Data Processing Addendum

Data Processing Addendum

Data Processing Addendum

Data Processing Addendum

Last updated: September 21, 2026

This Data Processing Addendum (“Addendum”) forms part of the agreement between Approveit, Inc. and the Customer, which comprises the Terms of Service available at https://approveit.today/terms-of-service (the “Terms of Service”), this Addendum and any order form (together, the “Agreement”), and governs Approveit, Inc.’s Processing of Personal Data on behalf of the Customer as part of the Services.

This Addendum is intended to meet the requirements of global data protection and privacy laws applicable to Approveit Inc. in its role as a processor or service provider, including but not limited to the EU General Data Protection Regulation (“GDPR”), the UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), and other Applicable Privacy Regulations.

By accessing or using the Services, the Customer enters into this Addendum with Approveit, Inc., a corporation organized under the laws of the State of Delaware.

Where the Customer is subject to the GDPR, the UK GDPR or the Swiss FADP, the transfer mechanisms in Section 5 apply automatically and require no further action by either party.

In case of conflict between the Terms of Service or any order form and this Addendum, this Addendum prevails with respect to the Processing of Personal Data. In case of conflict between this Addendum and any applicable Standard Contractual Clauses, the latter shall prevail.

Capitalized terms have the meanings given in Section 9 (Definitions). Terms not defined there have the meanings assigned in the Agreement, and otherwise the meanings given under Applicable Privacy Regulations.

1. Scope and Roles of the Parties

1. Scope and Roles of the Parties

1.1 Scope.
This Addendum governs Approveit, Inc.’s Processing of Personal Data on behalf of the Customer as necessary to provide the Services in accordance with the Agreement. It applies to Processing activities that Approveit performs as part of the Services, in each case to the extent the relevant Applicable Privacy Regulation applies to that Processing.


1.2 Roles of the Parties.
For the purposes of this Addendum and applicable data protection and privacy regulations: the Customer may act as a data controller or a data processor, as applicable; and Approveit, Inc. shall act as a data processor, or where the Customer acts as a processor, as a sub-processor, Processing Personal Data on behalf of the Customer and in accordance with this Addendum. Where the CCPA applies, Approveit acts as a “service provider” to the Customer as that term is defined in the CCPA.


1.3 Customer Warranties (when acting as Processor).
Where the Customer acts as a Data Processor, the Customer represents and warrants that: it is authorized by the relevant data controller to appoint Approveit as a sub-processor; the Customer’s instructions to Approveit accurately reflect the instructions of the relevant data controller; and the Customer has established and documented all legal bases or other requirements necessary to permit Approveit’s Processing of Personal Data on behalf of the Customer.

1.4 Customer Instructions.
Approveit shall Process Personal Data only on the Customer’s documented instructions, including instructions relating to international transfers, as set out in this Addendum, the Agreement, or Exhibit 1. Approveit shall not Process Personal Data for any other purpose unless required to do so by applicable law, in which case Approveit shall inform the Customer of that legal requirement before Processing unless the law prohibits it. Use of the AI Assistant by the Customer’s users while it is available to the Customer’s workspace, and any connection of an AI Client through the MCP Server, each constitute a documented instruction for the Processing described in Section 4. Any instruction that falls outside the scope of the Services or the Processing activities described in Exhibit 1 may constitute a request for additional services and may require prior written agreement. Approveit shall inform the Customer immediately if, in Approveit’s opinion, an instruction infringes Applicable Privacy Regulations, in which case Approveit may suspend performance of that instruction until it is confirmed, amended or withdrawn.


1.5 Nature and Purpose of Processing.
Approveit shall Process Personal Data solely as necessary to provide, maintain, support and secure the Services, or as otherwise permitted under the Agreement or this Addendum. Approveit shall not Process Personal Data to train or fine-tune generative AI models, and shall not use Personal Data to develop, improve or create products or services other than the Services provided to the Customer. This does not prevent the analytics, session replay and error monitoring Subprocessors identified in Exhibit 2A from applying automated and machine-learning techniques to the data they receive in order to deliver their own services to Approveit. Approveit may create aggregated and de-identified data derived from its Processing (“Usage Data”) and use it as set out in the Terms of Service, provided that Usage Data does not identify the Customer or any Data Subject and does not reproduce the substantive content of approval requests, and that Approveit maintains it in de-identified form, does not attempt to re-identify it, and requires any recipient to comply with the same restrictions.


1.6 Customer Responsibility.
The Customer is responsible for ensuring that its use of the Services and its instructions to Approveit comply with applicable data protection and privacy regulations, including where the Customer acts as a processor on behalf of a third-party data controller, and including informing its personnel that approval content may be Processed by AI Features where they are available to the Customer’s workspace.


1.7 CCPA Service Provider Terms.
Where Approveit Processes Personal Data that constitutes “personal information” under the CCPA, Approveit shall not: sell or share that personal information; retain, use or disclose it for any purpose other than the specific purpose of performing the Services, or as otherwise permitted by the CCPA; retain, use or disclose it outside the direct business relationship between the parties; or combine it with personal information received from another source, except as permitted by the CCPA. Approveit certifies that it understands and will comply with these restrictions, and shall impose the same restrictions on its Subprocessors. The Customer may take reasonable and appropriate steps to stop and remediate any unauthorized use of personal information by Approveit, including, on reasonable notice, requiring Approveit to provide documentation verifying its compliance with this Section, which Approveit shall provide in accordance with and subject to the limits in Section 2.6. Approveit shall notify the Customer promptly if it determines that it can no longer meet its obligations under the CCPA.


1.8 Affiliates.
Where the Customer’s affiliates are permitted to use the Services, they may benefit from this Addendum, but only the Customer may exercise rights or bring claims under it, on its own behalf and on behalf of those affiliates.

1.1 Scope.
This Addendum governs Approveit, Inc.’s Processing of Personal Data on behalf of the Customer as necessary to provide the Services in accordance with the Agreement. It applies to Processing activities that Approveit performs as part of the Services, in each case to the extent the relevant Applicable Privacy Regulation applies to that Processing.


1.2 Roles of the Parties.
For the purposes of this Addendum and applicable data protection and privacy regulations: the Customer may act as a data controller or a data processor, as applicable; and Approveit, Inc. shall act as a data processor, or where the Customer acts as a processor, as a sub-processor, Processing Personal Data on behalf of the Customer and in accordance with this Addendum. Where the CCPA applies, Approveit acts as a “service provider” to the Customer as that term is defined in the CCPA.


1.3 Customer Warranties (when acting as Processor).
Where the Customer acts as a Data Processor, the Customer represents and warrants that: it is authorized by the relevant data controller to appoint Approveit as a sub-processor; the Customer’s instructions to Approveit accurately reflect the instructions of the relevant data controller; and the Customer has established and documented all legal bases or other requirements necessary to permit Approveit’s Processing of Personal Data on behalf of the Customer.

1.4 Customer Instructions.
Approveit shall Process Personal Data only on the Customer’s documented instructions, including instructions relating to international transfers, as set out in this Addendum, the Agreement, or Exhibit 1. Approveit shall not Process Personal Data for any other purpose unless required to do so by applicable law, in which case Approveit shall inform the Customer of that legal requirement before Processing unless the law prohibits it. Use of the AI Assistant by the Customer’s users while it is available to the Customer’s workspace, and any connection of an AI Client through the MCP Server, each constitute a documented instruction for the Processing described in Section 4. Any instruction that falls outside the scope of the Services or the Processing activities described in Exhibit 1 may constitute a request for additional services and may require prior written agreement. Approveit shall inform the Customer immediately if, in Approveit’s opinion, an instruction infringes Applicable Privacy Regulations, in which case Approveit may suspend performance of that instruction until it is confirmed, amended or withdrawn.


