Legal documentation

WANT-A-TOP PRIVACY POLICY Version 2.1 — Effective Date: August 19, 2026 Controller: SOHA Media Systems Corp, a corporation organized under the laws of the State of Wyoming, USA — EIN 42-2677063 Principal place of business: 1500 S Dairy Ashford Rd, Suite 207, Houston, TX 77077, USA Privacy contact: privacy@wantatop.com

1. Scope and Roles

1.1. This Privacy Policy explains how SOHA Media Systems Corp ("SOHA", "we", "us") processes personal data in connection with the Want-A-Top affiliate network (the "Network"). Want-A-Top is an affiliate technology network and marketplace through which promotional programs and offers ("Programs" and "Offers") of different products, websites, services and platforms may be made available to affiliates. Program Operators may be companies related to SOHA, independent companies, or other third parties with which Want-A-Top has commercial arrangements. Nothing in this Policy implies that SOHA owns, controls or operates the products or platforms promoted through the Network.

1.2. This Policy covers two distinct processing activities carried out by SOHA as operator of the Network:

  • Affiliate Data: personal data of individuals who register for, participate in, or represent entities participating in, the Network — including account holders, authorized signatories and beneficial owners of corporate affiliates ("Affiliates").
  • Referral and Attribution Data: certain technical data relating to end users who interact with affiliate links, which SOHA processes as a consequence of operating the Network's tracking and attribution system (Section 3).

1.3. Each Program Operator is independently responsible for the processing it carries out on its own platforms, including account registration, customer profiles, subscriptions, content consumption, billing and customer relationships, customer support and, where applicable, age verification. Such processing is governed by the Program Operator's own privacy policy. SOHA describes and assumes responsibility in this Policy only for the processing it actually performs in its role as operator of the Network.

1.4. Affiliates act as independent controllers of the personal data they collect on their own websites, applications and channels, and are responsible for their own privacy notices and consent management, as required by the Want-A-Top Master Affiliate Agreement (the "Agreement").

2. Affiliate Data We Collect

2.1. At registration

  • Name or business name, country, email address and, where provided, telephone number and messaging handles used for commercial contact.
  • Account credentials.
  • Declared traffic sources (domains, applications, networks and channels through which the Affiliate intends to promote Offers).
  • Evidence of contract acceptance: IP address, date, time and version of the Agreement accepted through the click-wrap mechanism.

2.2. When a payout is first requested (KYC verification)

Before processing any payment, we collect and verify:

Individuals: (a) official photo identification (passport or national ID); (b) recent proof of address (issued within the last 3 months); (c) applicable tax form (W-8BEN for non-U.S. persons; W-9 for U.S. persons); (d) proof of bank account ownership matching the registered Affiliate.

Entities: (a) certificate of incorporation or commercial-registry extract; (b) evidence of the signatory's authority; (c) beneficial-ownership declaration identifying every individual holding twenty-five percent (25%) or more, with official identification of each beneficial owner; (d) applicable tax form (W-8BEN-E or W-9) and, for EU entities, VAT number; (e) proof of bank account ownership in the entity's name; (f) proof of business address where different from the registered address.

Some of these elements respond to legal obligations applicable to SOHA (in particular tax documentation, withholding and reporting, and compliance with sanctions regimes where applicable); others are contractual risk controls that SOHA applies to protect payment integrity, verify identity, prevent duplicate or fraudulent accounts and protect the Network. Section 4 assigns the corresponding legal basis to each purpose.

2.3. Generated during participation

  • Dashboard activity, campaign statistics, click and conversion data, commission and payment records, and invoices.
  • Access and security data: login IP addresses, device and browser information, and cookies used on the dashboard (see Section 10).
  • Results of sanctions screening (OFAC, EU, UK) and fraud- and compliance-related checks, risk assessments and account investigation records concerning the Affiliate's account.
  • Support tickets and commercial correspondence.
  • Where requested under the Agreement's audit provisions: traffic documentation provided by the Affiliate, including source lists, placements, creatives, traffic logs, audience-origin information and media-purchase invoices.

