Legal

Data Processing Addendum

Published · Version v2026.10.03

When this version applies. This Addendum applies immediately to accounts created on or after . For accounts created before that date it applies from ; until then, the processor terms of the previous version of the Terms of Use (the Hosted Apps clause) and of the Privacy Policy (Booking Pages and App Data) continue to govern those accounts. An existing Customer may adopt this Addendum earlier by writing to [email protected].

Counterparts: Terms of Use · Privacy Policy · Subprocessors. Data-protection questions: [email protected].

This Data Processing Addendum (the “Addendum” or “DPA”) is entered into between ApiWay, Inc., a corporation organised under the laws of Delaware, USA (“ApiWay”, “we”, “us”), and the Customer (as defined below). It supplements the Terms of Use and governs ApiWay’s processing of personal data on the Customer’s behalf.

Postal address: Suite S2, 1050 North Third Street, Laramie, Wyoming 82072, USA.

1. Definitions

1.1. “Customer” means a User who uses the Service on behalf of a business, organisation or other professional activity and who, through the Service, processes personal data of other people. Where a workspace is shared, the Customer is the account owner on whose behalf the workspace is operated.

1.2. “Customer Personal Data” means personal data that ApiWay processes on the Customer’s behalf in providing the features listed in Annex I. It does not include Account Data, billing data and other data ApiWay processes as a controller under the Privacy Policy.

1.3. “Data Protection Law” means all laws on the processing of personal data that apply to a party in connection with the Service, including Regulation (EU) 2016/679 (the “GDPR”), the GDPR as it forms part of the law of the United Kingdom and the UK Data Protection Act 2018 (the “UK GDPR”), the Swiss Federal Act on Data Protection of 25 September 2020 (the “FADP”), and the California Consumer Privacy Act as amended by the California Privacy Rights Act and its regulations (the “CCPA”), together with equivalent laws of other US states.

1.4. “Sub-processor” means any third party ApiWay engages to process Customer Personal Data. “SCCs” means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914. “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0, in force 21 March 2022).

1.5. “Controller”, “processor”, “data subject”, “personal data”, “personal data breach”, “processing”, “supervisory authority”, “business”, “service provider”, “sell” and “share” have the meanings given in Data Protection Law. Other capitalised terms have the meanings given in the Terms of Use.

2. Scope, roles and duration

2.1. Automatic application. This Addendum forms part of the Terms of Use and applies automatically, without signature, whenever a Customer uses any feature listed in Annex I to process Customer Personal Data. It does not apply to an individual who uses the Service purely for personal or household purposes.

2.2. Roles. The Customer is the controller (or, where it acts for its own client, a processor) of Customer Personal Data, and ApiWay is its processor (or sub-processor). For the CCPA, the Customer is the business and ApiWay is its service provider. Where the Customer acts as a processor for its own client, the Customer warrants that its client’s instructions, including the appointment of ApiWay, are authorised, and the Customer remains ApiWay’s sole point of contact.

2.3. ApiWay as controller. ApiWay processes as an independent controller, outside this Addendum, the data described in the Privacy Policy for which it decides purposes and means: Account Data, billing and payment records, security, abuse and fraud-prevention records, service logs, and aggregated or de-identified statistics about the use of the Service that do not identify the Customer’s data subjects. ApiWay also acts as a controller of a room or Booking Page it operates itself.

2.4. Third-party platforms the Customer connects. Google, Meta, Telegram, Shopify, Stripe and other platforms to which the Customer connects its own account process data under the Customer’s own agreement with them and act as independent controllers or as the Customer’s own processors. Data that the Service sends to or receives from those accounts at the Customer’s direction is not a transfer to an ApiWay Sub-processor, and ApiWay is not responsible for what those platforms do with it.

2.5. Subject matter, nature, purpose and duration. The subject matter is the provision of the Service to the Customer. The nature and purposes of the processing, the categories of data subjects and personal data, and the retention periods are set out per feature in Annex I. Processing lasts for the term of the Customer’s use of the Service and until Customer Personal Data is deleted under Section 11.

