PrimeApp Studio

Terms of Service

Last updated: 2026-08-10

These terms are a binding agreement between you (“you”, “Customer”) and [LEGAL_NAME], who operates PrimeApp Studio. By creating an account you accept them, including Annex A — the data processing agreement — which forms an integral part of this contract.

1. Who you are contracting with

In compliance with Spanish Law 34/2002 (LSSI-CE), art. 10, the service is provided by:

  • Name: [LEGAL_NAME]
  • Tax ID (NIF): [NIF]
  • Registered address: [STREET, POSTAL CODE, CITY, SPAIN]
  • Email: admin@primeappstudio.com
  • Website: primeappstudio.com

2. The service

PrimeApp Studio is a hosted, subscription-based set of business tools sold as separate modules. You subscribe to the modules you want; each one is unlocked for your workspace independently.

We may add, change or retire features. If we retire a module you are paying for, we will give reasonable notice and stop charging you for it, and your data will remain exportable as described in clause 8.

3. Accounts and security

You must give accurate registration details and keep your password confidential. You are responsible for everything done under your account and for the people you invite into your workspace.

You must be at least 18 years old and, where you are signing up on behalf of an organisation, authorised to bind it to these terms.

Tell us promptly at admin@primeappstudio.com if you believe an account has been compromised.

4. Trial, subscriptions and payment

  • Free trial. New workspaces get 15 days of full access to the pilot module. No card is required to start. When the trial ends without a subscription, the workspace becomes read-only — you keep access to your data and exports, you simply cannot add new records.
  • Subscriptions. Paid plans are billed monthly or annually in advance and renew automatically for the same period until cancelled.
  • Payments. Card payments are processed by Stripe Payments Europe, Ltd. We never receive or store your card number.
  • Taxes. Prices are shown exclusive of VAT unless stated otherwise. Applicable VAT is added at checkout based on your location.
  • Failed payments. If a charge fails, Stripe retries. During that period the workspace goes read-only rather than being deleted.
  • Price changes. We will give at least 30 days’ notice by email before a price change takes effect. You may cancel before it applies.

5. Cancellation and right of withdrawal

You can cancel at any time from your account. Cancellation takes effect at the end of the period you have already paid for; we do not refund part-used periods except where the law requires it.

If you are a consumer in the EU, you normally have 14 days to withdraw from a distance contract. Because the service is digital content supplied immediately, by subscribing and starting to use it you request immediate performance and acknowledge that you lose that right of withdrawal once the service has been fully provided for the period in question. This does not affect your statutory rights where you contract as a business.

6. Acceptable use

You agree not to:

  • use the service unlawfully, or to store data you have no right to store
  • attempt to access another customer's workspace or data
  • probe, scan or stress-test the service without our written permission
  • resell or white-label the service without an agreement with us
  • upload malware, or content that infringes someone else's rights

We may suspend an account that puts the service or other customers at risk. Where we can, we will warn you first.

7. Your data stays yours

You own everything you put into PrimeApp Studio. We claim no rights over it, and we process it only to provide the service — see Annex A.

Plainly: we do not sell your data, we do not share it with third parties for advertising, and we do not use it to train machine-learning models.

We own the software, design and documentation. These terms grant you a non-exclusive, non-transferable right to use it while your subscription lasts.

8. Export and termination

You can export your records at any time, including after cancelling. Cancelling a subscription makes a workspace read-only; it does not delete anything.

You may ask us to delete your workspace entirely by writing to admin@primeappstudio.com. We will do so within 30 days, except where we are legally required to retain something (for instance invoicing records).

We may terminate this agreement for material breach, or if required by law. In that case we will give you a reasonable opportunity to export your data first, unless doing so is itself unlawful.

9. Availability and support

We work to keep the service available and take regular backups, but we do not offer a contractual uptime guarantee. Maintenance may cause brief interruptions.

Support is by email at admin@primeappstudio.com during Spanish business days.

10. Liability

The service is provided as-is beyond the warranties that cannot be excluded under Spanish law. To the extent permitted by law, our total liability arising out of this agreement in any 12-month period is limited to the amount you paid us in that period.

We are not liable for indirect or consequential loss, loss of profits, or loss of data to the extent that loss results from you not keeping your own exports. Nothing here excludes liability for fraud, wilful misconduct, gross negligence, death or personal injury.

The service is a record-keeping tool. It is not accounting, tax or legal advice, and it does not replace your own obligation to file correct returns.

11. Changes to these terms

We may update these terms. For material changes we will notify account owners by email at least 30 days in advance, and the version date at the top of this page will change. Continuing to use the service after a change takes effect means you accept the new version; if you do not, you may cancel.

