Data Processing Agreement
Version 1.3 · Effective date: 12 September 2026 · Governing law: Scotland
Online incorporation
This Data Processing Agreement ("DPA") forms part of and is incorporated or accepted with the Terms of Service or applicable Order. It need not be separately signed. By expressly accepting the Terms where an acceptance control is presented or entering an Order, each party is treated as having signed this DPA and, where applicable, the Standard Contractual Clauses and UK Addendum incorporated by it. Each version applies from the later of that acceptance or Order date and the version effective date stated on its cover.
1 Parties and legal framework
This DPA is between the Customer identified in the applicable account or Order ("Controller") and AppGantry Ltd ("Processor"). It applies where Processor handles personal data on Controller's behalf in connection with mobile service offerings.
"Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the EU GDPR where applicable, and other data-protection law applicable to the processing. "Personal Data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings in Data Protection Law.
2 Scope, roles and instructions
Where Controller acts as controller, it determines the purposes and means of processing Customer Personal Data. Where Controller acts as a processor for a third-party controller, those purposes and means are determined by that controller and conveyed through Controller's documented instructions. Processor will process Customer Personal Data only on those documented instructions, including the Terms, Order, Service configuration and authorised support requests, unless law requires otherwise. If legally permitted, Processor will inform Controller before required processing.
Where Controller processes Customer Personal Data as a processor for a third-party controller, Controller warrants that it is authorised by that controller to enter this DPA and issue the instructions given under it. Those instructions must be consistent with the third-party controller's instructions. Controller will provide that controller's identity and contact details for the SCC annexes on Processor's reasonable request.
Processor will promptly tell Controller if it believes an instruction infringes Data Protection Law and may pause the affected processing while the parties clarify it. Controller is responsible for lawful instructions, notices, legal bases, data accuracy and the rights needed to provide Customer Personal Data.
For clarity, Customer Personal Data under this DPA is limited to personal data in Customer Content: Build binaries and their contents, Customer-authored filenames, release notes and descriptions, distribution lists or content supplied by Controller, and narrowly necessary metadata processed solely on Controller's instructions. AppGantry acts as controller, not Processor under this DPA, for account and authentication data, memberships and roles, tester identities, the device registry, download and session telemetry, audit events, metering, billing, support and security records it creates to operate the Service.
A recipient identifier is Customer Personal Data when it appears in a distribution list or other Customer Content supplied on Controller's instruction. Account, invitation, membership, device and download records that AppGantry creates and maintains about that person are AppGantry controller records governed by the Privacy Policy.
3 Confidentiality and personnel
Processor will ensure people authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality and receive access only where needed for their role. Processor will maintain proportionate privacy and security awareness measures.
4 Security
Processor will implement and maintain appropriate technical and organisational measures taking account of the state of the art, implementation costs, processing context and risks. The measures Processor is contractually obliged to maintain are those set out in Annex 2. The Security Overview provides further non-contractual description and does not vary Annex 2. Processor may update measures without materially reducing the overall protection of Customer Personal Data.
5 Subprocessors
Controller gives general written authorisation for Processor to appoint subprocessors. The current providers and functions are listed in the Subprocessor List supplied or otherwise made available with this DPA, which forms Annex 3. Processor will impose the same data-protection obligations as set out in this DPA on each subprocessor by contract, in particular sufficient guarantees to implement appropriate technical and organisational measures so processing meets Data Protection Law. Processor remains fully liable to Controller for the performance of each subprocessor's obligations.
Processor will give advance notice by email or in the Service of an intended new or replacement subprocessor. For processing subject to the incorporated SCCs, the notice period is 30 days unless Controller expressly agrees to a shorter period. For other processing, notice will normally be at least 30 days where practicable. Controller may object during the notice period on reasonable, documented data-protection grounds. The parties will work in good faith on a commercially reasonable solution. If no reasonable alternative is available, Controller may terminate the affected Service and receive a pro-rated refund of prepaid platform fees for the terminated period. This objection right does not apply to a provider used only at Controller's express direction, such as Customer's BYOSA tenant.
6 International transfers
Processor will ensure restricted transfers of Customer Personal Data use a lawful transfer mechanism, such as an applicable UK adequacy regulation or approved contractual safeguards, and supplementary measures where appropriate. Controller authorises transfers needed for the Service subject to these protections. Processor will provide relevant information reasonably needed for Controller's transfer assessment.
For transfers subject to the EU GDPR, the parties incorporate the European Commission Standard Contractual Clauses adopted by Decision (EU) 2021/914, Module 2 (controller to processor) and, where the transfer roles require it, Module 3 (processor to processor). For UK restricted transfers, the parties incorporate the UK International Data Transfer Addendum to the EU SCCs. Annexes 1 to 3 of this DPA populate the relevant SCC annexes and Addendum tables to the extent applicable.
