ViaLink Data Processing Agreement
Effective Date: September 1, 2026
Preamble
This Data Processing Agreement (“DPA”) is entered into by and between Linpert, Inc., a Delaware corporation (“Company”), and the customer that has agreed to the ViaLink Terms of Service or executed an order form referencing the Terms of Service (“Customer”), and forms part of and is incorporated into the agreement between Company and Customer governing Customer’s use of the ViaLink service (the “Agreement”).
This DPA applies to the extent that Company processes Personal Data on behalf of Customer in connection with the Service, where such processing is subject to Data Protection Laws. Capitalized terms not defined in this DPA have the meanings given to them in the Agreement.
1. Definitions
For purposes of this DPA:
- “Data Protection Laws” means all applicable laws and regulations governing the processing of Personal Data, including, as applicable, the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, and the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (“CCPA”).
- “Personal Data,” “Processing,” “Controller,” “Processor,” and “Data Subject” have the meanings given in the GDPR, and “Business,” “Service Provider,” “Sell,” and “Share” have the meanings given in the CCPA, in each case as applicable to the processing at issue.
- “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries pursuant to the GDPR, as approved by the European Commission, and, for transfers subject to the UK GDPR, the UK International Data Transfer Addendum.
- “Security Incident” means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data processed by Company under this DPA.
- “Subprocessor” means a third party engaged by Company to process Personal Data on behalf of Customer in connection with the Service.
2. Roles of the Parties
- As between Company and Customer, Customer is the Controller (or Business, as applicable) and Company is the Processor (or Service Provider, as applicable) of Personal Data processed under this DPA.
- Company will process Personal Data only on documented instructions from Customer, which instructions are constituted by the Agreement, any applicable order form, Customer’s configuration and use of the Service, and this DPA, unless otherwise required by applicable law, in which case Company will inform Customer of that legal requirement before processing, unless the law prohibits such notice.
3. Scope and Details of Processing
The subject matter, duration, nature and purpose of processing, categories of Data Subjects, and categories of Personal Data are described in Annex 1 to this DPA.
4. Company Personnel
- Company will ensure that personnel authorized to process Personal Data are subject to a binding written obligation of confidentiality and receive appropriate training on the handling of Personal Data.
- Company will limit access to Personal Data to those personnel who require such access to perform the Service.
5. Subprocessors
- Customer authorizes Company to engage the Subprocessors listed at vialink.app/subprocessors (the “Subprocessor List”) as of the effective date of this DPA, and to engage additional or replacement Subprocessors in accordance with this Article.
- Before engaging a new Subprocessor, Company will update the Subprocessor List and provide notice to Customer, through the Subprocessor List page or by email, at least ten (10) days in advance.
- If Customer has a reasonable data-protection-related objection to a new Subprocessor, Customer may notify Company within that ten (10) day period, and the parties will work together in good faith to resolve the objection. If the parties are unable to reach a resolution, Customer’s sole and exclusive remedy is to terminate the portion of the Service that cannot be provided without the objected-to Subprocessor, without penalty.
- Company remains liable for the acts and omissions of its Subprocessors to the same extent Company would be liable if performing the services of each Subprocessor directly, and will impose data protection obligations on each Subprocessor that are no less protective than those set out in this DPA.
6. Security Measures
- Company will implement and maintain appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, including the measures described in Annex 3 to this DPA.
- Company will not materially decrease the overall security of the Service during the term of the Agreement.
7. Security Incident Notification
- Company will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident affecting Customer’s Personal Data.
- Such notice will describe, to the extent then known, the nature of the Security Incident, the categories and approximate number of Data Subjects and records affected, and the measures taken or proposed to address the Security Incident. Company will provide reasonable cooperation to Customer in investigating and remediating the Security Incident.
8. Assistance with Data Subject Requests
- Taking into account the nature of the processing, Company will provide reasonable assistance to Customer, through the Service’s self-service functionality or otherwise, to enable Customer to respond to requests from Data Subjects to exercise their rights under applicable Data Protection Laws.
- If Company receives a request directly from a Data Subject concerning Personal Data processed on Customer’s behalf, Company will not respond to the request (other than to acknowledge receipt) and will forward it to Customer without undue delay, unless legally prohibited from doing so.
