PRIVACY NOTICE
At APPSeCONNECT Corp. (“APPSeCONNECT”, “Company”, “Corporation”, “Us” or “We”), we respect and protect the privacy of visitors to our website: www.appse.ai, and any affiliated websites related to our product appse ai (collectively, the “Sites”), as well as our customers who use our AI-powered integration platform, tools, applications, and related services, together with the Sites (the “Service(s)”).
This Privacy Notice (“Notice”) specifically applies to the appse ai platform and explains how we collect, use, disclose, and protect information from visitors and customers (“Users”) as part of the Service. Any reference to your use of the Service in this Notice includes your visits and interactions with the Sites and Services, whether or not you are a registered user of the appse ai platform.
1. DEFINITIONS
1.1. GDPR KEY DEFINITIONS
- 1.1.1. “General Data Protection Regulation (GDPR)” refers to Regulation (EU) 2016/679 of the European Parliament and Council of 27 April 2016, which governs the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
- 1.1.2. “Consent” refers to a clear affirmative act that signifies a freely given, specific, informed, and unambiguous indication of the data subject’s agreement to the processing of personal data relating to them, such as by a written or electronic statement, or oral confirmation.
- 1.1.3. “Data Subject” refers to an identified or identifiable natural person whose personal data is collected, held, or otherwise processed. An identifiable person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, ID number, location data, or one or more physical, physiological, genetic, mental, economic, cultural, or social factors.
- 1.1.4. “Data Controller” refers to the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- 1.1.5. “Data Processor” refers to the natural or legal person, public authority, agency, or other body which processes personal data on behalf of the Data Controller.
- 1.1.6. “Legitimate Interest” refers to a legal basis under GDPR where personal data processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party, provided such interests are not overridden by the interests or fundamental rights and freedoms of the data subject.
- 1.1.7. “Online Identifier” refers to data such as internet protocol (IP) addresses, cookie identifiers, or other similar identifiers provided by devices, applications, tools, and protocols that may be used to identify an individual.
- 1.1.8. “Personal Data” refers to any information relating to an identified or identifiable natural person. Examples include, but are not limited to:
- (a) Name;
- (b) Email address;
- (c) Primary contact number;
- (d) IP address;
- (e) Location data;
- (f) Browser and device details; and
- (g) Online identifiers.
1.2. OTHER DEFINITIONS
- 1.2.1. “APPSeCONNECT” refers to APPSeCONNECT Corp., a company registered in the United States with its principal office at 4512 Legacy Dr Ste 100, Plano, TX 75024, including all successors, subsidiaries, acquirers, administrators, and executors. This Privacy Notice applies specifically to appse ai, including appse ai OEM, and any other current or future products, services, or offerings made available by APPSeCONNECT.
- 1.2.2. “Licensee” refers to any legal or natural person, including end-users, trial users, or partners, who have been granted a license by APPSeCONNECT to access and use the appse ai platform, either with or without consideration.
- 1.2.3. “Partner” refers to any third party, including but not limited to integration developers, resellers, implementation partners, or referral agents, who have been granted limited and specific licenses or authorizations by APPSeCONNECT to promote, develop, or integrate with the appse ai platform. Partners operate as independent contractors.
- 1.2.4. “Person” refers to:
- (a) a Natural Person, meaning a human being; or
- (b) a Legal/Juristic Person, meaning an entity created under law (e.g., a corporation or organization) which is recognized as having legal rights and responsibilities.
- 1.2.5. “Service Data” refers to any personal or business data submitted to APPSeCONNECT by a Licensee, User, or third-party Data Controller, for the purpose of availing the appse ai services. Service Data includes:
- (a) Prompts and user inputs;
- (b) AI-generated outputs;
- (c) Logs, usage metadata, and configuration files; or
- (d) Any third-party data received or processed by appse ai on behalf of a Data Controller.
- 1.2.6. “Websites” refers to all websites owned or operated by APPSeCONNECT, including but not limited to: www.appse.ai (relating to appse ai) or www.appseconnect.com (relating to the iPaaS platform APPSeCONNECT).
