Data Processing Addendum

Last updated: 18 August 2026

This Addendum ("DPA") forms part of the Terms of Service between Go Live AI, operator of approve-it.online (the "Processor"), and the Tenant (the "Controller"). It applies whenever we process personal data on the Controller's behalf. Where it conflicts with the Terms on data protection, this DPA prevails.

1. Roles

The Controller decides why and how personal data is processed in its workspace. The Processor processes it only on the Controller's documented instructions, which are given through the Terms, this DPA, and the Controller's use of the product's settings and features.

2. Subject matter, nature and duration

Subject matter: providing a purchase-approval platform. Nature and purpose:hosting, storing, routing and transmitting request data, attachments and audit records; sending workflow notifications; and forwarding verified items to an accounting inbox the Controller nominates. Duration: for the term of the subscription plus the deletion period in section 9.

3. Categories of data subjects and personal data

4. Processor obligations

5. Subprocessors

The Controller authorises the subprocessors below. Each is bound by data-protection terms no less protective than this DPA. We will give at least 14 days' notice to Tenant Admins before adding or replacing a subprocessor, and the Controller may terminate the subscription without penalty if it reasonably objects.

Subprocessor rolePurposeData
Cloud application platformHosting, database, authentication, encrypted file storageAll Customer Data
Transactional email providerDelivering workflow notification emailsName, email, request summary

The accounting inbox the Controller nominates for auto-forwarding (for example a Xero draft inbox) is not our subprocessor — it is a recipient chosen and controlled by the Controller.

6. Assisting the Controller

We provide in-product tooling so the Controller and its users can satisfy data-subject rights directly: self-service export and deletion in the Privacy Centre, admin user management, and CSV export. Where a request cannot be met with those tools, we will assist within a reasonable time. We will also assist with data protection impact assessments and with consultations with a supervisory authority, so far as the processing is within our knowledge.

7. Personal data breaches

We will notify the Controller without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting its data, with the nature of the breach, the categories and approximate volume of data affected, the likely consequences and the remediation steps taken or planned.

8. Audit and information

On reasonable written request, and no more than once a year unless required by a supervisory authority, we will provide the information needed to demonstrate compliance with this DPA. Audits must be scheduled in advance, conducted during business hours, subject to confidentiality, and must not compromise other tenants' data.

9. Deletion and return

On request, or within 30 days of the subscription ending, we delete the Controller's personal data unless the law requires longer retention. Before deletion the Controller can export requests as CSV and download attachments. Where a user is deleted, personal identifiers in the audit trail are redacted while the financial record is retained for the Controller's internal control purposes.

10. International transfers

Where personal data leaves the UK/EEA, transfers rely on an adequacy decision or on Standard Contractual Clauses with the UK International Data Transfer Addendum, supported by encryption in transit and at rest.

11. Liability

The limitations of liability in the Terms apply to this DPA.

Annex — Technical and organisational measures


Questions about this document? Email info@go-liveai.com.