Data Processing Addendum
Article 28 processor terms for organisations deploying our apps. Takes effect on acceptance of the Terms; no signature required.
- Last updated
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the developer behind Leap Studio, named on the entity details page (“we”, “us”, “Processor”), and the organisation accepting those Terms (“you”, “Customer”, “Controller”).
This DPA takes effect automatically on your acceptance of the Terms. No signature is required. A countersigned copy is available on request at contact@leapstudio.dev.
1. Definitions
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, “Personal Data Breach” and “Supervisory Authority” have the meanings given in the GDPR.
“Data Protection Laws” means all laws applicable to the Processing of Personal Data under this DPA, including the GDPR, the UK GDPR, the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and applicable US state privacy laws.
“Customer Personal Data” means Personal Data that we Process on your behalf under the Terms — that is, the categories in section 2, and nothing else.
“Standard Contractual Clauses” or “SCCs” means the clauses annexed to European Commission Implementing Decision (EU) 2021/914.
“UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
2. Scope of processing
2.1 Subject matter and duration
Providing our apps to you under the Terms, for as long as the Terms are in force, plus the retention periods in section 10.
2.2 Nature and purpose
Validating subscriptions; and, for Jesus — WWJD only, product analytics.
2.3 Categories of Data Subject
Your personnel who install and use our apps.
2.4 Categories of Personal Data — exhaustive
| Category | Detail | Applies to |
|---|---|---|
| Subscription state | Anonymous purchase receipt, subscription status, an app-generated pseudonymous identifier. Not name, email or payment details. | Apps with subscriptions |
| Product analytics events | Which feature was used, response length and latency, counts, paywall variant. Not the content of anything a user writes or is shown. | Jesus — WWJD only |
| Support correspondence | Whatever a user includes when emailing us, including their email address. | All, if a user writes to us |
| Web server logs | IP address, URL, user agent, timestamp, from visiting this website. | Website |
2.5 What is expressly out of scope
We do not Process, and have no means of receiving:
- documents, files, images or other content placed in an app;
- prompts, questions, chats or generated output;
- meeting audio or transcripts;
- health data, including anything read from Apple Health;
- location data, other than where Auto Brightness Clock passes an approximate location directly to Apple’s weather service without it reaching us;
- contacts, calendar entries or reminders;
- names, email addresses or payment details of end users, from purchases.
2.6 Special category data
We do not Process special category Personal Data under this DPA. Where an app is used with special category data — clinical notes in Cloister AI, for instance — that data remains on the device and never reaches us.
3. Roles
You are the Controller. We are the Processor for the Customer Personal Data in section 2.4.
We are an independent Controller for our own limited purposes: keeping our business records, meeting our tax and legal obligations, and handling correspondence. Our Privacy Policy covers that.
4. Our obligations
We will:
- Process only on your documented instructions, which are given by the Terms and this DPA, and by your configuration of the apps. If we are required by law to Process otherwise, we will tell you first unless the law forbids it.
- Tell you if an instruction appears to breach Data Protection Laws, and we may suspend that processing until it is resolved.
- Ensure confidentiality. Everyone with access to Customer Personal Data is bound by confidentiality obligations.
- Implement appropriate technical and organisational measures under Article 32 — see section 7 and the Security overview.
- Engage subprocessors only as set out in section 6.
- Assist you with data subject requests (section 8), with security, breach notification, DPIAs and prior consultation, taking into account the nature of the processing and the information available to us.
- Delete or return Customer Personal Data at the end of the Terms (section 10).
- Make available the information needed to demonstrate compliance and allow audits (section 11).
5. Your obligations
You will:
- Ensure you have a lawful basis for the Personal Data your personnel put into our apps, and provide any notices required.
- Be responsible for the security of your own devices, including device encryption, passcodes, mobile device management and backup policy. Content created in our apps remains on the device and its confidentiality is determined by your device controls.
- Not instruct us to Process Personal Data in breach of Data Protection Laws.
6. Subprocessors
6.1 Authorisation
You give general written authorisation for us to engage subprocessors. The current list, with each one’s role, the data it touches and its location, is published at /legal/subprocessors.
6.2 Changes
We will update that page at least 30 days before a new subprocessor starts processing Customer Personal Data. To be notified directly, email contact@leapstudio.dev.
6.3 Objection
You may object on reasonable data protection grounds within 30 days. We will work with you to find an alternative. If we cannot, you may terminate the affected subscription through Apple.
