Compliance & your data agreement
The data processing agreement, what it gates, and the compliance controls behind partner access.
Partner access is contractual as well as technical. This explains the agreement and the controls that sit behind it — the detail your legal and compliance teams will want.
The data processing agreement (DPA)
Access to licensed data is gated behind a signed DPA. Until it’s in place, data endpoints and feeds are withheld — the gate is enforced in the platform, not just on paper. Your AskThis contact provisions access once the agreement is signed.
Dual-credential access
Partner authentication uses dual credentials and is fully isolated from the publisher app API. Access is scoped to your account; there is no path from partner credentials to raw events or another partner’s data.
The controls you’re relying on
- Consent at ingestion — data enters the pipeline only where consent allows, decided at the edge.
- Suppression on withdrawal — consent withdrawals propagate to a suppression list that removes people from future processing.
- k-anonymity floor — nothing is served below the minimum cohort size.
- No PII — identifiers are hashed at ingestion; allowlist serializers make exporting raw events or PII structurally impossible.
For your compliance file
The plain-language guarantees are in Consent & k-anonymity; AskThis’s public legal terms are on the Trust page and in the DPA.