2.4. Personal data we receive from third parties

Depending on the circumstances, SOHA may receive information relating to an Affiliate from third parties, including: Program Operators; advertising networks; traffic providers; media-buying platforms; payment institutions and banks; fraud-prevention providers; identity/KYC verification providers; sanctions-screening providers; card schemes and payment processors where applicable; auditors; publicly available sources; and other third parties reasonably used for compliance, verification, security or fraud prevention.

Such information may relate to: traffic sources; campaign activity; attribution; conversions; payment events; refunds; chargebacks; fraud indicators; compliance incidents; sanctions matches; identity verification outcomes; and discrepancies detected during audits.

In particular, where reasonably necessary for fraud prevention, attribution verification, traffic-quality verification, contractual enforcement, compliance, security, payment integrity or the defense of legal claims, SOHA may verify information provided by an Affiliate directly with relevant third parties (advertising networks, traffic providers, media-buying platforms, Program Operators, payment providers, fraud-prevention providers and other relevant providers). These verifications may involve the exchange and receipt of personal data relating to the Affiliate, limited to what is reasonably necessary for those purposes.

3. Referral and Attribution Data (End Users)

3.1. When an end user clicks an affiliate link, the Network's tracking and attribution system processes certain technical data. Depending on the technical implementation, this may include: affiliate and campaign identifiers; click IDs; timestamps; source and referrer information; IP address where processed; device and browser information; the Offer or Program destination; conversion events and transaction or conversion values reported back for commission calculation; attribution information; and other technical identifiers necessary for tracking, attribution, fraud prevention and commission calculation.

3.2. This data identifies end users pseudonymously: SOHA does not receive names, contact details, payment credentials or account content of end users of the Programs, and does not seek to identify end users directly. Referral and Attribution Data is not anonymous where it includes online identifiers such as IP addresses or click IDs, and it is treated as personal data where applicable law so requires.

3.3. SOHA processes Referral and Attribution Data for the following purposes: affiliate attribution; determining commission eligibility; preventing duplicate attribution; distinguishing valid and invalid traffic; fraud prevention; campaign measurement; the technical operation of affiliate links; routing traffic to Programs and Offers; enforcing attribution windows; resolving attribution disputes; security; and generating aggregated or pseudonymized reporting.

3.4. Traffic routing. Certain technical and contextual data (country or approximate location, device, browser, traffic source, campaign, Offer availability, Program restrictions, compliance requirements and performance criteria) may be used to select or route the most appropriate available Offer for a given click. This routing determines the destination of a promotional link and does not produce legal or similarly significant effects concerning the end user.

3.5. The attribution windows applied by the Network are short by design (by default, seven (7) days for prospecting traffic and twenty-four (24) hours for retargeting traffic), which limits the duration of active tracking.

3.6. Where cookies or similar technologies are stored on or read from an end user's device for these purposes, the applicable consent requirements are addressed in the Want-A-Top Cookie Policy and through the consent mechanisms deployed on the affiliate's properties and on the Program landing environments, as allocated in the Agreement and the applicable Offer arrangements.

4. Purposes and Legal Bases

For individuals in the European Economic Area or the United Kingdom, the legal bases under the GDPR/UK GDPR are as follows:

Affiliate Data:

Purpose

Legal basis (EEA/UK)
Creating and managing the account; operating tracking, attribution, reporting and the dashboard; Network communications
Performance of a contract (Art. 6(1)(b))
Tax documentation, withholding and reporting (including IRS reporting such as Forms 1099/1042 where applicable)
Legal obligation (Art. 6(1)(c))
Sanctions screening of account holders and beneficial owners
Legal obligation (Art. 6(1)(c)) where applicable; otherwise legitimate interest (Art. 6(1)(f)) in complying with international sanctions regimes
Identity, authority, beneficial-ownership and bank-details verification (KYC); prevention of duplicate or fraudulent accounts; payment integrity
Performance of a contract (Art. 6(1)(b)); legitimate interest (Art. 6(1)(f)) in protecting the Network and its payment flows
Fraud prevention and investigation; invalid-traffic detection; audit of traffic sources and third-party verification; monitoring compliance with the Agreement and the Affiliate Guidelines (including review of campaigns, disclosures, traffic sources and prohibited content); documenting suspension, termination, forfeiture and clawback decisions; preservation of technical evidence; defense of legal claims
Legitimate interest (Art. 6(1)(f)) in protecting the Network, the Programs, payment integrity and SOHA's legal position
Evidencing acceptance of the Agreement and its versions
Performance of a contract (Art. 6(1)(b)); legitimate interest (Art. 6(1)(f))
Dashboard security and prevention of unauthorized access
Legitimate interest (Art. 6(1)(f))
Compliance with court orders, regulatory requests and binding card-network requirements
Legal obligation (Art. 6(1)(c)); legitimate interest (Art. 6(1)(f))

