Last Updated: August 28
A.1 This Data Processing Addendum (this "DPA") forms part of and is incorporated by reference into the Terms of Service published at https://appy.ai/terms-of-service, or such other written agreement as governs Customer's access to and use of the Platform (the "Agreement"), between AppyPeople, Inc., a Delaware corporation ("AppyPeople," "we," "us") and the customer entity that has accepted the Agreement ("Customer," "you"). This DPA governs the Processing of Customer Personal Data by AppyPeople as a Processor acting on Customer's behalf.
A.2 No signature required. This DPA takes effect automatically, without signature, on the earlier of (a) Customer's acceptance of the Agreement, and (b) the date AppyPeople first Processes Customer Personal Data. It applies to every Customer, on every subscription plan, whether or not Customer has requested it. Customer is not required to sign, countersign, request, or otherwise take any step in order to have the benefit of this DPA.
A.3 Optional countersignature. Where Customer requires a countersigned copy, the parties may execute the countersignature schedule at the end of this DPA. Execution records the parties' agreement to the same terms and does not vary them; the terms in force are those published at https://appy.ai/dpa as at the date of execution. Nothing in this Section makes signature a condition of effectiveness.
A.4 Identification of Customer. Customer is identified by the account registration details recorded for Customer's account on the Platform, including the entity name, billing entity, and administrative contact. Where the parties have executed an order form or similar document, that document additionally identifies Customer.
A.5 Publication and changes. AppyPeople publishes this DPA at https://appy.ai/dpa and the list of Sub-processors at https://appy.ai/subprocessors. AppyPeople may amend this DPA only: (a) as required to reflect a change in Applicable Data Protection Law or in a transfer mechanism relied on under Section 12; (b) to add commitments in Customer's favour; or (c) with at least thirty (30) days' prior notice, where the amendment does not materially reduce the protections afforded to Customer. Customer may terminate the Agreement without penalty if a proposed amendment materially reduces those protections.
1.1 Capitalised terms used but not defined in this DPA have the meanings given in the Agreement. In this DPA:
(a) "Applicable Data Protection Law" means all laws and regulations applicable to a party's Processing of Customer Personal Data under this DPA, including, as applicable, EU GDPR, UK Data Protection Law, Swiss FADP, and US State Privacy Laws.
(b) "Controller," "Processor," "Data Subject," "Personal Data Breach," "Processing" and "Supervisory Authority" have the meanings given in the EU GDPR, and cognate terms are construed accordingly. References to a "business," "service provider," "sale," and "share" have the meanings given in the US State Privacy Laws.
(c) "Customer Personal Data" means Personal Data contained within Customer Data or End User Data that AppyPeople Processes on Customer's behalf under the Agreement. Customer Personal Data does not include Personal Data for which AppyPeople is a Controller under Section 2.3.
(d) "EU GDPR" means Regulation (EU) 2016/679.
(e) "Restricted Transfer" means a transfer of Customer Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country not benefiting from an adequacy decision, or an onward transfer of such data.
(f) "SCCs" means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914.
(g) "Sensitive Personal Data" means: (i) special categories of personal data within the meaning of Article 9 EU GDPR; (ii) personal data relating to criminal convictions and offences; (iii) protected health information within the meaning of HIPAA; (iv) government-issued identification numbers, financial account numbers, and payment card data; (v) biometric data; (vi) precise geolocation; and (vii) personal data of children under the age of 18 or such higher age as Applicable Data Protection Law prescribes.
(h) "Sub-processor" means any third party engaged by AppyPeople or an AppyPeople affiliate to Process Customer Personal Data on AppyPeople's behalf.
(i) "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
(j) "US State Privacy Laws" means the state privacy statutes of California, Colorado, Connecticut, Virginia, and any other US state statute governing the processing of personal data that applies to Customer's use of the Platform.
2.1 Customer as Controller. Customer is the Controller of Customer Personal Data and AppyPeople is the Processor. Customer is solely responsible for determining the purposes and means of Processing, for the lawfulness of the Processing, and for the accuracy, quality, and legality of Customer Personal Data and the means by which Customer acquired it.
2.2 Customer as Processor. Where Customer is itself a Processor acting on behalf of a third-party Controller, Customer warrants that it has the authority of that Controller to engage AppyPeople as a Sub-processor on the terms of this DPA, and that the instructions it gives AppyPeople are consistent with those it has received. In such case, references in this DPA to Customer's rights and obligations as Controller apply to Customer in its capacity as Processor, and Module Three of the SCCs applies as provided in Section 12.
