# Appfarm Policies

Policies and procedures that govern the use and development of the Appfarm platform.

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td><strong>Service &#x26; Usage</strong></td><td>Policies related to our platform services and their fair use.</td><td></td><td><a href="/pages/U2ByALMwZXZtlPrFZXSf">/pages/U2ByALMwZXZtlPrFZXSf</a></td><td><a href="/files/b8wyoqjf7CMIQ1VXSF4n">/files/b8wyoqjf7CMIQ1VXSF4n</a></td></tr><tr><td><strong>Privacy</strong></td><td>Our privacy policy and an overview of our data processors.</td><td></td><td><a href="/pages/NygGcZyfaRs1xS7mqeG0">/pages/NygGcZyfaRs1xS7mqeG0</a></td><td><a href="/files/2zywwYtaxymiwBuC6yAP">/files/2zywwYtaxymiwBuC6yAP</a></td></tr><tr><td><strong>Security</strong></td><td>Our platform security practices and compliance information.</td><td></td><td><a href="/pages/lN4WXGMujsOah1OACZPF">/pages/lN4WXGMujsOah1OACZPF</a></td><td><a href="/files/BO04z8yCE9iwmIYmPUfR">/files/BO04z8yCE9iwmIYmPUfR</a></td></tr><tr><td><strong>Product Glossary</strong></td><td>Definitions of our key product concepts.</td><td></td><td><a href="/pages/O2fzqAuDtWrUjG1SCr6B">/pages/O2fzqAuDtWrUjG1SCr6B</a></td><td><a href="/files/OhImGd68kjncBpZbxN1E">/files/OhImGd68kjncBpZbxN1E</a></td></tr><tr><td><strong>Code of Conduct</strong></td><td>Our commitments to our colleagues, customers, and partners.</td><td></td><td><a href="/pages/gzGtByuVcMJSMz6hmSwe">/pages/gzGtByuVcMJSMz6hmSwe</a></td><td><a href="/files/NnYfCKeDcMdsZoCfd8L2">/files/NnYfCKeDcMdsZoCfd8L2</a></td></tr></tbody></table>


# AI Credits Terms of Use

These terms apply to the purchase and use of [AI credits](/glossary/product-glossary#ai-credits) in Appfarm Create. The use of Appfarm Create is governed by your Appfarm Subscription Agreement or Free Trial License Agreement, which always takes priority in case of any conflict.

* [Documentation: AI credits](https://docs.appfarm.io/reference/appfarm-ai/ai-credits)

## Credit types

AI Credits are categorized by how they are acquired, which dictates their consumption and expiration logic. The three types are:

* **Granted:** Credits provided to your Solution by Appfarm, such as the initial bundle included with a new subscription or free trial.
* **Subscription:** Credits included in your ongoing subscription plan at no additional cost.
* **Purchased:** Credits acquired through a transaction in Appfarm Create, auto top-ups or contracted fixed monthly amounts.

Each subscription tier has the following allocated AI Credits:

<table><thead><tr><th width="274.272705078125">Credit type</th><th>Essential</th><th>Professional</th><th>Dedicated</th></tr></thead><tbody><tr><td>Initial bundle <strong>(Granted)</strong></td><td>5000</td><td>10 000</td><td>20 000</td></tr></tbody></table>

## Usage and billing

When you use AI features in Appfarm Create, AI credits are automatically deducted from your balance based on usage. If your Solution has multiple credit types available, they are spent in this order:

1. Granted
2. Subscription
3. Purchased

If you hold multiple credits of the same type, those with the earliest expiration date are consumed first.

## Credit validity and sharing&#x20;

Credits are locked to the specific [Solution](/glossary/product-glossary#solution) where they are allocated and cannot be transferred or reallocated.

* Granted and purchased credits expire after six months.&#x20;
* Subscription credits expire after one month.

All users working within a Solution in Appfarm Create share the same credit pool.&#x20;

## Purchases and refunds

All AI credit purchases are final and non-refundable.

Free-trial users can purchase credits directly in Appfarm Create via credit card. Subscribed customers have additional options, such as enabling auto top-up or contracting a fixed monthly amount, both of which are payable by invoice.

## Service availability

AI features are subject to change, interruption, or discontinuation. Appfarm makes no guarantee regarding the availability or performance of AI features.

## Fair use

Appfarm reserves the right to monitor usage and suspend access for abusive or excessive use that violates our [Acceptable Use Policy](/service-and-usage/acceptable-use-policy).

## Subscription termination

If your Appfarm subscription or free trial is terminated, cancelled, or expires, all remaining AI credits will be forfeited.

## No cash value

AI credits have no monetary value outside of Appfarm Create and cannot be exchanged for cash, refunded, or transferred to other parties.

## Revision history

<table><thead><tr><th width="153">Date</th><th>Revision</th></tr></thead><tbody><tr><td><code>09.10.2025</code></td><td>Document published.</td></tr><tr><td><code>06.01.2026</code></td><td>Added links to additional documentation.</td></tr><tr><td><code>09.04.2026</code></td><td>Added specification of credit types and invoice options for buying credits.</td></tr><tr><td><code>07.07.2026</code></td><td>Removed "Monthly Quota" in table under <strong>Credit Types.</strong></td></tr><tr><td><code>07.08.2026</code></td><td>Changed expiry of granted credits.</td></tr></tbody></table>


# Acceptable Use Policy

The Appfarm Platform is a fully-integrated full-stack application development platform enabling seamless development, deployment, and management of web apps. To ensure the stability of both the Appfarm Platform and your solution(s), this policy outlines technical usage limits and thresholds. This policy is subject to change and comes in addition to the commercial usage limits and thresholds specified in your Appfarm Subscription Agreements.

These usage limits are in place at all times, and as a customer and/or developer you should keep these in mind as you develop and distribute your applications. Exceeding these limits may result in degraded performance and availability of your applications.

If you expect sudden or extended periods of increased traffic or data processing, or are experiencing degraded performance due to such issues, you should immediately notify Appfarm. Our expert team can then assess the need for additional resources. If the change in usage pattern is expected to be enduring, this will likely result in our recommendation to upgrade your subscription to a tier with a higher allocation of infrastructure resources. When a solution requires a substantial amount, or specialized structure, of allocated resources in our infrastructure, it must upgrade to the Dedicated subscription tier where a custom infrastructure setup can be designed.

Appfarm will continually review this policy and adjust existing limits, as well as incorporate new limits, as deemed appropriate. Appfarm developers will be notified of any major revision of this policy.

## AI feature usage

The following restrictions apply to the use of AI features within Appfarm Create to ensure platform stability and fair access for all users.

**Prohibited AI usage:**

* Automated or scripted interactions with AI features designed to rapidly consume credits or overwhelm AI systems
* Attempting to manipulate AI prompts to reveal system instructions, bypass safety measures, or access unauthorized functionality
* Using AI features for purposes unrelated to legitimate application development within Appfarm Create
* Sharing Solution access or credentials with unauthorized parties to circumvent credit allocations
* Submitting prompts or content that violate applicable laws or your Appfarm Subscription Agreement

**Fair use principles:** AI features are intended for interactive application development by authorized users. Excessive usage patterns that significantly impact system performance or availability may result in temporary restrictions or account suspension, regardless of available credit balance.

**System protection:** Appfarm reserves the right to implement rate limiting, usage monitoring, and other technical measures to prevent abuse and ensure equitable access to AI features. Users experiencing legitimate high-volume development needs should contact Appfarm to discuss appropriate usage patterns.

## Prohibited actions

You are strictly prohibited from conducting load testing, stress testing, or any other forms of testing or activities that are designed to assess, challenge, or exceed the capabilities of our platform. Such activities can unfairly consume a significant amount of platform resources and potentially degrade the service for other users. Any attempts to perform these types of activities will be regarded as a violation of this policy. If you have questions about the resources available to your solution, platform performance, or the benefits of a custom infrastructure setup, please contact Appfarm.

## Platform units

A platform unit is a measure developed by Appfarm that represents the amount of computing and memory resources allocated to a solution in Appfarm Cloud. These resources are distributed across your solution infrastructure to suit actual utilization. Platform units scale dynamically to stabilize performance, subject to the below conditions. Each subscription tier has the following allocated platform units:

<table><thead><tr><th width="154"> </th><th>Essential</th><th>Professional</th><th>Dedicated</th></tr></thead><tbody><tr><td>Platform units</td><td>5</td><td>15</td><td>From 30</td></tr></tbody></table>

### Auto-scaling

To maintain optimal solution performance and availability under peak usage, platform units can temporarily scale up to 120% of your allocated resources.

If the average resource utilization of your solution over a 24-hour period exceeds the allocated amount of platform units, this will be flagged, and we will notify you. Depending on the cause, you may need to make adjustments to your solution or consider upgrading your subscription tier.

### Resource allocation by environment

The Production environment is allocated a higher percentage of the available resources. Operations that rely heavily on frequent API requests and/or have large data processing requirements should be run in the Production environment. If you deem it necessary to run such operations in an environment other than Production, please contact your Appfarm representative to discuss the optimal approach and related practical and commercial arrangements.

### Increased limits due to purchase of additional user bundles

The number of users will often impact the usage of resources in the Appfarm infrastructure. All other things equal, a solution with a large number of active users will consume more resources compared to one with few users. Appfarm will allocate 2 additional platform units for each additional user bundle that is purchased per solution.

## Global limits

Global limits apply to all solutions on the Appfarm Platform regardless of subscription tier.

<table><thead><tr><th width="273"> </th><th>Limit</th></tr></thead><tbody><tr><td>Concurrent user sessions</td><td>50% of your total active user allotment up to a maximum of 1.000</td></tr><tr><td>API payload size</td><td>1 MB</td></tr><tr><td>Concurrent API requests</td><td>2</td></tr><tr><td>Database operations</td><td>100 per second</td></tr></tbody></table>

**Concurrent user sessions**\
The total number of active user sessions at any given time. This includes both authenticated and anonymous users.

**API payload size**\
The size of the request body sent to a service endpoint.

**Concurrent API requests**\
The number of API requests received simultaneously.

**Database operations**\
The total number of read, write, delete, and query operations performed.

## **Revision history**

<table><thead><tr><th width="130.22265625">Date</th><th>Revision</th></tr></thead><tbody><tr><td><code>23.09.2022</code></td><td>Document published.</td></tr><tr><td><code>27.06.2023</code></td><td>Added section "Resource allocation by environment".</td></tr><tr><td><code>15.11.2023</code></td><td>Added section "Prohibited actions".</td></tr><tr><td><code>24.09.2024</code></td><td>Removed section "Limits by subscription tier" as this information is now included in the <a href="/pages/dIq6mgquC6Ezdc6wyExN">Product Glossary</a>.</td></tr><tr><td><code>09.10.2025</code></td><td>Added section "AI feature usage".</td></tr><tr><td><code>05.01.2026</code></td><td>Removed reference to Basic tier under "Platform units" as the Basic tier has been discontinued.</td></tr></tbody></table>


# Backup Policy

The Appfarm Platform implements routine automated backup procedures to assist in protecting your solution(s) from data loss. This policy defines what data is backed up, the backup procedures, and how to request data restoration in the event of data loss.

It is important to remember that backups can not prevent all data loss. Your primary protection from data loss is implementation of, and adherence to, your own data protection practices. You are responsible for configuring your solution appropriately in relation to your data protection practices. Backups should be considered supplementary to your internal procedures and some data loss may still occur if your solution is restored from a backup.

## Implementation and testing

Automated backup schedules are defined at the time of database creation. Appfarm undertakes manual restoration from backups on a regular basis to test and validate the backup and restoration process. These processes are tracked in an internal system.

## Solution model backups

The *solution model* contains the definition of your [global data model](https://docs.appfarm.io/reference/data-model), [apps](https://docs.appfarm.io/reference/apps), [services](https://docs.appfarm.io/reference/services), and other solution-specific metadata generated from Appfarm Create.

Solution models are considered part of the Appfarm Platform and are subject to Appfarm’s internal backup routines. Automated backups of solution models are run every 6 hours and are retained for up to 12 months. This schedule is subject to change without notice.

Solution model backups are distinct from [snapshots](https://docs.appfarm.io/reference/operations/deploy#snapshots). A snapshot also stores a copy of a solution model, but these can be created, applied, and deleted by users in Appfarm Create.

## **Solution data backups**

*Solution data* refers to the set of data in your solution that your apps and services read and manipulate, such as [objects](https://docs.appfarm.io/reference/platform-concepts/objects) you create and persist via [data sources](https://docs.appfarm.io/reference/apps/data/data-sources).

