AI Visibility

Draft — pending legal review. This text describes how the service operates today and will be finalised before it is relied on as a contract.

Data Processing Addendum

Effective 3 September 2026

This addendum forms part of the Terms of Service for customers who are subject to the GDPR, the UK GDPR or similar laws, and sets out how Appomate Pty Ltd (the Processor) processes personal data on behalf of the customer (the Controller).

1. Scope and roles

The Controller determines the purposes and means of processing customer data submitted to the Service; the Processor processes it only to provide the Service and on the Controller's documented instructions, which are the Terms, this addendum and the Controller's use of the product controls.

2. Nature of processing

CategoryDataSubjects
AccountNames, email addresses, roles of the Controller's usersController's staff
Website telemetryCrawler user agents, requested paths, request counts (no visitor identifiers by design)None intended
Connected analyticsAggregate GA4 / Search Console metrics and an OAuth refresh tokenController's staff (token owner)
ContentPrompts, competitors, knowledge base, generated reportsNone intended

3. Processor obligations

  • Process personal data only as instructed; inform the Controller if an instruction appears to infringe applicable law.
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Implement the technical and organisational measures in section 5.
  • Assist the Controller with data-subject requests through the export and deletion controls in the Service, and otherwise on request.
  • Notify the Controller without undue delay, and within 72 hours, after becoming aware of a personal data breach affecting the Controller's data.
  • Delete or return all personal data at the end of the Service, within 30 days of account deletion, except where retention is required by law.
  • Make available the information necessary to demonstrate compliance and allow for audits, subject to reasonable notice and confidentiality.

4. Subprocessors

The Controller authorises the subprocessors below. The Processor will give at least 14 days' notice by email of any addition, during which the Controller may object; if the objection cannot be resolved the Controller may terminate the affected Service.

SubprocessorPurposeLocation
SupabaseDatabase, authentication, storageSydney (AWS ap-southeast-2)
Google Cloud (GKE)Application hosting and scheduled jobsMelbourne / Sydney
StripePayments, invoicing, taxGlobal
AnthropicAI analysis (citation judging, gap audits, content briefs)United States
OpenAICitation monitoring — querying ChatGPT with web searchUnited States
Google (Gemini, Analytics, Search Console)Citation monitoring; GA4 and Search Console data you connectGlobal
PerplexityCitation monitoringUnited States
ResendTransactional emailUnited States / EU
CloudflareOptional edge collector you install on your own zoneGlobal

5. Security measures

  • Encryption in transit (TLS) and at rest for all stores.
  • Per-customer isolation enforced in the database (row-level security); all customer writes go through authenticated, role-checked application endpoints.
  • Secrets and credentials stored hashed or in managed secret stores; least-privilege service accounts; keyless CI deployments.
  • Automated tests and review gates before production changes; audit trail of billing and notification events.
  • Access to production limited to named Appomate staff with multi-factor authentication.

6. International transfers

Primary storage is in Australia. Transfers to subprocessors outside Australia, the EU or the UK rely on the subprocessor's standard contractual clauses or equivalent safeguards.

7. Term

This addendum applies for as long as the Processor processes personal data on the Controller's behalf and survives termination to the extent obligations remain. Requests for a countersigned copy: hello@appomate.com.au.