Last updated: September 21, 2026
This Data Processing Addendum (“Addendum”) forms part of the agreement between Approveit, Inc. and the Customer, which comprises the Terms of Service available at https://approveit.today/terms-of-service (the “Terms of Service”), this Addendum and any order form (together, the “Agreement”), and governs Approveit, Inc.’s Processing of Personal Data on behalf of the Customer as part of the Services.
This Addendum is intended to meet the requirements of global data protection and privacy laws applicable to Approveit Inc. in its role as a processor or service provider, including but not limited to the EU General Data Protection Regulation (“GDPR”), the UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), and other Applicable Privacy Regulations.
By accessing or using the Services, the Customer enters into this Addendum with Approveit, Inc., a corporation organized under the laws of the State of Delaware.
Where the Customer is subject to the GDPR, the UK GDPR or the Swiss FADP, the transfer mechanisms in Section 5 apply automatically and require no further action by either party.
In case of conflict between the Terms of Service or any order form and this Addendum, this Addendum prevails with respect to the Processing of Personal Data. In case of conflict between this Addendum and any applicable Standard Contractual Clauses, the latter shall prevail.
Capitalized terms have the meanings given in Section 9 (Definitions). Terms not defined there have the meanings assigned in the Agreement, and otherwise the meanings given under Applicable Privacy Regulations.
3.1 Confidentiality.
Approveit shall ensure that all personnel authorized to Process Personal Data on its behalf are bound by appropriate contractual or statutory obligations of confidentiality and receive training appropriate to their responsibilities regarding the handling of Personal Data.
3.2 Technical and Organizational Measures.
Approveit shall implement and maintain the technical and organizational measures set out in Exhibit 3. These measures are designed to protect Personal Data against unauthorized or unlawful Processing, accidental loss, destruction, or damage, and to support Approveit’s compliance with applicable privacy and data protection regulations, including Article 32 of the GDPR where relevant.
3.3 Updates to Security Measures.
Approveit may update or modify the technical and organizational measures in Exhibit 3 from time to time to reflect developments in industry standards, technology, or Approveit’s security practices, provided that such updates do not materially reduce the overall level of protection for Personal Data.
3.4 Customer Acknowledgment.
The Customer acknowledges that the technical and organizational measures described in Exhibit 3 are designed to provide a level of security appropriate to the nature of the Processing and the risks involved.
3.5 Restricted Data.
Unless the parties have agreed otherwise in writing, the Customer shall not submit, and shall configure its workflows so as not to submit, restricted data to the Services. Restricted data means special categories of personal data within the meaning of Article 9 of the GDPR, protected health information subject to HIPAA, full payment card numbers, and government identification numbers. The Approveit Service is not designed for, and Exhibit 3 does not describe controls appropriate to, such data. The Customer is responsible for any such data it submits, and Approveit has no liability arising from its submission.
4. AI Features and the MCP Server
5.1 Transfers.
Approveit Processes Personal Data primarily in the United States. Where Approveit has agreed to EU data residency for a Customer, primary storage occurs in the region agreed with that Customer, and support, monitoring and AI Features may nonetheless involve access from or transfer to the United States. The provision of the Services may involve the Processing of Personal Data outside the Customer’s jurisdiction and in countries that may have different privacy and data protection regulations than those applicable to the Customer.
5.2 Standard Contractual Clauses.
Where the Customer is established in the EEA, or is otherwise subject to the GDPR, and Personal Data is transferred to Approveit or its Subprocessors in the United States or another country outside the EEA that is not the subject of an adequacy decision, the parties agree that the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) are incorporated into this Addendum by reference and are deemed executed between the parties, with Module Two applying where the Customer is a controller and Module Three where the Customer is a processor. For the purposes of the Clauses: the Customer is the data exporter and Approveit is the data importer; the optional docking clause does not apply; Option 2 of Clause 9(a) applies with a notice period of 30 days; the governing law is that of Ireland; for the purposes of Clause 18(b), the courts of Ireland shall have jurisdiction; the competent supervisory authority is the supervisory authority of the EEA Member State in which the data exporter is established; where the data exporter is not established in the EEA but is subject to the GDPR under Article 3(2), the supervisory authority of the Member State in which its Article 27 representative is established or, where it is not required to appoint a representative, the supervisory authority of the Member State in which the relevant Data Subjects are located; the optional language in Clause 11(a) does not apply; and Annexes I, II and III are populated by Exhibits 1, 3 and 2A respectively.
