Terms of Service Summary
These Terms of Service govern your use of the ReferClub platform (joinreferclub.com). You retain 100% ownership of your customer and referral data. We provide cloud-based referral tracking, counter QR codes, and reward automation. You may cancel your subscription at any time.
1. Agreement to Terms & Parties
These Terms of Service ("Terms") constitute a legally binding contract between you (either an individual business proprietor or a legally incorporated business entity, "Customer", "Merchant", or "you") and ReferClub Inc. ("ReferClub", "we", "us", or "our").
These Terms govern your access to and use of our customer referral and rewards software platform, websites located at joinreferclub.com, counter QR code generation tools, merchant dashboards, and related software applications (collectively, the "Service").
By creating a workspace account, starting a trial, purchasing a subscription, or accessing the Service, you confirm that you have read, understood, and agreed to be bound by these Terms. If you are entering into these Terms on behalf of a company or other legal entity, you represent that you possess the legal authority to bind that entity. If you do not agree with these Terms, you must not access or use the Service.
2. Description of the Service & Workspaces
ReferClub provides a multi-tenant, cloud-based customer referral and reward platform designed for retail storefronts, hospitality venues, and independent service businesses. The Service provides tools to:
- Generate and deploy in-store counter display QR codes for instant customer enrollment.
- Distribute unique digital referral links and promotional friend vouchers.
- Track in-store and online friend redemptions, verify purchases, and credit customer reward points.
- Detect self-referral abuse, duplicate redemptions, and fraudulent referral activity.
- Review real-time campaign analytics, advocate leaderboards, and revenue attribution metrics.
ReferClub reserves the right to enhance, upgrade, or modify platform features over time to maintain software quality and security. Material deprecations of core functionality will be announced with reasonable advance notice.
3. Accounts, Roles & Credential Security
To access the platform, you must register for a workspace account. You agree to provide accurate, complete, and up-to-date business and contact information during registration and maintain its accuracy throughout the term of your account.
- Authorized Users: You may provision staff accounts or operator credentials for authorized personnel within your organization. You remain fully responsible for all actions taken under your workspace credentials.
- Credential Safeguarding: You are responsible for safeguarding login credentials and enforcing strong passwords. You must not share master administrative credentials with external third parties.
- Prompt Security Notice: You agree to notify ReferClub Inc. immediately at hello@joinreferclub.com if you detect or suspect any unauthorized access, breach, or compromise of your workspace.
4. Subscriptions, Billing, Trials & Cancellation
Access to premium features of ReferClub is provided on a subscription basis:
A. Free Trial Period
New merchant workspaces may be eligible for a 14-day free trial. During the trial period, you will have access to designated features without charge. Unless you activate a paid plan before the end of your trial, access to automated campaign features may be suspended until a paid subscription is activated.
B. Billing Cadence & Automatic Renewal
Paid subscriptions are billed in advance on a recurring monthly or annual basis, as selected during checkout. Subscriptions automatically renew at the end of each billing cycle unless cancelled prior to the renewal date.
C. Payment Processing & Taxes
Payments are processed securely via our PCI-DSS compliant third-party payment partner (e.g., Stripe). You agree to provide valid credit card or payment information. All subscription fees are exclusive of applicable federal, state, local, or international sales, use, value-added (VAT), or goods and services taxes, which will be invoiced where required by law.
D. Cancellation & Refunds
You may cancel your subscription at any time directly through your merchant dashboard settings or by emailing hello@joinreferclub.com. Cancellation takes effect at the end of the current paid billing term, and you will retain access through that period. Because subscriptions provide immediate platform access and cloud resource allocation, fees are non-refundable, except where required by mandatory consumer protection legislation.
5. Proprietary Rights & Customer Data Ownership
Customer Data Ownership (100% Retained)
As between Customer and ReferClub Inc., Customer retains 100% ownership, title, copyright, and intellectual property rights in and to all data, customer records, referral lists, campaign configurations, and logos uploaded or ingested into the Service ("Customer Data"). ReferClub Inc. claims zero ownership over your proprietary business records.