2. SCOPE OF PRIVACY NOTICE
- 2.1. This Privacy Notice applies to all users who visit or interact with the official websites operated by APPSeCONNECT Corp., including but not limited to the website of appse ai: www.appse.ai, as well as any Licensee or Partner who accesses or uses the appse ai platform, whether on a trial basis or as a paid customer.
- 2.2. This Notice governs the collection, use, and disclosure of personal data in connection with the browsing or interacting with any appse ai related websites; registering for or accessing the appse ai platform; submitting queries, participating in consultations, or engaging in any communications with us; and/or using our services or tools, whether free or paid.
- 2.3. This Privacy Notice is applicable specifically to the appse ai product and services, and to any associated tools, features, or brand elements explicitly linked to this Notice. In the absence of a product-specific privacy notice, this document shall apply by default & come into force.
- 2.4. Please note that certain legally enforceable privacy rights described herein such as those under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), or Canada’s PIPEDA may only be exercised by individuals who are citizens or residents of the jurisdictions where such laws apply.
- 2.5. Specifically, under the GDPR, rights are enforceable only with respect to the Personal Data of natural persons (i.e., human beings), and do not extend to legal entities such as corporations or partnerships.
- 2.6. By accessing or using the appse ai platform or associated websites, you agree to the terms of this Privacy Notice, which constitutes a legally binding agreement between you and APPSeCONNECT Corp., enforceable under applicable laws and regulations.
3. HOW DO WE COLLECT INFORMATION?
3.1. APPSeCONNECT Corp. collects personal and usage data when you interact with the appse ai platform, its associated websites including www.appse.ai, mobile applications, browser tools, or when you participate in our events, fill out forms, or communicate with us in any capacity. We act as a Data Controller for information collected through our own systems and as a Data Processor when acting on behalf of customers or third-party platforms. We collect personal data in the following ways:
- 3.1.1.1. Enquiries & Contact Requests — When you submit a query about appse ai or request information about our services or partnerships, we may collect your name, email address, phone number, IP address, company name, system environment, and location. This data is used to respond to your enquiries and provide relevant service information.
- 3.1.1.2. Account Registration and Subscription — When you create an account, subscribe to a service, or begin a free trial, we collect contact details, billing information, account credentials (such as usernames), and administrative contact information. This data is used for account management, license provisioning, billing, communication, and support.
- 3.1.1.3. Feedback and In-App Interactions — When you submit feedback from within the appse ai platform, we may collect your contact details and any associated comments, which may be used to improve the service or provide direct assistance.
- 3.1.1.4. Job Applications and Partner Forms — When you submit your application for a job or partnership opportunity, we may collect your name, contact details, resume, and other submitted materials. This data is used solely for evaluating and contacting candidates or partners.
3.1.1. Information You Provide Voluntarily:We collect personal data when you voluntarily provide it through the following means:
- 3.1.2.1. Technical Support — If you contact our support team, we may collect system logs, screenshots, chat transcripts, device and browser data, and other diagnostic information necessary to resolve the issue.
- 3.1.2.2. Service Conversations — Emails, chats, and calls with our representatives may be recorded and used for training, quality control, and improving support services.
3.1.2. Support and Communication Data: We collect information during customer support interactions to provide and improve services. Following are the different types of support and communication data collected:
3.1.3. Event Participation: When you register for or attend events (e.g., webinars, online demos, seminars), we may collect your name, email address, designation, and company details. This information may be used for follow-up communication, to share related content, or send service offers if you have consented.
- 3.1.4.1. Device and Usage Information — This may include your IP address, device type, browser type, location, referral URL, session data, and feature usage. We may use cookies, logs, and tracking technologies to understand user behavior and improve services.
- 3.1.4.2. Interaction Metrics — We collect data about user actions such as clicks, scrolls, conversions, drop-offs, and session heatmaps. This helps us optimize website performance and user journeys.
