Data Processing Agreement
Effective date: 1 October 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the Customer and Approvale governing the Customer's use of the Approvale service.
1. Parties and roles
This DPA applies where Rafał Migda – Lore Media, operating the Approvale service, processes Personal Data on behalf of the Customer in connection with the Approvale service.
Customer
The Customer is the entity or individual using Approvale and determining the purposes and means of processing Personal Data submitted to or processed through the service.
The Customer acts as:
- Controller, where the Customer determines the purposes and means of processing; or
- Processor, where the Customer processes Personal Data on behalf of another controller and is authorized to engage Approvale as a subprocessor.
Approvale
Rafał Migda – Lore Media acts as a Processor when processing Personal Data on behalf of the Customer.
Service Provider:
Rafał Migda – Lore Media
ul. Zuchów 131/1
43-300 Bielsko-Biała
Poland
NIP: 8691983646
REGON: 360319820
Contact:
2. Subject Matter and Duration
The subject matter of the processing is the provision of the Approvale service, including hosting, storing, retrieving, transmitting, displaying and otherwise processing Personal Data submitted to or generated within Customer workflows.
This may include Personal Data contained in:
- customer accounts
- connected forms
- Typeform submissions
- workflows
- workflow statuses
- comments
- attachments
- approval records
- email automation configuration
- activity and audit records
- other Customer Content processed through Approvale
Processing begins when Personal Data is submitted to or otherwise made available to Approvale and continues for as long as necessary to provide the service, unless the Customer instructs Approvale to delete or return the Personal Data or applicable law requires continued retention.
Following termination of the Customer's use of the service, Personal Data will be deleted or returned in accordance with Section 14 of this DPA and the applicable retention requirements.
3. Nature and Purpose of Processing
Approvale may process Personal Data for the following purposes:
- hosting and storing Customer Content
- receiving and processing Typeform submissions
- retrieving and displaying submissions
- operating approval workflows
- recording approval and rejection decisions
- storing comments and attachments
- sending transactional and workflow-related email notifications
- executing customer-configured email automations
- providing customer support
- maintaining security
- detecting and preventing abuse
- maintaining technical and security logs
- troubleshooting technical problems
- maintaining backups and service recovery mechanisms
- complying with applicable legal obligations
Approvale will not process Customer Personal Data for purposes unrelated to providing, securing or maintaining the Approvale service, except where required by applicable law.
4. Types of Personal Data
Depending on the Customer's use of Approvale, Personal Data may include:
- names
- email addresses
- telephone numbers
- postal addresses
- company or organization information
- job titles
- identifiers
- free-text responses
- form answers
- comments
- uploaded files and attachments
- information contained in documents
- IP addresses
- browser and device information
- timestamps
- workflow and approval history
- other Personal Data entered into connected forms or Approvale
The actual categories of Personal Data depend on the forms, workflows and information configured by the Customer.
The Customer must not use Approvale to process special categories of personal data or other highly sensitive information unless such processing is appropriate for the Customer's use case, legally permitted and supported by the applicable Approvale service and agreements.
5. Categories of Data Subjects
Personal Data processed through Approvale may concern:
- Customer employees
- Customer contractors
- Customer applicants
- Customer clients
- Customer customers
- Customer suppliers
- Customer partners
- form respondents
- website visitors
- other individuals whose Personal Data is submitted by the Customer
The Customer is responsible for determining which categories of Data Subjects are included in its processing activities.
6. Customer Instructions
Approvale will process Customer Personal Data only on documented instructions from the Customer.
The Customer's instructions include:
- configuration and use of Approvale
- connecting supported integrations
- importing or synchronizing data
- configuring workflows
- configuring email notifications and automations
- creating, modifying and deleting Customer Content
- managing users and access permissions
The Customer authorizes Approvale to process Personal Data as necessary to provide the functionality selected and configured by the Customer.
Approvale may also process Personal Data where required by applicable law. Where legally permitted, Approvale will inform the Customer of such requirement before processing unless the law prohibits such notification.
The Customer is responsible for ensuring that its instructions to Approvale comply with applicable data protection law.
7. Confidentiality
Approvale will ensure that persons authorized to process Customer Personal Data:
- have access only where necessary to perform their duties
- are subject to appropriate confidentiality obligations
- process Personal Data only as authorized
Confidentiality obligations continue after the end of the relevant person's involvement with the processing.