Customer grants ReferClub a non-exclusive, worldwide, limited license to host, transmit, reproduce, and display Customer Data solely to the extent necessary to provide, secure, and operate the platform on Customer's behalf, consistent with our Privacy Policy and Data Processing Addendum.
ReferClub Intellectual Property: ReferClub Inc. retains all right, title, and interest in and to the Service, including all software code, interface designs, brand assets, algorithms, documentation, and technical improvements. You may not copy, decompile, reverse engineer, or create derivative works from the platform without explicit written consent.
6. Merchant Responsibilities & Campaign Rules
As a merchant utilizing ReferClub to run customer referral incentives, you acknowledge and agree that:
- Program Rules & Honoring Rewards: You are solely responsible for determining promotional reward values, discount thresholds, expiration dates, and honoring promotional vouchers presented by retail customers at your store.
- Truth in Advertising: Your promotional offers, referral terms, and reward claims must comply with all applicable truth-in-advertising laws, trade regulations, and fair business practices.
- Communications Compliance: When sending referral invitations, rewards, or SMS/email reminders through the platform, you must comply with anti-spam regulations, including the CAN-SPAM Act, the Telephone Consumer Protection Act (TCPA), and European ePrivacy directives, ensuring valid customer consent has been obtained.
7. Acceptable Use Policy
You agree to use the Service strictly in compliance with applicable laws. You shall not, and shall not permit any third party to:
- Engage in automated referral botting, script click manipulation, self-referral spoofing, or fraudulent creation of fictitious advocate accounts.
- Probe, scan, or test the vulnerability of the Service or circumvent authentication or security protocols.
- Attempt to reverse engineer, decompile, disassemble, or derive source code from any portion of the platform.
- Transmit malicious software, viruses, Trojan horses, worm code, or destructive programs.
- Ingest or broadcast content that is illegal, defamatory, obscene, fraudulent, or infringes the intellectual property or privacy rights of any party.
- Resell, lease, sublicense, or operate the platform as a shared service bureau for unauthorized third parties without a commercial partner agreement.
Violation of the Acceptable Use Policy may result in immediate suspension or termination of your workspace account without prior notice or refund.
8. Data Protection & Privacy Compliance
Both parties agree to comply with applicable data privacy legislation, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
Our data collection, processing, and security practices are set forth in our Privacy Policy and GDPR Compliance documentation, which are incorporated into these Terms by reference. Where ReferClub processes end-customer personal data on behalf of an EU/UK merchant, our standard Data Processing Addendum (DPA) shall govern such processing.
9. Service Availability & Technical Support
ReferClub Inc. strives to provide continuous platform availability with a target cloud infrastructure uptime of 99.9%. However, service availability is subject to scheduled maintenance windows and circumstances beyond our reasonable control.
- Maintenance Windows: Routine system maintenance is conducted during off-peak hours with prior notice posted to merchant dashboards whenever possible.
- Technical Support: Customer support is available via email at hello@joinreferclub.com during standard business hours for troubleshooting, billing inquiries, and feature assistance.
10. Disclaimers of Warranties
Except as expressly set forth in these Terms, the Service is provided on an "AS IS" and "AS AVAILABLE" basis, without warranties of any kind, whether express, implied, statutory, or otherwise.
ReferClub Inc. specifically disclaims all implied warranties of merchantability, fitness for a particular purpose, non-infringement, and quiet enjoyment. We do not warrant that the Service will be uninterrupted, error-free, or entirely secure, or that any merchant campaign will generate a specific volume of customer referrals, sales conversion rates, or revenue increase.
11. Limitation of Liability
To the maximum extent permitted by applicable law:
- Exclusion of Consequential Damages: In no event shall ReferClub Inc., its directors, employees, partners, or suppliers be liable for any indirect, incidental, special, consequential, or punitive damages, including loss of profits, goodwill, business opportunities, data loss, or business interruption, arising out of or in connection with your use of or inability to use the Service.
- Aggregate Monetary Liability Cap: In no event shall the total aggregate liability of ReferClub Inc. arising out of or related to these Terms or the Service exceed the total amount of subscription fees actually paid by Customer to ReferClub during the twelve (12) months immediately preceding the event giving rise to the claim.
