About This Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer" or "Controller") and Applifyer, LLC d/b/a Answerplane ("Answerplane," "we," "us," "Processor"). This DPA applies when we process Personal Data on your behalf in connection with our Service.
Enterprise Customers: You may incorporate this DPA into your subscription agreement by reference or request a signed copy by contacting [email protected].
1. Definitions
For the purposes of this DPA:
- "Personal Data" means any information relating to an identified or identifiable natural person that is processed by Answerplane on behalf of Customer in connection with the Service, including but not limited to account information, user data, query metadata, chat history, saved queries, dashboards, uploads, exports, and materialized result artifacts where those features are used.
- "Data Subject" means the identified or identifiable person to whom Personal Data relates (e.g., Customer's employees, end users).
- "Processing" means any operation performed on Personal Data, such as collection, storage, use, disclosure, or deletion.
- "Controller" means Customer, who determines the purposes and means of processing Personal Data.
- "Processor" means Answerplane, who processes Personal Data on behalf of Customer.
- "Sub-processor" means any third party engaged by Answerplane to process Personal Data on behalf of Customer.
- "GDPR" means the General Data Protection Regulation (EU) 2016/679.
- "Data Protection Laws" means all applicable laws and regulations relating to privacy and data protection, including GDPR, CCPA, UK GDPR, and Swiss FADP.
2. Scope and Application
2.1 Scope of Processing
This DPA applies to the processing of Personal Data by Answerplane on behalf of Customer in connection with the Service, including:
- Customer account information (names, email addresses, job titles)
- User authentication and session data
- Database connection metadata (credentials, schema information)
- Query metadata (approved-source questions, generated SQL/NoSQL plans, execution times)
- Usage analytics and platform interaction data
2.2 Source Database Content and Aggregated Data
For clarity:
- Customer Source Database Content: Answerplane does not ingest or replicate Customer's connected database contents wholesale.
- Customer-Directed Service Records: Query results and related records are in scope for this DPA when they contain Personal Data and are processed or retained through configured Service features, including chat history, saved queries, dashboards, uploads, exports, or materialized result artifacts.
- Aggregated/Anonymized Data: Data that has been aggregated or anonymized such that it can no longer identify individuals is not Personal Data and is not subject to this DPA.
2.3 Nature and Purpose of Processing
- Nature of Processing: Collection, storage, organization, structuring, retrieval, use, disclosure, and deletion of Personal Data
- Purpose of Processing: To provide the trusted data layer for source-connected AI answers Service to Customer as described in the Terms of Service
- Duration of Processing: For the term of the Customer's subscription plus applicable retention periods
- Categories of Data Subjects: Customer's employees, contractors, authorized users, and end users (for embedded widget deployments)
3. Processor Obligations
3.1 Processing Instructions
Answerplane shall process Personal Data only:
- On documented instructions from Customer (as set out in the Terms of Service and this DPA)
- To provide the Service and related technical support
- To comply with legal obligations (in which case we will inform Customer unless prohibited by law)
- As otherwise agreed in writing between the parties
3.2 Confidentiality
Answerplane shall ensure that all personnel authorized to process Personal Data:
- Are subject to confidentiality obligations (contractual or statutory)
- Have received appropriate training on data protection
- Process Personal Data only as necessary to fulfill their duties
- Are subject to background checks where required by applicable law
3.3 Security Measures
Answerplane implements and maintains appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption: AES-256 encryption for data at rest, TLS 1.3 for data in transit
- Access Controls: Role-based access control (RBAC), multi-factor authentication (MFA), principle of least privilege
- Multi-Tenant Isolation: Physical database isolation per organization
- Network Security: Network controls, rate limits, monitoring, and secure connection handling
- Security Testing: Regular vulnerability scanning, penetration testing, and security audits
- Incident Response: 24/7 security monitoring, documented incident response procedures
- Compliance: Preparing controls and documentation for enterprise compliance reviews, including SOC 2 and ISO 27001 readiness
Detailed security measures are described in our Privacy Policy and are available in our Security Documentation (provided to Enterprise customers upon request).
4. Sub-processors
4.1 General Authorization
Customer provides general authorization for Answerplane to engage Sub-processors to process Personal Data, subject to the requirements of this Section 4.
4.2 Current Sub-processors
Answerplane currently engages the following Sub-processors:
| Sub-processor | Location | Processing Activity |
|---|---|---|
| Microsoft Azure | Germany West Central (EU) | Cloud infrastructure and hosting |
| OpenAI | United States | AI/LLM processing (optional) |
| Anthropic | United States | AI/LLM processing (optional) |
| Google AI | United States | AI/LLM processing (optional) |
| Stripe, Inc. | United States | Payment processing |
| Postmark (ActiveCampaign) | United States | Email delivery |
Detailed Subprocessor Information: For details including data processed, security safeguards, and AI provider terms and controls, see our Subprocessor List.