Referral and Attribution Data (end users): the purposes listed in Section 3.3 are based on SOHA's and the Affiliates' legitimate interest (Art. 6(1)(f)) in operating a reliable attribution and anti-fraud system for the Network. Performance of a contract is not relied upon in respect of end users, who are not party to the Agreement. Where the storage of or access to information on an end user's device requires consent under applicable ePrivacy rules, that consent is obtained through the mechanisms described in Section 3.6, and the processing described here applies to data collected consistently with those rules.

Automated tools. SOHA may use automated tools for fraud scoring, sanctions screening, duplicate-account detection, traffic-quality scoring, anomaly detection and risk assessment. Significant decisions concerning an Affiliate's account — including suspension, termination, forfeiture or clawback — are reviewed and adopted with human involvement and are not based solely on automated processing.

5. Disclosures of Personal Data

We disclose personal data only as follows:

  • Program Operators. The level of information available to each Program Operator depends on the structure of, and the arrangements applicable to, each Program or Offer. Depending on the Offer, a Program Operator may not know the identity of the Affiliate; may receive only an Affiliate ID or other identifiers; may receive performance and traffic information (campaign and Offer identifiers, click and conversion identifiers, conversion values, traffic-source information); may receive fraud indicators or compliance information; or, where the specific model so requires and a valid legal basis exists, may receive certain identifying information about the Affiliate. Where the conditions of an Offer or the arrangement with the relevant Program Operator grant it rights concerning Affiliate eligibility, compliance, traffic quality, suspension, restriction or termination, SOHA may process and communicate the information reasonably necessary for those purposes. The complete KYC file is not routinely shared with Program Operators and would only be disclosed where an exceptional legal or compliance need, consent where appropriate, or another valid legal basis exists. Data minimization and necessity principles apply to all such exchanges.
  • Banks and payment institutions: the data required to execute wire transfers.
  • Identity-verification, sanctions-screening and anti-fraud providers: acting as processors under contract with us.
  • External auditors and legal advisors: where reasonably necessary for audits, investigations or the establishment, exercise or defense of legal claims, subject to confidentiality.
  • Authorities, card schemes, acquirers and processors: where required by law, court order, regulatory request or binding scheme rules.
  • Group companies and successors: entities of our corporate group for internal administration, and any successor in a reorganization or business transfer, under equivalent safeguards.

6. No Sale of Personal Data

SOHA does not sell personal data to third parties. The operation of the Network does not involve the sale of personal data to data brokers, advertisers or other third parties, including within the broad definitions of "sale" used by applicable U.S. state privacy laws. The disclosures described in Section 5 — to service providers and processors, Program Operators, payment institutions, verification providers and authorities — are operational disclosures necessary to run the Network and are not sales of personal data.

7. International Transfers

7.1. SOHA is established in the United States and processes personal data there. Where SOHA offers the Network to Affiliates in the EEA or the UK, it complies with the GDPR/UK GDPR in respect of that processing.

7.2. Where personal data is transferred from the EEA or the UK to recipients in countries without an adequacy decision — including onward transfers by SOHA to its processors and other recipients described in Section 5 — SOHA relies on valid transfer mechanisms for ongoing transfers, in particular the European Commission's Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum or applicable UK mechanism. Should SOHA certify under the EU-U.S. Data Privacy Framework (and its UK extension), that framework will apply to the transfers it covers and this Section will be updated accordingly. Derogations under Article 49 GDPR are relied upon only exceptionally, where legally appropriate for specific, non-repetitive situations, and not as a structural basis for the service.