3. The Customer’s responsibilities

3.1. The Customer is responsible for the lawfulness of the processing it instructs, including having a lawful basis, giving the notices and obtaining the consents that Data Protection Law and electronic-marketing law require (for example for marketing emails, tracking of opens and clicks, automated messages and the collection of contact details), and for the accuracy of Customer Personal Data.

3.2. The Customer shall not use the Service to process special categories of personal data, data relating to criminal convictions, government identifiers, payment card data or personal data of children, unless the feature is designed for it, Data Protection Law allows it and the Customer has put the required safeguards in place.

3.3. The Customer’s instructions must comply with Data Protection Law. The Customer is responsible for its own privacy notice towards its data subjects and for answering their requests, with ApiWay’s assistance under Section 8.

4. Processing on documented instructions

4.1. ApiWay processes Customer Personal Data only on the Customer’s documented instructions, including with regard to international transfers, unless Union, Member State or other applicable law requires otherwise; in that case ApiWay informs the Customer of that legal requirement before processing, unless that law prohibits it on important grounds of public interest.

4.2. The Customer’s complete instructions are: the Terms of Use and this Addendum; the Customer’s configuration and use of the Service (including the automations, lists, forms, rooms, connectors and apps it sets up, and the requests it gives the Apiway assistant or its own AI client); and any further written instructions ApiWay accepts. Additional instructions that require a change to the Service may be subject to fees.

4.3. ApiWay informs the Customer without undue delay if, in its opinion, an instruction infringes Data Protection Law, and may suspend the affected processing until the instruction is confirmed or changed.

4.4. No other use. ApiWay does not sell or share Customer Personal Data, does not use it for advertising, does not combine it with personal data it receives from other sources or from its other customers except as Data Protection Law permits for a service provider, and does not use it to train or fine-tune AI models. Where a feature uses a third-party AI model, ApiWay sends the request on terms or tiers under which the provider does not use it to train its general models, where the provider offers them.

5. Confidentiality

5.1. ApiWay limits access to Customer Personal Data to personnel who need it to provide, secure and support the Service, and ensures that they are bound by a contractual or statutory duty of confidentiality that continues after their engagement ends.

5.2. ApiWay does not disclose Customer Personal Data to a public authority unless the law requires it. Where it receives a legally binding request, it will, where the law allows, redirect the authority to the Customer, notify the Customer promptly and disclose only the minimum the request lawfully requires.

6. Security

6.1. ApiWay implements and maintains the technical and organisational measures described in Annex II, which are designed to ensure a level of security appropriate to the risk, as required by Article 32 GDPR. ApiWay may update these measures as technology and risks evolve, provided that the overall level of security is not reduced.

6.2. The Customer is responsible for the security of its own account and devices, for the credentials and access it grants to its team, and for the configuration choices it makes in the Service (for example what it publishes, which links it shares and whom it invites).

7. Sub-processors

7.1. General authorisation. The Customer gives ApiWay general authorisation to engage Sub-processors. The current list is published at /legal/subprocessors and is accepted by the Customer.

7.2. Contract and responsibility. ApiWay imposes on each Sub-processor, by written contract, data protection obligations that offer at least the same level of protection as this Addendum, as far as appropriate to the service it provides. ApiWay remains liable to the Customer for the performance of each Sub-processor’s obligations as provided in Data Protection Law, subject to Section 14.

7.3. Notice of new Sub-processors. ApiWay gives at least thirty (30) days’ notice before a new Sub-processor starts processing Customer Personal Data, by updating the Subprocessors page and by email to the account owner’s address or by a notice in the Service. In an emergency (for example to keep the Service running when a provider fails or to address a security threat) ApiWay may engage a replacement sooner and will give notice as soon as practicable.

