DPA / GDPR
DPA and GDPR Readiness
Owner-selected data-processing position and the items still requiring a final DPA and professional approval.
Last updated: August 27, 2026
Legal review required before PROD
Draft for DEV validation only. This is not legal advice. Requires review and acceptance by a qualified lawyer before any PROD publication, checkout, onboarding, sales proposal, App Store submission or customer contract use.
Roles
MAXDATA APP LTD is selected as processor for workspace customer data, while workspace customers act as controllers for data they upload, connect or instruct Max AI to process.
MAXDATA APP LTD is selected as controller for account administration, billing, support, security and abuse-prevention data.
The final DPA and privacy notices must confirm these roles for each product surface and supported customer country.
DPA content needed
Before PROD sales, Max AI needs a lawyer-approved Article 28 Data Processing Addendum covering processing instructions, subject matter, duration, nature and purpose, data categories, data subjects, confidentiality, security, subprocessors, audits, deletion/return, breach notification and assistance with data-subject requests.
If data is transferred internationally, the DPA must include the appropriate UK/EU transfer mechanism, such as SCCs or UK IDTA where required.
Subprocessors and security
The final policy must publish the real subprocessors for hosting, database, authentication, AI providers, notifications, analytics, email, payment processing and support tooling. The selected change policy is 30 days' advance notice with a right to reasoned objection.
A security appendix should describe access controls, encryption, backups, logging, incident response and workspace-level permission handling.
Customer instructions and end-user notices
Workspace owners should be responsible for ensuring they have a lawful basis and required notices for customer records, website visitors, inbox messages, social-channel data and uploaded files processed through Max AI.
Max AI should process workspace customer data only under customer instructions, the product configuration, the DPA and applicable law.
Breach and request support
The selected DSAR process acknowledges a request within 5 business days and assists the customer without undue delay; the final DPA must define breach notices and exact operational responsibilities.
The final operational process should cover access, correction, export, deletion, objection, subprocessor deletion requests and backup retention windows.