Appspace is a Leader in the Gartner® Magic Quadrant™ for Intranet Packaged Solutions Get the report >
Last updated September 16, 2026
Data Processing Addendum
This Data Processing Addendum (this “Addendum”) forms part of the Appspace End User License Agreement (the “Agreement”) between you (“you” or “Customer”) and Appspace, Inc. a corporation formed under the laws of the state of Delaware, with offices located at 400 N. Tampa St., Suite 1725, Tampa, FL 33602, USA (“Appspace”) for the provision of the Products. Capitalized terms not expressly defined in this Addendum will have the meanings given to them in the Agreement. If and to the extent language in this Addendum or any of its Appendices conflicts with the Agreement, this Addendum shall take precedence. The term of this Addendum corresponds to the duration of the Agreement.
“Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. “Control,” for purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.
“Data Protection Legislation” means all applicable laws and regulations relating to the processing of personal data and privacy, including where applicable, the California Consumer Privacy Act of 2018, Cal. Civil Code § 1798.100 et seq., (“CCPA”), as well as any guidance notes and codes of practice issued by the European Commission, European Data Protection Board and applicable national supervisory authorities including without limitation the UK Data Protection Act 2018, UK GDPR, GDPR and Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (ePrivacy Directive), the Privacy and Electronic Communications (EC Directive) Regulations 2003 (SI 2003/2426), Swiss Data Protection Act 2020 and all local or national laws and regulations implementing the aforementioned, in each case as may be updated, amended, supplemented or replaced from time to time.
“Data Subject” means the identified or identifiable natural person to whom Customer Personal Data relates.
“Customer Personal Data” means the Personal Data within Customer Data Processed by Appspace on Customer’s behalf in the course of providing Products to Customer.
“GDPR” means EU Regulation 2016/679 on the protection of natural persons with regard to the processing of personal data.
“International Data Transfer” means any transfer of Customer Personal Data from the EEA, Switzerland or the United Kingdom to an international organization or to a country outside of the EEA, Switzerland and the United Kingdom.
“Personal Data” shall have the meaning assigned to the terms “personal data” or “personal information” under applicable Data Protection Legislation.
“Process” or “Processing” means any operation or set of operations which is performed on Personal Data or sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.
“Personal Data Breach” means the actual breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
“Standard Contractual Clauses” means (i) where the GDPR applies, the standard contractual clauses adopted by the European Commission in its Implementing Decision (EU) 2021/91 of 4 June 2021 (the “EU/EEA SCCs”); (ii) where the Swiss DPA applies, the applicable standard data protection clauses issued, approved or recognized by the Swiss Federal Data Protection and Information Commissioner (the “Swiss SCCs”); and (iii) where UK Data Protection Law apply, the standard data protection clauses adopted pursuant to or permitted under Article 46 of the UK GDPR (the “UK SCCs”).
“Subprocessor” means Appspace’s authorized Affiliates, vendors and third-party service providers that Process Customer Personal Data in the course of providing the Products.
“UK Addendum” means the addendum to the Standard Contractual Clauses issued by the UK information Commissioner under Section 119A(1) of the UK Data Protection Act 2018 (version B1.0, in force March 21, 2022).
“UK GDPR” means the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of Section 3 of the European Union (Withdrawal) Act 2018.
“Data Controller”, “Data Processor”, “Business”, and “Service Provider”, shall be interpreted in accordance with applicable Data Protection Legislation.
If changes in Data Protection Legislation result in new material obligations as it relates to Appspace’s assistance under this Section 2.3.2, the Parties will work together in good faith to agree upon an acceptable resolution. Each Party shall be responsible for its own costs incurred under this Section 2.3.2; and
This summary sets out details of the processing of Customer Personal Data under the Agreement by Appspace and any authorized Subprocessors (as listed below):
The subject matter and duration of the Processing
SYSTEMS: Appspace workplace experience hosted platform
SUBJECT MATTER: The subject-matter of the Processing is the provision of the Products that involves the Processing of Customer Personal Data.
DURATION OF PROCESSING: The Processing will be carried out until the Agreement terminates.
The nature and purpose of the Processing
PURPOSES OF PROCESSING: In accordance GDPR Art. 6, the lawful processing of information will be conducted to meet the performance of the contract (EULA)
LEGAL BASIS FOR PROCESSING: EU and EEA organizations agree the legal basis for collecting, using and processing personal data as described below is in order for their users to experience the full benefits of the Appspace platform in accordance with Appspace’s EULA
NATURE OF PROCESSING: As part of our data minimization practices, the collection, storage and other Processing necessary to provide, maintain, and optimize the Products provided to Customer in accordance with the Agreement.
The types of Personal Data being Processed
PERSONAL DATA:
SPECIAL CATEGORIES OF PERSONAL DATA: Appspace does not knowingly collect (and Customer shall not submit or upload) any special categories of data as defined under the Data Protection Legislation.
The categories of Data Subject
Customer and Affiliates employees and/or users.
#
Name
Territory
Area of use
1
Google LLC
Iowa, United States
Cloud Hosting Services
2
Google LLC
St. Ghislain, Belgium
Cloud Hosting Services
3
Google LLC
London, United Kingdom
Cloud Hosting Services
4
Google LLC
New South Wales, Australia
Cloud Hosting Services
5
Google LLC
Quebec, Canada
Cloud Hosting Services
6
Google LLC
Singapore, Singapore
Cloud Hosting Services
7
Google LLC
Dammam, Kingdom of Saudi Arabia
Cloud Hosting Services
8
Microsoft, Inc.
Iowa, United States
Cloud Hosting Services
9
Microsoft, Inc.
Paris, France
Cloud Hosting Services
9
Microsoft, Inc.
New South Wales, Australia
Cloud Hosting Services
10
Salesforce, Inc.
California, United States |
CRM/Support Services
11
Gainsight, Inc.
California, United States |
CRM/Support Services
12
SupportLogic, Inc.
California, United States |
CRM/Support Services
13
Intercom, Inc.
California, United States |
CRM/Support Services
14
Clari, Inc.
California, United States
CRM/Support Services
15
Goldcast, LLC
Virginia, United States
CRM/Support Services
Confidentiality (Article 32(1)(b) GDPR)
Measures must be taken to prevent unauthorized physical access to premises and facilities holding Customer Personal Data. Measures shall include:
Measures must be taken to prevent unauthorized access to IT systems. These must include the following technical and organizational measures for user identification and authentication:
Measures must be taken to prevent authorized users from accessing data beyond their authorized access rights and prevent the unauthorized input, reading, copying, removal modification or disclosure of data. These measures shall include:
Integrity (Article 32(1)(b) GDPR)
Measures must be taken to prevent the unauthorized access, alteration or removal of data during transfer, and to ensure that all transfers are secure and are logged. These measures shall include:
Measures must be put in place to ensure all data management and maintenance is logged, and an audit trail of whether data have been entered, changed or removed (deleted) and by whom must be maintained. Measures should include:
Measures should be put in place to ensure that data is processed strictly in compliance with the data importer’s instructions. These measures must include:
Availability and Resilience (article 32(1)(b))
Measures should be put in place designed to ensure that data are protected against accidental destruction or loss. These measures must include:
Measures should be put in place to allow data collected for different purposes to be processed separately. These measures should include:
© 2026 Appspace Inc. Appspace is a registered trademark of Appspace Inc. All rights reserved.