7.4. Right to object. The Customer may object to a new Sub-processor on reasonable data-protection grounds by writing to [email protected] within the notice period. The parties will discuss the objection in good faith, and ApiWay may offer a reasonable alternative (such as a change of configuration or not using the affected feature). If no solution is found within thirty (30) days, the Customer may terminate the affected feature or its subscription by written notice, and ApiWay will refund any prepaid subscription fees for the period after termination. This is the Customer’s sole remedy for an objection.

8. Assistance

8.1. Data-subject requests. Taking into account the nature of the processing, ApiWay assists the Customer by appropriate technical and organisational measures in responding to requests to exercise data-subject rights. The Service provides self-service tools for most requests (for example editing, exporting and deleting contacts, processing unsubscribes, deleting rooms, records and apps). If ApiWay receives a request directly from a data subject of the Customer, it will not answer it on the merits (except to confirm that the request relates to the Customer) and will forward it to the Customer without undue delay.

8.2. DPIAs and consultations. ApiWay provides reasonable assistance, with the information available to it, with the Customer’s data protection impact assessments and prior consultations with supervisory authorities, primarily by making this Addendum, its annexes and the Subprocessors list available. Assistance beyond that may be charged at reasonable cost.

9. Personal data breaches

9.1. ApiWay notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and aims to do so within seventy-two (72) hours. Notice is sent to the account owner’s email address and may also be given in the Service.

9.2. The notice describes, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Information that is not available at first is provided in phases as it becomes available.

9.3. ApiWay takes reasonable steps to contain and remedy the breach and to mitigate its effects, and cooperates with the Customer’s own notifications. Unless the law requires otherwise, the Customer, as controller, decides whether to notify supervisory authorities and data subjects. A notice under this Section is not an acknowledgement of fault or liability.

9.4. Unsuccessful attempts or activities that do not compromise the security of Customer Personal Data (such as pings, port scans, failed log-in attempts or denial-of-service attacks that expose no data) are not personal data breaches.

10. Audits and information

10.1. ApiWay makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR. It does so primarily through this Addendum, its annexes and documentation, and by answering a reasonable written security or privacy questionnaire not more than once in any twelve (12) months (more often after a personal data breach or where a supervisory authority requires it).

10.2. ApiWay does not currently hold an independent security certification (such as ISO/IEC 27001 or a SOC 2 report). If it obtains one, it may satisfy audit requests by providing a summary of that report.

10.3. An on-site audit or inspection takes place only where the information above is not sufficient to demonstrate compliance and Data Protection Law or a competent supervisory authority requires it. It is carried out at the Customer’s cost, with at least thirty (30) days’ written notice, during business hours, not more than once in any twelve (12) months, by the Customer or an independent auditor bound by confidentiality and not a competitor of ApiWay, in a way that does not interfere with the Service or expose other customers’ data. Audits under the SCCs are carried out in the same way, as far as the SCCs allow.

11. Deletion and return

11.1. During the term the Customer can export or delete Customer Personal Data using the functions the Service provides. Where the Service has no export for a category of data, ApiWay will provide it on request in a commonly used machine-readable format before the account is closed.

11.2. When the Customer deletes its account, or within thirty (30) days after the Customer’s use of the Service ends, ApiWay deletes Customer Personal Data from its live systems, except where the feature retention in Annex I says otherwise (for example the six-month restore window for a deleted Hosted App) or Data Protection Law or other law requires ApiWay to keep it. Copies in database backups are erased as those backups expire, within fourteen (14) days.

11.3. Data retained because the law requires it, and suppression records kept so that an unsubscribe or opt-out continues to be honoured, remain subject to this Addendum and are processed only for that purpose.

12. International transfers

12.1. ApiWay is established in the United States, and ApiWay and its Sub-processors process Customer Personal Data in the locations listed on the Subprocessors page. The Customer authorises these transfers, which ApiWay makes in accordance with Data Protection Law.

