Terms & policies

Data Processing Addendum

Effective July 14, 2026

This Data Processing Addendum ("DPA") supplements the OfferLab Terms of Service (the "Terms") entered into between Etison LLC d/b/a OfferLab ("OfferLab," "we," "our," or "us") and the person or entity holding an OfferLab account (the "Subscriber," "you," or "your"). This DPA describes how the parties will each handle Personal Data processed in connection with the OfferLab Platform, and forms part of the Agreement between you and OfferLab. Capitalized terms not defined in this DPA have the meanings given in the Terms or in the Glossary below.

By creating an OfferLab account or continuing to use the OfferLab Platform after the effective date above, you agree to the terms of this DPA on behalf of yourself and your business.

1. Definitions

"CCPA" means the California Consumer Privacy Act of 2018 as amended (including by the California Privacy Rights Act), together with its implementing regulations.

"Controller" means the entity that determines the purposes and means of the Processing of Personal Data, and includes equivalent terms under applicable Data Protection Laws (such as "business" under the CCPA).

"Data Protection Laws" means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including, as applicable, the GDPR, the UK GDPR and UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, the LGPD, and the CCPA and other U.S. state privacy laws.

"Data Subject" means the identified or identifiable natural person to whom Personal Data relates.

"End User" means a natural person whose Personal Data is collected through your use of the OfferLab Platform, including customers who visit your offer pages, purchase a product or bundle through OfferLab's checkout, or otherwise interact with pages, forms, or embeds you operate through the OfferLab Platform.

"End User Personal Data" means Personal Data relating to End Users that is Processed on OfferLab Platform systems on your behalf.

"GDPR" means Regulation (EU) 2016/679 (the General Data Protection Regulation), as amended or replaced from time to time.

"LGPD" means the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados), as amended.

"OfferLab Platform" means the websites, applications, checkout, and related tools and services made available by OfferLab, including offer pages, bundle pages, embeds, and associated dashboards.

"Partner Seller" means another OfferLab user whose products are included, with your approval, in a bundle or offer that you sell, or who sells a bundle or offer that includes your products.

"Personal Data" means any information relating to a Data Subject that is protected as "personal data," "personal information," or an equivalent term under applicable Data Protection Laws.

"Process" and "Processing" have the meanings given under applicable Data Protection Laws, and include any operation performed on Personal Data such as collection, storage, use, disclosure, and deletion.

"Processor" means the entity that Processes Personal Data on behalf of a Controller, and includes equivalent terms under applicable Data Protection Laws (such as "service provider" under the CCPA).

"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision (EU) 2021/914 of 4 June 2021, as completed under this DPA.

"Subscriber Personal Data" means Personal Data relating to you and your personnel that OfferLab collects in connection with your subscription and use of the OfferLab Platform, such as name, email address, and payment information.

"Subprocessor" means a third party engaged by OfferLab to Process End User Personal Data on OfferLab's behalf in connection with the OfferLab Platform.

"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0), as revised from time to time.

2. Scope and purpose

2.1.Subscriber personal data. OfferLab is the Controller of Subscriber Personal Data. We collect and Process Subscriber Personal Data to create and administer your account, provide and improve the OfferLab Platform, process subscription and payout transactions, and communicate with you, as further described in our Privacy Policy. With respect to Subscriber Personal Data, you are the Data Subject.

2.2.End user personal data. When you sell products, publish offer pages or bundles, or embed OfferLab's checkout, you collect Personal Data from your End Users. With respect to End User Personal Data, you are the Controller and OfferLab is your Processor to the extent End User Personal Data is stored or otherwise Processed on OfferLab Platform systems on your behalf.

2.3.Co-selling and partner sellers. The OfferLab Platform enables multiple Sellers to sell together in a single order. Where an End User purchases a bundle that includes products from one or more Partner Sellers, you instruct OfferLab to disclose to each Partner Seller the portion of the order information (such as the End User's name, shipping address, contact details, and the items purchased from that Partner Seller) necessary for that Partner Seller to fulfill, ship, support, and account for its part of the order. Each Partner Seller receives that information as an independent Controller and is responsible for its own compliance with Data Protection Laws, including providing any required privacy notices to End Users.

2.4.Purpose and compliance. This DPA sets out the parties' respective obligations with regard to both Subscriber Personal Data and End User Personal Data, so that each party can meet its obligations under applicable Data Protection Laws.

3. Controller obligations

3.1.Independent controllers. With respect to Subscriber Personal Data, the parties Process Personal Data as independent Controllers. Each party is separately responsible for complying with the obligations that apply to it as a Controller under applicable Data Protection Laws. You will indemnify and hold harmless OfferLab with respect to any investigation or claim by a supervisory authority or Data Subject arising out of your Processing of Personal Data as a Controller, except to the extent caused by OfferLab's breach of this DPA.

