Data Processing Addendum
Last updated: 13 August 2026
This Data Processing Addendum (“Addendum” or “DPA”) forms part of and supplements the Master SaaS and Services Agreement, Order Form, and/or Terms of Use between Appbrew Inc. (“Vendor” or “Appbrew”) and the customer that accepts it (“Client”), together the “Agreement”. This Addendum is entered into by reference from, and is deemed executed upon the Client’s acceptance of, the Agreement or the Client’s use of the Services; no separate signature is required. The Client and its authorised affiliates are identified by the account registration and Order Form details associated with the Agreement.In the event of any conflict between the provisions of the Agreement and this Addendum, this Addendum prevails with respect to the processing of personal data. Except as amended here, the Agreement remains in full force and effect.1. Definitions and interpretation
1.1 In this Addendum:“Affiliate” means any entity that controls, is controlled by, or is under common control with a party.“Data Protection Legislation” means all applicable data protection and privacy laws, including the EU General Data Protection Regulation (EU) 2016/679 (“EU GDPR”), the UK GDPR and UK Data Protection Act 2018 (“UK GDPR”), the Swiss Federal Act on Data Protection, and U.S. Data Protection Laws, together with any implementing or successor legislation and applicable regulatory guidance.“Data Controller”, “Data Processor”, “Data Subject”, “Personal Data”, “Processing”, “Supervisory Authority”, and “Appropriate Technical and Organisational Measures” have the meanings given in the applicable Data Protection Legislation.“Standard Contractual Clauses” or “SCCs” means, as applicable, (i) the clauses annexed to European Commission Implementing Decision (EU) 2021/914 (“EU SCCs”); and (ii) the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner (“UK Addendum”) for transfers subject to UK GDPR.“Restricted Transfer” means a transfer of Personal Data to a country that is not the subject of an adequacy decision under the EU GDPR or UK GDPR, as applicable.“Sub-processor” means any third party engaged by Vendor to process Personal Data in connection with the Services.“Security Breach” means any accidental, unauthorised, or unlawful destruction, loss, alteration, or disclosure of, or access to, Personal Data processed under this Addendum.“U.S. Data Protection Laws” means applicable U.S. federal and state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”).1.2 Annexes I, II, and III form part of this Addendum.2. Processing of personal data
2.1 This Addendum applies to Personal Data processed by Vendor on behalf of Client under the Agreement. Client is the Data Controller and Vendor is the Data Processor. For the purposes of U.S. Data Protection Laws, Vendor acts as a “service provider” / “processor”.2.2 The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are described in Annex I.3. Obligations of Vendor
3.1 Vendor shall process Personal Data only on documented instructions from Client, including as set out in this Addendum and the Agreement, and as necessary to provide the Services, unless required to do otherwise by law (in which case Vendor shall inform Client unless legally prohibited).3.2 Vendor shall notify Client if, in its opinion, an instruction infringes applicable Data Protection Legislation.3.3 Taking into account the nature of the processing, Vendor shall assist Client by Appropriate Technical and Organisational Measures, insofar as possible, in fulfilling Client’s obligations to respond to Data Subject rights requests, and in ensuring compliance with Articles 32 to 36 of the GDPR (security, breach notification, and data protection impact assessments), taking into account the information available to Vendor.3.4 Vendor shall implement and maintain the Appropriate Technical and Organisational Measures described in Annex II and at appbrew.com/security.4. Sub-processing
4.1 Client provides Vendor with a general authorisation to engage Sub-processors to process Personal Data, subject to this Section 4. Vendor maintains a current list of Sub-processors at appbrew.com/subprocessors.4.2 Vendor shall give Client at least thirty (30) days’ notice of the addition or replacement of any Sub-processor (via the sub-processor page’s subscription mechanism or by email). Client may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection in good faith, Client may terminate the affected Services on written notice.4.3 Vendor shall impose data protection obligations on each Sub-processor that are no less protective than those in this Addendum, and remains fully liable to Client for its Sub-processors’ performance.5. Confidentiality
5.1 Vendor shall ensure that personnel authorised to process the Personal Data are subject to binding confidentiality obligations and are appropriately reliable and trained.5.2 On expiry or termination of the Services, and at Client’s request, Vendor shall securely delete or return the Personal Data and delete existing copies, unless retention is required by law.6. Security breaches
6.1 Vendor shall notify Client without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a confirmed Security Breach affecting Client Personal Data.6.2 The notification shall describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it. Vendor shall provide reasonable updates as further information becomes available.6.3 Vendor shall, at its own expense, take reasonable steps to investigate, contain, and mitigate the Security Breach.7. International data transfers
