# Welcome

Welcome to Apphud Legal Section. If you have any questions feel free to contact us by email: <hi@apphud.com>.

{% content-ref url="/pages/-LwRotVe-ooG2yvZmKFv" %}
[Terms and Conditions](/terms)
{% endcontent-ref %}

{% content-ref url="/pages/-LwRvOz6Lp0E48EKJJK-" %}
[Privacy Policy](/privacy)
{% endcontent-ref %}

{% content-ref url="/pages/GyjYW5bpjsVZZgBtkNMF" %}
[Data Processing Addendum](/apphud-dpa)
{% endcontent-ref %}


# Terms and Conditions

Effective date: Apr 7, 2023

Please read these Terms and Conditions ("Terms", "Terms and Conditions") carefully before using the [https://apphud.com](https://apphud.com/) website (the "Service") operated by Apphud Inc. ("us", "we", or "our").

Your access to and use of the Service is conditioned upon your acceptance of and compliance with these Terms. These Terms apply to all visitors, users and others who wish to access or use the Service.

By accessing or using the Service you agree to be bound by these Terms. If you disagree with any part of the terms then you do not have permission to access the Service.

## **Communications**

By creating an Account on our service, you agree to subscribe to newsletters, marketing or promotional materials and other information we may send. However, you may opt out of receiving any, or all, of these communications from us by following the unsubscribe link or instructions provided in any email we send.

## **Subscriptions**

Some parts of the Service are billed on a subscription basis ("Subscription(s)"). You will be billed in advance on a recurring and periodic basis ("Billing Cycle"). Billing cycles are set either on a monthly or annual basis, depending on the type of subscription plan you select when purchasing a Subscription.

At the end of each Billing Cycle, your Subscription will automatically renew under the exact same conditions unless you cancel it or Apphud Inc. cancels it. You may cancel your Subscription renewal either through your online account management page or by contacting Apphud Inc. customer support team.

A valid payment method, including credit card or PayPal, is required to process the payment for your Subscription. You shall provide Apphud Inc. with accurate and complete billing information including full name, address, state, zip code, telephone number, and a valid payment method information. By submitting such payment information, you automatically authorize Apphud Inc. to charge all Subscription fees incurred through your account to any such payment instruments.

Should automatic billing fail to occur for any reason, Apphud Inc. will issue an electronic invoice indicating that you must proceed manually, within a certain deadline date, with the full payment corresponding to the billing period as indicated on the invoice.

## **Fee Changes**

Apphud Inc., in its sole discretion and at any time, may modify the Subscription fees for the Subscriptions. Any Subscription fee change will become effective at the end of the then-current Billing Cycle.

Apphud Inc. will provide you with a reasonable prior notice of any change in Subscription fees to give you an opportunity to terminate your Subscription before such change becomes effective.

Your continued use of the Service after the Subscription fee change comes into effect constitutes your agreement to pay the modified Subscription fee amount.

## **Refunds**

Certain refund requests for Subscriptions may be considered by Apphud Inc. on a case-by-case basis and granted in sole discretion of Apphud Inc.

## **Accounts**

When you create an account with us, you guarantee that you are above the age of 18, and that the information you provide us is accurate, complete, and current at all times. Inaccurate, incomplete, or obsolete information may result in the immediate termination of your account on the Service.

You are responsible for maintaining the confidentiality of your account and password, including but not limited to the restriction of access to your computer and/or account. You agree to accept responsibility for any and all activities or actions that occur under your account and/or password, whether your password is with our Service or a third-party service. You must notify us immediately upon becoming aware of any breach of security or unauthorized use of your account.

You may not use as a username the name of another person or entity or that is not lawfully available for use, a name or trademark that is subject to any rights of another person or entity other than you, without appropriate authorization. You may not use as a username any name that is offensive, vulgar or obscene.

## **Copyright Policy**

We respect the intellectual property rights of others. It is our policy to respond to any claim that Content posted on the Service infringes on the copyright or other intellectual property rights ("Infringement") of any person or entity.

If you are a copyright owner, or authorized on behalf of one, and you believe that the copyrighted work has been copied in a way that constitutes copyright infringement, please submit your claim via email to <hi@apphud.com>, with the subject line: "Copyright Infringement" and include in your claim a detailed description of the alleged Infringement as detailed below, under "DMCA Notice and Procedure for Copyright Infringement Claims".

You may be held accountable for damages (including costs and attorneys' fees) for misrepresentation or bad-faith claims on the infringement of any Content found on and/or through the Service on your copyright.

## **DMCA Notice and Procedure for Copyright Infringement Claims**

You may submit a notification pursuant to the Digital Millennium Copyright Act (DMCA) by providing our Copyright Agent with the following information in writing (see 17 U.S.C 512(c)(3) for further detail):

* an electronic or physical signature of the person authorized to act on behalf of the owner of the copyright's interest;
* a description of the copyrighted work that you claim has been infringed, including the URL (i.e., web page address) of the location where the copyrighted work exists or a copy of the copyrighted work;
* identification of the URL or other specific location on the Service where the material that you claim is infringing is located;
* your address, telephone number, and email address;
* a statement by you that you have a good faith belief that the disputed use is not authorized by the copyright owner, its agent, or the law;
* a statement by you, made under penalty of perjury, that the above information in your notice is accurate and that you are the copyright owner or authorized to act on the copyright owner's behalf.

You can contact our Copyright Agent via email at <hi@apphud.com>.

## **Intellectual Property**

The Service and its original content (excluding Content provided by users), features and functionality are and will remain the exclusive property of Apphud Inc. and its licensors.

## **Confidentiality**

Each party (the “**Receiving Party**”) understands that the other party (the “**Disclosing Party**”) has disclosed or may disclose business, technical or financial information relating to the

Disclosing Party’s business (hereinafter referred to as “**Proprietary Information**” of the Disclosing Party). Proprietary  Information of Apphud includes non-public information regarding features, functionality, and performance of the Service. Proprietary Information of Customer includes non-public data provided by Customer to Apphud to enable the provision of the Services, including, to the extent applicable, Connected Account Data (“Customer Data”).  The Receiving Party agrees: (i) to take reasonable precautions to protect such Proprietary Information, and (ii) not to use (except in performance of the Services or as otherwise permitted herein) or divulge to any third person any such Proprietary Information. The Disclosing Party agrees that the foregoing shall not apply with respect to any information after five (5) years following the disclosure thereof or any information that the Receiving Party can document (a) is or becomes generally available to the public, or (b) was in its possession or known by it prior to receipt from the Disclosing Party, or (c) was rightfully disclosed to it without restriction by a third party, or (d) was independently developed without the use of any Proprietary Information of the Disclosing Party or (e) is required to be disclosed by law. On the expiration or termination of the Agreement, the Receiving Party shall promptly return to the Disclosing Party all copies, whether in written, electronic, or other form or media, of the Disclosing Party’s  Confidential Information, or destroy all such copies and certify in writing to the Disclosing Party that such  Confidential Information has been destroyed. Each party’s obligations of non-use and non-disclosure with regard to  Confidential Information are effective as of the Effective Date and will expire three (3) years from the date of termination or expiration of this Agreement; provided, however, with respect to any Confidential Information that constitutes a trade secret (as determined under applicable law), such obligations of non-disclosure will survive the termination or expiration of this Agreement for as long as such Confidential Information remains subject to trade secret protection under applicable law.

**4.2 Customer Data**. Customer shall own all rights, title, and interest in and to the Customer Data. To the extent, any Customer Data provided under this Agreement includes any Customer Personal Data (as defined in the  DPA), Apphud’s then-current Data Processing Addendum, currently available at <https://apphud.com/dpa> (the “DPA”) is hereby incorporated by reference and forms an integral part of the parties’ agreement with one another.

## **Links To Other Web Sites**

Our Service may contain links to third party websites or services that are not owned or controlled by Apphud Inc.

Apphud Inc. has no control over, and assumes no responsibility for, the content, privacy policies, or practices of any third party websites or services. We do not guarantee the offerings of any of these organizations/individuals or their websites.

You acknowledge and agree that Apphud Inc. shall not be liable, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with use of or reliance on any such content, goods or services available on or through any such third party sites or services.

We strongly encourage you to review the terms and conditions and privacy policies of any third party websites or services you visit.

