Privacy Policy

v.4.4, effective 25 August 2026. Replaces v.3.0 of 12.02.2020.

HiTech Service LLC (hereinafter referred to as “we”, “our”, “us” or the “Company”) is a US based company with the address registered at 900 Foulk Rd, Suite 201, Wilmington, DE, USA, 19803. The Company operates the Approval Studio website at https://approval.studio/ (the “Website”) and the Approval Studio web application at https://app.approval.studio/ (the “Web Application”), together with the Approval Studio companion applications for iOS and Android, the ExpressReview application for web, iOS and Android (“ExpressReview”), and the plugins, extensions, application programming interfaces and integrations we make available (the “Integrations”). These are referred to together as the “Services”.

1. Introduction

This Policy provides an overview on how our Company protects the personal data and privacy of individuals who visit our Website, Web Application and applications (hereinafter referred to as “Visitors and Users”), who register to use our products and services, and of people who take part in a review without registering (see Section 6).

The Company is committed to protecting your privacy and handling your data in an open and transparent manner and in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”) and the relevant data protection legislation which is applicable in the United States of America.

2. Definitions

  • Controller – the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processor – a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
  • Personal data – any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • Data Protection Officer (DPO) – a person appointed by the Company that takes formal responsibility for data protection compliance within an organization.
  • Data Protection Authority – an independent public authority that is legally tasked with overseeing compliance with applicable data protection laws.
  • Content – the files, images, documents and other material a User uploads to the Services for review.
  • Reviewer – a person who opens a review link and comments on or decides upon Content without registering an account.

3. Who we are and how to contact us

HiTech Service LLC is the Controller of the personal data described in this Policy.

4. What personal data we collect

We only collect basic personal data about Visitors and Users. The categories below describe everything we hold; who receives it is set out in Section 8 and how long we keep it in Section 11.

  • Account and authentication data – email address, password (stored only as a one-way hash), first and last name, location. Where you sign in with Google, we receive your email address, a verified flag and a Google account identifier; we send nothing to Google. Enterprise customers may instead sign in through Okta, in which case we receive the identity details their Okta configuration releases to us.
  • Support data – your name, email address and the content of chat messages and support tickets you send us.
  • Demo requests – name and email address.
  • Marketing data – email address and name, where you have subscribed.
  • Security and anti-fraud data – IP address and browser identification.
  • Activity data – records of uploads, versions, comments, decisions and deletions, and the time of your last activity.
  • Consent records – the fact, date and version of your acceptance of our Terms and this Policy, together with the IP address and browser identification present at the time.
  • Billing and organisation data – for Approval Studio Platform accounts: your company name, billing address, country, postal code, city and telephone number, the administrator’s email address, your VAT number where you provide one, and your plan, payment status and subscription status. Card payments are entered with and processed by Stripe; we do not receive or store your card details.
  • AppSumo purchases – where you purchased a lifetime deal through AppSumo, the purchase is processed by AppSumo. We receive only the email address you registered with and your licence details.
  • Subscription data – for ExpressReview, the store you purchased from, the product and the renewal dates, and the billing email address returned to us by our billing provider. We never receive or hold your card details.
  • Device push tokens – where you use the mobile applications and enable notifications.
  • Reviewer contact data – where a User invites a Reviewer by email, that email address, together with the Reviewer’s name, comments and decisions. See Section 6.
  • Address book contacts – on plans that include the address book, the names, email addresses and groups you save so that you can reuse them when inviting reviewers. These are contact details of other people, which you provide to us and control.
  • API credentials – where your plan includes API access, the key issued to your account.
  • Analytics and cookie data – information about the devices and networks you use to reach the Services, as described in Section 15.

