Skip to content
NewIntroducing Reply Quality monitors

Data Processing Agreement

How the Provider processes personal data on the Customer's behalf.

Last updated: 6 September 2026
Effective date: 6 September 2026

This Data Processing Agreement (“DPA”) forms part of the agreement governing the Customer's use of the Service and applies only where and to the extent that the Provider Processes Customer Personal Data on behalf of the Customer.

1. Parties, Scope and Roles

This DPA forms part of the agreement between the Provider and the Customer governing the Customer's use of the Service, comprising the AppReply Terms of Service together with any applicable Order Form, invoice, checkout terms and other written commercial agreement expressly accepted by the Provider (collectively, the “Main Agreement”). The AppReply Terms of Service form part of the Main Agreement in all cases. References in this DPA to the Main Agreement are references to that agreement excluding this DPA. Where a term is defined in more than one component of the Main Agreement, the AppReply Terms of Service govern unless a separately signed agreement expressly states otherwise.

This DPA is entered into between Rasliak Labs, a sole proprietorship registered in Norway under organisation number 935 367 352, with VAT number NO 935 367 352 MVA and registered address at Bøkkerveien 16A, 0579 Oslo, Norway (the “Provider”), and the customer that has entered into the Main Agreement with the Provider (the “Customer”).

In respect of Processing under this DPA, the Customer acts as Controller, or as processor on behalf of a third-party controller, and the Provider acts as Processor, or as a sub-processor to the Customer, as applicable. For the avoidance of doubt, the Provider is not a “Subprocessor” as that term is defined in Section 2.

This DPA applies where and to the extent that the Provider Processes Customer Personal Data on behalf of the Customer in connection with the Service.

This DPA does not apply to Personal Data that the Provider Processes as an independent Controller for its own purposes, including business relationship administration, billing and accounting, customer communications, product and service analytics and improvement, security, fraud prevention, legal compliance, and the operation and protection of the Provider's business. The Provider's Processing of such Personal Data is described in the AppReply Privacy Policy and is subject to Applicable Data Protection Law.

The Provider's independent-Controller Processing under the preceding paragraph is limited to (i) Personal Data of the Customer's account holders, billing contacts and business contacts, (ii) authentication, access, audit, security and diagnostic records generated by the Provider's own systems, and (iii) usage telemetry and service-operation metadata. The Provider does not Process Customer Personal Data, including Platform Data, Review Data and Customer Content Processed on the Customer's behalf, as an independent Controller, and will not convert such data to independent-Controller Processing, except where required to do so by applicable law. The Provider does not act as a joint Controller with the Customer in respect of the Service.

This DPA also does not apply to information that is not Personal Data under Applicable Data Protection Law.

This DPA becomes effective when the Main Agreement becomes effective and applies to all Processing of Customer Personal Data carried out by the Provider on the Customer's behalf, including any such Processing carried out before that date. This DPA has no effect except in conjunction with a Main Agreement in force between the parties, and every reference in this DPA to the Main Agreement, including in Section 13, is a reference to the Main Agreement applicable to the Customer.

No separate signature is required unless the parties expressly agree otherwise in writing.

2. Definitions

For purposes of this DPA:

“Applicable Data Protection Law” means the data-protection and privacy laws applicable to the Processing of Customer Personal Data under this DPA, including, where applicable, Regulation (EU) 2016/679 (“GDPR”), the Norwegian Personal Data Act (personopplysningsloven), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection (“FADP”), and other applicable laws implementing, supplementing or relating to data protection and privacy.

“Customer Personal Data” means Personal Data Processed by the Provider on behalf of the Customer in connection with the Service.

“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data transmitted, stored or otherwise Processed.

“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of Personal Data to third countries adopted by the European Commission under Commission Implementing Decision (EU) 2021/914, as amended, replaced or superseded from time to time.

“Subprocessor” means a third party engaged by the Provider to Process Customer Personal Data on behalf of the Customer in connection with the Service.

“Controller”, “Data Subject”, “Personal Data”, “Processing”, “Process”, “Processed”, “Processor” and “Supervisory Authority” have the meanings given to them under Applicable Data Protection Law.

“Service” has the meaning given in the Main Agreement.

Capitalised terms not defined in this DPA have the meanings given in the Main Agreement.

References in this DPA to a Section or an Annex are references to a Section or Annex of this DPA unless expressly stated otherwise. References to a provision of the Main Agreement or the AppReply Terms of Service are identified as such.

3. Processing and Instructions

The Provider will Process Customer Personal Data only as necessary to provide the Service and in accordance with the Customer's documented instructions, this DPA, the Main Agreement and Applicable Data Protection Law.

The Customer's documented instructions include:

  • a. the Main Agreement and this DPA;
  • b. the Customer's configuration and use of the Service, including the Customer's continued use of the Service after the Provider has given notice of a new or changed feature, setting or default that operates within the purposes, categories of Customer Personal Data and scope of Processing described in Annex 1; a new or changed feature, setting or default that materially expands that Processing requires the Customer's affirmative selection or acceptance;
  • c. applications, accounts, integrations and data sources connected or selected by the Customer;
  • d. features, automation settings and functionality enabled or configured by the Customer;
  • e. requests and instructions submitted through functionality made available by the Service;
  • f. written instructions expressly accepted by the Provider;
  • g. the transfer of Customer Personal Data to and Processing by authorised Subprocessors in accordance with Sections 6 and 11 and Annex 3;
  • h. the production of anonymous information in accordance with Section 7.8 of the AppReply Terms of Service, limited to the aggregation or anonymisation of Customer Personal Data within the Provider's systems and to what is necessary to produce the anonymous output; information anonymised in accordance with that Section is not Customer Personal Data and is not subject to Section 12;
  • i. the Provider's exercise of the content-removal, transparency, protective, security, abuse-prevention and service-management measures described in Sections 7.5, 7.7, 9.1, 9.2 and 11 of the AppReply Terms of Service, which the Customer instructs the Provider to perform as part of the operation of the Service; and
  • j. the baseline analysis described in Annex 1, Section C, which the Customer instructs by connecting an application or data source to the Service and which does not require the Customer to enable a separate feature.