1.5 Nature and Purpose of Processing.
Approveit shall Process Personal Data solely as necessary to provide, maintain, support and secure the Services, or as otherwise permitted under the Agreement or this Addendum. Approveit shall not Process Personal Data to train or fine-tune generative AI models, and shall not use Personal Data to develop, improve or create products or services other than the Services provided to the Customer. This does not prevent the analytics, session replay and error monitoring Subprocessors identified in Exhibit 2A from applying automated and machine-learning techniques to the data they receive in order to deliver their own services to Approveit. Approveit may create aggregated and de-identified data derived from its Processing (“Usage Data”) and use it as set out in the Terms of Service, provided that Usage Data does not identify the Customer or any Data Subject and does not reproduce the substantive content of approval requests, and that Approveit maintains it in de-identified form, does not attempt to re-identify it, and requires any recipient to comply with the same restrictions.


1.6 Customer Responsibility.
The Customer is responsible for ensuring that its use of the Services and its instructions to Approveit comply with applicable data protection and privacy regulations, including where the Customer acts as a processor on behalf of a third-party data controller, and including informing its personnel that approval content may be Processed by AI Features where they are available to the Customer’s workspace.


1.7 CCPA Service Provider Terms.
Where Approveit Processes Personal Data that constitutes “personal information” under the CCPA, Approveit shall not: sell or share that personal information; retain, use or disclose it for any purpose other than the specific purpose of performing the Services, or as otherwise permitted by the CCPA; retain, use or disclose it outside the direct business relationship between the parties; or combine it with personal information received from another source, except as permitted by the CCPA. Approveit certifies that it understands and will comply with these restrictions, and shall impose the same restrictions on its Subprocessors. The Customer may take reasonable and appropriate steps to stop and remediate any unauthorized use of personal information by Approveit, including, on reasonable notice, requiring Approveit to provide documentation verifying its compliance with this Section, which Approveit shall provide in accordance with and subject to the limits in Section 2.6. Approveit shall notify the Customer promptly if it determines that it can no longer meet its obligations under the CCPA.


1.8 Affiliates.
Where the Customer’s affiliates are permitted to use the Services, they may benefit from this Addendum, but only the Customer may exercise rights or bring claims under it, on its own behalf and on behalf of those affiliates.

2. Processor’s Duties

Processing of Personal
Data

2.1 Compliance with Applicable Privacy Regulations.
Approveit shall comply with the data protection and privacy regulations applicable to its role as a processor or sub-processor in connection with the Services. Upon reasonable written request, and no more than once in any 12-month period, Approveit shall provide the Customer with information reasonably necessary to demonstrate its compliance with this Addendum. Approveit may satisfy this Section by providing the materials described in Section 2.6.


2.2 Assistance with Data Subject Requests.
Taking into account the nature of the Processing, Approveit shall assist the Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to requests from individuals exercising their rights under Applicable Privacy Regulations. Where Approveit receives such a request directly from a Data Subject relating to Personal Data Processed on behalf of the Customer, Approveit shall not respond to it substantively and shall promptly forward it to the Customer. The Customer shall first use the functionality of the Services to respond to such requests. Approveit may charge a reasonable fee at its then-current professional services rates for assistance that goes beyond the functionality of the Services.


2.3 Assistance with Assessments and Regulatory Inquiries.
To the extent required under Applicable Privacy Regulations and taking into account the nature of the Processing and the information available to Approveit, Approveit shall assist the Customer with compliance with the obligations in Articles 32 to 36 of the GDPR by providing information available to Approveit that the Customer reasonably requires in order to conduct data protection impact assessments and prior consultations under Articles 35 and 36, and by responding to inquiries or investigations initiated by regulatory authorities relating to the Processing of Personal Data under this Addendum. Approveit is not required to conduct such assessments on the Customer’s behalf. Assistance requiring resources beyond the materials Approveit makes generally available is provided at the Customer’s cost, at Approveit’s then-current professional services rates.

2.4 Assistance with Security Obligations.
Approveit shall assist the Customer in ensuring compliance with its obligations under Article 32 of the GDPR by making available the information and materials described in Sections 2.1 and 2.6, taking into account the nature of the Processing and the information available to Approveit. Assistance requiring resources beyond those materials is provided at the Customer’s cost, at Approveit’s then-current professional services rates.

2.5 Breach Notification.
Approveit shall notify the Customer without undue delay, and where feasible within 72 hours, after becoming aware of a Personal Data Breach affecting Personal Data Processed on behalf of the Customer. Such notification shall include information reasonably required for the Customer to meet its obligations under Applicable Privacy Regulations. Approveit’s initial notification may be preliminary, and Approveit shall supplement it as further information becomes available. Approveit’s notification or response shall not be construed as an acknowledgement of fault or liability. Where an incident results from the acts or omissions of the Customer, its users or anyone using the Services on its behalf, including compromise of their credentials, Approveit’s obligation under this Section is limited to informing the Customer without undue delay after becoming aware of it.

2.6 Audits and Information Rights.
Approveit shall make available to the Customer the information reasonably necessary to demonstrate its compliance with this Addendum, including its then-current SOC 2 Type II report and any other security attestation, certification or questionnaire response that Approveit then makes generally available, under confidentiality. The Customer shall first review these materials. If the Customer reasonably determines that they are not sufficient to demonstrate Approveit’s compliance with this Addendum, or where a supervisory authority requires it, the Customer may request an audit of Approveit’s compliance with this Addendum, no more than once in any 12-month period unless required by a supervisory authority or following a Personal Data Breach affecting the Customer’s Personal Data. Such an audit must be conducted by the Customer or an independent auditor who is not a competitor of Approveit and who is bound by confidentiality obligations, requires at least 30 days’ written notice, takes place during normal business hours for the duration agreed in the audit plan, is conducted remotely where reasonably possible, and must not unreasonably disrupt Approveit’s operations. Following a confirmed Personal Data Breach affecting the Customer’s Personal Data, Approveit shall provide the Customer with a written incident report describing the incident, its impact and the remedial measures taken.


The Customer shall submit a proposed audit plan at least 30 days in advance describing the scope, duration and start date of the audit, and the parties shall agree the plan in writing before the audit begins. An audit shall not extend to, and Approveit shall not be required to disclose, (i) data or information relating to any other customer of Approveit, (ii) Approveit’s internal accounting, financial or commercial information, (iii) information subject to a duty of confidentiality owed to a third party, or (iv) any information the disclosure of which would in Approveit’s reasonable judgement compromise the security of the Services. Approveit may require the auditor to execute a non-disclosure agreement in a form reasonably acceptable to Approveit before the audit begins.


All information disclosed in connection with an audit, and the audit report and its findings, constitute Approveit’s Confidential Information. The Customer may use them solely to assess Approveit’s compliance with this Addendum and shall not disclose them to any third party other than its professional advisers or a supervisory authority where required by law.


The Customer bears its own costs and reimburses Approveit’s reasonable costs of supporting the audit at Approveit’s then-current professional services rates in all cases.


