The owner who creates a workspace accepts this agreement on behalf of their organisation, together with the terms of use. Apportly records the version accepted, the date and the account that accepted it; each new version must be accepted again.
1. Parties and subject matter
This agreement is entered into between the customer organisation that creates and administers an Apportly workspace (the “Organisation”), as controller, and DJIDJELLI, entreprise individuelle (EI), SIREN 493 003 677, R.C.S. Manosque, based in 04000 Digne-les-Bains, which publishes the Apportly platform (“Apportly”), as processor within the meaning of Article 28 of Regulation (EU) 2016/679 (GDPR).
It supplements the terms of use and prevails over any other provision as regards personal data processed on behalf of the Organisation.
Processing that Apportly carries out for its own purposes, such as user accounts and their security, billing, prospecting or demo requests, does not fall under this agreement: it is described in the privacy policy.
Current version: 2026-09-23.
2. Duration, nature and purposes of the processing
Apportly provides the Organisation with a web back office and a mobile app under its own brand to manage its network of referrers, the leads they refer, communications, contracts and commissions. Apportly processes the related personal data solely to provide this service.
Nature of the operations: hosting, recording, organisation, consultation, alteration, making available to authorised users, transmission by email, notification or integration, export, anonymisation and deletion.
Purposes: network management (registrations, invitations, individual contracts, activation), tracking of referrals and leads, messaging and posts, calculation and tracking of commissions and rewards, notifications, showcase website and mobile app under the Organisation’s brand, integrations that it enables.
Duration: for the term of the Organisation’s subscription, then during the reversibility period, until the data is actually deleted as provided for in clause 11.
For a merchant using the Carte app, this agreement also applies to the data of its loyalty programme: customers holding its card, points, visits, benefits and referrals. The Carte customer account and the shared app, however, fall under Apportly, which is the controller for that processing.
3. Data and data subjects
Data subjects:
- members of the Organisation’s network: referrers, introducers, agents and partners;
- referred leads and, where applicable, their contact persons;
- users of the Organisation: owner, administrators and team members;
- customers holding the loyalty card of a merchant using Carte;
- individuals featured on the Organisation’s showcase website.
Categories of data:
- identity and contact details: surname, first name, email, phone number, photo, company and job title;
- business data: company name, SIREN number of a sole trader, legal representative and address;
- contractual data: individual contracts, accepted versions, date of acceptance and browser used;
- financial data: commission rules and amounts, rewards and payment references, excluding bank details;
- referrals: the lead’s identity and contact details, need, stages, amounts, comments and the referrer’s declaration that the lead has been informed;
- communications: messages, posts, photos and attachments;
- technical data: identifiers, sessions, notification tokens and logs.
The service is not designed to process sensitive data within the meaning of Article 9 of the GDPR or data relating to criminal convictions. The Organisation must refrain from entering such data in free-text fields.
4. Documented instructions
The Organisation, as controller, determines the purposes and legal bases of its processing, informs the data subjects, in particular through the privacy policy published on its website, and is responsible for the lawfulness of the data it enters, imports or has its referrers submit.
Apportly processes the data only on the documented instructions of the Organisation. These instructions consist of: this agreement, the terms of use, the workspace configuration and every action taken by an authorised user of the Organisation in the back office, the mobile app or the API.
Enabling a webhook, creating an API key or authorising the AI connector constitutes an instruction from the Organisation to transmit the data concerned to the recipient it has chosen. That recipient then acts under the sole responsibility of the Organisation, which provides the legal framework for any transfer outside the European Union.
If Union or Member State law requires Apportly to carry out processing without instructions, Apportly informs the Organisation of that requirement before processing, unless that law prohibits this on important grounds of public interest.
Apportly immediately informs the Organisation if it considers that an instruction infringes the GDPR or any other data protection provision.
5. Confidentiality
Only persons authorised by Apportly and bound by a confidentiality obligation have access to the data, to the extent necessary for the support, maintenance or security of the service.
A support session in an Organisation’s workspace is explicitly authorised, limited to that workspace and recorded in the audit log. It cannot be used to accept the platform terms on behalf of the Organisation.
6. Security measures
Apportly implements the following technical and organisational measures, which it reviews regularly and updates without lowering their level of protection:
- hosting of application data and files with Convex, in the European region eu-west-1 (Ireland);
- encryption of communications in transit (HTTPS);
- isolation of each workspace: the user’s organisation, role and permissions are verified server-side on every request, never on the basis of data supplied by the browser;
- passwords, one-time codes and API keys stored only as hashes; encrypted two-factor authentication secrets, invitation tokens and webhook secrets;
- two-factor authentication required for platform administrators and for workspace owners and administrators, and offered to every account, with a lockout after repeated failures;
- audit log of sensitive operations: permissions, contracts, publishing, support sessions and acceptances;
- rate limiting on public entry points;
- signed webhooks, restricted to HTTPS and rejecting private destinations;
- email sending log with no recipient or subject in plain text.
7. Sub-processors
The Organisation gives Apportly general authorisation to engage the sub-processors listed in the annex, for the purposes stated there.
Apportly informs the workspace owner by email at least 30 days before adding or replacing a sub-processor. During this period, the Organisation may object in writing on reasonable grounds relating to data protection. If no solution is found, it may terminate the service concerned without penalty before the change takes effect.
Apportly imposes on each sub-processor, by contract, data protection obligations equivalent to those of this agreement and remains liable to the Organisation for the performance of those obligations.