The subject matter, duration, nature and purpose of the Processing, types of Customer Personal Data and categories of Data Subjects are described in Annex 1.

The Provider will not Process Customer Personal Data for purposes unrelated to providing the Service on behalf of the Customer, except where required by applicable law.

Where applicable law requires the Provider to Process Customer Personal Data other than on the Customer's documented instructions, the Provider will inform the Customer of that legal requirement before the Processing unless applicable law prohibits such notice.

The Provider will immediately inform the Customer if, in the Provider's opinion, an instruction infringes Applicable Data Protection Law.

The Provider may refuse or suspend affected Processing where an instruction:

  • a. infringes Applicable Data Protection Law;
  • b. exceeds the agreed scope or supported functionality of the Service;
  • c. conflicts with the Main Agreement or this DPA;
  • d. would require the Provider to assume additional legal, regulatory, technical or operational obligations not contemplated by the Main Agreement or this DPA; or
  • e. cannot reasonably be implemented using the Service or the Provider's existing technical and organisational arrangements.

The Provider is not required to develop new functionality, modify its infrastructure, enter into additional third-party agreements, obtain certifications or assume additional regulatory status in order to comply with an instruction unless expressly agreed in writing.

4. Customer Obligations

The Customer is responsible for ensuring that its collection, use, disclosure and other Processing of Customer Personal Data, and its instructions to the Provider, comply with Applicable Data Protection Law.

Without limiting the foregoing, the Customer is responsible for:

  • a. establishing and maintaining an appropriate lawful basis for the Processing of Customer Personal Data;
  • b. providing all notices, disclosures and information required to be provided to Data Subjects;
  • c. obtaining all consents, permissions, rights and authorisations required for the Customer's use of the Service and for the Provider to Process Customer Personal Data on the Customer's behalf;
  • d. ensuring that Customer Personal Data and the Customer's instructions are lawful, appropriate and within the scope of the Main Agreement and this DPA;
  • e. ensuring that it has all necessary rights and authority to connect applications, accounts, integrations, digital distribution platforms and other data sources to the Service;
  • f. ensuring that its collection and use of Personal Data obtained through Third-Party Services complies with applicable law and applicable third-party terms and policies;
  • g. determining whether the Service and the Customer's configuration, instructions, automation and use of the Service are appropriate for the Customer's legal, regulatory and data-protection requirements;
  • h. responding to Data Subjects and Supervisory Authorities, except to the extent that the Provider is expressly required to assist under this DPA or Applicable Data Protection Law;
  • i. ensuring that the Customer does not intentionally use the Service for categories of Personal Data that the Service is not designed or expressly agreed to support;
  • j. maintaining appropriate security and access controls for accounts, systems, credentials, devices and environments under the Customer's control; and
  • k. promptly informing the Provider where the Customer becomes aware that an instruction, configuration or use of the Service may violate Applicable Data Protection Law.

Where the Customer acts as Processor on behalf of a third-party Controller, the Customer represents that:

  • a. it is authorised by that Controller to engage the Provider to Process Customer Personal Data on the Customer's behalf;
  • b. its instructions to the Provider are consistent with the Controller's instructions and the Customer's obligations to that Controller; and
  • c. it has authority to enter into this DPA on behalf of the relevant Processing arrangement.

The Customer remains responsible for the accuracy, quality and legality of Customer Personal Data and for the means by which Customer Personal Data was obtained.

5. Provider Obligations as Processor

The Provider will:

  • a. Process Customer Personal Data only on documented instructions from the Customer, except where Processing is required by applicable law;
  • b. ensure that persons authorised by the Provider to Process Customer Personal Data are subject to appropriate confidentiality obligations;
  • c. implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data, as described in Annex 2;
  • d. comply with Section 6 when engaging Subprocessors;
  • e. taking into account the nature of the Processing and functionality available through the Service, provide reasonable assistance to the Customer with Data Subject requests to the extent required by Applicable Data Protection Law;
  • f. provide reasonable assistance to the Customer, taking into account the nature of the Processing and information available to the Provider, in relation to security of Processing, Personal Data Breaches, data protection impact assessments and prior consultation with Supervisory Authorities, to the extent required by Applicable Data Protection Law;
  • g. upon termination of the relevant Processing, delete or return Customer Personal Data in accordance with Section 12, unless retention is required by applicable law; and
  • h. make available information reasonably necessary to demonstrate compliance with the Provider's obligations under this DPA, subject to Section 10.

The obligations in this Section apply only to the extent required by Applicable Data Protection Law and taking into account the nature of the Service, Processing and information available to the Provider.

6. Subprocessors

6.1 General Authorisation

The Customer provides the Provider with general written authorisation to engage Subprocessors to Process Customer Personal Data in connection with the Service.

The Provider may appoint, replace or remove Subprocessors from time to time in accordance with this Section.

The Provider's current Subprocessors are listed in Annex 3.

6.2 Changes to Subprocessors

The Provider will provide reasonable advance notice of an intended addition or replacement of a Subprocessor that will Process Customer Personal Data. The Provider will not permit the new or replacement Subprocessor to Process Customer Personal Data before the objection period in this Section has expired or, where an objection is received, before that objection has been resolved under Section 6.3.

