ApplyDesk

Data processing addendum

Last updated 14 September 2026

This addendum sits with the ApplyDesk privacy policy when an Enterprise workspace owner accepts it in the dashboard. It describes how ApplyDesk processes applicant and staff personal data on behalf of that workspace. It is a practical processor terms sheet for UK GDPR and EU GDPR — not legal advice, and not a substitute for your own counsel.

1. Roles

The workspace (the community) is the controller of applicant submissions, staff membership records for that workspace, and any Discord messages it chooses to receive. ApplyDesk is the processor for that data. ApplyDesk is a separate controller for platform accounts, billing, and abuse prevention as described in the privacy policy.

2. Subject matter

ApplyDesk hosts the workspace portal, stores form answers and review decisions, sends transactional email you enable, and (if you connect the bot or webhooks) delivers application events to Discord or a URL you configure.

3. Duration

Processing lasts while the workspace exists, plus a short backup window on our host. You can delete the workspace at any time. Applicants and staff can also make a request at /privacy/request.

4. Nature and purpose

Storage, retrieval, display to authorised staff, optional Discord delivery, optional outbound webhooks, and export (CSV / JSON) so you can review applications and keep your own records.

5. Types of data

6. Instructions

We process this data only to provide ApplyDesk, to follow documented dashboard actions (approve, reject, export, erase), and to meet law. We will not sell it or use it for advertising.

7. Sub-processors

Hosting and file storage (Vercel), database (Postgres on our configured provider), email (Resend), payments (Stripe — billing identity only), identity and messaging (Discord) when you use those features. We will keep this list current on the privacy policy.

8. Security

Access to a workspace is limited to members you invite. Applicant portals are tenant-isolated by hostname. We use HTTPS, hashed session cookies, and signed webhook deliveries when you configure a secret.

9. Assistance

We will help you respond to data-subject requests that concern processor data we hold, including exports and erasure through the product and the public request form. Enterprise audit logs are available in the dashboard.

10. Deletion and return

Deleting a workspace removes its forms, applications, domains, and staff memberships from the live database. CSV export is available before you delete. Backups rotate on the host schedule.

11. International transfers

Infrastructure may be in the UK, EEA, or the United States depending on the providers above. Standard contractual clauses or equivalent safeguards apply where our providers offer them.

12. Acceptance

An Enterprise workspace owner accepts this addendum in Settings. We store the time and the accepting user. Either party may end processing by deleting the workspace or closing the ApplyDesk account.

Questions: use the data request form.