8. Assistance with data subject rights
Apportly provides the Organisation, within its workspace, with the means to respond to requests from data subjects:
- rectify the record of a contact or lead;
- anonymise a lead, for example following an erasure request;
- add a person to the Organisation’s objection list, which prevents any new referral concerning them;
- export a person’s data for an access or portability request;
- send the lead, when they are referred, an information email containing an objection link.
When a person contacts Apportly directly about data processed for the Organisation, Apportly forwards their request to the Organisation without delay and does not respond to it itself, unless instructed to do so by the Organisation. Apportly assists the Organisation, as far as possible, with any request that cannot be handled from the workspace.
9. Personal data breaches
Apportly notifies the Organisation of any personal data breach affecting it without undue delay, and no later than 48 hours after becoming aware of it, by email to the workspace owner.
The notification describes, where possible, the nature of the breach, the categories and approximate number of data subjects and records concerned, its likely consequences, the measures taken or proposed and the contact point at Apportly. Information that is not yet available is provided as soon as possible.
The Organisation, as controller, decides whether to notify the supervisory authority and inform the data subjects; Apportly provides it with the necessary information.
10. Data protection impact assessment and prior consultation
On request, Apportly provides the Organisation with the information available to it to carry out a data protection impact assessment and, where applicable, to consult the supervisory authority.
11. End of the contract: return and deletion
At the end of the subscription, the Organisation has a 90-day reversibility period. During this period, its owner may export all the workspace data in a structured, commonly used format, and Apportly reminds the owner of the deletion date by email.
At the end of this period, Apportly automatically deletes the workspace and the data it contains, unless a legal retention obligation applies. Any backup copies held by the hosting provider are deleted at the end of their rotation cycle. The Organisation may also delete its workspace at any time from its settings.
12. Documentation and audits
Apportly makes available to the Organisation the information necessary to demonstrate compliance with this agreement, including the description of the security measures, the list of sub-processors and their transfer safeguards.
The Organisation may carry out an audit, or have one carried out by an independent auditor bound by confidentiality, once a year or after a personal data breach, subject to 30 days’ notice. The audit is conducted without disrupting the service or exposing other organisations’ data; each party bears its own costs.
13. Transfers outside the European Union
Workspace data is hosted in the European Union. Some sub-processors listed in the annex may process data from a third country, in particular the United States. Each transfer relies on an adequacy decision, including the EU-US Data Privacy Framework where the provider is certified under it, or on the European Commission’s standard contractual clauses. The mechanism used is set out in the annex; the note “to be confirmed” indicates that a check with the provider is in progress.
A copy of the applicable safeguards can be obtained on request from clarisse@apportly.app.
14. Liability, changes and governing law
Each party’s liability under this agreement is governed by the terms of use and the applicable contract. Nothing in this agreement limits the rights that data subjects have under the GDPR.
Apportly may amend this agreement to reflect changes to the service, the sub-processors or regulations. Any new version is presented to the workspace owner, who must accept it to continue using the back office.
This agreement is governed by French law.
Annex: sub-processors and recipients
Apportly’s sub-processors for the Organisation’s data:
| Recipient | Purpose | Data received | Location | Transfer safeguard |
|---|---|---|---|---|
| Convex | The platform’s database, files, authentication and real-time functions | All workspace data: accounts, network, leads, messages, contracts, commissions and files | European Union, eu-west-1 region (Ireland); company based in the United States | Hosting in the European Union; for any access from the United States, Data Privacy Framework or standard contractual clauses (to be confirmed) |
| Cloudflare | Delivery and protection of the website, back office and web app | Web traffic: IP address, session cookies, URLs visited and relayed sign-in requests | Global network; company based in the United States | Data Privacy Framework or standard contractual clauses (to be confirmed) |
| Resend | Sending transactional emails: codes, invitations, contracts, notifications and statements | Recipient address, email subject and content, including names, amounts, links and attached commission statements | United States (sending region to be confirmed) | Data Privacy Framework or standard contractual clauses (to be confirmed) |
| Expo | Relaying notifications to iOS, building and updating the mobile apps | Device token, notification title and text; IP address during an update | United States | Data Privacy Framework or standard contractual clauses (to be confirmed) |
| Google Firebase Cloud Messaging | Delivering notifications on Android and in the browser | Device or browser token, notification title and text; browser IP address | United States | Data Privacy Framework (to be confirmed) |
| Apple Push Notification service | Delivering notifications on iPhone and iPad | Device token, notification title and text | United States | Data Privacy Framework (to be confirmed) |
Recipients that act on their own behalf, under their own terms:
| Recipient | Purpose | Data received | Location | Transfer safeguard |
|---|---|---|---|---|
| Apple App Store Connect, Google Play | Publishing the organisation’s app in the app stores | Review contact (name, email, phone number), demo account and testers’ email addresses | United States | Separate controllers; their own terms and safeguards apply |
Destinations chosen and configured by the Organisation itself:
| Recipient | Purpose | Data received | Location | Transfer safeguard |
|---|---|---|---|---|
| Webhooks | Sending events to the addresses configured by the organisation | Names of leads and contacts, programme, stages and amounts | Chosen by the organisation | Instruction from the organisation, which itself provides the legal framework for this transfer |
| Public API | Access by the organisation’s systems to its own data using an API key | Complete lead records, including email addresses and phone numbers | Chosen by the organisation | Instruction from the organisation, which itself provides the legal framework for this transfer |
| AI assistant (MCP connector) | Consultation of the workspace by the AI assistant that an authorised user approves | Lead names, companies, stages and amounts, network directory; no email addresses, phone numbers or messages | Depends on the assistant’s provider, often in the United States | Instruction from the organisation; the chosen provider applies its own terms |
Reference sources
Official references used to keep this page up to date.