This DPA forms part of the agreement between Flows360 LTD ("Flows360") and the customer ("Customer") where Flows360 processes Personal Data on Customer's behalf.
Roles
Customer is Controller or Processor acting for another Controller. Flows360 is Processor or Subprocessor as applicable. Each party complies with laws applicable to its role.
Instructions
Flows360 processes Customer Personal Data only to provide contracted services, according to documented Customer instructions, or as legally required. The agreement, configuration and authorised service use constitute instructions. Flows360 may notify Customer and suspend affected processing if it believes an instruction infringes applicable data-protection law.
Processing details
Subject matter: Flows360 integration, workflow automation and related software services.
Duration: Applicable agreement plus limited deletion, backup or legal-retention periods.
Nature: Receiving, transmitting, mapping, querying, transforming, storing where applicable, organising and otherwise processing information through Customer-configured workflows/integrations.
Purpose: Providing the service according to Customer instructions.
Data subjects and data
Depending on configuration, data subjects may include Customer personnel, prospects/customers, system users, suppliers/partners, business contacts and other individuals lawfully processed by Customer.
Data may include names, business contact details, account identifiers, CRM/support information, operational records, workflow/usage records and other Customer-configured personal information.
Special-category/highly sensitive information may only be processed where relevant service, infrastructure and contracts expressly permit it.
Confidentiality
Authorised Flows360 personnel processing Customer Personal Data will be subject to appropriate confidentiality obligations.
Security
Flows360 will maintain reasonable technical and organisational measures appropriate to the service and processing risk. As applicable these may include access/authentication controls, encrypted transport, infrastructure security, logging/monitoring, tenant/application access controls, secure credential handling, incident response and approved-provider security controls.
Security is shared between Flows360, its infrastructure providers and Customer's own systems/configuration.
Subprocessors
Customer grants general authorisation for subprocessors necessary to provide the service. A current list is maintained at flows360.co/subprocessors. Flows360 will impose appropriate data-protection obligations on subprocessors and provide reasonable notice of material new subprocessors where required.
International transfers
Where required, international transfers will use appropriate mechanisms such as adequacy, Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum.
Data-subject requests
Taking account of processing nature, Flows360 will reasonably assist Customer with applicable data-subject requests. Direct requests concerning Customer-controlled data may be referred to Customer unless prohibited by law.
Personal Data Breaches
Flows360 will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data and provide reasonably available information to assist Customer's legal obligations.
DPIAs and regulators
Taking account of processing and available information, Flows360 will reasonably assist with required DPIAs and regulatory consultation relating to Flows360 processing.
Return and deletion
At service end, Flows360 will, at Customer's choice and where technically/legally applicable, delete or return Customer Personal Data. Copies may remain temporarily in ordinary backup/disaster-recovery cycles. Legally required information may be retained.
Compliance and audit
Flows360 will make reasonably necessary compliance information available. If law requires further audit rights and evidence is insufficient, the parties will agree an appropriate audit process minimising disruption and protecting other customers' confidentiality/security.
Customer responsibilities
Customer is responsible for data lawfulness, notices, lawful basis/consents, lawful instructions, appropriate configuration and determining suitability for its regulatory requirements.
Conflict and governing law
This DPA prevails over general Terms concerning Customer Personal Data. Unless otherwise agreed, it is governed by England and Wales law.