3.1.4. Automatically Collected Data: When you visit the appse ai websites or use the platform, certain data is automatically collected through technical means. Following are the different kinds of data collected:
3.1.5. Testimonials and Reviews: We may post user testimonials or reviews on our website (with your prior written consent). Where these include your Personal Data (e.g., name or job title), we will obtain your consent before publication. You can request removal at any time by contacting us at support@appseconnect.com.
3.1.6. Marketing and Communications: With your explicit consent, we may use your contact details to send you marketing communications, newsletters, product announcements, or offers related to our own services or those of our authorized partners. You may withdraw your consent at any time by clicking the unsubscribe link in the email or contacting us directly at support@appseconnect.com.
- 3.1.7.1. User Responsibility — We do not intentionally collect sensitive personal data (e.g., financial information, health data, government IDs). Users are responsible for ensuring that such data is not submitted, unless necessary and lawful.
- 3.1.7.2. AI Training Data — Inputs such as prompts, queries, or feedback submitted via appse ai may be retained and used to train or improve underlying AI models in a secure and anonymized manner. Where such use is based on your consent, you may withdraw that consent at any time by contacting us at legal@appseconnect.com. Withdrawal of consent will not affect the lawfulness of any processing carried out prior to withdrawal.
3.1.7. Sensitive Data and AI Training Inputs:
4. DO WE COLLECT CHILDREN’S PERSONAL DATA?
- 4.1. APPSeCONNECT does not knowingly collect or process Personal Data from individuals under the age of 18 years. If you are under 18 years of age, please do not submit any Personal Data through our websites, including www.appse.ai, or through any services offered by appse ai.
- 4.2. If we become aware that Personal Data has been collected from a child under 18 years of age without verified parental consent, we will take reasonable steps to delete such information and, where applicable, terminate the associated account from our systems.
- 4.3. If you believe that a child under 18 years may have submitted Personal Data to us, please contact us immediately at support@appseconnect.com, and we will promptly address the matter in accordance with applicable data protection laws.
5. DATA MINIMIZATION
5.1. APPSeCONNECT collects and processes Personal Data only to the extent necessary for the specific purposes described in this Privacy Notice and in accordance with Article 5(1)(c) of the GDPR. We ensure that Personal Data is adequate, relevant, and limited to what is required to provide our Services, fulfil contractual obligations, comply with legal requirements, and pursue legitimate business interests.
5.2. Where APPSeCONNECT acts as a Data Processor on behalf of its customers, the categories and scope of Personal Data processed are determined by the respective Data Controller, and we process such data strictly in accordance with documented instructions.
5.3. We implement appropriate technical and organizational measures to prevent the collection, use, or retention of excessive or unnecessary Personal Data and to ensure timely deletion or anonymization when data is no longer required.
6. INDIRECT COLLECTION
6.1. APPSeCONNECT primarily collects Personal Data directly from you through the channels described in this Privacy Notice. We do not ordinarily obtain Personal Data from third-party sources within the meaning of Article 14 GDPR. In the limited event that Personal Data is obtained indirectly, we will provide the required privacy information to the data subject within one (1) month of obtaining such data, or earlier where required by applicable law. Where we act as a Data Processor, Personal Data is provided to us by our customers in accordance with their documented instructions.
7. WHAT KIND OF INFORMATION DO WE COLLECT?
7.1. APPSeCONNECT Corp., through its appse ai platform, collects and processes different categories of information depending on the user’s role, the nature of the services used, and how the platform is accessed. These categories include:
- 7.1.1. Service Data (Processed on Behalf of Customers): As a business-to-business (B2B) integration platform, most of our customers are companies or legal entities. We collect and process Service Data that is submitted to appse ai by our customers during their use of the platform. For such data, APPSeCONNECT acts as a Data Processor, while the Customer remains the Data Controller. Service Data may include:
- 7.1.1.1. User and end-user identifiers such as names, email addresses, or IP addresses;
- 7.1.1.2. Integration-related metadata and logs;
- 7.1.1.3. API requests, system configurations, and usage patterns; or
- 7.1.1.4. Any other data submitted by the Customer through their account.
