Skip to main content
AppFrameBack to AppFrame
For customers

Last updated
25 July 2026

Data Processing Addendum

Prelaunch notice

This legal text reflects the current prelaunch setup and should receive a final legal review before the public launch.

This page summarises the intended AppFrame DPA for customers acting as controllers of personal data contained in project material. A countersignable final agreement will be provided before paid or public availability.

Roles and instructions

The customer is controller and Estopia Engineering Ltd is processor for project material processed to provide AppFrame. We process it only on documented instructions expressed through the service, support requests and the agreement.

Subject matter and duration

Processing covers private storage, screen understanding, story and copy generation, editing, rendering, export and user-authorised support for the duration of the account and applicable deletion windows.

Security

  • Private object storage and short-lived object-bound URLs.
  • RLS and workspace-scoped authorisation.
  • Encryption in transit and provider encryption at rest.
  • Least-privilege service credentials and audited support access.
  • Daily encrypted backups and monthly restore testing target.

Subprocessors and transfers

Current subprocessors and purposes are listed on the Subprocessors page. We will provide appropriate notice of material changes and use approved transfer mechanisms where required.

Assistance and deletion

AppFrame provides account data export and deletion controls and will reasonably assist with data-subject requests, security incidents, impact assessments and regulator enquiries relating to the service.

Request the final DPA

Contact [email protected].

© 2026 Estopia Engineering Ltd
PrivacyImprint