Where the Provider must engage a replacement Subprocessor on an emergency basis to maintain the availability, security or lawfulness of the Service, including where an existing Subprocessor becomes unavailable, suffers a security incident or discontinues its service, or where continued use of an existing Subprocessor would breach applicable sanctions, export controls or a binding legal requirement, the Provider may engage that Subprocessor immediately and will give notice as soon as reasonably practicable and in any event within five (5) business days. The Customer's objection right under this Section applies from the date of that notice and Section 6.3 applies to any resulting objection.

Notice may be provided by email, through the Service, by updating Annex 3 together with an electronic notice, or by another reasonable electronic method.

The Customer may object to the appointment of a new Subprocessor on reasonable grounds relating specifically to the protection of Customer Personal Data.

Any objection must:

  • a. be submitted in writing within ten (10) calendar days after the Customer receives notice of the proposed change; and
  • b. describe the specific and documented data-protection grounds for the objection.

If the Customer does not object within that period, the proposed Subprocessor will be deemed accepted.

6.3 Subprocessor Objections

Where the Customer raises a valid objection under Section 6.2, the parties will use reasonable efforts to resolve the objection.

The Provider may, at its discretion:

  • a. elect not to appoint the proposed Subprocessor;
  • b. take reasonable measures to address the Customer's data-protection concerns;
  • c. provide an available alternative configuration or arrangement that avoids the use of the proposed Subprocessor; or
  • d. discontinue the affected functionality or permit termination of the affected Service where the objection cannot reasonably be resolved.

The Customer has no general right to prohibit the appointment or replacement of a Subprocessor for reasons unrelated to the protection of Customer Personal Data.

A valid objection does not oblige the Provider to discontinue the affected functionality or the affected Service. If the Provider terminates an affected paid Service solely because the Provider cannot reasonably accommodate a valid Subprocessor objection, such termination will be treated as a termination by the Provider without Customer breach under Section 12.4 of the AppReply Terms of Service, and the prorated refund in that Section will apply. This DPA does not otherwise create any right to a refund, credit or reimbursement arising from an objection to a Subprocessor, and any other financial consequences are governed by the Main Agreement except where Applicable Data Protection Law requires otherwise.

6.4 Subprocessor Obligations

Before permitting a Subprocessor to Process Customer Personal Data, the Provider will impose on that Subprocessor the data-protection obligations required by Article 28(4) GDPR, to the extent applicable to the Subprocessor's Processing.

The Provider remains responsible for the performance of its Subprocessors' data-processing obligations to the extent required by Applicable Data Protection Law and subject to Section 13 and the liability provisions of the Main Agreement.

7. Security

The Provider will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data.

Such measures will take into account the state of the art, implementation costs, nature, scope, context and purposes of the Processing, and the risks to the rights and freedoms of Data Subjects.

The measures applicable to the Service are described in Annex 2.

The Provider may update or modify its technical and organisational measures to reflect:

  • a. technical developments;
  • b. changes to the Service or Subprocessors;
  • c. identified risks;
  • d. security improvements;
  • e. operational requirements; or
  • f. applicable legal requirements,

provided that such changes do not materially reduce the overall level of protection for Customer Personal Data.

The Customer is responsible for security within systems, accounts, devices and environments under its control, including:

  • a. protecting credentials;
  • b. managing authorised-user access;
  • c. configuring the Service appropriately;
  • d. granting only necessary permissions;
  • e. maintaining the security of connected Third-Party Accounts and integrations; and
  • f. promptly revoking access that is no longer required.

No method of electronic transmission, storage or Processing can be guaranteed to be completely secure. The Provider's obligations under this DPA are obligations to implement and maintain appropriate measures and do not constitute a guarantee that a security incident or Personal Data Breach will never occur.

8. Personal Data Breaches

The Provider will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

The notification will include, to the extent reasonably available to the Provider and required by Applicable Data Protection Law:

  • a. a description of the nature of the Personal Data Breach;
  • b. the categories of affected Customer Personal Data and Data Subjects where reasonably ascertainable;
  • c. the likely consequences of the Personal Data Breach;
  • d. measures taken or proposed to investigate, contain, remediate or mitigate the Personal Data Breach; and
  • e. available contact information for further communication.

Information may be provided in phases as it becomes reasonably available.

The Provider will take reasonable measures to investigate, contain and mitigate a Personal Data Breach within systems and environments under the Provider's control.

The Customer will reasonably cooperate where investigation or mitigation requires information or action relating to systems, accounts, integrations, configurations or environments controlled by the Customer.

The Customer is responsible for determining whether notification to a Supervisory Authority, Data Subjects or another person is required and for making notifications required of the Customer by Applicable Data Protection Law.

The Provider will provide reasonable assistance to the extent required by Applicable Data Protection Law.

The Provider will not notify a Supervisory Authority or affected Data Subjects on the Customer's behalf unless:

  • a. required by applicable law; or
  • b. expressly agreed in writing.

Notification, investigation, cooperation or remedial action relating to a Personal Data Breach does not constitute an admission by the Provider of fault, liability or breach of this DPA or the Main Agreement.

The Customer is responsible for maintaining current contact information through which the Provider can provide security or Personal Data Breach notices.

9. Data Subject and Regulatory Assistance

If the Provider receives a request directly from a Data Subject relating to Customer Personal Data, the Provider may:

  • a. direct the Data Subject to the Customer; or
  • b. forward the request to the Customer.

The Provider will not independently determine or fulfil the request on the Customer's behalf unless instructed by the Customer, expressly agreed in writing, or required by applicable law.

