicable legislation: the GDPR, the UAVG (the Dutch GDPR Implementation Act), the e-Privacy Directive (Directive 2002/58/EC as implemented), and binding guidance from the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and the European Data Protection Board.

1.3. If a provision of this DPA conflicts with the Terms and Conditions, this DPA prevails insofar as the processing of personal data is concerned.


2. Allocation of roles

Within the Klatsa Network the allocation of roles varies per type of processing. This DPA covers three scenarios:

2.1. Klatsa as Processor (Article 28 GDPR)

Klatsa acts as Processor on behalf of the Counterparty for:

  • Receiving, storing and forwarding conversion data reported back by the Advertiser through the S2S postback (order number, order amount, currency, product category and optional meta fields).
  • Hosting and forwarding publisher feeds and promotional material supplied by the Advertiser, insofar as these contain personal data.

In this scenario the Counterparty is the Controller.

2.2. Klatsa and Counterparty as Joint Controllers (Article 26 GDPR)

Klatsa and the Counterparty are Joint Controllers for:

  • Setting and reading tracking cookies and click IDs in the browser of end users for the purpose of click and conversion attribution.
  • Recording clicks (IP address and user agent in hashed form only, referrer, geo derivative, timestamp, deeplink ID) on to.klatsa.nl.
  • The attribution of conversions to publishers for the purpose of commission calculation and invoicing.

The allocation of roles between Joint Controllers is set out in Annex A.

2.3. Klatsa as independent Controller

Klatsa is an independent Controller for:

  • The processing of account and contact details of Advertisers and Publishers (Chamber of Commerce number, VAT number, contact person, login, financial details) for the purpose of platform access, invoicing, customer service and compliance.
  • Fraud detection and network monitoring on the basis of aggregated data.

Only the Klatsa Privacy Statement applies to this (https://klatsa.nl/en/privacy), and not this DPA.


3. Subject matter, nature, duration and purpose of the processing

Element Specification
Subject matter Processing of personal data of end users (visitors) and sales data, in the context of affiliate tracking, conversion attribution and commission settlement.
Nature Collecting, recording, structuring, storing, transmitting, consulting, using, erasing or destroying.
Purpose Affiliate marketing: measuring clicks, conversions and commissions; invoicing; fraud detection; reporting.
Duration For the term of the agreement between Klatsa and the Counterparty, plus any statutory retention periods (see Article 8).
Categories of data subjects End users (visitors to publisher sites and advertiser sites).
Categories of personal data See Article 4.

4. Categories of personal data

Klatsa does not process special categories of personal data (health, religion, political opinions, etc.).

What is processed: technical and transactional identifiers:

  • Click ID (ULID, pseudonymous identifier)
  • IP address and user agent: stored in the click data in hashed form only, with a key that changes daily. The IP address itself is held in working memory for at most 1 hour for the check on VPN and proxy traffic (see Annex C, proxycheck.io)
  • For attributing orders without a Click ID: a hash of the IP address and user agent with a fixed key, retained for at most 30 days
  • Referrer URL
  • Timestamp of the click and of the conversion
  • Geo derivative (country/region based on IP, not an exact location)
  • Tracking cookie ID (first-party on to.klatsa.nl, maximum lifetime in line with the Programme Cookie Period)
  • Conversion data: order number (hashed or in clear text depending on the Advertiser's choice), order amount, currency, product category, optionally a customer segment (e.g. "new customer" / "returning customer")
  • Sub IDs or custom parameters passed on by the Publisher (often not related to a person)

Email addresses or name and address details of end users are not processed by Klatsa as standard. If an Advertiser nevertheless sends such data, Article 5.4 applies.


5. Obligations of Klatsa as Processor (scenario 2.1)

5.1. Klatsa processes personal data solely on the basis of documented instructions from the Counterparty, as recorded in the IO, in the platform or in this DPA. Outside those instructions Klatsa only processes where it is legally required to do so, in which case Klatsa informs the Counterparty beforehand (unless the law prohibits this).