2.3 AppyPeople as Controller. AppyPeople is an independent Controller with respect to: (a) account registration, authentication, and administrative contact data of Administrative Users; (b) billing and payment data; (c) Usage Data collected for the purposes of security, fraud prevention, billing, support, and service operation; and (d) Personal Data collected through AppyPeople's own websites and marketing activities. AppyPeople Processes that data in accordance with its Privacy Policy. This DPA does not apply to that Processing.
2.4 Compliance. Each party shall comply with its respective obligations under Applicable Data Protection Law in respect of the Processing contemplated by this DPA. Neither party is responsible for the other's compliance failures.
3.1 Documented Instructions. AppyPeople shall Process Customer Personal Data only: (a) as described in Annex I; (b) in accordance with the Agreement and this DPA; (c) as necessary to provide, secure, support, and maintain the Platform, the Support Services, and any Professional Services; (d) in accordance with Customer's further documented written instructions where those instructions are consistent with the Agreement; and (e) as required by applicable law. The Agreement, this DPA, and Customer's configuration of the Platform constitute Customer's complete and final documented instructions to AppyPeople.
3.2 Unlawful Instructions. AppyPeople shall inform Customer without undue delay if, in AppyPeople's opinion, an instruction from Customer infringes Applicable Data Protection Law, unless prohibited from doing so by law. AppyPeople may suspend performance of the affected instruction until it is withdrawn, amended, or confirmed.
3.3 Compelled Disclosure. If AppyPeople receives a legally binding request from a public authority for disclosure of Customer Personal Data, AppyPeople shall, unless legally prohibited: (a) notify Customer without undue delay and before disclosure; (b) seek to redirect the authority to request the data directly from Customer; (c) challenge the request where it is unlawful or overbroad; and (d) disclose only the minimum amount of data legally required. Where AppyPeople is prohibited from notifying Customer, it shall use reasonable efforts to obtain a waiver of that prohibition and shall document its assessment for Customer's inspection.
3.4 No Model Training. AppyPeople shall not, and shall ensure that its Sub-processors do not, use Customer Personal Data to train, fine-tune, adapt, evaluate, or otherwise develop any machine learning or artificial intelligence model, other than: (a) models that operate solely for Customer's own tenant and are not made available to any other customer, where Customer has expressly enabled that functionality; and (b) abuse, safety, and security classifiers operating on a transient basis and retaining no Customer Personal Data. AppyPeople shall procure that no third-party provider of Third-Party AI Models uses Customer Personal Data to train or improve that provider's models.
3.5 No Secondary Use. AppyPeople shall not: (a) sell or share Customer Personal Data within the meaning of the US State Privacy Laws; (b) retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in this DPA, including for any commercial purpose of AppyPeople; (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between the parties; or (d) combine Customer Personal Data with personal data received from or on behalf of any other person, except as permitted by the US State Privacy Laws for a service provider.
3.6 Aggregated and De-identified Data. AppyPeople may create and use aggregated or de-identified data derived from Customer Personal Data for the purposes of operating, securing, benchmarking, and improving the Platform, provided that such data: (a) is processed so that it can no longer be attributed to an identified or identifiable natural person and cannot reasonably be re-identified, whether by AppyPeople or any third party; (b) is not re-identified or attempted to be re-identified; and (c) is not disclosed in a manner that identifies Customer or any Data Subject. AppyPeople shall implement and maintain technical safeguards and business processes prohibiting re-identification.
3.7 Sensitive Personal Data. The Platform is not designed or intended for the Processing of Sensitive Personal Data. Customer shall not, and shall ensure that its Authorized Users and End Users do not, submit Sensitive Personal Data to the Platform. AppyPeople has no liability for Sensitive Personal Data submitted in breach of this Section, and Customer shall be solely responsible for any resulting non-compliance. Nothing in this Section limits AppyPeople's obligations under Sections 5 and 8 with respect to Customer Personal Data actually in its possession.
3.8 Protected Health Information. AppyPeople is not a business associate of Customer and the Platform may not be used to Process protected health information within the meaning of HIPAA unless the parties have executed a separate written business associate agreement. In the absence of such an agreement, Customer shall not submit protected health information to the Platform.
4.1 AppyPeople shall treat Customer Personal Data as Confidential Information of Customer under the Agreement and shall not disclose it except as permitted by this DPA.
