Data Processing Addendum
DRAFT v1.0 — prepared for review by qualified counsel before publication. Replace bracketed placeholders.
Version: 1.0 · Effective date: [EFFECTIVE DATE] · Published at: flowagenci.com/legal/dpa
This Data Processing Addendum ("DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between [FLOWAGENCI LLC LEGAL NAME], a [STATE] limited liability company with its registered address at [REGISTERED ADDRESS] ("FlowAgenci"), and the organization that has agreed to the Agreement ("Customer"). It applies automatically when Customer accepts the Agreement; no signature is required. Customers who need a countersigned copy may request one at legal@flowagenci.com.
1. Definitions
Capitalized terms not defined in this DPA have the meaning given in the Agreement.
- "Applicable Data Protection Law" means all laws relating to the processing of Personal Data that apply to a party in connection with the Service, including, as applicable: the EU General Data Protection Regulation 2016/679 ("GDPR"); the GDPR as incorporated into UK law and the UK Data Protection Act 2018 ("UK GDPR"); the Swiss Federal Act on Data Protection ("FADP"); Chilean Law 19.628 and, from 1 December 2026, Law 21.719 ("Chilean Law"); the California Consumer Privacy Act as amended by the CPRA and other comprehensive US state privacy laws ("US State Privacy Laws"); Brazil's LGPD (Law 13.709/2018); Mexico's LFPDPPP; Argentina's Law 25.326; and Colombia's Law 1581 of 2012.
- "Customer Data" means all data, including Personal Data, submitted to the Service by or on behalf of Customer, its Authorized Users (team members and guests) and its Portal Users (Customer's clients invited to the Client Portal), and processed by FlowAgenci on Customer's behalf.
- "Customer Personal Data" means Personal Data contained in Customer Data.
- "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Supervisory Authority" and "Personal Data Breach" have the meanings given in the GDPR (or the equivalent terms in other Applicable Data Protection Law, such as "responsable" and "encargado" under Chilean Law, or "business", "service provider" and "consumer" under US State Privacy Laws).
- "Subprocessor" means any third party engaged by FlowAgenci to process Customer Personal Data.
- "SCCs" means the Standard Contractual Clauses approved by the European Commission Implementing Decision (EU) 2021/914; "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner.
- "Account Data" means Personal Data FlowAgenci processes as a Controller to manage the relationship with Customer (for example, account owner and billing contact details, authentication and security logs). Account Data is governed by the Privacy Policy, not by this DPA.
2. Scope and roles
2.1 Roles. With respect to Customer Personal Data, Customer is the Controller (or, where Customer acts on behalf of its own clients, a Processor, in which case FlowAgenci is a sub-processor) and FlowAgenci is the Processor. Under US State Privacy Laws, FlowAgenci is a "service provider" or "processor".
2.2 Customer responsibilities. Customer is responsible for the lawfulness of the Processing it instructs, including having a valid legal basis, providing any required notices to Data Subjects (including Portal Users and contacts stored in its CRM), and obtaining any required consents. Customer shall not submit special categories of Personal Data, government identification numbers beyond tax identifiers ordinarily shown on commercial documents, or payment card data to the Service unless expressly permitted in the Agreement.
2.3 Details of Processing. The subject matter, nature, purpose and duration of the Processing, and the types of Personal Data and categories of Data Subjects, are described in Annex I.
3. Processing on documented instructions
3.1 FlowAgenci shall process Customer Personal Data only on Customer's documented instructions, which are: (a) to provide, secure, support and maintain the Service in accordance with the Agreement and the Documentation; (b) as initiated by Authorized Users through their use of the Service (for example, sending an invoice, inviting a Portal User, or connecting a custom domain); and (c) as otherwise agreed in writing.
3.2 FlowAgenci shall inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, and may suspend the affected Processing until the instruction is confirmed or modified.
