Data Processing Agreement
Scope & roles
This Data Processing Agreement (DPA) forms part of the AppRoute Terms of Service. AppRoute acts as Processor; you act as Controller in respect of Personal Data submitted to or generated by the service on your behalf.
Data categories & subjects
- End users who click your links — hashed IP, User-Agent, country (from IP), referrer
- Your team members — name, email, role, account events
- Your account billing — name, billing address, payment method (tokenized via Stripe)
- Your custom domains — host names, DNS-verification status, and routing/TLS metadata
Sub-processors
AppRoute uses the sub-processors listed at getapproute.com/legal/sub-processors. We notify you of additions at least 30 days in advance; you have the right to object.
International transfers
Where a listed provider transfers personal data outside the EU/UK, AppRoute relies on the transfer safeguards described in that provider's current data-processing terms, including Standard Contractual Clauses where applicable.
Security measures
- Encrypted network transport for application and provider connections
- Encryption at rest provided by our infrastructure vendors
- Role-based application access and tenant-scoped authorization checks
- Restricted production credentials and server-side secret handling
- Operational logging and rate limits for sensitive workflows
Breach notification
We notify you without undue delay and in any event within 72 hours of becoming aware of a Personal Data breach affecting your data, by email to the security contacts in your account.
Audit rights
You may request available security and compliance documentation from AppRoute. Where relevant, we may satisfy an audit request using current reports or certifications supplied by our infrastructure sub-processors.