12. Indemnification
You agree to defend, indemnify, and hold harmless ReferClub Inc., its officers, directors, employees, and agents from and against any third-party claims, damages, liabilities, losses, costs, or expenses (including reasonable attorneys' fees) arising out of or relating to:
- Your Customer Data or promotional campaign content.
- Your breach of these Terms or the Acceptable Use Policy.
- Disputes between you and any of your retail customers or referral participants concerning promotional discounts or reward redemptions.
- Your violation of any applicable marketing, consumer protection, or privacy laws.
13. Term, Suspension & Termination
These Terms commence on the date you register for an account or first access the Service and remain in effect until terminated by either party.
- Termination by Customer: You may terminate your account at any time by cancelling your subscription in the dashboard or contacting support.
- Suspension or Termination by ReferClub: We may suspend or terminate your workspace immediately if you materially breach these Terms, fail to pay fees when due, engage in suspected fraudulent referral activities, or pose a security risk to the platform.
- Post-Termination Grace Period: Following account closure, merchant workspace data is retained in an inactive state for 30 calendar days to allow for data export, after which production records are scheduled for permanent deletion in accordance with our Privacy Policy.
14. Dispute Resolution & Governing Law
These Terms and any dispute arising out of or related to them shall be governed by and construed in accordance with the laws of the State of California, United States, without giving effect to any conflict of law principles.
Informal Resolution: Prior to initiating formal legal proceedings, the parties agree to make a good faith effort to resolve any dispute informally through mutual discussion within thirty (30) days of written notice.
Jurisdiction & Venue: Any legal action, suit, or proceeding arising under these Terms shall be instituted exclusively in the state or federal courts located in San Francisco County, California, and each party irrevocably submits to the personal jurisdiction of such courts.
15. General Provisions
- Entire Agreement: These Terms, together with the Privacy Policy and GDPR Compliance documentation, constitute the entire agreement between the parties with respect to the subject matter hereof.
- Severability: If any provision of these Terms is held to be invalid or unenforceable, that provision will be enforced to the maximum extent permissible, and the remaining provisions will remain in full force.
- No Waiver: Failure by either party to enforce any right or provision will not be deemed a waiver of future enforcement of that or any other provision.
- Assignment: You may not assign or transfer these Terms without our prior written consent. ReferClub may assign these Terms in connection with a corporate reorganization, merger, or sale of assets.
- Force Majeure: Neither party shall be liable for delays or failures in performance resulting from acts beyond reasonable control, including acts of God, labor disputes, utility disruptions, or internet carrier failures.
16. Contact & Legal Inquiries
If you have questions regarding these Terms of Service or need to provide formal legal notice, please contact us:
ReferClub Inc.
Attn: Legal & Corporate Compliance
100 Innovation Way, Suite 400, San Francisco, CA 94107, USA
Email: hello@joinreferclub.com
Summary Notice
This Privacy Policy explains how ReferClub Inc. collects, uses, and discloses information when you use our websites (joinreferclub.com), merchant dashboards, and customer referral tools. We are committed to data minimization, transparent processing, and never selling your personal data.
1. Introduction & Scope
This Privacy Policy applies to personal information processed by ReferClub Inc. ("ReferClub", "we", "us", or "our") through our website located at joinreferclub.com, our merchant web portal, referral campaign applications, counter QR code generators, and associated software services (collectively, the "Service").
Depending on your relationship with ReferClub, we process data in two distinct legal capacities:
- ReferClub as a Data Controller: When you visit our public marketing website, register for a merchant workspace, purchase a subscription, or contact our support team, we determine the purposes and means of processing your account and billing data.
- ReferClub as a Data Processor / Service Provider: When our merchant clients deploy our platform to issue referral links, capture in-store counter QR scans, record friend referrals, or manage reward point distributions to retail customers ("End Customers"), we process those records solely on behalf of and pursuant to the instructions of our merchant clients.
2. Information We Collect
We collect personal data across three primary categories:
A. Information You Provide Directly
- Account Credentials: Full name, business email address, physical retail store address, phone number, and encrypted password hash.