12.2. EU SCCs. To the extent Customer Personal Data subject to the GDPR is transferred to ApiWay in a country that does not have an adequacy decision, the SCCs are incorporated into this Addendum by reference and apply as follows: Module Two (controller to processor) applies where the Customer is a controller, and Module Three (processor to processor) applies where the Customer is a processor. The Customer is the data exporter and ApiWay is the data importer. The parties make the following selections:

  • Clause 7 (docking clause) applies.
  • Clause 9: Option 2 (general written authorisation) applies, with the notice period in Section 7.3 of this Addendum.
  • Clause 11(a): the optional language does not apply.
  • Clause 13: where the Customer is established in an EU Member State, the supervisory authority of that Member State; where the Customer is not established in the EU but falls within Article 3(2) GDPR and has appointed a representative, the supervisory authority of the Member State where the representative is established; otherwise, the Data Protection Commission of Ireland.
  • Clause 17: the law of Ireland.
  • Clause 18(b): the courts of Ireland.
  • Annex I of the SCCs is completed by Annex I of this Addendum (with the parties’ details in the Preamble), Annex II by Annex II of this Addendum, and Annex III by the Subprocessors page.
  • The audit and deletion mechanics in Sections 10 and 11 of this Addendum, and the liability terms in Section 14, apply to the SCCs to the extent they do not contradict them.

12.3. United Kingdom. For transfers subject to the UK GDPR, the UK Addendum is incorporated by reference and applies to the SCCs as selected above. Table 1 is completed with the parties’ details in the Preamble; Table 2 with the Modules and selections in Section 12.2; Table 3 with Annexes I and II of this Addendum and the Subprocessors page; and in Table 4 the Importer may end the UK Addendum as set out in its Section 19.

12.4. Switzerland. For transfers subject to the FADP, the SCCs apply with these amendments: the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority; references to the GDPR are read as references to the FADP; references to a “Member State” do not exclude data subjects in Switzerland from suing for their rights in their place of habitual residence.

12.5. If a court or authority invalidates a transfer mechanism, or a new one is adopted, ApiWay may implement an alternative lawful mechanism, and the parties will cooperate to put it in place.

13. US state privacy laws (CCPA/CPRA)

13.1. With respect to Customer Personal Data that is “personal information” under the CCPA or a comparable US state law, ApiWay acts as a service provider (or processor) and shall not: (a) sell or share it; (b) retain, use or disclose it for any purpose, including any commercial purpose, other than the business purposes of providing the Service as specified in this Addendum and the Terms of Use, or as otherwise permitted for service providers by the CCPA; (c) retain, use or disclose it outside the direct business relationship between ApiWay and the Customer; or (d) combine it with personal information it receives from or on behalf of another person, or collects from its own interactions with the consumer, except as the CCPA permits.

13.2. ApiWay complies with the obligations that apply to it under the CCPA, provides the same level of privacy protection the CCPA requires of businesses, and notifies the Customer if it determines that it can no longer meet those obligations. The Customer may take reasonable and appropriate steps to ensure ApiWay uses Customer Personal Data consistently with the Customer’s CCPA obligations and, upon notice, to stop and remediate unauthorised use.

13.3. ApiWay certifies that it understands and will comply with the restrictions in this Section 13. Where ApiWay receives de-identified data from the Customer, it will not attempt to re-identify it.

14. Liability

14.1. Each party’s liability arising out of or relating to this Addendum, including the SCCs, is subject to the exclusions and the limitation of liability in the Terms of Use, which apply in the aggregate to all claims under the Terms of Use and this Addendum together.

14.2. Nothing in this Section limits either party’s liability towards data subjects under the third-party-beneficiary rights of the SCCs, or any liability that cannot be limited under Data Protection Law.

15. Precedence, changes and term

15.1. In the event of a conflict, the order of precedence is: (a) the SCCs (including the UK Addendum and the Swiss amendments), to the extent they apply; (b) this Addendum; (c) the Terms of Use and the Privacy Policy. On matters of the protection of Customer Personal Data, this Addendum prevails over any other agreement between the parties, unless that agreement is a separate data processing agreement signed by both parties and expressly says it prevails.

