Data Processing Addendum
Effective 3 September 2026
This addendum forms part of the Terms of Service for customers who are subject to the GDPR, the UK GDPR or similar laws, and sets out how Appomate Pty Ltd (the Processor) processes personal data on behalf of the customer (the Controller).
1. Scope and roles
The Controller determines the purposes and means of processing customer data submitted to the Service; the Processor processes it only to provide the Service and on the Controller's documented instructions, which are the Terms, this addendum and the Controller's use of the product controls.
2. Nature of processing
| Category | Data | Subjects |
|---|---|---|
| Account | Names, email addresses, roles of the Controller's users | Controller's staff |
| Website telemetry | Crawler user agents, requested paths, request counts (no visitor identifiers by design) | None intended |
| Connected analytics | Aggregate GA4 / Search Console metrics and an OAuth refresh token | Controller's staff (token owner) |
| Content | Prompts, competitors, knowledge base, generated reports | None intended |
3. Processor obligations
- Process personal data only as instructed; inform the Controller if an instruction appears to infringe applicable law.
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement the technical and organisational measures in section 5.
- Assist the Controller with data-subject requests through the export and deletion controls in the Service, and otherwise on request.
- Notify the Controller without undue delay, and within 72 hours, after becoming aware of a personal data breach affecting the Controller's data.
- Delete or return all personal data at the end of the Service, within 30 days of account deletion, except where retention is required by law.
- Make available the information necessary to demonstrate compliance and allow for audits, subject to reasonable notice and confidentiality.
4. Subprocessors
The Controller authorises the subprocessors below. The Processor will give at least 14 days' notice by email of any addition, during which the Controller may object; if the objection cannot be resolved the Controller may terminate the affected Service.
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, storage | Sydney (AWS ap-southeast-2) |
| Google Cloud (GKE) | Application hosting and scheduled jobs | Melbourne / Sydney |
| Stripe | Payments, invoicing, tax | Global |
| Anthropic | AI analysis (citation judging, gap audits, content briefs) | United States |
| OpenAI | Citation monitoring — querying ChatGPT with web search | United States |
| Google (Gemini, Analytics, Search Console) | Citation monitoring; GA4 and Search Console data you connect | Global |
| Perplexity | Citation monitoring | United States |
| Resend | Transactional email | United States / EU |
| Cloudflare | Optional edge collector you install on your own zone | Global |
5. Security measures
- Encryption in transit (TLS) and at rest for all stores.
- Per-customer isolation enforced in the database (row-level security); all customer writes go through authenticated, role-checked application endpoints.
- Secrets and credentials stored hashed or in managed secret stores; least-privilege service accounts; keyless CI deployments.
- Automated tests and review gates before production changes; audit trail of billing and notification events.
- Access to production limited to named Appomate staff with multi-factor authentication.
6. International transfers
Primary storage is in Australia. Transfers to subprocessors outside Australia, the EU or the UK rely on the subprocessor's standard contractual clauses or equivalent safeguards.
7. Term
This addendum applies for as long as the Processor processes personal data on the Controller's behalf and survives termination to the extent obligations remain. Requests for a countersigned copy: hello@appomate.com.au.