- Billing & Invoicing Details: Business legal name, VAT/tax identification number, billing contact address, and transaction identifiers. All credit card processing is handled directly by our PCI-DSS compliant third-party payment gateway (such as Stripe); we never store raw credit card numbers or CVV codes on our servers.
- Campaign Configuration Data: Reward tiers, promotional coupon rules, custom store branding, and staff operator credentials configured in your dashboard.
- Communications & Inquiries: Transcripts of customer support inquiries, feedback submissions, and email correspondence.
B. Information Processed via Referral Programs (End Customers)
When retail customers scan counter QR codes or participate in a merchant's referral campaign, the platform captures transactional referral tokens:
- Referee and advocate identifiers (email address or phone number submitted for reward delivery).
- Referral code tokens, redemption timestamps, and associated merchant location identifiers.
- Purchase verification values and points balances credited to the customer.
C. Information Collected Automatically
- Device & Network Telemetry: IP address, browser type and version, operating system, device manufacturer, screen resolution, and language preferences.
- Usage Analytics: Referral link click counts, QR scan timestamps, page interaction durations, error logs, and navigation flow within the merchant portal.
3. Cookies & Tracking Technologies
We use strictly necessary and functional cookies and local browser storage to operate our platform securely and reliably:
- Strictly Necessary: Essential for user authentication, maintaining active sessions across dashboard navigation, and preventing Cross-Site Request Forgery (CSRF).
- Preferences & Functionality: Storing language preferences, UI theme toggles, and collapsed menu states.
- Anonymized Performance Metrics: Aggregate telemetry regarding page load speeds and service uptime to assist in technical diagnostics.
You can instruct your browser to block or delete cookies through browser settings. Note that disabling essential cookies will prevent authentication and access to the ReferClub dashboard. We do not engage in cross-site behavioral tracking or sell tracking data to third-party ad networks.
4. Legal Bases for Processing
If you are located in the European Economic Area (EEA), the United Kingdom, or jurisdictions with similar data protection regulations, we process personal data under the following legal bases:
- Contractual Performance: Processing required to establish your account, provide software tools, compute referral rewards, and fulfill our obligations under the Terms of Service.
- Legitimate Interests: Securing our network against unauthorized access, detecting automated referral botting and fraud, improving platform usability, and supporting customer care, where such interests do not override your privacy rights.
- Legal Compliance: Retaining mandatory accounting, tax, and invoicing records, or responding to lawful governmental and judicial orders.
- Consent: Where you have voluntarily opted in to specific non-essential communications or preview features.
5. How We Use Information
We use personal data strictly to deliver and improve our services:
- Providing, operating, and optimizing the ReferClub platform and merchant administrative tools.
- Generating dynamic counter QR codes, attributing customer referrals, and validating in-store friend redemptions.
- Preventing self-referrals, voucher fraud, voucher duplication, and system abuse.
- Processing recurring subscription billing, issuing invoices, and tracking payment histories.
- Sending critical transactional alerts, such as password resets, security notifications, and billing receipts.
- Offering responsive customer support and technical troubleshooting.
- Enforcing our Terms of Service and defending legal claims.
6. Sharing & Disclosure of Information
We do not sell, rent, monetize, or disclose your personal data to third parties for commercial marketing purposes. We share information only under these necessary operational circumstances:
- With Merchant Clients: End-customer referral records (such as referee email, referral date, and redemption status) are shared directly with the specific merchant whose referral program the customer engaged with.
- Vetted Sub-processors & Infrastructure Providers: Trusted third-party vendors who provide cloud hosting (e.g., AWS, Cloudflare), managed database infrastructure, transactional email delivery, payment processing, and application error monitoring. All vendors operate under strict Data Processing Agreements.
- Corporate Reorganization: In the event of a merger, acquisition, corporate reorganization, or sale of substantial assets, personal data may be transferred subject to the commitments in this Privacy Policy.
- Legal & Safety Mandates: Where required by valid subpoena, warrant, or court order, or to defend the safety, property, and rights of ReferClub, our clients, or the public.
7. Data Retention & Lifecycle
We retain personal data only for as long as necessary to fulfill the operational purposes described in this policy, unless a longer retention period is mandated or permitted by law:
- Active Accounts: Workspace data, customer lists, and referral logs are retained during the duration of your active subscription.