5. Why we process your data, and our legal basis

PurposeData usedLegal basis
Creating and running your account; authenticationAccount and authentication dataPerformance of a contract, Art. 6(1)(b)
Providing the review service; storing, processing and displaying ContentContent, activity dataPerformance of a contract, Art. 6(1)(b)
Customer support, tickets and chatSupport dataPerformance of a contract, Art. 6(1)(b)
Billing, subscriptions and entitlement checksBilling and organisation data; subscription dataContract, Art. 6(1)(b); legal obligation for tax and accounting records, Art. 6(1)(c)
Security monitoring, anti-fraud, rate limitingIP address, browser identificationLegitimate interests, Art. 6(1)(f) — keeping the Services secure and available
Diagnostics and error investigationRoute, error detail, account identifierLegitimate interests, Art. 6(1)(f) — operating a reliable service
Administrative audit recordsAdministrator and affected account email addresses, action takenLegitimate interests, Art. 6(1)(f), and legal obligation, Art. 6(1)(c)
Evidencing your acceptance of our Terms and this PolicyConsent recordsLegal obligation, Art. 6(1)(c), read with Art. 5(2) and 7(1)
Marketing emails, news and offersMarketing dataConsent, Art. 6(1)(a), withdrawable at any time
Website and product analyticsAnalytics and cookie dataConsent, Art. 6(1)(a), given through the cookie banner
Notifying you of review activity on your filesPush token, reviewer name, file namePerformance of a contract, Art. 6(1)(b)
Recording who reviewed Content and what they decidedReviewer name or email address, annotations, decisionsLegitimate interests, Art. 6(1)(f) — see Section 6

We do not use automated decision-making policies, including profiling. Our AI features assist you in working with Content; they do not make decisions about you, and they do not profile Users.

6. People who review Content without an account

Both the Approval Studio Platform and ExpressReview allow a User to send Content out for review to someone who does not hold an account with us. A person who reviews Content in this way — a Reviewer — can view it, comment on it, and approve or reject it without registering.

There are two ways a Reviewer can be given access, and they differ in what we hold about them.

6.1 Review by shared link

  • A User can generate a link and send it to anyone through their own channels. Before commenting, the Reviewer is asked to introduce themselves and type a name.
  • We collect that name, together with the Reviewer’s comments and any approve or reject decision. We do not collect or verify an email address, and we hold no means of contacting the Reviewer.
  • Access is controlled solely by possession of the link. The User decides who receives it, and neither the User nor we have any control over onward forwarding.
  • A new link is generated each time a new version of a file is uploaded, and the previous link ceases to give access.

6.2 Review by email invitation

  • Where a User invites a Reviewer by entering their email address, we collect and store that email address. It is used as the Reviewer’s identity: comments and decisions are recorded against it in the file’s history and audit records.
  • That email address is visible to the User’s colleagues who have access to the project. There is currently no setting that hides a Reviewer’s email address from a User’s team.
  • We use the address to send the review invitation, and, where the User has enabled it, to notify the Reviewer when a new version is uploaded.
  • If an invitation email is forwarded and the recipient reviews the Content using the forwarded link, the comments and the decision are recorded against the person originally invited, because the Services cannot detect that the email was passed on. An entry in the history may therefore name someone who did not make that decision.

6.3 Reviewers generally

  • A Reviewer does not enter into an agreement with us and has no account with us. Any information a Reviewer provides is processed so that the User who requested the review can see who responded and what they decided.
  • A Reviewer’s name and the name of the file may be included in a notification sent to the User who owns it, and therefore reach our notification provider.
  • A Reviewer who wishes to exercise a data protection right, including correcting a record that names them, should contact us at the address in Section 3. We will act on it in respect of the records we hold, and will involve the User who requested the review where the record belongs to their project.

7. The Content you upload

Content — the files you upload for review — may itself contain personal data, and is frequently the confidential material of your own clients. We process it only to provide the Services to you.

  • Content uploaded through ExpressReview is transmitted to and stored on the Approval Studio Platform. ExpressReview holds the file bytes in memory only while forwarding them, and does not write them to its own storage; it records the file name and which account the file belongs to.
  • On the Approval Studio Platform, Content is held within the project you upload it to, together with its versions, reference files, comments and decisions, for as long as you keep the project.
  • Where you use website proofing, you give us the address of a live or staged website so that it can be displayed for review. That address, and the material we retrieve from it in order to display it, are treated as your Content. A staging address may itself be confidential, and you are responsible for ensuring you are entitled to submit it.
  • We do not use your Content to train models, and we do not disclose it except as described in this Policy or as required by law.
  • On first use of ExpressReview we create a project on the Approval Studio Platform named after the part of your email address before the “@”.

