Legal

GDPR & Data Processing Agreement

Our GDPR and UAE PDPL commitments, your data-protection rights, and the Data Processing Agreement for customers.

Last updated: 27 June 2026  ·  Version 1.0

This page has two parts. Part A is our GDPR and UAE PDPL statement, explaining our commitments and your rights. Part B is the Data Processing Agreement (“DPA”) that applies whenever FlowTracker processes personal data on behalf of a customer (the controller). The DPA forms part of, and is incorporated into, our Terms & Conditions.

Part A — GDPR & UAE PDPL Statement

A1.Our commitment

Delien Media FZE is committed to processing personal data in accordance with the EU GDPR, the UK GDPR, the UAE Federal Decree-Law No. 45 of 2021 (PDPL) and other applicable privacy laws. We apply the principles of lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. We maintain records of processing activities and conduct data protection impact assessments (DPIAs) for high-risk processing such as large-scale tracking, profiling and cross-device matching.

A2.Lawful bases

We rely on the lawful bases set out in our Privacy Policy. For advertising-related tracking, fingerprinting, profiling and conversion data sharing, the lawful basis is the consent of the relevant individual, obtained before processing and capable of being withdrawn at any time. For platform operation, billing and security we rely on contract, legal obligation and legitimate interests as applicable.

A3.Your rights & how to exercise them

You may exercise the rights of access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and the right not to be subject to solely automated decision-making with legal or similarly significant effects. Submit requests to dpo@flowtracker.io. We will verify your identity and respond within the timeframes required by law (generally one month under the GDPR). Where we process your data on behalf of a customer, we will promptly refer your request to that customer or act on their documented instructions.

A4.International transfers

As a UAE-based operator, we transfer personal data internationally. The UAE has not received an EU adequacy decision, so transfers of EU/EEA and UK personal data to us and to other non-adequate countries are protected by the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, together with a transfer impact assessment and supplementary measures where appropriate.

A5.Supervisory authorities & complaints

You have the right to lodge a complaint with a supervisory authority. In the UAE this is the UAE Data Office. In the EU/EEA you may complain to the data protection authority of your country of residence, work, or the place of the alleged infringement; in the UK, the Information Commissioner’s Office (ICO). We ask that you contact us first so we can try to resolve your concern.

Part B — Data Processing Agreement

This DPA applies where FlowTracker processes personal data on behalf of a Customer acting as controller. Capitalised terms not defined here have the meaning given in the Terms & Conditions or, where used, in the GDPR. In case of conflict with the Terms regarding the processing of personal data, this DPA prevails.

B1.Roles & instructions

For Customer Personal Data, the Customer is the controller (or processor acting for a third-party controller) and FlowTracker is the processor. FlowTracker will process Customer Personal Data only on the Customer’s documented instructions, including those set out in the Terms and this DPA, unless required to act otherwise by applicable law (in which case it will inform the Customer unless legally prohibited). The subject matter, duration, nature, purpose, categories of data and data subjects are described in Annex 1. The Customer warrants it has a lawful basis and all required consents for the processing it instructs.

B2.Confidentiality & staff

FlowTracker ensures that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations and receive appropriate data-protection training, and that access is limited to those who need it to provide the service.

B3.Security (Article 32)

FlowTracker implements and maintains appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex 2, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing.

B4.Sub-processors

The Customer provides general authorisation for FlowTracker to engage sub-processors to process Customer Personal Data. A current list is set out in Annex 3. FlowTracker imposes data-protection obligations on each sub-processor that are no less protective than those in this DPA and remains liable for its sub-processors’ performance. FlowTracker will give the Customer prior notice of intended additions or replacements of sub-processors, and the Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Customer may terminate the affected service.

B5.Assistance with data-subject rights

Taking into account the nature of the processing, FlowTracker will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights, and will promptly notify the Customer if it receives such a request directly.

B6.Personal data breach notification

FlowTracker will notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to assist the Customer in meeting its own notification obligations to authorities and data subjects.

B7.DPIA & prior consultation

FlowTracker will provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of processing and the information available to FlowTracker.