Solution data backups are generated via scheduled disk snapshots which are created by the underlying cloud provider for Appfarm Cloud. Backups are stored in the same region as the primary data.

Files stored in [file object classes](https://docs.appfarm.io/reference/data-model/object-classes#file-object-class) are stored in object storage with high availability and durability. These files are not currently replicated due to the service levels afforded this type of object storage.

Solution data backup schedules and retention periods are set according to your subscription tier.

### **Essential and Professional**

* Backups are run every 6 hours and retained for 7 days.
* Weekly backups are retained for 4 weeks.
* Monthly backups are retained for 3 months.

### **Dedicated**

For [Dedicated subscriptions](https://docs.appfarm.io/solution-administration/dedicated-tier-benefits) the backup schedule may be customized on customer request. The defined schedule applies to all solutions incorporated in the Subscription Agreement. By default, the schedule above will be implemented. Material changes to backup frequency and/or retention may incur additional fees.

## **File backups**

*Files* are static files uploaded to [Files](https://docs.appfarm.io/reference/resources/files) within Appfarm Create.

When a file is uploaded, a backup is generated. When a file is deleted from Appfarm Create it is moved to a temporary location in the Appfarm Cloud. After 30 days the file is permanently deleted and is no longer stored on the Appfarm Platform.

## **Data recovery**

If a solution has suffered data loss you may request that your data is restored from a backup. The data restoration process will be completed within 7 days from when your request is received, provided there are sufficient grounds for the request. To make a data recovery request, please contact your Customer Success Manager.

## **Revision history**

<table><thead><tr><th width="130.15234375">Date</th><th>Revision</th></tr></thead><tbody><tr><td><code>30.09.2022</code></td><td>Document published.</td></tr><tr><td><code>13.10.2025</code></td><td>Solution data backups: Extended the section for Dedicated subscriptions to include that material changes to frequency and retention may incur additional fees.</td></tr><tr><td><code>05.01.2026</code></td><td>Removed reference to Basic tier under "Solution data backups" as the Basic tier has been discontinued.</td></tr></tbody></table>


# ESIN Policy

Email, SMS, and Integrated Messaging and Notification Policy

This policy outlines acceptable use and specifies limitations of the integrated messaging and notification services in Appfarm Create. These services include email, SMS, push notifications, and other messaging or notification components made available in, or created using Appfarm Create. Throughout this policy, we will use the term “Messaging Services” to refer to these services and “Message” to refer to an individual notification or message.

In general, Appfarm expects developers to follow industry best practices. Notification and Messaging Services should use “privacy first” principles, with appropriate consent from users. Sender information and message content must be clear and accurate. You must respect opt-out and unsubscribe requests and facilitate the processing of such requests where appropriate. Bulk messaging should be used sparingly and must be tested vigorously.

You may not assist, encourage, or otherwise enable other users or third parties in a manner that would breach or infringe upon this policy. If Appfarm determines that you have breached this policy, or acted in a manner that is not in the spirit of this policy, Appfarm may suspend or terminate your access to Messaging Services or ultimately suspend or terminate your access to the Service.

If you become aware of a breach of this policy, you must report it in accordance with the Notice and Takedown Policy. Appfarm may update this policy at any time. Changes will be clearly stated in the revision history log.

## Prohibited actions

You may not use Messaging Services to engage in, or in any way facilitate, the following actions:

* Sending spam. Spam is unsolicited Messages and can be in the form of bulk Messages or one-to-one commercial Messages.
* Any activity or conduct that is, or is likely to be, in breach of any applicable laws, codes, or regulations, including data privacy laws.
* Sending Messages to third-party mailing lists, or lists that have been purchased, rented, or otherwise shared with you.
* Sending email or SMS validation or re-engagement campaigns.
* Using any misleading or incorrect names, addresses, email addresses, subject lines, or other information in a Message.

## Requirements

You are required to follow these guidelines when using the Messaging Services.

* You must respect the limits to Messaging Services as specified in your Subscription Agreement and any other agreements entered into with Appfarm, as well as other policies in effect.
* In general, Messaging Services are to be used for transactional Messages. Non-transactional usage (commercial or marketing Messages) is permitted on the condition that you can document that the recipients have provided active consent to receive that specific type of communication in line with applicable privacy laws.
* Non-transactional Messages must include a clear and easy method for unsubscribing and unsubscribe requests must be honored without delay.
* You must use clean contact lists which contain valid and accurate email addresses and phone numbers.

## Prohibited content

You may not use Notification and Messaging Services with content, or in a manner that:

* is harassing, stalking, threatening, abusive or defamatory;
* is false, deceptive or misleading;
* contains indecent, vulgar, obscene or otherwise unlawful material;
* harvests or otherwise collect information about others, including email addresses, without their consent;
* is not a good faith use of Notification and Messaging Services;
* promotes, encourages or facilitates: hate speech, violence, discrimination based on race, colour, sexual orientation, marital status, gender or identity expression, parental status, religion or creed, national origin or ancestry, sex, age, physical or mental disability, veteran status, genetic information, citizenship and/or any other characteristic protected by law;
* constitutes, depicts, fosters, promotes or relates in any manner to child pornography, bestiality, non-consensual sex acts or otherwise unlawfully exploits persons under 18 years of age;

## Message delivery

Appfarm does not guarantee that Messages sent using the Notification and Messaging Services will be delivered to the given recipient. Neither you nor the intended recipient will be notified if the given Message is not delivered or is delivered to the incorrect recipient. Appfarm takes no responsibility for any damages arising from the incorrect delivery of Messages.

While the Notification and Messaging Services are facilitated by Appfarm, you are responsible for any Messages sent. [Third-party service providers](/privacy/data-processors) are used for delivering these services, and Appfarm cannot guarantee the availability or service levels of those services.

## Email

You can send up to 500 emails per month using the integrated email component. If you wish to send emails in excess of this limit, you must configure a custom service provider.

Emails sent using the integrated email component are permanently deleted from Appfarm’s databases after 24 hours. Email log information is deleted after five days. You should strongly consider implementing your own procedures for logging the details and content of sent emails.

## SMS

You can send up to 50 messages per day and up to 500 messages per month using the integrated SMS component. Refer to the Appfarm documentation for information on how the amount and type of characters can affect the number of messages sent. If you wish to send SMS in excess of this limit, please contact your Customer Success Manager or <support@appfarm.io>.

SMS sent using the integrated SMS component are permanently deleted after 30 days. You should strongly consider implementing your own procedures for logging the details and content of sent SMS.

## Push notifications

Push notifications should be used to augment the experience of your app and should not be used as the sole channel for delivering information that is considered important or time critical. You must not include any sensitive or confidential information in a push notification. Push notifications are based on the capabilities of Progressive Web Apps (PWAs) in the context of native desktop and mobile operating systems. Appfarm cannot guarantee the availability of push notifications. &#x20;

Push notifications sent using the integrated push notification component are not stored. You should strongly consider implementing your own procedures for logging the details and content of sent push notifications.

## Revision history

14.12.22: Document published.


# Invoicing and Payment Policy

## Background and purpose

Appfarm aims to maintain transparent and fair invoicing and payment practices, ensuring alignment with the Customer’s contractual agreements (i.e., the Appfarm Subscription Agreement) related to Appfarm’s software subscription services (“the Service”).&#x20;

This policy provides guidance regarding the following main areas:&#x20;

* Invoicing of software services, including both Contracted Product Capabilities and Resources, as well as Additional Resources and Capabilities (e.g., product add-ons and other consumables).&#x20;
* Annual adjustment of prices.
* Payment terms and deadlines, including overdue and reminder processes.
* Procedures related to accounts in arrears or default due to lack of payment, which may lead to suspension or termination of the Service.

This policy relates to Appfarm’s software subscription services only. Invoicing for product success and other related professional services is covered in separate agreements and/or policies, although certain procedures and principles follow similar practices.

## Invoicing of software services

The Subscription Agreement (including appendices and policies) governs the Customer's subscription scope. Customers generally subscribe to one of Appfarm’s available Subscription Tiers (“Subscription Tier”), which define the scope of included resources and capabilities for a fixed fee (i.e., “Base Subscription Fee”) at the time of conclusion of the agreement.&#x20;

In addition, the Customer may choose to include and contract specific additional resources and capabilities beyond what is included in their Subscription Tier (i.e., “Contracted Product Capabilities and Resources”), or, during the subscription period, choose to make use of and consume additional resources and capabilities if available within their Subscription Tier (i.e., “Additional Resources and Capabilities”).

Generally, Appfarm’s invoicing process is performed at the start of each calendar month (i.e., on the first working day of the month).&#x20;

### Contracted Product Capabilities and Resources

Contracted Product Capabilities and Resources are invoiced in advance, together with the Base Subscription Fee, at the start of the applicable Invoicing Period, as stipulated in the Subscription Agreement (under “Invoice Structure”), for the entire length of a given Invoicing Period.

Subscriptions commencing partway through a calendar month will be prorated based on the number of days active in that month.

Invoicing is performed according to the volumes, amounts, timing, and payment terms set out in the Subscription Agreement and will continue until cancelled or terminated in accordance with the contracted terms.

### Additional Resources and Capabilities

Usage of Additional Resources and Capabilities generally follows the same invoicing model as Contracted Product Capabilities and Resources. Once activated, they incur monthly fees, and follow the same subscription term, termination conditions, invoice structure, and payment terms as set out in the Subscription Agreement, unless the usage is explicitly approved and labeled as part of a complementary testing period (or similar).

Purchase of Additional Resources and Capabilities is operationally executed in one of two ways:

* Appfarm-assisted: The Customer makes a request, and Appfarm enables the resource or capability.
* Customer self-service: The Customer enables the resource or capability directly via the Service (either explicitly, or implicitly by exceeding set Subscription Tier threshold limits).

When usage of an additional resource or capability is identified, the invoicing system generates a purchase order assigned to the subscription. The purchase order will trigger an additional separate invoice to be issued as soon as practicable (at the latest in connection with the next monthly invoicing process). The additional usage will then be added to the Customer’s subscription, and invoiced together with the Base Subscription Fee, and any Contracted Product Capabilities and Resources, for subsequent invoices.

Invoicing will continue until cancellation or termination in accordance with the contracted terms.

Note: For countable resources (e.g., number of Apps, Environments, etc), invoicing is based on the maximum usage recorded during a calendar month. Reasonable pro-rata adjustments based on within-month usage between activation and termination dates may be made at Appfarm’s discretion.

There are some notable exceptions related to the above for (i) Active Users, and (ii) Other consumable services (e.g., SMS or AI Credits).&#x20;

#### Active Users

Due to its variable and accumulative nature within a specific calendar month, the invoicing of [Product Glossary](/glossary/product-glossary#active-users) consumption is managed differently.

All Subscription Tiers have an included quota of Active Users per month, and any usage beyond this threshold triggers separate invoicing of one or more additional Active Users bundles based on the actual usage within each calendar month.&#x20;

Note: Surpassing the threshold in one month does not imply continuing charges for subsequent months unless usage remains above the threshold.

#### Other consumable services

Consumable services such as SMS and AI Credits are resources and capabilities made available in the Service that can have very variable usage patterns over time and depend heavily on customer use cases. Consumables are generally invoiced in arrears (i.e., monthly or quarterly), depending on usage volume and customer agreement. Other consumables may be purchased by self-service option directly in the Service.&#x20;

One example is [Product Glossary](/glossary/product-glossary#sms), which can be enabled as integrated functionality in customer applications. SMS usage may be billed quarterly by default, but if usage exceeds a certain volume in a single month (e.g., above 5,000 SMS), a monthly invoice may be triggered. Conversely, very low monthly consumption volumes (e.g., below 500 SMS) may be billed semi-annually or annually to reduce administrative overhead.

Another example is [Product Glossary](/glossary/product-glossary#ai-credits), which can be purchased directly in the Service via credit card. By special agreement, bulk purchases of AI Credits may be arranged via invoice.&#x20;

### Annual adjustment of prices

In accordance with the Subscription Agreement, Appfarm reserves the right to adjust all subscription fees (i.e., the Base Subscription Fee, fees for Contracted Product Capabilities and Resources, and fees for Additional Resources and Capabilities) on an annual basis. The annual adjustment will be the greater of either (i) a 5% increase or (ii) the percentage change in the relevant retail/consumer price index (for example, Statistics Norway’s *Konsumprisindeksen* in Norway) over the preceding year. This mechanism reflects Appfarm’s continued investment in research and development to enhance the quality and value of the Service.

Adjusted fees are calculated by applying the annual adjustment rate to the current fees, and rounding the result to the nearest NOK 50 or EUR 5.