Taking into account the nature of the Processing and functionality available through the Service, the Provider will provide reasonable assistance to the Customer with Data Subject requests to the extent required by Applicable Data Protection Law.

The Customer remains responsible for:

  • a. verifying the requester's identity and authority;
  • b. determining the validity and scope of the request;
  • c. determining applicable limitations or exceptions;
  • d. determining the appropriate response; and
  • e. communicating the final response to the Data Subject.

The Provider will also provide reasonable assistance, taking into account the nature of the Processing and information available to the Provider, with:

  • a. data protection impact assessments;
  • b. prior consultations with Supervisory Authorities; and
  • c. binding requests from competent Supervisory Authorities,

to the extent required by Applicable Data Protection Law.

The Customer remains responsible for determining whether such assessments, consultations, notifications or regulatory actions are required and for its overall compliance with Applicable Data Protection Law.

Where the Customer requests assistance materially beyond the Provider's obligations under Applicable Data Protection Law or the ordinary functionality of the Service, the Provider may charge reasonable fees reflecting the time and resources required.

The Provider will inform the Customer of such fees in advance where reasonably practicable.

No additional fee will apply to the extent that the assistance is required directly because of the Provider's material breach of this DPA or Applicable Data Protection Law.

10. Audits and Demonstration of Compliance

The Provider will make available information reasonably necessary to demonstrate compliance with its obligations under this DPA.

Where reasonably sufficient, the Provider may satisfy this obligation through available:

  • a. documentation;
  • b. policies;
  • c. security information;
  • d. audit or assessment reports;
  • e. certifications held by the Provider or relevant service providers; or
  • f. other appropriate compliance materials.

If the information made available by the Provider is not reasonably sufficient to satisfy the Customer's rights under Applicable Data Protection Law, the Customer may request an audit relating specifically to the Provider's Processing of Customer Personal Data.

Except where otherwise required by Applicable Data Protection Law or a competent Supervisory Authority, any audit must:

  • a. be requested on reasonable prior written notice;
  • b. occur during normal business hours;
  • c. minimise disruption to the Provider's business;
  • d. be limited to matters reasonably necessary to assess compliance with this DPA;
  • e. use documentary or remote review methods where reasonably sufficient;
  • f. not expose data relating to other customers;
  • g. not compromise the security, confidentiality, intellectual property or trade secrets of the Provider or any third party;
  • h. not include penetration testing, vulnerability scanning, source-code inspection or other intrusive technical testing without the Provider's prior written agreement; and
  • i. be conducted by the Customer or an independent auditor that is not a competitor of the Provider and is subject to appropriate confidentiality obligations.

Unless required by a competent Supervisory Authority or Applicable Data Protection Law, or unless the Customer has reasonable documented grounds to believe that the Provider has materially breached this DPA, the Customer may request no more than one audit in any twelve-month period.

The Customer will bear its own audit and professional-adviser costs.

The Provider may charge reasonable personnel, administrative and professional-adviser costs incurred in connection with a Customer-requested audit, except where prohibited by Applicable Data Protection Law or where the audit demonstrates a material breach of this DPA by the Provider.

The Provider may require advance agreement regarding the scope, timing, method and estimated costs of an audit.

Nothing in this Section limits the lawful investigative or audit powers of a competent Supervisory Authority.

11. International Data Transfers

The Customer acknowledges and instructs that Customer Personal Data may be Processed by authorised Subprocessors located in, or accessing Customer Personal Data from, jurisdictions outside Norway or the European Economic Area (“EEA”) where reasonably necessary to provide the Service.

The Provider will ensure that any transfer of Customer Personal Data subject to international-transfer restrictions under Applicable Data Protection Law uses a lawful transfer mechanism.

Where a valid adequacy decision applies, the Provider may rely on that decision.

Where an adequacy decision is not available, the Provider may rely on:

  • a. the SCCs;
  • b. an applicable UK international-transfer mechanism;
  • c. an applicable Swiss international-transfer mechanism;
  • d. another valid contractual, organisational or certification-based safeguard; or
  • e. another lawful transfer mechanism recognised under Applicable Data Protection Law.

Where SCCs or another transfer mechanism are used in relation to a Subprocessor, the Provider will require the applicable Subprocessor to implement the safeguards required by Applicable Data Protection Law.

The Provider may update or replace an international-transfer mechanism where:

  • a. required by law;
  • b. the existing mechanism is invalidated, withdrawn or materially changed; or
  • c. another lawful transfer mechanism becomes available.

The Provider will implement supplementary technical, contractual or organisational measures where required by Applicable Data Protection Law.

If SCCs or another transfer instrument are legally required directly between the Customer and the Provider in a particular case, the parties will cooperate to complete the applicable module, addendum or required annexes.

Nothing in this Section requires use of SCCs or another transfer mechanism where the relevant transfer is not a restricted international transfer under Applicable Data Protection Law.

The locations and transfer information relating to current Subprocessors are described in Annex 3.

Where the Customer instructs or enables the Service to publish replies or other content to, or otherwise transmit Customer Personal Data to, a connected Third-Party Service, the Provider transmits the relevant Customer Personal Data to that Third-Party Service on the Customer's instruction. The operator of a connected Third-Party Service may act as an independent Controller in respect of Personal Data it receives and Processes on its own platform and is not a Subprocessor for the purposes of this DPA. The Customer is responsible for establishing a lawful basis and, where applicable, a lawful transfer mechanism for that disclosure.

12. Data Return and Deletion

Upon termination or expiration of the Service involving Processing of Customer Personal Data, the Provider will, at the Customer's choice, delete or return Customer Personal Data Processed on behalf of the Customer.

