Appbrew logo with stylized glass and smiling face icon.
Features
Glowing orange rounded square with two small vertical white rectangles inside on a white background.
Milo ✨
Push Notifications
Analytics
Subscription
Personalization
View all features
Brand stories
Case Studies
View all
How mCaffeine Built a High-Performance Mobile Experience Around Bundling, Discovery, and Retention
2.3x
higher conversion rate on app vs web
How Kiyoko Beauty Turned a Brand Refresh Into a High-Conversion Mobile Experience with Appbrew
60%
higher conversion rate on app compared to web
How SUGAR Rebuilt Mobile Into a High-Impact Commerce Engine for Promotions, Bundles, and Conversion with 70% higher conversion
70%
Higher Conversions
How Mixology Turned Offline Strength into Omnichannel Growth with Appbrew
2x
Increase in Conversion Rate
Podcast
View All
Inside Appbrew: eCommerce tech founders on building apps with AI
She Walked Away From Five Sharks: Rimjim Deka on Building Littlebox From a One-BHK Apartment
Steve Morales Scaled a Denim Brand from $20M to $50M
How to Build a Multi-Million Dollar Cross-Border Brand
Help Centre
Visit
Pricing
Resources
Blogs
View All
Shopify SEO Checklist
Shopify SEO Checklist: 34 Steps to Rank Your Store in 2026
Mobile App Retention: Benchmarks and Strategies for Online Stores (2026)
Mobile App Retention: Benchmarks and Strategies for Online Stores (2026)
Customer Retention Statistics 2026
Customer Retention Statistics by Industry: 2026 Report
Push Notifications vs SMS: Which Wins for Ecommerce?
Push Notifications vs SMS: Ecommerce Costs, CTR and Conversion Data (2026)
Shopify SEO Checklist
Shopify SEO Checklist: 34 Steps to Rank Your Store in 2026
Mobile App Retention: Benchmarks and Strategies for Online Stores (2026)
Mobile App Retention: Benchmarks and Strategies for Online Stores (2026)
Customer Retention Statistics 2026
Customer Retention Statistics by Industry: 2026 Report
Comparison
View All
Two Ionic columns, one cracked with tapcart logo, the other blue with glowing Appbrew logo on top.
Tapcart vs Appbrew
Show Comparison
Two classical columns side by side: one stone with Shopney logo, one blue with Appbrew logo in night sky.
Shopney vs Appbrew
Show Comparison
Help Centre
Visit
Partners
Integrations
View All (100+)
Subscriptions
Yotpo company logo with white text on a blue background.Loop brand logo in white on a purple background.White abstract geometric shapes forming an angular symbol on a solid blue background.Gray text showing plus 20 symbol on white background.
Rewards
Minimalist white upside-down U shape on a solid yellow background.Black circular abstract logo design with concentric lines on a turquoise background.Loox brand logo with stylized double infinity symbol on black background.Gray text showing plus 20 symbol on white background.
Reviews
White silhouette of a running rabbit on a red background.White bold text on a red background spelling the word BOLD.Green square icon with a white scissors cutting a white ticket or coupon shape.Gray text showing plus 20 symbol on white background.
Search
White chat bubble with magnifying glass inside on a blue square background.Infinity symbol in purple and orange gradient inside white circle on blue to yellow background.Magnifying glass icon with a black handle on a blue to purple gradient background.Gray text showing plus 20 symbol on white background.
Analytics
Google Analytics logo with three vertical bars in orange shades.Blue triangular geometric shape with gradient from light to dark blue.CleverTap logo with a red curved line on the left and black text on white background.Gray text showing plus 20 symbol on white background.
Agencies
Explore Service Partners
Start a Free Trial
Talk to us

Data Processing Addendum

Last updated: 13 August 2026

This Data Processing Addendum (“Addendum” or “DPA”) forms part of and supplements the Master SaaS and Services Agreement, Order Form, and/or Terms of Use between Appbrew Inc. (“Vendor” or “Appbrew”) and the customer that accepts it (“Client”), together the “Agreement”. This Addendum is entered into by reference from, and is deemed executed upon the Client’s acceptance of, the Agreement or the Client’s use of the Services; no separate signature is required. The Client and its authorised affiliates are identified by the account registration and Order Form details associated with the Agreement.

In the event of any conflict between the provisions of the Agreement and this Addendum, this Addendum prevails with respect to the processing of personal data. Except as amended here, the Agreement remains in full force and effect.

1. Definitions and interpretation

1.1 In this Addendum:

“Affiliate” means any entity that controls, is controlled by, or is under common control with a party.

“Data Protection Legislation” means all applicable data protection and privacy laws, including the EU General Data Protection Regulation (EU) 2016/679 (“EU GDPR”), the UK GDPR and UK Data Protection Act 2018 (“UK GDPR”), the Swiss Federal Act on Data Protection, and U.S. Data Protection Laws, together with any implementing or successor legislation and applicable regulatory guidance.