2.7 Government and Third-Party Requests
Approveit shall promptly notify the Customer if it receives any legally binding request from a public authority or third party for access to Personal Data Processed on behalf of the Customer, unless such notification is prohibited by law. If notification is prohibited, Approveit will use commercially reasonable efforts, having regard to the cost and likelihood of success, to seek a waiver of the prohibition or to limit the scope of the disclosure, and will notify the Customer as soon as it is lawfully permitted to do so.

2.1 Compliance with Applicable Privacy Regulations.
Approveit shall comply with the data protection and privacy regulations applicable to its role as a processor or sub-processor in connection with the Services. Upon reasonable written request, and no more than once in any 12-month period, Approveit shall provide the Customer with information reasonably necessary to demonstrate its compliance with this Addendum. Approveit may satisfy this Section by providing the materials described in Section 2.6.


2.2 Assistance with Data Subject Requests.
Taking into account the nature of the Processing, Approveit shall assist the Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to requests from individuals exercising their rights under Applicable Privacy Regulations. Where Approveit receives such a request directly from a Data Subject relating to Personal Data Processed on behalf of the Customer, Approveit shall not respond to it substantively and shall promptly forward it to the Customer. The Customer shall first use the functionality of the Services to respond to such requests. Approveit may charge a reasonable fee at its then-current professional services rates for assistance that goes beyond the functionality of the Services.


2.3 Assistance with Assessments and Regulatory Inquiries.
To the extent required under Applicable Privacy Regulations and taking into account the nature of the Processing and the information available to Approveit, Approveit shall assist the Customer with compliance with the obligations in Articles 32 to 36 of the GDPR by providing information available to Approveit that the Customer reasonably requires in order to conduct data protection impact assessments and prior consultations under Articles 35 and 36, and by responding to inquiries or investigations initiated by regulatory authorities relating to the Processing of Personal Data under this Addendum. Approveit is not required to conduct such assessments on the Customer’s behalf. Assistance requiring resources beyond the materials Approveit makes generally available is provided at the Customer’s cost, at Approveit’s then-current professional services rates.

2.4 Assistance with Security Obligations.
Approveit shall assist the Customer in ensuring compliance with its obligations under Article 32 of the GDPR by making available the information and materials described in Sections 2.1 and 2.6, taking into account the nature of the Processing and the information available to Approveit. Assistance requiring resources beyond those materials is provided at the Customer’s cost, at Approveit’s then-current professional services rates.

2.5 Breach Notification.
Approveit shall notify the Customer without undue delay, and where feasible within 72 hours, after becoming aware of a Personal Data Breach affecting Personal Data Processed on behalf of the Customer. Such notification shall include information reasonably required for the Customer to meet its obligations under Applicable Privacy Regulations. Approveit’s initial notification may be preliminary, and Approveit shall supplement it as further information becomes available. Approveit’s notification or response shall not be construed as an acknowledgement of fault or liability. Where an incident results from the acts or omissions of the Customer, its users or anyone using the Services on its behalf, including compromise of their credentials, Approveit’s obligation under this Section is limited to informing the Customer without undue delay after becoming aware of it.

2.6 Audits and Information Rights.
Approveit shall make available to the Customer the information reasonably necessary to demonstrate its compliance with this Addendum, including its then-current SOC 2 Type II report and any other security attestation, certification or questionnaire response that Approveit then makes generally available, under confidentiality. The Customer shall first review these materials. If the Customer reasonably determines that they are not sufficient to demonstrate Approveit’s compliance with this Addendum, or where a supervisory authority requires it, the Customer may request an audit of Approveit’s compliance with this Addendum, no more than once in any 12-month period unless required by a supervisory authority or following a Personal Data Breach affecting the Customer’s Personal Data. Such an audit must be conducted by the Customer or an independent auditor who is not a competitor of Approveit and who is bound by confidentiality obligations, requires at least 30 days’ written notice, takes place during normal business hours for the duration agreed in the audit plan, is conducted remotely where reasonably possible, and must not unreasonably disrupt Approveit’s operations. Following a confirmed Personal Data Breach affecting the Customer’s Personal Data, Approveit shall provide the Customer with a written incident report describing the incident, its impact and the remedial measures taken.


The Customer shall submit a proposed audit plan at least 30 days in advance describing the scope, duration and start date of the audit, and the parties shall agree the plan in writing before the audit begins. An audit shall not extend to, and Approveit shall not be required to disclose, (i) data or information relating to any other customer of Approveit, (ii) Approveit’s internal accounting, financial or commercial information, (iii) information subject to a duty of confidentiality owed to a third party, or (iv) any information the disclosure of which would in Approveit’s reasonable judgement compromise the security of the Services. Approveit may require the auditor to execute a non-disclosure agreement in a form reasonably acceptable to Approveit before the audit begins.


All information disclosed in connection with an audit, and the audit report and its findings, constitute Approveit’s Confidential Information. The Customer may use them solely to assess Approveit’s compliance with this Addendum and shall not disclose them to any third party other than its professional advisers or a supervisory authority where required by law.


The Customer bears its own costs and reimburses Approveit’s reasonable costs of supporting the audit at Approveit’s then-current professional services rates in all cases.


2.7 Government and Third-Party Requests
Approveit shall promptly notify the Customer if it receives any legally binding request from a public authority or third party for access to Personal Data Processed on behalf of the Customer, unless such notification is prohibited by law. If notification is prohibited, Approveit will use commercially reasonable efforts, having regard to the cost and likelihood of success, to seek a waiver of the prohibition or to limit the scope of the disclosure, and will notify the Customer as soon as it is lawfully permitted to do so.

3. Confidentiality and Security Measures

3. Confidentiality and Security Measures

3.1 Confidentiality.
Approveit shall ensure that all personnel authorized to Process Personal Data on its behalf are bound by appropriate contractual or statutory obligations of confidentiality and receive training appropriate to their responsibilities regarding the handling of Personal Data.


3.2 Technical and Organizational Measures.
Approveit shall implement and maintain the technical and organizational measures set out in Exhibit 3. These measures are designed to protect Personal Data against unauthorized or unlawful Processing, accidental loss, destruction, or damage, and to support Approveit’s compliance with applicable privacy and data protection regulations, including Article 32 of the GDPR where relevant.


3.3 Updates to Security Measures.
Approveit may update or modify the technical and organizational measures in Exhibit 3 from time to time to reflect developments in industry standards, technology, or Approveit’s security practices, provided that such updates do not materially reduce the overall level of protection for Personal Data.


3.4 Customer Acknowledgment.

The Customer acknowledges that the technical and organizational measures described in Exhibit 3 are designed to provide a level of security appropriate to the nature of the Processing and the risks involved.


3.5 Restricted Data.

Unless the parties have agreed otherwise in writing, the Customer shall not submit, and shall configure its workflows so as not to submit, restricted data to the Services. Restricted data means special categories of personal data within the meaning of Article 9 of the GDPR, protected health information subject to HIPAA, full payment card numbers, and government identification numbers. The Approveit Service is not designed for, and Exhibit 3 does not describe controls appropriate to, such data. The Customer is responsible for any such data it submits, and Approveit has no liability arising from its submission.


4. AI Features and the MCP Server

4.1 AI Assistant.
The Services include optional AI Features as described in the Agreement. Where the AI Assistant is available to the Customer’s workspace and a user invokes it, Approveit Processes Personal Data by transmitting to its AI model Subprocessor the content of the user’s instruction and the relevant approval requests, workflow configurations, comments and metadata that the user is entitled to access within the Services, for the sole purpose of generating a response to that user.