Adjusted fees will take effect from January 1st each year. Appfarm will typically apply the changes in arrears on the first invoice in the new year. In certain cases, adapting to the Customer’s invoice period and frequency, the effects may be applied in advance on the last invoice in the preceding year.&#x20;

Note: Appfarm reserves the right to adjust prices to reflect material changes in market conditions and/or unforeseen and material increases in direct costs associated with providing the Service, including, but not limited to, costs of technical infrastructure, data processing capabilities and storage, associated technologies, and changes in prices or availability of third-party services or others that constitute a part of the Service. In such cases, price adjustments must be reasonably documented by Appfarm, and written notice will be provided to the Customer at least 60 days prior to the effective date of the price adjustment.&#x20;

## Payment terms

Appfarm’s Payment Terms are set out in the Subscription Agreement (i.e., “Invoice Structure & Payment Terms”).

Generally, invoices are issued annually, semi-annually or quarterly, in advance, on the first day of each Invoicing Period. The length of the Invoicing Period typically correlates with the Customer’s Subscription Tier (i.e., Essential, Professional, or Dedicated).

Payment deadlines commonly range from 14 to 60 days after the invoice date, dependent on the Customer’s Subscription Tier and any supplemental agreements.

Note: All prepaid fees are non-refundable without exception. This includes circumstances when the Customer terminates the subscription under applicable law or statutory rights.

### Overdue and reminder process

If payment is not received by the invoice due date, the invoice is deemed overdue. An automated reminder from Appfarm’s invoicing system is sent within 3 days after the due date. Additional automated reminders follow every 4 days for overdue invoices.

After multiple reminders (usually not more than 3, at Appfarm’s discretion), a final notice (i.e., *Inkassovarsel* in Norwegian) is sent with a 14-day deadline. If payment is still not received after this final notice period, the overdue invoice may be forwarded to a third-party collection agency for further follow-up.

## Default and suspension of the Service

An account is considered in default if payment remains unsettled after the 14-day final notice period specified under [#overdue-and-reminder-process](#overdue-and-reminder-process "mention").

Upon default, Appfarm may suspend or terminate the Customer’s access to the Service, including any and all of the Customer’s [Solutions](/glossary/product-glossary#solution) related to the defaulting account, until all outstanding balances are settled.

If no timely resolution is reached, Appfarm reserves the right to initiate Customer Termination, in accordance with the termination provisions of the Subscription Agreement. The effective termination date will be determined pursuant to those provisions (e.g., the first day of the calendar month following a formal termination notice, or as otherwise specified). For clarity, the date on which the account is declared in default will be treated as the date of receipt of formal termination notice, unless otherwise stated in the Subscription Agreement.

## Communication and escalation

Appfarm’s Customer Success and Partner Success teams are your primary contacts, and handle follow-up of overdue invoices and default situations in close cooperation with Appfarm’s Finance department.&#x20;

If suspension or termination of the Service is imminent, this will be communicated via official channels (e.g., email, phone) to the Customer’s designated points of contact, referencing the specific invoice(s) and any remedial steps.

Where relevant, Appfarm-certified Partners will be informed or involved, particularly if they manage the Customer’s technical deployments on the Customer’s behalf.

## Updates and revisions

This policy may be updated periodically to align with evolving business practices and/or regulations. Any material changes will be communicated to Customers and Partners via standard communication channels (e.g., email or notice within the Service). If revised terms require Customer acceptance, continued use of the Service following the notice period will constitute acceptance of the updated policy.

Disclaimer: This policy is intended as a supplement to the governing terms set out in the Subscription Agreement (including appendices and associated policies), including (but not limited to) the Service Level Agreement and Data Processing Agreement. In the event of any inconsistency or conflict between this policy and the Subscription Agreement, the terms of the Subscription Agreement shall prevail.

If you have any questions regarding this policy, please reach out to your Appfarm Customer Success or Partner Success representative.

## Revision history

<table><thead><tr><th width="153">Date</th><th>Revision</th></tr></thead><tbody><tr><td><code>16.10.2025</code></td><td>Document published.</td></tr></tbody></table>


# Notice and Takedown Policy

Appfarm respects the rights of intellectual property holders, the ideals of data protection set out in GDPR and other personal data frameworks, and requires lawful and ethical use of the Appfarm Platform. This policy establishes a procedure for handling reported intellectual property infringements or other breaches of Appfarm policies. Appfarm may update this policy at any time. Changes will be clearly stated in the revision history log.

## Appfarm’s obligations

Due to the nature of Appfarm Create, where the developer is free to develop virtually any type of software application, Appfarm cannot accept a comprehensive and general obligation to monitor the use of, and the substance of, content created and stored using the Appfarm Platform. However, Appfarm agrees to address any breach of Appfarm policies, including any breach of law or breach or infringement of third-party rights, where it is properly notified of such a breach or infringement. Any such action will be made in accordance with the procedures laid out in this policy.

Appfarm will respond to proper written notices of an alleged infringement. As part of the response Appfarm may remove or disable access to allegedly infringing content stored on the Appfarm Platform. Appfarm reserves the right to suspend or terminate the offending user account and/or Appfarm Solution upon confirmation of a policy breach or infringement.

## Reporting policy infringement

If you believe that any content stored or accessible on or through the Appfarm Platform constitutes an infringement of intellectual property or other breach of Appfarm policies, you are encouraged to send a notice of infringement containing the following information to <privacy@appfarm.io>:

* Identification of the type of infringement which you believe has occurred (for example violation of intellectual property rights, infringement of the GDPR provisions, use of illegal and unethical content, etc.);
* Identification of the content that is alleged to be infringing with sufficient detail to enable Appfarm to locate and verify its existence;
* Your contact information, including your name, telephone number, and email address; and,&#x20;
* A statement that the information provided in the notice is accurate.

If the notice refers to a violation of intellectual property rights, you must also include the following:

* Identification of the intellectual property right you allege has been infringed;&#x20;
* If you are not the owner of the intellectual property right, a description of your affiliation to the intellectual property holder;
* A statement that you are authorized to make the complaint on behalf of the owner of the intellectual property right; and&#x20;
* A physical or electronic signature of the owner of the intellectual property right or the person authorized to act on behalf of the owner of the intellectual property right.

Note that the information provided in a notice of infringement may be forwarded to the user who uploaded or distributed the allegedly infringing content.

Following receipt of a proper written notification, Appfarm will promptly notify the affected user that the data or content may be removed or have access to it disabled.

## Revision history

14.12.22: Document published.


# Early Release Channel SLA Policy

This policy clarifies the Service Level Agreement (SLA) terms for customers who opt to use Appfarm's **Early** release channel for their Solutions. It is a standalone addition to Appfarm's contracts and documentation, and it applies to all customers under a paid subscription agreement who choose to run any Solution on the Early channel. In line with Appfarm's [existing documentation](https://docs.appfarm.io/solution-administration/release-channels) (which describes the Early channel and other release channels), this policy avoids restating those definitions and focuses solely on the impact on SLA commitments.

**SLA suspension on Early release channel:** When a Solution is on the Early channel, Appfarm's standard SLA commitments (as defined in the customer's subscription contract) are suspended for that solution. In practice, this means:

* **No standard SLA guarantees:** Appfarm does not guarantee the usual SLA metrics (such as specific uptime levels, system performance, or support response times) for any Solution while it remains on the Early channel. This "relaxed SLA" status acknowledges that Solutions on the Early channel receive the latest updates with a higher risk of bugs or instability, and thus the normal SLA assurances do not apply during this period.
* **Waiver of SLA remedies:** All SLA-related responsibilities and remedies outlined in the subscription agreement are void for a Solution on the Early channel. The customer cannot claim any SLA breach credits, refunds, or other penalties for service issues occurring while the Solution is on the Early channel, because Appfarm's SLA obligations are waived during that time.
* **Reinstatement upon switching channels:** If a Solution is moved from the Early channel to the Standard or Stable release channel, the standard SLA terms and commitments outlined in the contract will be reinstated for that Solution following a transition period.

  \
  The switch between release channels does not occur instantly due to Appfarm's rolling release schedule. Instead, upgrades are paused until the Solution is running on the same platform version as the most current release for the target channel (Standard or Stable).

  \
  During this transition period, the "relaxed SLA" status (suspension of standard SLA guarantees) will continue to apply. Once the Solution reaches version parity with its new target channel, full SLA coverage as defined in the subscription agreement is automatically reinstated from that point forward.

Except for the SLA modifications noted above, all other terms of the customer's subscription agreement and Appfarm's policies remain unchanged and in full effect. This policy does not alter any contract provisions or documentation beyond clarifying that opting into the Early release channel effectively waives Appfarm's SLA obligations for the duration of that Early channel usage.

### Revision history

| Date         | Revision            |
| ------------ | ------------------- |
| `07.01.2026` | Document published. |


# Data Processors

To support the delivery of our services, Appfarm AS may engage and use data processors with access to certain customer data (each, a "data processor"). This page provides vital information about each processor's identity, location, and role. Terms used on this page but not defined have the meaning outlined in the Software Service Agreement or superseding written agreements between the Customer and Appfarm.

## **Third-party data processors for the Appfarm Platform (the "Service") processing customer personal data** <a href="#third-party-subprocessors-for-the-appfarm-platform-the-service-processing-customer-personal-data" id="third-party-subprocessors-for-the-appfarm-platform-the-service-processing-customer-personal-data"></a>

Appfarm and its affiliates engage the following third-party entities to assist in connection with the Service as specified below:

<table data-full-width="true"><thead><tr><th width="211">Entity Name</th><th width="100">Service</th><th width="159">Service location</th><th width="239">Task performed</th><th width="293">Type of data stored</th><th width="100">Storage period</th><th>Type</th><th width="208">Country of registration</th><th width="226">Registered address</th><th width="209">GDPR compliance</th><th data-hidden>Participant in Data Privacy Framework</th><th data-hidden>Schrems II</th><th data-hidden>Link to DPA</th></tr></thead><tbody><tr><td><strong>Report-URI Ltd.</strong></td><td>Report URI</td><td>Norway*</td><td>Automated Content Security Policy anomaly reporting for platform users (Platform Security)</td><td>IP address, URL of Appfarm solution, Browser information (User Agent string)</td><td>Deleted after 30 days</td><td>Integrated</td><td>England and Wales</td><td><p>22 Shireburn Avenue</p><p>Clitheroe, Lancashire</p><p>United Kingdom, BB7 2PN</p></td><td>​<a href="https://report-uri.com/home/privacy_policy">View</a>​</td><td>Not relevant (processing within EU/EEA)</td><td>​<a href="https://cdn.report-uri.com/pdf/Report%20URI%20-%20Data%20Protection%20Analysis%20(1v4R).pdf">View</a>​</td><td>​<a href="https://cdn.report-uri.com/pdf/Report%20URI%20-%20DPA%20(2v0).pdf">View</a>​</td></tr><tr><td><strong>Functional Software, Inc.</strong></td><td>Sentry</td><td>USA *****</td><td>Automated error reporting for platform users</td><td>IP address, browser information (User Agent string), internal Appfarm identifier and crash logs. End-users</td><td>Deleted after 90 days</td><td>Integrated</td><td>USA</td><td><p>132 Hawthorne Street</p><p>San Francisco, CA 94107</p></td><td>​<a href="https://sentry.io/security/">View</a>​</td><td>YES</td><td>​<a href="https://help.sentry.io/account/legal/how-are-you-handling-the-invalidation-of-the-privacy-shield-under-schrems-ii/">View</a>​</td><td>​<a href="https://sentry.io/legal/dpa/">View</a>​</td></tr><tr><td><strong>Mailgun Technologies, Inc.</strong></td><td>Email</td><td>EU/EEA</td><td>Email services</td><td>Email address and other data used in email body</td><td>Deleted after 30 days</td><td>Integrated</td><td>USA</td><td><p>548 Market Street, Suite 43099</p><p>San Francisco, CA 94101</p></td><td>​<a href="https://www.mailgun.com/gdpr/">View</a>​</td><td>Not relevant (processing within EU/EEA)</td><td>​<a href="https://www.mailgun.com/gdpr/">View</a>​</td><td>​<a href="https://drive.google.com/file/d/1gZ7Co8Aus3wBZcic3RK0AGJcAQqwoJ1d/view?usp=sharing">View</a>​</td></tr><tr><td><strong>OnlineCity ApS</strong></td><td>GatewayAPI</td><td>EU/EEA</td><td>SMS Services</td><td>Phone number, internal Appfarm identifier</td><td>​Deleted after 30 days</td><td>Optional</td><td>Denmark</td><td><p>Buchwaldsgade 50,</p><p>5000 Odense C</p></td><td>​<a href="https://gatewayapi.com/blog/business/2018/05/15/blog-on-gdpr.html">View</a>​</td><td>Not relevant (processing within EU/EEA)</td><td>​<a href="https://blog.gatewayapi.com/new-eu-ruling-impacts-your-choice-of-an-sms-gateway-learn-why/">View</a>​</td><td>​<a href="https://drive.google.com/file/d/1mNlgcfnR-QBcTahxx3qR-4-aNFVsKNg-/view?usp=sharing">View</a>​</td></tr><tr><td><strong>MongoDB Limited</strong></td><td>MongoDB Cloud</td><td>Belgium</td><td>Database services</td><td>Given name, surname, email address, company name, all data stored through Appfarm Create and the applications created on the platform</td><td>**</td><td>Integrated</td><td>Ireland</td><td><p>3 Shelbourne Building, 3rd floor</p><p>Crampton Avenue</p><p>Ballsbridge</p><p>Dublin 4</p></td><td>​<a href="https://www.mongodb.com/cloud/trust/compliance/gdpr">View</a>​</td><td>Not relevant (processing within EU/EEA)</td><td>​<a href="https://www.mongodb.com/cloud/trust/compliance/gdpr">View</a>​</td><td>​<a href="https://www.mongodb.com/legal/dpa">View</a>​</td></tr><tr><td></td><td></td><td></td><td><sub>Appfarm AI data storage</sub></td><td><sub>AI prompt history and feedback</sub></td><td><sub>**</sub></td><td><sub>Optional</sub></td><td></td><td></td><td></td><td></td><td></td><td></td></tr><tr><td><strong>Amazon Web Services EMEA SARL</strong></td><td>Amazon Web Services</td><td>Sweden</td><td>Cloud infrastructure for servers and databases. Email.</td><td>IP-address and email address</td><td>**</td><td>Integrated</td><td>Luxembourg</td><td><p>38 avenue John F. Kennedy </p><p>L-1855 Luxembourg, R.C.S. Luxemburg: B186284</p></td><td>​<a href="https://aws.amazon.com/compliance/gdpr-center/">View</a>​</td><td>Not relevant (processing within EU/EEA)</td><td>​<a href="https://aws.amazon.com/compliance/eu-data-protection/">View</a>​</td><td>​<a href="https://d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdf">View</a>​</td></tr><tr><td><strong>Google Cloud EMEA Limited</strong></td><td>Google Cloud Platform</td><td>Belgium</td><td>Cloud infrastructure for servers and databases</td><td>IP-address and email address</td><td>**</td><td>Integrated</td><td>Ireland</td><td><p>Gordon House</p><p>Barrow Street </p><p>Dublin 4</p></td><td>​<a href="https://cloud.google.com/privacy/gdpr">View</a>​</td><td>Not relevant (processing within EU/EEA)</td><td>​<a href="https://cloud.google.com/privacy/gdpr">View</a>​</td><td>​<a href="https://cloud.google.com/terms/data-processing-addendum">View</a>​</td></tr><tr><td><strong>Twilio Ireland Limited</strong></td><td>Twilio Sendgrid</td><td>USA *****</td><td>Email handling and email address validation</td><td>Email address and other data used in email body</td><td>​***</td><td>Integrated</td><td>Ireland</td><td><p>3 Dublin Landings</p><p>North Wall Quay</p><p>Dublin 1</p></td><td><a href="https://sendgrid.com/resource/general-data-protection-regulation-2/">View</a></td><td>YES</td><td><a href="https://sendgrid.com/resource/general-data-protection-regulation-2/">View</a></td><td><a href="https://drive.google.com/file/d/1obdCOAuFyTDSKQOLrQpHW6fPy6azDWDa/view?usp=sharing">View</a></td></tr><tr><td><strong>Heap, Inc.</strong></td><td>Heap </td><td>USA *****</td><td>Product usage analytics</td><td>Pageviews, user interactions, timing, IP address, browser details</td><td>****</td><td>Integrated</td><td>USA</td><td><p>225 Bush St. 2nd floor </p><p>San Francisco, CA 94104</p></td><td><a href="https://www.heap.io/blog/heaps-commitment-to-gdpr-and-data-privacy">View</a></td><td>YES</td><td></td><td><a href="https://drive.google.com/file/d/1aSO8N-blAdfMfHG_xDzur0FfAHRV_cuq/view">View</a></td></tr><tr><td><strong>Docspring, Inc.</strong></td><td>Docspring</td><td>EU/EEA</td><td>PDF-generator API Service </td><td>Appfarm client specific PDF-data</td><td>Up to 7 days</td><td>Optional</td><td>USA</td><td><p>2035 Sunset Lake Road, Suite B-2</p><p>Newark, Delaware 19702</p></td><td><a href="https://docspring.com/privacy">View</a></td><td></td><td></td><td></td></tr></tbody></table>

*\* Data is sent to the service location (Cloudflare edge node) closest to the user. For users in Norway, this is Oslo; in other countries, it is most likely the country of origin.*

*\*\* Customer data is continuously stored (and backed up) as long as the customer has an active Appfarm subscription. Customer data is stored up to 1 year after a subscription is canceled (if not otherwise instructed by the customer) to facilitate the customer's data transfer procedures.*

*\*\*\* Most data is deleted automatically according to Twilio's* [*retention schedule*](https://support.twilio.com/hc/en-us/articles/4410585868443-Data-Retention-and-Deletion-in-Twilio-Products#h_01FMXDYRR2N4RDECNP69Q9HAME) *within a maximum of 37 days. Twilio does retain some email event data in pseudonymized form (not including the message body content) for up to a year for security, fraud detection, anti-abuse, and network protection purposes.*

*\*\*\*\*  Data is stored in accordance with Appfarm’s privacy policy at* [*https://www.appfarm.io/privacy*](https://www.appfarm.io/privacy)*.*

\*\*\*\*\* Company is part of the Data Privacy Framework or has adequate safeguards for data transfer such as SCC.

***

## **Third-party data processors for Appfarm AI processing AI interaction data** <a href="#third-party-subprocessors-for-the-appfarm-platform-the-service-processing-customer-personal-data" id="third-party-subprocessors-for-the-appfarm-platform-the-service-processing-customer-personal-data"></a>

Appfarm and its affiliates engage the following third-party entities to assist in connection with Appfarm AI as specified below:

<table data-full-width="true"><thead><tr><th width="211">Entity Name</th><th width="100">Service</th><th width="159">Service location</th><th width="239">Task performed</th><th width="293">Type of data stored</th><th width="100">Storage period</th><th>Type</th><th width="208">Country of registration</th><th width="226">Registered address</th><th width="209">GDPR compliance</th><th data-hidden>Participant in Data Privacy Framework</th><th data-hidden>Schrems II</th><th data-hidden>Link to DPA</th></tr></thead><tbody><tr><td><strong>Google Cloud EMEA Limited</strong></td><td>Gemini</td><td>EU/EEA</td><td>AI language model services</td><td>None</td><td>N/A</td><td>Optional</td><td>Ireland</td><td><p>Gordon House</p><p>Barrow Street </p><p>Dublin 4</p></td><td>​<a href="https://cloud.google.com/privacy/gdpr">View</a></td><td></td><td></td><td></td></tr><tr><td><strong>Google Cloud EMEA Limited</strong></td><td>Vertex AI</td><td>Global *</td><td>Hosting services for AI language models</td><td>None</td><td>N/A</td><td>Optional</td><td>Ireland</td><td><p>Gordon House</p><p>Barrow Street </p><p>Dublin 4</p></td><td>​<a href="https://cloud.google.com/privacy/gdpr">View</a></td><td></td><td></td><td></td></tr><tr><td><strong>OpenAI Inc.</strong></td><td>GPT</td><td>EU/EEA</td><td>AI language model services</td><td>None</td><td>N/A</td><td>Optional</td><td>USA</td><td>1455 3rd Street, San Francisco, CA 94158</td><td><a href="https://openai.com/enterprise-privacy/">View</a></td><td></td><td></td><td></td></tr><tr><td><strong>Anthropic, PBC</strong></td><td>Claude </td><td>Global *</td><td>AI language model services</td><td>None</td><td>N/A</td><td>Optional</td><td>USA</td><td>548 Market Street, PMB 90375, San Francisco, CA 94104 </td><td><a href="https://privacy.claude.com/en/collections/10663361-commercial-customers">View</a></td><td></td><td></td><td></td></tr></tbody></table>

\* Uses Google's currently most available Vertex AI endpoint, which can be either Belgium Europe, Ohio in the USA, or Singapore in Asia.

***

## Updates

As our business grows and evolves, the data processors we engage may also change. We will endeavor to provide the owner of the Customer's account with notice of any new data processors to the extent required under the Agreement, along with posting such updates here. Please check back frequently for updates.

### 2025-10-30: Data processor table updates

We've reorganized our data processors page to improve clarity:

* We've created a separate table for data processors involved with Appfarm AI. These AI service providers process prompts and return results but do not store user data.
* We've added a row under MongoDB Limited to specify what data is stored when customers use Appfarm AI.

### 2025-10-08: Additional data processors

As of today, Appfarm has added new data processors to its list. The new processors are:&#x20;

* OpenAI, Inc.: providing the AI model OpenAI API.
* Anthropic, PBC: providing the AI model Claude Sonnet.

In addition to these two, Appfarm has also added two new services provided by an existing processor:

* Vertex AI: AI model hosting service provided by Google Cloud EMEA Limited
* Gemini:  AI model provided by Google Cloud EMEA Limited

These are all services involved in our newly launched AI services for Appfarm Create, and are strictly optional.

The AI models mentioned above process data through AI prompts, but do not store data through these services. The data is handled and stored as regular user data in Appfarm Create, and follows the rules and is set up as other user data regarding the Service.

Vertex AI is used to host language models in a Google Cloud Environment, powering AI models, such as Claude Sonnet. Appfarm is currently running Vertex AI with multi-region to ensure the best possible availability of the AI services. Our team is working closely with Google to offer Vertex AI on EU/EEA only servers.

### 2025-06-12: Updates to our data processors

Appfarm has, as of today, updated its data processor list based on recommendations from an independent third-party privacy assessment from legal counsel and requests from customers. The objective is to improve clarity, relevance, and transparency for customers and users:

* We’ve moved data processors not directly tied to the Service (the Appfarm Platform) to our [Privacy Policy](https://www.appfarm.io/privacy) as they are not related to Appfarm's role as a data processor to our customers.
* We’ve introduced a new category, "Type", in the list of data processors to indicate whether the relevant service is integrated with the Service or optional. Optional services are available as a voluntary opt-in by Appfarm Create users. GatewayAPI and Docspring have been marked as optional.
* We've reorganized asterisk markers to improve readability and logic.
* We've removed outdated columns (including Schrems II article links and signed DPA links) due to low relevance and high maintenance overhead.

We continue to prioritize data protection, transparency, and customer control.

### 2025-06-12: Addition of new data processor

Appfarm has, as of today, added a new data processor to the list:

* Docspring, Inc: an optional service used for API-based generation of PDF documents

### 2023-11-13: Additional data processors

Appfarm has, as of today, added new data processors to the list. The new processors are:&#x20;

* Twilio, Inc.: an email handling and email address validation system, connected to the Service. Twilio is a participant in the Data Privacy Framework (DPF),
* Zendesk, Inc.: a customer support system,
* Hotjar Ltd.: an analytics tool used on Appfarm's website.

The following companies listed as data processors have, since the last update, become participants of the DPF:

* Notion Labs, Inc.

### **2023-09-07: Update on the Data Privacy Framework**

The EU–US Data Privacy Framework is a transatlantic data transfer framework between the United States and the European Union. The European Commission adopted its [adequacy decision](https://ec.europa.eu/commission/presscorner/detail/en/qanda_23_3752) for the framework on July 10, 2023. The adequacy decision concludes that the United States ensures an adequate level of protection for personal data transferred from the EU to companies participating in the EU-U.S. Data Privacy Framework. With the adoption of the adequacy decision, European entities are able to transfer personal data to participating companies in the United States without having to put in place additional data protection safeguards. Although Appfarm has put in place necessary safeguards (e.g., standard contractual clauses) with all US-based data processors outlined above, this decision will apply to all US-based data processors participating in the framework as the US is now considered a [secure third country](https://gdpr-info.eu/issues/third-countries/#:~:text=Secure%20third%20countries%20are%20those,to%20those%20of%20EU%20law.) under GDPR.