4.2 AppyPeople shall ensure that access to Customer Personal Data is limited to personnel who require access in order to perform AppyPeople's obligations under the Agreement, and that such personnel are: (a) subject to written obligations of confidentiality that survive termination of their engagement; (b) informed of the confidential nature of the data; and (c) have received training on their data protection and information security responsibilities appropriate to their role.
4.3 AppyPeople shall conduct background screening of personnel with access to Customer Personal Data to the extent permitted by applicable law.
5.1 Security Measures. AppyPeople shall implement and maintain the technical and organisational measures described in Annex II, designed to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing.
5.2 Changes to Measures. AppyPeople may update the measures in Annex II from time to time provided that no such update results in a material degradation of the overall security of the Platform. The current version of Annex II is available at https://appy.ai/dpa or on request.
5.3 Independent Assurance. AppyPeople maintains an information security programme as described in Annex II. Where AppyPeople holds a current third-party audit report, attestation, or certification covering the Platform, it shall make that report or certificate available to Customer on request, subject to confidentiality obligations.
5.4 Customer Responsibilities. Customer is responsible for its own configuration of the Platform, for managing access and permissions of its Authorized Users, for the security of its credentials and its own systems and networks, and for assessing whether the measures in Annex II meet Customer's requirements under Applicable Data Protection Law.
6.1 General Authorisation. Customer grants AppyPeople general authorisation to engage Sub-processors to Process Customer Personal Data. The Sub-processors engaged as at the date of this DPA are listed in Annex III and published at https://appy.ai/subprocessors.
6.2 Sub-processor Obligations. AppyPeople shall enter into a written agreement with each Sub-processor imposing data protection obligations that are no less protective than those in this DPA, to the extent applicable to the nature of the services provided by that Sub-processor. AppyPeople shall conduct appropriate due diligence on each Sub-processor prior to engagement and periodically thereafter.
6.3 Liability for Sub-processors. AppyPeople remains fully liable to Customer for the performance of each Sub-processor's obligations in relation to Customer Personal Data, and for any act or omission of a Sub-processor that would constitute a breach of this DPA if committed by AppyPeople.
6.4 Notice of Changes. AppyPeople shall notify Customer of any intended addition or replacement of a Sub-processor at least thirty (30) days before that Sub-processor begins Processing Customer Personal Data. Notice shall be given by email to the security, privacy, or administrative contact recorded in Customer's account, and by updating the page at https://appy.ai/subprocessors, to which Customer may subscribe for notifications of changes.
6.5 Objection. Customer may object to an intended addition or replacement of a Sub-processor on reasonable data protection grounds by written notice within fifteen (15) days of AppyPeople's notice. The parties shall discuss the objection in good faith. If AppyPeople is unable to make available a commercially reasonable alternative within thirty (30) days, Customer may terminate the affected subscription by written notice, effective immediately, and AppyPeople shall refund any Fees prepaid in respect of the period after the effective date of termination, calculated on a pro-rata basis. Where Customer is billed monthly and has prepaid no more than the then-current month, this Section entitles Customer to terminate without further charge.
6.6 Emergency Replacement. AppyPeople may engage a new Sub-processor without advance notice where necessary to address a material security, availability, or legal risk, provided it notifies Customer as soon as reasonably practicable thereafter and Customer's rights under Section 6.5 apply from the date of that notice.
7.1 The Platform provides Customer with controls enabling Customer to access, correct, export, restrict, and delete Customer Personal Data. Customer is responsible for responding to Data Subject requests using those controls.
7.2 Where Customer is unable to address a Data Subject request through the functionality of the Platform, AppyPeople shall, on Customer's written request, provide reasonable assistance to enable Customer to respond, taking into account the nature of the Processing. AppyPeople may charge a reasonable fee for assistance that is disproportionate or repetitive, on prior written notice to Customer.
7.3 If AppyPeople receives a request directly from a Data Subject relating to Customer Personal Data, AppyPeople shall not respond to the request other than to acknowledge receipt and direct the Data Subject to Customer, and shall forward the request to Customer without undue delay.
8.1 Notification. AppyPeople shall notify Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notice shall be given by email to the security, privacy, or administrative contact recorded in Customer's account or, failing that, to Customer's Administrative Users.