- Account Closure Grace Period: Following account cancellation, merchant workspace data is maintained in an inactive state for 30 calendar days to allow for data export or account reactivation, after which production records are queued for permanent deletion or anonymization.
- Statutory Financial Records: Invoicing, billing tokens, and transaction receipts are retained for up to 7 years to comply with statutory tax and accounting standards.
- Diagnostic Logs: Server connection logs, raw IP access records, and telemetry are routinely rotated and purged within 90 to 180 days.
8. Data Security Safeguards
We employ multi-layered technical and organizational safeguards designed to protect personal information from unauthorized access, loss, or alteration:
- Encryption Standards: 256-bit AES encryption for all data at rest across databases and storage buckets; TLS 1.3 transport encryption for all data in transit across public networks.
- Access Governance: Principle of Least Privilege (PoLP), strict role-based access controls, and mandatory multi-factor authentication (MFA) for administrative systems.
- Monitoring & Defense: Automated vulnerability audits, continuous dependency monitoring, rate limiting, and web application firewall protection.
- Disaster Recovery: Encrypted automated backups replicated across secure, geographically separated cloud zones with routine restoration testing.
9. International Data Transfers
ReferClub Inc. is headquartered in the United States, and our primary servers and cloud infrastructure are hosted in the United States and reputable global cloud data centers.
When transferring personal data originating in the European Economic Area (EEA), United Kingdom, or Switzerland to countries outside those territories, we implement valid legal transfer mechanisms, including the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, supplemented by technical encryption measures.
10. Your Privacy Rights & Choices
Depending on your jurisdiction (including the EU/EEA, UK, and states such as California under the CCPA/CPRA), you possess distinct rights regarding your personal data:
- Right of Access & Portability: Request confirmation of data processing and receive a machine-readable export of your personal information.
- Right to Rectification: Update inaccurate, incomplete, or outdated personal information in your profile.
- Right to Erasure ("Right to be Forgotten"): Request the permanent deletion of your personal information, subject to statutory retention obligations.
- Right to Restrict or Object: Restrict certain processing activities or object to processing carried out under legitimate interests.
- Right to Opt-Out of Direct Marketing: Unsubscribe from promotional announcements at any time via the unsubscribe link in any email.
- Non-Discrimination Guarantee: We will never deny services, provide a different quality of service, or charge different rates because you exercised your lawful privacy rights.
To exercise any of these rights, please email our privacy team at hello@joinreferclub.com. We respond to verified requests within thirty (30) days.
11. Children's Privacy
The ReferClub platform is strictly a commercial B2B service intended for business operators and retail consumers aged 18 and older. We do not knowingly solicit, collect, or process personal information from children under the age of 18 (or 16 in the EEA/UK). If we learn that we have inadvertently collected personal data from a minor without verifiable parental consent, we will promptly delete that information.
12. Changes to This Privacy Policy
We may modify or update this Privacy Policy from time to time to reflect evolving regulatory frameworks or platform enhancements. When modifications occur, we will update the "Last updated" date at the top of this page. For material updates affecting your rights, we will provide prominent notice via email or within the merchant dashboard.
13. Contact & Data Privacy Office
If you have questions, feedback, or requests regarding this Privacy Policy or our data handling practices, please contact us:
ReferClub Inc.
Attn: Data Privacy & Compliance
100 Innovation Way, Suite 400, San Francisco, CA 94107, USA
Email: hello@joinreferclub.com
GDPR Compliance Commitment
ReferClub Inc. is committed to full compliance with the European Union General Data Protection Regulation (Regulation (EU) 2016/679) and the UK GDPR (Data Protection Act 2018). This document outlines our data protection architecture, sub-processor governance, lawful processing bases, and data subject rights procedures.
1. Regulatory Framework & Principles
ReferClub Inc. operates in compliance with the General Data Protection Regulation (EU 2016/679) ("GDPR") and the UK GDPR. We adhere to the fundamental principles established under Article 5:
- Lawfulness, Fairness, and Transparency: Processing personal data legally, ethically, and with complete operational visibility.