The following companies listed as data processors in a third country currently not listed in the Data Privacy Framework are:

* Mailgun Technologies, Inc.
* Notion Labs, Inc.
* Docspring, Inc.
* Civilized Discourse Construction Kit, Inc.
* EdInvent, Inc.

Appfarm has engaged in dialog with the companies in question regarding their timeline to get registered on the list of the Data Privacy Framework.

### **2023-01-02: Removal of Atlassian, Inc. as data processors**

**‍**Appfarm has discontinued use of Atlassian Inc. and their service Trello.

### **2022-12-13: Addition of new data processors**

Appfarm has added new data processors in order to provide our existing and prospective customers, users, and partners with an improved and more comprehensive product offering:

* Notion Labs, Inc. (with its service Notion): Internal communication tool, process management, and project management system.
* Contractbook ApS (with its service Contractbook): Contract management platform
* Webflow, Inc. (with its service Webflow): Website services
* Civilized Discourse Construction Kit, Inc. (with its service Discourse): Community and forum platform used to organize engagement and processes
* Docspring, Inc. (with its service Docspring):  PDF template management and API service
* Teamtailor AB (with its service Teamtailor): Applicant tracking system

None of these new data processors are directly connected to the Service but offer services Appfarm uses for auxiliary business activities, of which some customer data may be processed.

### **2022-11-29: Freshworks, Inc. has been removed as a data processor**

Appfarm has, as of today, discontinued Freshworks, Inc. and its service Freshworks as a data processor.

### **2022-04-25: Added EdInvent, Inc. and Mettl Technologies, Inc. as new processors**

Appfarm has, as of today, added EdInvent, Inc. and Mettl Technologies, Inc. as new data processors. Both vendors are used in relation to our certification program and are not connected to the Service.

### **2022-04-20: Added Hubspot as a** data processor

Appfarm has, as of today, added HubSpot, Inc. as a new data processor. Hubspot is used as a customer relationship management (CRM) system and is not connected to the Service. HubSpot offers [regional data hosting](https://legal.hubspot.com/hubspot-regional-data-hosting-policy), and all data is located in HubSpot’s product infrastructure hosted on Amazon Web Services (AWS) in Germany.

### **2021-08-17: Added AWS as a** data processor

Appfarm has, as of today, added Amazon Web Services (AWS) as a new data processor for the Service processing Customer personal data. The current use of AWS in the Service will be restricted to the use of the Amazon Simple Email Service (SES). Other AWS services may be used at a later time.

The reason for the change is that several Appfarm customers have, at times, experienced poor delivery times with the internal Appfarm email service, which, among others, is used for the delivery of PIN codes for user authentication purposes. The Appfarm engineering team has concluded that the current vendor and data processor (Mailgun Technologies) should be replaced with a more reliable service to secure the highest service quality of the Service.

All Appfarm customers have been notified of the change. In line with the Appfarm Data Processing Agreement (section 7.2), the new data processor will not take effect and become active in use in the Service until 30 days (September 17th, 2021) if not otherwise instructed by Appfarm customers.

### **2021-01-29: International Data Transfers**

Although, in the light of European Court of Justice decision C-311/18 (Schrems-II), in which Privacy Shield as grounds for data transfers to third countries was invalidated, Appfarm is still ensuring that its third-party data processors are compliant with the GDPR framework, either by implementing Standard Contractual Clauses ensuring the same level of protection for its users or similar grounds accepted by the EDPB. This includes but is not limited to, already existing service providers and service providers in the future.


# Responsible Disclosure Policy

This web page represents a legal document with terms and conditions applicable to all individuals who intend to research information security vulnerabilities on Appfarm AS assets.

## **The Submission Process**

If you believe you have found any vulnerabilities in assets defined in the scope, a thorough report can be submitted to <security@appfarm.io>.

A member of our security team will then review the report and get back to you, normally within a week. Depending on the criticality of the report, response time will vary.

## Triage

We’re always interested in hearing about any reproducible vulnerability that affects the security of users, including:

* Remote Code Execution (RCE)
* SQL Injection (SQLi)
* Server Side Request Forgery (SSRF)
* Cross-Site Request Forgery (CSRF)
* Cross-Site Scripting (XSS)

We are generally not interested in reports pointing out the following issues:

* HTTP sniffing or HTTP tampering exploits
* Open API endpoints serving public data
* Brute force, DoS, DDoS, phishing, text injection, or social engineering attacks.
* Output from automated scans
* Clickjacking with minimal security implications
* Missing DMARC records or other email headers
* Missing CAA
* URL Injection with minimal security impact.
* Missing webpage headers
* Missing rate-limiter
* Content Spoofing with minimal impact or relevance

Reports containing findings on our not-wanted list will be closed without a response.

## **Scope**

Currently, all Appfarm services run on the following domains and subdomains:

* appfarm.io
* \*.appfarm.io

Potential problems with our sub-processors will be forwarded to the responsible party so they can evaluate the report.

When testing our self-sign-up sandbox service, researchers are limited to signing up and activating only one environment. Researchers disregarding this restriction will be disqualified.

## **Reward**

We do not currently have any set prices for reports that we receive. We do not offer monetary rewards, but we do offer swag if we believe that a report provides valuable information for our organization.


# Platform Security & Compliance

Appfarm uses a combination of enterprise-class security features, industry best practices, and comprehensive audits to ensure data protection.

## Compliance

<details>

<summary>Security compliance</summary>

**ISO 27001:2022 Certification**

Appfarm is ISO 27001:2022 certified for a three-year period from December 2023–December 2026

</details>

<details>

<summary>Artifacts</summary>

Our ISO 27001:2022 certificate can be requested at our [Trust Center](https://trust.appfarm.io/).

</details>

<details>

<summary>Trust Center</summary>

To learn more about how Appfarm remains compliant, please visit our [Trust Center](https://trust.appfarm.io/), which tracks ISO 27001:2022 controls and other security-related compliance.

</details>

## Cloud Security

<details>

<summary>Data center physical security</summary>

**Facilities**&#x20;

Appfarm hosts all Service Data in Google Cloud data centers. Google Cloud Platform has been certified as ISO27001,  PCI DSS level 4, and SOC 2 compliant. Read more about [compliance at Google Cloud](https://cloud.google.com/compliance?hl=en).

**On-site security**

Google Cloud on-site security includes features such as security guards, fencing, intrusion detection systems, security feeds, comprehensive camera coverage, and other security measures. Read more about [Google Cloud on-site security](https://www.google.com/about/datacenters/data-security/).

**Data hosting location**

Appfarm leverages services at Google Cloud running in Belgium.

</details>

<details>

<summary>Vendor security</summary>

Appfarm minimizes the risk associated with third-party service providers by performing reviews on all vendors with any level of access to Appfarm's systems or data. These reviews are revised annually.

</details>

<details>

<summary>Network security</summary>

**Protection**

Our cloud network is protected by several Google Cloud Platform security services, regular security audits, and network intelligence technologies, which monitor and/or block unknown malicious traffic and network attacks.

**Architecture**

Our network security architecture is set up through layers of security using the principle of least privilege. Services run with only the privileges required to perform the tasks intended. Our Kubernetes clusters run in a zero-trust environment, allowing only intended functionality and communication and isolating customers from each other. Strict network policies further isolate services from each other.

**Third-party security audits**

In addition to an in-house security team that performs regular security audits in the development cycle, Appfarm also employs annual security audits by third-party security specialists. The audit consists of a complete whitebox audit of the Service, including access to the cloud environment.

**Network vulnerability scanning**

Security Health Analytics, Rapid Vulnerability Detection, Workload Vulnerability Scanner, and Web Security Scanner give Appfarm comprehensive knowledge and insight to quickly identify out-of-compliance or potentially vulnerable systems and services.

**Intrusion detection and prevention**

Ingress and egress traffic is monitored, detecting anomalous behavior. The systems are configured to generate alerts when incidents and values exceed predetermined thresholds.&#x20;

**Threat intelligence program**

Appfarm participates in several threat intelligence programs, and our information security team is active in the cyber security community. Threats that occur are monitored, and action is taken based on risk.

**DDoS mitigation**

All Appfarm services running in Google Cloud Platform run behind Google load balancers. These load balancers are protected by Google Cloud Armor, which has many security features, including DDoS protection.

**Logical access**

Appfarm runs a least-privileged environment, where access to the Appfarm production network is restricted to only personnel who require access to maintain the running of the Service. Multi-factor authentication is required for all services connected to Appfarm systems.

**Security incident response**

In case of a system alert, events are escalated to our Cloud or Security team. Employees are trained on security incident response processes, including communication channels and escalation paths.

**Logging and monitoring**

Appfarm collects extensive access and traffic logs on the service and cloud environment, and log retention is set to 30 or 400 days depending on the log type. Alerts are set up to detect suspicious behavior or performance issues and are immediately handled by the cloud or development teams.

</details>

<details>

<summary>Encryption</summary>

**Encryption in transit**

All communication with Appfarm endpoints is encrypted via industry-standard HTTPS/TLS over a public network. Appfarm regularly performs scans on our public endpoints, evaluates TLS configurations, and upgrades them if needed to maintain the highest level of information security in transit.

**Encryption at Rest**

Service data is encrypted at rest in Google Cloud using AES-256 key encryption.

</details>

<details>

<summary>Availability and continuity</summary>

**Uptime**

Appfarm maintains a publicly available [status page](https://status.appfarm.io/), which includes system availability details, scheduled maintenance, service incident history, and relevant security events.

**Redundancy**

By running in Google Cloud Platform on a regional basis, Appfarm is protected through Google's redundancy services in multiple geographical locations.  The applications run in multi-zone Kubernetes, and the databases run by default on three different nodes in different zones. Our strict backup regime, including regular backup tests, and our business continuity plan allow us to deliver a high service availability in compliance with agreed-upon SLAs.

**Business continuity and disaster recovery**

Our Business Continuity and Disaster Recovery Plan ensures that our services remain available and are easily recoverable in case of a disaster. The plan is tested regularly to identify areas of improvement and provide training to personnel.

**Backup in alternative cloud**

Appfarm runs a backup of the version control system at an alternative cloud provider to avoid relying on only one cloud provider. This allows us to start operations elsewhere in a reasonable timeframe in the case of an unforeseen event at our main cloud provider.&#x20;

</details>

## Application Security

<details>

<summary>Secure Development Lifecycle</summary>

**Secure code training**

All engineers go through mandatory secure coding training based on the OWASP Top 10 framework and ASVS.

**Version control**

Appfarm employs a version control system for coding, with mandatory code reviews for changes that also take into account information security requirements.

**Quality assurance**

Appfarm's Quality Assurance department tests the codebase, and an in-house security team performs security tests on new and existing functionality added to the Service. Automatic tests are implemented in the codebase to ensure code changes don't introduce new bugs.

**Separate environments**

For development purposes, Appfarm runs four different environments; Development, Test, Staging, and Production. Only the Production environment contains data from customers.

</details>

<details>

<summary>Vulnerability management</summary>

**Dynamic vulnerability scanning**

Appfarm runs third-party security tools that dynamically scan Appfarm Create regarding, but not limited to, OWASP's Top 10 security risks. Our in-house product security team tests and works with the engineering team to discover and remediate issues.

**Software composition analysis**

Libraries and dependencies used in the Appfarm Service are scanned to identify vulnerabilities and ensure they are mitigated.

</details>

## Product Security

<details>

<summary>Authentication security</summary>

**Appfarm Create authentication**

Appfarm Create has several different options for authentication: one-time password, SSO with Google, and username and password.\
\
**Appfarm Client authentication**

The Appfarm Client has several different options for authentication: one-time password, login link, SSO with custom identity provider using OpenID Connect, and username and password.

**Credential storage**

Appfarm follows security best practices by only storing passwords in salted one-way hashes with SCRYPT and never in a human-readable format.

</details>

<details>

<summary>Role-based access controls</summary>

Appfram Create has an extensive system for controlling [permissions](https://docs.appfarm.io/reference/security/permissions) and [roles](https://docs.appfarm.io/reference/security/roles). Appfarm has built-in roles that maintain "security by default" practices and also allows for custom roles to be made. More information about permissions and roles can be found in the [Appfarm documentation](https://docs.appfarm.io/reference/security).

</details>

<details>

<summary>Secrets</summary>

To allow our versatile platform to communicate and integrate with external systems, [secrets](https://docs.appfarm.io/reference/security/secrets) can be used to store sensitive values. Secrets are only available server-side and are not available in the Appfarm Client.&#x20;

</details>

## HR Security

<details>

<summary>Security awareness</summary>

**Policies**

Appfarm has developed a comprehensive collection of security policies to cover everything to ensure security in the day-to-day operations of the company. All employees and contractors with access to Appfarm information assets read and accept these policies.