8.2 Contents of Notice. AppyPeople's notice shall include, to the extent known and as it becomes known: (a) the nature of the breach, including the categories and approximate number of Data Subjects and records concerned; (b) the likely consequences; (c) the measures taken or proposed to address the breach and mitigate its effects; and (d) a contact point for further information. AppyPeople shall provide supplementary information as the investigation progresses and shall not delay initial notification in order to complete its investigation.
8.3 Cooperation and Remediation. AppyPeople shall take reasonable steps to contain, investigate, and remediate the breach, shall preserve relevant evidence and logs, and shall provide reasonable cooperation to enable Customer to meet its own notification obligations to Supervisory Authorities and Data Subjects.
8.4 No Admission. AppyPeople's notification of or response to a Personal Data Breach is not an acknowledgement of fault or liability. AppyPeople shall not notify any Supervisory Authority or Data Subject of a Personal Data Breach affecting Customer Personal Data on Customer's behalf, or identify Customer in any public statement concerning a breach, without Customer's prior written consent unless required by law.
9.1 AppyPeople shall provide reasonable assistance to Customer, at Customer's cost, in connection with any data protection impact assessment or prior consultation with a Supervisory Authority that Customer is required to carry out under Articles 35 and 36 EU GDPR in relation to Customer's use of the Platform, in each case solely to the extent Customer does not otherwise have access to the relevant information. Such assistance may be provided by making available AppyPeople's standard documentation, security whitepapers, audit reports, and completed assessment questionnaires.
9.2 AppyPeople shall notify Customer if it becomes aware of a change in its Processing operations that would materially affect an assessment previously provided to Customer.
10.1 During the Term. Customer may export and delete Customer Personal Data using the functionality of the Platform at any time during the Subscription Term.
10.2 On Termination. On expiry or termination of the Agreement, AppyPeople shall, at Customer's election, delete or return all Customer Personal Data in its possession or control. Absent a written election by Customer within thirty (30) days of termination, AppyPeople shall delete Customer Personal Data. Deletion from active production systems shall be completed within thirty (30) days of the election or the expiry of that period, and from backup and archival media within ninety (90) days, in each case in accordance with AppyPeople's documented retention schedule.
10.3 Retention Exceptions. AppyPeople may retain Customer Personal Data to the extent required by applicable law, and may retain aggregated or de-identified data created in accordance with Section 3.6. Any data so retained shall remain subject to the confidentiality and security obligations of this DPA for as long as it is retained.
10.4 Certification. AppyPeople shall certify deletion in writing on Customer's written request.
11.1 Documentation. AppyPeople shall make available to Customer such information as is reasonably necessary to demonstrate compliance with this DPA, which may be satisfied in the first instance by providing AppyPeople's then-current third-party audit reports, certifications, penetration test summaries, and completed security questionnaires.
11.2 Audit. Where the information provided under Section 11.1 is not sufficient to demonstrate compliance, or following a Personal Data Breach affecting Customer Personal Data, Customer or an independent auditor appointed by Customer and reasonably acceptable to AppyPeople may audit AppyPeople's compliance with this DPA, subject to the following: (a) no more than once in any twelve-month period, save where required by a Supervisory Authority or following a Personal Data Breach; (b) on at least thirty (30) days' prior written notice; (c) during normal business hours and in a manner that does not disrupt AppyPeople's operations; (d) subject to the auditor executing confidentiality obligations reasonably acceptable to AppyPeople; (e) excluding access to any other customer's data, and to premises, systems, or information of third parties; and (f) at Customer's cost.
11.3 Sub-processor Audits. AppyPeople shall use reasonable efforts to procure equivalent audit rights in relation to its Sub-processors, or to provide Customer with the outputs of audits it has conducted or obtained.
12.1 Transfer Mechanism. To the extent AppyPeople's Processing of Customer Personal Data involves a Restricted Transfer, the SCCs are incorporated into this DPA by reference and apply to that transfer as set out below.
12.2 EEA Transfers. For transfers from the EEA:
(a) Where Customer is a Controller, Module Two of the SCCs applies, with Customer as data exporter and AppyPeople as data importer.
(b) Where Customer is a Processor, Module Three of the SCCs applies, with Customer as data exporter and AppyPeople as data importer.
(c) Clause 7 (docking clause) does not apply. In Clause 9, Option 2 (general written authorisation) applies, with the notice period specified in Section 6.4 of this DPA. In Clause 11, the optional independent dispute resolution language does not apply. In Clause 17, the SCCs are governed by the law of Ireland. In Clause 18(b), the forum is the courts of Ireland.