The Customer may exercise that choice at any time during the seven (7) calendar days following termination or expiration (the “Retrieval Period”). During the Retrieval Period, Customer Personal Data remains available for ordinary export or read-only retrieval through functionality made available by the Service, and the Provider will not delete Customer Personal Data from active systems other than on the Customer's instruction or where required by applicable law.

Where export functionality is ordinarily available through the Service, the Provider may satisfy a request for return by making Customer Personal Data available through that functionality during the Retrieval Period. Where such functionality is not available, the Provider will return Customer Personal Data in a commonly used electronic format, subject to the fees described below.

If the Customer does not exercise its choice before the end of the Retrieval Period, the Provider will delete Customer Personal Data from active systems within a reasonable period thereafter. The Provider does not retain Customer Personal Data under internal retention practices beyond the periods described in this Section.

Where applicable law requires retention, the Provider may retain the minimum Customer Personal Data required and will Process such data only for the legally required purpose and duration.

Customer Personal Data contained in backups or disaster-recovery systems may remain for a limited period after deletion from active systems until the relevant backup is overwritten, rotated or otherwise deleted through the Provider's ordinary backup lifecycle, as described in Annex 2.

During that period, Customer Personal Data retained solely in backups will not be Processed for ordinary Service purposes and will remain subject to applicable security protections.

The Provider is not required to reconstruct, recreate or restore Customer Personal Data already deleted in accordance with this DPA and applicable retention practices. Backup copies are not made available for Customer export or retrieval.

Where return, migration or export requires material work beyond functionality ordinarily provided through the Service, the Provider may charge reasonable fees after informing the Customer in advance where reasonably practicable.

No additional fee will apply to the extent that such work is required directly because of the Provider's material breach of this DPA or Applicable Data Protection Law.

13. Liability

13.1 Application of Main Agreement Liability Limits

To the fullest extent permitted by Applicable Data Protection Law and other applicable law, the Provider's total liability to the Customer arising out of or relating to this DPA, whether in contract, tort, under statute or otherwise, including any claim for recourse or contribution under Article 82(5) GDPR, is subject to the exclusions, limitations and aggregate liability cap set out in the Main Agreement.

Claims arising under or relating to this DPA, including claims concerning privacy, data protection, security incidents, Personal Data Breaches, Subprocessors or international transfers, do not create a separate or additional liability cap.

13.2 Aggregate Liability

Any liability of the Provider to the Customer arising under or relating to this DPA will be aggregated with, and not be in addition to, liability arising under the Main Agreement for purposes of calculating the applicable liability cap.

The number of:

  • a. claims;
  • b. affected Data Subjects;
  • c. Processing activities;
  • d. Personal Data Breaches;
  • e. Subprocessors;
  • f. incidents; or
  • g. legal grounds

does not increase the applicable aggregate liability cap.

13.3 Customer Responsibility

To the fullest extent permitted by applicable law, the Provider is not responsible to the extent that any claim, loss, penalty, cost, damage, regulatory matter or other liability results from:

  • a. the Customer's unlawful or unauthorised instructions;
  • b. the Customer's lack of a lawful basis, consent, notice, permission, right or authority;
  • c. the Customer's breach of Applicable Data Protection Law;
  • d. inaccurate, unlawful or improperly obtained Customer Personal Data;
  • e. systems, accounts, devices, credentials, integrations, configurations or environments under the Customer's control;
  • f. the Customer's failure to implement appropriate security or access controls;
  • g. acts or omissions of the Customer or its authorised users; or
  • h. Processing that the Provider performed in accordance with the Customer's specific instructions under Section 3(e) or 3(f), other than the engagement of Subprocessors, for which Section 6.4 applies.

13.4 Mandatory Rights and Customer Indemnification

Nothing in this DPA limits or excludes:

  • a. rights of Data Subjects;
  • b. powers of competent Supervisory Authorities; or
  • c. liability that cannot lawfully be limited or excluded.

Nothing in this DPA limits or reduces the Customer's indemnification obligations under the Main Agreement.

13.5 Claims by Third-Party Controllers

Where the Customer acts as processor on behalf of a third-party controller, the Customer will:

  • a. ensure that its arrangements with that controller do not give the controller rights against the Provider exceeding those the Customer has under this DPA and the Main Agreement;
  • b. bring any claim relating to that controller's Personal Data in its own name; and
  • c. indemnify and hold harmless the Provider against any claim, demand, recourse or contribution asserted directly against the Provider by that controller, including under Article 82(5) GDPR, to the extent it exceeds the amount for which the Provider would have been liable to the Customer under this Section 13 had the Customer brought the same claim, except to the extent that liability cannot lawfully be limited or excluded.

14. Term and General Provisions

14.1 Term and Effect of Termination

This DPA remains in effect for as long as the Provider Processes Customer Personal Data on behalf of the Customer, and thereafter to the extent provided in Section 14.5.

Termination, cancellation or expiration of the Main Agreement will not terminate this DPA to the extent that the Provider continues Processing Customer Personal Data for deletion, return, backup lifecycle, legal compliance or another purpose permitted by this DPA and Applicable Data Protection Law.

Payment obligations and rights or liabilities accrued before termination remain unaffected. Termination under this Section does not release the Customer from any minimum commitment, committed term or committed spend agreed in an Order Form, invoice commitment or other written commercial agreement, which remains payable in full unless Applicable Data Protection Law requires otherwise.