4.2 AI Model Subprocessor.
The AI model Subprocessor for the AI Assistant is Anthropic, PBC, engaged under Anthropic’s commercial terms and data processing terms. Approveit uses commercial API services only and does not use consumer AI products for the Processing of Personal Data on behalf of the Customer. The MCP Server does not transmit Personal Data to the AI model Subprocessor.


4.3 No Training.
Approveit does not use Personal Data to train or fine-tune generative AI models. Certain analytics, session replay and error monitoring Subprocessors apply automated and machine-learning techniques to the data they receive in order to deliver their own services to Approveit, as described in Exhibit 2A. Approveit’s AI model Subprocessor is contractually prohibited from training its models on Personal Data transmitted through the Services.


4.4 Retention by the AI Model Subprocessor
Personal Data transmitted to the AI model Subprocessor is retained in accordance with that Subprocessor’s then-current published commercial retention policy. As at the date of this Addendum, that policy provides for deletion within a limited period, save for content flagged by that Subprocessor’s automated trust and safety systems, which may be retained for longer. Approveit will update Exhibit 2A to reflect material changes to that policy of which it becomes aware.


4.5 Disabling the AI Assistant.
A workspace administrator may have the AI Assistant disabled for its workspace at any time by contacting Approveit at support@approveit.today, which Approveit shall action without undue delay and in any event within two business days, after which Approveit stops transmitting that workspace’s Personal Data to the AI model Subprocessor. Disabling the AI Assistant does not of itself terminate MCP connections; a workspace administrator may revoke authorized MCP connections separately as described in Section 4.7.


4.6 Customer-directed disclosures.
Where the Customer connects the Services to a user’s Google Calendar, the Customer instructs Approveit to disclose to that Google account the event data needed to create and update events the Services create. Google acts under the Customer’s own relationship with Google and is not a Subprocessor of Approveit for that disclosure.


4.7 MCP Server and AI Clients.
Where the Customer authorizes a connection between the Services and a third-party AI Client through the MCP Server, the Customer instructs Approveit to disclose the Personal Data covered by the permissions granted to that AI Client. The operator of the AI Client is not a Subprocessor of Approveit. The Customer is the controller of that disclosure and of any subsequent Processing by the AI Client, is responsible for the terms on which it engages the AI Client operator, and is responsible for maintaining a lawful basis and any transfer mechanism required for that Processing. Approveit shall maintain a record of authorized connections and shall make revocation available to workspace administrators at any time.


4.8 Automated Decision-Making.
The AI Assistant generates suggestions, drafts and summaries and does not, of itself, produce decisions about Data Subjects. Approval actions are executed under an Approveit user account and recorded in the audit trail, including the identity of that account and any connected AI Client through which the action was taken. Where the Customer configures a service account, integration or AI Client to submit approval decisions without human intervention, the Customer is the controller of that decision and is responsible for compliance with Article 22 of the GDPR and any equivalent requirement, including providing human intervention on request. Approveit makes the audit trail available to support the Customer in meeting that obligation.


4.9 Session replay opt-out.
On written request from a workspace administrator, Approveit shall, without undue delay and in any event within 10 business days, exclude that workspace from session replay by the Subprocessors identified in Exhibit 2A as providing session replay.

4.1 AI Assistant.
The Services include optional AI Features as described in the Agreement. Where the AI Assistant is available to the Customer’s workspace and a user invokes it, Approveit Processes Personal Data by transmitting to its AI model Subprocessor the content of the user’s instruction and the relevant approval requests, workflow configurations, comments and metadata that the user is entitled to access within the Services, for the sole purpose of generating a response to that user.

4.2 AI Model Subprocessor.
The AI model Subprocessor for the AI Assistant is Anthropic, PBC, engaged under Anthropic’s commercial terms and data processing terms. Approveit uses commercial API services only and does not use consumer AI products for the Processing of Personal Data on behalf of the Customer. The MCP Server does not transmit Personal Data to the AI model Subprocessor.


4.3 No Training.
Approveit does not use Personal Data to train or fine-tune generative AI models. Certain analytics, session replay and error monitoring Subprocessors apply automated and machine-learning techniques to the data they receive in order to deliver their own services to Approveit, as described in Exhibit 2A. Approveit’s AI model Subprocessor is contractually prohibited from training its models on Personal Data transmitted through the Services.


4.4 Retention by the AI Model Subprocessor
Personal Data transmitted to the AI model Subprocessor is retained in accordance with that Subprocessor’s then-current published commercial retention policy. As at the date of this Addendum, that policy provides for deletion within a limited period, save for content flagged by that Subprocessor’s automated trust and safety systems, which may be retained for longer. Approveit will update Exhibit 2A to reflect material changes to that policy of which it becomes aware.


4.5 Disabling the AI Assistant.
A workspace administrator may have the AI Assistant disabled for its workspace at any time by contacting Approveit at support@approveit.today, which Approveit shall action without undue delay and in any event within two business days, after which Approveit stops transmitting that workspace’s Personal Data to the AI model Subprocessor. Disabling the AI Assistant does not of itself terminate MCP connections; a workspace administrator may revoke authorized MCP connections separately as described in Section 4.7.


4.6 Customer-directed disclosures.
Where the Customer connects the Services to a user’s Google Calendar, the Customer instructs Approveit to disclose to that Google account the event data needed to create and update events the Services create. Google acts under the Customer’s own relationship with Google and is not a Subprocessor of Approveit for that disclosure.


4.7 MCP Server and AI Clients.
Where the Customer authorizes a connection between the Services and a third-party AI Client through the MCP Server, the Customer instructs Approveit to disclose the Personal Data covered by the permissions granted to that AI Client. The operator of the AI Client is not a Subprocessor of Approveit. The Customer is the controller of that disclosure and of any subsequent Processing by the AI Client, is responsible for the terms on which it engages the AI Client operator, and is responsible for maintaining a lawful basis and any transfer mechanism required for that Processing. Approveit shall maintain a record of authorized connections and shall make revocation available to workspace administrators at any time.


4.8 Automated Decision-Making.
The AI Assistant generates suggestions, drafts and summaries and does not, of itself, produce decisions about Data Subjects. Approval actions are executed under an Approveit user account and recorded in the audit trail, including the identity of that account and any connected AI Client through which the action was taken. Where the Customer configures a service account, integration or AI Client to submit approval decisions without human intervention, the Customer is the controller of that decision and is responsible for compliance with Article 22 of the GDPR and any equivalent requirement, including providing human intervention on request. Approveit makes the audit trail available to support the Customer in meeting that obligation.


4.9 Session replay opt-out.
On written request from a workspace administrator, Approveit shall, without undue delay and in any event within 10 business days, exclude that workspace from session replay by the Subprocessors identified in Exhibit 2A as providing session replay.

5. Cross-border Transfers of Personal Data

5. Cross-border Transfers of Personal Data

5.1 Transfers.
Approveit Processes Personal Data primarily in the United States. Where Approveit has agreed to EU data residency for a Customer, primary storage occurs in the region agreed with that Customer, and support, monitoring and AI Features may nonetheless involve access from or transfer to the United States. The provision of the Services may involve the Processing of Personal Data outside the Customer’s jurisdiction and in countries that may have different privacy and data protection regulations than those applicable to the Customer.