“Data Controller”, “Data Processor”, “Data Subject”, “Personal Data”, “Processing”, “Supervisory Authority”, and “Appropriate Technical and Organisational Measures” have the meanings given in the applicable Data Protection Legislation.

“Standard Contractual Clauses” or “SCCs” means, as applicable, (i) the clauses annexed to European Commission Implementing Decision (EU) 2021/914 (“EU SCCs”); and (ii) the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner (“UK Addendum”) for transfers subject to UK GDPR.

“Restricted Transfer” means a transfer of Personal Data to a country that is not the subject of an adequacy decision under the EU GDPR or UK GDPR, as applicable.

“Sub-processor” means any third party engaged by Vendor to process Personal Data in connection with the Services.

“Security Breach” means any accidental, unauthorised, or unlawful destruction, loss, alteration, or disclosure of, or access to, Personal Data processed under this Addendum.

“U.S. Data Protection Laws” means applicable U.S. federal and state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”).

1.2 Annexes I, II, and III form part of this Addendum.

2. Processing of personal data

2.1 This Addendum applies to Personal Data processed by Vendor on behalf of Client under the Agreement. Client is the Data Controller and Vendor is the Data Processor. For the purposes of U.S. Data Protection Laws, Vendor acts as a “service provider” / “processor”.

2.2 The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are described in Annex I.

3. Obligations of vendor

3.1 Vendor shall process Personal Data only on documented instructions from Client, including as set out in this Addendum and the Agreement, and as necessary to provide the Services, unless required to do otherwise by law (in which case Vendor shall inform Client unless legally prohibited).

3.2 Vendor shall notify Client if, in its opinion, an instruction infringes applicable Data Protection Legislation.

3.3 Taking into account the nature of the processing, Vendor shall assist Client by Appropriate Technical and Organisational Measures, insofar as possible, in fulfilling Client’s obligations to respond to Data Subject rights requests, and in ensuring compliance with Articles 32 to 36 of the GDPR (security, breach notification, and data protection impact assessments), taking into account the information available to Vendor.

3.4 Vendor shall implement and maintain the Appropriate Technical and Organisational Measures described in Annex II and at appbrew.com/security.

Cookies: Like many online services, we use cookies to collect information. “Cookies” are small pieces of information that a website sends to your computer’s hard drive while you are viewing the website or application. We may use both session Cookies (which expire once you close your web browser) and persistent Cookies (which stay on your computer until you delete them) to provide you with a more personal and interactive experience on our Site and Services.

4. Sub-processing

4.1 Client provides Vendor with a general authorisation to engage Sub-processors to process Personal Data, subject to this Section 4. Vendor maintains a current list of Sub-processors at appbrew.com/subprocessors.

4.2 Vendor shall give Client at least thirty (30) days’ notice of the addition or replacement of any Sub-processor (via the sub-processor page’s subscription mechanism or by email). Client may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection in good faith, Client may terminate the affected Services on written notice.

5. Confidentiality

5.1 Vendor shall ensure that personnel authorised to process the Personal Data are subject to binding confidentiality obligations and are appropriately reliable and trained.

5.2 On expiry or termination of the Services, and at Client’s request, Vendor shall securely delete or return the Personal Data and delete existing copies, unless retention is required by law.

6. Security breaches

6.1 Vendor shall notify Client without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a confirmed Security Breach affecting Client Personal Data.

6.2 The notification shall describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it. Vendor shall provide reasonable updates as further information becomes available.

6.3 Vendor shall, at its own expense, take reasonable steps to investigate, contain, and mitigate the Security Breach.

7. International data transfers

7.1 Any Restricted Transfer of Personal Data under this Addendum is subject to the appropriate Standard Contractual Clauses, which are incorporated into this Addendum by reference and completed as set out below.

7.2 EU GDPR transfers — EU SCCs apply, completed as follows: Module Two applies where Client is a controller, and Module Three applies where Client is a processor acting for a third-party controller; the docking clause (Clause 7) applies as required; in Clause 9, Option 1 (general written authorisation) applies, with the notice period in Section 4.2 of this Addendum; the Clause 11 optional independent-redress language does not apply; the governing law and forum for the EU SCCs (Clauses 17 and 18) is the Republic of Ireland; the Clause 8.9 audit rights are satisfied by Section 8 of this Addendum; the Clause 16(d) obligations are satisfied by the deletion and return measures in this Addendum; and Annexes I, II, and III of the EU SCCs are completed with the corresponding Annexes of this Addendum.

7.3 UK GDPR transfers — UK Addendum applies: the EU SCCs as completed above apply as amended by the UK Addendum issued by the UK Information Commissioner, which is deemed executed between the parties.

7.4 No Sub-processor shall undertake a Restricted Transfer except in compliance with the applicable SCCs and Data Protection Legislation.

