approvallo
  • Features
  • Use cases
  • How it works
  • Pricing
  • Testimonials
Sign in Start for free
Features Use cases How it works Pricing Testimonials
Sign in Start for free →

GDPR Data Processing Agreement (DPA)

Last updated: July 10, 2026

Data Processing Agreement (DPA)

Effective Date: July 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Approvallo ("Approvallo", "we", "us", or "Processor") and the customer identified in the applicable subscription agreement, order form, or account registration ("Customer", "you", or "Controller").

This DPA governs the processing of Personal Data by Approvallo on behalf of the Customer when Customer uses the Approvallo platform and related services ("Services").

This DPA is intended to meet the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable data protection laws.

1. Definitions

For the purposes of this DPA, the following terms have the meanings below:

1.1 Personal Data

"Personal Data" means any information relating to an identified or identifiable natural person, as defined under applicable data protection laws.

1.2 Processing

"Processing" means any operation performed on Personal Data, including collection, storage, organization, access, retrieval, use, disclosure, modification, restriction, deletion, or destruction.

1.3 Controller

"Controller" means the entity that determines the purposes and means of processing Personal Data.

Customer acts as the Controller of Personal Data processed through the Services unless otherwise agreed in writing.

1.4 Processor

"Processor" means the entity that processes Personal Data on behalf of the Controller.

Approvallo acts as the Processor when processing Personal Data according to Customer's instructions.

1.5 Data Subject

"Data Subject" means an identified or identifiable individual whose Personal Data is processed.

1.6 Subprocessor

"Subprocessor" means any third party engaged by Approvallo to process Personal Data on behalf of the Customer.

2. Scope and Purpose of Processing

This DPA applies when Approvallo processes Personal Data on behalf of Customer in connection with the Services.

The purpose of processing is to enable Approvallo to provide its review, feedback, collaboration, approval, and workflow management platform.

Processing activities may include:

  • Hosting and storing Customer data uploaded to the Services.
  • Providing collaboration, review, commenting, and approval functionality.
  • Managing user accounts and access permissions.
  • Providing customer support and technical assistance.
  • Maintaining platform security, availability, and performance.
  • Performing required maintenance and troubleshooting activities.

3. Roles and Responsibilities

3.1 Customer Responsibilities

Customer is responsible for:

  • Ensuring that Personal Data is collected and processed lawfully.
  • Providing appropriate notices and obtaining required consents from Data Subjects.
  • Determining the purposes and legal basis for processing Personal Data.
  • Ensuring instructions provided to Approvallo comply with applicable laws.
  • Managing user access permissions within Customer accounts.
  • Ensuring uploaded content does not violate applicable laws or third-party rights.

3.2 Approvallo Responsibilities

Approvallo will:

  • Process Personal Data only according to Customer's documented instructions.
  • Maintain appropriate technical and organizational security measures.
  • Ensure personnel authorized to process Personal Data are subject to confidentiality obligations.
  • Assist Customer with reasonable requests related to GDPR compliance.
  • Notify Customer of Personal Data breaches as required under this DPA.

4. Processor Obligations

Approvallo will process Personal Data only to provide the Services and according to the documented instructions provided by the Customer, unless processing is required by applicable law.

Approvallo agrees to:

  • Process Personal Data only for the purposes described in this DPA and the applicable Customer agreement.
  • Ensure that persons authorized to process Personal Data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational measures to protect Personal Data.
  • Assist Customer in responding to Data Subject requests where required.
  • Assist Customer with obligations relating to security, breach notifications, and privacy impact assessments where applicable.
  • Delete or return Personal Data according to the terms of this DPA and Customer instructions.

5. Technical and Organizational Measures

Approvallo implements reasonable technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.

Security measures may include:

5.1 Data Encryption

  • Encryption of data during transmission using industry-standard encryption protocols.
  • Appropriate protection of stored data using security controls designed to prevent unauthorized access.

5.2 Access Control

  • Role-based access controls to limit access to authorized personnel.
  • Authentication mechanisms to protect user accounts.
  • Access reviews and management practices appropriate to operational needs.
  • Restriction of administrative access based on business requirements.

5.3 Infrastructure Security

  • Use of reputable hosting and infrastructure providers.
  • System monitoring and security logging where appropriate.
  • Backup and recovery procedures designed to support service availability.
  • Regular maintenance and security updates.

5.4 Application Security

  • Secure software development practices.
  • Protection against unauthorized access and misuse.
  • Monitoring and investigation of suspicious activity.
  • Controls designed to maintain confidentiality, integrity, and availability of Customer data.