Where the Provider materially fails to comply with this DPA, or can no longer provide the guarantees required under Article 28(1) GDPR, the Customer may terminate the affected Processing, and the affected Service to the extent necessary to comply with Applicable Data Protection Law, provided that, where the failure is capable of remedy, the Customer has first given the Provider written notice specifying the failure in reasonable detail and the Provider has not remedied it within thirty (30) days of receipt. No cure period applies where the failure is not capable of remedy, where continuation of the Processing would be unlawful, or where a competent Supervisory Authority or court requires the Processing to cease earlier.

Where a termination under the preceding paragraph ends a paid Service, that termination will be treated as a termination by the Provider without Customer breach under Section 12.4 of the AppReply Terms of Service. The Provider will refund the prepaid fees for the unused portion of the terminated Service, prorated from the effective date of termination, and that refund is the Customer's sole refund or credit consequence of the termination itself. Any claim for the underlying failure remains subject to Section 13.

This DPA does not otherwise create a right for the Customer to cancel or terminate the Service or to obtain a refund, credit or reimbursement except where such right is expressly provided by the Main Agreement or required by Applicable Data Protection Law.

14.2 Order of Precedence

In the event of conflict, the order of precedence set out in Section 21.2 of the AppReply Terms of Service applies. For the avoidance of doubt:

  • a. the SCCs or another mandatory transfer instrument, where applicable, prevail to the extent required by their terms;
  • b. this DPA prevails over the Main Agreement solely with respect to the Processing and protection of Customer Personal Data, other than fees, charges, costs, refunds, limitations or exclusions of liability, indemnification and intellectual property, which are governed by paragraph (c); and
  • c. the Main Agreement prevails in all other respects, including fees, subscriptions, refunds, intellectual property, Service availability (except in respect of the availability and resilience of Processing systems to the extent required by Article 32 GDPR or an equivalent requirement of Applicable Data Protection Law), indemnification and limitations of liability, except where Applicable Data Protection Law requires otherwise.

14.3 Customer Documents

Section 21.3 of the AppReply Terms of Service applies to any document supplied by or on behalf of the Customer and governs whether and how such a document may modify this DPA. No such document modifies this DPA or imposes additional obligations on the Provider except as provided in that Section.

14.4 Changes to this DPA

The Provider may update this DPA to reflect changes in:

  • a. Applicable Data Protection Law;
  • b. regulatory requirements;
  • c. the Service;
  • d. Processing operations;
  • e. Subprocessors;
  • f. transfer mechanisms; or
  • g. technical and organisational measures.

Changes to Subprocessors are subject to Section 6.

The Provider will publish the updated DPA at appreply.co/dpa with a revised “Last updated” date. Where an update materially affects the Customer's rights or obligations under this DPA, the Provider will provide reasonable prior notice by email to the Customer's designated contact address or through the Service, and the update will take effect on the stated effective date. All other updates take effect on publication.

The Customer's continued use of the Service after the effective date of an updated DPA constitutes acceptance of the updated DPA. Where a change to this DPA also constitutes a material change to the AppReply Terms of Service, Section 21.1 of the AppReply Terms of Service applies in addition to this Section.

No update will materially reduce the data-protection obligations required of the Provider under Applicable Data Protection Law or authorise Processing contrary to the Customer's documented instructions. The Provider will maintain dated prior versions of this DPA and will make the version applicable to a given period available to the Customer on request.

14.5 Governing Law, Assignment and Miscellaneous

Except where the SCCs, another mandatory transfer mechanism or Applicable Data Protection Law require otherwise, this DPA is governed by the governing-law and dispute-resolution provisions of the Main Agreement.

This DPA may be assigned or transferred together with the Main Agreement in accordance with the assignment and business-reorganisation provisions of the Main Agreement.

If any provision of this DPA is invalid, unlawful or unenforceable, that provision will be limited or removed only to the extent necessary and the remaining provisions will continue in effect.

A failure or delay by the Provider to exercise a right under this DPA does not constitute a waiver of that right.

Sections 4, 10, 12, 13, 14.2, 14.3 and 14.5 survive termination or expiration of this DPA and of the Main Agreement, and continue in effect notwithstanding that the Provider has ceased all Processing of Customer Personal Data. Section 13 survives without limit of time in respect of any claim relating to Processing performed while this DPA was in effect. Other provisions that by their nature should survive termination will survive for as long as necessary to give effect to their purpose.

Except for Data Subjects and Supervisory Authorities to the extent of rights and powers conferred on them by Applicable Data Protection Law, and except for third-party beneficiaries expressly designated by the SCCs where the SCCs have been entered into by the Provider in accordance with Section 11, this DPA does not confer any right, benefit or remedy on any person other than the Provider and the Customer. No third-party controller on whose behalf the Customer acts as processor acquires any right against the Provider under this DPA, and the Customer is solely responsible to that controller in respect of the Processing.

Questions or notices relating to this DPA may be sent to help@appreply.co.

Annex 1: Details of Processing

A. Subject Matter

Processing of Customer Personal Data as reasonably necessary to provide, operate, support and secure the Service, including mobile app-store intelligence, review management, analytics, AI-assisted functionality, generation and publication of replies, connected integrations, workspace functionality and related Service features.

B. Duration

For the duration of the Customer's use of the relevant Service and thereafter only for as long as reasonably necessary for deletion, return, ordinary backup lifecycle, legal compliance or another purpose permitted by this DPA and Applicable Data Protection Law.

