Legal
Data Processing Addendum
Last updated 13 August 2026
This Addendum applies where CDrop LLC, a limited liability company registered in the State of Wyoming, United States processes personal data on behalf of a developer, and forms part of the Developer Terms. It takes effect automatically when you fund a campaign; no signature is needed.
If your organisation needs a countersigned copy or its own paper, email privacy@testfi.app.
01Who is controller, and for what
You are the controller and we are your processor for personal data you put into the platform: your campaign content, scenarios, test credentials, and any personal data contained in the app you ask testers to use.
We are an independent controller for tester accounts, tester identity and payout data, session scoring, fraud prevention, and platform operation. You do not instruct us on any of that, and this Addendum does not give you rights over it. Our processing as controller is described in the Privacy Policy.
A tester's recording is delivered to you as part of what you bought. Once you hold it, you decide what you do with it, and for that you are a controller in your own right, subject to clause 8 of the Developer Terms.
02Subject matter, duration, nature and purpose
Subject matter and purpose: running the testing campaigns you order.
Duration: for as long as you have an account, plus the retention periods in the Privacy Policy.
Categories of data subject: testers who take your campaigns, and any individual whose data you place in your app or scenario.
Categories of personal data: session submissions, recordings, transcripts, answers, and whatever you choose to include in campaign content.
03Our obligations
We will:
- process your personal data only on your documented instructions, which the Developer Terms and your use of the product constitute, unless the law requires otherwise, in which case we tell you first unless prohibited
- ensure people authorised to process it are bound by confidentiality
- apply appropriate technical and organisational security measures, described in clause 5
- help you respond to data subject requests, and with your data protection impact assessments and consultations, taking into account what we know and can see
- tell you without undue delay after becoming aware of a personal data breach affecting your data
- delete or return your personal data at the end of the service, subject to legal retention
- make available the information needed to show compliance, and allow audits under clause 7
If we think an instruction breaches data protection law, we will tell you.
04Your obligations
You confirm you have a lawful basis for the personal data you place in campaign content, that you have given any notices and obtained any consents required, and that your scenarios comply with the Acceptable Use Policy. Do not put production customer data, special category data, or children's data into a test.
05Security measures
Encryption in transit, encryption at rest for sensitive fields using AES-256-GCM, row level security so one account cannot read another's records, authenticated and restricted production access, time limited links for recordings rather than public URLs, and scheduled deletion of recordings on the retention timetable published in the Privacy Policy.
06Subprocessors
You give general authorisation for us to engage subprocessors. The current list is at testfi.app/subprocessors. We impose data protection obligations on each of them no less protective than these, and we remain liable for their performance. Ask at privacy@testfi.app to be notified in advance of additions, and you may object on reasonable data protection grounds, in which case we will work with you or you may stop using the affected part of the service.
07Audit
On reasonable written notice, not more than once a year unless a regulator requires otherwise or there has been a breach, we will provide the information reasonably needed to verify our compliance with this Addendum. Where the information is not enough, we will cooperate with an audit conducted at your cost and in a way that does not disrupt the platform or compromise the confidentiality of other customers or testers.
08International transfers
Where this Addendum involves transferring personal data out of the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, the European Commission Standard Contractual Clauses apply, with the UK Addendum or International Data Transfer Agreement where the transfer is from the United Kingdom, and are incorporated here by reference. Data may be processed in the United States and accessed from Türkiye.
09Liability and precedence
Liability under this Addendum is subject to the limitations in the Developer Terms. If this Addendum conflicts with the Developer Terms on the processing of personal data, this Addendum wins. If it conflicts with the Standard Contractual Clauses, the Clauses win.