5.2 Standard Contractual Clauses.
Where the Customer is established in the EEA, or is otherwise subject to the GDPR, and Personal Data is transferred to Approveit or its Subprocessors in the United States or another country outside the EEA that is not the subject of an adequacy decision, the parties agree that the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) are incorporated into this Addendum by reference and are deemed executed between the parties, with Module Two applying where the Customer is a controller and Module Three where the Customer is a processor. For the purposes of the Clauses: the Customer is the data exporter and Approveit is the data importer; the optional docking clause does not apply; Option 2 of Clause 9(a) applies with a notice period of 30 days; the governing law is that of Ireland; for the purposes of Clause 18(b), the courts of Ireland shall have jurisdiction; the competent supervisory authority is the supervisory authority of the EEA Member State in which the data exporter is established; where the data exporter is not established in the EEA but is subject to the GDPR under Article 3(2), the supervisory authority of the Member State in which its Article 27 representative is established or, where it is not required to appoint a representative, the supervisory authority of the Member State in which the relevant Data Subjects are located; the optional language in Clause 11(a) does not apply; and Annexes I, II and III are populated by Exhibits 1, 3 and 2A respectively.


5.3 UK and Switzerland.
Where the UK GDPR applies to a transfer of Personal Data to a country not subject to UK adequacy regulations, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0) is incorporated and deemed executed, with the information required by its Tables taken from Section 5.2 and the Exhibits. For the purposes of Table 4 of the UK Addendum, the Importer may end the UK Addendum as set out in Section 19 of it. Where the Swiss FADP applies to a transfer of Personal Data to a country not recognized as adequate by the Swiss Federal Council, the Standard Contractual Clauses apply to that transfer and references in the Clauses are read as referring to the Swiss FADP and the Federal Data Protection and Information Commissioner, the term “Member State” shall not be interpreted so as to exclude Data Subjects in Switzerland from exercising their rights in their place of habitual residence, and the Clauses also protect the data of legal entities where Swiss law so requires.


5.4 Transfer Impact Assessment.
Approveit maintains a transfer impact assessment covering transfers under this Section and will make a summary of it available to the Customer on request, subject to confidentiality and to redaction of Approveit’s confidential and security-sensitive information.


5.5 Subprocessor Transfers.
Approveit shall put in place an appropriate transfer mechanism for each onward transfer to a Subprocessor located outside the EEA, the UK or Switzerland.

6. Subprocessors

6. Subprocessors

6.1 General Authorization.

The Customer provides a general authorization for Approveit to engage Subprocessors to support the provision of the Services. The current list of Subprocessors is set out in Exhibit 2A. Vendors that Approveit engages as a controller for its own business operations are listed in Exhibit 2B and are not Subprocessors.


6.2 Notice of Changes.
Approveit shall give the Customer at least 30 days’ notice before a new Subprocessor begins Processing Personal Data, by updating Exhibit 2A of this Addendum and notifying the email address on the Customer’s account. Where Approveit must engage a replacement Subprocessor on an emergency basis, including to maintain the security or continuity of the Services, Approveit shall give notice as soon as reasonably practicable thereafter, and the Customer’s objection right under Section 6.3 applies from that notice. This emergency exception does not apply to the AI model Subprocessor and, where the Standard Contractual Clauses apply, applies only to the extent they permit.


6.3 Objection.
The Customer may object to a new Subprocessor on reasonable data protection grounds by notifying Approveit in writing at support@approveit.today within 10 days of the notice given under Section 6.2. If the Customer does not object within that period, the Subprocessor is deemed accepted. The parties shall discuss the objection in good faith, and Approveit may, at its option, avoid Processing the Customer’s Personal Data through the new Subprocessor. If the objection is not resolved, the Customer’s sole and exclusive remedy is to terminate the affected Services on written notice, effective no later than the date on which the new Subprocessor begins Processing the Customer’s Personal Data or, for a Subprocessor engaged under the emergency exception in Section 6.2, on the Customer’s notice. Fees already paid are non-refundable.


6.4 Subprocessor Obligations.
Approveit shall engage each Subprocessor under a written contract imposing data protection obligations that provide at least the same level of protection as this Addendum, to the extent applicable to the nature of the services provided by that Subprocessor, including the prohibition on training in Section 4.3 where the Subprocessor provides AI model services. Where a Subprocessor’s standard terms differ, Approveit remains responsible to the Customer for that Subprocessor’s performance of the Processing as if performed by Approveit. Approveit remains responsible for the acts and omissions of its Subprocessors in connection with the Processing of Personal Data under this Addendum. Approveit’s responsibility under this Section is subject in all cases to Section 8 and to the limitations of liability in the Agreement.

7. Deletion or Return of Personal Data

7. Deletion or Return of Personal Data

Upon termination or expiration of the Agreement, the Customer may retrieve Personal Data using the export functionality of the Services for 30 days. The Customer may at any time instruct Approveit in writing, at support@approveit.today, to delete Personal Data Processed on its behalf, and Approveit shall delete it within 30 days of that instruction. Unless and until the Customer gives that instruction, the Customer instructs Approveit to retain Personal Data after termination so that the Customer’s records remain available, and Approveit may delete it at its discretion at any time from 90 days after termination. This Addendum continues to apply to any Personal Data Approveit retains. Approveit may retain Personal Data where retention is required by applicable law, in which case Approveit shall continue to protect it in accordance with this Addendum and shall Process it only for the purpose of that legal requirement. Personal Data residing in encrypted backup media is isolated from active Processing and is deleted in the ordinary course of Approveit’s backup rotation. On the Customer’s written request, Approveit will confirm in writing that deletion has been carried out in accordance with this Section.

8. Term and Limitation of Liability

This Addendum takes effect on the Customer’s acceptance of the Agreement and remains in effect for as long as Approveit Processes Personal Data on behalf of the Customer. It terminates automatically once all such Personal Data has been deleted or returned in accordance with Section 7, save that Sections 8 and 9 survive.

The limitations and exclusions of liability set out in the Agreement apply to this Addendum. Claims under the Agreement and claims under this Addendum are subject to a single aggregate limit, and Approveit’s total liability under both documents together shall not exceed the amount stated in clause 14 of the Terms of Service. Nothing in this Addendum shall limit either Party’s liability where such limitation is not permitted under applicable law, or limit the rights of Data Subjects under the Standard Contractual Clauses.

9. Definitions

For the purposes of this Addendum, and unless stated otherwise, the following capitalized terms have the meanings set out below:


“Addendum” means this Data Processing Addendum, including all Exhibits incorporated into it.


“AI Client” means a third-party artificial intelligence application connected to the Services by the Customer through the MCP Server.


“AI Assistant” means the Approveit AI Assistant, which uses the AI model Subprocessor identified in Section 4.2.


“AI Features” means the AI Assistant and the MCP Server, as described in the Agreement.


“Applicable Privacy Regulations” means all data protection and privacy laws applicable to Approveit in its role as a processor or service provider, including the GDPR, the UK GDPR, the CCPA, and comparable privacy laws applicable to the Customer or the Processing of Personal Data.


“Customer” means the entity or individual that has entered into the Agreement and uses the Services, and on whose behalf Approveit Processes Personal Data.


“Data Controller” or “Controller” means the entity that determines the purposes and means of Processing Personal Data, as defined under Applicable Privacy Regulations.


“Data Processor” or “Processor” means the entity that Processes Personal Data on behalf of a Controller, as defined under Applicable Privacy Regulations.


“Data Subject” means an identified or identifiable individual whose Personal Data is Processed under the Agreement and this Addendum.


“MCP Server” means Approveit’s server implementing the Model Context Protocol.


“Personal Data” means any information relating to a Data Subject that is defined as “personal data,” “personal information,” or any equivalent term under Applicable Privacy Regulations and that Approveit Processes on behalf of the Customer.