## **Termination**

We may terminate or suspend your account and bar access to the Service immediately, without prior notice or liability, under our sole discretion, for any reason whatsoever and without limitation, including but not limited to a breach of the Terms.

If you wish to terminate your account, you may simply discontinue using the Service.

All provisions of the Terms which by their nature should survive termination shall survive termination, including, without limitation, ownership provisions, warranty disclaimers, indemnity and limitations of liability.

## **Indemnification**

You agree to defend, indemnify and hold harmless Apphud Inc. and its licensee and licensors, and their employees, contractors, agents, officers and directors, from and against any and all claims, damages, obligations, losses, liabilities, costs or debt, and expenses (including but not limited to attorney's fees), resulting from or arising out of a) your use and access of the Service, by you or any person using your account and password; b) a breach of these Terms, or c) Content posted on the Service.

## **Limitation Of Liability**

In no event shall Apphud Inc., nor its directors, employees, partners, agents, suppliers, or affiliates, be liable for any indirect, incidental, special, consequential or punitive damages, including without limitation, loss of profits, data, use, goodwill, or other intangible losses, resulting from (i) your access to or use of or inability to access or use the Service; (ii) any conduct or content of any third party on the Service; (iii) any content obtained from the Service; and (iv) unauthorized access, use or alteration of your transmissions or content, whether based on warranty, contract, tort (including negligence) or any other legal theory, whether or not we have been informed of the possibility of such damage, and even if a remedy set forth herein is found to have failed of its essential purpose.

## **Disclaimer**

Your use of the Service is at your sole risk. The Service is provided on an "AS IS" and "AS AVAILABLE" basis. The Service is provided without warranties of any kind, whether express or implied, including, but not limited to, implied warranties of merchantability, fitness for a particular purpose, non-infringement or course of performance.

Apphud Inc. its subsidiaries, affiliates, and its licensors do not warrant that a) the Service will function uninterrupted, secure or available at any particular time or location; b) any errors or defects will be corrected; c) the Service is free of viruses or other harmful components; or d) the results of using the Service will meet your requirements.

## **Exclusions**

Some jurisdictions do not allow the exclusion of certain warranties or the exclusion or limitation of liability for consequential or incidental damages, so the limitations above may not apply to you.

## **Governing Law**

These Terms shall be governed and construed in accordance with the laws of Delaware, United States, without regard to its conflict of law provisions.

Our failure to enforce any right or provision of these Terms will not be considered a waiver of those rights. If any provision of these Terms is held to be invalid or unenforceable by a court, the remaining provisions of these Terms will remain in effect. These Terms constitute the entire agreement between us regarding our Service, and supersede and replace any prior agreements we might have had between us regarding the Service.

## **Changes**

We reserve the right, at our sole discretion, to modify or replace these Terms at any time. If a revision is material we will provide at least 30 days notice prior to any new terms taking effect. What constitutes a material change will be determined at our sole discretion.

By continuing to access or use our Service after any revisions become effective, you agree to be bound by the revised terms. If you do not agree to the new terms, you are no longer authorized to use the Service.

## **Contact Us**

If you have any questions about these Terms, please contact us by email: <hi@apphud.com>.


# Privacy Policy

Effective date: Apr 7, 2023

Apphud Inc. ("us", "we", or "our") operates the [https://apphud.com](https://apphud.com/) website (the "Service").

This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service and the choices you have associated with that data.

We use your data to provide and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this policy. Unless otherwise defined in this Privacy Policy, terms used in this Privacy Policy have the same meanings as in our Terms and Conditions, accessible from <https://legal.apphud.com/terms>.

## **Definitions**

**Service**

Service is the [https://apphud.com](https://apphud.com/) website operated by Apphud Inc.

**Personal Data**

Personal Data means data about a living individual who can be identified from those data (or from those and other information either in our possession or likely to come into our possession).

**Usage Data**

Usage Data is data collected automatically either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).

**Cookies**

Cookies are small pieces of data stored on your device (computer or mobile device).

**Data Controller**

Data Controller means the natural or legal person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal information are, or are to be, processed. For the purpose of this Privacy Policy, we are a Data Controller of your Personal Data.

**Data Processors (or Service Providers)**

Data Processor (or Service Provider) means any natural or legal person who processes the data on behalf of the Data Controller.

We may use the services of various Service Providers in order to process your data more effectively.

**Data Subject (or User)**

Data Subject is any living individual who is using our Service and is the subject of Personal Data.

**End User**

Any living individual who is using User’s iOS app with Service's SDK installed.

## **Information Collection And Use**

We collect several different types of information for various purposes to provide and improve our Service to you.

**Types of Data Collected**

**Personal Data**

While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you ("Personal Data"). Personally identifiable information may include, but is not limited to:

* Email address
* First name and last name
* Cookies and Usage Data
* Address
* Phone number
* Personal description and photograph
* Login and password details
* Information about your apps: app name, bundle ID, App Store shared secret key, information about subscription and other in-app purchases

**Our promotional updates and communications**

We may use your Personal Data to contact you with newsletters, marketing or promotional materials and other information that may be of interest to you. You may opt out of receiving any, or all, of these communications from us by following the unsubscribe link or instructions provided in any email we send.

**Usage Data**

We may also collect information how the Service is accessed and used ("Usage Data"). This Usage Data may include information such as your computer's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

**Tracking Cookies Data**

We use cookies and similar tracking technologies (such as device-IDs, in-app codes, pixel tags or web beacons) to track the activity on our Service and hold certain information.

Cookies and similar technologies are files with small amount of data which may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Tracking technologies also used are beacons, tags, and scripts to collect and track information and to improve and analyze our Service.

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.

Examples of Cookies we use:

Session Cookies. We use Session Cookies to operate our Service.

Preference Cookies. We use Preference Cookies to remember your preferences and various settings.

Security Cookies. We use Security Cookies for security purposes.

**End Users data**

We may collect information sent by a User’s End Users via our SDK. This information may include, but is not limited to:

* Country
* Locale
* Language
* Time zone
* Current IP address
* Mobile platform
* Device model
* OS version installed on device
* Last seen – the last time a user used your app
* In-App Purchase history
* Device Identifiers, such as IDFA, IDFV (iOS), Advertiser ID (Android)

## **Use of Data**

Apphud Inc. uses the collected data for various purposes:

* To provide and maintain our Service
* To notify you about changes to our Service
* To allow you to participate in interactive features of our Service when you choose to do so
* To provide customer support
* To gather analysis or valuable information so that we can improve our Service
* To monitor the usage of our Service
* To detect, prevent and address technical issues

To provide you with news, special offers and general information about other goods, services and events which we offer that are similar to those that you have already purchased or enquired about unless you have opted not to receive such information.

**Data processed on behalf of our Customers**

Apphud may process end-user information on behalf of its customers. We are not the data controller and act as data processor and have no direct relationship with the individuals or end users whose personal information it processes. The processing of personal data received from our customers is governed by our **Terms of Use**, **Data Processing Addendum**or any other agreement agreed to and signed by us with our customers. These agreements cover the transfer of data to third parties, which may occur as part of Apphud's provision of its services to the Customer. We will process such data on behalf of the customer as provided for in the relevant agreements between Apphud and the customer. The customer's privacy policy or other agreement between the customer and you (or your organization) will apply to such processing, not this policy.

If your personal data is processed by Apphud on behalf of one of our customers and you wish to stop such processing, or if you wish to correct, amend or delete inaccurate data, please contact Apphud's customer directly (the data controller). The Apphud client should then provide us with instructions, if necessary. If the data controller requests that the data be deleted, we will respond within a reasonable amount of time. We will retain personal information in accordance with our data retention policy and will retain this personal information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

## **Legal Basis for Processing Personal Data Under General Data Protection Regulation (GDPR)**

If you are from the European Economic Area (EEA), Apphud Inc. legal basis for collecting and using the personal information described in this Privacy Policy depends on the Personal Data we collect and the specific context in which we collect it.

Apphud Inc. may process your Personal Data because:

* We need to perform a contract with you
* You have given us permission to do so
* The processing is in our legitimate interests and it's not overridden by your rights
* For payment processing purposes
* To comply with the law

## **Retention of Data**

Apphud Inc. will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.

Apphud Inc. will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of our Service, or we are legally obligated to retain this data for longer time periods.

