Data Processing Addendum
Last updated:
This Data Processing Addendum (“DPA”) forms part of the Agreement between Flowstate and the Customer and applies to all plans. Capitalised terms not defined here have the meaning given in the Terms of Service.
1. Definitions
- “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach” and “Processing” have the meanings given in the Data Protection Laws.
- “Customer Personal Data” means Personal Data contained in Customer Data that Flowstate processes on the Customer’s behalf.
- “Data Protection Laws” means the UK GDPR, the Data Protection Act 2018, the EU GDPR and any other data protection law applicable to the Processing.
- “De-identified Data” means data from which Flowstate has removed customer identifiers, API keys and other direct identifiers of the Customer.
- “Restricted Transfer” means a transfer of Personal Data that requires safeguards under the Data Protection Laws.
- “Sub-processor” means any third party Flowstate engages to process Customer Personal Data.
2. Roles
2.1 The Customer is the Controller and Flowstate is the Processor of Customer Personal Data.
2.2 Flowstate shall process Customer Personal Data only on the Customer’s documented instructions, unless required to do otherwise by law, in which case Flowstate shall inform the Customer unless the law prohibits it. The Agreement, the Customer’s configuration of the Services and the Customer’s use of the Services constitute the Customer’s complete instructions.
2.3 Flowstate shall inform the Customer if, in its opinion, an instruction infringes the Data Protection Laws. Flowstate is not obliged to carry out any such instruction.
3. Customer obligations
3.1 The Customer warrants that:
- it has a lawful basis for all Processing under this DPA, and has provided all notices and obtained all consents required by the Data Protection Laws;
- its instructions comply with the Data Protection Laws; and
- it shall not submit special category Personal Data, criminal offence data or Personal Data of children to the Services.
3.2 The Customer is solely responsible for the accuracy and lawfulness of Customer Personal Data and for selecting its Selected Region.
4. Flowstate obligations
Flowstate shall:
- ensure that all personnel authorised to process Customer Personal Data are bound by obligations of confidentiality;
- implement the security measures set out in Schedule 2;
- store Customer Personal Data in the Selected Region, logically separated by Tenant from the data of other customers, save as set out in Schedule 4; and
- not sell Customer Personal Data.
5. AI Requests and De-identified Data
5.1 Flowstate shall retain Requests, including prompts, responses and metadata, in the Selected Region for up to 7 days for the purpose of reconciling the Customer’s reporting.
5.2 Flowstate shall remove customer identifiers and API keys from Requests during processing, and shall hold Requests in that de-identified form until deletion.
5.3 The Customer authorises Flowstate to use De-identified Data to classify tasks, produce aggregated analytics about request volumes and business types, and develop and train Flowstate’s own classification and analytical models. To the extent such use constitutes Processing of Personal Data, Flowstate acts as an independent Controller for that use.
5.4 Flowstate shall not use Customer Data or De-identified Data to train or fine-tune any language model.
6. Sub-processors
6.1 The Customer grants Flowstate general authorisation to engage Sub-processors. The Sub-processors engaged at the date of this DPA are listed in Schedule 3.
6.2 Flowstate shall give the Customer not less than 30 days’ notice of any intended addition or replacement of a Sub-processor.
6.3 The Customer may object to a new Sub-processor on reasonable data protection grounds by written notice within 15 days of Flowstate’s notice. The parties shall discuss the objection in good faith. If they cannot resolve it within 30 days, the Customer’s sole remedy is to terminate the affected Services by written notice. No Fees shall be refunded.
6.4 Flowstate shall impose on each Sub-processor data protection obligations no less protective than those in this DPA, and remains liable for each Sub-processor’s performance of those obligations.
7. Personal Data Breaches
7.1 Flowstate shall notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
7.2 Flowstate shall provide the information reasonably available to it that the Customer requires to meet its obligations under the Data Protection Laws, and shall update that information as it becomes available.
7.3 Flowstate’s notification of a Personal Data Breach is not an acknowledgement of fault or liability.
8. Assistance
8.1 Taking into account the nature of the Processing, Flowstate shall provide reasonable assistance to the Customer in responding to requests from Data Subjects, and with data protection impact assessments and prior consultations with supervisory authorities relating to the Services.
8.2 Flowstate shall refer to the Customer any request it receives directly from a Data Subject relating to Customer Personal Data, and shall not respond except as instructed by the Customer.
8.3 Flowstate may charge the Customer at its standard rates for assistance that goes beyond the functionality of the Services.
9. Deletion
9.1 Flowstate shall delete Customer Personal Data within 30 days of the termination or expiry of the Agreement.
9.2 Flowstate may retain Customer Personal Data to the extent required by law, subject to this DPA, for so long as that law requires.
10. Audits
10.1 Flowstate shall make available to the Customer, on request and subject to confidentiality obligations, its most recent SOC 2 Type II report, and shall respond to reasonable written security questionnaires no more than once in any 12-month period.