15.2. ApiWay may update this Addendum (for example to reflect new features, Sub-processors or changes in law) in the same way as the Terms of Use. A change that materially reduces the protection of Customer Personal Data takes effect for existing Customers no earlier than thirty (30) days after notice. Updates required by law or by a supervisory authority, and the addition of features to Annex I, may take effect sooner.

15.3. This Addendum remains in force for as long as ApiWay processes Customer Personal Data. Sections that by their nature should survive (including confidentiality, deletion and liability) survive its end. If any provision is invalid, the rest remains in force.

Annex I — Description of the processing

Parties. Data exporter: the Customer, as identified by its account details; its contact person is the account owner; activity: use of the Service. Data importer: ApiWay, Inc. (details in the Preamble); contact: [email protected]; activity: provider of the Service. Signature and date: by the Customer’s acceptance of the Terms of Use and use of the features below.

For all features. Frequency: continuous, for as long as the Customer uses the feature. Special categories of data: not intended; the Customer should not submit them (Section 3.2). Common processing operations: collection through the Service, storage, organisation, retrieval, transmission to the destinations the Customer chooses, display, backup and deletion. Competent supervisory authority: as set out in Section 12.2.

Email Marketing (contacts, lists, forms, campaigns, sequences)

Data subjects
The Customer’s subscribers, contacts and leads; people who submit the Customer’s hosted sign-up forms; recipients of the Customer’s campaigns and automated sequences.
Personal data
Email address, name, phone number and custom fields the Customer stores; list membership; subscription status and its source; suppression records (unsubscribes, bounces, complaints); the per-recipient send ledger; delivery, bounce and complaint events; open and click events with time, clicked URL, IP address and user agent; form submissions.
Nature and purpose
Storing and organising the Customer’s contacts; sending the messages the Customer writes, schedules or automates; measuring delivery and engagement; processing unsubscribes and suppressing future sends to unsubscribed, bounced or complaining addresses; showing reports to the Customer.
Retention
Until the Customer deletes the contact or the account. IP address and user agent on open and click events: twelve (12) months, then erased. Suppression records are kept for as long as they are needed to keep honouring an unsubscribe or complaint.

Booking Pages (apiway.ai/book/…)

Data subjects
Invitees who request a meeting with the Customer through its Booking Page.
Personal data
Name, email address, note and answers to the Customer’s questions, selected time and time zone, the Customer’s own marketing-consent choice, campaign attribution parameters (UTM, ref, gclid, fbclid), referring and landing URL.
Nature and purpose
Computing available slots from the Customer’s calendar free/busy data; creating the meeting and the calendar event in the Customer’s connected calendar; sending confirmation, change, cancellation and reminder messages; adding the Invitee to the Customer’s contact list only where the Invitee opted in.
Retention
While the Customer keeps the booking record, and then as described in the Privacy Policy. Any newsletter opt-in that subscribes an Invitee to ApiWay’s own newsletter is ApiWay’s processing as a controller and is outside this DPA.

Lead Transfer (lead automations)

Data subjects
People who submit the Customer’s lead forms on advertising and social platforms (such as Meta and TikTok) or through other sources the Customer connects.
Personal data
Name, email address, phone number and answers to the Customer’s form questions; campaign, ad set, ad and form identifiers; submission time; delivery status and error records.
Nature and purpose
Receiving leads from the source the Customer connected under its own authorisation, delivering them to the destinations the Customer configures (for example Google Sheets, Telegram, email or the Customer’s CRM), retrying failed deliveries and showing delivery history and errors.
Retention
Lead data received from ad forms and the delivery status records: kept while the Customer’s account exists (also after an automation is removed), and erased with the account or earlier on the Customer’s deletion request. Copies delivered to the Customer’s destinations are governed by the Customer’s own arrangements with those services.