5.3 UK and Switzerland.
Where the UK GDPR applies to a transfer of Personal Data to a country not subject to UK adequacy regulations, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0) is incorporated and deemed executed, with the information required by its Tables taken from Section 5.2 and the Exhibits. For the purposes of Table 4 of the UK Addendum, the Importer may end the UK Addendum as set out in Section 19 of it. Where the Swiss FADP applies to a transfer of Personal Data to a country not recognized as adequate by the Swiss Federal Council, the Standard Contractual Clauses apply to that transfer and references in the Clauses are read as referring to the Swiss FADP and the Federal Data Protection and Information Commissioner, the term “Member State” shall not be interpreted so as to exclude Data Subjects in Switzerland from exercising their rights in their place of habitual residence, and the Clauses also protect the data of legal entities where Swiss law so requires.
5.4 Transfer Impact Assessment.
Approveit maintains a transfer impact assessment covering transfers under this Section and will make a summary of it available to the Customer on request, subject to confidentiality and to redaction of Approveit’s confidential and security-sensitive information.
5.5 Subprocessor Transfers.
Approveit shall put in place an appropriate transfer mechanism for each onward transfer to a Subprocessor located outside the EEA, the UK or Switzerland.
6.1 General Authorization.
The Customer provides a general authorization for Approveit to engage Subprocessors to support the provision of the Services. The current list of Subprocessors is set out in Exhibit 2A. Vendors that Approveit engages as a controller for its own business operations are listed in Exhibit 2B and are not Subprocessors.
6.2 Notice of Changes.
Approveit shall give the Customer at least 30 days’ notice before a new Subprocessor begins Processing Personal Data, by updating Exhibit 2A of this Addendum and notifying the email address on the Customer’s account. Where Approveit must engage a replacement Subprocessor on an emergency basis, including to maintain the security or continuity of the Services, Approveit shall give notice as soon as reasonably practicable thereafter, and the Customer’s objection right under Section 6.3 applies from that notice. This emergency exception does not apply to the AI model Subprocessor and, where the Standard Contractual Clauses apply, applies only to the extent they permit.
6.3 Objection.
The Customer may object to a new Subprocessor on reasonable data protection grounds by notifying Approveit in writing at support@approveit.today within 10 days of the notice given under Section 6.2. If the Customer does not object within that period, the Subprocessor is deemed accepted. The parties shall discuss the objection in good faith, and Approveit may, at its option, avoid Processing the Customer’s Personal Data through the new Subprocessor. If the objection is not resolved, the Customer’s sole and exclusive remedy is to terminate the affected Services on written notice, effective no later than the date on which the new Subprocessor begins Processing the Customer’s Personal Data or, for a Subprocessor engaged under the emergency exception in Section 6.2, on the Customer’s notice. Fees already paid are non-refundable.
6.4 Subprocessor Obligations.
Approveit shall engage each Subprocessor under a written contract imposing data protection obligations that provide at least the same level of protection as this Addendum, to the extent applicable to the nature of the services provided by that Subprocessor, including the prohibition on training in Section 4.3 where the Subprocessor provides AI model services. Where a Subprocessor’s standard terms differ, Approveit remains responsible to the Customer for that Subprocessor’s performance of the Processing as if performed by Approveit. Approveit remains responsible for the acts and omissions of its Subprocessors in connection with the Processing of Personal Data under this Addendum. Approveit’s responsibility under this Section is subject in all cases to Section 8 and to the limitations of liability in the Agreement.
Upon termination or expiration of the Agreement, the Customer may retrieve Personal Data using the export functionality of the Services for 30 days. The Customer may at any time instruct Approveit in writing, at support@approveit.today, to delete Personal Data Processed on its behalf, and Approveit shall delete it within 30 days of that instruction. Unless and until the Customer gives that instruction, the Customer instructs Approveit to retain Personal Data after termination so that the Customer’s records remain available, and Approveit may delete it at its discretion at any time from 90 days after termination. This Addendum continues to apply to any Personal Data Approveit retains. Approveit may retain Personal Data where retention is required by applicable law, in which case Approveit shall continue to protect it in accordance with this Addendum and shall Process it only for the purpose of that legal requirement. Personal Data residing in encrypted backup media is isolated from active Processing and is deleted in the ordinary course of Approveit’s backup rotation. On the Customer’s written request, Approveit will confirm in writing that deletion has been carried out in accordance with this Section.