(d) Annex I to the SCCs is completed by Annex I to this DPA, Annex II to the SCCs by Annex II to this DPA, and the list of Sub-processors by Annex III to this DPA. The certification of deletion in Clause 8.5 is addressed in Section 10.4.
12.3 UK Transfers. For transfers subject to UK Data Protection Law, the SCCs as incorporated above apply as amended by the UK Addendum. Tables 1 to 3 of the UK Addendum are completed by the corresponding information in this DPA and its Annexes. In Table 4, neither party may end the UK Addendum as set out in Section 19 of the UK Addendum.
12.4 Swiss Transfers. For transfers subject to the Swiss FADP, the SCCs apply with the following modifications: references to the GDPR are to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; and the term "Member State" shall not be interpreted so as to exclude Data Subjects in Switzerland from enforcing their rights in Switzerland.
12.5 Alternative Mechanisms. If AppyPeople adopts an alternative lawful transfer mechanism, including certification under the EU-US Data Privacy Framework and its UK Extension and Swiss-US counterpart, that mechanism shall apply in place of the SCCs to the extent it lawfully covers the relevant transfer, and the SCCs shall apply only to transfers not so covered.
12.6 Transfer Impact Assessment. AppyPeople shall provide Customer with information reasonably necessary for Customer to complete a transfer impact assessment, including information about the legal regime applicable in each country to which Customer Personal Data is transferred and the government access requests AppyPeople has received, to the extent AppyPeople is permitted to disclose it.
13.1 To the extent the US State Privacy Laws apply, AppyPeople acts as a service provider or processor to Customer as business or controller. AppyPeople shall comply with the obligations applicable to a service provider or processor and shall provide Customer Personal Data the same level of privacy protection as required of Customer.
13.2 AppyPeople certifies that it understands and shall comply with the restrictions in Section 3.5. AppyPeople shall notify Customer without undue delay if it determines that it can no longer meet its obligations under the US State Privacy Laws.
13.3 Customer may take reasonable and appropriate steps to stop and remediate any unauthorised use of Customer Personal Data by AppyPeople, including as provided in Sections 8 and 11.
14.1 Each party's liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement, and any reference in the Agreement to the liability of a party means the aggregate liability of that party under the Agreement and this DPA together.
14.2 Nothing in this DPA or the Agreement limits or excludes either party's liability to a Data Subject under Applicable Data Protection Law or under Clause 12 of the SCCs.
15.1 Order of Precedence. In the event of a conflict between this DPA and the Agreement in relation to the Processing of Customer Personal Data, this DPA prevails. In the event of a conflict between this DPA and the SCCs, the SCCs prevail. Where the parties have executed a countersigned copy of this DPA or a separate negotiated data processing agreement, that document prevails over the version published at https://appy.ai/dpa in respect of that Customer only.
15.2 Term. This DPA takes effect as provided in Section A.2 and continues for so long as AppyPeople Processes Customer Personal Data, and thereafter until AppyPeople has deleted or returned it in accordance with Section 10. Provisions intended to survive shall survive.
15.3 Changes in Law. If Applicable Data Protection Law changes, or a transfer mechanism relied on under Section 12 is invalidated or amended, the parties shall negotiate in good faith such amendments to this DPA as are reasonably necessary to maintain compliance, and shall execute any additional documents reasonably required for that purpose. AppyPeople may give effect to such amendments in accordance with Section A.5.
15.4 Governing Law. This DPA is governed by the law governing the Agreement, save that the SCCs are governed as provided in Section 12.2(c) and the UK Addendum as provided in the UK Addendum.
15.5 Severability. If any provision of this DPA is held invalid or unenforceable, the remainder shall continue in full force and effect.
15.6 Notices. AppyPeople shall give notices under this DPA to the administrative, security, or privacy contact recorded in Customer's account or, failing that, to Customer's Administrative Users. Notices under Section 6.4 may additionally be given by updating the page at https://appy.ai/subprocessors, provided Customer has been given the means to subscribe to notifications of changes to that page. Customer shall give notices under this DPA in writing to [email protected]. Customer is responsible for maintaining current and monitored contact details in its account, and AppyPeople is not liable for a failure to receive a notice sent to the details Customer has recorded.