7.3. This structure is designed so that, should Affiliates in the EEA be contracted or managed in the future by a separate European entity of the group, the transfer framework can be adapted without redesigning the system.

8. Retention

  • Account and contract data (including click-wrap acceptance evidence): duration of participation plus applicable statute-of-limitations periods for contractual claims.
  • KYC, tax and payment records: at least seven (7) years from the relevant payment or tax year, as required by applicable tax and accounting rules.
  • Referral and Attribution Data: retained in identifiable (pseudonymous) form for as long as necessary for attribution, commission calculation, chargeback processing, fraud investigation and audit — and in any event for no less than the twenty-four (24) month clawback and audit period provided in the Agreement — after which it is deleted or aggregated/anonymized for reporting.
  • Traffic, audit, fraud and compliance investigation documentation (including internal fraud records, risk assessments, investigation history, decisions and supporting evidence): at least twenty-four (24) months, and for as long as reasonably necessary to defend a suspension, termination, forfeiture or clawback decision or any related claim.
  • Sanctions-screening results: duration of the relationship plus five (5) years.
  • Security logs: up to twenty-four (24) months.

Retention periods are extended where an investigation, litigation, legal hold, regulatory requirement or pending dispute so requires. Upon expiry, data is deleted or irreversibly anonymized.

9. Your Rights

EEA/UK individuals have the rights of access, rectification, erasure, restriction, portability and objection (including to processing based on legitimate interest), and the right to lodge a complaint with a supervisory authority. Where processing is required by law or necessary for the contract (e.g., KYC before payment), exercising erasure or objection may make it impossible for us to process payments.

U.S. residents have the rights granted by applicable U.S. state privacy laws where their respective scope and thresholds are met — which may include confirmation of processing, access, correction, deletion, portability, opt-out rights and the right to appeal a refusal. Texas residents' rights under the Texas Data Privacy and Security Act are honored where that law applies.

To exercise any right, contact privacy@wantatop.com. We will verify your identity before responding and reply within the legally applicable period. End users wishing to exercise rights in relation to a Program should contact the relevant Program Operator; where a request concerns Referral and Attribution Data processed by SOHA, we will handle it or coordinate with the relevant parties as appropriate.

10. Cookies and Tracking Technologies

The Want-A-Top website and affiliate dashboard use cookies for authentication, session management, security, preferences and, where deployed, analytics. Separately, the Network's affiliate tracking system uses cookies and similar technologies for affiliate identifiers, attribution, referral tracking, conversion measurement, fraud prevention and the enforcement of attribution windows. Both categories are described in the Want-A-Top Cookie Policy, which forms part of this legal framework and should be read together with this Policy. This Policy governs the personal-data aspects of that tracking (Sections 3 and 4).

11. Minors

Affiliate accounts may only be held by individuals aged 18 or over (or the higher age of majority in their jurisdiction); accounts found to belong to minors will be closed. The Network's tracking services are not directed at minors, and the adult nature of certain Offers is subject to the age-assurance and audience restrictions established in the Agreement, the Affiliate Guidelines and the applicable Offer Terms.

12. Security

We apply technical and organizational measures appropriate to the risk, including encryption in transit, access controls, segregation of the KYC repository, logging of administrative access, and contractual confidentiality and security obligations on all processors. We will notify affected individuals and competent authorities of personal-data breaches where legally required.

13. Changes to this Policy

We may update this Policy to reflect legal, technical or operational changes. Material changes will be notified through the dashboard and/or by email at least fifteen (15) days before taking effect. The version and effective date are indicated in the header.

14. Contact

SOHA Media Systems Corp — principal place of business: 1500 S Dairy Ashford Rd, Suite 207, Houston, TX 77077, USA — privacy@wantatop.com.

© SOHA Media Systems Corp. All rights reserved.