5.2. Klatsa ensures that persons with access to personal data are bound by a duty of confidentiality.

5.3. Klatsa takes appropriate technical and organisational measures as described in Annex B.

5.4. If a Counterparty supplies personal data that falls outside the normal categories of Article 4 (for example customer email addresses or name and address details), Klatsa informs the Counterparty that such data is not necessary for affiliate attribution and requests its deletion or pseudonymisation. Until deletion, the same security standard applies to that data.

5.5. Assistance regarding data subjects. Klatsa assists the Counterparty, insofar as reasonably possible, in responding to requests from data subjects for access, rectification, erasure and objection.

5.6. Assistance with DPIAs and consultation of the Dutch Data Protection Authority. Klatsa assists the Counterparty with DPIAs and any prior consultation of the Dutch Data Protection Authority, insofar as this relates to processing under this DPA.

5.7. Data breach. Klatsa informs the Counterparty without undue delay and in any event within 48 hours after establishing a personal data breach, providing the information referred to in Article 33(3) GDPR. The obligation to notify the Dutch Data Protection Authority and the data subjects remains with the Counterparty (in scenario 2.1).

5.8. End of processing. After termination of the agreement Klatsa erases the personal data within 90 days, or returns it to the Counterparty in a commonly used machine-readable format if the Counterparty requests this within 30 days of termination. Statutory retention periods continue to apply (see Article 8).

5.9. Audit. The Counterparty may, once per calendar year, at its own expense and with at least 30 days' prior notice, carry out or commission an audit of Klatsa's compliance with this DPA. Klatsa may instead submit a recent independent audit report (for example ISAE 3402, ISO 27001) if one is available.


6. Sub-processors

6.1. The Counterparty gives Klatsa general authorisation to engage sub-processors, provided that Klatsa concludes a written agreement with each sub-processor imposing the same obligations as this DPA.

6.2. The current list of sub-processors is set out in Annex C.

6.3. Klatsa informs the Counterparty at least 30 days in advance of intended changes to the list of sub-processors (addition, replacement). Within that period the Counterparty may object in writing, stating reasons; if the objection is well founded, the parties will seek a reasonable solution or the Counterparty may terminate the agreement.


7. Transfers outside the EEA

7.1. Klatsa processes personal data within the EEA as standard (hosting on a dedicated server at OVHcloud, EU data centre; backups also remain within the EEA).

7.2. If a transfer to a third country does take place (for example through a sub-processor), Klatsa ensures appropriate safeguards in accordance with Article 46 GDPR (standard contractual clauses, or an adequacy decision).


8. Retention periods

Data type Retention period
Click data (raw) 13 months, aggregated thereafter
Hash of IP address and user agent (attribution without a Click ID) 30 days
Conversion data 7 years (tax retention obligation for invoicing)
Cookie in the end user's browser In line with the Programme Cookie Period (usually a maximum of 90 days)
Account and contact data of the Counterparty Term of the agreement + 7 years (tax)
Audit logs / login history 12 months
Data breach incident register 5 years

9. Liability

9.1. Liability under this DPA is limited per calendar year to the amount stated in the main agreement (Terms and Conditions), subject to mandatory exceptions under the GDPR.

9.2. Fines imposed on the Counterparty by the Dutch Data Protection Authority or another authority can only be recovered from Klatsa insofar as they are the direct and demonstrable result of an attributable failure by Klatsa under this DPA.


10. Final provisions

10.1. This DPA takes effect on the commencement date stated in the main agreement and ends automatically when the main agreement ends, with the exception of provisions that by their nature continue to apply (right of audit, confidentiality, retention periods, data breach notifications insofar as they relate to facts that already exist).

10.2. This DPA is governed by Dutch law. Disputes are submitted to the competent court (District Court of North Holland, Rechtbank Noord-Holland).