- 7.1.1.5. Note - We do not access or use this data except as required to provide the services; when responding to support requests; or as permitted or required by law. Customers are responsible for obtaining appropriate consents and complying with applicable data protection laws. We do not knowingly process sensitive personal data (such as health or financial data), and Customers are advised not to upload such information unless specifically agreed upon and lawfully permitted.
- 7.1.2. Business and Contractual Information: We also collect business-related information from Customer representatives and Partners to execute contracts, grant software licenses, or manage ongoing engagements. This information may include:
- 7.1.2.1. Name, job title, email address, and phone number;
- 7.1.2.2. Organization name and billing address; and
- 7.1.2.3. IP address or browser details at the time of sign-up.
- 7.1.2.4. Note - Such data is used for identification, communication, license management, billing, and administration. This information is not treated as Service Data and may be used internally to improve operations and ensure compliance with contractual obligations.
- 7.1.3. Aggregated and Anonymized Data: To enhance platform performance and understand user engagement, we analyze trends across our user base using aggregated and anonymized data. This data does not personally identify individuals and may be shared with affiliates or business partners; current or prospective customers; and for analytical, research, or marketing purposes. This processing is done in accordance with applicable laws and does not compromise the privacy of any individual.
8. THIRD-PARTY APPLICATIONS, INTEGRATIONS, AND ORGANIZATIONAL USE
8.1. appse ai enables Customers to integrate their accounts with various third-party applications, services, and platforms in order to automate workflows and exchange data between systems. When you choose to use these integrations, your use of third-party applications is subject to the following data protection practices:
8.1.1. Third-Party Application Integrations
- 8.1.1.1. Certain features of appse ai allow you to connect, authenticate, and transmit data to third-party applications. To enable these integrations, you may be required to log in to, authenticate with, or maintain active accounts on such third-party platforms.
- 8.1.1.2. By enabling an integration, you instruct APPSECONNECT and the relevant third-party application to exchange information to execute the workflows you have configured. For this purpose, appse ai may securely store limited authentication information (such as access tokens or credentials) strictly to maintain the integration and provide you with the Service.
- 8.1.1.3. The collection, use, storage, and disclosure of your data by any third-party application is governed solely by that application’s own privacy policy and terms. APPSECONNECT does not control and is not responsible for any third-party application’s data-handling practices. You acknowledge that APPSECONNECT shall not be liable for any loss or damage arising from the actions, omissions, or data practices of any third-party service you choose to integrate with appse ai.
8.1.2. Personal Data You Process Through appse ai
- 8.1.2.1. appse ai allows you to process, transmit, or disclose information, including Personal Data belonging to other individuals, through your workflows. You are solely responsible for ensuring that:
- (i) You have the legal right to collect, process, transmit, or disclose such Personal Data;
- (ii) Your own privacy policy accurately describes your data-processing practices;
- (iii) You have obtained all legally required notices, permissions, and consents; and
- (iv) Your processing of data complies with all applicable laws and regulations.
- 8.1.2.2. APPSeCONNECT acts only as a Data Processor for such data and processes it strictly according to your instructions and configuration settings. You acknowledge that you remain the Data Controller with respect to all Personal Data you submit or process through the platform.
8.1.3. Organizational Use and Administrative Control
- 8.1.3.1. appse ai is intended for use by organizations and their authorized personnel. Where an organization holds the primary or administrative account, that organization controls the configuration, access permissions, user roles, and processing activities within its account. Where supported, account administrators may delete, export, or manage account data directly through the available administrative tools.
9. COOKIES AND TRACKING TECHNOLOGIES
- 9.1. APPSeCONNECT Corp. uses cookies and similar tracking technologies on the appse ai platform and associated websites to provide a secure, functional, and personalized user experience.
- 9.2. We use the following categories of cookies:
- 9.2.1. Essential Cookies — These are strictly necessary for the operation of the platform, including user authentication, secure login, and navigation across core features.
- 9.2.2. Analytics Cookies — These help us understand how users interact with the platform by collecting usage data. Tools such as Google Analytics and Hotjar allow us to monitor traffic patterns, optimize performance, and improve user experience.