6.4 Liability
We remain fully liable to you for our subprocessors’ performance of their obligations.
7. Security
Our measures are set out in the Security overview. In summary:
- Data minimisation — customer content is not collected.
- Encryption in transit — TLS on all connections, HSTS on this site.
- Encryption at rest — user content is protected by iOS file-level encryption on the device; our subprocessors encrypt at rest.
- Access control — multi-factor authentication on every account that could touch Customer Personal Data.
- No production data store for customer content.
- Vulnerability handling — a published disclosure route and response times.
8. Data subject requests
We hold no directly identifying data about end users and are usually unable to locate records for a specific individual. Content is held on the user’s own device and is deleted when the app is deleted.
We will assist you without undue delay and at no charge. Requests to contact@leapstudio.dev.
If a data subject contacts us directly, we will tell them to contact you where we can identify you as the controller, and will not respond substantively unless you ask us to.
9. Personal data breach
We will notify you without undue delay and in any event within 48 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data, giving you what you need to meet your own Article 33 obligation within 72 hours.
The notification will describe the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, the measures taken or proposed, and a contact point.
We will also meet our own obligations under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth).
Reports to contact@leapstudio.dev.
10. Deletion and return
On termination, we will delete Customer Personal Data within 90 days, except where we must keep it by law — principally purchase and tax records, which Australian law requires us to keep for seven years.
We hold no customer content, so there is nothing to return. Your content remains on your devices and under your control.
11. Audit
We will make available the information needed to demonstrate compliance with Article 28.
We provide, at no charge:
- the published Security overview and Subprocessors list;
- written responses to a security questionnaire within 15 business days;
- a call to answer specific questions.
Where Data Protection Laws entitle you to an audit that these do not satisfy, we will not obstruct it. You bear the cost, give 30 days’ notice, audit no more than once in 12 months absent a breach, and the auditor signs a confidentiality agreement.
12. International transfers
We are in Australia. Australia has not received an EU adequacy decision.
Where you transfer Customer Personal Data to us and Chapter V of the GDPR applies, the Standard Contractual Clauses are incorporated into this DPA by reference and take effect automatically:
- Module Two (Controller to Processor) applies.
- Clause 7 (docking) applies.
- Clause 9: Option 2, general written authorisation, with the 30-day notice period in section 6.2.
- Clause 11: the optional independent dispute resolution body is not used.
- Clause 17: governed by the law of Ireland.
- Clause 18(b): the courts of Ireland.
- Annex I.A — the parties are you and us, contactable as set out in the Terms and at contact@leapstudio.dev.
- Annex I.B — the categories in section 2 of this DPA, transferred continuously for the duration of the Terms.
- Annex I.C — the competent supervisory authority is that of the EU member state in which you are established, or, where you are not established in the EU, that of the member state where your Article 27 representative is.
- Annex II — the measures in section 7 and the Security overview.
- Annex III — the Subprocessors list.
For transfers from the UK, the UK Addendum is incorporated on the same terms, with Tables 1 to 3 populated as above and Table 4 set to “neither party”.
For transfers from Switzerland, the SCCs apply with references to the GDPR read as references to the Swiss FADP and the competent authority read as the FDPIC.
Transfer impact. We have assessed these transfers. The data transferred is limited to the pseudonymous records in section 2.4. No subprocessor holds data identifying an end user by name. We have received no government access request. If we receive one we will challenge it where there are lawful grounds and notify you where permitted.
13. Australian Privacy Principles
Where the Privacy Act 1988 (Cth) applies to you, we will handle Customer Personal Data consistently with the Australian Privacy Principles, including APP 6 (use and disclosure), APP 8 (cross-border disclosure) and APP 11 (security).
Under this DPA that obligation is contractual and binding.
14. US state privacy laws
Where the CCPA as amended by the CPRA, or a comparable state law, applies, we act as a service provider or processor as those terms are defined.
We will not sell or share Customer Personal Data, will not retain, use or disclose it except to provide the services or as permitted by law, and will not combine it with data from other sources except as permitted. We certify that we understand and will comply with these restrictions. See US State Privacy Rights.
15. Liability
Each party’s liability under this DPA is subject to the limitations in section 8 of the Terms of Service, except where Data Protection Laws do not permit those limitations.
Nothing in this DPA limits a data subject’s rights, including under Clause 12 of the SCCs.
16. Conflicts
If this DPA conflicts with the Terms of Service, this DPA prevails on data protection matters. If it conflicts with the SCCs, the SCCs prevail.