We may also retain aggregate information beyond this time for research purposes and to help us develop and improve our services. You cannot be identified from aggregate information retained or used for these purposes.

## **Transfer Of Data**

Your information, including Personal Data, may be transferred to – and maintained on – computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction.

If you are located outside United States and choose to provide information to us, please note that we transfer the data, including Personal Data, to United States and process it there.

Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.

Apphud Inc. will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information.

## **Disclosure Of Data**

**Disclosure for Law Enforcement**

Under certain circumstances, Apphud Inc. may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).

**Legal Requirements**

Apphud Inc. may disclose your Personal Data in the good faith belief that such action is necessary to:

* To comply with a legal obligation
* To protect and defend the rights or property of Apphud Inc.
* To prevent or investigate possible wrongdoing in connection with the Service
* To protect the personal safety of users of the Service or the public
* To protect against legal liability

## **Security Of Data**

All information you pass to us is stored on secure servers.

The security of your data is important to us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.

**Payment processing**

The payment data you provide to us will be encrypted using Secure Socket Layer (SSL) technology before it is transmitted to us over the Internet. Online payments are made through our payment gateway provider. You provide your credit or debit card information directly to the operator, who uses a secure server to process the payment data, encrypt your credit/debit card information, and authorize the payment. The information you provide is not under our control and is subject to the operator's privacy policy and terms and conditions.

## **"Do Not Track" Signals**

We do not support Do Not Track (“DNT”). Do Not Track is a preference you can set in your web browser to inform websites that you do not want to be tracked.

You can enable or disable Do Not Track by visiting the Preferences or Settings page of your web browser.

## **Public forums**

From time to time, the site may make available to its users chat rooms, message boards, newsgroups and/or other public forums. Any information that is disclosed in these places becomes public, so you should be careful when using them and avoid posting any personal information.

## **Your Data Protection Rights Under General Data Protection Regulation (GDPR)**

If you are a resident of the European Economic Area (EEA), you have certain data protection rights. Apphud Inc. aims to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data.

If you wish to be informed what Personal Data we hold about you and if you want it to be removed from our systems, please contact us.

In certain circumstances, you have the following data protection rights:

* The right to access, update or to delete the information we have on you. Whenever made possible, you can access, update or request deletion of your Personal Data directly within your account settings section. If you are unable to perform these actions yourself, please contact us to assist you.
* The right of rectification. You have the right to have your information rectified if that information is inaccurate or incomplete.
* The right to object. You have the right to object to our processing of your Personal Data.
* The right of restriction. You have the right to request that we restrict the processing of your personal information.
* The right to data portability. You have the right to be provided with a copy of the information we have on you in a structured, machine-readable and commonly used format.
* The right to withdraw consent. You also have the right to withdraw your consent at any time where Apphud Inc. relied on your consent to process your personal information.

Please note that we may ask you to verify your identity before responding to such requests.

You can also exercise the rights listed above at any time by contacting us at <hi@apphud.com>. We will respond to your requests within a reasonable timeframe. Please note these rights may be limited in certain circumstances as provided by applicable law.

We would appreciate the opportunity to directly address any GDPR issues you may have. Please contact us at <hi@apphud.com>. You do, however, have the right to approach your local data protection authority, (see <http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.html> for data protection authorities in the EU).

## **Service Providers**

We may employ third party companies and individuals to facilitate our Service ("Service Providers"), to provide the Service on our behalf, to perform Service-related services or to assist us in analyzing how our Service is used.

These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

**Analytics**

We may use third-party Service Providers to monitor and analyze the use of our Service.

**Google Analytics**

Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. Google uses the data collected to track and monitor the use of our Service. This data is shared with other Google services. Google may use the collected data to contextualize and personalize the ads of its own advertising network.

You can opt-out of having made your activity on the Service available to Google Analytics by installing the Google Analytics opt-out browser add-on. The add-on prevents the Google Analytics JavaScript (ga.js, analytics.js, and dc.js) from sharing information with Google Analytics about visits activity.

For more information on the privacy practices of Google, please visit the Google Privacy Terms web page: <http://www.google.com/intl/en/policies/privacy/>**.**

**Amplitude**

Amplitude is an analytics tool offered by Amplitude, Inc. We may send some of your personal information to Amplitude in order to provide the better service. For more information on the privacy of Amplitude, please visit their privacy page: <https://amplitude.com/privacy>.

**Payments**

We may provide paid products and/or services within the Service. In that case, we use third-party services for payment processing (e.g. payment processors).

We will not store or collect your payment card details. That information is provided directly to our third-party payment processors whose use of your personal information is governed by their Privacy Policy. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of payment information.

The payment processors we work with is Stripe. Their Privacy Policy can be viewed at <https://stripe.com/privacy>.

**Other services**

We may use other Service Providers to improve the quality of our Service.

## **Links To Other Sites**

Our Service may contain links to other sites that are not operated by us. If you click on a third party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit.

We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.

## **Children's Privacy**

Our Service does not address anyone under the age of 16 ("Children").

We do not knowingly collect personally identifiable information from anyone under the age of 16. If you are a parent or guardian and you are aware that your Children has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers.

## **Changes To This Privacy Policy**

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.

We will let you know via email and/or a prominent notice on our Service, prior to the change becoming effective and update the "effective date" at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

## **Contact Us**

If you have any questions about this Privacy Policy, please contact us:

Apphud Inc.

1111B S Governors Ave STE 82558, Dover, DE 19904

<hi@apphud.com>


# Referral Program

## Customer Referral Program Terms and Conditions

Apphud Inc. ("Apphud" or “We”) offers to existing clients (“Referrer” or “You”) the opportunity to participate in its referral program (the “Program”). We reserve the right to amend or terminate the Program at any time, for any reason. The Program is administered by Apphud.

Referrers are bound by these Terms and Conditions by participating in the Program. By participating in the Program, Referrers agree to use the Program in the manner specified in these Terms and Conditions. If you do not agree to these Terms and Conditions in their entirety, you are not authorized to register as a Referrer or to participate in the Program in any other manner. Referrers may not participate in the Program where doing so would be prohibited by any applicable law or regulations.

We reserve the right to modify or amend at any time these Terms and Conditions and/or the methods through which rewards are earned. We reserve the right to disqualify any Referrers from participation in the Program at any time at our sole discretion, including without limitation if he/she does not comply with any of these Terms and Conditions or otherwise fails to comply with any applicable laws (including, without limitation, through any failure to include any disclosures as required by the FTC or otherwise required by Apphud).

#### Children.

No part of the program is directed to persons under the age of 18. IF YOU ARE UNDER 18 YEARS OF AGE, YOU MAY NOT USE, ACCESS OR PARTICIPATE IN THE PROGRAM AT ANY TIME OR IN ANY MANNER.

### I. How the Program Works

#### A. Program Participation, Generally

1. To participate in the Program, Referrers should visit the [apphud.com/profile/referral](https://app.apphud.com/profile/referrals) page and follow the on-screen instructions to refer friends or colleagues to the program by copying the Program link and then share it.
2. Individuals who receive a referral link are "Friends" (or, singly, a “Friend”). An "Eligible" Referrer who is fully compliant with these Terms and Conditions may receive "Reward(s)" for every "Qualified Referral” (all terms in quotes to be understood as defined below).

#### B. Eligible Referrer

To be "Eligible," a Referrer must be at least 18 years old.

#### C. Making a Referral

1. A Referrer mustn't be registered at [apphud.com](http://apphud.com) to make a referral. Once a Referrer refers a Friend, he/she will be contacted if a purchase is made by the referred Friend within 60 days after the registration.
2. Referrers must respect the spirit of the Program by only referring real individuals who meet the requirements of these Terms and Conditions. Referrers cannot refer themselves. For example, a Referrer may not create multiple or fake accounts with Apphud or participate in the Program using multiple or fake email addresses or identities.

#### D. Qualified Referrals

1. A “Qualified Referral” means that all the following conditions are met:
2. The Friend completed the purchase of at least $49 USD of Apphud Pro, Expert or Enterprise plan. Both monthly and annual plans are eligible.
3. The Friend had not previously made a purchase with Apphud under any email address or alias;
4. The Friend is at least 18 years old;
5. Only one Qualified Referral can be earned for each Friend, Referrer can invite unlimited number of Friends per calendar year, unless otherwise updated by Apphud. Any additional or subsequent purchases made by a Friend will not be considered Qualified Referrals and thus not be entitled to the benefits of Qualified Referrals.

