Data Processing Agreement
This Data Processing Agreement ("DPA") is part of the Terms of Service between you (the "Controller") and SSWAP MEDIA LLC, a Wyoming limited liability company, 30 N Gould St Ste N, Sheridan, WY 82801, USA (the "Processor") for the use of CashoutGuard. It applies to personal data of your end users that CashoutGuard processes on your behalf.
1. Subject, nature and purpose
- Purpose: detection and prevention of fraud, abuse, multi-accounting and money laundering on the Controller's services.
- Categories of data subjects: visitors and registered users of the Controller's websites and apps.
- Categories of data: IP address and derived network data; device and browser characteristics and hashes; a random device identifier; user ID; hashed email and payout addresses; event data (type, time, amount, offer).
- Duration: for the term of the agreement and the retention period of the Controller's plan.
- Service-wide risk signals: the Controller instructs the Processor to use pseudonymous risk signals derived from the processing for all customers (for example, the number of distinct time zones seen on an IP address, or whether the same email hash or device was blocked by another customer) to detect fraud across the Service. These signals never disclose the Controller's data to other customers.
2. Processor obligations
The Processor shall:
- process personal data only on the Controller's documented instructions, which are the Terms, this DPA and the Controller's configuration of the Service;
- ensure persons authorised to process the data are bound by confidentiality;
- implement appropriate technical and organisational measures (Annex);
- engage sub-processors only as listed in the Privacy Policy, with 30 days' notice of changes during which the Controller may object;
- assist the Controller in responding to data subject requests and with data protection impact assessments;
- notify the Controller without undue delay, and within 48 hours where possible, after becoming aware of a personal data breach;
- delete the personal data at the end of the retention period or of the agreement, unless the law requires storage;
- make available the information necessary to demonstrate compliance and allow reasonable audits, at most once a year with 30 days' notice.
3. International transfers
Data is hosted in the European Union. Any transfer outside the EU/EEA is made under the European Commission's Standard Contractual Clauses or another valid transfer mechanism.
4. Controller obligations
The Controller is responsible for having a lawful basis, informing its users (including about fraud prevention with CashoutGuard), and for the decisions it takes based on risk scores.
Annex: security measures
- Encryption in transit (TLS 1.2+); hosting in ISO 27001 certified data centres.
- Secret API keys, passwords, emails and payout addresses stored as one-way hashes.
- Logical separation of each customer's data; access control on every query.
- Automatic deletion according to plan retention.
- Least-privilege staff access, logged administrative actions, regular backups.
- The collector does not read keystrokes, form contents or page content.