8. Security Measures
Approvale implements technical and organizational measures appropriate to the risks associated with processing Personal Data.
Depending on the service configuration, these measures include:
Access control
- account authentication
- password hashing
- session security
- role and permission controls where applicable
- restricted access to production infrastructure
- access based on operational necessity
Encryption and transmission security
- HTTPS/TLS for production web traffic
- encrypted storage of sensitive integration credentials where implemented
- secure transmission of data between supported services where applicable
Application security
- CSRF protection where applicable
- server-side authorization checks
- input validation
- protection against unauthorized access
- security logging
- dependency and software updates
Infrastructure security
Approvale uses managed hosting and infrastructure services and applies access controls to production infrastructure.
Backup and recovery
Approvale may maintain backups for service recovery and operational continuity.
Backups are subject to access controls and retention procedures appropriate to the service.
Security monitoring
Approvale may maintain technical and security logs to detect, investigate and respond to security incidents and misuse.
Approvale may update its technical and organizational measures from time to time, provided that the overall level of security is not materially reduced.
9. Subprocessors
The Customer generally authorizes Approvale to engage subprocessors necessary to provide the Approvale service.
Current subprocessors and service providers may include:
| Subprocessor / Provider | Purpose | Processing |
|---|---|---|
| Netcup | Hosting and infrastructure | Application data, Customer Content, technical data |
| Ploi | Server management and deployment | Infrastructure and technical access |
| Typeform | Form integration | Form metadata and submissions when connected by Customer |
| Brevo | Email delivery | Recipient information, email content and delivery events |
| Paddle | Payment and billing services | Customer and billing information where applicable |
| Analytics, Tag Manager and advertising services | Analytics and advertising data where enabled | |
| Meta | Advertising and conversion measurement | Advertising and conversion data where enabled |
Not every provider processes Customer Personal Data in every configuration.
For example, analytics and advertising services are generally associated with website visitors and are not intended to receive Customer submission data unless specifically configured by the Customer.
Changes to subprocessors
Approvale may add or replace subprocessors where reasonably necessary to provide, secure or improve the service.
Where required by applicable law, Approvale will provide information about material changes to subprocessors and provide the Customer with any legally required opportunity to object.
Approvale remains responsible for the performance of its subprocessors in accordance with applicable data protection requirements.
10. Data Subject Rights
Taking into account the nature of the processing and the information available to Approvale, Approvale will provide reasonable assistance to the Customer in responding to requests from Data Subjects exercising their rights under applicable data protection law.
Such assistance may include:
- providing access to relevant Customer Personal Data
- assisting with deletion requests
- assisting with correction requests
- assisting with restriction requests
- providing relevant information available through the service
- supporting reasonable searches for Customer Personal Data
The Customer remains responsible for determining whether a Data Subject request is valid and for communicating directly with the Data Subject where the Customer acts as Controller.
Where a Data Subject contacts Approvale directly regarding Personal Data processed on behalf of a Customer, Approvale may direct the individual to the relevant Customer where appropriate.
11. Assistance with Compliance
Taking into account the nature of processing and information available to Approvale, Approvale will provide reasonable assistance to the Customer with obligations under applicable data protection law relating to:
- security of processing
- data subject rights
- personal data breaches
- data protection impact assessments
- consultations with supervisory authorities where required
Any assistance that requires substantial manual work beyond the normal operation of the service may be subject to reasonable limitations or fees where permitted by applicable law and agreed with the Customer.
12. Personal Data Breaches
Approvale will notify the Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
Where reasonably available, the notification will include:
- a description of the nature of the breach
- the categories of Personal Data affected
- the approximate categories or number of Data Subjects affected
- the likely consequences of the breach
- measures taken or proposed to address the breach
- measures taken or proposed to mitigate potential adverse effects
Approvale will provide additional information as it becomes reasonably available.
The Customer remains responsible for determining whether the breach must be notified to a supervisory authority or Data Subjects.
13. Data Protection Impact Assessments and Regulatory Assistance
Where reasonably necessary and taking into account the nature of the processing, Approvale will provide reasonable assistance to the Customer with:
- Data Protection Impact Assessments
- consultations with supervisory authorities
- security assessments
- information reasonably necessary to demonstrate compliance with applicable data protection obligations
The Customer remains responsible for conducting its own assessment of the legality and risks of its processing activities.