Instagram automations (Comment → DM, replies to comments, mentions and story reactions, DM flows)

Data subjects
People who comment on, mention, react to or send direct messages to the Customer’s Instagram account.
Personal data
Instagram-scoped user ID, username and, where Meta provides it, display name and profile picture; comment and message text and attachments; contact details a person chooses to give in a flow the Customer configured (such as email address or phone number); interaction timestamps and automation state.
Nature and purpose
Running the automations the Customer configures and sending replies from the Customer’s own account through Meta’s API; collecting the details the Customer’s flow asks for; showing statistics. ApiWay only queries the Customer’s own account, people who messaged it, and media that tagged it.
Retention
Direct-message log: thirty (30) days, then erased. Contact details collected by a flow: until the Customer deletes them or the automation. Event statistics: while the connection exists.

Mail, Calendar, rooms and share pages

Data subjects
The Customer’s email correspondents, meeting attendees, and participants of the rooms and share pages the Customer creates.
Personal data
Names and email addresses; message envelopes (sender, recipients, subject, date, labels); message content read live from the Customer’s connected mailbox; facts, tasks and agreements the Customer’s assistant extracts from threads; contact card fields; attachments the Customer stores in a room; read receipts (without IP address or location); recordings the Customer sends.
Nature and purpose
Displaying the Customer’s mail and calendar, drafting replies at the Customer’s request, organising tasks and agreements, and publishing the rooms and share pages the Customer chooses to create. Message bodies are read live from the mailbox and are not copied into ApiWay’s database, except where a feature described in Annex I stores a specific item (for example an attachment saved to a room).
Retention
Cached envelopes and derived records: while the mailbox stays connected or until the Customer deletes them. Share pages: until the Customer revokes or deletes them.

Telegram team rooms and the personal assistant in Telegram

Data subjects
Members of the Telegram group chats the Customer connects and activates; people who message the Customer’s assistant; people named in tasks.
Personal data
Telegram user ID, username and name; message text and voice-message transcripts; files shared in the chat; tasks, agreements, reminders and the messages the bot sends.
Nature and purpose
Turning the conversation into tasks, agreements and reminders the Customer asked for; delivering reminders and follow-ups; answering the Customer’s requests. A group chat is processed only after the Customer activates it in the Service.
Retention
Message text: ninety (90) days, then erased. Tasks, agreements and stored files: until the Customer deletes them or the room.

Apiway Workspace AI Bot rooms (CC the bot)

Data subjects
Participants of email threads in which the Customer or a participant addressed the bot.
Personal data
Names and email addresses of thread participants; cleaned message text; attachments; invitation and opt-out records.
Nature and purpose
Hosting the thread as a room, inviting participants under the rules shown in the Service and carrying out the commands participants give the bot (such as creating a task). The bot processes only mail it was an addressee of.
Retention
While the room exists; deleted together with the room. Opt-out records are kept for as long as needed to keep honouring the opt-out.

Hosted Apps (App Factory)

Data subjects
Users, clients, visitors and team members of the Customer’s Hosted App (the “End Users”).
Personal data
Whatever the Customer’s Hosted App collects and stores: typically account and contact details, content End Users submit, records in the app’s database, files, and technical logs.
Nature and purpose
Running, securing, backing up, restoring and supporting the Hosted App on the Customer’s behalf. ApiWay hosts the app; the Customer decides what it collects and why.
Retention
While the Hosted App exists. Database backups are made daily and the last fourteen (14) are kept. A deleted Hosted App is kept for six (6) months so it can be restored and is then permanently deleted with its database, code versions, backups and brief materials.

Apiway Pages, recordings, files and other content the Customer publishes or shares

Data subjects
People who are named or depicted in content the Customer uploads, publishes or shares; viewers of that content.
Personal data
Whatever personal data the Customer includes in the content. Views of shared recordings are counted anonymously (no IP address, no user agent).
Nature and purpose
Storing, rendering and serving the content the Customer chose to publish or share.
Retention
Until the Customer unpublishes or deletes it. On the free plan: screen-recording video thirty (30) days, other files one hundred eighty (180) days; screenshots and voice recordings are kept.