3.2.Lawful basis and notices. Each party will maintain a lawful basis for its Processing as a Controller and will provide Data Subjects with any legally required privacy notices. Your use of the OfferLab Platform to collect End User Personal Data must comply with the Terms of Service, our Acceptable Use Policy, and applicable Data Protection Laws, including any consent, notice, and disclosure requirements that apply to your marketing and sales activities.

3.3.International transfers of subscriber personal data. You acknowledge that OfferLab and its service providers maintain operations in the United States and other jurisdictions that may not provide the same level of data protection as your home jurisdiction. Where Subscriber Personal Data relating to Data Subjects located in the European Economic Area, the United Kingdom, or Switzerland is transferred to OfferLab in the United States, the parties enter into the Standard Contractual Clauses, Module One (Controller to Controller), which are incorporated into this DPA by reference and completed as set out in the Standard Contractual Clauses section and Annex I and Annex II below.

4. Processor obligations

4.1.Appropriate measures. Where OfferLab Processes End User Personal Data as your Processor, OfferLab will implement appropriate technical and organizational measures designed to meet the requirements of applicable Data Protection Laws and to protect End User Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Annex II.

4.2.Processing instructions. OfferLab will Process End User Personal Data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law (in which case OfferLab will inform you of that legal requirement before Processing, unless the law prohibits it). The Agreement, this DPA, and your configuration and use of the OfferLab Platform (including your approval of Partner Sellers and publication of offers) constitute your documented instructions.

4.3.Confidentiality. OfferLab will ensure that persons authorized to Process End User Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4.4.Appointment of subprocessors. You provide OfferLab with a general authorization to engage Subprocessors to deliver the OfferLab Platform. OfferLab maintains a current list of its Subprocessors, including their names and locations, and will provide the list to you on request at compliance@offerlab.com. OfferLab will notify you in writing at least ten (10) days before adding or replacing a Subprocessor. If you reasonably object to the change on data protection grounds and the parties cannot resolve the objection, you may terminate the affected services and this DPA. OfferLab will impose data protection obligations on each Subprocessor by written contract that are substantially the same as those in this DPA, and OfferLab remains fully responsible to you for each Subprocessor's performance.

4.5.Assistance. Taking into account the nature of the Processing and the information available to OfferLab, OfferLab will reasonably assist you in fulfilling your obligations under applicable Data Protection Laws, including your obligations to respond to Data Subject requests, to secure Processing, to notify supervisory authorities and Data Subjects of Personal Data breaches, and to carry out data protection impact assessments and prior consultations.

4.6.End user requests. OfferLab will promptly notify you if it receives a request from an End User to exercise rights under applicable Data Protection Laws with respect to End User Personal Data, and will not respond to the request other than to direct the End User to you, unless you authorize otherwise or applicable law requires a response. OfferLab will reasonably cooperate with you in fulfilling such requests, and you will bear OfferLab's reasonable costs of doing so.

4.7.Breach notification. OfferLab will notify you without undue delay after becoming aware of a Personal Data breach affecting End User Personal Data, and will provide the information reasonably required for you to meet your breach notification obligations (including, where available, the information described in Article 33(3) of the GDPR) as it becomes available.

4.8.Deletion and return. Upon termination of the Agreement, or earlier at your written request, OfferLab will delete or return End User Personal Data, at your choice, unless applicable law requires or permits continued retention (for example, records retained for tax, accounting, or fraud prevention purposes), in which case OfferLab will continue to protect the retained data in accordance with this DPA and will Process it only as required by applicable law.

4.9.Audits and information. OfferLab will make available to you the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by you or an independent auditor mandated by you, at reasonable intervals, on reasonable prior written notice, and subject to reasonable confidentiality obligations. OfferLab may satisfy audit requests by providing summaries of relevant third-party audit reports or certifications.

4.10.International transfers of end user personal data. End User Personal Data is transferred to and Processed in the United States. Where End User Personal Data relating to Data Subjects located in the European Economic Area, the United Kingdom, or Switzerland is transferred to OfferLab in the United States, the parties enter into the Standard Contractual Clauses, Module Two (Controller to Processor), which are incorporated into this DPA by reference and completed as set out in the Standard Contractual Clauses section and Annex I and Annex II below.

4.11.No sale of personal data. The disclosure of End User Personal Data to OfferLab is not a sale or sharing of personal information. OfferLab will not sell or share End User Personal Data, will not retain, use, or disclose End User Personal Data for any purpose other than providing the services under the Agreement (including as permitted for service providers under the CCPA), and will not combine End User Personal Data with Personal Data it controls or receives from third parties, except as instructed by you or permitted by applicable Data Protection Laws. OfferLab certifies that it understands and will comply with the restrictions in this section.