C. Nature and Purpose of Processing

Depending on the Customer's use and configuration of the Service, Processing may include:

  • a. retrieving, receiving, storing, organising and displaying Platform Data containing Personal Data;
  • b. retrieving and organising app-store reviews and ratings;
  • c. analysing, classifying, categorising, embedding, sentiment-scoring and summarising review and other Platform Data, including free-text review content and reviewer identifiers, using authorised AI Subprocessors; where the Customer's plan or trial includes analytics functionality, this baseline analysis is an inherent part of the Service, begins when the Customer connects an application or data source, and does not require the Customer to enable a separate feature;
  • d. generating analytics, insights and reports based on Customer-selected data;
  • e. generating suggested or automated replies using artificial-intelligence functionality, only where the Customer has enabled the applicable reply-generation functionality;
  • f. publishing replies or other content where instructed or enabled by the Customer;
  • g. Processing Customer prompts, instructions, templates, knowledge-base materials and other Customer Content;
  • h. connecting and maintaining Third-Party Accounts and integrations;
  • i. maintaining authentication, permissions and workspace functionality to the extent Processing is performed on behalf of the Customer;
  • j. support, troubleshooting, security monitoring performed as part of the operation of the Service on the Customer's behalf (as distinct from the Provider's own security and fraud-prevention Processing described in Section 1), and technical operation of the Service, to the extent such activities involve Customer Personal Data;
  • k. transmission to authorised Subprocessors necessary to provide requested Service functionality; and
  • l. deletion or return of Customer Personal Data.

D. Frequency

Continuous, periodic or on demand, depending on the Customer's configuration and use of the Service.

E. Categories of Data Subjects

Depending on Customer use, Data Subjects may include:

  • a. individuals who submit reviews, ratings or other content through third-party platforms or data sources selected or connected by the Customer;
  • b. individuals identified or identifiable in Platform Data Processed on behalf of the Customer;
  • c. Customer employees, contractors and other authorised users, only to the extent their Personal Data is Processed on behalf of the Customer rather than by the Provider for its independent Controller purposes;
  • d. individuals whose Personal Data is included by the Customer in prompts, instructions, templates, knowledge-base materials or other Customer Content; and
  • e. other individuals whose Personal Data the Customer lawfully instructs the Provider to Process through supported Service functionality.

F. Types of Customer Personal Data

Depending on Customer use and configuration, Customer Personal Data may include:

Platform and review data

Reviewer names, usernames, public identifiers or other identifiers made available by a Third-Party Service;

review text and other submitted content;

ratings and scores;

language and country or regional information;

timestamps;

application, platform and review metadata;

technical or device-related metadata made available by the applicable Third-Party Service; and

other Platform Data containing Personal Data.

Customer-provided Processing data

Prompts;

instructions;

templates;

knowledge-base materials;

brand or business information containing Personal Data;

other Customer Content containing Personal Data; and

information supplied by the Customer for Processing through supported Service functionality.

Generated or published content

AI Output, suggested replies, automated replies, summaries, classifications, analyses and related generated content where such content contains Personal Data.

Connected account and integration data

Account identifiers;

application identifiers;

integration identifiers;

permission and authentication metadata;

credentials or tokens to the extent they constitute Personal Data; and

other metadata necessary to perform the Customer's documented instructions.

Authorised-user information

Names;

business email addresses;

roles;

workspace identifiers;

permission records; and

other user-provisioning information,

only to the extent Processed by the Provider on behalf of the Customer.

G. Special Categories and Restricted Data

The Service is not designed for the systematic or intentional Processing of:

  • a. special categories of Personal Data under Article 9 GDPR;
  • b. Personal Data relating to criminal convictions and offences under Article 10 GDPR; or
  • c. other highly sensitive or specially regulated categories of Personal Data requiring processing arrangements not ordinarily provided by the Service.

The Customer must not intentionally use the Service for the purpose of Processing such data unless the Provider has expressly agreed in writing to support that Processing.

Such information may occur incidentally in unstructured reviews, Customer Content or other third-party content. Incidental inclusion does not mean that the Provider offers or has agreed to provide the Service for specialised Processing of such data.

H. Competent Supervisory Authority

Where the SCCs apply, the competent Supervisory Authority will be determined in accordance with Clause 13 of the applicable SCCs.

Annex 2: Technical and Organisational Measures

The Provider implements and maintains technical and organisational measures designed to protect Customer Personal Data appropriate to the nature and risks of the Processing.

The measures below describe the security controls applicable to the Service at a category level.

The Provider may replace, modify or update individual technologies, vendors or controls provided that the overall level of protection is not materially reduced.

Managed Infrastructure and Network Protection

The Provider operates the Service as a hosted, multi-tenant SaaS service using managed cloud infrastructure.

Primary application storage is configured in an EU region.

Customer Personal Data may also be transmitted to and Processed by authorised Subprocessors in other jurisdictions in accordance with Section 11 and Annex 3.

Managed infrastructure, network and edge protections are used to mitigate malicious traffic, unauthorised access and distributed denial-of-service attacks where applicable.

Encryption

Customer Personal Data is protected by encryption at rest provided by applicable managed infrastructure.

Data transmitted between supported systems is protected using encrypted transport, including TLS 1.2 or higher where supported.

Identity, Access Control and Tenant Separation

Access to production systems and Customer Personal Data is restricted according to operational need.

The Provider uses role-based access controls and database-level access controls designed to prevent unauthorised access and inappropriate cross-customer access.

Access rights may vary according to account role and operational responsibility.

Privileged Access and Multi-Factor Authentication

Privileged production and infrastructure access is limited to designated persons with an operational need for such access.

Multi-factor authentication is used for privileged administrative access where supported by the applicable system.

Credentials and Secrets

Sensitive credentials, API keys and other secrets are protected using managed encrypted secret-storage mechanisms where applicable.

Secrets are not intended to be exposed to ordinary end users or stored directly in publicly accessible application source code.

Logging, Monitoring and Diagnostics

The Provider uses monitoring, error-diagnostic and security-related logging mechanisms to support operation, troubleshooting, reliability and security of the Service.