**Training**

All employees attend Security Awareness Training, which is given upon hire and renewed annually. Certain personnel also attend extra specialized training designed for their explicit roles and responsibilities. The Appfarm Security team provides additional awareness updates via email, Slack groups, and presentations during internal events.

</details>

<details>

<summary>Employee vetting</summary>

**Confidentiality agreements**

All new hires are required to sign non-disclosure and confidentiality agreements.

</details>


# Product Glossary

## Platform Concepts

The following key concepts related to the Appfarm platform are relevant to every product subscription tier and are fundamental to evaluate platform capabilities and commercial arrangements.

### Appfarm Create

A modern, full-stack, web-based tool for the design, development, and management of cloud-based software in the form of progressive web applications (PWAs). Appfarm Create provides full flexibility to express complex visual designs, functionality, and integrations tailored to an organization’s unique needs and circumstances. Appfarm Create is made available, and used directly, through modern web browsers. All customers have access to Appfarm Create, regardless of whether the subscription is with Appfarm directly or through a certified Appfarm partner in a reseller agreement.

* [Getting started with Appfarm](https://docs.appfarm.io/getting-started/what-is-appfarm)
* [Documentation: Appfarm Create](https://docs.appfarm.io/reference/appfarm-create)

### Appfarm Cloud

The managed cloud infrastructure designed exclusively for the deployment, hosting, and maintenance of software created with Appfarm Create. In the Subscription Agreement, the Appfarm Cloud may be referred to as the Appfarm Platform. Together, Appfarm Create and Appfarm Cloud are typically referred to as “the Service” in our legal agreements with customers.

### Appfarm AI

The umbrella term for AI capabilities integrated within Appfarm Create that enable conversational development and AI-assisted application building. Appfarm AI operates through two distinct modes:

**Build mode** provides conversational development functionality, allowing users to build and modify applications by describing business requirements in natural language. The agent orchestrates subagents to generate transparent visual models and applications based on these descriptions, consuming [AI Credits](#ai-credits) for each development session.

**Ask mode** provides free AI assistance grounded in Appfarm documentation and best practices, helping users understand platform capabilities and implementation approaches without consuming credits.

Appfarm AI enables rapid application development while maintaining the visual transparency and enterprise governance that distinguish Appfarm from traditional code generation tools. All AI-generated applications remain fully visible and editable within the standard Appfarm Create interface.

* [Documentation: Appfarm AI](https://docs.appfarm.io/reference/appfarm-ai)

### Solution

A distinct development environment for creating and managing [Apps](#app) (responsive web apps for mobile, tablet, and desktop interfaces) and [Services](#service) (server-side workflows) and [Flows](#flow) (reusable server-side logic) that rely on a shared global data model. A Solution features advanced configuration across many dimensions as well as user management possibilities.

The definition of a Solution’s global data model, Apps, Services, Flows and other Solution-specific metadata generated within Appfarm Create, is referred to as the *solution model*.

A Solution can run up to four deployment environments for development, testing, and production purposes. Apps and Services deployed from within the same Solution share a common root URL. For example, *yoursolution.appfarm.app* or a [custom domain](#custom-domain).

Each Solution is provisioned with four separate databases: one for each of the Development, Test, and Production environments, and one for solution metadata. These databases reside on shared database infrastructure managed and optimized by Appfarm, where resources such as CPU, memory, and connections are pooled across multiple customers. Each of the customer's databases is isolated through access controls, while the underlying database infrastructure is shared. Organizations that require dedicated resources, custom configuration, or stronger isolation can opt for [dedicated database infrastructure](#dedicated-database-infrastructure).

Each subscription tier includes one or more Solutions. A Solution can manage a principally unlimited number of apps, users, and integrations. Organizations on any subscription tier can purchase additional Solutions beyond their included allocation to facilitate differing development needs across and within departments. The purchase of an additional Solution includes an increased quota of Apps for the subscription, where relevant, and an upfront grant of [AI credits](#ai-credits) for the new Solution.

When a subscription includes multiple Solutions:

* Allocated resources are shared across all Solutions. This encompasses the number of Apps, Active Users, Database and File Storage, API Integrations, and other resources outlined in the Subscription Agreement.
* Platform capabilities are mirrored in all Solutions based on the subscription tier. For example, an organization on the Essential subscription tier with multiple Solutions will have Essential tier capabilities available in each Solution.

The amount of cloud resources allocated to a Solution is determined by subscription tier. These resources are distributed across your Solution infrastructure in accordance with actual utilization and scale dynamically to stabilize performance under increased load. Resource allocation and scaling are further described in the [Acceptable Use Policy](/service-and-usage/acceptable-use-policy).

* [Documentation: Data model](https://docs.appfarm.io/reference/data-model)

### Environment

A deployment environment for a Solution’s Apps, Services and Flows. Up to four environments are available: Development, Test, Staging, and Production. Each environment has its own URL, database, and configuration, with the exception of Staging, which uses the Production database as per usual practice. The Production environment is allocated a significantly higher percentage of a Solution’s available cloud resources.

As changes are made in Appfarm Create, they are instantly deployed to the Development environment. In order to push changes to another environment, they can be manually deployed with one click, either instantly or at a scheduled time.

[Registered users](#users) exist across all environments, but access can be restricted and controlled as required.

Each subscription tier is allocated a given number of environments.

* [Documentation: Environments](https://docs.appfarm.io/reference/operations/deploy#environments)

### App

An end-user application. An App is a fully customizable responsive web app composed of a user interface, data sources, and logic. Data sources provide access to the data in the shared global data model as well as other application-specific data. Actions enable application flow and business logic. The user interface is connected to data sources and actions to display data and collect and respond to user input.

A fundamental feature of Appfarm is that there are no restrictions on application complexity in any subscription tier. Apps can be restricted to internal use, opened to external registered users such as customers and suppliers, or made publicly available with unauthenticated access. Apps can be restricted based on interface (mobile, tablet, desktop) or be configured and offered on all interfaces with responsive design capabilities.

There are **no restrictions on the complexity** of an App, although it is common and recommended to create separate apps for different user groups or purposes. For example, a mobile app for data collection in the field and a desktop app for analysis and reporting.

There are **no restrictions on the number of integrations** that can be implemented in an App (or Service). There is also no limit on the number of requests sent to external API endpoints.

Each subscription tier is allocated a given number of Apps, and additional Apps are available for purchase through App Bundles. The number of Apps in a Solution is calculated based on the maximum number of applications in use within a calendar month. The Dedicated subscription tier includes an unlimited number of Apps. Apps not deployed outside the Development environment (“Dev Only Apps”), and apps made available only for [Developer users](#users) (“Config Apps” and “Admin Apps”), are not counted for billing purposes.

* [Documentation: Apps](https://docs.appfarm.io/reference/apps)

### Service

A fully customizable server-side workflow to automate business logic and/or provide a flexible API. A Service is composed of one or more HTTP endpoints, data sources, and logic. An endpoint acts as the external interface of the service, defining the request format, facilitating which data is returned in response, and what logic is to be run.

Services can be triggered by external API calls (including webhooks), by schedules, or by other Services and Apps.

* [Documentation: Services](https://docs.appfarm.io/reference/services)

### Flow

A fully customizable server-side workflow to reuse business logic across the Apps in a Solution, provide a flexible API, and/or expose business logic as MCP servers. A Flow is composed of one or more actions, each of which defines the inputs it accepts, the logic it runs, and the outputs it returns.&#x20;

Flows can be triggered by external API calls (including webhooks), by an MCP client, by schedules, or by other Flows and Apps.

* [Documentation: Flows](https://docs.appfarm.io/reference/flows)

### Users

A user is categorized into one of three groups.

1. **Developer user:** A user with access to Appfarm Create. This includes both built-in roles (Owner, Maintainer, Developer) and custom roles granted permission to access Appfarm Create.
2. **Registered user:** A user with an account registered in a Solution. Registered users include developer users.
3. **Guest user:** A user that interacts with a public App without having an authenticated user session.

#### **Active Users**

A registered user that has had at least one authenticated user session in Appfarm Create or any environment within a calendar month. For subscriptions that include multiple Solutions, active users are counted uniquely across all Solutions within that subscription.

For billing purposes, Appfarm prefers counting active registered users. We believe that active registered users are a fairer and more customer-oriented metric compared to simply registered users, which is better connected to value created and return on investment for the customer. It also facilitates, without escalating costs, solving use cases that can potentially reach many registered users but with a low number of expected active users per month. Appfarm does not separate between internal and external users.

Each subscription tier is allocated a quota of active users. The activity of guest users does not count towards your subscription's active user quota.

Additional users are available for purchase through Active User Bundles. Active User Bundles follow a volume-based pricing structure, meaning that the price for additional active users becomes lower as the total number of active users increases.

***

## Subscription Tier-Based Resource Quotas

The resource quota granted for each of the following platform resources is determined by subscription tier.

### AI Credits

The usage-based credit allocation for [Appfarm AI](#appfarm-ai), which enables conversational development of applications through natural language descriptions.

Credits are consumed when the agent creates development plans and generates application changes based on user requirements. AI credit consumption varies based on the complexity of the development request and the scope of application modifications being generated. Ask mode does not consume credits.

Each new subscription includes an initial quota of AI credits, granted upfront. AI credits apply at the Solution level. For organizations on the Dedicated subscription tier with access to multiple Solutions, the included credits apply by default to the primary Solution.

If a subscription is upgraded to a higher tier, the Solution will be granted the difference in the quota of AI credits allocated to the two tiers.

Additional AI credits can be purchased on demand as needed from within a Solution with access to Appfarm AI. Additional AI credits are valid as long as the subscription remains active and are non-refundable. The purchase and usage of AI credits is subject to the [Terms of Use](/service-and-usage/ai-credits-terms-of-use).

* [Documentation: AI credits](https://docs.appfarm.io/reference/appfarm-ai/ai-credits)

### API Integrations

An API integration is classified by the destination of the HTTP request. There are **no restrictions on the number of integrations** that can be implemented in an App or Service.

* **External integration**: Outbound HTTP requests sent to external API endpoints. For example to send data to, or retrieve data from, a third-party CRM, ERP, or database.
* **Solution integration:** Inbound HTTP requests received by a Solution API endpoint. Solution API endpoints include custom-defined endpoints (Services) and built-in endpoints (for example, Time Series, Data Extract, and GraphQL). Requests include those generated from external hosts, scheduled Services in Appfarm, and other Services and Apps. Solution integrations are subject to Appfarm’s [Acceptable Use Policy](https://policies.appfarm.io/policies/acceptable-use-policy#limits-by-subscription-tier).

API integration quotas are defined in four tiers.

<table><thead><tr><th width="218">Integration</th><th width="119">Tier 1</th><th width="124">Tier 2</th><th width="128">Tier 3</th><th>Tier 4</th></tr></thead><tbody><tr><td><strong>External (outbound)</strong></td><td>Unlimited</td><td>Unlimited</td><td>Unlimited</td><td>Unlimited</td></tr><tr><td><strong>Solution (inbound),</strong><br><strong>per 24 hours*</strong></td><td>500</td><td>1.500</td><td>15.000</td><td>50.000</td></tr></tbody></table>

\*A higher allocation may be accommodated by custom agreement.

* [Documentation: Integrate with external systems](https://docs.appfarm.io/how-to/integrations/integrate-with-external-systems)

### Archive Files

The integrated file archive component enables the creation of archive files (.zip files) containing one or more files stored in file objects. Developers can configure file hierarchy within an archive file through fully customizable file names and file paths. Each Solution can archive up to 1 GB of input files per month using the integrated component. This quota is measured based on the total size of source files being archived, not the resulting archive size. Increased quotas for high-volume usage can be purchased. Archive files can be downloaded or stored as a file object. Archive files stored as file objects count towards a Solution’s [file storage](#file-storage) allocation.

* [Documentation: Create file archive](https://docs.appfarm.io/library/action-nodes/create-file-archive)

### Database Storage

The amount of database storage dedicated to Solution data read and manipulated by Apps and Services. For example, customer data, order data, or project data. Files uploaded in file objects are not included (see File storage). Each subscription tier is allocated a certain amount of database storage, and additional storage can be purchased.

<table><thead><tr><th width="250.1171875"></th><th width="150.359375">Essential</th><th width="149.9765625">Professional</th><th width="150.01953125">Dedicated</th></tr></thead><tbody><tr><td><strong>Allocated database storage</strong></td><td>1 GB</td><td>3 GB</td><td>10 GB</td></tr></tbody></table>

### File Storage

The amount of database storage dedicated to files uploaded in file objects from Apps and Services, and static resource files uploaded under Files in Appfarm Create. Example files include pictures (e.g., JPEG, PNG), documents (e.g., DOCX, PDF), and spreadsheets (XLSX, CSV). Each subscription tier is allocated an amount of file storage, and additional storage can be purchased.