6.1 Transfer elections
For the EU SCCs, Clause 9 Option 2 applies, using general written authorisation and the notice period in the Subprocessors section of this DPA. In Clause 17, Option 1 applies and the selected law is Ireland. Under Clause 18, disputes are resolved by the courts of Ireland. Transfers may occur continuously for the subscription duration. For Annex I.C, the competent supervisory authority is determined under SCC Clause 13 from the exporter's establishment, representative or affected data subjects. Where those details do not identify a single authority, Controller will identify the applicable authority before the relevant restricted transfer.
For the UK Addendum, the parties and their details are those supplied by this DPA and the applicable Order. The selected EU SCCs are Module 2 or Module 3 as applicable. Annexes 1 to 3 of this DPA supply the information required for the Addendum tables and appendices. For Table 4, neither Party may end the Addendum solely because the Information Commissioner's Office issues a revised Approved Addendum. The Addendum's mandatory clauses prevail over inconsistent terms.
The incorporated transfer terms permit docking by an eligible new party in accordance with their docking clause. If those mandatory transfer terms conflict with this DPA or another agreement, they have priority to the extent required for the restricted transfer. The parties do not reproduce the external clauses here; references are to the official forms as amended, replaced or approved by the competent authority.
7 Assistance
Taking account of the nature of processing and information available, Processor will reasonably assist Controller with:
- appropriate technical and organisational measures for responding to data-subject requests;
- security obligations, breach assessment and notifications;
- data-protection impact assessments and prior consultation with regulators; and
- information reasonably needed to demonstrate compliance with Article 28 UK GDPR.
If a data subject contacts Processor about Customer Personal Data, Processor will refer the request to Controller where practicable and will not respond substantively except on Controller's instruction or as required by law. Reasonable charges may apply for exceptional assistance outside ordinary Service functionality, agreed in advance where practicable.
8 Personal data breaches
Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. As information becomes available, notice will describe the nature of the breach, likely consequences, affected categories and approximate numbers, contact point, and measures taken or proposed. Processor may provide information in phases. Notification is not an admission of fault or liability.
9 Return and deletion
During the Service term, Controller can retrieve Customer Personal Data through ordinary access and download functions while access remains available. On Controller's written request before organisation deletion, Processor will, at Controller's choice, provide a copy of Customer Personal Data in a commonly used format where reasonably practicable or delete it, subject to applicable law. This obligation is separate from any individual personal-data export.
On termination or expiry of the Service, and whenever Processor otherwise ceases to provide processing services to Controller, Controller may elect in writing within 30 days to receive a copy of Customer Personal Data in a commonly used format where reasonably practicable. Unless Controller makes that election, Processor will delete Customer Personal Data from operational systems within 30 days after the end of the processing services. If Controller elects return, Processor will delete the remaining operational copies after providing the copy. Residual copies may remain only in isolated, protected backups until overwritten through the ordinary rotation cycle and must not be used operationally except for recovery. These obligations are also subject to lawful retention. Processor will confirm deletion in writing on Controller's request.
Cancellation of a paid subscription stops renewal or changes billing state according to the Service. It does not itself delete the organisation or create a 30-day organisation recovery window. Organisation deletion requested by an authorised administrator is immediate and irreversible in the current implementation. Controller must retrieve or download required Builds and request any processor-data copy before requesting organisation deletion.
A developer's separate Account deletion request locks that Account and has a 30-day cancellation and recovery window. Hard deletion occurs when the account-deletion process runs after that period, subject to safeguards that prevent deletion from leaving an organisation without an administrator and to lawful retention.
Trial expiry has a separate 30-day grace period; automatic post-trial organisation deletion is deployment/configuration dependent. Team and other hosted prepaid credit exhaustion has a separate 30-day Build-reclamation period, and that reclamation path is active. Intended Build retention defaults are Team 30 days, Business 12 months and Enterprise custom, but scheduled automatic expiry applies only where enabled and configured.
Processor may retain limited billing, tax, audit, security, backup and rights-request records where law requires or permits, with access restricted and data pseudonymised where appropriate. Data in backups is removed through the ordinary protected rotation cycle and remains unavailable for operational use except recovery.
10 Audit and documentation
Processor will provide information reasonably necessary to demonstrate compliance, initially through current policies, security materials, questionnaires and independent reports if available. If those are insufficient, Controller may request an audit no more than once annually, and additionally after a material breach, on at least 30 days' notice.
Audits must occur during normal business hours, avoid disruption, protect other customers' information, comply with security rules and be performed by an independent qualified auditor bound by confidentiality. Controller bears its audit costs and reimburses Processor's reasonable costs unless the audit identifies a material Processor breach. No audit requires access to another customer's data, source code, vulnerability details or information that would compromise security.