6. Confidentiality

Approvallo understands that Customer Data may contain confidential information. Approvallo will ensure that individuals authorized to process Personal Data:

  • Access Personal Data only when necessary to provide the Services.
  • Maintain confidentiality of Customer information.
  • Do not use Customer Personal Data for unauthorized purposes.

These confidentiality obligations continue after termination of the Customer relationship unless otherwise required by law.

7. Personal Data Breach Notification

Approvallo maintains procedures designed to identify, investigate, respond to, and mitigate Personal Data breaches.

If Approvallo becomes aware of a Personal Data breach affecting Customer Personal Data, Approvallo will notify Customer without undue delay after confirming the incident.

Where available, breach notifications may include:

  • The nature of the Personal Data breach.
  • Categories of affected Personal Data.
  • Approximate number of affected Data Subjects, where known.
  • Measures taken or planned to address the breach.
  • Recommended actions Customer may take to reduce potential impact.

Customer remains responsible for determining whether notification to supervisory authorities or affected individuals is required under applicable law.

8. Subprocessors

Customer authorizes Approvallo to engage third-party service providers ("Subprocessors") to assist in providing the Services and processing Personal Data.

Approvallo remains responsible for ensuring that Subprocessors process Personal Data in accordance with applicable data protection requirements and obligations consistent with this DPA.

Subprocessors may provide services including:

  • Cloud hosting and infrastructure services.
  • Data storage and backup services.
  • Security monitoring and protection services.
  • Email delivery and communication services.
  • Payment processing services.
  • Analytics and operational support services.

8.1 Subprocessor Requirements

Approvallo will ensure that each Subprocessor:

  • Processes Personal Data only for authorized purposes.
  • Maintains appropriate technical and organizational security measures.
  • Is subject to confidentiality obligations.
  • Provides protections consistent with applicable data protection laws.

8.2 Changes to Subprocessors

Approvallo may add or replace Subprocessors as necessary to maintain and improve the Services.

Where required by applicable law, Approvallo will provide Customer with information about new Subprocessors and allow Customer to raise reasonable objections.

9. International Data Transfers

Customer acknowledges that Approvallo and its Subprocessors may process Personal Data in countries outside the European Economic Area ("EEA"), United Kingdom, or Customer's country of residence.

When transferring Personal Data internationally, Approvallo will implement appropriate safeguards required under applicable data protection laws.

These safeguards may include:

  • Adequacy decisions recognized by applicable authorities.
  • Standard Contractual Clauses ("SCCs") approved by the European Commission.
  • UK International Data Transfer mechanisms where applicable.
  • Additional contractual, technical, or organizational protections.

Where required, the applicable transfer mechanism will form part of this DPA.

10. Assistance With Data Subject Rights

Taking into account the nature of processing, Approvallo will provide reasonable assistance to Customer to fulfill obligations relating to Data Subject rights under applicable privacy laws.

These rights may include:

  • Access to Personal Data.
  • Correction of inaccurate Personal Data.
  • Deletion of Personal Data.
  • Restriction of processing.
  • Data portability.
  • Objection to certain processing activities.

Customer is responsible for verifying the identity of Data Subjects and determining whether requests are legally valid.

Approvallo will not respond directly to Data Subject requests unless authorized by Customer or required by applicable law.

11. Compliance Audits and Information Rights

Approvallo will make available information reasonably necessary to demonstrate compliance with the obligations described in this DPA.

Upon reasonable notice, Customer may request information regarding Approvallo's privacy and security practices.

Audit requests must:

  • Be limited to information relevant to Customer's use of the Services.
  • Respect Approvallo's confidentiality obligations toward other customers.
  • Avoid unnecessary disruption to Approvallo operations.
  • Be conducted during normal business hours.

Where appropriate, Approvallo may satisfy audit requirements by providing relevant security documentation, compliance reports, certifications, or questionnaires instead of allowing direct physical audits.

12. Return and Deletion of Personal Data

Upon termination of the Services, Approvallo will handle Customer Personal Data according to Customer instructions and applicable legal requirements.

Customer may request:

  • Export or return of Customer Personal Data where technically feasible.
  • Deletion of Personal Data stored within Approvallo systems.

Approvallo may retain limited information where required for legal obligations, security purposes, dispute resolution, accounting requirements, or legitimate business needs.

Backup copies may remain temporarily available until securely overwritten according to Approvallo's backup retention practices.

13. Relationship With Other Agreements

This Data Processing Agreement forms part of the agreement between Approvallo and Customer governing Customer's use of the Services.

