Back to Home

Data Processing Agreement

Effective date: January 1, 2026

Not a signed contract until accepted in a final published form or countersigned order.

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Ali Media, the company that operates Creatornet ("Creatornet" or "Processor") and the Brand that uses Creatornet ("Controller").

1. Roles

For Brand personal data processed to provide Creatornet on the Brand's instructions, Creatornet is the processor and the Brand is the controller. Where Creatornet processes personal data for its own purposes, such as account, billing and website data and the commission and payout records it keeps, it is the controller and the Privacy Policy applies instead of this DPA.

2. Subject Matter and Duration

Processor processes personal data to provide Creatornet features the Brand enables, including store integrations, attribution, commission calculation, Meta connection features where used, hosting, security and support. Processing continues for the term of the Brand's use of Creatornet and until deletion or return under this DPA.

3. Nature and Purpose

Processing includes collection through connected store integrations, Processor's attribution technology and conversion events the Brand sends from its own systems, together with storage, use for attribution and reporting, erasure or anonymization and disclosure to the sub-processors named in the Sub-processor List.

The purpose is to provide the Services under the Terms of Service and the Brand's documented instructions, including configuration in the product and the Shopify and Meta grants.

4. Types of Personal Data and Data Subjects

Data subjects may include the Brand's staff users; creators collaborating with the Brand; and the Brand's visitors, customers and clients whose data reaches Creatornet through the features the Brand enables.

Personal data categories may include store, customer, visitor and session identifiers, order and commercial data needed for attribution, a masked IP and a country code, browser and device information, campaign and click parameters, credentials for connected platforms, creator account data linked to the Brand's campaigns, a coded identifier derived from an email address or phone number the Brand sends from its own site and a marketing consent flag.

Processor removes buyer contact fields before storage and retains customer identifiers. Fields that are not removed are retained as the store platform sends them. Some of those fields can identify a buyer depending on how the store is configured. Creatornet is not intended for the processing of special category or criminal-offense personal data. Controller will not instruct Processor to process it.

5. Controller Instructions

Processor will process personal data only on documented instructions from Controller, including the Terms of Service, product configuration and platform-required compliance webhooks, unless EEA, UK or Swiss law requires otherwise (in which case Processor informs Controller before that processing unless legally prohibited). Processor will also inform Controller without undue delay if, in its opinion, an instruction infringes the GDPR or other applicable data-protection law.

Controller is responsible for the lawfulness of the personal data it provides and of the instructions it gives. That includes having a legal basis for the processing and giving data subjects the information the law requires.

6. Confidentiality

Processor ensures that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. That commitment survives the end of their engagement.

7. Security

Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including access control, authentication, TLS in transit, provider encryption at rest, minimization of store order data, IP masking on store events and rate limiting.

8. Sub-processors

Controller authorizes Processor to use the sub-processors named in the Sub-processor List, as that list is updated from time to time. Processor will impose data-protection obligations no less protective than this DPA and remains responsible to Controller for each sub-processor's performance.

Processor will update the Sub-processor List and tell Controller by email or a prominent notice in the Services before a new sub-processor begins processing Controller personal data. Controller may object on reasonable data-protection grounds. The parties will then work in good faith to address the objection. If they cannot, Controller may stop using the affected Services and terminate this DPA as it applies to them.

9. International Transfers

Where Processor transfers personal data from the EEA, the UK or Switzerland to a third country, Processor will ensure an appropriate safeguard applies, such as the EU Standard Contractual Clauses or, for certified vendors, the EU-US Data Privacy Framework.

10. Assistance with Data-Subject Rights

Taking into account the nature of processing and the information available to it, Processor will assist Controller by appropriate technical and organizational measures with Controller's obligation to respond to data-subject requests and with Controller's duties under GDPR Articles 32 to 36, including security, personal data breach notification, data protection impact assessments and prior consultation.

Where the Brand's store runs on Shopify, its GDPR webhooks are a primary assistance path for store customer access and erasure requests. Erasure requests arriving that way are actioned automatically. For any other store, Controller may send requests of either kind to privacy@creatornet.io.

11. Breach Notification

Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Controller personal data and will provide information reasonably available to help Controller meet legal notification duties. Notifying Controller of a personal data breach or responding to one is not an admission of fault or liability.

12. Deletion and Return

On termination or Controller's written request, Processor will, at Controller's choice, return Controller personal data or delete or anonymize it in Creatornet systems within a reasonable period. Retention continues where the law requires it. Data that remains in a backup is isolated from ordinary processing and is removed when that backup is replaced. Where the store runs on Shopify, Shopify's shop and customer redaction webhooks are followed. For any other store, deletion follows Controller's written request. Where a user deletes the Creatornet connection through Meta's data-deletion process, the Meta ad data imported through that connection is deleted, including where the requester is not the Controller. Raw webhook payloads are retained for 30 days.

13. California

Where Controller personal data is subject to the CCPA, Controller is a business and Processor is a service provider. Processor will process that data only for the purposes described in this DPA, will not sell or share it, will not retain, use or disclose it outside its business relationship with Controller and will not combine it with personal data from other sources, in each case except as the CCPA permits. Processor will notify Controller if it determines it can no longer meet its obligations under the CCPA or this DPA.

14. Audits

Processor will make available information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Controller or an auditor Controller mandates, that are reasonable in scope, frequency and confidentiality, on reasonable notice, no more than once per year unless a supervisory authority or breach requires more. Processor may answer an audit request with the documentation and reports it holds where those address the request.

15. Liability

Liability under this DPA follows the liability terms in the Terms of Service, except where mandatory data-protection law requires otherwise. Liability to data subjects is allocated by GDPR Article 82.

16. Governing Law

Norwegian law governs this DPA. Disputes under it follow the venue in the Terms of Service.

17. Contact Us

For questions, concerns or notices under this DPA, contact:

Ali Media
VAT number NO 835 517 632 MVA
Moraveien 29
1542 Vestby
Norway

Email: privacy@creatornet.io