3.3 FlowAgenci may process Customer Personal Data where required by law applicable to it. In that case, FlowAgenci shall inform Customer of the legal requirement before Processing, unless the law prohibits such notice on important grounds of public interest.
3.4 Prohibited uses. FlowAgenci shall not: (a) sell or share Customer Personal Data (as those terms are defined in US State Privacy Laws); (b) retain, use or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement, including for targeted or cross-context behavioural advertising; (c) combine Customer Personal Data with Personal Data it receives from other sources, except as permitted by US State Privacy Laws; or (d) use Customer Data to train artificial intelligence models of FlowAgenci or of any third party. FlowAgenci may create aggregated, de-identified data that does not identify Customer or any individual, to operate and improve the Service, and shall not attempt to re-identify it. FlowAgenci certifies that it understands and will comply with these restrictions.
4. Confidentiality of personnel
FlowAgenci shall ensure that persons authorized to process Customer Personal Data are bound by written obligations of confidentiality or are under an appropriate statutory duty of confidentiality, receive appropriate data protection training, and access Customer Personal Data only as necessary to provide the Service. Staff access to a Customer workspace for support purposes is time-limited (30 minutes per session), read-only by default, requires a stated reason, requires two-factor authentication and is recorded in an audit log visible to Customer's owners.
5. Security
5.1 FlowAgenci shall implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against Personal Data Breaches, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the Processing, as well as the risk to the rights and freedoms of natural persons. These measures include, at a minimum, those described in Annex II.
5.2 FlowAgenci may update the security measures from time to time, provided that updates do not materially decrease the overall level of protection of Customer Personal Data.
5.3 Customer is responsible for its own secure use of the Service, including configuring user roles and permissions, choosing which content is visible in the Client Portal, managing Portal User access, protecting account credentials and enabling two-factor authentication where available.
6. Subprocessors
6.1 General authorization. Customer grants FlowAgenci a general authorization to engage Subprocessors. The current list of Subprocessors, including their location and function, is published at /legal/subprocessors (Annex III).
6.2 Obligations. FlowAgenci shall impose on each Subprocessor, by written contract, data protection obligations that offer at least the same level of protection as this DPA to the extent applicable to the nature of the services provided. FlowAgenci remains liable for the acts and omissions of its Subprocessors as for its own, subject to the Agreement's limitations of liability.
6.3 Notice of changes. FlowAgenci shall give at least 30 days' notice of any intended addition or replacement of a Subprocessor by updating the Subprocessors page and emailing account owners who have subscribed to updates on that page.
6.4 Objection. Customer may object to a new Subprocessor on reasonable data protection grounds by writing to privacy@flowagenci.com within the notice period. The parties shall discuss the objection in good faith. If FlowAgenci cannot reasonably accommodate the objection, Customer may terminate the affected part of the Service by written notice before the change takes effect and receive a pro-rata refund of prepaid fees for the terminated period.
7. Assistance with Data Subject requests
7.1 Taking into account the nature of the Processing, FlowAgenci shall assist Customer by appropriate technical and organizational measures, insofar as possible, to fulfil Customer's obligation to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law (including access, rectification, erasure, restriction, objection, portability and not being subject to automated decisions). The Service provides self-service tools for this purpose, including record editing and deletion, contact and portal access management, user account deletion and full organization export.
7.2 If FlowAgenci receives a request directly from a Data Subject relating to Customer Personal Data, it shall not respond to the request itself (other than to acknowledge it and direct the Data Subject to Customer) and shall forward it to Customer without undue delay, unless the law requires otherwise.
8. Data protection impact assessments and consultations
FlowAgenci shall provide reasonable assistance to Customer, taking into account the nature of the Processing and the information available to FlowAgenci, with any data protection impact assessment and prior consultation with a Supervisory Authority that Customer is required to carry out in relation to its use of the Service. FlowAgenci may charge a reasonable fee for assistance that goes beyond making available its standard documentation.