Access to relevant diagnostic information is restricted according to operational need.

Backups and Recovery

The Provider maintains regular backups of relevant production data through managed infrastructure for operational recovery and resilience.

Backup data is subject to appropriate access controls and ordinary backup rotation and deletion cycles. The ordinary backup retention period is currently seven (7) days.

Data deleted from active systems may remain temporarily in backup systems until overwritten or deleted through the ordinary backup lifecycle.

Personnel and Confidentiality

Persons authorised by the Provider to access Customer Personal Data are limited to those with a legitimate operational need and are subject to appropriate confidentiality obligations.

Subprocessor Security

The Provider imposes applicable contractual data-protection obligations on Subprocessors in accordance with Section 6.

Customer Personal Data transmitted to Subprocessors is transferred using encrypted connections where supported.

AI Processing

Customer Personal Data transmitted to authorised AI Subprocessors for the Processing described in Section 3 and Annex 1 is transmitted only to the extent necessary to provide the applicable functionality, over encrypted connections where supported, and in accordance with the Customer's documented instructions.

The Provider does not use Customer Personal Data to train, fine-tune or improve general-purpose artificial-intelligence models, and does not enable any optional programme under which an AI Subprocessor would use Customer Personal Data submitted by the Provider for that purpose.

Review and Improvement

The Provider may review and update security controls in response to changes in:

  • a. the Service;
  • b. infrastructure;
  • c. Subprocessors;
  • d. identified risks;
  • e. security developments; or
  • f. applicable legal requirements,

provided that the overall level of protection for Customer Personal Data is not materially reduced.

Annex 3: Current Subprocessors

The following Subprocessors may Process Customer Personal Data on behalf of the Provider in connection with the Service.

The Provider may update this Annex in accordance with Section 6.

This Annex lists Subprocessors that Process Customer Personal Data on behalf of the Customer. It does not list third parties with which the Provider engages as independent Controller for its own purposes, including the applicable Merchant of Record identified in Section 4.2 of the AppReply Terms of Service, whose Processing of billing and transaction data is described in the AppReply Privacy Policy and falls outside this DPA under Section 1. It also does not list operators of connected Third-Party Services to which the Provider transmits Customer Personal Data on the Customer's instruction, as described in Section 11.

Supabase, Inc.

Purpose: Database, authentication, storage and backend infrastructure.

Processing: Customer Personal Data stored or Processed through the primary application backend, authentication and storage systems.

Processing location: Primary application storage is configured in an EU region. Limited ancillary Processing may occur in other jurisdictions used by Supabase or its authorised subprocessors.

Transfer safeguards: Applicable adequacy decisions, SCCs or other lawful transfer mechanisms where required.

Vercel Inc.

Purpose: Application hosting, deployment, server-side infrastructure and network delivery.

Processing: Customer Personal Data transmitted or Processed through application hosting and server-side functionality.

Processing location: EEA and other jurisdictions used in connection with Vercel infrastructure, network and authorised subprocessors.

Transfer safeguards: Applicable adequacy decisions, SCCs or other lawful transfer mechanisms where required.

Nango Inc.

Purpose: Third-party integrations and authentication connections.

Processing: Integration credentials, tokens, account identifiers, connection metadata and Customer Personal Data transmitted through supported integrations where required to provide the connected functionality.

Processing location: United States and other jurisdictions used by Nango or its authorised subprocessors.

Transfer safeguards: SCCs, adequacy decisions or other lawful transfer mechanisms where required.

Functional Software, Inc. (Sentry)

Purpose: Application monitoring, error diagnostics, performance monitoring, troubleshooting and security-related technical analysis.

Processing: Technical, diagnostic and error information that may contain Customer Personal Data depending on the relevant application event.

Processing location: The Provider uses an EU data region. Limited ancillary Processing may occur in other jurisdictions used by Sentry or its authorised subprocessors.

Transfer safeguards: Applicable adequacy decisions, SCCs or other lawful transfer mechanisms where required.

OpenAI Ireland Ltd. and applicable affiliates

Purpose: Artificial-intelligence functionality.

Processing: Customer Personal Data submitted to AI functionality for the purposes described in Section 3 and Annex 1, including baseline analysis of ingested Platform Data and, where enabled by the Customer, reply generation.

Processing location: EEA and other jurisdictions used by OpenAI and its authorised subprocessors, including jurisdictions outside the EEA.

Transfer safeguards: Applicable adequacy decisions, SCCs or other lawful international-transfer mechanisms.

Anthropic PBC and applicable affiliates

Purpose: Artificial-intelligence functionality.

Processing: Customer Personal Data submitted to AI functionality for the purposes described in Section 3 and Annex 1, including baseline analysis of ingested Platform Data and, where enabled by the Customer, reply generation.

Processing location: United States and other jurisdictions used by Anthropic and its authorised subprocessors.

Transfer safeguards: SCCs, applicable adequacy decisions or other lawful international-transfer mechanisms where required.

OpenRouter, Inc. and applicable affiliates

Purpose: Artificial-intelligence functionality, provided by routing requests to third-party model providers.

Processing: Customer Personal Data submitted to AI functionality for the purposes described in Section 3 and Annex 1, including baseline analysis of ingested Platform Data and, where enabled by the Customer, reply generation. OpenRouter transmits that data to the third-party model provider serving the selected model, which it engages as its own subprocessor.

Processing location: United States and other jurisdictions used by OpenRouter and its authorised subprocessors, including the jurisdictions in which the selected model provider operates.

Transfer safeguards: SCCs, applicable adequacy decisions or other lawful international-transfer mechanisms where required.