5. Standard contractual clauses

5.1.Incorporation. Where this DPA provides for the Standard Contractual Clauses to apply, they are incorporated into this DPA by reference and completed as follows: (a) for Subscriber Personal Data, Module One (Controller to Controller) applies; (b) for End User Personal Data, Module Two (Controller to Processor) applies; (c) in Clause 7, the optional docking clause does not apply; (d) in Clause 9, Option 2 (general written authorization) applies with the notice period stated in this DPA; (e) in Clause 11, the optional language on independent dispute resolution does not apply; (f) in Clauses 17 and 18, the governing law and forum are the law and courts of the Netherlands; and (g) Annex I and Annex II to the SCCs are as set out in the Annexes to this DPA. You are the data exporter and OfferLab is the data importer.

5.2.Uk transfers. For transfers of Personal Data subject to the UK GDPR, the SCCs apply as amended by the UK Addendum, which is incorporated by reference. The information required by Part 1 of the UK Addendum is as set out in the Annexes to this DPA, and either party may end the UK Addendum as set out in Section 19 of the UK Addendum.

5.3.Swiss transfers. For transfers of Personal Data subject to the Swiss Federal Act on Data Protection, the SCCs apply with the adaptations required by the Swiss Federal Data Protection and Information Commissioner, including that references to the GDPR are understood as references to the Swiss Federal Act on Data Protection and that the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner.

6. Precedence and binding effect

If there is a conflict between this DPA and the Terms of Service or the Privacy Policy with respect to the subject matter of this DPA, this DPA controls to the extent of the conflict, and the Standard Contractual Clauses control over this DPA to the extent of any conflict with them. Your continued use of the OfferLab Platform constitutes your affirmative agreement to be bound by this DPA.

Appendix: Annex I (parties and description of transfer)

A. list of parties

Data exporter: the Subscriber, as identified in the OfferLab account records. Activities: use of the OfferLab Platform to sell products and collect End User Personal Data. Role: Controller.

Data importer: Etison LLC d/b/a OfferLab, 225 Reformation Parkway, Suite 204, Canton, GA 30114, United States. Contact: compliance@offerlab.com. Activities: providing the OfferLab Platform. Role: Controller with respect to Subscriber Personal Data (Module One); Processor with respect to End User Personal Data (Module Two).

B. description of transfer

Categories of Data Subjects: the Subscriber and its personnel (Module One); End Users, including customers and visitors of the Subscriber's offer pages, bundles, and embeds (Module Two).

Categories of Personal Data: identification and contact data (such as name, email address, phone number, billing and shipping address), transaction and order data (such as items purchased, order value, and payment status), account data, device and usage data (such as IP address and operating system), and communications with support.

Sensitive data: none intended. The OfferLab Platform is not designed for the collection of special categories of data, and the Acceptable Use Policy restricts their collection.

Frequency of transfer: continuous, for the duration of the Agreement.

Nature and purpose of the Processing: hosting and operation of offer pages, bundles, and checkout; order processing and routing (including disclosure of order information to Partner Sellers at the Subscriber's instruction); payment facilitation through the parties' payment processor; media and content generation; analytics; and customer support, in each case to perform the services described in the Terms of Service.

Retention period: for the duration of the Agreement and thereafter for up to two (2) years after the Subscriber ceases to be a customer, unless a longer period is required by applicable law.

Transfers to Subprocessors: OfferLab may transfer Personal Data to its Subprocessors for the subject matter, nature, and duration described above.

C. competent supervisory authority

The competent supervisory authority will be determined in accordance with Clause 13 of the SCCs, based on the circumstances of the relevant Data Subjects.

Appendix: Annex II (technical and organizational measures)

Encryption

Personal Data is encrypted at rest on OfferLab's systems and in transit between End Users, the OfferLab Platform, and OfferLab's infrastructure using current industry-standard protocols.

Payment security

Card payment processing is performed by Stripe, a PCI DSS Level 1 certified payment processor. OfferLab does not store full payment card numbers on its own systems.

Infrastructure and availability

The OfferLab Platform is hosted on enterprise cloud infrastructure that maintains physical and environmental security controls, with redundancy and continuous backups designed to prevent data loss and enable restoration following an incident.

Access control

Access to systems Processing Personal Data is limited to authorized personnel on a need-to-know basis, using dedicated user accounts, strong password requirements, automatic session timeouts, lockout on repeated failed logins, and centralized logging of access activity. Multi-factor authentication is required for personnel with access to systems containing Personal Data. Access lists are reviewed regularly.

Security program

OfferLab maintains formal information security and data protection policies covering the collection, storage, access, Processing, and transmission of Personal Data, conducts periodic security reviews of its facilities, networks, and systems, and maintains an incident response plan with triage and escalation procedures for security incidents and software defects.

Assistance measures

The measures above, together with the OfferLab Platform's account tools and OfferLab's support processes, are the measures by which OfferLab provides assistance to the data exporter for Data Subject requests and other Controller obligations.