9. Data Protection Impact Assessments
Company will provide reasonably requested information to assist Customer in connection with any data protection impact assessment or prior consultation with a supervisory authority that Customer reasonably considers necessary. Company may charge Customer for time spent on requests that require extraordinary effort.
10. International Data Transfers
- Where Company processes Personal Data originating from the European Economic Area, the United Kingdom, or Switzerland in a country that has not been recognized as providing an adequate level of data protection, the transfer will be governed by the Standard Contractual Clauses (Module Two: Controller to Processor), which are incorporated into this DPA by reference, with Customer as “data exporter” and Company as “data importer.”
- For transfers subject to the UK GDPR, the parties incorporate the UK International Data Transfer Addendum to the Standard Contractual Clauses in place of, or in addition to, the EU Standard Contractual Clauses, as applicable.
11. CCPA / CPRA Terms
- With respect to Personal Information (as defined in the CCPA) that Company processes on Customer’s behalf, Customer is a “Business” and Company is a “Service Provider,” and Company receives Personal Information solely to perform the Service on Customer’s behalf (a “Business Purpose”).
- Company certifies that it understands the restrictions in this Article and agrees that it will not:
- sell or share Personal Information;
- retain, use, or disclose Personal Information for any purpose other than the Business Purpose specified in the Agreement, or as otherwise permitted by the CCPA;
- retain, use, or disclose Personal Information outside of the direct business relationship between Company and Customer; or
- combine Personal Information received from Customer with personal information Company receives from or on behalf of another person, except as permitted by the CCPA.
12. Audit Rights
- No more than once in any twelve (12) month period, or following a Security Incident, or where required by a supervisory authority, Customer may request information reasonably necessary to demonstrate Company’s compliance with this DPA.
- Company may satisfy such a request by providing a summary of its most recent third-party audit report (such as a SOC 2 report) or a completed security questionnaire. If such materials are not reasonably sufficient to demonstrate compliance, Company will permit an on-site audit during normal business hours, upon at least thirty (30) days’ prior written notice, at Customer’s expense, subject to reasonable confidentiality protections and without disrupting Company’s business operations.
13. Return or Deletion of Personal Data
Upon termination or expiration of the Agreement, Company will, at Customer’s election, delete or return all Personal Data processed on Customer’s behalf, except to the extent applicable law requires Company to retain some or all of the Personal Data, in which case Company will continue to protect that Personal Data in accordance with this DPA and the Company’s data retention policy.
14. Liability; Order of Precedence; Governing Law
- Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
- This DPA forms part of the Agreement. In the event of a conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA controls; in all other respects, the Agreement controls.
- This DPA is governed by the laws of the State of Delaware, consistent with the governing law provision of the Agreement.
- This DPA remains in effect for as long as Company processes Personal Data on Customer’s behalf under the Agreement.
Annex 1 — Details of Processing
- Subject matter: Provision of the ViaLink deep link creation and management, click redirection, deferred deep linking, event tracking, and attribution analytics Service described in the Agreement.
- Duration: For the term of the Agreement, and thereafter in accordance with Article 13 of this DPA and the retention periods described in Company’s Privacy Policy.
- Nature and purpose of processing: Processing necessary to provide, maintain, and improve the Service, including deep link creation and management, click redirection and platform-specific routing, deferred deep linking (fingerprint-based matching), and click and event analytics.
- Categories of Data Subjects: End users of Customer’s mobile applications and websites who interact with Customer’s deep links, and, where applicable, Customer’s own personnel who access the Service dashboard.
- Categories of Personal Data: Device and click data (IP address, User-Agent, referrer, hashed device fingerprint), application usage and event data, and account information of Customer’s authorized users (name, email address).
- Special categories of data: Company does not intentionally collect or process special categories of personal data (such as health, biometric, or genetic data, or data revealing racial or ethnic origin, religious beliefs, or trade union membership) through the Service.
Annex 2 — Subprocessors
As of the effective date of this DPA, Company engages the following Subprocessors. The current list, including any updates made in accordance with Article 5, is maintained at vialink.app/subprocessors.
Annex 3 — Security Measures
Company maintains the following technical and organizational security measures:
- Encryption of passwords using the bcrypt hash function
- Encryption of data in transit using TLS 1.3
- Access controls restricting access to Personal Data to personnel who require it to perform their duties
- Intrusion detection systems
- Retention of access logs for at least one (1) year