#### E. Earning Rewards

1. Referrer will receive a reward (each, a "Reward") in the form and value determined by Apphud for each verified Qualified Referral generated by Referrer. There is no maximum or limit to the Reward that Referrer may earn for a Qualified Referral in the form of a coupon or direct payment.
2. Reward may be redeemed in various forms at Apphud's sole discretion, including, but not limited to, discount coupons. Restrictions may apply. For example, if the Reward is in the form of a discount coupon, it may be subject to the terms and conditions of the issuer.
3. Referrer may choose to receive a Reward in the form of a discount on Apphud service payments or a direct payment via Apphud-supported payment methods. Only one type of Reward is supported per Referrer.
4. If Referrer is eligible to get back 20% of a Friend's payments (after tax deduction) for the first 6 months of the Referred's paid subscription and 10% for the further Referred's payments. The Rewards are collected while the Friend is paying for Apphud. This Reward condition applies only to Friends invited since April 1, 2023.

#### F. Verified Qualified Referrals

1. Rewards are subject to verification. Apphud may delay a Reward for the purposes of investigation. Apphud may also refuse to verify and process any transaction Apphud deems, in its sole discretion, to be fraudulent, suspicious, in violation of these Terms and Conditions, or believes will impose potential liability on Apphud, its subsidiaries, affiliates or any of their respective officers, directors, employees, representatives and agents. All of Apphud’s decisions are final and binding, including decisions as to whether a Qualified Referral, or Reward is verified.

#### G. Transfer and Value of Credit and Rewards

1. Rewards have no monetary value and may not be redeemed for cash. Rewards are not transferable and may not be auctioned, traded, bartered or sold. Upon termination of the referral program or any portion thereof for any reason, any unredeemed Rewards that have not yet been delivered to Referrer are forfeited.

### II. Privacy.

Referrers may participate in the Program made available by Apphud in order to refer their Friends to Apphud as the new Apphud customers. To do this, Referrers may submit personal information about their Friends, such as e-mail address information, so that Apphud can send communications to the Friends on the Referrers’ behalf. The personal information will be collected, processed and used in accordance with Apphud’s Privacy Statement, which can be found at <https://legal.apphud.com/privacy>. Referrers understand that, in addition to the initial communications to Friends, Apphud may also use the personal information to send to Friends additional follow-up communications on behalf of the Referrers in order to encourage or remind the Friends to complete a purchase. The personal information may also be used by Apphud to contact Referrers with regards to their participation in the Program and to send to Referrers additional communications from Apphud.

### III. Liability.

#### A. By participating in the Program, Referrers agree to:

1. Be bound by these Terms and Conditions, the decisions of Apphud and its designees, and the Privacy Policy of Apphud;
2. Defend, indemnify, release and hold harmless Apphud, its parent companies, affiliates and subsidiaries, together with their respective employees, directors, officers, licensees, licensors, shareholders, attorneys and agents including, without limitation, their respective advertising and promotion entities and any person or entity associated with the production, operation or administration of the Program (collectively, the "Released Parties"), from any and all claims, actions, demands, damages, losses, liabilities, costs or expenses caused by, arising out of, in connection with, or related to Referrers’ participation in the Program (including, without limitation, any property loss, damage, personal injury or death caused to any person(s) and/or the awarding, receipt and/or use or misuse of the Program or any Reward);

#### B. Apphud shall not be liable for:

1. Late, lost, delayed, stolen, misdirected, incomplete, unreadable, inaccurate, unreliable, garbled or unintelligible entries, communications or affidavits, regardless of the method of transmission;
2. Telephone system, telephone or computer hardware, software or other technical or computer malfunctions, lost connections, disconnections, delays or transmission errors;
3. Data corruption, theft, destruction, unauthorized access to or alteration of entry or other materials;
4. Any printing, typographical, administrative or technological errors in any websites or materials associated with the referral program; or
5. Claims, demands, and damages in disputes among Referrers or between Referrers and Friends; or
6. Any other injuries, losses or damages of any kind resulting from acceptance, possession or use of a reward, or from participation in the Program, that were not reasonably foreseeable to Apphud at the relevant time.

#### C. Apphud disclaims any liability for:

Damage to any computer system resulting from participating in, or accessing or downloading information in connection with the Program, and reserves the right, in its sole discretion, to cancel, modify or suspend the Program should a virus, bug, computer problem, unauthorized intervention or other cause beyond Apphud’s control corrupt the administration, security or proper operation of the Program.

#### D. Apphud shall not be liable to:

Any Referrer for failure to supply any Reward or any part thereof, by reason of any acts of God, any action(s), regulation(s), order(s) or request(s) by any governmental or quasigovernmental entity (whether or not the action(s), regulations(s), order(s) or request(s) prove(s) to be invalid), equipment failure, threatened terrorist acts, terrorist acts, air raid, blackout, act of public enemy, earthquake, tornado, tsunami, war (declared or undeclared), fire, flood, epidemic, explosion, unusually severe weather, hurricane, embargo, labor dispute or strike (whether legal or illegal), labor or material shortage, transportation interruption of any kind, work slowdown, civil disturbance, insurrection, riot, or any other similar or dissimilar cause beyond any of the released parties' control.

#### E. Apphud reserves the right to:

Cancel or suspend the Program should Apphud determine, in its sole discretion, that the administration, security or fairness of the Program has been compromised in any way.

#### F. Disclaimer of Warranties

REFERRERS EXPRESSLY UNDERSTAND AND AGREE THAT: (A) YOUR USE OF THE PROGRAM IS AT YOUR SOLE RISK; THE PROGRAM IS PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS AND APPHUD EXPRESSLY DISCLAIMS ALL WARRANTIES, CONDITIONS AND TERMS (COLLECTIVELY, "PROMISES") OF ANY KIND, WHETHER EXPRESS OR IMPLIED BY STATUTE, COMMON LAW OR CUSTOM, INCLUDING, BUT NOT LIMITED TO, WARRANTIES AS TO PRODUCTS OR SERVICES OFFERED THROUGH THE USE OF THE PROGRAM, IMPLIED WARRANTIES OF MERCHANTABILITY, SATISFACTORY QUALITY, FITNESS FOR A PARTICULAR PURPOSE, AND NONINFRINGEMENT; (B) APPHUD MAKES AND GIVES NO WARRANTY THAT (i) THE PROGRAM WILL MEET YOUR REQUIREMENTS OR BE UNINTERRUPTED, TIMELY, SECURE, OR ERROR FREE, (ii) THE RESULTS OBTAINED FROM THE USE OF THE PROGRAM WILL BE ACCURATE OR RELIABLE, (iii) THE QUALITY OF ANY PRODUCTS, SERVICES, INFORMATION, OR OTHER MATERIAL OBTAINED BY YOU THROUGH THE PROGRAM WILL MEET YOUR EXPECTATIONS, AND (iv) ANY ERRORS IN THE SERVICE WILL BE CORRECTED; AND (C) ANY MATERIAL DOWNLOADED OR OTHERWISE OBTAINED THROUGH THE USE OF THE PROGRAM IS ACCESSED AT YOUR OWN DISCRETION AND RISK, AND YOU WILL BE SOLELY RESPONSIBLE FOR ANY DAMAGE TO YOUR COMPUTER SYSTEM OR MOBILE DEVICE OR LOSS OF DATA THAT RESULTS FROM THE DOWNLOAD OR USE OF ANY SUCH MATERIAL.

