DPA / GDPR
DPA and GDPR Readiness
Draft summary of the data-processing items that must be finalized before Max AI is sold publicly.
Last updated: June 24, 2026
Legal review required before PROD
Draft for DEV validation only. This is not legal advice. Requires review and acceptance by a qualified lawyer before any PROD publication, checkout, onboarding, sales proposal, App Store submission or customer contract use.
Roles
MAXDATA APP LTD may act as a service provider or processor for workspace customer data, while workspace owners may act as controllers for the data they upload, connect or instruct Max AI to process.
MAXDATA APP LTD may also act as a controller for account administration, billing, support, security, abuse-prevention and product-operation data.
The final DPA must confirm the controller/processor roles for each customer segment and product surface.
DPA content needed
Before PROD sales, Max AI needs a lawyer-approved Data Processing Addendum covering processing instructions, subject matter, duration, nature and purpose of processing, data categories, data-subject categories, confidentiality, security, subprocessors, audits, deletion/return, breach notification and assistance with data-subject requests.
If data is transferred internationally, the DPA must include the appropriate UK/EU transfer mechanism, such as SCCs or UK IDTA where required.
Subprocessors and security
The final policy must list real subprocessors for hosting, database, authentication, AI providers, notifications, analytics, email, payment processing and support tooling.
A security appendix should describe access controls, encryption, backups, logging, incident response and workspace-level permission handling.
Customer instructions and end-user notices
Workspace owners should be responsible for ensuring they have a lawful basis and required notices for customer records, website visitors, inbox messages, social-channel data and uploaded files processed through Max AI.
Max AI should process workspace customer data only under customer instructions, the product configuration, the DPA and applicable law.
Breach and request support
The final DPA should define how Max AI notifies customers about personal-data breaches, what information is provided, and how Max AI assists with data-subject requests.
The final operational process should cover access, correction, export, deletion, objection, subprocessor deletion requests and backup retention windows.