- 9.2.3. Marketing Cookies — Used for personalization and targeted advertising. These may include tracking technologies such as Meta Pixel or LinkedIn Insight Tag, which help us measure campaign effectiveness and display relevant ads to users across other platforms.
- 9.2.4. Functional Cookies — These remember your preferences and settings, such as selected language or user interface layout, to enhance your experience on future visits.
- 9.3. By continuing to use the appse ai platform, you consent to the use of cookies as described above. You may manage your cookie preferences through your browser settings or opt out of certain tracking mechanisms as outlined in our detailed Cookie Policy. To learn more about the types of cookies we use, how they work, and how you can control or disable them, please refer to our Cookie Policy.
10. HOW DO WE USE YOUR PERSONAL DATA AND OTHER INFORMATION
- 10.1. APPSeCONNECT Corp. does not sell or rent your Personal Data to any third party. We use the information you provide us with in accordance with this Privacy Notice and for the purposes for which it was collected.
- 10.2. If you provide Personal Data for specific reasons such as submitting an inquiry, requesting a demo, signing up for an account, or subscribing to a service, we will use that information solely to fulfill that request or provide the relevant services. For example: If you contact us via email or through a form on our website, we will use your contact details to respond to your inquiry or address your concern. If you register to use appse ai, we will process your Personal Data to create and manage your account, deliver services, and monitor usage for operational, security, and support purposes.
- 10.3. In addition, we may use your Personal Data and other non-personally identifiable data to:
- 10.3.1. Improve the content, performance, and usability of the appse ai platform and associated services;
- 10.3.2. Analyze user behavior and preferences to enhance user experience;
- 10.3.3. Conduct internal research and development; and
- 10.3.4. Provide tailored support, recommendations, and communications relevant to your usage patterns.
- 10.4. We may also use your information to send you marketing or promotional communications related to appse ai or other offerings from APPSeCONNECT that we believe may be of interest to you. If you receive such communications, you will have the ability to opt out at any time by following the unsubscribe instructions provided in the message. If you prefer not to receive future communications or wish to have your information removed from our mailing lists, you may also contact us directly at the details provided in the “Grievances” clause of this Notice.
- 10.5. Where APPSeCONNECT intends to process Personal Data for a purpose other than that for which it was originally collected, we will inform the data subject in advance of such new purpose and provide all relevant information required under Articles 13(3) and 14(4) GDPR. Such processing will only take place where there is a valid legal basis under applicable data protection law.
11. WHEN WE DISCLOSE YOUR PERSONAL DATA AND OTHER INFORMATION
11.1. APPSeCONNECT Corp. does not sell your Personal Data under any circumstances. We view your information as a valuable part of our relationship with you. However, there are limited situations where we may need to share your Personal Data with third parties, without additional notice, in accordance with applicable law and this Privacy Notice. These situations include:
- 11.1.1. Business Transfers: If APPSeCONNECT undergoes a corporate transaction such as a merger, acquisition, sale of assets, restructuring, or insolvency proceeding, Personal Data associated with appse ai may be transferred as part of that transaction. In such cases, we will ensure that the acquiring party is bound by obligations of confidentiality and data protection substantially similar to those set out in this Privacy Notice.
- 11.1.2. Legal Obligations and Enforcement: We may disclose your Personal Data where such disclosure is necessary to comply with applicable laws, regulations, or legal processes; respond to lawful requests by public authorities (e.g., courts, law enforcement); protect and defend the rights, property, or safety of APPSeCONNECT, our users, or the public; prevent or investigate potential fraud, abuse, or other violations of law; and enforce our contractual rights or respond to legal claims.
- 11.1.3. These disclosures are made in good faith and only when deemed necessary for legal or operational integrity.
12. WHAT IS OUR LEGAL BASIS FOR PROCESSING PERSONAL DATA?
12.1. If you are located in the European Economic Area (EEA), the United Kingdom, or any jurisdiction that recognizes lawful bases for data processing, APPSeCONNECT Corp. processes your Personal Data for the appse ai platform based on one or more of the following legal grounds, depending on the specific context in which the data is collected:
- 12.1.1. Performance of a Contract: We process Personal Data when it is necessary to enter into or fulfill a contract with you, for example, when you register for an appse ai account, use our services, or interact with our support team.