#### G. Limitation of Liability and Indemnification

1. REFERRERS EXPRESSLY UNDERSTAND AND AGREE THAT APPHUD (INCLUDING ANY VENDORS AND SERVICE PROVIDERS ASSOCIATED WITH OR ASSISTING IN PROVIDING THE PROGRAM) SHALL NOT BE LIABLE TO YOU FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR EXEMPLARY DAMAGES, INCLUDING, BUT NOT LIMITED TO, DAMAGES FOR LOSS OF PROFITS, GOODWILL, USE, DATA OR OTHER INTANGIBLE LOSSES (EVEN IF APPHUD WAS ADVISED OF THE POSSIBILITY OF SUCH DAMAGES), RESULTING FROM: (i) THE USE OR THE INABILITY TO USE THE PROGRAM; (ii) THE COST OF PROCUREMENT OF SUBSTITUTE GOODS AND SERVICES RESULTING FROM ANY GOODS, DATA, INFORMATION OR SERVICES OBTAINED OR MESSAGES RECEIVED OR TRANSACTIONS ENTERED INTO THROUGH, FROM, OR AS A RESULT OF THE PROGRAM; (iii) UNAUTHORIZED ACCESS TO OR ALTERATION OF YOUR TRANSMISSIONS OR DATA; (iv) STATEMENTS OR CONDUCT OF ANY THIRD PARTY ON OR THROUGH THE PROGRAM; OR (v) ANY OTHER MATTER RELATING TO THE PROGRAM. SOME JURISDICTIONS DO NOT ALLOW THE EXCLUSION OF CERTAIN WARRANTIES OR THE LIMITATION OR EXCLUSION OF LIABILITY FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES. ACCORDINGLY, SOME OF THE ABOVE LIMITATIONS IN THIS PARAGRAPH MAY NOT APPLY TO YOU.
2. TO THE FULLEST EXTENT POSSIBLE BY LAW, APPHUD'S (INCLUDING ANY VENDORS AND SERVICE PROVIDERS) MAXIMUM LIABILITY ARISING OUT OF OR IN CONNECTION WITH THE PROGRAM, REGARDLESS OF THE CAUSE OF ACTION (WHETHER IN CONTRACT, TORT, BREACH OF WARRANTY, OR OTHERWISE), SHALL NOT EXCEED $100 USD.
3. REFERRERS SHOULD USE THE PROGRAM AT THEIR OWN RISK.

### V. Conduct.

#### A. If a solution cannot be found to restore the integrity of the Program after the occurrence of Prohibited Conduct (as defined below), Apphud reserves the right to cancel, change, or suspend the Program.

#### B. Prohibited Conduct, Generally

1. Referrers agree not to use the Program to:
2. Violate applicable law;
3. Infringe the intellectual property rights of Apphud or any third parties;
4. Stalk, harass, or harm another individual;
5. Collect or store personal data about other Referrers;
6. Impersonate any person or otherwise misrepresent Referrer's identity;
7. Interfere with, disrupt or violate the Terms and Conditions or servers or networks connected to the Program; or disobey any requirements, procedures, policies, or regulations of such networks;
8. Interfere with another Referrer's use of the Program;
9. Attempt to gain unauthorized access to the Program, other accounts, computer systems, or networks connected to the Program;
10. Transmit any file that contains viruses, worms, trojan horses, or any other contaminating or destructive features;
11. Conduct any illegal activity or solicit the performance of any illegal activity or other activity that infringes the rights of others;
12. Resell, barter, trade, auction or otherwise generate income by providing access to the Program to others.

#### C. Bulk Distribution ("Spam")

1. If a Referrer provides a Personal Link to [apphud.com/profile/referral](https://app.apphud.com/profile/referrals) to a Friend by email, the email must be created and distributed in a personal manner that is appropriate and customary for communications with friends, colleagues and family members.
2. Bulk referrals, distribution to strangers, or any other promotion of a Program in a manner that would constitute or appear to constitute unsolicited commercial email or "spam" in Apphud’s sole discretion is expressly prohibited and may be grounds for immediate termination of the Referrer's participation in the Program. Apphud has a no-tolerance spam policy.
3. Apphud has no obligation to monitor the content provided by Referrers; however, Apphud may choose to do so and block any email messages, remove any such content, or prohibit any use of the Program.
4. While Apphud is the actual sender of the referral email, each Referrer must nonetheless comply with applicable law. Referrers who do not comply with the law, including antispam laws, are obligated to indemnify Apphud and all of the Released Parties against any liabilities, costs and expenses incurred as a results of such violation.

#### D. Fraudulent and Suspicious Behavior

1. Apphud may prohibit a Referrer from participating in the Program or receiving a Reward, in Apphud’s sole discretion, if Apphud determines that such Referrer is attempting to undermine the fairness, integrity or legitimate operation of the Program in any way by cheating, hacking, deception, or any other unfair playing practices of intending to annoy, abuse, threaten or harass any other Referrers or any representatives of Apphud.
2. Use of any affiliate website, affiliate network properties, automated systems, script, or macro to participate is strictly prohibited and will result in disqualification.
3. Referrers may not enter with multiple or fake emails addresses or accounts, use fictitious identities or use any system, bot or other device or artifice to participate in the Program or receive a Reward.
4. Apphud reserves the right to disqualify any Referrer and/or cancel any Reward(s) if Apphud finds a Referrer to be tampering with the entry process or the operation of the Program or violating these Terms and Conditions in any way.
5. CAUTION: ANY ATTEMPT TO DELIBERATELY DAMAGE OR UNDERMINE THE LEGITIMATE OPERATION OF THE PROGRAM MAY BE IN VIOLATION OF CRIMINAL AND CIVIL LAWS AND WILL RESULT IN DISQUALIFICATION FROM PARTICIPATION IN THE PROGRAM. SHOULD SUCH AN ATTEMPT BE MADE, APPHUD RESERVES THE RIGHT TO SEEK REMEDIES AND DAMAGES (INCLUDING ATTORNEY FEES) TO THE FULLEST EXTENT OF THE LAW, INCLUDING CRIMINAL PROSECUTION.

### VI. Suggestions and Submissions.

A. Apphud appreciates hearing from users and welcomes your comments regarding the Program. Please be advised, however, that Apphud does not accept or consider creative ideas, suggestions, inventions, or materials ("Creative Ideas") other than those which we have specifically requested. While Apphud values your feedback on the program, please be specific in your comments and do not submit Creative Ideas. If, despite this request, you send Apphud Creative Ideas, Apphud:

1. Shall own, exclusively, all now known or later discovered rights to the Creative Ideas;
2. Shall not be subject to any obligation of confidentiality and shall not be liable for any use or disclosure of any Creative Ideas; and
3. Shall be entitled to unrestricted use of the Creative Ideas for any purpose whatsoever, commercial or otherwise, without compensation to you or any other person.

### VII. Applicable Law; Arbitration; Class Waiver; and Waiver of Jury Trial.

#### A. Any and all disputes, claims and causes of action arising out of or related to the Program or any Reward or other prize awarded pursuant to the Program or to this agreement shall be resolved under New York law (without reference to its conflicts of laws principles).

#### B. Referrers and Apphud agree to submit to the personal and exclusive arbitration of any disputes relating to the use of Apphud’s online platform or the Program under the rules of the American Arbitration Association. Any such arbitration, to the extent necessary, shall be conducted within New York County in the state of New York. Referrers covenant not to sue or otherwise bring a claim against Apphud in any other forum.

#### C. Referrers also acknowledge and understand that, with respect to any dispute with the Released Parties arising out of or relating to Referrers' use of the Program or this agreement:

1. REFERRERS ARE GIVING UP THEIR RIGHT TO HAVE A TRIAL BY JURY; and
2. REFERRERS ARE GIVING UP THEIR RIGHT TO SERVE AS A REPRESENTATIVE, AS A PRIVATE ATTORNEY GENERAL, OR IN ANY OTHER REPRESENTATIVE CAPACITY, OR TO PARTICIPATE AS A MEMBER OF A CLASS OF CLAIMANTS, IN ANY LAWSUIT INVOLVING ANY SUCH DISPUTE.

### VIII. General Terms.

A. These terms constitute the entire agreement between Referrers and Apphud concerning Referrers' use of the Program. The failure of Apphud to exercise or enforce any right or provision of these terms shall not constitute a waiver of such right or provision. If any provision of these terms is found by a court of competent jurisdiction to be invalid, Apphud and Referrers nevertheless agree that the court should endeavor to give effect to the intentions reflected in the provision, and that the other provisions of these terms shall remain in full force and effect. The section titles in these terms are for convenience only and have no legal or contractual effect. A person who is not a party to these terms shall have no right to enforce or receive the benefit of any of these terms.


# Data Processing Addendum

**Effective: Aug 8, 2023**

This document, known as the Data Processing Addendum (DPA), is an integral part of the Customer Agreement, SaaS Services Agreement, Terms of Use (available at [**https://legal.apphud.com/terms**](https://legal.apphud.com/terms) or any other location that may be specified periodically), or any other written or electronic agreement between the Customer and Apphud. The Agreement outlines the terms governing the Customer's use of the Services. In case of any discrepancies between the terms of this DPA and other provisions in the Agreement, the DPA will prevail.

