Data processing addendum

Last updated 2026-08-27

This addendum forms part of the terms of service and applies whenever we process personal data on your behalf. It takes effect automatically when you create an account — you do not have to sign anything, though we will sign a countersigned copy on request.

1. Roles

For data captured by the recorder on your site, you are the controller and we are the processor. For your own account data we are the controller; that is covered by our privacy policy.

2. Subject matter, duration, nature and purpose

  • Subject matter: recording and replaying visitor sessions on websites you operate.
  • Duration: for as long as your account is open, plus the retention window you configure.
  • Nature and purpose: capturing page structure and interaction events, storing them, and making them replayable to people you authorise.
  • Categories of data subject: visitors to your websites.
  • Categories of personal data: online identifiers of a technical kind (user-agent, viewport, country), behavioural data (clicks, scrolling, page addresses), and any personal data your own pages render that you have not blocked or masked. Input values are excluded by design.
  • Special category data: not requested, not required, and not permitted under the terms. If your pages display it, block those elements.

3. Our obligations

  • We process only on your documented instructions, which your configuration in the dashboard forms part of.
  • Everyone with access is bound by confidentiality.
  • We keep the security measures described in our security page.
  • We help you respond to data-subject requests — the deletion tooling is in the product and needs no ticket.
  • We help you with impact assessments and regulator consultations, to the extent the information is ours to give.
  • On termination we delete your data, or return it first if you ask before deletion.
  • We make available the information needed to demonstrate compliance with this clause.

4. No independent use

We do not use your visitors' data for our own purposes. Specifically: not to build profiles, not to train machine-learning models, not for advertising, and not to enrich any dataset we sell or share. It exists to be replayed by you and then deleted.

5. Sub-processors

You give general authorisation for the sub-processors on our sub-processor page. We will give at least 30 days' notice before adding or replacing one, and you may object; if we cannot resolve the objection you may terminate the affected service without penalty.

6. International transfers

Where personal data leaves the EEA or the UK, transfers rely on the European Commission's standard contractual clauses and, for the UK, the International Data Transfer Addendum, together with the measures described on our security page. Our infrastructure provider operates a global network; see the sub-processor page for their own transfer mechanisms.

7. Security measures

Encryption in transit and at rest; input values never captured; sensitive URL parameters redacted in the browser and again on ingest; role-based access with per-site scoping; two-factor authentication available on every account; an append-only audit log of who viewed, shared and deleted what; hashed session tokens; and retention enforced by both a scheduled job and a storage-level expiry.

8. Personal data breach

We will notify you without undue delay, and in any case within 48 hours of becoming aware, with what we know at the time and what we are doing about it.

9. Audit

On reasonable notice, and no more than once a year unless a regulator requires otherwise, we will answer a written security questionnaire and give you the information needed to verify this addendum.

10. Your obligations

You warrant that you have a lawful basis for the processing you instruct, that you have obtained consent where your jurisdiction requires it, that you disclose the processing in your own privacy notice, and that you can demonstrate how consent was collected. You are responsible for configuring blocking and masking for any element of your pages that should not be captured.

11. Contact

privacy@appifycommerce.com. For a countersigned copy, ask and we will send one.

This document describes our contractual commitments. It is not legal advice about your own obligations.