Customer as controller
The customer decides why and how customer personal data is processed.
This agreement describes how FlowPard processes customer personal data when providing the platform and forms part of the agreement between FlowPard and each customer using the service.
Customer as controller
The customer decides why and how customer personal data is processed.
FlowPard as processor
FlowPard processes customer data only to provide and secure the service.
Security safeguards
Reasonable technical and organisational measures protect customer data.
Return and deletion
Customer data is returned or deleted when services end, subject to legal retention.
Agreement status
This Data Processing Agreement supplements FlowPard's Terms of Service and applies where FlowPard processes personal data on behalf of a customer.
This Data Processing Agreement applies to personal data submitted, stored, transmitted, generated, or otherwise processed through FlowPard on behalf of a customer. It governs processing connected with CRM records, contacts, proposals, contracts, invoices, appointments, messages, analytics, prompt tools, documents, API activity, communication services, and other enabled FlowPard features.
If this agreement conflicts with the general Terms of Service on matters concerning customer personal data, this Data Processing Agreement will control to the extent of that conflict.
Customer
The customer generally acts as the data controller and determines the purposes and lawful basis for processing customer personal data.
FlowPard
FlowPard generally acts as the data processor and processes customer personal data only to provide, maintain, secure, and support the service.
Each party is responsible for complying with the data-protection obligations that apply to its role. The customer is responsible for ensuring that its collection and instructions are lawful and that required notices or permissions have been provided.
| Processing Element | Description |
|---|---|
| Subject matter | Providing, operating, maintaining, securing, supporting, and improving the FlowPard service for the customer. |
| Duration | For the period the customer uses FlowPard and any limited retention period required for deletion, backup, legal, security, or financial purposes. |
| Nature of processing | Collection, storage, organisation, retrieval, consultation, transmission, analysis, backup, deletion, and other operations needed to deliver the service. |
| Purposes | Account administration, CRM, communication, invoicing, analytics, collaboration, automation, support, fraud prevention, security, and related customer-configured workflows. |
| Data subjects | Customer users, employees, contractors, clients, leads, contacts, suppliers, recipients, and other individuals whose data is entered into FlowPard. |
| Data categories | Identity, contact, account, communication, billing, transaction, appointment, CRM, document, usage, device, technical, and customer-provided data. |
| Sensitive data | Not required for ordinary use. Customers should avoid submitting sensitive data unless necessary, lawful, and adequately protected. |
FlowPard will process customer personal data only on documented instructions from the customer, including instructions contained in the Terms of Service, this agreement, account settings, feature configurations, support requests, and actions performed through the platform.
FlowPard will restrict access to customer personal data to personnel and service providers who require access to perform authorised duties. Persons authorised to process customer personal data will be subject to confidentiality duties or another appropriate legal obligation of confidentiality.
FlowPard will maintain reasonable technical and organisational measures designed to protect customer personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
Access controls
Authentication, permissions, account controls, and restricted administrative access.
Secure transmission
Encrypted network communication where supported by the platform and service providers.
Logging and monitoring
Security logs, operational monitoring, error tracking, and suspicious-activity detection.
Resilience and recovery
Backups, recovery procedures, availability controls, and infrastructure safeguards appropriate to the service.
Security measures may evolve as technology, risk, and the FlowPard platform change, provided the overall level of protection is not materially reduced.
The customer authorises FlowPard to engage subprocessors that assist with hosting, databases, cloud infrastructure, authentication, communications, analytics, payments, support, monitoring, storage, and related platform operations.
FlowPard and its service providers may process customer personal data in countries other than the customer's location. Where required, FlowPard will use appropriate contractual, organisational, or legal safeguards for international transfers.
Customers are responsible for ensuring that their use of FlowPard and their instructions concerning international transfers comply with laws applicable to them and their data subjects.
FlowPard will provide reasonable assistance to help the customer respond to lawful requests from individuals seeking access, correction, deletion, restriction, portability, or objection concerning customer personal data.
FlowPard will notify the affected customer without undue delay after becoming aware of a confirmed personal data breach involving customer personal data, where notification is required by applicable law.
The notice may include available information about the nature of the incident, affected data, likely consequences, mitigation steps, and contact information. FlowPard may provide information in stages as the investigation develops.
The customer remains responsible for determining whether notifications to individuals, regulators, or other parties are required.
During the service period, customers may access and export available customer data through FlowPard features. After termination or account closure, FlowPard will delete or return customer personal data within a reasonable period, subject to:
On reasonable written request, FlowPard may provide information reasonably necessary to demonstrate compliance with this agreement, subject to confidentiality, security, legal, and operational restrictions.
Any audit request must be proportionate, relevant, scheduled in advance, avoid unnecessary disruption, and protect FlowPard's systems, other customers, confidential information, and security controls. The requesting customer may be responsible for reasonable costs associated with a specialised audit.
Contact FlowPard for data-processing questions, security enquiries, subprocessors, data-subject requests, or a signed enterprise data-processing agreement.
Data-processing enquiries
support@flowpard.comInclude your organisation name, FlowPard account email, and the nature of your request.