Data Processing Addendum
Last updated: 18 August 2026
This Addendum ("DPA") forms part of the Terms of Service between Go Live AI, operator of approve-it.online (the "Processor"), and the Tenant (the "Controller"). It applies whenever we process personal data on the Controller's behalf. Where it conflicts with the Terms on data protection, this DPA prevails.
1. Roles
The Controller decides why and how personal data is processed in its workspace. The Processor processes it only on the Controller's documented instructions, which are given through the Terms, this DPA, and the Controller's use of the product's settings and features.
2. Subject matter, nature and duration
Subject matter: providing a purchase-approval platform. Nature and purpose:hosting, storing, routing and transmitting request data, attachments and audit records; sending workflow notifications; and forwarding verified items to an accounting inbox the Controller nominates. Duration: for the term of the subscription plus the deletion period in section 9.
3. Categories of data subjects and personal data
- Data subjects — the Controller's staff and contractors who use the platform as requesters, approvers, finance reviewers or admins; individuals named in requests or supplier records; and individuals identifiable from uploaded documents.
- Personal data — name, work email, role and tenant membership; request content (reason, description, supplier, category, location, cost, comments); attachment contents such as quotes and invoices; audit metadata including IP address, user agent and timestamps.
- Special category data — not requested and not intended to be stored. The Controller must not upload it.
4. Processor obligations
- Process personal data only on the Controller's documented instructions, and tell the Controller if an instruction appears unlawful.
- Ensure personnel with access are bound by confidentiality and access data on a need-to-know basis.
- Implement and maintain the technical and organisational measures in the Annex.
- Not sell personal data or use it for advertising, profiling or model training.
5. Subprocessors
The Controller authorises the subprocessors below. Each is bound by data-protection terms no less protective than this DPA. We will give at least 14 days' notice to Tenant Admins before adding or replacing a subprocessor, and the Controller may terminate the subscription without penalty if it reasonably objects.
| Subprocessor role | Purpose | Data |
|---|---|---|
| Cloud application platform | Hosting, database, authentication, encrypted file storage | All Customer Data |
| Transactional email provider | Delivering workflow notification emails | Name, email, request summary |
The accounting inbox the Controller nominates for auto-forwarding (for example a Xero draft inbox) is not our subprocessor — it is a recipient chosen and controlled by the Controller.
6. Assisting the Controller
We provide in-product tooling so the Controller and its users can satisfy data-subject rights directly: self-service export and deletion in the Privacy Centre, admin user management, and CSV export. Where a request cannot be met with those tools, we will assist within a reasonable time. We will also assist with data protection impact assessments and with consultations with a supervisory authority, so far as the processing is within our knowledge.
7. Personal data breaches
We will notify the Controller without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting its data, with the nature of the breach, the categories and approximate volume of data affected, the likely consequences and the remediation steps taken or planned.
8. Audit and information
On reasonable written request, and no more than once a year unless required by a supervisory authority, we will provide the information needed to demonstrate compliance with this DPA. Audits must be scheduled in advance, conducted during business hours, subject to confidentiality, and must not compromise other tenants' data.
9. Deletion and return
On request, or within 30 days of the subscription ending, we delete the Controller's personal data unless the law requires longer retention. Before deletion the Controller can export requests as CSV and download attachments. Where a user is deleted, personal identifiers in the audit trail are redacted while the financial record is retained for the Controller's internal control purposes.
10. International transfers
Where personal data leaves the UK/EEA, transfers rely on an adequacy decision or on Standard Contractual Clauses with the UK International Data Transfer Addendum, supported by encryption in transit and at rest.
11. Liability
The limitations of liability in the Terms apply to this DPA.
Annex — Technical and organisational measures
- Encryption — TLS in transit; encryption at rest for the database and file storage.
- Tenant isolation — row-level security policies scope every table to the acting user's tenant, enforced by the database rather than by application code alone.
- Access control — roles stored in a dedicated table separate from user profiles and checked server-side; least-privilege database grants; privileged operations restricted to server-side code.
- File storage — attachments held in private buckets, reachable only through short-lived signed links issued to authorised users.
- Workflow integrity — server-side validation of every stage transition, self-approval prevention, and variance checks between approved amount and invoiced amount.
- Auditability — append-only audit events recording actor, action, entity and timestamp for approvals, role changes and admin configuration changes.
- Input validation — schema validation of all submitted data on both client and server.
- Email hygiene — authenticated sending domain with SPF, DKIM and DMARC alignment, plus suppression handling for bounces and unsubscribes.
- Resilience — managed platform backups; deletion routines that remove data on termination.
Questions about this document? Email info@go-liveai.com.