4.3 Sub-processor Obligations
Answerplane shall:
- Impose data protection obligations on Sub-processors that provide substantially the same level of protection as this DPA
- Ensure Sub-processors are bound by written contracts that include Standard Contractual Clauses where required
- Remain fully liable to Customer for the performance of Sub-processors
- Conduct appropriate due diligence before engaging Sub-processors
4.4 Notice of New Sub-processors
Answerplane shall:
- Provide at least 30 days advance notice before adding new Sub-processors
- Update the Sub-processor list
- Notify Customer via email to the account email address on file
4.5 Right to Object
Customer may object to a new Sub-processor on reasonable grounds relating to data protection by notifying Answerplane in writing within 10 days of receiving notice. If the parties cannot resolve the objection:
- Customer may terminate the affected Service without penalty
- Answerplane will refund any prepaid fees for the terminated portion of the subscription
- Customer must exercise termination rights within 30 days of the original notice
5. International Data Transfers
5.1 Transfer Mechanisms
Where Personal Data is transferred from the European Economic Area (EEA), United Kingdom, or Switzerland to countries not recognized as providing adequate data protection:
- Answerplane relies on Standard Contractual Clauses (SCCs) approved by the European Commission
- The SCCs are incorporated into this DPA by reference (EU SCCs 2021/914)
- For transfers to the United States, Answerplane implements supplementary measures as required by EDPB guidance
5.2 Primary Data Location
Answerplane's primary infrastructure is located in the European Union (Azure Germany West Central, Frankfurt). Personal Data is stored and processed primarily within the EU. Transfers outside the EU occur only for:
- AI/LLM processing (question text and schema metadata only, not database content)
- Payment processing via Stripe (billing information only)
- Email delivery via Postmark (recipient addresses and message content)
5.3 Standard Contractual Clauses
The following Standard Contractual Clause modules apply:
- Module 2: Controller to Processor (Customer to Answerplane)
- Module 3: Processor to Sub-processor (Answerplane to Sub-processors)
Optional Clause: Customer may exercise audit rights under Clause 8.9 of the SCCs by providing 30 days advance written notice to [email protected].
6. Data Subject Rights
6.1 Assistance with Data Subject Requests
Answerplane shall, taking into account the nature of processing, assist Customer by appropriate technical and organizational measures in fulfilling Customer's obligations to respond to Data Subject requests to exercise their rights under Data Protection Laws, including:
- Right of access
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object
6.2 Self-Service Tools
Answerplane provides self-service tools within the Service that enable Customer to:
- Access and export Personal Data (account settings, query history, configurations)
- Update and rectify Personal Data
- Delete Personal Data (account deletion, database disconnection)
- Manage user access and permissions
6.3 Requests Received Directly
If Answerplane receives a Data Subject request directly, we will:
- Promptly notify Customer (within 5 business days)
- Redirect the Data Subject to Customer unless prohibited by law
- Not respond to the request without Customer's prior written authorization
6.4 Fees for Assistance
Answerplane will provide reasonable assistance at no additional charge. If assistance requires substantial resources beyond normal operations, we may charge reasonable fees based on our standard rates (to be agreed in advance).
7. Data Breach Notification
7.1 Notification Obligations
Answerplane shall notify Customer without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data breach affecting Customer's Personal Data. The notification shall include:
- Description of the nature of the breach (categories and approximate number of Data Subjects and records affected)
- Name and contact details of Answerplane's data protection officer or other contact point
- Description of likely consequences of the breach
- Description of measures taken or proposed to address the breach and mitigate its effects
7.2 Incident Response
Upon discovery of a Personal Data breach, Answerplane shall:
- Take immediate steps to contain and remediate the breach
- Preserve evidence and logs for investigation and regulatory purposes
- Provide reasonable cooperation and assistance to Customer in investigating the breach
- Provide updates to Customer as the investigation progresses
7.3 Notification Method
Breach notifications will be sent to the email address associated with Customer's account and to any additional security contacts designated by Customer.