- Purpose Limitation: Collecting data exclusively for explicit, legitimate business purposes related to operating our referral platform.
- Data Minimization: Limiting personal data collection strictly to what is adequate, relevant, and necessary for referral tracking and reward fulfillment.
- Accuracy: Maintaining mechanisms for merchants and customers to verify, update, and correct records.
- Storage Limitation: Enforcing automated data retention and purging cycles so data is retained no longer than necessary.
- Integrity and Confidentiality: Safeguarding records with industry-standard encryption, strict access governance, and continuous vulnerability monitoring.
2. Data Controller vs. Data Processor Roles
Under Article 4 of the GDPR, legal obligations differ depending on whether an organization acts as a Data Controller or a Data Processor:
ReferClub as a Data Controller (Article 4(7))
We act as a Data Controller for personal data collected directly from our merchant customers (e.g., store owner name, business email, billing profile, staff accounts) and website visitors. We determine the purposes and means of processing this data to manage accounts, bill for subscriptions, and provide platform support.
ReferClub as a Data Processor (Article 4(8))
When merchant clients utilize ReferClub to operate customer referral campaigns, capture counter QR scans, record friend referrals, or distribute reward vouchers to retail shoppers ("End Customers"), the merchant is the Data Controller. ReferClub acts strictly as a Data Processor, processing records exclusively under the merchant's instructions and our Data Processing Addendum (DPA).
3. Lawful Bases for Processing (Article 6 GDPR)
ReferClub ensures that every data processing activity is supported by a documented lawful basis under Article 6:
- Article 6(1)(b) — Performance of a Contract: Processing necessary to provision merchant accounts, process subscriptions, issue QR codes, track referral attribution, and credit reward points pursuant to our Terms of Service.
- Article 6(1)(f) — Legitimate Interests: Processing necessary for defending platform security, preventing referral fraud (such as bot networks or duplicate self-referrals), enforcing rate limits, and improving software stability, balanced against individual privacy rights.
- Article 6(1)(c) — Legal Obligation: Processing required to maintain statutory accounting ledgers, comply with tax regulations, and respond to lawful government orders.
- Article 6(1)(a) — Consent: Applicable where explicit opt-in consent is requested, such as optional feature surveys or promotional newsletters.
4. Data Subject Rights (Articles 15–22 GDPR)
The GDPR grants individuals in the European Economic Area and the United Kingdom comprehensive rights regarding their personal data:
- Right of Access (Article 15): Obtain confirmation as to whether your personal data is processed, along with a copy of the data and details on processing purposes and recipients.
- Right to Rectification (Article 16): Request correction of inaccurate or incomplete personal information without undue delay.
- Right to Erasure ("Right to be Forgotten") (Article 17): Request permanent deletion of personal data where it is no longer needed, consent has been withdrawn, or processing is unlawful.
- Right to Restriction of Processing (Article 18): Restrict active processing while data accuracy or lawful grounds are contested.
- Right to Data Portability (Article 20): Receive your personal data in a structured, commonly used, and machine-readable format (e.g., JSON or CSV), or request its transfer to another provider.
- Right to Object (Article 21): Object at any time to processing based on legitimate interests or direct marketing.
- Automated Decision-Making Protections (Article 22): Right not to be subject to decisions based solely on automated processing or profiling that produce legal or similarly significant effects. ReferClub does not perform automated decision-making of this nature.
How to Exercise Your Rights
For Merchant Account Holders: Send your request directly to our Data Protection Officer at hello@joinreferclub.com. We respond without undue delay and within one (1) calendar month. Proof of identity is required to protect unauthorized disclosures.
For Retail End Customers: Because ReferClub acts as a Data Processor for merchant referral campaigns, end customers seeking to access, update, or erase their referral records should submit requests directly to the merchant whose referral program they participated in. ReferClub provides merchants with administrative dashboard tools and technical support to promptly fulfill end-customer requests.
5. Data Processing Addendum (DPA)
To satisfy Article 28 requirements, ReferClub offers a comprehensive Data Processing Addendum (DPA) for all customers subject to the GDPR or UK GDPR. Our DPA incorporates:
- The European Commission's Standard Contractual Clauses (SCCs) (Module 2: Controller-to-Processor and Module 3: Processor-to-Processor).
