Legal
Data Processing Addendum
Last updated: 24 July 2026
This summary describes how AppTuring processes personal data on behalf of clients. A countersigned Data Processing Addendum (DPA) forms part of every services agreement and prevails over this summary.
1. Roles
For personal data processed to deliver Employer of Record services, the client is the data controller and AppTuring acts as processor, except where local employment law makes AppTuring a controller of employee data as the legal employer.
2. Scope & instructions
AppTuring processes personal data only on documented instructions from the client and as required to provide the services and comply with applicable law.
3. Security measures
We maintain technical and organizational measures appropriate to the risk, including encryption in transit, access controls on a need-to-know basis, and regular review of our security practices.
4. Sub-processors
We engage vetted sub-processors (for example, payroll, email, form handling, and analytics providers) under written terms that impose data-protection obligations no less protective than this addendum. A current list is available on request.
5. International transfers
Where personal data is transferred between the United States, Vietnam, or other jurisdictions, we apply appropriate safeguards, including standard contractual clauses where required.
6. Data-subject requests & breach notice
We assist the client in responding to data-subject requests and notify the client without undue delay after becoming aware of a personal-data breach affecting their data.
7. Return & deletion
On termination, we return or delete personal data processed on the client’s behalf, except where retention is required by law.
8. Requesting the full DPA
To receive the full, signable DPA, email legal@appturing.com.
This page is provided for general information and does not constitute legal advice. Questions? Email legal@appturing.com.