8. Audit

8.1 Vendor shall make available to Client the information reasonably necessary to demonstrate compliance with Article 28 of the GDPR and this Addendum, primarily through Vendor’s then-current security documentation, certifications (e.g., its hosting providers’ ISO 27001 and PCI DSS certifications), and responses to reasonable security questionnaires.

8.2 Where that information is not sufficient, Client (or an independent auditor bound by confidentiality) may conduct an audit of Vendor’s processing on reasonable prior written notice (at least thirty (30) days), no more than once per twelve (12) month period (unless required more frequently by a Supervisory Authority or following a Security Breach), during business hours, without unreasonably disrupting Vendor’s operations, and at Client’s cost.

9. Liability

9.1 Each party’s aggregate liability arising out of or related to this Addendum and the processing of Personal Data, whether in contract, tort, or otherwise, shall not exceed the total fees paid or payable by Client under the Agreement in the twelve (12) months preceding the event giving rise to the claim. This cap supersedes any conflicting limitation of liability in the Agreement with respect to data-protection claims, and applies in the aggregate across the Agreement and this Addendum.

10. U.S. state privacy laws

10.1 To the extent required by U.S. Data Protection Laws, Vendor shall not: (a) sell Client Personal Data or share it for cross-context behavioural advertising; (b) retain, use, or disclose Client Personal Data for any purpose other than performing the Services or as permitted by law; (c) retain, use, or disclose Client Personal Data outside the direct business relationship between the parties; or (d) combine Client Personal Data with personal data from other sources except as permitted by U.S. Data Protection Laws. Vendor certifies that it understands and will comply with these restrictions.

11. Term and termination

11.1 This Addendum takes effect on the Client’s acceptance of the Agreement and continues until the Agreement expires or terminates. Provisions that by their nature should survive termination shall survive. Termination does not affect accrued rights or obligations.

Annex I - Description of the processing

Parties. The data exporter / Client / controller is the customer identified by the account and Order Form associated with the Agreement. The data importer / Vendor / processor is Appbrew Inc., 919 North Market Street, Suite 950, Wilmington, New Castle, DE 19801, USA; data protection contact: Mayank Agarwal, mayank@appbrew.tech.

Categories of Data Subjects: (i) consumers/end users of the Client’s platform or app; and (ii) the Client’s personnel who use the Services.

Categories of Personal Data: consumer identifying and contact information (e.g., name, email address, date of birth, country of residence, address history), messages, settings, ratings, and price, payment, and booking information; and technical data including device and browser information and IP address. For Client personnel: name, email address, and technical/device data.

Sensitive data: none intended or required.

Frequency of transfer: continuous, for the term of the Agreement.

Nature and purpose of processing: performance of the Services as described in the Agreement.

Retention period: for as long as necessary to provide the Services, or as required by applicable law.

Competent Supervisory Authority: determined in accordance with the GDPR based on the data exporter’s establishment or representative.

Annex II - Technical and organisational measures

A summary of Appbrew’s technical and organisational security measures is maintained at appbrew.com/security and forms part of this Addendum. These include, at a minimum: encryption of Personal Data in transit and at rest; role-based access controls and multi-factor authentication; use of certified cloud infrastructure (ISO 27001, PCI DSS); network security and continuous monitoring; regular backups and disaster recovery; vulnerability management, patching, and penetration testing; documented incident response; and personnel confidentiality and security-awareness training.

Annex III - Sub-processors

The current list of authorised Sub-processors is maintained at appbrew.com/subprocessors and forms part of this Addendum.

Apollo7 logo with stylized text and a leaf-shaped icon.
Instantly turn your Shopify store into an epic mobile app, no coding required.
Intercert logo with text: ISO/IEC 27001:2022 Certified.
Shopify logo with text 'Find it on the Shopify App Store' in a rectangular button.
Solutions
PlatformInstall AppbrewPush NotificationsIntegrationsPricing
Company
About UsContact usPrivacy policyTerms of useData processing addendumSub-processorsSecurityTrust & compiance
Resources
BlogsCase studiesHelp centreNewsletterDeveloper docs
Free tools
Markup calculatorCalculate customer acquisition costPercent off & discount calculatorMargin calculatorMobile app development costApp icon generator & resizerSKU & bar code generator
Comparisons
Tapcart vs AppbrewShopney vs AppbrewVajro vs AppbrewMobiLoud vs AppbrewVenn Apps vs AppbrewOneMobile vs AppbrewAppbrew vs Competitors
LIMITED TIME

Before you go...

Want 3x higher conversions and 6x higher LTV for your Shopify store?

We'll show you exactly how.

Unlock the secret
Maybe later

Unlocking the secret...

Fill the details and we'll share it with you

Thanks — we'll be in touch!

We've received your details and will share the secret with you shortly.

logo-1 logo-2 logo-3 logo-4 logo-5 logo-6 logo-7 logo-8