10.2 Where the information in clause 10.1 is insufficient to demonstrate compliance with this DPA, or where required by a supervisory authority, the Customer may conduct an audit, provided that:
- the Customer gives not less than 30 days’ written notice;
- the audit takes place no more than once in any 12-month period, during business hours, and does not unreasonably disrupt Flowstate’s operations;
- the auditor is bound by confidentiality obligations acceptable to Flowstate and is not a competitor of Flowstate;
- the audit does not extend to the data, systems or information of any other customer; and
- the Customer bears all costs of the audit, including Flowstate’s reasonable costs.
11. International transfers
11.1 Flowstate shall not make a Restricted Transfer except in compliance with the Data Protection Laws.
11.2 Where a Restricted Transfer occurs, the parties agree that the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, as applicable, are incorporated into this DPA by reference.
12. Liability
Each party’s liability arising under or in connection with this DPA is subject to the exclusions and limitations of liability in the Terms of Service.
Schedule 1: Details of Processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the Services |
| Duration | The Subscription Term and the deletion period in clause 9 |
| Nature and purpose | Hosting, storage, analysis and transmission of Customer Data to provide, secure and support the Services |
| Data Subjects | The Customer’s employees, contractors and Authorised Users, and individuals whose data is contained in Third-Party Services connected by the Customer |
| Categories of Personal Data | Names, work email addresses, job titles, organisational structure, compensation and cost data, project assignments, work activity data from connected services, AI usage metadata, and Requests |
| Special category data | None |
Schedule 2: Security measures
- Encryption of data in transit using TLS 1.2 or higher, and at rest using AES-256.
- Access control on the principle of least privilege, with multi-factor authentication for all platform and personnel access.
- Logging and recording of all privileged sessions.
- Isolation of databases and caching infrastructure within virtual private clouds.
- Logical separation of Customer Data by Tenant.
- Continuous monitoring, logging and alerting across the platform.
- Independent penetration testing at least annually.
- Endpoint detection and response and full-disk encryption on all personnel devices.
- An annual SOC 2 Type II examination.
Schedule 3: Sub-processors
| Sub-processor | Purpose | Location | Scope |
|---|---|---|---|
| Google Cloud Platform | Hosting, compute, storage, databases, logging, analytics and AI processing | Selected Region. Application logs in GB1. Product analytics in EU1 | All customers |
| Cloudflare | AI Router | Cloudflare location nearest the Authorised User | Customers using the AI Router |
| Sentry | Error monitoring | European Union | All customers, unless opted out |
| Stripe | Payment processing | United States | Self-Serve Plans |
| Google Cloud Vertex AI, Amazon Web Services Bedrock, Microsoft Azure | Failover Service | Selected Region where available. Otherwise, the nearest location where the alternative provider offers the service | Customers using the Failover Service |
Schedule 4: Data location
1. Infrastructure
1.1 Flowstate provides the Services using Google Cloud Platform. Where the Customer uses the AI Router, Flowstate also uses Cloudflare, unless the Customer has agreed an alternative deployment in an Order Form.
1.2 Flowstate offers the following regions. Customers on Enterprise Plans may request additional regions, which Flowstate may provide at its discretion.
| Region | Location |
|---|---|
| EU1 | Belgium |
| GB1 | London, United Kingdom |
| US1 | South Carolina, United States |
1.3 Each region is operated as an independent deployment.
2. Storage of Customer Data
2.1 Flowstate stores and processes Customer Data, including all user account data, in the Selected Region, save as set out in paragraphs 3 and 4.
2.2 Following authentication, Flowstate routes the Customer’s requests directly to the Selected Region. Before authentication, the web application may be served from the location nearest the Authorised User.
3. Data in transit outside the Selected Region
The following data may transit locations outside the Selected Region. Flowstate does not store such data outside the Selected Region, save as stated.
| Data | Transit location | Retention outside the Selected Region |
|---|---|---|
| Email address of an Authorised User at login | Each Flowstate region, to identify the Customer’s Tenant | None. Not recorded in any log |
| Requests sent through the AI Router | The Cloudflare location nearest the Authorised User | Only until forwarded to the Selected Region |
| Webhook payloads from Third-Party Services | The Flowstate region nearest the sender | Only until forwarded to the Selected Region |
| Requests routed through the Failover Service | The alternative provider selected under the Terms of Service | Governed by that provider’s no-logging and no-retention terms |
4. Service data held outside the Selected Region
| Data | Location | Content |
|---|---|---|
| Routing identifiers | All Flowstate regions | Mappings between internal identifiers, such as Tenant and user identifiers, and regions. No Customer Data |
| Application logs | GB1 | Internal identifiers only. No names, email addresses or Customer Data |
| Product analytics | EU1 | Usage events and user identifiers, which may include email addresses. Excludes Customer Data |
| Error monitoring | Sentry, European Union | Application error reports |
5. Opt-out
5.1 The Customer may opt out of product analytics, error monitoring or both by written request to its support channel.
5.2 Where the Customer opts out, Flowstate shall have no liability for any failure to detect, prevent or resolve any issue that product analytics or error monitoring would have identified, and no such failure shall constitute Downtime under the SLA.