* [Documentation: File objects](https://docs.appfarm.io/reference/data-model/object-classes#file-object-class)
* [Documentation: Files](https://docs.appfarm.io/reference/resources/files)

### Messaging Services

Integrated messaging services to send email and SMS messages from Apps and Services. Use of these services is subject to Appfarm’s [Email, SMS, and Integrated Messaging and Notification Policy](/service-and-usage/esin-policy) (ESINP).

#### **Email**

Each Solution can send up to 500 emails per month using the integrated email component, with no additional configuration, via the default Appfarm email service. To send emails in excess of this limit, and to apply further customization, a [custom email provider](https://docs.appfarm.io/reference/configuration/environments#email-settings) must be configured within Appfarm Create. A custom email provider can be easily configured for each enabled [environment](#environment).

#### **SMS**

Each Solution can send up to 50 SMS messages per day and up to 500 SMS messages per month using the integrated SMS component. Refer to the documentation for sending SMS for information on how the amount and type of characters can affect the number of messages sent. A higher quota of SMS messages can be arranged upon request.

* [Documentation: Send SMS](https://docs.appfarm.io/library/action-nodes/send-sms)

***

## Subscription Tier-Based Platform Capabilities

The right to use the following platform capabilities is determined by subscription tier.

### Advanced Data Visualization

A collection of premium UI components with advanced customization options for visualizing data, including Heatmap and Gantt charts. Any use of advanced charting in billable applications will trigger the additional monthly fee (if not already included in your subscription tier). Basic charting capabilities are included in all subscription tiers.

* [Documentation: Advanced Charts](https://docs.appfarm.io/library/ui-components#advanced-charts)

### Full-Text Search

*Formerly known as Advanced Search.* The capability to run full-text search directly in the database. This enables more complex and performant queries of persisted data. Fuzzy matching is supported to generate search results incorporating likely matches in addition to exact matches. Search results are ranked by relevance score. Typical use cases include searching within multiple properties, searching across a large volume of data, and searching within long-form content.

Full-Text Search functions through the indexing of selected object class properties at the database level. The functionality is similar to that provided by tools such as Elasticsearch and Solr.

### Conditional Permissions

The capability to employ an additional layer of data access control at the Solution level. Conditional permissions enable the granular definition of user access to read and manipulate data within a single object based on a user’s roles and data stored within the object. These permissions are evaluated prior to database operations regardless of origin, ensuring the security and integrity of data across Apps, Services, and GraphQL.

Conditional permissions are required in order to implement multi-tenant solution architecture optimally.

* [Documentation: Conditional Permissions](https://docs.appfarm.io/reference/security/permissions/conditional-permissions)

### Custom Authentication

The capability to configure third-party authentication for Apps with providers such as Microsoft Entra ID (Azure AD), Auth0, and Google, using OAuth 2.0. With this integration, users can be automatically registered in Appfarm when they first log in to an app using a configured third-party authentication provider. There are two levels of custom authentication:

* **Standard**: Includes the built-in Appfarm user authentication options, and one (1) third-party authentication provider.
* **Advanced:** Includes **Standard** capabilities and support for multiple third-party authentication providers.
* [Documentation: Custom auth providers](https://docs.appfarm.io/reference/configuration/login/custom-auth-providers)

### Custom Domain

The capability to configure a custom domain for a Solution. By connecting a domain (*yourdomain.com*) or subdomain (*subdomain.yourdomain.com*) to a Solution, the Apps and Services in Production can be accessed using the custom domain. By default, every Solution is assigned an *appfarm.app* subdomain (*yoursolution.appfarm.app*) and this URL is used to access Apps and Services when a custom domain is not configured.

* [Documentation: Add a custom domain](https://docs.appfarm.io/how-to/security-testing-and-deployment/add-a-custom-domain)

### Custom UI Integrations

The capability to create custom-coded interactive UI components in Apps that can leverage the shared global data model and application logic. A custom UI Integration can utilize third-party JavaScript and CSS resources.

Typical use cases include implementing interactive components such as maps, audio/video playback, and 3D viewers, or integrating third-party widgets where using the [Iframe component](https://docs.appfarm.io/library/ui-components/iframe) is undesirable.

* [Documentation: Coded Component](https://docs.appfarm.io/library/ui-components/coded-component)

### Data Extract API

The capability to efficiently extract large volumes of data from the Solution database. It is designed for transferring data into data warehouses and data lakes for further analysis and storage.

Data can be exported at the object class level, allowing for targeted data extraction. For each object class where data export is enabled, a unique endpoint is activated. These endpoints use cursor-based pagination, a method that enables efficient extraction of large datasets. Calling an endpoint requires an API key configured with explicit permissions, ensuring data security.

### Offline Apps

The capability to create Apps that can be opened and used without network connectivity. Typical use cases involve mobile workforces operating in environments without an internet connection, such as remote fieldwork, at sea, or in tunnels and large buildings under construction.

**Public release:** 23-08-2023

* [Documentation: Offline data handling](https://docs.appfarm.io/how-to/data-modeling/offline-data-handling)

### Sandbox Solution

A Solution dedicated to experimental, innovation, and product development use. Compared to other [Solutions](#solution), Sandbox Solutions are configured with reduced resources and capabilities. A Sandbox Solution has one deployment environment, Development. The Test environment may be activated upon request.

By default, Sandbox Solutions are assigned to a database cluster designed exclusively for this type of Solution. Organizations on the Dedicated subscription tier can request to have their Sandbox Solution(s) assigned to their dedicated database infrastructure. In this case the Sandbox Solution(s) will share resources with other Solutions in that infrastructure.

### Scheduled Workflows

The capability to automate Services to run on a recurring schedule. Common use cases are running batch and recurring jobs such as synchronizing data with an external system, polling for changes, and sending notifications.

* [Documentation: Schedules](https://docs.appfarm.io/reference/operations/schedules)

### Targeted Deploy

The capability to selectively deploy changes to specific Apps, Services, Themes, and Schedules to any active environment. With Targeted Deploy, developers can choose which Apps, Services, Themes, and Schedules to deploy and push them to the desired environment either instantly or at a scheduled time. Any dependencies required by the selected items, such as data model changes, are automatically included in the deployment.

Targeted Deploy facilitates more efficient development workflows within a Solution. Development teams can develop and release multiple Apps and Services independently, implement bug fixes quickly, and manage versioning more effectively.

### Time Series Data

The capability to efficiently store and query time series data in a Solution. This is particularly useful for storing data related to IoT sensors, machine usage and performance, warehouse inventory levels, and financial or other volume-based transactions.

An additional type of object class is enabled specifically for modeling time series data. Data storage features include the ability to specify time granularity, handle duplicate records, and configure rule-based automatic data deletion. Querying time series data includes support for data aggregation.

Time series data counts towards a Solution's [database storage](#database-storage) quota. Data usage that exceeds the quota requires upgrading to the Dedicated subscription tier. For organizations on the Dedicated subscription tier, additional data storage can be purchased.

* [Documentation: Time series data](https://docs.appfarm.io/reference/data-model/time-series-data)

***

## Subscription Tier-Based Platform Add-Ons

The right to subscribe to the following platform add-ons is determined by subscription tier.

### Advanced Search Service

An additional platform service that routes [Full-Text Search](#full-text-search) operations through specialized database infrastructure designed for handling intensive text search workloads. This separation ensures that complex search tasks do not interfere with standard database operations such as data reads, writes, and queries.

This add-on is particularly valuable for applications that perform frequent or complex full-text searches, require consistent search response times during peak usage, or use Full-Text Search as a core feature of their user experience.

### Client Data Service

An additional platform service that creates a dedicated channel for data transfer between a Solution's Apps and the database. In the standard configuration, both Apps and Services share a single data service for database operations. For Solutions with high data processing demands, this shared arrangement can create performance bottlenecks when Apps with many active users operate concurrently with data-intensive Services.

The Client Data Service add-on creates a separate data pathway exclusively for App traffic, while restricting the existing data service to handle only Service-related operations (including GraphQL and Data Extract API requests). This separation provides two key benefits:

1. Improved performance for end-users by preventing Service operations from competing with App operations for database access.
2. Enhanced system resilience through load distribution across two independent data services.

This add-on is particularly valuable for Solutions that experience high simultaneous usage from both human users in Apps and automated processes in Services.

### Data Aggregation Service

An additional platform service that provides access to specialized database infrastructure that caters exclusively to analytics and aggregation workloads. By default, aggregation queries share database resources with standard operations; this service routes them to separate infrastructure.

This service handles database aggregations executed from GraphQL queries, or from Apps or Services using the [Aggregate Data action node](https://docs.appfarm.io/library/action-nodes/aggregate-data). Heavy usage of [Conditional Permissions](#conditional-permissions), which rely on aggregations, also benefits from this dedicated infrastructure.

Enabling Data Aggregation Service also provides access to more complex aggregation queries in Appfarm Create, allowing aggregation and grouping by nested properties when using the Aggregate Data action node.

By isolating analytics workloads, the Data Aggregation Service delivers two critical benefits:

1. Enhanced analytics capabilities that enable customers to run significantly heavier aggregation workloads and implement extensive Conditional Permissions without performance concerns. Extended query timeouts allow for longer-running analytic operations that would otherwise be interrupted.
2. Improved performance for standard database operations by preventing long-running analytic tasks from competing with transactional workloads.

This add-on is particularly valuable for Solutions that require complex data analysis, extensive reporting capabilities, or sophisticated multi-tenant architectures with granular Conditional Permissions.

### Production-Grade QA Environment

Additional resources granted to a Test or Staging environment in order to replicate Production-level performance. By default, Test and Staging environments have fewer resources available due to their significantly lower usage patterns. However, additional resources may be required in cases where it has been deemed necessary to run operations that utilize frequent API requests and/or have large data processing requirements on the Test and/or Staging environment.

* [Acceptable Use Policy: Resource allocation by environment](https://policies.appfarm.io/policies/acceptable-use-policy#resource-allocation-by-environment)

### Static IP for Web Requests

The capability to route outbound HTTP requests from a Solution through a dedicated proxy with a fixed IP address.

When enabled, developers can configure individual Web Request action nodes to use the static IP address. This ensures that all requests generated by those action nodes will consistently originate from the same IP address, facilitating integration with external systems protected by IP-based firewalls or other security measures that require IP address whitelisting.

The static IP address remains constant across all active environments within the associated Solution. When static IP is enabled, Web Request action nodes support sending JSON data only.

***

## Dedicated Subscription Tier Platform Capabilities

The Dedicated subscription tier has the option to use multiple [Solutions](#solution). In this case:

* Dedicated infrastructure is shared across all Solutions.
* Allocated resources are shared across all Solutions. This encompasses the number of Apps, Active Users, Database and File Storage, API Integrations, and other resources outlined in the Subscription Agreement.
* Platform capabilities are included in all Solutions. This encompasses Offline Apps, Conditional Permissions, Data Extract API and other capabilities outlined in the Subscription Agreement.

### Dedicated Database Infrastructure

A dedicated database cluster designed for high availability and performance, isolated from other Appfarm customers. A database cluster consists of multiple database servers that store the same data set. This architecture provides durability, redundancy, and automatic failover.

Dedicated database infrastructure provides more stable and reliable database performance in comparison to shared infrastructure where other customers can trigger high resource utilization. It also allows for increased robustness, scalability, and customization through custom resource provisioning and custom data backup policies, if required.

An organization on the Dedicated subscription tier can elect to add further dedicated database infrastructure and transfer one or several existing Solutions to the new cluster.

* [Backup Policy: Solution Data](/service-and-usage/backup-policy#dedicated)

***

## Dedicated Subscription Tier Add-Ons

The following platform add-ons are available exclusively in the Dedicated subscription tier.

### Backup Testing

Regular testing of both solution data backups and solution model backups to verify the integrity of data stored in the Production environment database. Testing frequency can be monthly or quarterly.

* [Backup Policy: Solution Data](/service-and-usage/backup-policy#solution-data-backups)
* [Backup Policy: Solution Model](/service-and-usage/backup-policy#solution-model-backups)

### Dedicated Database Scale

Enhanced database infrastructure available in progressive scale levels, each providing substantially increased performance and computational resources for Solutions with demanding data processing requirements. Each scale level corresponds to a higher-performance database tier with significantly greater memory, processing power, cache allocation, and concurrent connection limits, along with independent storage scaling and expert performance analysis from Appfarm's platform operations team.