“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data Processed on behalf of the Customer. It does not include unsuccessful attempts or activities that do not compromise the security of Personal Data, such as unsuccessful log-in attempts, pings, port scans and blocked network attacks.


“Process” or “Processing” means any operation or set of operations performed on Personal Data, whether by automated means or not, including collection, storage, transmission, access, retrieval, modification, disclosure, or deletion.


“Services” means the Approveit platform and related products or services provided under the Agreement.


“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914, as incorporated by Section 5.2.


“Swiss FADP” means the Swiss Federal Act on Data Protection.


“Subprocessor” means any third party engaged by Approveit to Process Personal Data on its behalf in connection with the Services.

Exhibit 1 — Details of the Data Processing

This Exhibit populates Annex I of the Standard Contractual Clauses.


A. List of Parties
Data exporter: the Customer, as identified in the Agreement. Address: as stated in the Customer’s account record. Contact person: the account administrator named in the Customer’s account. Activities relevant to the data transferred: use of the Approveit approval-workflow Service as described in the Agreement. Role: controller under Module Two, or processor under Module Three, as applicable under Section 1.2. Signature and date: by accepting the Agreement, the Customer is deemed to have signed these Clauses as of the date of acceptance.


Data importer: Approveit, Inc., 455 Valencia Street, San Francisco, CA 94103, USA. Contact person: Serge Gusev, Chief Executive Officer, serge@approveit.today. Activities relevant to the data transferred: provision of the Approveit Service as described in this Exhibit. Role: processor under Module Two, or sub-processor under Module Three. Signature and date: by making the Services available, Approveit is deemed to have signed these Clauses as of the date of the Customer’s acceptance of the Agreement.


B. Description of the Transfer
1. Subject matter. Processing of Personal Data as necessary to provide, operate, maintain, and support the Approveit Service in accordance with the Agreement and this Addendum.


2. Duration. For the term of the Agreement and until all Personal Data is deleted or returned in accordance with Section 7 of the Addendum.


3. Frequency. Continuous, for the duration of the Agreement.


4. Nature of the Processing. Approveit processes Personal Data as required to provide the Services, including: receiving, storing, and transmitting approval requests; enabling approval workflows inside integrated platforms such as Slack and Microsoft Teams; displaying workflow-related information to users; maintaining logs, metadata, and audit trails; where a user invokes the AI Assistant, transmitting request content and the user’s instruction to the AI model Subprocessor for the purpose of generating a response, and storing the resulting conversation in the Customer’s workspace; where the Customer has authorized an MCP connection, disclosing the permitted data to the AI Client the Customer has connected; synchronizing events that the Service creates with a user’s Google Calendar at the Customer’s direction; product analytics, session replay and error monitoring to operate, maintain and troubleshoot the Service; customer support; securing, backing up, and updating the Service; and deleting or returning data upon termination.


5. Purpose of the Processing. To enable the Customer to create, manage, and automate approval workflows and related communication within the Approveit Service, and to provide, secure, support, maintain and troubleshoot the Services.


6. Categories of Personal Data. Name, display name, username, or nickname; email address; workplace information such as team or department; identifiers provided by integrated platforms such as a Slack user ID; content of approval requests, attachments, comments and workflow messages; the content of instructions submitted by users to AI Features; timestamps such as creation time and approval time; usage logs, audit trails, session recordings and technical metadata necessary for service functionality and security.


7. Special categories of data. The Services are not intended for, and the Customer is responsible under Section 3.5 for not submitting, special categories of Personal Data. The parties do not anticipate the transfer of special category data. Any such data submitted by the Customer contrary to Section 3.5 is Processed under the measures set out in Exhibit 3.


8. Categories of Data Subjects. The Customer’s employees, contractors, and other authorized users of the Approveit Service; and individuals whose data is included in approval workflows submitted by the Customer.


C. Competent Supervisory Authority

9. The supervisory authority determined in accordance with Section 5.2.

This Exhibit populates Annex I of the Standard Contractual Clauses.


A. List of Parties
Data exporter: the Customer, as identified in the Agreement. Address: as stated in the Customer’s account record. Contact person: the account administrator named in the Customer’s account. Activities relevant to the data transferred: use of the Approveit approval-workflow Service as described in the Agreement. Role: controller under Module Two, or processor under Module Three, as applicable under Section 1.2. Signature and date: by accepting the Agreement, the Customer is deemed to have signed these Clauses as of the date of acceptance.


Data importer: Approveit, Inc., 455 Valencia Street, San Francisco, CA 94103, USA. Contact person: Serge Gusev, Chief Executive Officer, serge@approveit.today. Activities relevant to the data transferred: provision of the Approveit Service as described in this Exhibit. Role: processor under Module Two, or sub-processor under Module Three. Signature and date: by making the Services available, Approveit is deemed to have signed these Clauses as of the date of the Customer’s acceptance of the Agreement.


B. Description of the Transfer
1. Subject matter. Processing of Personal Data as necessary to provide, operate, maintain, and support the Approveit Service in accordance with the Agreement and this Addendum.


2. Duration. For the term of the Agreement and until all Personal Data is deleted or returned in accordance with Section 7 of the Addendum.


3. Frequency. Continuous, for the duration of the Agreement.


4. Nature of the Processing. Approveit processes Personal Data as required to provide the Services, including: receiving, storing, and transmitting approval requests; enabling approval workflows inside integrated platforms such as Slack and Microsoft Teams; displaying workflow-related information to users; maintaining logs, metadata, and audit trails; where a user invokes the AI Assistant, transmitting request content and the user’s instruction to the AI model Subprocessor for the purpose of generating a response, and storing the resulting conversation in the Customer’s workspace; where the Customer has authorized an MCP connection, disclosing the permitted data to the AI Client the Customer has connected; synchronizing events that the Service creates with a user’s Google Calendar at the Customer’s direction; product analytics, session replay and error monitoring to operate, maintain and troubleshoot the Service; customer support; securing, backing up, and updating the Service; and deleting or returning data upon termination.


5. Purpose of the Processing. To enable the Customer to create, manage, and automate approval workflows and related communication within the Approveit Service, and to provide, secure, support, maintain and troubleshoot the Services.


6. Categories of Personal Data. Name, display name, username, or nickname; email address; workplace information such as team or department; identifiers provided by integrated platforms such as a Slack user ID; content of approval requests, attachments, comments and workflow messages; the content of instructions submitted by users to AI Features; timestamps such as creation time and approval time; usage logs, audit trails, session recordings and technical metadata necessary for service functionality and security.


7. Special categories of data. The Services are not intended for, and the Customer is responsible under Section 3.5 for not submitting, special categories of Personal Data. The parties do not anticipate the transfer of special category data. Any such data submitted by the Customer contrary to Section 3.5 is Processed under the measures set out in Exhibit 3.


8. Categories of Data Subjects. The Customer’s employees, contractors, and other authorized users of the Approveit Service; and individuals whose data is included in approval workflows submitted by the Customer.


C. Competent Supervisory Authority

9. The supervisory authority determined in accordance with Section 5.2.

Exhibit 2 — Vendors

Exhibit 2 — Vendors

Exhibit 2 comprises Exhibit 2A (Subprocessors) and Exhibit 2B (vendors Approveit engages for its own business operations).

Exhibit 2A - Subprocessors of Personal Data Processed on behalf of the Customer

Exhibit 2A - Subprocessors of Personal Data Processed on behalf of the Customer

These Subprocessors Process Personal Data that Approveit Processes on behalf of the Customer. This Exhibit populates Annex III of the Standard Contractual Clauses.