Connectors, the Apiway assistant and the MCP server

Data subjects
People whose data is held in the third-party accounts the Customer connects (for example the Customer’s own customers in Stripe or contacts in a CRM) and in the Customer’s workspace.
Personal data
The records a connector report returns for the Customer’s question (for example names, email addresses, order or payment details); the Customer’s conversation with the assistant.
Nature and purpose
Answering the Customer’s questions and carrying out the actions the Customer asks the assistant or its own AI client (through the MCP server) to take, within the connectors the Customer granted.
Retention
Connector data is used for the request and is not stored separately; it remains in the Customer’s conversation history until the Customer deletes it. An access log records which connector and report were used and when, but not the data returned.

Annex II — Technical and organisational security measures

These are the measures ApiWay applies today. They are commitments of practice, kept under review, and are not a certification.

Encryption

  • All public endpoints are served over HTTPS (TLS), with HTTP Strict Transport Security.
  • Files and generated media are stored in Amazon S3, which encrypts stored objects at rest by default.
  • Database backups are encrypted at rest (AES-256 server-side encryption) in a separate bucket that is checked for all four public-access blocks before each upload.
  • Selected third-party credentials, such as advertising-platform tokens and integration webhook secrets, are additionally encrypted in the application with AES-256-GCM.
  • Account passwords are stored only as bcrypt hashes. Share-link and magic-link tokens are stored only as SHA-256 hashes, and lookups of short share links are rate-limited.

Access control and least privilege

  • Every Customer’s data is scoped to its owner: server-side queries filter on the owning account, and access to a workspace requires an authenticated session.
  • The administration panel uses its own authentication, separate from customer accounts, with an HMAC-signed session cookie that expires after 24 hours and fails closed if its secret is missing. Failed administrator log-ins are monitored and alerted.
  • Features that read a whole mailbox are limited to explicitly allowed accounts and have no administrator bypass.
  • Production secrets live in an environment file readable only by the service account, never in the source repository. Cloud credentials are scoped to the minimum actions they need (for example, the backup credential can only write and delete backups).
  • Server and production access is limited to a small number of authorised engineers.

Availability, backups and recovery

  • The main database is backed up daily and the last fourteen (14) daily backups are kept; each Hosted App database is backed up daily with the last fourteen kept.
  • Deployments use pre-built, digest-verified container images with health checks, so a failed release does not replace a working one, and a previous release can be restored.
  • Automated monitoring checks the database, disk, memory, background jobs, backup freshness and certificate expiry every minute, and an external uptime check runs every five minutes; alerts go to the engineering team.

Data minimisation

  • Mail message bodies are read live from the connected mailbox and are not copied into ApiWay’s database; only the envelope needed for the list, and items a feature expressly stores, are kept.
  • Read receipts and views of shared recordings are recorded without IP address or location.
  • Usage analytics run on a separate system reachable only through an encrypted tunnel, and analytics failures never affect customer requests.
  • Retention periods in Annex I are enforced by scheduled deletion jobs.

Logging and accountability

  • Reads of data through connectors are recorded in an access log (which connector, which report, when), without the data returned.
  • Background jobs, deliveries and security-relevant events are logged for troubleshooting and incident investigation.

Secure development and change management

  • Changes pass automated tests before release, and production is deployed only through the controlled release pipeline.

Personnel and sub-processors

  • Personnel with access to Customer Personal Data are bound by confidentiality.
  • Sub-processors are engaged under written contracts with data protection obligations (Section 7).

Incident response

  • Incidents are triaged by the engineering team on alert; personal data breaches are handled and notified as described in Section 9.

Annex III — Sub-processors

The list of Sub-processors authorised under Section 7 is published at /legal/subprocessors.