9. Personal Data Breach
9.1 FlowAgenci shall notify Customer without undue delay, and in any event within 48 hours, after confirming a Personal Data Breach affecting Customer Personal Data.
9.2 The notice shall be sent to the account owner(s) by email and in-app notice and shall describe, to the extent known: the nature of the breach, including the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and a contact point for more information. Where information is not yet available, FlowAgenci shall provide it in phases as it becomes available.
9.3 FlowAgenci shall take reasonable steps to contain, investigate and remediate the breach and shall cooperate with Customer in meeting its notification obligations to Supervisory Authorities and Data Subjects. FlowAgenci's notification of or response to a Personal Data Breach is not an acknowledgement of fault or liability.
10. Deletion and return of Customer Data
10.1 During the term, Customer may export its Customer Data at any time using the Service's export features, and may delete records, files and users.
10.2 On termination or expiry of the Agreement, the Customer workspace becomes read-only for 90 days, during which Customer may export its data. After that period, FlowAgenci shall delete Customer Data from its production systems within 30 days, unless Applicable Data Protection Law or other law requires storage.
10.3 Deletion by Customer. An owner may delete the workspace at any time. It is closed immediately and can be restored for 30 days; after that, FlowAgenci deletes Customer Data, files, custom domains and the subscription from its production systems. Database point-in-time recovery (Cloudflare D1 Time Travel) keeps backups for up to 30 days after deletion, after which they are gone.
10.4 Customer Data in backups is deleted on the regular backup rotation, within 30 days, and is protected by the measures in this DPA until then. Records that FlowAgenci must keep by law (for example, billing records that include Account Data) are governed by the Privacy Policy.
10.5 Upon request, FlowAgenci shall confirm deletion in writing.
11. Audits and information
11.1 FlowAgenci shall make available to Customer the information reasonably necessary to demonstrate compliance with this DPA. Customer agrees to exercise its audit rights first by reviewing FlowAgenci's security documentation, third-party reports or certifications (where available, including those of its Subprocessors), and written responses to a reasonable security questionnaire (no more than once per year).
11.2 If that information is not sufficient to demonstrate compliance, or where required by a Supervisory Authority or by Applicable Data Protection Law, Customer may carry out an audit, including an on-site inspection, provided that: (a) Customer gives at least 30 days' written notice; (b) the audit takes place no more than once per 12 months, during business hours, and does not unreasonably disrupt FlowAgenci's operations; (c) the auditor is bound by confidentiality and is not a competitor of FlowAgenci; (d) the audit does not give access to data of other customers; and (e) Customer bears the costs of the audit, including FlowAgenci's reasonable time at its then-current professional services rates. Audits of Subprocessors are carried out through the reports and mechanisms those Subprocessors make available.
12. International transfers
12.1 Location. FlowAgenci and its Subprocessors may process Customer Personal Data in the United States and in other countries where they operate. FlowAgenci's primary database region is North America; content is delivered through Cloudflare's global network.
12.2 EEA transfers. To the extent Customer Personal Data subject to the GDPR is transferred to a country that has not received an adequacy decision, the parties agree that the SCCs are incorporated into this DPA by reference and apply as follows: Module 2 (controller to processor) where Customer is a Controller, and Module 3 (processor to processor) where Customer is a Processor; Clause 7 (docking clause) applies; in Clause 9, Option 2 (general authorization) applies with the notice period in Section 6.3; in Clause 11, the optional language does not apply; in Clause 17, Option 1 applies and the SCCs are governed by the law of Ireland; in Clause 18(b), disputes are resolved before the courts of Ireland; Annexes I, II and III of the SCCs are completed with the information in Annexes I, II and III of this DPA; and the competent Supervisory Authority is the one determined in accordance with Clause 13.