Subprocessor

Subprocessor

Subprocessor

Amazon Web Services (AWS)

Amazon Web Services (AWS)

Amazon Web Services (AWS)

Slack Technologies, LLC

Slack Technologies, LLC

Slack Technologies, LLC

Microsoft Teams / Microsoft Corporation

Microsoft Teams / Microsoft Corporation

Microsoft Teams / Microsoft Corporation

Intercom R&D Unlimited Company

Intercom R&D Unlimited Company

Intercom R&D Unlimited Company

Anthropic, PBC

Anthropic, PBC

Anthropic, PBC

PostHog, Inc.

PostHog, Inc.

PostHog, Inc.

ELU Labs, Inc.

ELU Labs, Inc.

ELU Labs, Inc.

Amplitude, Inc.

Amplitude, Inc.

Amplitude, Inc.

Functional Software, Inc. dba Sentry

Functional Software, Inc. dba Sentry

Functional Software, Inc. dba Sentry

Address

Address

Address

410 Terry Ave N, Seattle, WA 98109, USA

410 Terry Ave N, Seattle, WA 98109, USA

500 Howard St, San Francisco, CA 94105, USA

500 Howard St, San Francisco, CA 94105, USA

One Microsoft Way, Redmond, WA 98052, USA

One Microsoft Way, Redmond, WA 98052, USA

2nd Floor, Stephen Court, 18-21 St Stephen’s Green, Dublin 2, Ireland

2nd Floor, Stephen Court, 18-21 St Stephen’s Green, Dublin 2, Ireland

548 Market St, PMB 90375, San Francisco, CA 94104, USA

548 Market St, PMB 90375, San Francisco, CA 94104, USA

965 Mission St, San Francisco, CA 94103, USA

965 Mission St, San Francisco, CA 94103, USA

United States

United States

201 Third Street, Suite 200, San Francisco, CA 94103, USA

201 Third Street, Suite 200, San Francisco, CA 94103, USA

45 Fremont St, San Francisco, CA 94105, USA

45 Fremont St, San Francisco, CA 94105, USA

Purpose of Processing

Purpose of Processing

Purpose of Processing

Core infrastructure, hosting, databases, storage, backups

Core infrastructure, hosting, databases, storage, backups

Core infrastructure, hosting, databases, storage, backups

Workflow notifications and approval actions via Slack integration

Workflow notifications and approval actions via Slack integration

Workflow notifications and approval actions via Slack integration

Workflow notifications and collaboration via the Teams integration

Workflow notifications and collaboration via the Teams integration

Customer support chat, helpdesk, in-app support

Customer support chat, helpdesk, in-app support

Customer support chat, helpdesk, in-app support

AI model provider for the AI Assistant. Acceptable use policy: anthropic.com/legal/aup

AI model provider for the AI Assistant. Acceptable use policy: anthropic.com/legal/aup

Product analytics and session replay within the Service, including automated analysis of usage events and recordings to produce analytics

Product analytics and session replay within the Service, including automated analysis of usage events and recordings to produce analytics

Session replay and automated detection of errors and usability issues, including automated analysis of recordings

Session replay and automated detection of errors and usability issues, including automated analysis of recordings

Product analytics within the Service, including automated analysis of usage events


Product analytics within the Service, including automated analysis of usage events


Application error and performance monitoring, including automated grouping and analysis of error events

Application error and performance monitoring, including automated grouping and analysis of error events

Types of Personal Data Processed

Types of Personal Data Processed

Types of Personal Data Processed

Account data; workflow records; attachments; logs

Account data; workflow records; attachments; logs

User identity; approver metadata; message payloads

User identity; approver metadata; message payloads

User identity; workflow metadata

User identity; workflow metadata

User identity; support chat messages; usage context

User identity; support chat messages; usage context

User instructions and the approval content needed to answer them

User instructions and the approval content needed to answer them

Usage events, user identifiers, session recordings with sensitive fields masked

Usage events, user identifiers, session recordings with sensitive fields masked

Session recordings with sensitive fields masked, user identifiers, technical metadata

Session recordings with sensitive fields masked, user identifiers, technical metadata

Usage events, user identifiers, technical metadata


Usage events, user identifiers, technical metadata


Error events, stack traces, request metadata, user identifiers

Error events, stack traces, request metadata, user identifiers

Region

Region

Region

US (default), EU on request

US (default), EU on request

USA

USA

Depends on Customer tenant region

Depends on Customer tenant region

US / EU

US / EU

USA

USA

USA

USA

USA

USA

USA

USA

USA

USA

Contact for each Subprocessor is available from Approveit at support@approveit.today on request. The duration of Processing by each Subprocessor is the term of the Agreement and any retention period under Section 7.

Anthropic does not train its models on Personal Data transmitted through the Services, as provided in Section 4.3. Approveit’s agreements with the other Subprocessors listed above restrict their use of Personal Data to the provision of their services to Approveit, as provided in Section 6.4.

Where a Subprocessor listed above records sessions or receives error payloads, Approveit configures masking of sensitive fields to the extent that Subprocessor supports it.

Exhibit 2B - Vendors used by Approveit for its own business operations

Exhibit 2B - Vendors used by Approveit for its own business operations

These vendors do not Process Personal Data on behalf of the Customer. They process data for which Approveit is the controller, such as billing contacts, marketing contacts and website analytics. They are listed for transparency only, do not form part of Approveit’s contractual obligations under this Addendum, and are not Subprocessors for the purposes of Section 6 or Annex III.

Vendor

Vendor

Vendor

Stripe, Inc.

Stripe, Inc.

Stripe, Inc.

HubSpot, Inc.

HubSpot, Inc.

HubSpot, Inc.

Fathom Video, Inc.

Fathom Video, Inc.

Fathom Video, Inc.

Zoom Video Communications, Inc.

Zoom Video Communications, Inc.

Zoom Video Communications, Inc.

Hotjar Ltd.

Hotjar Ltd.

Hotjar Ltd.

Purpose

Purpose

Purpose

Payment processing and billing

Payment processing and billing

CRM and marketing communications

CRM and marketing communications

Meeting transcription and summaries for Approveit’s own sales and support calls

Meeting transcription and summaries for Approveit’s own sales and support calls

Video conferencing for Approveit’s own calls

Video conferencing for Approveit’s own calls

Website behavioural analytics

Website behavioural analytics

Region

Region

Region

USA

USA

USA

USA

USA

USA

USA

USA

EU

EU

Exhibit 3 — Technical and Organizational Measures

Exhibit 3 — Technical and Organizational Measures

This Exhibit populates Annex II of the Standard Contractual Clauses. Approveit maintains an information security program designed to protect Personal Data against unauthorized access, loss, misuse, alteration, or disclosure. The measures below describe Approveit’s own controls as at the date of this Addendum, at a level appropriate to the scale and nature of Approveit’s operations, and are designed to provide a level of security appropriate to the risk. They do not constitute a warranty that any individual control operates without exception. Subprocessor controls are addressed in Section 6.4.


1. Organizational Security

Approveit maintains a documented information security program aligned with the AICPA Trust Services Criteria and holds a SOC 2 Type II attestation. Approveit will make its then-current report available under confidentiality on request, for the scope and period stated in it. Security roles and responsibilities are defined. All personnel receive appropriate security and privacy training and are subject to confidentiality obligations.