| Data exporter | Data importer | |
|---|---|---|
| Name | Customer, being the entity identified in the account registration details for Customer's account on the Platform | AppyPeople, Inc. |
| Address | The address recorded in Customer's account or otherwise notified to AppyPeople | 68 SE 6th St, Apt 2704, Miami, FL 33131, United States |
| Contact | Customer's administrative or privacy contact as designated in the Platform | [email protected] |
| Activities relevant to the transfer | Use of the Platform to build and operate AI agents that process Customer Personal Data | Provision of the Platform, Support Services, and Professional Services |
| Role | Controller (Module Two) or Processor (Module Three) | Processor (Module Two) or Sub-processor (Module Three) |
| Item | Detail |
|---|---|
| Categories of Data Subjects | Customer's Administrative Users and Authorized Users; Customer's End Users; and any individual whose Personal Data is contained in content that Customer or its Authorized Users submit to or connect to the Platform, which may include Customer's employees, contractors, customers, prospects, suppliers, and correspondents. |
| Categories of Personal Data | Identifiers and contact details (name, email address, username, telephone number, job title, employer); authentication data; profile data received from a social or enterprise identity provider; message, document, and file content submitted to or retrieved by an AI agent, including any Personal Data it contains; prompts and inputs; outputs generated by an AI agent; data retrieved from third-party systems that Customer connects to the Platform; and technical and log data associated with the foregoing. The scope of Personal Data Processed is determined by Customer's configuration of the Platform and by the systems Customer chooses to connect. |
| Sensitive Personal Data | None. The Platform is not intended for Sensitive Personal Data and Customer is prohibited from submitting it under Sections 3.7 and 3.8. |
| Frequency of transfer | Continuous, for the duration of the Subscription Term. |
| Nature of Processing | Collection, receipt, recording, organisation, structuring, storage, retrieval, indexing, transmission to and processing by Third-Party AI Models, consultation, use, disclosure to Sub-processors, alignment, restriction, erasure, and destruction, in each case as necessary to provide the Platform. |
| Purpose of Processing | To provide, maintain, secure, and support the Platform, the Support Services, and any Professional Services in accordance with the Agreement and Customer's instructions, including operating AI agents configured by Customer and delivering their outputs through the interfaces Customer has connected. |
| Retention period | For the duration of the Subscription Term, and thereafter as provided in Section 10. Sub-processors retain data no longer than necessary to provide their services to AppyPeople. |
| Sub-processor processing | As set out in Annex III. |
Where Customer is established in the EEA, the Supervisory Authority of the Member State in which Customer is established. Where Customer is not established in the EEA but has designated a representative under Article 27 EU GDPR, the Supervisory Authority of the Member State in which that representative is established. Where Customer is not established in the EEA and has not designated a representative, the Supervisory Authority of the Member State in which the Data Subjects whose Personal Data is transferred are located.
| Measure | Description |
|---|---|
| Pseudonymisation and encryption | Customer Personal Data is encrypted in transit using TLS 1.2 or higher at the platform edge and on every internal and third-party connection (database, cache, object storage, APIs). Data at rest is encrypted by the hosting providers (Neon, AWS S3, Upstash) using AES-256 with provider-managed keys. Integration credentials and messaging tokens are additionally encrypted at the application layer using AES-256-GCM with a key held outside the database in the platform secret store. Customer-managed encryption keys are not currently offered. |
| Confidentiality, integrity, availability, and resilience | Production infrastructure is hosted in the United States: application compute on Vercel (Washington, D.C., iad1), the primary database on Neon (AWS us-east-1), object storage, email and event routing on AWS (us-east-1), model inference via Vercel AI Gateway and Google Cloud (us-central1). Customer tenants share a single database and schema; every tenant-owned record carries an organisation identifier, and isolation is enforced in the application layer by the authorisation framework and tenant-scoped queries, with the tenant identity derived solely from the authenticated session. Object storage uses shared buckets with per-tenant key prefixes and short-lived signed URLs. Realtime channels are per-tenant. |
| Restoring availability and access | The primary database uses continuous point-in-time recovery, allowing restoration to any moment within the preceding 7 days. Database storage is replicated by the provider. Object storage durability is provided by AWS S3. Neon does not rely on periodic scheduled snapshots for point-in-time recovery; write-ahead log records are captured continuously, allowing restoration to any second within the history window, so the recovery point objective is effectively zero. Daily snapshots are additionally retained for 15 days. Vercel supports rapid rollback to any previous production deployment, which can hold service while remediation work is performed. The recovery time objective is 24 hours. |
| Testing and assessment of effectiveness | Every change is gated by automated controls before reaching production: type checking, unit tests, formatting, database migration drift detection and automated policy review rules, with mandatory peer review on a protected main branch. Dependency vulnerability alerts are enabled, dependency updates are reviewed weekly, and a 7-day minimum release age is enforced on all new package versions. Production smoke tests run continuously and Content-Security-Policy violations are reported and monitored. Independent penetration testing is performed annually by Astra Security against a staging environment seeded with synthetic data, the most recent test being conducted on 30 July 2026. |