- 12.1.2. Legitimate Interests: We may process your Personal Data where it is in our legitimate interests to do so and where those interests are not overridden by your fundamental rights and freedoms. This includes activities such as improving the functionality of the appse ai platform, maintaining security, preventing fraud, and analyzing usage patterns.
- 12.1.3. Consent: In certain cases, we will rely on your explicit consent to process your Personal Data, for example, when sending you marketing communications, collecting analytics data, or using your inputs to train large language models (LLMs). You may withdraw your consent at any time by following the instructions provided in the communication or by contacting us directly.
- 12.1.4. Legal Obligation: We may process your Personal Data to comply with legal and regulatory obligations, such as tax reporting, audit requirements, or law enforcement requests.
- 12.1.5. Vital Interests: In rare situations, we may process your data to protect your vital interests or those of another natural person, particularly in matters related to safety or legal rights.
12.2. If we collect Personal Data from you in order to comply with a legal obligation or to perform a contract, we will make this clear at the point of collection and inform you whether the provision of the data is mandatory, along with the consequences of not providing it. If you have any questions about the legal basis on which your Personal Data is processed in relation to the appse ai platform, you may contact us at legal@appseconnect.com.
13. THIRD PARTY LINKS
- 13.1. The appse ai platform, website, or communications may contain links to third-party websites, applications, or services for your convenience and information. Please be aware that these external sites operate independently and may have their own privacy policies, terms of service, and data handling practices. We do not control, endorse, or assume responsibility for the content, practices, or policies of any third-party sites or services. Accessing such links is at your own discretion, and we encourage you to review the privacy policies and terms applicable to those third-party platforms before interacting with them. APPSeCONNECT shall not be liable for any loss or damage arising from your use of or reliance on any third-party resources.
14. HOW DO WE STORE AND SECURE YOUR PERSONAL DATA AND OTHER INFORMATION?
14.1. At APPSeCONNECT Corp., we take the security and privacy of your Personal Data seriously. The appse ai platform is built with modern security standards to protect your information from unauthorized access, misuse, loss, alteration, or disclosure. While no online service can guarantee absolute security, we implement a combination of technical, administrative, and organizational safeguards to minimize risk and ensure that your data remains protected.
14.2. Data Ownership and Confidentiality — You retain full ownership of the data you submit or store on the appse ai platform. We do not access, use, sell, or share your data with third parties except as required to deliver our services, comply with legal obligations, or as explicitly authorized by you. Your data will never be used by us to compete with your business or to market to your customers. Key security measures implemented include:
- 14.2.1. Data Encryption:AES-256 encryption is applied to data at rest. All data in transit is encrypted using HTTPS with TLS 1.2 or higher. Client-side encryption is enabled via HTTPS or SMB 3.0.
- 14.2.2. Authentication and Access Controls: Two-factor authentication (2FA) is required for user access to the appse ai product portal. Role-based access control (RBAC) is enforced to ensure that only authorized personnel can access data. Access to Personal Data is restricted to APPSeCONNECT employees, contractors, or partners who need it to perform their duties and are bound by confidentiality agreements.
- 14.2.3. Platform and Infrastructure Security: Code signing certificates are used to validate the integrity and authenticity of our software. The appse ai platform is hosted on secure cloud infrastructure with regular vulnerability assessments and patch management. Industry-standard SSL/TLS (2048-bit SSL v3 or higher) secures all communication between users and the website.
- 14.2.4. Internal Security Practices: Our personnel are trained in data privacy and information security protocols. We conduct routine reviews of our data handling, processing, and physical security practices. Breach response procedures are in place to detect, respond to, and mitigate any potential incidents.