2. Access Control

Access to systems containing Personal Data is restricted based on role and least-privilege principles. Approveit requires unique user IDs, strong authentication, and password standards. Access rights are reviewed periodically and revoked promptly upon termination or role change. Administrative access is limited to authorized personnel.


3. Data Security and Encryption

Personal Data is encrypted in transit using industry-standard transport encryption (TLS). Personal Data at rest in Approveit’s production environment is encrypted using AES-256 or an equivalent industry-standard algorithm. Encryption keys are managed through a managed key service with rotation enabled. Communications with integrations such as Slack and Microsoft Teams, and with the AI model Subprocessor, occur through secure, authenticated channels.


4. Application and Infrastructure Security

Approveit uses Amazon Web Services for hosting and follows AWS security best practices. Network security controls include firewalls, filtering, and monitoring. Vulnerability scanning is performed on a risk-assessed basis, and patches are applied under a documented patch management process. Development, staging, and production environments are logically separated.


5. Logging and Monitoring

Approveit logs system activity, access to production systems, and security events, including invocations of AI Features and access via the MCP Server. Automated monitoring and alerting mechanisms are in place to detect suspicious activity. Logs are retained for an appropriate period to support security investigations.


6. Data Backup, Availability, and Resilience

Regular backups are performed and stored securely. Backup integrity is periodically tested. AWS infrastructure provides redundancy and fault tolerance. Approveit maintains backup and restoration procedures appropriate for a cloud-based service.


7. Data Minimization and Separation

Personal Data is logically segregated by Customer in a multi-tenant environment. Production data is not used for development or testing. No Personal Data from one Customer is used to generate responses for another Customer through AI Features. Personal Data is retained and deleted in accordance with Section 7 of the Addendum.


8. AI-specific controls

Requests to the AI Assistant are scoped to the data the requesting user is already permitted to access. Actions and data access through the MCP Server are executed under the Approveit user account that authorized the connection. The AI Assistant is disabled at workspace level on request. Personal Data is not used to train or fine-tune generative AI models, and the AI model Subprocessor is contractually prohibited from doing so.


9. Incident response

Approveit maintains a documented incident response plan. Security incidents are promptly investigated and remediated. Customers are notified in accordance with Section 2.5 of the Addendum.


10. Vendor and subprocessor management

Approveit conducts risk-based security and privacy diligence on Subprocessors before engagement. Approveit requires Subprocessors to maintain security measures appropriate to the nature of the services they provide, as provided in Section 6.4 of the Addendum. Subprocessor compliance is reviewed periodically.


11. Physical security

Physical security of data centers is ensured by AWS and includes industry-standard measures such as access controls, monitoring, and environmental protections. Approveit does not operate its own data centers.


End of Data Processing Addendum

This Exhibit populates Annex II of the Standard Contractual Clauses. Approveit maintains an information security program designed to protect Personal Data against unauthorized access, loss, misuse, alteration, or disclosure. The measures below describe Approveit’s own controls as at the date of this Addendum, at a level appropriate to the scale and nature of Approveit’s operations, and are designed to provide a level of security appropriate to the risk. They do not constitute a warranty that any individual control operates without exception. Subprocessor controls are addressed in Section 6.4.


1. Organizational Security

Approveit maintains a documented information security program aligned with the AICPA Trust Services Criteria and holds a SOC 2 Type II attestation. Approveit will make its then-current report available under confidentiality on request, for the scope and period stated in it. Security roles and responsibilities are defined. All personnel receive appropriate security and privacy training and are subject to confidentiality obligations.


2. Access Control

Access to systems containing Personal Data is restricted based on role and least-privilege principles. Approveit requires unique user IDs, strong authentication, and password standards. Access rights are reviewed periodically and revoked promptly upon termination or role change. Administrative access is limited to authorized personnel.


3. Data Security and Encryption

Personal Data is encrypted in transit using industry-standard transport encryption (TLS). Personal Data at rest in Approveit’s production environment is encrypted using AES-256 or an equivalent industry-standard algorithm. Encryption keys are managed through a managed key service with rotation enabled. Communications with integrations such as Slack and Microsoft Teams, and with the AI model Subprocessor, occur through secure, authenticated channels.


4. Application and Infrastructure Security

Approveit uses Amazon Web Services for hosting and follows AWS security best practices. Network security controls include firewalls, filtering, and monitoring. Vulnerability scanning is performed on a risk-assessed basis, and patches are applied under a documented patch management process. Development, staging, and production environments are logically separated.


5. Logging and Monitoring

Approveit logs system activity, access to production systems, and security events, including invocations of AI Features and access via the MCP Server. Automated monitoring and alerting mechanisms are in place to detect suspicious activity. Logs are retained for an appropriate period to support security investigations.


6. Data Backup, Availability, and Resilience

Regular backups are performed and stored securely. Backup integrity is periodically tested. AWS infrastructure provides redundancy and fault tolerance. Approveit maintains backup and restoration procedures appropriate for a cloud-based service.


7. Data Minimization and Separation

Personal Data is logically segregated by Customer in a multi-tenant environment. Production data is not used for development or testing. No Personal Data from one Customer is used to generate responses for another Customer through AI Features. Personal Data is retained and deleted in accordance with Section 7 of the Addendum.


8. AI-specific controls

Requests to the AI Assistant are scoped to the data the requesting user is already permitted to access. Actions and data access through the MCP Server are executed under the Approveit user account that authorized the connection. The AI Assistant is disabled at workspace level on request. Personal Data is not used to train or fine-tune generative AI models, and the AI model Subprocessor is contractually prohibited from doing so.


9. Incident response

Approveit maintains a documented incident response plan. Security incidents are promptly investigated and remediated. Customers are notified in accordance with Section 2.5 of the Addendum.


10. Vendor and subprocessor management

Approveit conducts risk-based security and privacy diligence on Subprocessors before engagement. Approveit requires Subprocessors to maintain security measures appropriate to the nature of the services they provide, as provided in Section 6.4 of the Addendum. Subprocessor compliance is reviewed periodically.


11. Physical security

Physical security of data centers is ensured by AWS and includes industry-standard measures such as access controls, monitoring, and environmental protections. Approveit does not operate its own data centers.


End of Data Processing Addendum

Exhibit 1 — Details of the Data Processing

1. Subject Matter
Processing of Personal Data as necessary to provide, operate, maintain, and support the Approveit Service in accordance with the Agreement and this Addendum.


2. Duration
For the term of the Agreement and until all Personal Data is deleted or returned in accordance with Section 6 of the Addendum.


3. Nature of the Processing
Approveit processes Personal Data as required to provide the Services, including:

  • receiving, storing, and transmitting approval requests;

  • enabling approval workflows inside integrated platforms (such as Slack);

  • displaying workflow-related information to users;

  • maintaining logs, metadata, and audit trails;

  • securing, backing up, and updating the Service;

  • deleting or returning data upon termination.


4. Purpose of the Processing
To enable the Customer to create, manage, and automate approval workflows and related communication within the Approveit Service.


5. Categories of Personal Data
Personal Data processed may include, as applicable:

  • name, display name, username, or nickname;

  • workplace information (e.g., team, department);

  • identifiers provided by integrated platforms (e.g., Slack user ID);

  • content of approval requests and workflow messages;

  • timestamps (e.g., creation time, approval time);

  • usage logs and metadata necessary for service functionality and security.


6. Categories of Data Subjects
Personal Data relates to:

  • Customer’s employees, contractors, and other authorized users of the Approveit Service;

  • individuals whose data is included in approval workflows submitted by the Customer.

Data Processing Addendum