| User identification and authorisation | Source control requires unique named accounts with mandatory two-factor authentication. Production changes require a reviewed pull request and passing required checks on a protected branch that administrators cannot bypass. Accounts on the Platform are created and authenticated exclusively through Slack or Microsoft OAuth; AppyPeople does not operate a password database and does not store Authorized User credentials. Organisation roles (admin, member, guest) are applied within the Platform following authentication. Internal administrative access is restricted to company-domain identities. Production secrets are held in the hosting platform's encrypted environment store. Access to production environments is controlled via Google Workspace, which enforces two-factor authentication. Identity validation and access to information systems are monitored continuously by automated controls, with exceptions raised for remediation. Access is revoked on role change or termination by automated deprovisioning, ordinarily within one minute and in any event within one business day. Non-human identities, including service accounts, continuous integration runners, and automated engineering agents, are provisioned with scoped credentials held in the platform secret store, are recorded in the vendor and access registers, and are subject to the same review as named accounts. |
| Protection of data in transmission | All external network traffic is encrypted in transit using TLS. Service-to-service traffic within the production environment (application to database, cache, object storage, event bus and third-party APIs) is also encrypted in transit using TLS; there is no unencrypted internal hop. Production services do not rely on private network segmentation; access to each datastore is controlled by credentials held in the platform secret store and by TLS. |
| Protection of data in storage | Encryption at rest is applied by the respective providers to the primary database (Neon), object storage (AWS S3), the cache and pub/sub layer (Upstash Redis), message queues (Vercel Queue, AWS EventBridge), and log and error stores (Vercel, Sentry). Database point-in-time recovery history is held within the encrypted database storage. AppyPeople does not operate a vector database. |
| Physical security | Production infrastructure is hosted in third-party data centres operated by AppyPeople's cloud providers, which maintain independently audited physical security controls. AppyPeople is a fully remote organisation and maintains no data centre or office premises at which Customer Personal Data is stored. Endpoint controls are applied to personnel devices via Dr. Sprinto and Rippling. |
| Event logging | Application and security-relevant events, including authentication webhook verification failures and operational alerts, are logged to the hosting platform's log store and to a centralised error and tracing service (Sentry) with access restricted to authorised engineering staff. Every authenticated API request is traced with the acting user, organisation and operation. Alerting is configured for defined operational and security events. Log retention is 30 days in Vercel (Pro plan, Observability Plus) and 30 days in Sentry. |
| System configuration | Application configuration, database schema migrations, deployment settings and CI/CD pipelines are held in version control. AWS infrastructure is provisioned through infrastructure-as-code. All changes to production follow a change management process requiring a pull request, at least one independent peer review, and passing automated checks (type checking, unit tests, formatting, migration drift detection, policy rules) on a protected main branch that administrators cannot bypass. Production deployments are automatic on merge and can be rolled back to a previous deployment via Vercel. Managed serverless runtimes remove the need for operating system hardening; application hardening is enforced through security headers, a Content-Security-Policy, exact dependency pinning and a minimum dependency release age. |
| Governance and management | AppyPeople maintains an information security programme with a designated Information Security Officer, documented policies reviewed at least annually, a risk register and risk assessment process, security awareness training for all personnel at onboarding and annually thereafter, a documented incident response plan, and a vendor risk management process. |
| Data minimisation | The Platform collects the data necessary to provide the configured functionality. Customer controls what data is submitted and which third-party systems are connected, and can limit the scope of each connection. |
| Data quality | Customer retains the ability to access, correct, and delete Customer Personal Data through the Platform. AppyPeople does not independently modify Customer Personal Data other than as necessary to provide the Platform. |
| Limited retention | Log data is retained for 30 days in Vercel and Sentry. Database point-in-time recovery history is retained for 7 days and daily snapshots for 15 days. Retention periods are applied to AI agent conversation history and to object storage |
| Accountability | AppyPeople maintains records of processing activities, a sub-processor register, a data protection risk assessment process, and documented assignment of data protection responsibilities. |
| Portability and erasure | Customer can export Customer Personal Data in a structured, commonly used, machine-readable format and can delete it, through the Platform. Deletion on termination is addressed in Section 10. |
| Measures for Sub-processors | Sub-processors are subject to due diligence prior to engagement, written data protection terms no less protective than this DPA, and periodic review. A register of Sub-processors is maintained and published as provided in Annex III. |
AppyPeople engages the following Sub-processors to Process Customer Personal Data. All Processing takes place in the United States.