12.3 UK and Switzerland. For transfers subject to the UK GDPR, the UK Addendum applies, with Table 1 to 3 completed with the information in this DPA and its Annexes, and either party may end the UK Addendum as set out in its Section 19. For transfers subject to the FADP, the SCCs apply with the modifications required by the FADP, including that references to the GDPR are to be read as references to the FADP and the Swiss Federal Data Protection and Information Commissioner is the competent authority.
12.4 Chile. For international transfers of Customer Personal Data subject to Chilean Law, the parties agree that this DPA, together with the SCCs where applicable, constitutes the contractual clauses providing adequate safeguards, and FlowAgenci shall apply any model clauses or other transfer mechanisms approved by the Agencia de Protección de Datos Personales once issued.
12.5 Other jurisdictions. For transfers subject to other Applicable Data Protection Law (including Brazil, Mexico, Argentina and Colombia), the parties agree that the obligations in this DPA constitute the contractual safeguards required by that law, and shall execute any additional standard clauses required by a competent authority.
12.6 Supplementary measures. FlowAgenci applies the measures in Annex II, including encryption in transit and at rest and strict access controls, and shall, to the extent legally permitted, challenge and notify Customer of any government request for access to Customer Personal Data that it considers unlawful.
13. US State Privacy Laws
To the extent FlowAgenci processes Customer Personal Data that is subject to US State Privacy Laws, FlowAgenci: (a) processes it only for the business purposes set out in the Agreement and this DPA; (b) complies with applicable obligations and provides the same level of privacy protection as required of Customer; (c) notifies Customer if it determines it can no longer meet its obligations; (d) allows Customer to take reasonable and appropriate steps to stop and remediate unauthorized use; and (e) engages Subprocessors only under contracts that impose equivalent restrictions.
14. Liability
Each party's liability arising out of or related to this DPA, whether in contract, tort or any other theory, is subject to the limitations and exclusions of liability in the Agreement, to the extent permitted by Applicable Data Protection Law. Nothing in this DPA limits either party's liability to Data Subjects under the SCCs.
15. Order of precedence and general terms
15.1 Order of precedence. In case of conflict, the following order applies: (1) the SCCs or UK Addendum, where applicable; (2) this DPA; (3) the Agreement.
15.2 Governing law. This DPA is governed by the law that governs the Agreement (the laws of the State of [STATE], USA), except where Applicable Data Protection Law or the SCCs require otherwise.
15.3 Changes. FlowAgenci may update this DPA to reflect changes in Applicable Data Protection Law, Subprocessors or the Service, with at least 30 days' notice for changes that are material and adverse to Customer, unless required earlier by law. Changes do not reduce the protection of Customer Personal Data.
15.4 Termination. This DPA remains in effect for as long as FlowAgenci processes Customer Personal Data.
15.5 Contact. Data protection questions: privacy@flowagenci.com · Security incidents: security@flowagenci.com · Legal notices: legal@flowagenci.com.
Annex I — Description of the Processing
A. List of parties
| Data exporter | Data importer | |
|---|---|---|
| Name | Customer, as identified in its account | [FLOWAGENCI LLC LEGAL NAME] |
| Address | As provided in the account | [REGISTERED ADDRESS] |
| Contact | Account owner email | privacy@flowagenci.com |
| Activities | Use of the Service to run its agency business | Provision of the Service |
| Role | Controller (or Processor on behalf of its clients) | Processor (or sub-processor) |
| Signature and date | By accepting the Agreement | By making the Service available |
B. Categories of Data Subjects
- Authorized Users: Customer's team members, managers, administrators and guests (contractors).
- Portal Users: Customer's clients and their staff invited to the Client Portal.
- Contacts and leads: individuals stored in Customer's CRM, including prospects submitted through public forms.
- Other individuals whose data appears in content uploaded by Customer (for example, people appearing in deliverables or documents).
C. Categories of Personal Data
- Identity and contact data: name, email, phone, job title or role, company, city, language and timezone.
- Authentication and usage data: user identifiers, session and sign-in records, IP address, user agent, in-app activity and notifications.