#### **Definitions**

In this DPA:

The term "2021 Standard Contractual Clauses" refers to a set of clauses issued by the European Commission in June 2021, which provide a standardized framework for transferring personal data from the European Union to third countries, in compliance with the EU General Data Protection Regulation (GDPR). These standard contractual clauses can be accessed via the link and are completed as described in the "Data Transfers" section of the agreement or contract. The use of these clauses is important for ensuring that any transfer of personal data to third countries is done in a secure and compliant manner, protecting the privacy and rights of individuals whose data is being transferred.

The term "**Applicable Law**" is definition states that Applicable Law includes all laws, regulations, and other legal requirements that are relevant to either (i) Apphud as the provider of the Services or (ii) the Customer as the user of the Services. This may include a wide range of laws and regulations, depending on the nature of the Services being provided and the location of the parties involved.

Examples of specific laws and regulations mentioned in the definition include the General Data Protection Regulation (GDPR), which is a data protection law that applies to the processing of personal data in the European Union; the Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR), which are equivalent requirements in the United Kingdom; and the California Privacy Rights Act of 2020 (the “CPRA”) and its implementing regulations (together referred to as the “CCPA”), which are data protection laws that apply to the processing of personal data of California residents, and the Brazilian Federal Law 13,709 (“LGPD”).

By defining Applicable Law in this way, the parties to the agreement can ensure that they are aware of and complying with any legal requirements that may impact the provision or use of the Services, and can take appropriate steps to mitigate any legal risks or compliance issues that may arise.

The term "**Designated Address**" refers to the email address provided by the Customer for legal notices. This may be the email address listed on the Order Form or the email address associated with the Customer's account information on record.

The term "**Personal Data**" refers to any information that relates to an identified or identifiable individual, within the meaning of the GDPR. This definition is important because it establishes the scope of data that is subject to the terms of the agreement or contract, and ensures that the parties are using a common understanding of what constitutes personal data.

The term "**Personal Data Breach**" refers to a security incident that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or other processing of, or access to, personal data. This definition is important because it establishes the consequences that may result from a security incident involving personal data, and provides a framework for responding to such incidents in a timely and effective manner.

The term "**Process**" and "**Processing**" refers to any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means. Examples of such operations include the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction of personal data. This definition is important because it establishes the scope of activities that may be performed with personal data and helps ensure that both parties understand the types of processing that are subject to the terms of the agreement.

The next term is "**Subprocessor**", which refers to a subcontractor engaged by Apphud for the processing of personal data. This definition is important because it helps establish the responsibilities of Apphud and its subcontractors with respect to the processing of personal data, and ensures that the parties are aware of and have agreed to the use of any subprocessors in the provision of services.

The term "**UK Addendum**" refers to the International Data Transfer Addendum to the 2021 Standard Contractual Clauses, issued by the Information Commissioner under S119A(1) Data Protection Act 2018, Version B1.0. The UK Addendum is designed to be used in conjunction with the 2021 Standard Contractual Clauses for the transfer of personal data from the European Economic Area to countries outside of the EEA, in order to comply with the UK GDPR and other applicable data protection laws. The UK Addendum is available at <https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-addendum.pdf>

Certain terms may be defined later in the DPA, and capitalized terms used in the DPA but not defined within it will have the meaning set forth in the Agreement. This is a common provision in contracts and agreements, which helps ensure that the parties are using consistent terminology throughout the document and that any undefined terms are interpreted in a manner consistent with the parties' intentions as expressed elsewhere in the agreement.

#### **Scope, Relationship of the Parties, and Data Use Limitations**

This DPA only applies to the extent that Apphud processes Personal Data that is considered Customer Data, which is the data that the Customer submits to Apphud as part of the Services. If Apphud processes any other Personal Data that is not Customer Data, this DPA does not apply to such processing.

Apphud will process Personal Data in order to perform the Services for Customer, comply with the DPA, and carry out Customer's reasonable written instructions that are consistent with the Agreement and DPA. Additionally, Apphud will not sell the Personal Data as defined in the CCPA, and will not retain, use, or disclose Personal Data outside of the direct business relationship between Customer and Apphud, unless required by Applicable Law. Finally, Apphud certifies that it understands and will comply with the restrictions and obligations set forth in this DPA.

Apphud will follow if it receives a demand under Applicable Law to engage in Processing that is not permitted by the terms of the DPA. To the extent legally permitted and commercially reasonable, Apphud may notify Customer of such demand and, where appropriate, direct the requesting authority to Customer. It's worth noting that this section does not affect Apphud's obligations under the 2021 Standard Contractual Clauses or the UK Addendum with respect to access by public authorities, which may have additional requirements related to notice and transparency.

With respect to Personal Data, the parties acknowledge and agree that Customer is the “Controller” and Apphud is Customer’s “Processor” as such terms are defined in the GDPR (regardless of whether the GDPR applies). For clarity, with respect to CCPA, Apphud is Customer’s “Service Provider” as defined therein.

#### **Confidentiality and Training**

Apphud is committed to ensuring the confidentiality of the Personal Data that it processes on behalf of the Customer. Specifically, Apphud will require its authorized personnel to maintain the confidentiality of the Personal Data through contractual obligations. This means that Apphud will ensure that its employees, contractors, or agents who have access to the Personal Data are bound by confidentiality obligations to protect the confidentiality and security of such data.

#### **Security**

Apphud will comply with the security obligations of the GDPR and other applicable laws in its processing of Personal Data on behalf of the Customer. This means that Apphud will take appropriate technical and organizational measures to protect the Personal Data from unauthorized access, alteration, or destruction, and to ensure the confidentiality, integrity, and availability of the data.

#### **Subprocessors**

Apphud can use other companies or individuals (Subprocessors) to provide the Application Services as long as they follow the DPA. Subprocessors can only use Customer Data for providing the Application Services and are not allowed to use it for any other purpose. Apphud is responsible for ensuring that its sub-processors comply with the obligations of the DPA.

The customer allows Apphud to use Subprocessors to process Personal Data according to Applicable Law and GDPR Art. 28. Apphud will ensure that its Subprocessors have similar or more strict contractual obligations as Apphud under this DPA, based on the nature of the services provided.

Apphud is responsible for the actions and failures of its Subprocessors in the same way that it is responsible for its own actions and failures, within the limitations of liability stated in the Agreement or this DPA.

Both parties acknowledge that the auditing privileges granted in this DPA are limited to Apphud's affiliated Subprocessors' facilities and do not encompass the facilities of non-affiliated Subprocessors.

#### **Assistance Responding to Individuals’ Requests to Exercise Rights**

Apphud is responsible for reasonably and timely assisting Customer in fulfilling its obligation to honor and respond to requests by individuals to exercise their Personal Data-related rights under the GDPR or other Applicable Law. This includes requests for access, correction, deletion, or other actions related to their Personal Data, to the extent that such assistance is technically possible. In other words, Apphud must provide reasonable assistance to Customer in responding to such requests, but only to the extent that it is technically feasible for Apphud to do so. This obligation helps to ensure that Customer can fulfill its obligations under the applicable data protection laws and regulations with respect to Data Subject Requests.

Apphud's obligable to reasonably assist the customer in responding to requests from data subjects under Data Protection Legislation. This includes requests for information about the processing, access, rectification, erasure, or portability of personal data. Apphud will provide this assistance to the extent possible and only if legally permitted to do so. The customer will be responsible for reimbursing Apphud for any reasonable costs incurred in providing this assistance. If Apphud receives a request from a data subject in relation to the customer's personal data, Apphud will advise the data subject to submit their request to the customer. The customer will then be responsible for responding to the request, including using the functionality of the Application Services if necessary. The customer agrees that Apphud may confirm to a data subject that their request relates to the customer.

Apphud handles Data Subject Requests or complaints from individuals or their representatives. If Apphud receives such a communication that identifies Customer or pertains to the Personal Data that Apphud Processes for Customer, Apphud will forward it to Customer at the Designated Address as soon as commercially practicable if the communication arrives via <hi@apphud.com> or any other contact method specified in Apphud's then-current publicly available Privacy Notice.

