Data processing agreement
Last updated 21 August 2026
This covers the personal data you put into Advoro about your leads, your customers and your partners. You are the controller: you decide who to track and why. Ascendz is the processor: we hold it and act on your instructions.
Data about you, meaning your own sign-in and your staff’s, is covered by the privacy policy instead, because there we are the controller.
What we do with it
Match a sale to the partner who introduced the buyer. Work out what is owed, hold it for your refund window, clear it, claw it back on a refund. Record what a non-cash reward promised and whether it was handed over. Group what is owed into a payout and request an invoice. Send transactional email to your partners and referred customers on your behalf. Show you, and each partner, what they have earned.
Advoro never moves money. A partner invoices you and you pay them directly.
What we hold
Leads: email, first name, last name, phone, whether they consented to marketing and the exact wording they agreed to, where they came from, and a salted hash of their IP address.
Customers: email, name, and their id in your payment provider.
Partners: email, name, referral code, commission terms, payout email, VAT details, company details, invoices, and their acceptance of your partner terms with a salted hash of their IP.
Traffic: salted hashes of IP address and browser, the referring page and the landing path.
Never: card numbers, bank details or any payment instrument. No special category data. No children’s data. No profiling and no automated decisions with legal or similarly significant effects.
Who else touches it
The full list is at sub-processors. We tell you before it changes, with a reasonable period to object.
How it is protected
Specifics rather than reassurance, because “industry standard” is not a measure.
- Every table enforces row level security, and related rows carry composite keys so a row in your workspace cannot reference another business’s partner, programme, lead or customer even by accident.
- Payment provider credentials are encrypted with AES-256-GCM and the key is held outside the database, so holding a copy of the database is not holding the credentials.
- IP addresses and browsers are hashed with a keyed HMAC and never stored raw. API keys are stored as a hash and shown once.
- The commission ledger is append only. It cannot be updated, deleted or truncated, and that is enforced by the database rather than by the application.
- Every Ascendz staff member with cross-account access must use a second factor, and needs a fresh code before anything that changes what you have. Every support session against your workspace is written into your own audit log, so you can see that somebody looked and when.
- Files your partners download are private and served by short-lived signed links. Uploads are checked by reading the file’s actual bytes rather than trusting what it was called.
- Every password is checked against known breaches. A second factor is available to everybody.
Each of those is covered by a test that fails if the protection is removed, so they cannot quietly stop being true.
How long we keep it
- Email bodies and merge fields: 30 days, then scrubbed. The record that it was sent stays.
- Raw payment provider payloads: 14 days, then emptied.
- Delivered webhook attempts: 30 days, then deleted.
- Click identifiers: the hashed IP, browser and referring page on a click are erased once no cookie window at your business could still credit a partner from it, which is your longest window plus thirty days. The click itself stays, so your figures do not change.
- Leads: kept until you erase them or close your workspace, unless you set a limit in Settings, Security, in which case leads that never bought and are not waiting on a reward are erased once past it. A lead with a sale behind it is never erased this way.
- Customers: until you erase them or close your workspace.
- The commission ledger: for as long as you need it for your accounts. It is append only and holds no contact details.
Helping you answer people
- Access or portability: export your leads, sales, partners and payouts as CSV, whenever you like.
- Erasure: erase any lead or customer from Leads and sales. Their details go; any sale they produced keeps its amount and stops pointing at anybody, because you need that figure for your accounts and it says nothing about who bought.
- Correction: every field is editable.
- Consent: we record the flag and the exact wording each lead agreed to, so you can show what was said.
If something goes wrong
We tell you without undue delay, with what we know and what we do not, rather than waiting for a complete picture. As a processor we do not report to the ICO on your behalf: that is your decision as controller, and we give you what you need to make it.
Ending it
Export what you need, then close your workspace from Settings, Security. That deletes everything in it: programmes, partners, leads, customers, sales, the ledger, payouts, assets and emails. Backups age out on our hosting providers’ own schedules.
Your partners keep their own accounts. A partner works with several businesses through one login, and that identity is not any one business’s to delete.
Contact
clientsupport@ascendz.co