14. International Transfers
Approvale may use subprocessors or infrastructure providers that process Personal Data outside the European Economic Area.
Where such transfers are subject to GDPR requirements, Approvale will use an appropriate legal transfer mechanism, which may include:
- an adequacy decision
- Standard Contractual Clauses approved by the European Commission
- another legally recognized transfer mechanism
Approvale will implement appropriate safeguards where required by applicable law.
Information about relevant subprocessors and applicable transfer mechanisms may be made available through Approvale's current subprocessor information.
15. Return and Deletion of Personal Data
Upon termination of the Customer's use of Approvale, the Customer may request deletion or return of Customer Personal Data where technically available and required by applicable law.
Unless otherwise required by law or agreed in writing:
- active Customer Personal Data will be deleted or made inaccessible following account termination in accordance with Approvale's applicable deletion procedures
- information required for legal, accounting, security or dispute-resolution purposes may be retained for the period required for those purposes
- backup copies may remain temporarily as part of normal backup and disaster-recovery procedures
- retained backup data will remain subject to appropriate security measures and will be deleted according to the applicable backup lifecycle
Where Personal Data is retained because of a legal obligation, Approvale will continue to protect that Personal Data and will not process it for other purposes except where permitted or required by law.
16. Customer Responsibilities
The Customer is responsible for:
- determining the purposes and legal basis of processing
- providing appropriate privacy notices to Data Subjects
- obtaining required consents where applicable
- ensuring that Personal Data submitted to Approvale is collected lawfully
- ensuring that the Customer has the necessary rights to provide Personal Data to Approvale
- configuring forms and integrations appropriately
- ensuring that instructions provided to Approvale are lawful
- managing access to the Customer's Approvale account
- responding to Data Subject requests where the Customer acts as Controller
- determining appropriate retention periods for Customer Personal Data
The Customer must not instruct Approvale to process Personal Data in a manner that would violate applicable law.
17. Audit and Compliance Information
Approvale will make available to the Customer information reasonably necessary to demonstrate compliance with the obligations applicable to Approvale as a processor under Article 28 of the GDPR.
Where reasonably necessary, the Customer may request additional information concerning:
- technical and organizational measures
- subprocessors
- security practices
- data processing arrangements
Audit requests must:
- be made with reasonable advance notice
- occur during normal business hours
- avoid unreasonable disruption to Approvale's operations
- respect confidentiality and security requirements
- not expose the Personal Data or confidential information of other customers
Where available, Approvale may satisfy audit requests by providing relevant documentation, security information or third-party reports instead of an on-site audit.
Any on-site audit must be agreed in advance by both parties.
18. Customer Data and Other Customers
Approvale operates a multi-customer service.
Approvale will maintain appropriate logical and technical controls designed to prevent one Customer from accessing another Customer's Personal Data.
Customer Personal Data will not be intentionally disclosed to another Customer.
19. Government and Legal Requests
If Approvale receives a legally binding request from a public authority for access to Customer Personal Data, Approvale may disclose the requested information where legally required.
Where legally permitted, Approvale will notify the Customer of such request before disclosure and provide reasonable assistance so that the Customer can seek appropriate protection.
Approvale will disclose only the information legally required.
20. Processing by Approvale for Its Own Purposes
This DPA applies to processing carried out by Approvale on behalf of the Customer.
Approvale may separately process certain information for its own legitimate purposes, such as:
- account administration
- billing
- fraud prevention
- service security
- technical diagnostics
- legal compliance
- maintaining business records
Such processing is governed by the Approvale Privacy Policy and applicable law.
21. Precedence
This DPA forms part of the agreement between the Customer and Approvale.
If there is a conflict between this DPA and the Approvale Terms of Service regarding the processing of Personal Data on behalf of the Customer, this DPA will prevail to the extent of that conflict.
Nothing in this DPA limits any mandatory rights or obligations under applicable data protection law.
22. Term and Termination
This DPA remains effective for as long as Approvale processes Personal Data on behalf of the Customer.
The obligations concerning confidentiality, security, deletion, return and other provisions that by their nature should survive termination will continue for as long as applicable.
23. Contact
For questions regarding this DPA or data processing arrangements, please contact:
Rafał Migda – Lore Media
ul. Zuchów 131/1
43-300 Bielsko-Biała
Poland
NIP: 8691983646
REGON: 360319820
Email: support@approvale.io