7.1 Any Restricted Transfer of Personal Data under this Addendum is subject to the appropriate Standard Contractual Clauses, which are incorporated into this Addendum by reference and completed as set out below.7.2 EU GDPR transfers — EU SCCs apply, completed as follows: Module Two applies where Client is a controller, and Module Three applies where Client is a processor acting for a third-party controller; the docking clause (Clause 7) applies as required; in Clause 9, Option 1 (general written authorisation) applies, with the notice period in Section 4.2 of this Addendum; the Clause 11 optional independent-redress language does not apply; the governing law and forum for the EU SCCs (Clauses 17 and 18) is the Republic of Ireland; the Clause 8.9 audit rights are satisfied by Section 8 of this Addendum; the Clause 16(d) obligations are satisfied by the deletion and return measures in this Addendum; and Annexes I, II, and III of the EU SCCs are completed with the corresponding Annexes of this Addendum.7.3 UK GDPR transfers — UK Addendum applies: the EU SCCs as completed above apply as amended by the UK Addendum issued by the UK Information Commissioner, which is deemed executed between the parties.7.4 No Sub-processor shall undertake a Restricted Transfer except in compliance with the applicable SCCs and Data Protection Legislation.8. Audit
8.1 Vendor shall make available to Client the information reasonably necessary to demonstrate compliance with Article 28 of the GDPR and this Addendum, primarily through Vendor’s then-current security documentation, certifications (e.g., its hosting providers’ ISO 27001 and PCI DSS certifications), and responses to reasonable security questionnaires.8.2 Where that information is not sufficient, Client (or an independent auditor bound by confidentiality) may conduct an audit of Vendor’s processing on reasonable prior written notice (at least thirty (30) days), no more than once per twelve (12) month period (unless required more frequently by a Supervisory Authority or following a Security Breach), during business hours, without unreasonably disrupting Vendor’s operations, and at Client’s cost.9. Liability
9.1 Each party’s aggregate liability arising out of or related to this Addendum and the processing of Personal Data, whether in contract, tort, or otherwise, shall not exceed the total fees paid or payable by Client under the Agreement in the twelve (12) months preceding the event giving rise to the claim. This cap supersedes any conflicting limitation of liability in the Agreement with respect to data-protection claims, and applies in the aggregate across the Agreement and this Addendum.10. U.S. state privacy laws
10.1 To the extent required by U.S. Data Protection Laws, Vendor shall not: (a) sell Client Personal Data or share it for cross-context behavioural advertising; (b) retain, use, or disclose Client Personal Data for any purpose other than performing the Services or as permitted by law; (c) retain, use, or disclose Client Personal Data outside the direct business relationship between the parties; or (d) combine Client Personal Data with personal data from other sources except as permitted by U.S. Data Protection Laws. Vendor certifies that it understands and will comply with these restrictions.11. Term and termination
11.1 This Addendum takes effect on the Client’s acceptance of the Agreement and continues until the Agreement expires or terminates. Provisions that by their nature should survive termination shall survive. Termination does not affect accrued rights or obligations.Annex I — Description of the processing
Parties. The data exporter / Client / controller is the customer identified by the account and Order Form associated with the Agreement. The data importer / Vendor / processor is Appbrew Inc., 919 North Market Street, Suite 950, Wilmington, New Castle, DE 19801, USA; data protection contact: Mayank Agarwal, mayank@appbrew.tech.Categories of Data Subjects: (i) consumers/end users of the Client’s platform or app; and (ii) the Client’s personnel who use the Services.Categories of Personal Data: consumer identifying and contact information (e.g., name, email address, date of birth, country of residence, address history), messages, settings, ratings, and price, payment, and booking information; and technical data including device and browser information and IP address. For Client personnel: name, email address, and technical/device data.Sensitive data: none intended or required.Frequency of transfer: continuous, for the term of the Agreement.Nature and purpose of processing: performance of the Services as described in the Agreement.Retention period: for as long as necessary to provide the Services, or as required by applicable law.Competent Supervisory Authority: determined in accordance with the GDPR based on the data exporter’s establishment or representative.Annex II — Technical and organisational measures
A summary of Appbrew’s technical and organisational security measures is maintained at appbrew.com/security and forms part of this Addendum. These include, at a minimum: encryption of Personal Data in transit and at rest; role-based access controls and multi-factor authentication; use of certified cloud infrastructure (ISO 27001, PCI DSS); network security and continuous monitoring; regular backups and disaster recovery; vulnerability management, patching, and penetration testing; documented incident response; and personnel confidentiality and security-awareness training.Annex III — Sub-processors
The current list of authorised Sub-processors is maintained at appbrew.com/subprocessors and forms part of this Addendum.