- 14.2.5. Data Transfers — Where required for contractual obligations or operational efficiency, your Personal Data may be transferred to and processed in countries outside your country of residence or economic zone, including India and the United States. All such transfers are carried out in accordance with applicable data protection law, including Chapter V of the GDPR where applicable. Where Personal Data is transferred from the EEA or the United Kingdom to a country not recognized as providing an adequate level of protection, APPSeCONNECT ensures that appropriate safeguards are in place, including the use of Standard Contractual Clauses as approved by the European Commission under Article 46(2)(c) of the GDPR, or the UK International Data Transfer Addendum where applicable. Copies of the relevant safeguards may be obtained by contacting us at legal@appseconnect.com.
15. HOW LONG DO WE RETAIN YOUR DATA?
- 15.1. We retain your Personal Data for as long as your appse ai account remains active or as necessary to provide you with access to our services. Once your subscription is suspended, terminated, or expires, we will retain your data for an additional period of three (3) months, unless you request earlier deletion.
- 15.2. In certain circumstances, we may retain your information beyond this period if:
- (i) It is required to comply with applicable legal or regulatory obligations;
- (ii) It is necessary to resolve ongoing disputes or claims;
- (iii) It is needed to enforce our contractual rights or agreements; or
- (iv) It is required for audit, tax, or compliance purposes.
16. WHAT RIGHTS DO YOU HAVE?
- 16.1. At APPSeCONNECT Corp., we respect your data protection rights under applicable laws including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the Personal Information Protection and Electronic Documents Act (PIPEDA), and other relevant global regulations. These rights apply to your Personal Data collected via the appse ai platform, whether you are a customer, user, partner, or visitor. If you wish to exercise any of these rights, you may fill out and submit a Data Subject Access Request Form or contact us at legal@appseconnect.com. These rights are applicable only to natural persons and personally identifiable data.
- 16.2. Right to Access. You have the right to request access to your Personal Data stored by us, including (i) a copy of the data we hold about you; (ii) the purposes for which it is processed; (iii) the categories of data processed; (iv) the recipients or categories of recipients to whom the data is disclosed; and (v) the duration for which your data is retained.
- 16.3. Right to Rectification. If you believe that any Personal Data we hold about you is inaccurate or incomplete, you can request that we update or correct it.
- 16.4. Right to Erasure / Right to Be Forgotten. You may request the deletion of your Personal Data where (i) the data is no longer necessary for the purpose for which it was collected; (ii) you withdraw consent and there is no other legal basis for processing; and (iii) the data has been unlawfully processed. Note: Deletion of user data does not affect business or organization-level content created during your use of the platform (e.g., workflows, support tickets, documentation). We may also retain certain data as required for legal, regulatory, or operational purposes.
- 16.5. Right to Restrict Processing. You can request that we restrict processing of your data in certain circumstances, such as (i) when you contest the accuracy of the data; (ii) if the processing is unlawful but you oppose deletion; and (iii) if you need the data for legal claims after we no longer require it.
- 16.6. Right to Object. You have the right to object to processing based on legitimate interests, particularly for (i) direct marketing purposes (which we will cease upon request); and (ii) profiling or data analytics activities without explicit consent. Note: We will assess your objection and, unless we demonstrate compelling legitimate grounds, we will cease processing.
- 16.7. Right to Data Portability. You have the right to request that your Personal Data be provided to you in a structured, commonly used, machine-readable format and, where feasible, transmitted to another controller.
- 16.8. Right to Control Data Sharing. You may control how and with whom your Personal Data is shared. We share Personal Data with your explicit consent; to fulfill contractual obligations (e.g., with service providers, processors, or partners); when required by law or in response to valid legal requests; and during business transitions (e.g., mergers or acquisitions) with proper notification.
- 16.9. DSAR Response Timelines and Extension. APPSeCONNECT shall respond to a valid DSAR within one (1) calendar month of receipt. Where a request is complex or numerous, this period may be extended by a further two (2) months (maximum three (3) months in total). The data subject shall be notified of any such extension, including the reasons for the delay, within one (1) month of receipt of the original request.
- 16.10. DSAR Refusal. Where APPSeCONNECT is unable or declines to act on a DSAR, it shall notify the data subject in writing within one (1) calendar month of receipt, stating: (i) the reasons for non-action or refusal; (ii) the data subject’s right to lodge a complaint with the competent supervisory authority; and (iii) the data subject’s right to seek judicial remedy.
