Data Processing Addendum
Last updated July 20, 2026. How TSI processes Customer Personal Data for Appify customers.
This Data Processing Addendum (“DPA”) forms part of the Terms of Service when you use the Service to process personal data of end users or other individuals (“Customer Personal Data”).
1. Roles
- You are the controller (or processor instructing us on behalf of a controller) of Customer Personal Data you submit to the Service.
- TSI is the processor of that Customer Personal Data, and the controller of account and platform data as described in the Privacy Policy.
2. Scope of processing
Subject matter: hosting and processing Customer Personal Data to provide Appify features you enable (previews, forms, databases you connect, AI proxies, builds). Duration: for the term of your account plus deletion/backup windows. Nature: storage, transmission, generation, logging. Purpose: provide the Service on your documented instructions (configuration + API/product usage).
3. Our obligations
- Process Customer Personal Data only on your instructions (including these Terms and product settings)
- Ensure personnel are bound by confidentiality
- Implement appropriate technical and organizational security measures
- Engage sub-processors (hosting, AI, email, payments, Expo, etc.) under written terms with equivalent protections
- Assist with data subject requests and security incidents as reasonably required
- Delete or return Customer Personal Data after account closure, subject to legal retention
4. Your obligations
- Have a lawful basis to collect and process Customer Personal Data
- Provide required notices to end users (including your own privacy policy in published apps)
- Do not instruct us to process data in violation of law
- Configure credentials, retention, and access inside your apps appropriately
5. Sub-processors
We use infrastructure and product vendors necessary to run Appify. A current list is available on request at legal@tsi.app. We will provide notice of material sub-processor changes where required.
6. International transfers
Where Customer Personal Data is transferred internationally, parties will use appropriate safeguards (for example SCCs) as required by applicable law.
7. Security incidents
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help you meet your obligations.