GDPR Data Controller Notice
Effective date: 19 June 2026 • Applicable to: EU/EEA data subjects (Germany, France, Spain)
1. Who we are
This notice is issued by:
Company Applify, Inc.
Trading as Missioned by Applify
Website applify.co / missioned.ai
Role Data Controller (for outbound marketing communications)
Privacy contact support@missioned.ai
Address Applify, Inc., 600 Stewart St, Ste 400, Seattle, WA 98101, United States
2. Why you received this communication
You have received an outbound email from Applify, Inc. (trading as Missioned by Applify) regarding mandatory AWS compliance requirements (Partner Central Migration and Partner Revenue Measurement) that apply to AWS partner accounts.
We are contacting you in your professional capacity as a representative of an AWS partner organisation. We believe this information is directly relevant to your role and to the continued operation of your organisation's AWS partner account.
3. Where we obtained your data
Your contact information was obtained from Apollo.io, a third-party B2B data intelligence platform. Apollo.io collects and maintains professional contact data from publicly available sources, including company websites, professional directories, and publicly accessible business profiles.
Apollo.io operates in compliance with GDPR and maintains records of processing for EU data subjects. Their privacy policy is available at apollo.io/privacy-policy.
The data we hold about you is limited to:
• Your professional name and job title
• Your business email address
• Your employer's company name and website domain
• Your geographic region (country)
4. Lawful basis for processing
We rely on Legitimate Interests (Article 6(1)(f) of the GDPR) as our lawful basis for processing your personal data and sending you this communication.
Legitimate Interests Assessment (summary)
Purpose: To inform AWS partner contacts of mandatory compliance deadlines (PCM and PRM) that directly affect their organisation's co-sell access, Marketplace operations, and AWS funding eligibility.
Necessity: Direct email contact is necessary because AWS does not proactively notify all affected partners through automated channels, and missing the deadline results in immediate, material operational consequences.
Balancing test: The communication is limited to professional contact data, sent to individuals in their business capacity, about a matter directly relevant to their professional role. It does not involve sensitive personal data, personal life, or consumer contexts. The impact on the individual's privacy interests is minimal relative to the legitimate business and operational interest being served.
Safeguards: Every email includes a clear unsubscribe mechanism. Opt-out requests are honoured immediately. We do not share recipient data with third parties for any purpose.
5. How we use your data
We use your contact information solely for the following purposes:
• To send you information about mandatory AWS compliance requirements (PCM and PRM) that apply to your organisation's AWS partner account
• To follow up on that communication if you have previously engaged with it (opened, clicked, or replied)
• To process any inquiry, form submission, or meeting booking you initiate in response to our communications
• To maintain a suppression record if you unsubscribe, to ensure we do not contact you again
We do not use your data for advertising, profiling, automated decision-making, or any purpose unrelated to AWS partner compliance communications.
6. Data sharing
We do not sell, rent, or disclose your personal data to third parties, except in the following limited circumstances:
• Salesforce Marketing Cloud (SFMC): used as our email delivery platform. SFMC processes data as a data processor on our behalf under a Data Processing Agreement.
• Apollo.io: we obtained your data from Apollo.io. We do not share data back to Apollo.io.
• Legal obligations: if required by law, court order, or supervisory authority.
All processors are contractually bound to process data only on our documented instructions and in accordance with GDPR requirements.
7. How long we keep your data
We retain your contact information for a maximum of 12 months from the date of first contact, unless:
• You unsubscribe or object to processing, in which case we delete your contact data within 30 days and retain only a suppression record (your email address and opt-out date) to prevent future contact.
• You enter into a business relationship with Applify, in which case our standard client data retention terms apply.
• Applicable law requires a longer retention period for specific records.
8. Your rights under GDPR
As an EU data subject, you have the following rights in relation to your personal data.
What it means:
Access Request a copy of the personal data we hold about you.
Rectification Ask us to correct any inaccurate or incomplete data.
Erasure Request deletion of your personal data. We will comply within 30 days and confirm in writing.
Restriction Ask us to limit how we use your data while a dispute is resolved. Receive your data in a structured, machine-readable format.
Object to processing based on legitimate interests. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.
Withdraw consent Not applicable here as we rely on legitimate interests, not consent. However, you may object at any time using the contact details below.
To exercise any of these rights, contact us at support@missioned.ai. We will respond within 30 days.
You also have the right to lodge a complaint with your national supervisory authority:
• Germany: Bundesbeauftragter fur den Datenschutz und die Informationsfreiheit (BfDI) — bfdi.bund.de
• France: Commission Nationale de l'Informatique et des Libertes (CNIL) — cnil.fr
• Spain: Agencia Espanola de Proteccion de Datos (AEPD) — aepd.es
9. International data transfers
Applify, Inc. is incorporated and headquartered in the United States. By processing your data, we transfer it from the EU/EEA to the United States. We rely on Standard Contractual Clauses (SCCs) as approved by the European Commission (Decision 2021/914) as the transfer mechanism for all EU-to-US data transfers. A copy of the applicable SCCs is available upon request at support@missioned.ai.
Our email delivery sub-processor (Salesforce Marketing Cloud) also transfers data to the US and operates under its own SCCs and DPA, details of which are available at salesforce.com/privacy.
10. Contact and opt-out
To unsubscribe from our communications, object to processing, or exercise any other right, you may:
• Click the unsubscribe link in any email we send you
• Email us at support@missioned.ai with the subject line & GDPR opt-out &; or &;Data deletionrequest &;
• Write to us at: Applify, Inc., 600 Stewart St, Ste 400, Seattle, WA 98101, United States
All opt-out requests are processed within 30 days. Unsubscribe requests actioned via email link are processed immediately and you will receive no further communications from us.
This notice covers outbound marketing and compliance communications only and does not govern data processed within the Missioned platform. For platform data processing, refer to the Missioned Platform Privacy Policy at missioned.ai/privacy.