Annex A — Joint Controller allocation of roles (Article 26 GDPR)

For the processing operations in scenario 2.2, Klatsa and the Counterparty divide the GDPR obligations as follows:

Obligation Responsible
Obtaining cookie consent from the end user (e-Privacy / TCF) Counterparty (on its own site/app)
Implementing the tracking pixel in line with the consent status Counterparty
Setting the cookie on to.klatsa.nl Klatsa
Privacy statement for own site plus reference to Klatsa Counterparty
Privacy statement for app.klatsa.nl / to.klatsa.nl Klatsa
Security of the tracking infrastructure Klatsa
Responding to an access or erasure request received through own channel The party first approached (with assistance from the other)
Notifying the Dutch Data Protection Authority and data subjects of a breach in the Klatsa system Klatsa
Notifying the Dutch Data Protection Authority and data subjects of a breach in own channel Counterparty
Central point of contact for end users (for processing under this DPA) Klatsa via privacy@klatsa.nl

Klatsa publishes the essence of this allocation of roles at https://klatsa.nl/en/privacy.


Annex B — Security measures

Organisational:

  • Duty of confidentiality for all employees and volunteers with platform access.
  • Need-to-know access policy and role-based permissions (Filament policies).
  • Documented incident response process.
  • Periodic awareness training for employees (security, phishing, GDPR basics).

Technical:

  • HTTPS/TLS 1.2+ on all endpoints (app.klatsa.nl, to.klatsa.nl).
  • HSTS, secure cookies (SameSite=Lax where functionally possible).
  • Passwords hashed with bcrypt (Laravel default), 2FA option for admins.
  • Database (PostgreSQL 18) behind a restrictive firewall, accessible only from the application server.
  • Daily encrypted database backups, retained for at most 30 days.
  • Server-side logging (errors via Sentry) without PII in stack traces where possible.
  • Monitoring for suspicious login patterns, brute force attempts and unusual API calls.
  • Patching: critical security updates within 14 days of release.
  • IP addresses are not stored in click logs, only as a hash with a key that changes daily. The hash of IP address and user agent used for attribution without a Click ID is erased automatically after 30 days.

Software supply chain:

  • Composer dependencies checked regularly (composer audit).
  • No unnecessary third-party JavaScript on to.klatsa.nl.

Annex C — Sub-processors (as at the effective date)

Sub-processor Purpose Location Legal basis for transfer
OVHcloud (OVH SAS) Hosting (dedicated servers) of klatsa.nl, app.klatsa.nl and to.klatsa.nl, including backups and the self-hosted error monitoring (Sentry) Germany (Frankfurt), backups in France (EU) EU/EEA, no transfer outside the EEA. OVH DPA version 17.10.2025, part of the OVH terms.
Postmark (ActiveCampaign LLC) Transactional email (account, invoice and notification emails) United States EU standard contractual clauses, Postmark DPA as part of the terms
proxycheck.io Checking the IP address of a click for VPN, proxy, Tor and data centre traffic (fraud detection) United Kingdom; requests from Europe are answered by servers in Europe UK adequacy decision (Article 45 GDPR)
Front (FrontApp, Inc.) Shared mailbox and customer service, including requests to privacy@klatsa.nl United States EU-U.S. Data Privacy Framework and EU standard contractual clauses, Front DPA as part of the terms
Google Ireland Ltd. — Google Analytics 4 Anonymous usage statistics on klatsa.nl (only with the visitor's consent, IP anonymisation enabled, no advertising link) Ireland (EU); engineering access from the US EU standard contractual clauses, Google Ads Data Processing Terms as part of the terms
Jortt (Jortt B.V.) Bookkeeping / invoice export Netherlands (EU) EU/EEA, no transfer. Jortt DPA as part of the terms
ABN AMRO Bank N.V. Payment of commissions Netherlands (EU) EU/EEA, no transfer (statutory banking relationship)

Klatsa keeps this list up to date and publishes changes at https://klatsa.nl/en/data-processing-agreement.


Contact

For questions about this DPA or about the processing of personal data:

Jaspers Media — Klatsa Network Email: privacy@klatsa.nl Address: Westerweg 16, 1906 ED Limmen, the Netherlands Chamber of Commerce: 02093573 · VAT: NL002155155B89

Version 1.2 · Effective date 18 September 2026.
Questions? legal@klatsa.nl