8. Term and Limitation of Liability
This Addendum takes effect on the Customer’s acceptance of the Agreement and remains in effect for as long as Approveit Processes Personal Data on behalf of the Customer. It terminates automatically once all such Personal Data has been deleted or returned in accordance with Section 7, save that Sections 8 and 9 survive.
The limitations and exclusions of liability set out in the Agreement apply to this Addendum. Claims under the Agreement and claims under this Addendum are subject to a single aggregate limit, and Approveit’s total liability under both documents together shall not exceed the amount stated in clause 14 of the Terms of Service. Nothing in this Addendum shall limit either Party’s liability where such limitation is not permitted under applicable law, or limit the rights of Data Subjects under the Standard Contractual Clauses.
9. Definitions
For the purposes of this Addendum, and unless stated otherwise, the following capitalized terms have the meanings set out below:
“Addendum” means this Data Processing Addendum, including all Exhibits incorporated into it.
“AI Client” means a third-party artificial intelligence application connected to the Services by the Customer through the MCP Server.
“AI Assistant” means the Approveit AI Assistant, which uses the AI model Subprocessor identified in Section 4.2.
“AI Features” means the AI Assistant and the MCP Server, as described in the Agreement.
“Applicable Privacy Regulations” means all data protection and privacy laws applicable to Approveit in its role as a processor or service provider, including the GDPR, the UK GDPR, the CCPA, and comparable privacy laws applicable to the Customer or the Processing of Personal Data.
“Customer” means the entity or individual that has entered into the Agreement and uses the Services, and on whose behalf Approveit Processes Personal Data.
“Data Controller” or “Controller” means the entity that determines the purposes and means of Processing Personal Data, as defined under Applicable Privacy Regulations.
“Data Processor” or “Processor” means the entity that Processes Personal Data on behalf of a Controller, as defined under Applicable Privacy Regulations.
“Data Subject” means an identified or identifiable individual whose Personal Data is Processed under the Agreement and this Addendum.
“MCP Server” means Approveit’s server implementing the Model Context Protocol.
“Personal Data” means any information relating to a Data Subject that is defined as “personal data,” “personal information,” or any equivalent term under Applicable Privacy Regulations and that Approveit Processes on behalf of the Customer.
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data Processed on behalf of the Customer. It does not include unsuccessful attempts or activities that do not compromise the security of Personal Data, such as unsuccessful log-in attempts, pings, port scans and blocked network attacks.
“Process” or “Processing” means any operation or set of operations performed on Personal Data, whether by automated means or not, including collection, storage, transmission, access, retrieval, modification, disclosure, or deletion.
“Services” means the Approveit platform and related products or services provided under the Agreement.
“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914, as incorporated by Section 5.2.
“Swiss FADP” means the Swiss Federal Act on Data Protection.
“Subprocessor” means any third party engaged by Approveit to Process Personal Data on its behalf in connection with the Services.
Exhibit 2 comprises Exhibit 2A (Subprocessors) and Exhibit 2B (vendors Approveit engages for its own business operations).
These Subprocessors Process Personal Data that Approveit Processes on behalf of the Customer. This Exhibit populates Annex III of the Standard Contractual Clauses.
Contact for each Subprocessor is available from Approveit at support@approveit.today on request. The duration of Processing by each Subprocessor is the term of the Agreement and any retention period under Section 7.
Anthropic does not train its models on Personal Data transmitted through the Services, as provided in Section 4.3. Approveit’s agreements with the other Subprocessors listed above restrict their use of Personal Data to the provision of their services to Approveit, as provided in Section 6.4.
Where a Subprocessor listed above records sessions or receives error payloads, Approveit configures masking of sensitive fields to the extent that Subprocessor supports it.
These vendors do not Process Personal Data on behalf of the Customer. They process data for which Approveit is the controller, such as billing contacts, marketing contacts and website analytics. They are listed for transparency only, do not form part of Approveit’s contractual obligations under this Addendum, and are not Subprocessors for the purposes of Section 6 or Annex III.