- The UK International Data Transfer Addendum issued by the Information Commissioner’s Office.
- Detailed specifications regarding processing scope, security measures, sub-processors, and data breach notification protocols.
EU and UK business clients may request an executed copy of our standard DPA at any time by contacting hello@joinreferclub.com.
6. Sub-processor Governance (Article 28 GDPR)
ReferClub engages third-party sub-processors to assist in delivering infrastructure, hosting, and platform tooling. Under Article 28(2) and 28(4), we enforce strict qualification and oversight:
- Rigorous Vendor Vetting: Comprehensive reviews of data security controls, SOC 2 / ISO 27001 certifications, and GDPR compliance posture prior to onboarding.
- Binding Contractual Safeguards: Mandatory execution of DPAs incorporating data protection obligations equivalent to our customer commitments.
- Sub-processor Categories:
- Cloud Compute & Content Delivery Networks (e.g., AWS, Cloudflare)
- Distributed Database & Object Storage Providers
- Transactional Email & Notification Services (e.g., Postmark, SendGrid)
- Payment Gateway & Billing Infrastructure (e.g., Stripe)
- Operational Logging, Performance, & Error Diagnostics
- Notification of Changes: We maintain an updated register of sub-processors and notify customers of intended changes, providing an opportunity to object on reasonable data protection grounds.
7. International Cross-Border Transfers (Articles 44–49)
When personal data originating in the EEA, UK, or Switzerland is transferred to servers located outside these regions (including the United States), ReferClub ensures appropriate safeguards pursuant to Chapter V of the GDPR:
- Execution of the European Commission's approved Standard Contractual Clauses (Implementing Decision (EU) 2021/914).
- Implementation of the UK International Data Transfer Addendum (IDTA).
- Performance of Transfer Impact Assessments (TIAs) to evaluate foreign legal frameworks.
- Supplementary technical safeguards, including 256-bit AES encryption at rest and TLS 1.3 in transit, preventing unauthorized government or third-party interception.
8. Technical & Organizational Measures (Article 32 GDPR)
ReferClub maintains comprehensive Technical and Organizational Measures (TOMs) to ensure a level of security appropriate to processing risks:
- Pseudonymization & Encryption: All sensitive data is encrypted at rest using AES-256 and in transit using TLS 1.3. User credentials are cryptographically salted and hashed.
- System Confidentiality & Access: Access to production systems is restricted under the Principle of Least Privilege (PoLP) and requires multi-factor authentication (MFA) and VPN/SSH key controls.
- System Resilience & Availability: Fault-tolerant multi-zone cloud architecture, automated backups replicated across secure zones, and routine disaster recovery exercises.
- Vulnerability Management & Testing: Continuous automated vulnerability scanning, automated dependency security patching, and regular infrastructure reviews.
9. Personal Data Breach Notification (Articles 33 & 34)
ReferClub maintains a structured Incident Response Plan to address potential security events:
- Immediate Triage & Remediation: Incident response teams isolate affected systems and initiate forensic analysis upon detection.
- Supervisory Authority Notification: In the event of a confirmed personal data breach likely to result in a risk to data subjects, we notify the competent supervisory authority within 72 hours of becoming aware, in accordance with Article 33.
- Customer Notification (Processor Role): When acting as a Processor, we notify affected merchant controllers without undue delay upon verifying an incident affecting customer data, providing details necessary for the merchant to satisfy its regulatory obligations.
- Communication to Data Subjects: When a breach is likely to result in a high risk to the rights and freedoms of natural persons, notifications are delivered without undue delay in compliance with Article 34.
10. Data Protection Officer & Supervisory Authority Escalation
For questions, DPA requests, or data subject rights inquiries under the GDPR or UK GDPR, please contact our designated Data Protection Officer:
ReferClub Inc.
Attn: Data Protection Officer (DPO)
100 Innovation Way, Suite 400, San Francisco, CA 94107, USA
Email: hello@joinreferclub.com
Under Article 77 of the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement. In the United Kingdom, you may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.