Legal

Data Processing Addendum

How we process personal data on behalf of account holders, as required by Article 28 of the UK GDPR.

Current version. Effective and last updated 8 September 2026.

1. Parties and incorporation

This Data Processing Addendum (“DPA”) is entered into between My Pet Walker Ltd, trading as Appy Hub, registered in England and Wales with company number 11215766 and registered office at 247 Bury Old Road, Prestwich, Manchester, M25 1JE (“Appy Hub”, “we”, the processor), and the account holder that uses the Appy Hub platform (“you”, the controller).

This DPA is incorporated into and forms part of our Terms of Service and should be read alongside our Privacy Policy. Where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails.

“UK GDPR” means the UK General Data Protection Regulation as supplemented by the Data Protection Act 2018. “Personal data”, “processing”, “controller”, “processor”, “subprocessor” and “data subject” carry the meanings given in the UK GDPR.

2. Roles of the parties

You are the controller of the personal data you and your team put into the platform, and of the personal data contained in the messages, contacts and records you receive through the channels you connect. We act as your processor for that data and process it only on your documented instructions, which are given through your use of the platform, your workspace settings and this DPA.

We act as controller in our own right only for the limited data we need to run our business: your account and billing records, support correspondence with us, and security and service logs. That processing is described in our Privacy Policy and is not governed by this DPA.

3. Subject matter and duration

The subject matter of the processing is the provision of the Appy Hub platform to you. Processing lasts for as long as your account is open, and then for the short period described in section 13 and in the retention section of our Privacy Policy while data is deleted or returned.

4. Nature and purpose of processing

  • Receiving, storing, organising and displaying messages from the channels you connect, including email, WhatsApp, Telegram, Facebook, Instagram, Messenger, TikTok and website live chat.
  • Storing and organising contact, client and prospect records, appointments, projects, documents and accounting entries.
  • Sending messages, replies and notifications on your instruction.
  • Generating suggested replies, summaries, transcriptions and drafts where you have AI features switched on.
  • Hosting, backup, error monitoring, security protection and technical support.

5. Types of personal data

  • Identifiers and contact details: names, email addresses, telephone numbers, messaging handles and account identifiers.
  • Message content and attachments, including images, documents, voice notes and their transcriptions.
  • Appointment, booking and location details you record.
  • Financial and transactional data you record, such as invoices, payments and expenses.
  • Notes, tags, pipeline stages and other free-text records created by you or your team.
  • Technical data such as IP addresses and device information contained in logs.

You should not use the platform to process special category data or criminal offence data unless you have told us in writing and we have agreed the additional measures required.

6. Categories of data subject

  • Your customers, clients and prospective customers.
  • People who message you through any connected channel.
  • Your employees, contractors and other authorised users of your workspace.
  • Your suppliers and other business contacts.

7. Our obligations as processor

In line with Article 28 of the UK GDPR, we will:

  • Process personal data only on your documented instructions, including on international transfers, unless we are required to do otherwise by law, in which case we will tell you before processing unless the law prohibits it.
  • Ensure that everyone authorised to process the data is subject to a duty of confidentiality.
  • Implement the technical and organisational security measures described in section 10.
  • Engage subprocessors only on the terms in section 8.
  • Assist you in responding to data subject requests, as described in section 12.
  • Assist you with data protection impact assessments and prior consultation with the Information Commissioner's Office, so far as the information is available to us.
  • Notify you of a personal data breach without undue delay, as described in section 12.
  • Delete or return personal data at the end of the service, as described in section 13.
  • Make available the information needed to demonstrate compliance and allow audits, as described in section 9.
  • Tell you promptly if, in our opinion, an instruction from you would infringe data protection law.

8. Subprocessors

You give us general authorisation to engage the subprocessors listed in section 7 of our Privacy Policy, which at the date of this DPA are:

  • Supabase — database, authentication and file storage, hosted in the EU.
  • Lovable — application hosting.
  • Stripe — payments and billing.
  • Meta Platforms — Facebook, Messenger and Instagram messaging and publishing, where you connect those channels.
  • DigitalOcean — infrastructure for messaging connectors.
  • Cloudflare — DNS and network security.
  • The Appy Hub mail server at mail.appyhub.io — transactional and enquiry email.
  • The AI and messaging providers named in our Privacy Policy — only for the features and channels you enable.

We impose data protection obligations on every subprocessor that are no less protective than those in this DPA, and we remain responsible to you for their performance. We will give you at least 30 days’ notice by email, and by updating the list in our Privacy Policy, before adding or replacing a subprocessor. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative, and if we cannot you may terminate the affected part of the service without penalty for the unused portion of any prepaid fees.

9. Audit rights

On written request, and no more than once a year unless a breach or regulator requires otherwise, we will provide the information you reasonably need to verify our compliance with this DPA. Where that is not enough, you or an independent auditor you appoint may audit our processing on at least 30 days’ notice, during working hours, subject to confidentiality and to reasonable steps to avoid disruption to our service or to other customers.

10. Security measures

  • Encryption of data in transit using TLS, and encryption of data at rest.
  • Row-level database security so each workspace can only reach its own records.
  • Role-based permissions within a workspace, and invite-only access to the platform.
  • Two-factor authentication available on accounts, and enforced for administrative access.
  • Least-privilege access for our staff, granted only where needed to operate or support the service.
  • Uptime, error and security monitoring with alerting, and audit logging of administrative actions.
  • Regular backups, and restoration testing of those backups.
  • Secret and credential management outside the application code base.

11. International transfers

Personal data is stored in the United Kingdom or the European Economic Area. Where a subprocessor processes personal data outside the UK, we rely on UK adequacy regulations where they apply, and otherwise on the International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses, together with a transfer risk assessment and any additional safeguards it identifies. You instruct us to make those transfers for the purposes of providing the service.

12. Data subject requests and breach notification

You can access, export, correct and delete the personal data in your workspace directly through the platform. If a data subject contacts us instead of you, we will not respond on your behalf except to confirm the request has been passed on, and we will tell you without undue delay. We will give you reasonable technical assistance in meeting requests you cannot fulfil yourself.

If we become aware of a personal data breach affecting personal data we process for you, we will notify you without undue delay and in any event within 48 hours of becoming aware, describe the nature of the breach and the categories and approximate number of records affected so far as known, describe the likely consequences and the measures we have taken or propose to take, and keep you updated as we learn more.

13. Deletion or return on termination

You can export your data at any time while your account is open. On termination, and on request, we will return your personal data in a commonly used machine-readable format. We will then delete the personal data we process for you within 30 days of account closure, including from routine backups within the backup cycle, except where we are required by law to keep it, in which case we will keep only what the law requires and continue to protect it under this DPA.

14. Liability, changes and contact

The liability provisions of the Terms of Service apply to this DPA. We may update this DPA where a change in law, in our subprocessors or in the service requires it. Material changes will be notified by email to account holders and by publishing the new version on this page with a new date.

Questions about this DPA, or requests for a signed copy, can be sent to privacy@appyhub.io.