
Last updated September 2026
This Data Processing Addendum (“DPA”) forms part of the Agreement (the Appearify Terms of Service, and any Agency MSA) between Maren Augmented Intelligence LLC (DBA Appearify) (“Appearify,” “Processor”) and the customer identified in the Agreement (“Customer,” “Controller”). It applies where Appearify processes Personal Data on Customer’s behalf.
“Personal Data,” “Controller,” “Processor,” “Processing,” and “Data Subject” have the meanings given under applicable data protection law (including US state privacy laws such as the CCPA/CPRA, and, where applicable, the GDPR). “Applicable Law” means the data protection laws that apply to Customer’s use of Appearify.
Customer is the Controller (or, under US state law, “Business”) and Appearify is the Processor (or “Service Provider”). Appearify processes Personal Data only to provide the service and only on Customer’s documented instructions, including as set out in the Agreement and this DPA. Appearify will tell Customer if, in its opinion, an instruction violates Applicable Law.
Appearify will: (a) process Personal Data only per Customer’s instructions; (b) ensure persons authorized to process it are under confidentiality obligations; (c) implement appropriate technical and organizational security measures (Section 7); (d) not sell or share Personal Data, and not retain, use, or disclose it for any purpose other than providing the service or as permitted by Applicable Law; (e) assist Customer, taking into account the nature of processing, with data-subject requests and with security, breach-notification, and impact-assessment obligations.
Customer authorizes Appearify to engage the subprocessors listed at /legal/subprocessors to process Personal Data. Appearify imposes data-protection terms on each subprocessor no less protective than this DPA and remains responsible for their performance. Appearify will give Customer advance notice of any new subprocessor (by updating that page and, where Customer has subscribed to notice, by email). Customer may object on reasonable data-protection grounds within 30 days; if the parties cannot resolve the objection, Customer may terminate the affected service.
Where Personal Data is transferred across borders, the parties will rely on a lawful transfer mechanism (such as the EU Standard Contractual Clauses or UK equivalent, incorporated by reference where applicable). At launch, processing is primarily in the United States for US-addressed businesses.
Appearify maintains technical and organizational measures appropriate to the risk, including: encryption of raw third-party captures and personal data with per-record keys (with only ciphertext and hashes stored in the sealed record); access controls and least-privilege database posture (row-level security enforced; client access mediated by audited server routines); audit logging; and secret management with spend caps armed before any metered call. A summary is available on request under NDA.
Consistent with the Privacy Policy: when Customer or a Data Subject exercises a deletion right, Appearify destroys the per-record encryption key (crypto-shredding), which renders the personal data unrecoverable without rewriting the dated, tamper-evident receipt. Where an individual’s name appears inside a receipt, the remedy is display redaction, disclosed on export, not deletion of the record. Appearify resolves verified requests within 45 calendar days.
Appearify will, to the extent legally permitted, promptly notify Customer if it receives a request from a Data Subject and will not respond except on Customer’s instructions or as required by law. Appearify provides self-serve access, correction, deletion, and redaction tooling to assist.
Appearify will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer’s data, with the information reasonably available, and will cooperate on remediation and required notifications.
Appearify will make available information reasonably necessary to demonstrate compliance and will allow for audits on reasonable prior notice, subject to confidentiality and no more than once per year absent a regulator requirement or a breach.
On termination, Appearify will, at Customer’s choice, delete or return Personal Data within 30 days, except (a) the append-only receipt record, which follows the crypto-shred/redaction model above, and (b) data Appearify must retain by law. Customer can export its receipts at any time.
This DPA is subject to the limitation of liability in the Agreement. If there is a conflict on data-protection matters, this DPA controls; on all other matters, the Agreement controls.
Need a countersigned copy for your procurement or privacy team? Email hello@appearify.ai and we will send this DPA for signature as an addendum to the Terms of Service.
Maren Augmented Intelligence LLC (DBA Appearify), 4003 Twin Rivers Trl, Parrish, FL 34219, USA.