- 16.11. No Fee. Responses to DSARs are provided free of charge. Where a request is manifestly unfounded or excessive (in particular due to its repetitive nature), APPSeCONNECT may charge a reasonable administrative fee or decline to act. In such cases, APPSeCONNECT shall notify the data subject accordingly and bears the burden of demonstrating the manifestly unfounded or excessive character of the request.
- 16.12. Rights of Users Outside the EEA. Users located outside the European Economic Area, including those in the United States (California) and Canada, may exercise equivalent privacy rights applicable under their respective local laws, including the CCPA and PIPEDA, by submitting a request via the Data Subject Access Request Form or by contacting us at legal@appseconnect.com. We will respond to all such requests in a manner consistent with the applicable local law and within a reasonable timeframe.
- 16.13. If you believe that your data protection rights under applicable laws have been violated or that your request has not been addressed in accordance with this Privacy Notice, you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction. We encourage you to first contact us at legal@appseconnect.com so we can attempt to address your concerns directly and promptly. If you believe a specific right under your national or regional data protection law is not listed here, please reach out to us at legal@appseconnect.com and we will address your concerns promptly.
17. PROCESSING OF DATA THROUGH THE appse ai IN-APP LLM
17.1. The appse ai platform includes an optional feature referred to as the appse ai LLM, which enables AI-powered actions within workflows (including text generation, summarization, validation, interpretation, and similar functionalities). The appse ai LLM is not an APPSeCONNECT-built model. Instead, the feature operates by transmitting user-provided inputs to one or more third-party large language model (LLM) providers engaged under backend enterprise subscriptions.
17.2. When you choose to use the appse ai LLM, certain data that you provide within workflows, including prompts, workflow variables, context, text inputs, or other content submitted to the AI agent node may be transmitted to external third-party LLM systems solely for the purpose of generating an AI output. These third-party LLM providers process such data under their own terms, privacy policies, and data-handling practices.
17.3. APPSeCONNECT does not control or dictate how these third-party LLM providers store, retain, secure, or otherwise process data once it is transmitted for inference. Their processing activities are governed by their respective privacy policies, and we encourage users to review those policies before choosing to use the appse ai LLM. Use of the appse ai LLM is entirely optional. If you do not wish for your data to be processed by external LLM providers, you may opt out and instead connect your own API key for your preferred LLM provider, in which case your data will flow directly between you and that external provider and will not be routed through appse ai LLM infrastructure.
17.4. By enabling and using the appse ai LLM, you acknowledge and agree that your data may be transmitted to third-party LLM providers for processing; such processing is subject to those providers’ independent privacy and security practices; and APPSeCONNECT cannot assume responsibility for the data protection measures of third-party LLM vendors. If you do not agree to this processing activity, you should refrain from using the appse ai LLM and instead utilize your own externally managed LLM credentials.
18. MODIFICATION
- 18.1. We may update this Privacy Notice from time to time. All changes will be posted on this page and will become effective upon publication, unless stated otherwise. For material changes, we will notify you at least 30 days in advance through either a notice on the appse ai website; or email (if you are a registered Licensee or Partner). Your continued use of appse ai after any changes are posted will be deemed acceptance of those changes. If you do not agree with the revised terms, you may stop using the platform and services.
- 18.2. Please note, changes to the cookie list may be made without prior notice to keep it accurate and current.
- 18.3. Where APPSeCONNECT intends to process your Personal Data for a purpose other than that for which it was originally collected, you will be informed of the new purpose and the applicable legal basis before such processing begins, in accordance with Article 13(3) and Article 14(4) of the GDPR. Where consent is the applicable legal basis, fresh consent shall be sought prior to processing.
19. GRIEVANCES
19.1. you face any difficulty in availing any of the data control features, need assistance with filling the DSAR form, have questions regarding this Notice, or have any other related grievances, you may reach to our Privacy Grievance Officer:
- Name: Bikramjit Chatterji
- Email: legal@appseconnect.com