| Sub-processor | Purpose | Data processed | Location of processing |
|---|---|---|---|
| Amazon Web Services | Object storage (S3), email routing, and event broadcast (EventBridge) | All Customer Personal Data | United States |
| Vercel | Application hosting and compute, message queueing, log storage, and routing of model inference via Vercel AI Gateway | All Customer Personal Data | United States |
| Neon | Primary database — persistence and retrieval of Customer Personal Data | All Customer Personal Data | United States |
| Upstash ‡ | Cache and publish/subscribe layer | Customer Personal Data held transiently in cache and realtime channels | United States |
| Cloudflare | Content delivery, DNS, and network security in front of the Platform web application and the GraphQL endpoint | Data in transit to and from the protected endpoints, which may contain Customer Personal Data | United States |
| Anthropic | Third-Party AI Model inference | Prompts, inputs, and outputs, including any Personal Data they contain | United States |
| OpenAI | Third-Party AI Model inference | Prompts, inputs, and outputs, including any Personal Data they contain | United States |
| Google (Google Cloud AI) | Third-Party AI Model inference | Prompts, inputs, and outputs, including any Personal Data they contain | United States |
| xAI | Third-Party AI Model inference | Prompts, inputs, and outputs, including any Personal Data they contain | United States |
| Together AI | Third-Party AI Model inference | Prompts, inputs, and outputs, including any Personal Data they contain | United States |
| fal.ai | Third-Party AI Model inference | Prompts, inputs, and outputs, including any Personal Data they contain | United States |
| ElevenLabs | Speech synthesis for AI agent output | Text submitted for synthesis, including any Personal Data it contains | United States |
| AgentMail | Outbound and inbound email handling for AI agents | Recipient and sender contact details and message content | United States |
| Metabase | Analytics and reporting over Platform data | Customer Personal Data queried for operational reporting and support | United States |
| Sentry | Error and performance monitoring | Technical and log data, which may incidentally contain Personal Data | United States |
| Cognition (Devin) | Software engineering automation. Creates database branches containing point-in-time copies of production data, and receives production output shared by engineers during sessions | All Customer Personal Data present in the database when a branch is created, and any Customer Personal Data contained in output shared during a session | United States |
Excluded from this Annex
The following vendors appear in the internal vendor register but do not Process Customer Personal Data on AppyPeople's behalf, and are dealt with under Section 2.3 rather than listed here: GitHub (source control), Google Workspace (internal email, productivity, and control of AppyPeople staff access to production), Linear (internal ticketing), Rippling (human resources), Sprinto (compliance monitoring and endpoint management), Stripe (payment processing), and Astra Security (penetration testing conducted against a staging environment seeded with synthetic data).
PostHog processes Usage Data for AppyPeople's own operational purposes, for which AppyPeople is a Controller under Section 2.3, and is therefore excluded from this Annex. That data includes identifiers, so PostHog is disclosed in AppyPeople's Privacy Policy rather than here.
Slack and Microsoft are the sole means by which accounts are created and authenticated on the Platform. In that capacity they authenticate their own users and disclose identity claims to AppyPeople; they act as independent controllers rather than as Sub-processors of AppyPeople, and are not listed above on that basis. Where a Customer connects Slack or Microsoft Teams as a Delivery Channel, they are Connected Services authorised by that Customer and likewise are not Sub-processors of AppyPeople.
This DPA is effective without signature in accordance with Section A.2. This Schedule is provided solely for the convenience of Customers whose internal procurement or audit requirements call for a countersigned copy. Executing it records agreement to the terms published at https://appy.ai/dpa and does not vary them, extend them, or confer any right not otherwise available to every Customer.
| AppyPeople, Inc. | Customer |
|---|---|
| Signature: | Signature: |
| Name: | Name: |
| Title: | Title: |
| Date: | Date: |
| Entity name: | |
| Account email or workspace: | |
| Address: |