#### **Personal Data Breach Notification**

Apphud will comply with the Personal Data Breach-related obligations applicable to it under the GDPR and other Applicable Laws. Apphud will assist Customer in complying with those applicable to Customer by informing Customer of a Personal Data Breach after becoming aware of a Personal Data Breach impacting Customer and by otherwise complying with this Personal Data Breach Notification section of this DPA.

Any notification required under this DPA will be provided by Apphud to the Customer at the Designated Address.

If Apphud becomes aware of a Personal Data Breach, it will notify Customer at the Designated Address.

#### **Data Return and Destruction**

During the Data Retrievability Period of thirty (30) days, Apphud will make all Personal Data stored within the Services available to Customer. After this period, Apphud will promptly destroy all Personal Data, except where retention is required by Applicable Law or necessary to resolve a dispute between the parties.

If retention of Personal Data is required by Applicable Law, Apphud will retain only the Personal Data required by law and only for as long as required by law. Apphud will continue to comply with this DPA with respect to such retained Personal Data and will destroy it as soon as legally permissible.

#### **Data Transfers**

In order to ensure that Personal Data transferred out of the European Economic Area and its member states, the United Kingdom, and/or Switzerland is protected, Customer gives Apphud authorization to conduct such international transfers subject to the 2021 Standard Contractual Clauses and the UK Addendum, as applicable. The parties are considered to have signed the 2021 Standard Contractual Clauses and UK Addendum by entering into this DPA.

Under GDPR, the 2021 Standard Contractual Clauses are included in this DPA and take precedence over any conflicting provisions of this DPA for international transfers of Personal Data. The following terms apply to the 2021 Standard Contractual Clauses:

* Customer acts as controller and Apphud acts as processor for the Personal Data governed by the 2021 Standard Contractual Clauses, and Module 2 (Controller to Processor) applies.
* Clause 7 (the optional docking clause) does not apply.
* The parties select Option 2 (General written authorization) under Clause 9 (Use of subprocessors), and Apphud must update the list of subprocessors at least 10 business days prior to any intended additions or replacements.
* The optional requirement under Clause 11 (Redress) that data subjects be permitted to lodge a complaint with an independent dispute resolution body does not apply. e. The parties choose Option 1 (the law of an EU Member State that allows for third-party beneficiary rights) under Clause 17 (Governing law), and the law of the Netherlands is selected.
* The courts of the Netherlands are selected under Clause 18 (Choice of forum and jurisdiction).
* Annexes I and II of the 2021 Standard Contractual Clauses are included in Schedule A of the DPA.
* Annex III of the 2021 Standard Contractual Clauses (Subprocessor List) is included in Schedule B of the DPA.

If required under UK Data Protection Law, the UK Addendum will be part of this DPA and will take priority over the rest of the DPA in case of any conflict for such transfer. The following provisions will apply:

* The Customer is the exporter, and their contact details are in Schedule A.
* Apphud is the importer, and their contact details are in Schedule A.
* The 2021 Standard Contractual Clauses as completed in Section 27 above will be the Approved EU SCCs referred to in Table 2 of the UK Addendum.
* Schedule A of the DPA contains Annex 1A and 1B of the UK Addendum.
* Annex II of Schedule A of the DPA is Annex II of the UK Addendum.
* Schedule B of the DPA contains Annex III of the UK Addendum.
* The Customer and Apphud can terminate the UK Addendum according to the terms set out in Table 4 of the UK Addendum.

To protect transfers of Personal Data from Switzerland, the 2021 Standard Contractual Clauses are included in this DPA and will take precedence over the rest of this DPA in case of any conflict. The 2021 Standard Contractual Clauses will be completed as outlined in Section 27, except for the following modifications:

* The Swiss Federal Data Protection and Information Commission will be the competent supervisory authority under Clause 13 to the extent that the transfer is governed by the Swiss Federal Act on Data Protection.
* The term "Member State" in the 2021 Standard Contractual Clauses will refer to Switzerland, and data subjects can exercise and enforce their rights under the 2021 Standard Contractual Clauses in Switzerland.
* References to GDPR in the 2021 Standard Contractual Clauses will refer to the Swiss Federal Act on Data Protection (as amended and replaced).

**Data Processing LGPD and CCPA compliance**

If Customer Data includes personal data that is subject to the LGPD ("LGPD Covered Data"), then Customer Personal Data, as that term is used in this document, shall be deemed to include LGPD Covered Data.

If Apphud processes Customer Personal Data within the scope of the CCPA ("CCPA Personal Data"), the Parties agree as follows. CCPA Personal Data will be disclosed by Customer only for the limited and specified purposes of providing Services to Customer pursuant to the terms of the Agreement. Each party agrees to comply with applicable obligations under the CCPA and to provide the same level of privacy protection for CCPA Personal Data as required by the CCPA.

Customer shall have the right to take reasonable and appropriate steps to ensure that Apphud uses the CCPA Personal Data in a manner consistent with its obligations under the CCPA.

Apphud will notify Customer if it determines that it can no longer comply with its obligations under the CCPA. Apphud agrees not to retain, use or disclose CCPA Personal Data obtained in the course of providing services for any purpose other than the Business Purposes set forth in the Agreement, including retaining, using or disclosing CCPA Personal Data for a commercial purpose other than the Business Purpose set forth in the Agreement or as otherwise permitted by the CCPA.

Apphud will not sell (as defined in the CCPA) or share (as defined in the CCPA) any CCPA Personal Data, retain, use or disclose any CCPA Personal Data outside of the direct business relationship between Apphud and Customer, combine any CCPA Personal Data with personal data that Apphud has received from or on behalf of any other person or persons, or collects from its own interactions with the consumer, provided that Apphud may combine any CCPA Personal Data to fulfill a Business Purpose as defined in regulations adopted by the California Privacy Protection Agency.

Notwithstanding the foregoing, Apphud may:

* Process or maintain personal information on behalf of the entity that provided the personal information or directed the service provider to collect the personal information and in accordance with the written contract for services required by the CCPA.
* To retain and employ another service provider (as defined in the CCPA) as a subcontractor, if the subcontractor meets the requirements for a service provider under the CCPA and applicable regulations.
* For Apphud's internal use to develop or improve the quality of the services it provides to Customer, even if this Business Purpose is not specified in the Agreement, provided that Apphud does not use the CCPA Personal Data to provide services on behalf of another person.
* To prevent, detect, or investigate data security incidents or protect against malicious, deceptive, fraudulent, or illegal activity, even if this Business Purpose is not specified in the Agreement, or for the purposes enumerated in California Civil Code section 1798.145, subdivisions (a)(1) through (a)(7).

#### **Miscellaneous**

This provision establishes a data processing agreement (DPA) that governs the processing of personal data by Apphud on behalf of a customer. Here are the meanings of the numbered provisions:

1. This provision establishes that if there is a conflict between the DPA and the Agreement (presumably the main contract between the parties), the DPA will take precedence and control the parties' obligations with respect to personal data.
2. This provision limits the liability of each party (presumably the customer and Apphud) in connection with the DPA, SCCs (Standard Contractual Clauses), and any other data protection agreements or security addenda that the parties have signed in connection with the main Agreement. The liability of each party will be subject to the limitations of liability section in the Agreement, which presumably sets out the maximum amount of damages that a party can be liable for under the Agreement as a whole.
3. This provision states that the DPA supersedes and replaces any previous agreements or understandings between the parties related to the subject matter of the DPA. This means that any previous agreements or understandings related to the processing of personal data by Apphud on behalf of the customer are no longer valid and have been replaced by the DPA.

#### **Schedule A to DPA**

Annexes I and II of the 2021 Standard Contractual Clauses

**ANNEX I**

A. LIST OF PARTIES

MODULE TWO: Transfer controller to processor

**Data exporter(s):**

This provision establishes a Standard Contractual Clauses (SCCs) document used in the context of data transfers from a data exporter (likely a customer) to a data importer (the other party). Here are the meanings of the items listed:

* Name: Refers to the name of the customer entity identified in the Agreement or on any applicable Order Document.
* Address: Refers to the address of the customer as specified on the Ordering Document.
* Contact Name, Position, and Contact Details: Refers to the name, position, and contact information of the customer's designated contact person who will receive notifications related to the SCCs.
* Activities relevant to the data transferred under the Standard Contractual Clauses: Refers to a brief description of the customer's activities that involve the transfer of personal data to the data importer. In this case, it indicates that the data exporter (customer) is using the services of the data importer as described in the Agreement.
* Role (controller/processor): This refers to the customer's role as either a controller or processor of the personal data being transferred under the SCCs.