12. Governing law

These terms are governed by the laws of Spain. Disputes fall to the courts of the provider’s registered address, except that consumers keep the right to bring proceedings in the courts of their own place of residence and the protection of their local mandatory law.

Personal data is handled as described in our Privacy Policy.


Annex A — Data Processing Agreement

This annex applies whenever you enter personal data about other people into the service — members, donors, contacts. For that data you are the controller and [LEGAL_NAME] is the processor, under art. 28 GDPR. Accepting these terms when you create your account concludes this agreement in writing in electronic form, as art. 28.9 GDPR allows — there is no separate document to sign.

A.1 Subject matter, duration, nature and purpose

We process personal data on your behalf solely to provide the subscribed modules — storing, organising, displaying, exporting and backing up the records you enter. Processing lasts as long as your account does, plus the deletion period in clause A.9.

A.2 Types of data and categories of data subjects

Data subjects: the people whose records you keep, such as congregation members, donors and contacts. Categories of data: identification and contact details, and financial contribution records (amounts, dates, categories, notes) that you choose to enter.

You must not use the service for special categories of data under art. 9 GDPR unless you have your own valid legal basis for doing so and have satisfied yourself that the service is appropriate for it. Note that in some jurisdictions membership of a religious organisation is itself a special category of data — assessing that is your responsibility as controller.

A.3 Processing only on documented instructions

We process the data only on your documented instructions. Your configuration and use of the service, together with these terms, constitute those instructions. We will tell you if an instruction appears to breach the GDPR, and we will inform you if EU or member state law requires us to process data beyond your instructions, unless that law forbids the notification.

A.4 Confidentiality

Everyone we authorise to access the data is bound by confidentiality and only gets the access their work requires.

A.5 Security (art. 32)

The measures currently in place include:

  • all traffic served over HTTPS with HSTS
  • data encrypted at rest by our database provider
  • passwords stored only as bcrypt hashes, never in plain text
  • tenant isolation: every record is scoped to a workspace and access is checked on each request
  • role-based permissions within a workspace (owner, admin, member)
  • sessions that can be revoked centrally, and rate limiting on sign-in by both account and network address
  • security headers restricting framing, content types and referrer leakage
  • regular automated backups

These measures are reviewed as the service evolves; we may replace one with an equivalent or stronger measure.

A.6 Sub-processors

You give general authorisation for the sub-processors below. We remain responsible for their performance and impose equivalent data protection obligations on them.

Sub-processorPurposeLocation
NeonDatabase hosting — stores all workspace recordsEuropean Union
VercelApplication hosting — serves the app and processes requestsEuropean Union / United States (SCCs)
Stripe Payments Europe, Ltd.Subscription billing and card processingIreland / United States (SCCs)
ResendTransactional email (sign-up, password reset)United States (SCCs)

We will notify account owners by email at least 30 days before adding or replacing a sub-processor. If you reasonably object on data protection grounds, you may terminate the affected subscription and receive a pro-rata refund of the unused period.

A.7 Assisting you with data subject rights

The service lets you access, correct, export and delete records yourself, which is normally all that is needed to answer a request. Where it is not, we will assist you by appropriate technical and organisational measures, taking into account the nature of the processing.

If a data subject contacts us directly about data you control, we will not answer on your behalf; we will refer them to you and let you know.

A.8 Breach notification and assistance (arts. 32–36)

We will notify you without undue delay, and in any case within 48 hours of becoming aware, of any personal data breach affecting your data, with the information you need to meet your own art. 33 obligations. We will also assist you, on request and taking into account the information available to us, with security, breach notification and data protection impact assessments.

A.9 Deletion or return at the end

You can export your data yourself at any time, during the subscription and after cancelling. On termination, and at your choice, we will delete or return the personal data. Absent a different instruction, we delete workspace data within 30 days of a deletion request, and backups age out within a further 30 days.

A.10 Audits

We will make available the information necessary to demonstrate compliance with art. 28 and allow for audits, including inspections, conducted by you or an auditor you mandate. Audits are at your cost, on reasonable notice, no more than once a year unless a breach or a supervisory authority requires otherwise, and must not disrupt the service or expose other customers’ data.

A.11 International transfers

We aim to keep customer data hosted in the European Union. Where a sub-processor processes data outside the EEA, the transfer relies on an adequacy decision, on the EU-U.S. Data Privacy Framework, or on the European Commission’s Standard Contractual Clauses together with any supplementary measures required.

A.12 No secondary use

We do not sell your data, do not share it with third parties for advertising, and do not use it to train machine-learning models. The analytics described in the Privacy Policy measure website visitors and never touch the records inside a workspace.

A.13 Precedence

In case of conflict between this annex and the rest of the Terms, in matters of personal data processing this annex prevails.