AppCompliance is built in the EU, for teams that take the GDPR as a floor rather than a hurdle. This page explains the roles, the paperwork and the practice.
Roles
- For your account data (email, team, billing) we are the controller.
- For the builds you upload and the findings we produce, we act as a processor working on your instructions. You decide what gets scanned and when it gets deleted.
The paperwork
- A data processing agreement (DPA) is part of every paid plan and available on request before you buy anything.
- The sub-processor list is public on the EU-first data handling page and versioned; we announce changes before they take effect.
- Records of processing and our incident response procedure are maintained internally and summarised for customers on request.
The practice
- Binaries are destroyed immediately after each scan; there is nothing to request deletion of.
- Findings live inside your retention window and are deleted when it ends or when you delete them, whichever comes first.
- Data stays on EU infrastructure with EU vendors, with Stripe as the single named exception for payments.
- Access by our own team is limited and logged.
Data subject requests
Access, correction, deletion, portability: mail info@appcompliance.io. We respond within the statutory month, and usually much faster.