Dedicated Database Scale addresses Solutions that require greater computational resources due to high-volume data operations, complex queries across large datasets, or intensive concurrent processing demands. The enhanced resources enable faster query execution across all database operations, improved concurrent user support, and more efficient handling of data-intensive workloads.

The first scale level doubles memory and processing power, doubles concurrent connection capacity, and provides four times the effective cache—a particularly impactful improvement for read-heavy workloads. Higher scale levels continue to deliver similar resource expansions.

The configuration process includes analysis of the Solution's specific usage patterns and requirements, followed by resource provisioning at the appropriate scale level and database optimization tailored to those needs. This ensures the enhanced infrastructure delivers maximum value for the Solution's particular data processing profile.

This add-on is particularly valuable for Solutions experiencing performance constraints during peak usage periods, managing rapidly growing datasets, or running intensive database operations that exceed standard database resources regardless of workload type.

### Dedicated Cloud Infrastructure

A dedicated Kubernetes cluster of virtual machines to host one or more Solutions, designed for optimal platform performance, isolated from other Appfarm customers. This includes dedicated load balancing with cloud resources provisioned to only manage traffic to that cluster.

Dedicated cloud infrastructure provides more stable and reliable Solution performance in comparison to shared infrastructure where other customers can trigger high resource utilization. Additionally, there is greater flexibility afforded to the allocation of resources which can be tailored to align directly with the requirements of the Solution(s) running on the infrastructure.

#### **Dedicated Network (with encryption key management)**

*Must be combined with Dedicated Cloud Infrastructure.*

A dedicated network is provisioned to host the dedicated cloud infrastructure, entirely separate from other Appfarm infrastructure. With full separation on a network level, there is no possibility for interaction with other Appfarm customer Solutions, providing an additional layer of robustness and security. The dedicated network also includes the ability to manage encryption keys in a separate Key Management Service (KMS) system within GCP, AWS, or Azure.

## Revision history

<table><thead><tr><th width="104">Version</th><th width="137">Date</th><th>Revision</th><th>Approved By</th></tr></thead><tbody><tr><td><code>1.0</code></td><td><code>23.01.2024</code></td><td>Document published.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.0.1</code></td><td><code>04.06.2024</code></td><td>Users: Clarified that the activity of guest users does not count towards the active user quota.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.1</code></td><td><code>24.09.2024</code></td><td>Added allocated database storage per subscription tier, and definitions for Archive Files, Time Series Data, and Data Extract API.<br>Clarified that Solution integrations include requests received by all custom and built-in endpoints.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.2</code></td><td><code>22.10.2024</code></td><td>Custom authentication: Adjusted the Standard level to include support for credential pass-through and moved support for multiple third-party authentication providers to the Advanced level.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.2.1</code></td><td><code>08.11.2024</code></td><td>Users: Clarified that active users are counted uniquely across all Solutions within the same subscription.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.2.2</code></td><td><code>25.11.2024</code></td><td>Dedicated: Expanded the definitions of allocated resources and platform capabilities to ensure they encompass all listed in the Subscription Agreement.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.3</code></td><td><code>05.02.2025</code></td><td>Added definition for Static IP for Web Requests.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.3.1</code></td><td><code>18.02.2025</code></td><td>Archive Files: Clarified that quotas are based on input file size.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.3.2</code></td><td><code>19.02.2025</code></td><td>Client Data Service: Clarified the technical configuration and benefits.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.4</code></td><td><code>14.04.2025</code></td><td>Added definition for Targeted Deploy.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.5</code></td><td><code>09.10.2025</code></td><td>Added definitions for Appfarm AI platform concept and AI Credits resource quota.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.6</code></td><td><code>26.11.2025</code></td><td>Added definition for Dedicated Database Scale.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.6.1</code></td><td><code>02.12.2025</code></td><td>Dedicated Database Scale: Clarified the technical resource increases.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.6.2</code></td><td><code>03.12.2025</code></td><td>Removed the Basic column in the Data storage table as the Basic tier has been discontinued.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.7</code></td><td><code>12.12.2025</code></td><td>Added definition for Data Aggregation Service.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.7.1</code></td><td><code>19.12.2025</code></td><td>Removed the Basic level of Custom Authentication as the Basic subscription tier has been discontinued.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.8</code></td><td><code>06.01.2026</code></td><td>Solution: Expanded the definition to account for multiple Solutions on any subscription tier.<br>AI Credits: Clarified that AI credits are granted upfront and for new subscriptions.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.8.1</code></td><td><code>08.01.2026</code></td><td>Sandbox Solution: Expanded the definition.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.8.2</code></td><td><code>03.02.2026</code></td><td>Advanced Search: Renamed to Full-Text Search.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.9</code></td><td><code>04.02.2026</code></td><td>Added definition for Advanced Search Service</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.9.1</code></td><td><code>19.05.2026</code></td><td>Solution: Expanded the definition to clarify database provisioning.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.9.2</code></td><td><code>01.06.2026</code></td><td>Appfarm AI: Removed sentence about Appfarm AI being in beta.<br>Environments: Removed sentence about possibility to purchase additional environments.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.9.3</code></td><td><code>10.06.2026</code></td><td>Data Aggregation Service: Added that the service enables use of nested properties in the Aggregate Data action node.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.10</code></td><td><code>05.08.2026</code></td><td>Added definition for Flow. Solution and Environment: updated to include Flows alongside Apps and Services.</td><td>Marius Tuft, CEO</td></tr><tr><td><code>1.10.1</code></td><td><code>07.08.2026</code></td><td>Appfarm AI: Renamed Agent mode to Build mode and use of subagents.</td><td>Marius Tuft, CEO</td></tr></tbody></table>


# Code of Conduct

At Appfarm, we believe all people should be treated with fairness and respect, and aim to help each other, our customers and partners, as a company and as people. This Code of Conduct provides guidelines for all Appfarm employees. These guidelines address both the things we strive to do and the things we won't do.

At Appfarm, we are committed to providing a healthy work environment and culture: one where everyone is respected, welcomed, included, and free from discrimination, harassment, and intimidation for any reason. We expect all Appfarm employees to hold themselves to the highest standards as part of the Appfarm family. We recognize that each of us is an ambassador for Appfarm and for each other. Integrity is central to protecting our culture as well as our reputation. Therefore, we consider those who do not abide by this Code of Conduct as not welcome in the Appfarm team, and breach of this code of conduct will have consequences both short term and long term.

## We act with integrity

1. We are honest and transparent. If we say something either publicly or privately, then we believe that it is true. We do not intentionally omit important and relevant factual information to deceive others. We strive to be clear and transparent in our communications.
2. We protect sensitive information. When we are entrusted with sensitive, confidential, or personal information, we use appropriate measures to secure it. We respect requests for privacy and confidentiality.
3. We disclose known conflicts of interest as early as possible.
4. We do not steal assets or content. We encourage and respect independent, innovative thinking.
5. We are responsible with controlled substances. If consuming alcohol, we do so responsibly. Alcohol is never provided to minors. We do not drive under the influence of any legal or illegal drug. We do not distribute, use, or operate under the influence of illegal drugs (defined by law) while participating or engaging in any Appfarm event.
6. We abide by all local and national laws. We do not do business with bad actors or actors where we suspect foul play or ill intent. We honor international sanctions. We are careful to do business only with lawful parties.
7. In the fight against climate change, every action matters. We are committed to making environmentally conscious choices regarding how we run our business, including how we choose to travel. Sustainability and environmental impact are considered factors in all our business decisions.
8. We do not pay or accept bribes. We do not engage in any form of corruption. We act with integrity in our dealings with others and strictly prohibit corrupt activities. The presence of kick-back or bonus models in our business dealings with partners should be clearly communicated to end-customers if asked.

## We treat others with respect

9. We commit to non-hostile, open, and welcoming workplaces. We intentionally create workplace environments where employees, partners, customers, and visitors feel accepted and free to express their opinions, concerns, and needs with an expectation that they will be heard and respected. We communicate professionally and appropriately.
10. We don’t tolerate illegal discrimination or harassment in any form. Discrimination is unfairly treating a person or group of people differently from other people. Harassment is unwanted and unwelcome words, deeds, actions, gestures, or behaviors that make someone feel uncomfortable. The following conduct, depending upon the circumstances, may constitute discrimination or harassment, including for observers:
    * Slurs, jokes, statements, remarks, questions, or gestures that are derogatory or demeaning to an individual’s or group’s characteristics or that promote negative stereotypes;
    * Visual displays (including photographs, cartoons, and drawings) of suggestive or degrading images or stereotypes of any individual or group;
    * Limiting opportunities to work on certain assignments based on, for example, race, color, gender, age, religion, national origin, disability, or sexual orientation;
    * Unwelcome sexual jokes, language, advances or propositions, or comments about an individual’s body;
    * Written or verbal abuse of a sexual nature or the display of sexually suggestive objects, pictures, posters, or cartoons;
    * Unwelcome touching, leering, whistling, brushing against the body, or suggestive, insulting or obscene comments or gestures or inquiries about sexual conduct;
    * Demanding sexual favors in exchange for favorable reviews, assignments, promotions, or continued employment, or promises of the same;
11. We will quickly take action against employees who display discriminatory or harassing conduct, and train our employees to recognize and address bad behavior. We will ban or disassociate with mentors, investors, employees, contractors, and others who discriminate against or harass others.
12. We are committed to diversity and inclusion. We are committed to building inclusive work environments that reflect and value the diversity of people and cultures found in the world, which we believe leads to a better and higher-performing company.
13. We stand up for others. We report violations, and we appropriately intervene in situations when we witness violations of this Code.
14. We are reachable and responsive. Anyone doing business with us can have a reasonable expectation of receiving a response in a timely fashion.
15. We respect our legal agreements. We follow the spirit and intent of our legal agreements.
16. We keep our promises. If we commit to doing something, we do our best to do it. If we can’t keep our promises for some reason, then we strive to make it right in any way possible.
17. We do right by our customers. We strive to deliver products that delight our customers and seek to exceed their expectations.
18. We do not attack others electronically. We don’t maliciously attack others using scripts, robots, or similar techniques.
19. We are not spammers. We do not send bulk unsolicited emails or scrape contact lists and abuse them. We don’t harass prospective customers who have clearly said no to us and opted out of communications.
20. We encourage professional development. As a company, we do everything we can to ensure the happiness and professional growth of our employees.
21. We avoid gossip. We don’t share disparaging comments and rumors about others. We are constructive in our feedback and always provide it directly to the individual or company to which it pertains.
22. We ensure fair pay for equal work. We are committed to ensuring everyone receives fair compensation. We appreciate the commitment of our employees and agree to compensate them without regard to ability status, age, ancestry, civil union, class, color, ethnicity, familial status, gender, gender identity, genetic information, marital status, national origin, pregnancy, race, religion, sexual orientation, or other status.
23. The Appfarm Code of Conduct is a living document managed by the Appfarm team. For suggested changes, please reach out.

## Pay it forward

24. &#x20;We help others whenever possible. We are all busy, but when asked, we should respond and help. We are respectful of each other’s time and are clear and focused in our requests.
25. &#x20;We are punctual and respond quickly. We make every attempt to prioritize and respond to requests from each other, our customers, and partners.
26. &#x20;When somebody takes the initiative, we support, encourage and endorse them.
27. &#x20;We pay it forward. We proactively work to give back to the ecosystem by giving first to others in our community with no specific expectations of return.
28. &#x20;We appreciate the help of others. Building a startup is a team activity. We express our appreciation for the help of our customers, mentors, and others that make our success possible.

## It's OK to:

29. &#x20;Not know everything, and ask for help.
30. &#x20;Challenge things you disagree with or are not comfortable with.
31. &#x20;Add pauses to your day to think, reflect and rest.
32. &#x20;Have good days and smile. And have bad days and not smile.
33. &#x20;Let your team or manager know things are going great or not going so great.
34. &#x20;Put your family before your work.

We strongly encourage everyone to report any violations of this Code of Conduct to any member of Appfarm management you are comfortable reporting to.

*Note: The Appfarm Code of Conduct is inspired by the Techstars Code of Conduct and the Arkwright X Code of Conduct.*

## **Revision history**

<table><thead><tr><th width="104">Version</th><th width="137">Date</th><th>Revision</th><th>Approved By</th></tr></thead><tbody><tr><td><code>1.0</code></td><td><code>07.03.2024</code></td><td>Document published.</td><td>Marius Tuft, CEO</td></tr></tbody></table>