B8.International transfers & SCCs

Where processing under this DPA involves the transfer of Customer Personal Data from the EU/EEA or UK to a country without an adequacy decision, the parties agree that the European Commission’s Standard Contractual Clauses (Decision 2021/914) and, for UK data, the UK Addendum, are incorporated by reference and apply as described in Annex 4, with FlowTracker generally acting as “data importer”.

B9.Audit

FlowTracker will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, on reasonable prior notice, no more than once per year except where required by a supervisory authority, subject to confidentiality and to not compromising the security of other customers.

B10.Return & deletion

On termination or expiry of the service, FlowTracker will, at the Customer’s choice, delete or return Customer Personal Data and delete existing copies, unless applicable law requires continued storage, in which case FlowTracker will protect the data and process it only as required by that law.

B11.Liability

Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms & Conditions, to the extent permitted by applicable law.

Annex 1 — Details of processing

ItemDescription
Subject matterProvision of attribution, CRM, omnichannel messaging and conversion-measurement services.
DurationFor the term of the Customer’s subscription, plus any legally required retention.
Nature & purposeCollection, storage, organisation, analysis, profiling, matching, enrichment and disclosure to advertising platforms for measurement and optimisation, on the Customer’s instructions.
Categories of data subjectsThe Customer’s leads, prospects, customers and website/ad audience members.
Categories of personal dataIdentifiers and online identifiers; device and browser characteristics (including fingerprint signals); IP address; advertising click IDs; event/behavioural data; contact details; messaging content and metadata; conversion signals (e.g. deposit value and currency).
Special categoriesNone intended; the Customer must not instruct processing of special-category data.

Annex 2 — Technical & organisational security measures

  • Encryption of data in transit (TLS) and encryption of data at rest for stored personal data;
  • Role-based access controls, least-privilege access and unique credentials, with multi-factor authentication for administrative access;
  • Network segmentation, firewalls and protection against malicious traffic;
  • Logging, monitoring and alerting for security events;
  • Secure software development practices, dependency management and change control;
  • Regular backups and tested restoration procedures;
  • Vendor due diligence and contractual data-protection obligations on sub-processors;
  • Incident response procedures and staff confidentiality and training obligations.

These measures are reviewed and updated as the service evolves; current details are available to customers on request.

Annex 3 — Sub-processors

FlowTracker engages the following categories of sub-processors. The named providers are indicative and the current authoritative list is provided to customers on request.

CategoryPurposeExamples
Cloud hosting & infrastructureApplication hosting, storage, databases, CDN[Hosting provider — to be specified]
Advertising platformsConversion measurement & optimisationMeta, TikTok, Google, Snapchat
PaymentsBilling & transaction signalsStripe
Messaging channelsOmnichannel inbox deliveryTelegram, WhatsApp/Meta, Instagram, Live Chat
Operational toolingEmail, support, analytics, logging[To be specified]

Annex 4 — Transfer mechanism

For restricted transfers, the EU Standard Contractual Clauses (Decision 2021/914) apply, with Module Two (controller-to-processor) or Module Three (processor-to-processor) as applicable; FlowTracker is the data importer and the Customer is the data exporter. The optional docking clause applies; the governing law and forum are as permitted by the Clauses; and the technical and organisational measures are those in Annex 2. For UK transfers, the UK International Data Transfer Addendum to the SCCs applies. The competent supervisory authority is determined in accordance with the Clauses.

Contact & Identity of the Data Controller

Delien Media FZE (“FlowTracker”, “we”, “us”), a Free Zone Establishment registered with the Umm Al Quwain Free Trade Zone Authority (Licence No. 11289).

Registered address: Al Shmookh Business Center, One UAQ, UAQ Free Trade Zone, Umm Al Quwain, United Arab Emirates.

General / legal: legal@flowtracker.io
Privacy & data requests: privacy@flowtracker.io
Data Protection Officer: dpo@flowtracker.io

EU / EEA Representative (GDPR Article 27): [To be appointed — name and EU address to be inserted before processing EU personal data].
UK Representative (UK GDPR Article 27): [To be appointed, if targeting UK users].

Early Access

Join the Beta

Get early access to FlowTracker — full-funnel attribution built for performance affiliates. Limited spots available.

We'll review your application and get back within 24 hours.