11 Liability, duration and precedence
The liability provisions of the Terms or applicable signed agreement apply to this DPA. This DPA continues while Processor processes Customer Personal Data. For data-protection subject matter, this DPA prevails over conflicting Terms. A separately signed agreement, and then an Order, prevails only to the extent it expressly identifies and varies the conflicting DPA provision and the variation complies with law.
AppGantry may update this DPA prospectively, identifying the new version and effective date and giving reasonable notice of material changes by email or in the Service. No update will reduce protections required by Data Protection Law or vary the incorporated SCCs or UK Addendum except as their terms and the competent authority permit.
12 Contact and governing law
Privacy and DPA enquiries: Data Protection Officer, AppGantry Ltd, contact@appgantry.com. The governing-law and jurisdiction provisions in the Terms or applicable signed agreement apply, except for the specific transfer elections stated above.
Annex 1 — Processing details
Part A — Parties
Data exporter: the Customer identified in the applicable Account or Order, at the address and through the administrative contact recorded there. The exporter acts as controller for Module 2 or processor for Module 3, as applicable. Its relevant activity is using the Service to upload, manage and distribute Customer Content.
Data importer: AppGantry Ltd, company number SC892971, of 5 South Charlotte Street, Edinburgh, EH2 4AN, United Kingdom. Data-protection contact: Data Protection Officer, AppGantry Ltd at contact@appgantry.com. The importer acts as processor. Its relevant activity is providing the processing described below.
Part B — Description of transfer
Subject matter and duration
Provision of mobile service offerings for the subscription term, including the recovery and deletion periods described above and any legally required retention.
Frequency
Processing and restricted transfers may occur continuously for the subscription duration.
Retention period or criteria
Customer Personal Data is retained for the subscription term and then returned or deleted under the Return and deletion section, subject to Controller-selected deletion, enabled/configured retention settings, protected backup rotation and lawful retention requirements.
Nature and purpose
Hosting, storing, organising, transmitting, making available, securing, backing up, deleting and supporting mobile Builds, distribution information and related Customer Content according to Controller's settings and instructions.
Data subjects
Build recipients, application users whose data Controller includes, individuals in Controller-authored distribution content, and other individuals represented in Customer Content.
Personal data
Names, email addresses and other identifiers in Controller-supplied distribution lists or content; Customer-authored filenames, release notes and descriptions; Build binaries and their contents; and narrowly necessary Build or distribution metadata processed solely on Controller's instructions. This list excludes AppGantry controller records described in the Scope, roles and instructions section.
Special categories
The Service is not designed for special-category or criminal-offence data. Controller must not include such data in filenames, release notes, descriptions or other free-text fields, and must not otherwise transfer it without prior written agreement. If agreed, the restrictions and safeguards include strict purpose limitation, encryption in transit and at rest, role-based access limited to authorised personnel under confidentiality duties, audit logging, subprocessor flow-down obligations and deletion under the Return and deletion section.
For transfers to subprocessors, the subject matter, nature and duration of their processing are the functions described in Annex 3, for the period in which the relevant provider is engaged to support the Service.
Part C — Competent supervisory authority
The competent supervisory authority is determined under SCC Clause 13 as stated in the Transfer elections section and identified by Controller before the relevant restricted transfer where the exporter's details do not identify a single authority.
Annex 2 — Technical and organisational measures
- TLS protects data in transit and Microsoft Azure encryption protects data at rest.
- Passwords are hashed using Argon2; relevant tokens are hashed, scoped or revocable.
- MFA/TOTP, recovery codes and passkeys are supported; Business and Enterprise support SSO/SAML.
- Tenant authorisation and separation of public and administrative surfaces restrict access.
- Managed identities and Azure Key Vault support secrets and service identity management.
- Role-based employee access, confidentiality obligations and access review principles limit internal access.
- Audit logging, operational monitoring, security alerting and data redaction support detection and investigation.
- Backups, recovery procedures and resilience measures address accidental loss and service restoration.
- Development practices include change control, dependency management, review, testing and remediation based on risk.
- Incident procedures support containment, investigation, recovery and legally required communications.
- Customer-controlled retention is supported where offered; Enterprise BYOSA places artifact storage in Controller's Azure tenant.
Annex 3 — Subprocessors
The Subprocessor List supplied or otherwise made available with this DPA, as updated under the notice and objection clause, states the current processing functions, relevant data and, where stated, location information. It supplies relevant transfer-appendix or table information to the extent applicable; further legal-entity, location and transfer information is available on request.
Questions about this document? support@appgantry.com.