**Data importer(s):**

* Name: Apphud, Inc.
* Address: 1111B S Governors Ave STE 82558, Dover, DE 19904
* Name, position and contact details of the Contact person: Renat Kurbanov, Chief Product Officer, <hi@apphud.com>
* Activities relevant to the data transferred under these Clauses: The data importer provides certain services to the data exporter as described in the Agreement.
* Role (controller/processor): Processor.

B. DESCRIPTION OF TRANSFER

MODULE TWO: Transfer controller to processor

**Categories of data subjects whose personal data is transferred:**

Apphud allows customers to transfer personal data from their end-users of mobile and web applications. The extent of this personal data is determined and controlled by the customer in their sole discretion, meaning they have full control over what personal data they transfer to Apphud.

It's important to note that the customer is responsible for complying with relevant data protection regulations and obtaining appropriate consent from their end-users for the collection and use of their personal data. Apphud has a responsibility to ensure the security and confidentiality of any personal data it processes, as outlined in its Privacy Policy and in accordance with applicable laws.

**Categories of personal data transferred:**

1. Identifying information: Names, email addresses, and telephone numbers of end users.
2. Browsing activity: Information related to the website and application browsing activity of end users.
3. Login history: Information related to the login history of end users.
4. Location information: Information related to the location of end users.
5. Device information: Information related to the devices used by end users, such as device identifiers (excluding Apple ID), operating system, and IP addresses.

If sensitive data is transferred, there must be appropriate restrictions and safeguards in place to protect the nature of the data and minimize any potential risks involved. These may include strict purpose limitation, access restrictions (e.g., limited access only to staff who have undergone specialized training), keeping a record of access to the data, restrictions for onward transfers, or additional security measures.

**The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis):**

The transfer of personal data to Apphud is on a continuous basis and will continue until all customer personal data is deleted.

**Nature of the processing:**

Apphud will process personal data to provide services to the customer as outlined in the Agreement and as instructed by the customer.

**Purpose(s) of the data transfer and further processing:**

The purpose of the data transfer and further processing is to provide the services agreed upon in the Agreement and to comply with reasonable instructions from the customer regarding the processing of personal data.

It's important to note that the customer is responsible for providing clear and specific instructions to Apphud regarding the processing of personal data to ensure compliance with applicable data protection regulations. Apphud has a responsibility to process personal data in accordance with the customer's instructions and to provide appropriate technical and organizational measures to ensure the security and confidentiality of the personal data.

C. COMPETENT SUPERVISORY AUTHORITY

MODULE TWO: Transfer controller to processor

1. If the data exporter is established in an EU Member State, the supervisory authority of that Member State is the competent supervisory authority.
2. If the data exporter is not established in an EU Member State but has appointed a representative in accordance with Article 27(1) of Regulation (EU) 2016/679, the supervisory authority of the Member State in which the representative is established shall act as the competent supervisory authority.
3. If the data exporter is not established in an EU Member State and is not required to appoint a representative in accordance with Article 27(2) of Regulation (EU) 2016/679, the supervisory authority of one of the Member States in which the data subjects whose personal data are transferred under these clauses are located shall act as the competent supervisory authority. This is applicable when the data subjects are located in a Member State in connection with the offering of goods or services to them or monitoring their behavior.

**ANNEX II**

**Introduction**

Apphud has established an Information Security Policy that outlines commercially reasonable organizational and technical measures to protect Customer Data from unauthorized access, use, modification, or disclosure. These security measures are designed to prevent security breaches and ensure the confidentiality, integrity, and availability of Customer Data. Apphud is responsible for maintaining and updating these security measures to ensure that they remain effective and appropriate over time. By implementing such measures, Apphud aims to safeguard the privacy and security of Customer Data stored on systems under Apphud's control.

**Customer Data and Management**.

Apphud has implemented the following measures to limit its personnel's access to Customer Data:

* Requires unique user access authorisation through secure logins and passwords, including multi-factor authentication for Cloud Hosting administrator access and individually assigned Secure Socket Shell (SSH) keys for external engineer access. This ensures that only authorized personnel have access to Customer Data.
* Limits Customer Data available to Apphud personnel on a "need to know" basis. This means that only personnel who require access to the data to perform their job responsibilities are granted access to it.
* Restricts access to Apphud's production environment by Apphud personnel on a "need to know" basis. This further limits access to the production environment where Customer Data is stored.
* Encrypts user security credentials for production access. This protects user security credentials in case of unauthorized access.

By implementing these measures, Apphud is taking steps to ensure the security and confidentiality of Customer Data and limit access to it to only authorized personnel on a need-to-know basis.

**Data Encryption**.

Apphud will use standard production encryption to protect Customer Data. By implementing modern encryption standards, Apphud is taking steps to protect Customer Data from unauthorized access, use, or disclosure by ensuring that only authorized parties with the proper credentials and keys can access the data.

**Network Security, Physical Security and Environmental Controls**

Apphud has implemented the following measures to ensure network security, physical security, and environmental controls:

* Apphud uses firewalls, network access controls, and other techniques to prevent unauthorized access to systems that process Customer Data. This helps ensure that only authorized personnel and devices can access the network and systems that contain Customer Data.
* Apphud maintains measures to assess, test, and apply security patches to all relevant systems and applications used to provide the Services. This helps ensure that Apphud's systems and applications are up-to-date with the latest security patches and updates to protect against known vulnerabilities.
* Apphud will monitor privileged access to applications that process Customer Data, including cloud services. This includes monitoring and logging of privileged access to systems that process Customer Data to detect and prevent unauthorized access or misuse.

By implementing these measures, Apphud is taking steps to ensure the security and integrity of its network, systems, and applications that process Customer Data. These measures help to prevent unauthorized access, mitigate security risks, and maintain the confidentiality and integrity of Customer Data.

**Incident Response**.

If Apphud becomes aware of unauthorized access or disclosure of Customer Data under its control (a “**Breach**”), Apphud will take reasonable steps to mitigate the harmful effects of the Breach and to prevent further unauthorised access or disclosure:

1. Apphud maintains backup and recovery procedures to ensure the availability and integrity of Customer Data. These procedures include regular backups of Customer Data.
2. Apphud may use third-party service providers to assist in providing the Services, and may transfer Customer Data to such third-party service providers for that purpose. Apphud will require any third-party service providers to provide sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of applicable data protection law. Apphud will also require any such third-party service providers to enter into a written agreement that provides for the processing of Customer Data in accordance with applicable data protection law and the terms of the Customer Agreement.

   * Apphud will retain Customer Data in accordance with the terms of the Customer Agreement or as required by applicable law. When Customer Data is no longer required for the purposes for which it was collected, Apphud will securely delete or destroy the Customer Data in accordance with applicable data protection law.
   * To the extent required by applicable data protection law, Apphud will assist Customer in responding to requests from data subjects to exercise their rights under such law with respect to Customer Data, including requests to access, correct, or delete personal data. Apphud will also assist Customer in responding to requests from data subjects to exercise their right to object to the processing of their personal data or to restrict the processing of their personal data, to the extent required by applicable data protection law.

**Business Continuity Management**

Business continuity and disaster recovery planning are essential to ensure that Apphud can maintain operations and continue to provide the Services to customers in the event of unexpected disruptions or disasters. The following measures are implemented by Apphud to ensure business continuity and disaster recovery:

* Apphud maintains procedures to ensure failover redundancy with its systems, networks, and data storage. This means that if one system or network fails, there are backup systems and networks available to ensure continuity of service.

By implementing these measures, Apphud ensures that it is prepared to respond to unexpected events and minimize disruptions to the Services.

**Personnel Management**

Apphud has personnel management measures in place, which include:

* Apphud performs employment verification.
* Upon employee termination, whether voluntary or involuntary, Apphud immediately disables all access to Apphud systems, including Apphud’s physical facilities.

These measures help ensure that only trustworthy individuals are granted access to Apphud systems and that access is promptly revoked when no longer required.