8. Audit Rights
8.1 Compliance Documentation
Upon Customer's written request (maximum once per year), Answerplane shall make available:
- SOC 2 Type II reports (when available)
- ISO 27001 certifications (when available)
- Security and compliance documentation
- Evidence of compliance with this DPA
8.2 On-Site Audits (Enterprise Only)
For Enterprise plan customers only, Customer may conduct on-site audits or inspections subject to:
- Minimum 30 days advance written notice
- Maximum frequency: Once per year (unless required by supervisory authority following a breach)
- Audits conducted by qualified third-party auditors bound by confidentiality agreements
- Audits conducted during normal business hours with minimal disruption
- Customer bears all costs of the audit
- Audits must not access other customers' data or compromise security
8.3 Audit Findings
If an audit reveals non-compliance with this DPA:
- Answerplane will remediate critical findings within 90 days
- A remediation plan will be provided within 15 days of receiving the audit report
- Customer may conduct follow-up audits to verify remediation (at Customer's expense)
9. Data Retention and Deletion
9.1 Retention Periods
Answerplane retains Personal Data as follows:
- Account Data: Duration of subscription plus 90 days (or 30 days for GDPR deletion requests)
- Database Credentials: Duration of connection, then deletion from primary systems within 30 days or sooner where legally required
- Billing Records: 7 years (legal requirement)
- Audit Logs: 2 years (security and compliance)
9.2 Deletion Upon Termination
Upon termination or expiration of the subscription, Customer may:
- Export available Personal Data and platform records within 30 days using self-service or support-assisted tools
- Request deletion of eligible Personal Data, except records retained for legal compliance, security, fraud prevention, backup, or dispute-resolution purposes
Answerplane will delete or anonymize Personal Data within:
- Primary Systems: 30 days after termination or deletion request
- Backup Systems: Up to 90 days after deletion from primary systems
9.3 Certification of Deletion
Upon written request, Answerplane will provide written certification that Personal Data has been deleted in accordance with this DPA (except for data retained pursuant to legal obligations).
10. Cooperation and Compliance
10.1 Regulatory Cooperation
Answerplane shall reasonably cooperate with and assist Customer in:
- Responding to requests from supervisory authorities
- Conducting Data Protection Impact Assessments (DPIAs) where required
- Implementing measures to address risks identified in DPIAs
- Prior consultations with supervisory authorities where required
10.2 Impact Assessments
If Customer is required to conduct a DPIA regarding processing activities performed by Answerplane, Answerplane will provide reasonable assistance by:
- Providing relevant information about our processing activities
- Describing technical and organizational security measures
- Assisting with risk assessment and mitigation strategies
11. Limitation of Liability
Each party's liability under this DPA shall be subject to the limitations and exclusions of liability set forth in the Terms of Service. Nothing in this DPA shall limit either party's liability for:
- Violations of Data Protection Laws caused by willful misconduct or gross negligence
- Breaches of confidentiality obligations
- Indemnification obligations under the Terms of Service
12. Term and Termination
12.1 Term
This DPA takes effect on the date Customer accepts the Terms of Service and remains in effect until termination of the Service or until Personal Data has been deleted, anonymized, returned, or retained only as permitted by this DPA, whichever is later.
12.2 Effect of Termination
Upon termination:
- Answerplane will cease processing Personal Data (except as necessary for deletion or legal compliance)
- Customer may export Personal Data within 30 days
- Answerplane will delete or return Personal Data as instructed by Customer
- Provisions related to confidentiality, audit rights, and liability shall survive termination
13. General Provisions
13.1 Governing Law
This DPA is governed by the laws of the State of Delaware, United States, except where Data Protection Laws require otherwise. For matters relating to GDPR, the law of the relevant EU Member State shall apply.
13.2 Order of Precedence
In the event of conflict:
- Standard Contractual Clauses (where applicable)
- This Data Processing Agreement
- Terms of Service
13.3 Amendments
Answerplane may update this DPA to reflect:
- Changes in Data Protection Laws
- Changes in our processing activities
- Guidance from supervisory authorities
Material changes will be notified at least 30 days in advance. The updated DPA will be available at https://answerplane.com/legal/dpa.
13.4 Severability
If any provision of this DPA is held invalid or unenforceable, the remaining provisions will remain in full force and effect. The parties shall negotiate in good faith to replace the invalid provision with a valid provision that achieves the same purpose.
14. Contact Information
For questions or concerns regarding this DPA, contact:
Data Protection Officer: [email protected]
Enterprise DPA Requests: [email protected]
Legal Inquiries: [email protected]
Address:
Applifyer, LLC
131 Continental Dr, Suite 305
Newark, DE 19713
United States
Enterprise Customers
If you require a signed copy of this DPA, custom amendments, or a Business Associate Agreement (BAA) for HIPAA compliance, please contact our Enterprise sales team:
- Email: [email protected]
- Subject Line: "Enterprise DPA Request - [Company Name]"
- Include: Company name, contact information, and specific requirements