- Business content: files and deliverables (images, PDFs, video, documents), comments with timestamps and position anchors, approvals and change requests, messages, form responses, time entries and allocations.
- Commercial documents: proposals, quotes, invoices, payment reports and receipts, tax identifiers and addresses that appear on them.
- Acceptance evidence: typed full name, date and time, IP address and user agent recorded when a document is accepted.
D. Sensitive data
Not intended. Customer shall not submit special categories of Personal Data. If Customer does so, the security measures in Annex II apply.
E. Frequency of transfer
Continuous, for the duration of the Agreement.
F. Nature and purpose of the Processing
Hosting, storage, retrieval, organization, display, transmission (including email delivery and PDF generation), backup, malware scanning, deletion and other Processing necessary to provide the Service: project and task management, CRM, time tracking and planning, proposals, quotes and invoicing, the Client Portal (deliverable review and annotation, asset requests, forms, invoices and messages), notifications, support and security.
G. Duration and retention
For the term of the Agreement, plus the 90-day read-only period and up to 30 days for deletion, and up to 30 days in backups (Section 10).
H. Transfers to Subprocessors
As listed in Annex III, for the purposes described there and for the duration of the Agreement.
Annex II — Technical and organizational security measures
- Encryption. All traffic uses TLS 1.2 or higher. Data at rest in databases and object storage is encrypted by the hosting provider. Two-factor secrets are encrypted; passwords and recovery codes are stored only as salted hashes.
- Tenant isolation. Every record of Customer Data is scoped to its organization. Data access is enforced in a central data layer that requires the organization context; automated tests verify that one organization cannot read or modify another organization's data. Portal Users are further limited to the client and projects they have been granted.
- Access control. Role-based permissions for Authorized Users (owner, admin, manager, member, guest). Least-privilege access for FlowAgenci staff; production access is restricted to authorized personnel with two-factor authentication. Staff access to a Customer workspace is only possible through audited impersonation sessions limited to 30 minutes, read-only by default and requiring a reason.
- Authentication. Passwords, magic links and one-time codes (valid for 15 minutes, single use), optional passkeys and 2FA, organization-enforced 2FA on eligible Plans, session expiry, and per-IP and per-email rate limits on sign-in.
- Application security. Origin checks against cross-site request forgery, a strict Content Security Policy, bot protection (Cloudflare Turnstile) on public forms, input validation, and security headers.
- File security. Uploaded files are scanned for malware before they become available. Files are accessed only through short-lived signed URLs (typically 5–15 minutes) issued after an authorization check; stored objects are immutable per version.
- Availability and backups. Database point-in-time recovery for 30 days, nightly copies of object storage retained for 30 days, and documented restore procedures that are tested periodically.
- Logging and monitoring. Application and platform logs, error monitoring with Personal Data scrubbing, activity and audit logs (retained 24 months), security logs (retained 12 months), and alerting.
- Incident response. A documented incident response process, including triage, containment, investigation, notification to Customer within 48 hours of confirmation, and post-incident review.
- Secure development. Code review, automated tests in continuous integration (including tenant isolation tests), dependency updates, development and testing on isolated local environments with synthetic data (Customer Data is not copied to development environments), gated production deployments with database point-in-time recovery, and secrets managed outside source code with a rotation runbook.
- Vendor management. Due diligence of Subprocessors and written data protection terms with each of them.
- Personnel. Confidentiality obligations and data protection training for staff with access to Customer Data.
- Data minimization and retention. Short retention for tokens and notifications, defined retention for logs, and deletion of Customer Data after termination as set out in Section 10.
Annex III — Subprocessors
The list of authorized Subprocessors, with their location, function and the categories of data they process, is maintained at /legal/subprocessors and forms part of this Annex. At the effective date, it includes Cloudflare, Inc., Stripe, Inc. (Account Data only), Functional Software, Inc. d/b/a Sentry, and Google LLC (optional sign-in).