shopmycode

Legal

Data processing addendum

Effective 19 September 2026 · Part of the Terms of service for every brand ("Customer") using Shopmycode

Brands decide what their campaigns collect and why; Shopmycode processes that data on their instructions. This addendum sets out the processor obligations under the GDPR (Art. 28), the UK GDPR, the CCPA/CPRA (service-provider terms) and India's DPDP Act (data processor terms). It applies automatically; no signature is needed. A signed copy is available on request from legal@ttlmedia.in.

1. Roles and scope

For Customer Data — personal data of visitors, sign-ups and buyers that the Customer's campaigns, pages and snippet report to Shopmycode — the Customer is the controller (data fiduciary) and TTL Media Private Limited ("Processor") is the processor. For its own account holders and for the counted open of a link, Shopmycode is an independent controller as described in the Privacy policy; that data is outside this addendum.

2. Details of the processing

Subject matterRunning the Customer's referral and affiliate campaigns on Shopmycode
DurationFor as long as the Customer has an account, plus the deletion period in §9
Nature and purposeCounting opens, page presence and results; attributing them to links and marketers; showing live numbers and journeys; calculating and settling rewards; fraud prevention
Data subjectsVisitors to the Customer's links and pages; people who sign up or buy through them
Categories of dataTime of open, country/region/city, device family, browser, language, referrer, campaign tag, visitor and device ids (where allowed), keyed IP hash, page path and title on the Customer's site, time on page, goal name and page address, and any user id the Customer chooses to send. No special-category data is expected; the Customer must not send any.

3. Customer's instructions and responsibilities

4. Processor's obligations

5. Sub-processors

The Customer authorises the sub-processors listed in the Privacy policy §5 (currently Amazon Web Services in Mumbai for hosting and email; PayU and Easebuzz for payments; Meta (WhatsApp) for sign-in codes by phone; Apify and Google for profile look-ups a user requests). The Processor flows down equivalent data-protection obligations to each and remains liable for them. Changes are announced on that page and by email to the brand's primary admin at least 30 days in advance; the Customer may object on reasonable data-protection grounds within that period, in which case the parties will look for a solution and, failing one, the Customer may end the affected service without penalty.

6. International transfers

Customer Data is stored in India. Where the Customer or its data subjects are in the EU/EEA, the UK or Switzerland, transfers to the Processor are made under the EU Standard Contractual Clauses (Module 2, controller to processor), the UK International Data Transfer Addendum and the Swiss amendments, which are incorporated into this addendum by reference and provided in full on request. The limited-tracking path for visitors from those regions (no identifiers, no device characteristics) is the Processor's supplementary measure.

7. Security measures

8. Audits

Once a year, or after a security incident, the Customer may request a written description of the Processor's controls and the results of any recent independent review. If that is not enough to satisfy a legal duty, the Customer may audit on 30 days' notice, during business hours, under confidentiality, at its own cost, without disrupting the service.

9. Deletion and return

When a brand account closes, the Customer may export its campaign data from the app beforehand. Customer Data is deleted within 30 days of closure, except what must be kept for settlement, tax and accounting (8 years, kept only for that purpose) and raw events already within their 13-month expiry.

10. Personal-data breaches

The Processor notifies the Customer's primary admin without undue delay, and in any case within 48 hours of becoming aware of a breach affecting Customer Data, with what is known at the time, and keeps the Customer informed so it can meet its own 72-hour (GDPR/UK) and DPDP notification duties.

11. California (CCPA/CPRA) service-provider terms

The Processor is a service provider. It will not sell or share Customer Data, retain, use or disclose it for any purpose other than the business purposes in this addendum or outside the direct business relationship with the Customer, or combine it with personal data from other sources except as the CPRA permits. The Processor will notify the Customer if it can no longer meet these obligations; the Customer may then stop and remedy unauthorised use. The Processor certifies that it understands these restrictions.

12. India (DPDP Act) processor terms

The Processor processes Customer Data only under this contract, implements the security safeguards above, notifies the Customer of breaches as in §10, and deletes the data as in §9 unless retention is required by law. The Customer, as data fiduciary, remains responsible for notices, consent and grievance handling towards its data principals; the Processor assists as in §4.

13. Liability and precedence

Liability under this addendum is subject to the limitations in the Terms of service. If this addendum conflicts with the Terms, the addendum prevails for data protection; if the Standard Contractual Clauses conflict with either, the Clauses prevail.

TTL Media Private Limited · Office No. 205, Conclave, CTS No. 1703 B, Final Plot No. 100, Bhambhurda, Narveer Tanaji Wadi, Shivajinagar, Pune, Maharashtra 411005, India · legal@ttlmedia.in