Parties and roles
This addendum forms part of the Terms between Snaply and the customer and applies on every plan, free included. The customer is the controller of its app users’ personal data (or a processor for its own client) and Snaply processes it on the customer’s behalf. Under the Armenian Law on Protection of Personal Data, the customer is the data processor and Snaply acts as its authorised person.
What is processed
Data subjects: the people using the customer’s apps and the customer’s own team. Data: device details, the device identifier, identity the app passes (user ID, name, phone), support codes, app sessions, consent-log entries, and screenshots, saved live frames and recordings with annotations. Purpose: providing the service the customer uses, for as long as the Terms are in force and until deletion under this addendum. Special-category data is not meant to be processed; the customer must mask any screen that can show it.
Instructions
Snaply processes the data only on the customer’s documented instructions: the Terms, the settings chosen in the product and the customer’s API calls. If we believe an instruction breaks the law, we tell the customer and may refuse it.
Our people
Everyone at Snaply with access is bound by confidentiality, has only the access their role needs, and is logged when they use it. Snaply’s staff tools have no access to capture content and no one analyses it. Only the infrastructure administrators who run the servers could technically reach stored captures, and they do not do so except to operate the service.
Security measures
Captures and recordings encrypted at rest (server-side AES-256-GCM); backups encrypted (GPG AES-256); traffic between users and the service encrypted in transit (TLS 1.2+); per-workspace isolation; least-privilege access with audit logging; two-factor sign-in; masking on the device before frames are encoded; live view relayed in memory and not stored; automatic deletion on the retention schedule; nightly encrypted backups kept for 14 days; and a signed, tamper-evident consent log. We review these measures and may improve them, but will not reduce the overall level of protection.
Sub-processors
Telecom Armenia OJSC (hosting) and Google Workspace (transactional email). Payment processors are not on this list: they process Snaply’s own billing with the customer, not app users’ data. We give 30 days’ notice before adding or changing a sub-processor, bind each one to obligations no weaker than these, and remain responsible for them. The customer may object on reasonable data-protection grounds; if we cannot resolve it, the customer may end the affected service and receive a refund of fees prepaid for the remaining period. DNS and certificate providers (GoDaddy and Let’s Encrypt) see only the domain name and never customer personal data, so they are not sub-processors.
International transfers
Data is hosted in the Republic of Armenia. Snaply transfers it outside Armenia only where the Armenian Law on Protection of Personal Data allows, with the safeguards it requires; data that comes from other countries is transferred with the safeguards their laws require (see European data and US and other laws below). Snaply does not store data in the Russian Federation; the customer must not use the service where Russian data-localisation rules require the personal data of Russian citizens to be stored there.
European data
Where the GDPR or UK GDPR applies, this addendum is the contract Article 28 requires. Armenia has no EU adequacy decision, so transfers of personal data from the EEA to Snaply are made under the EU Standard Contractual Clauses (Commission Decision 2021/914), Module 2 where the customer is a controller and Module 3 where it is a processor, incorporated by reference: Clause 7 included; Clause 9 option 2, with 30 days’ notice; the optional wording in Clause 11 omitted; Clauses 17 and 18 the law and courts of Ireland; the annexes are What is processed (Annex I, with the customer as data exporter and Snaply as data importer), Security measures (Annex II) and Sub-processors (Annex III) above. The competent supervisory authority is that of the Member State where the customer or its representative is established, and otherwise the Irish Data Protection Commission. Transfers from the UK use the UK International Data Transfer Addendum; transfers from Switzerland use the clauses as adapted for the Swiss FADP.
US and other laws
Where the California Consumer Privacy Act or another US state privacy law applies, Snaply is a service provider and processor: it does not sell or share the personal information; does not keep, use or disclose it outside the direct business relationship with the customer or for any purpose other than the service; does not combine it with data from other sources except as that law allows; and tells the customer if it can no longer meet these duties, so the customer can take reasonable steps to stop unauthorised use. Where another law applies, such as Brazil’s LGPD, Canada’s PIPEDA, India’s DPDP Act, Singapore’s PDPA or Australia’s Privacy Act, Snaply gives the same protections and accepts any further terms that law requires of a processor.
Personal data breaches
We notify the customer without undue delay, and in any case within 72 hours of becoming aware of a breach affecting its data, with what we know: what happened, the data and people affected, likely consequences, and what we are doing. We update the customer as we learn more and help it meet its own notification duties.
Assistance
The dashboard lets the customer answer data-subject requests itself: delete a user’s data, export the consent log, and set retention. Beyond that, we help with requests, data-protection impact assessments and questions from authorities as far as reasonably possible; substantial extra work may be charged at reasonable cost.
Audits
On request we provide the information needed to show compliance with this addendum. The customer, or an independent auditor bound by confidentiality, may audit once a year, after 30 days’ notice, during business hours and at the customer’s cost, or at any time after a breach affecting its data.
Deletion and return
Captures and recordings are erased on the retention schedule. Ask us to erase your data, or close your account, and we delete it within 30 days. A deletion request for an app user erases that user’s captures, recordings and device records; the consent log keeps its earlier entries as proof of consent, as described in the Privacy policy. Backups made before a deletion are overwritten within 14 days, and if we restore a backup we repeat the deletions made since. If we end your access for breach of the Terms, that is not a deletion: your data is kept and can be exported, and we erase it when you ask, and in any case no later than 12 months after termination, except where the law requires us to keep it. The consent log can be exported at any time as audit evidence.
Customer obligations
The customer confirms it has a lawful basis and any required consent for every capture, gives app users the notices the law requires, masks sensitive screens, does not send data the Terms exclude, and registers or notifies its processing with the authorities where the law requires it, including with the Armenian Personal Data Protection Agency.
Liability and precedence
Liability under this addendum is subject to the limits in the Terms, but nothing limits the rights of data subjects or either party’s liability to them. On personal data, this addendum prevails over the Terms; a signed agreement prevails over both.