8. Who receives your personal data

RecipientWhat they receivePurpose
3W InfraAll data stored by the ServicesHosting provider. Servers in Amsterdam, the Netherlands. DPO: [email protected]
Cloudflare Inc.Traffic metadata including IP addressesDDoS protection and edge delivery. DPO: [email protected]
tawk.toName, email address, chat messages, support ticket content and any attachmentsCustomer support chat and support ticket system. DPO: [email protected]
StripeCard details entered at checkout, billing address, VAT number and subscription recordsFinancial services. DPO: [email protected]
Google LLCWebsite analytics data; Google Sign-In verification; device push tokens and notification contentAnalytics, marketing, authentication and push notification delivery
Amplitude, Inc.Product analytics dataProduct analytics for the Website and Web Application
Meta Platforms, Inc. (Facebook)Website marketing identifiersMarketing on the Website only, and only where you have given cookie consent
RevenueCat, Inc.An account identifier; we receive entitlement status and a billing email backExpressReview subscription entitlement
Mandrill (Intuit Mailchimp)Email address and message contentTransactional email such as password resets
Apple Inc.; Google LLC (Google Play)Purchase and subscription recordsExpressReview in-app purchases
Third-party services you connectContent and related data you direct us to sendIntegrations you enable, including AI services via the MCP server — see Section 9
AppSumoNothing is sent. We receive the email address you registered with and your licence detailsPurchases of lifetime deals, which AppSumo processes
Link shortening providerReview link dataShort links, where a tenant is configured to use an external shortener
HiTech Service LLCAll of the aboveSoftware development, storage of personal data and customer support data. DPO: [email protected]

9. Integrations, the MCP server and AI services

You may connect the Services to third-party platforms and services. These connections are optional and operate only where you enable them.

  • Where you connect an Integration such as Shopify, Figma, Adobe Creative Cloud, Zapier or Slack, you authorise us to exchange data with that platform. Its own privacy policy governs what it then does with that data.
  • Where you use the MCP server to connect the Services to a third-party artificial intelligence or automation service — for example Claude, ChatGPT, n8n or Make — you instruct us to transmit Content and related data to the service you have selected. We do not control that service. Before connecting one, you should review its terms and privacy policy, including whether it retains submitted data or uses it to train models, and satisfy yourself that sending the Content to it is permitted — particularly where the Content is a third party’s confidential material.

10. Transfer of your personal data to a third country

Our production servers are located in Amsterdam, the Netherlands. Personal data you provide to us directly is stored within the European Economic Area.

Some of the recipients listed in Section 8 are established outside the EEA, principally in the United States. Where personal data is transferred to them, we rely on the following, in this order:

  • An adequacy decision of the European Commission, including the EU–US Data Privacy Framework where the recipient is certified under it;
  • Otherwise, the Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914, together with an assessment of whether the law of the destination country affords the protection those clauses require, and any supplementary measures that assessment identifies as necessary.

11. How long we keep your personal information for

All Personal Data will be kept in a format that allows the Data Subjects to be identified for no longer than is necessary for the purposes for which the personal data are processed.

Personal data may be stored for longer periods of time if personal data are processed solely for archiving purposes and for reasons of general interest, scientific or historical research or for statistical purposes or for the defense of any legal rights.

Deleting your account removes your account records, your Content and your activity history. A limited number of records survive deletion where we are required to keep them for security, audit or legal compliance purposes; the records held by our payment, email and notification providers are not removed by deleting your account.

