Data Processing Agreement
Last updated: June 2026 · For business customers under GDPR
1. Purpose & Scope
This Data Processing Agreement ("DPA") applies to business customers ("Controller") who use AppNeedSolutions applications ("Processor") and in doing so cause AppNeedSolutions to process personal data on their behalf. This DPA forms part of, and is incorporated into, the Terms of Use.
2. Definitions
Personal Data, Processing, Controller, Processor have the meanings given in Regulation (EU) 2016/679 (GDPR). "Customer Data" means any personal data submitted by or on behalf of the Controller through the Application.
3. Processor Obligations
AppNeedSolutions shall: (a) process Customer Data only on documented instructions from the Controller; (b) ensure that personnel authorised to process Customer Data are bound by confidentiality obligations; (c) implement appropriate technical and organisational security measures; (d) not engage sub-processors without prior written authorisation; (e) assist the Controller in responding to data subject rights requests; (f) delete or return Customer Data upon termination of the agreement.
4. Controller Obligations
The Controller confirms that: (a) it has a lawful basis for processing the personal data it submits; (b) it has provided appropriate notices to data subjects; (c) the instructions it gives AppNeedSolutions comply with applicable law.
5. Sub-Processors
The Controller authorises AppNeedSolutions to use the following sub-processors: Vercel Inc. (hosting, USA — Standard Contractual Clauses apply) · Cloudflare Inc. (CDN/DNS, USA — SCCs apply) · LemonSqueezy (payments) · Web3Forms (form submissions). AppNeedSolutions will notify the Controller of any intended changes to sub-processors with at least 14 days' notice.
6. International Transfers
Where Customer Data is transferred outside the EEA, AppNeedSolutions ensures appropriate safeguards are in place, including Standard Contractual Clauses (EU Commission Decision 2021/914) where applicable.
7. Security
AppNeedSolutions implements appropriate technical and organisational measures to protect Customer Data against unauthorised access, loss, or destruction, including encryption in transit (TLS) and access controls.
8. Data Breach Notification
AppNeedSolutions will notify the Controller without undue delay (and in any event within 72 hours) upon becoming aware of a personal data breach affecting Customer Data.
9. Duration & Termination
This DPA remains in force for the duration of the subscription. Upon termination, AppNeedSolutions will, at the Controller's choice, delete or return all Customer Data within 30 days.
10. Contact
For DPA-related enquiries or to request a signed copy: info@appneedsolutions.app