In the event of a conflict between this DPA and another agreement regarding the processing of Personal Data, this DPA will control to the extent of that conflict.

All other terms of the applicable subscription agreement, order form, or Terms of Service remain unchanged.

14. Liability

Each party remains responsible for complying with the obligations applicable to it under data protection laws.

Approvallo's liability relating to Personal Data processing is subject to the limitations and exclusions contained in the applicable agreement between Approvallo and Customer.

Nothing in this DPA limits any rights or obligations that cannot be limited under applicable data protection laws.

15. Compliance With Applicable Privacy Laws

Approvallo is committed to processing Personal Data responsibly and in accordance with applicable privacy and data protection laws.

This DPA is primarily intended to address requirements under:

  • Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR).
  • United Kingdom GDPR and applicable UK data protection laws.
  • Applicable Canadian privacy laws, where relevant.
  • Other applicable privacy regulations depending on Customer location and use of Services.

Where additional legal requirements apply, the parties may agree to additional terms as necessary.

16. Changes to This Data Processing Agreement

Approvallo may update this DPA from time to time to reflect changes in legal requirements, security practices, subprocessors, or the Services.

Material changes affecting Customer rights or obligations will be communicated through appropriate channels.

The updated version will become effective on the date specified in the revised DPA.

17. Governing Law and Jurisdiction

This DPA is governed by the laws applicable to the agreement between Approvallo and Customer, unless otherwise required by applicable data protection laws.

Nothing in this section affects rights granted to Data Subjects or requirements imposed by mandatory privacy laws.

18. Contact Information

Questions regarding this Data Processing Agreement or privacy matters may be directed to:

Approvallo
Ontario, Canada
Email: privacy@approvallo.com

Appendix A - Processing Details

A.1 Subject Matter of Processing

Processing of Personal Data required to provide Approvallo's review, feedback, collaboration, approval, and workflow management Services.

A.2 Duration of Processing

Processing will continue for the duration of Customer's subscription and any applicable retention period required for backup, legal, security, or operational purposes.

A.3 Nature and Purpose of Processing

Processing activities may include:

  • Storage and organization of Customer content.
  • User account management.
  • Collaboration and communication features.
  • Review, approval, and workflow activities.
  • Service security and maintenance.

A.4 Categories of Data Subjects

Data Subjects may include:

  • Customer employees and representatives.
  • Contractors and collaborators.
  • Customers, clients, or business partners of Customer.
  • Other individuals whose information Customer uploads or processes through the Services.

A.5 Categories of Personal Data

Personal Data processed may include:

  • Name and contact information.
  • Email addresses and account identifiers.
  • User activity and collaboration information.
  • Files, documents, comments, and content submitted through the platform.
  • Technical information required for security and operation.

Appendix B - Technical and Organizational Measures

Approvallo maintains security measures appropriate to the risks associated with processing Personal Data.

  • Secure authentication mechanisms.
  • Access management controls.
  • Data transmission protection.
  • System monitoring and security practices.
  • Backup and recovery procedures.
  • Confidentiality obligations for authorized personnel.
  • Security updates and maintenance processes.

Appendix C - Subprocessor List

Approvallo may use the following categories of Subprocessors:

Category Purpose
Cloud Infrastructure Provider Hosting, storage, and application infrastructure
Email Service Provider Transactional communications and notifications
Payment Provider Subscription billing and payment processing
Security Provider Monitoring, protection, and fraud prevention
Analytics Provider Service improvement and performance analysis

Specific Subprocessor names and locations may be provided to Customer upon request or through an updated Subprocessor register.

Acceptance

By using Approvallo Services, Customer acknowledges and agrees to the terms of this Data Processing Agreement where applicable.

For enterprise agreements requiring execution:


Approvallo

Name: _______________________________

Title: _______________________________

Signature: ____________________________

Date: ________________________________


Customer

Organization: _________________________

Name: _______________________________

Title: _______________________________

Signature: ____________________________

Date: ________________________________

approvallo

The professional design approval and proofing platform built for creative teams who value clarity, speed, and accountability.

𝕏 in

Product

  • Features
  • Use cases
  • Digital Approval Seal
  • Pricing
  • How it works
  • Changelog
  • API Docs

Use cases

  • All use cases
  • Legal documents
  • Creative designs
  • Video review
  • Brand & packaging
  • Architecture
  • Product & UX

Support

  • User Guide
  • Status page
  • Community
  • Sign in
  • Start free

© 2026 approvallo. All rights reserved.

Privacy Policy Terms of Service Cookie Settings DPA