Data Processing Addendum

Last updated 30 August 2026

This Data Processing Addendum ("DPA") forms part of the agreement between LefamTech, Lda, operating Appvise ("Appvise"), and the customer using the service ("Customer"). It applies automatically when Appvise processes personal data on the Customer's behalf.

1. Roles and scope

"Customer Personal Data" means personal data in the prompts, apps, files, databases, or other Customer Content that Appvise processes for the Customer. For that data, the Customer is the controller and Appvise is the processor. If the Customer processes data for someone else, the Customer is a processor and Appvise is its sub-processor.

Appvise is an independent controller for account, billing, security, and service usage data that it handles for its own purposes under the Privacy Policy.

2. Instructions and Customer responsibilities

Appvise will process Customer Personal Data only to provide, secure, and support the service, as documented in the agreement and through the Customer's use and configuration of Appvise. The Customer is responsible for ensuring that its instructions are lawful, that it has a valid legal basis, and that it gives data subjects any required notice.

The Customer must not provide highly regulated data unless Appvise has confirmed in writing that the relevant service and plan support it.

3. Appvise commitments

Appvise will:

  • process Customer Personal Data only on documented instructions, including for international transfers, unless the law requires otherwise;
  • tell the Customer about a legal requirement before processing where the law permits;
  • ensure that authorised personnel are bound by confidentiality;
  • maintain appropriate technical and organisational security measures;
  • assist the Customer, taking account of the nature of the processing, with data subject requests and its obligations concerning security, breach notification, impact assessments, and regulator consultation;
  • notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data;
  • delete or return Customer Personal Data at the end of the service, at the Customer's choice, unless the law requires retention; and
  • provide information reasonably necessary to show compliance with this DPA and allow reasonable audits, subject to confidentiality and reasonable notice.

Appvise will promptly tell the Customer if, in our opinion, an instruction infringes applicable data-protection law.

4. Sub-processors

The Customer gives Appvise general written authorisation to use the sub-processors in Annex C. Appvise will require them to protect Customer Personal Data to a standard consistent with this DPA and remains responsible for their processing as required by law.

We may update Annex C. Where applicable law requires prior notice, we will email the Customer's account owner at least 15 days before a new sub-processor begins processing Customer Personal Data. The Customer may object during that period on reasonable data-protection grounds. We will work in good faith to resolve the objection; if we cannot, the Customer may stop using the affected feature.

5. International transfers

Each party will comply with the transfer rules that apply to it. When a transfer of Customer Personal Data from the European Economic Area to Appvise is not covered by an adequacy decision, the European Commission's Standard Contractual Clauses (Decision 2021/914) ("SCCs") are incorporated into this DPA.

Module Two applies where the Customer is a controller and Module Three where it is a processor. For Clause 9, Option 2 applies with 15 days' notice; the optional text in Clause 11 does not apply; under Clauses 17 and 18, Irish law and the courts of Ireland apply. Annexes A–C below complete the corresponding SCC annexes. The parties will apply any legally required UK or Swiss addendum or modification. The SCCs control if they conflict with this DPA.

6. Security and incidents

Appvise will maintain the measures in Annex B, taking account of the state of the art, implementation cost, the nature and risks of the processing, and the data the Customer chooses to submit. If a breach affects Customer Personal Data, our notice will include the information reasonably available to help the Customer meet its own obligations.

7. Return, deletion, and audit

During the agreement, the Customer may use available product controls to access or delete data. After termination or account deletion, Appvise will delete Customer Personal Data from active systems and allow residual copies in backups and logs to expire, unless retention is required by law.

An audit must not unreasonably disrupt the service or expose another customer's data. The Customer will first use current security documentation and questionnaires where they can meet the request. On-site audits require reasonable advance notice and are limited to once a year unless a regulator or confirmed incident requires more.

8. Term and liability

This DPA remains in effect while Appvise processes Customer Personal Data. The liability limits and governing-law terms in the main agreement apply to this DPA, except where applicable data-protection law or the SCCs require otherwise.

Annex A · Processing details

PartiesThe data exporter is the Customer and the data importer is LefamTech, Lda. Their contact details are those in the agreement, order, or account records; Appvise's privacy contact is privacy@appvise.ai. Each party is deemed to sign the SCCs when this DPA becomes binding.
Subject matterProviding the Appvise app-building, hosting, and data service
DurationThe agreement term plus the deletion period described above
FrequencyContinuous or as initiated by the Customer and its end-users
Nature and purposeCollecting, storing, organising, retrieving, transmitting, hosting, generating, securing, and deleting data to provide and support Appvise and the apps the Customer configures
Data subjectsThe Customer's personnel, contractors, clients, app end-users, and other people whose data the Customer submits
Personal dataData chosen by the Customer, which may include names, contact and account details, identifiers, app records, messages, prompts, files, images, technical data, and authentication data
Sensitive dataNot intended unless Appvise has confirmed support in writing; any such data is determined and controlled by the Customer
Supervisory authorityDetermined under Clause 13 of the SCCs

Annex B · Security measures

  • encryption in transit for client-to-service and service-to-service traffic;
  • role-based access controls and separation between customer projects;
  • scoped upload links and controlled paths for stored files;
  • encrypted handling of connection credentials and managed environment secrets;
  • logging, error monitoring, rate limits, and incident-response procedures;
  • software review, dependency management, and restricted production access; and
  • account, project, and asset deletion procedures.

Annex C · Approved sub-processors

An AI provider receives Customer Personal Data only when the relevant model or feature is used.

Sub-processorPurposeLocation
Cloudflare, Inc.Hosting, compute, storage, database, network, email, and AI gatewayGlobal network / United States
Anthropic, PBCAI inference for app generation and repairUnited States
Google LLCAI inference, image processing, and optional Google sign-inGlobal infrastructure / United States
OpenAI, L.L.C.Managed image generationUnited States
Fireworks.ai, Inc.AI inference for app generationUnited States
Functional Software, Inc. (Sentry)Error and performance monitoringUnited States
PostHog, Inc.Product analytics; app record content is not intentionally collectedEuropean Union hosting / United States company

Questions or objections: privacy@appvise.ai.

← Back to Appvise