12. How we protect your data

  • Passwords are stored only as a one-way hash and are never recoverable, including by us.
  • Sessions use signed tokens which are invalidated when you change your password.
  • Credentials for our platform services are encrypted at rest with a key held outside the database.
  • Client applications never receive platform credentials; only our server communicates with the Approval Studio Platform.
  • Login, registration and password reset are rate limited.
  • Administrative access is restricted to an explicit list of addresses, and administrative actions are logged.
  • If a personal data breach occurs, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, and will inform affected individuals where the breach is likely to result in a high risk to their rights and freedoms.

13. Your data protection rights

You have the following rights, in terms of your personal data we hold about you:

  • Receive access to your personal data.
  • Request correction of the personal data we hold about you.
  • Request erasure of your personal information, where there is no good reason for us continuing to process it.
  • Request restriction of processing — you may ask us to suspend the processing of your personal data, for example while its accuracy is being verified or while an objection is being considered (Article 18 GDPR).
  • Request the portability of your personal data — to receive the data you provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible (Article 20 GDPR).
  • Object to the processing of your personal data, where we are relying on a legitimate interest and there is something about your particular situation which makes you want to object to processing on this ground.
  • Withdraw consent that you gave us with regard to the processing of your personal data at any time. Any withdrawal of consent shall not affect the lawfulness of processing based on consent before it was withdrawn.

Approval Studio Platform accounts are deleted on request: contact the address in Section 3 and we will process the deletion, normally within one business day. If you use ExpressReview you can delete your account yourself from within the application, and you can export your data yourself, at any time and without contacting us, from the account screen. That export does not currently include every category of data we hold about you; a request under this Section will always be answered in full.

To exercise any of your rights, or if you have any other questions about our use of your personal data, please contact the DPO at the address in Section 3. We will respond without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests, in which case we will tell you within the first month.

14. Right to lodge a complaint

If after complaining to the DPO you still feel that your Personal Data has not been handled appropriately, you may lodge a complaint with a supervisory authority.

  • If you are in the European Economic Area, you have the right to lodge a complaint with the supervisory authority of the country in which you live, in which you work, or in which the alleged infringement took place.
  • You may also contact the Office of the Delaware Department of Justice (Delaware Attorney General), Delaware Department of Justice, Carvel State Building, 820 N. French St., Wilmington, DE 19801, [email protected].

15. Cookies and analytics

We use cookies. This technology provides us with information about devices and networks you utilize to access our Website. A full list of the cookies we set, their providers, purposes and durations is maintained in our Cookie Policy at approval.studio/cookie-policy.

  • Cookies that are strictly necessary to operate the Services are set without consent. All other categories — preferences, statistics and marketing — are set only after you accept them through our cookie banner.
  • You can withdraw or change your cookie consent at any time through the same banner, and delete cookies through your browser settings.
  • We use Google Analytics and Amplitude Analytics to understand how the Website and Web Application are used, and Meta advertising tools on the Website. These operate only where you have consented to the corresponding cookie category.
  • The ExpressReview application contains no analytics, tag manager or third-party tracking of any kind. It stores only your session token and your language preference on your device.

16. Children

The Services are intended for business use and our Terms of Service require Users to be at least 18 years old. We do not knowingly collect personal data from children. When it comes to the collection of personal information from children under the age of 13 years old, the Children’s Online Privacy Protection Act (COPPA) puts parents in control. We do not specifically market to children under the age of 13 years old.

17. California privacy rights

Residents of California have the right to request from a business, with whom the California resident has an established business relationship, certain information with respect to the types of personal information the business shares with third parties for those third parties’ direct marketing purposes. To exercise your rights, you may make one request each year by emailing us. According to CalOPPA, we agree the Users can visit our site anonymously.

  • We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law.

Approval Studio does not currently respond to browser “Do Not Track” (DNT) signals or other mechanisms. Third parties may collect personal data about your online activities over time and across sites when you visit the Site or use the Service.

18. Changes to this Privacy Policy

HiTech Service LLC will occasionally update this Privacy Policy to reflect company and customer feedback. We encourage you to periodically review this Privacy Policy to be informed of how we are protecting your information. Where a change materially affects how we use your personal data, we will notify you by email or in the Services before it takes effect. Each version carries a version number and an effective date, and we retain previous versions.