FlowQi Data Processing Agreement
Effective date: 27 August 2026 · Version: 1.1 · Language: English (binding version)
This Data Processing Agreement (the “DPA”) forms part of the Terms of Service (the “Agreement”) between you (the “Controller”) and the FlowQi contracting entity determined under Article 2.1 of the Terms (the “Processor”, “FlowQi”). It governs FlowQi’s processing of personal data on your behalf.
Most customers do not need to sign anything: Schedule C of the Terms already contains processor terms that meet Article 28(3) GDPR, and it applies automatically. This DPA is the same commitment as a standalone document, for procurement and vendor-review processes that require one. Where you and FlowQi have signed a separate data processing agreement, that signed agreement prevails over both this page and Schedule C.
1. Definitions
Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject”, “supervisory authority” and “personal data breach” have the meaning given in the GDPR (Regulation (EU) 2016/679) and, for the United Kingdom, the UK GDPR and the Data Protection Act 2018. “Customer Data” and other capitalised terms have the meaning given in the Agreement. “Data Protection Law” means the GDPR, the UK GDPR, the Dutch UAVG, and any other applicable data protection law.
2. Roles and scope
2.1 As between the parties, the Controller is the controller and FlowQi is the processor of personal data contained in Customer Data. Where the Controller is itself a processor for a third party, FlowQi acts as sub-processor.
2.2 FlowQi processes personal data only to provide and support the Services and on the Controller’s documented instructions, including as set out in the Agreement, this DPA, and the Controller’s use of the admin settings. FlowQi will inform the Controller if, in its opinion, an instruction infringes Data Protection Law, unless it is legally prohibited from doing so.
2.3 The subject matter, duration, nature, purpose, types of personal data and categories of data subjects are described in Annex I.
2.4 AI features. AI-assisted features are not currently enabled in the product, and no AI provider processes Customer Data at this time. Where such features are introduced, FlowQi may process prompts, inputs and outputs as Customer Data solely to provide, secure, debug and support the Services. Any third-party AI provider used will be listed as a sub-processor before the feature is activated, and will be contractually restricted from training its own models on Customer Data.
3. Processor obligations
FlowQi will:
a. process personal data only on documented instructions, including for international transfers, unless required by EU, EU member state or UK law, in which case it will inform the Controller unless legally prohibited; b. ensure that persons authorised to process personal data are bound by confidentiality; c. implement the technical and organisational measures in Annex II, as required by Article 32 GDPR; d. respect the conditions for engaging sub-processors in section 5; e. assist the Controller, insofar as possible and by appropriate technical and organisational measures, in responding to data subject requests under Articles 12 to 23, providing reasonable assistance without undue delay and, where feasible, within 10 business days of the Controller’s request; f. assist the Controller with security, breach notification, data protection impact assessments and prior consultation under Articles 32 to 36, taking into account the nature of the processing and the information available to FlowQi; g. at the Controller’s choice, delete or return all personal data at the end of the provision of the Services, and delete existing copies unless storage is legally required, as set out in section 7; and h. make available the information necessary to demonstrate compliance and allow for and contribute to audits, as set out in section 8.
4. Security
FlowQi maintains appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex II, including encryption in transit and at rest, access controls and least-privilege access, multi-factor authentication options, logging and monitoring, resilience and backup, and regular testing of measures. FlowQi may update those measures provided the overall level of protection is not reduced.
5. Sub-processors
5.1 The Controller grants general written authorisation for FlowQi to engage sub-processors to process personal data, provided FlowQi:
a. maintains a current list of sub-processors, published at flowqi.com/legal/subprocessors and available on request at legal@flowqi.com; b. imposes data protection obligations on each sub-processor that are no less protective than this DPA; and c. remains liable for its sub-processors’ performance, as required under Article 28(4) GDPR.
5.2 FlowQi will give the Controller at least 30 days’ notice of any intended addition or replacement of a sub-processor that processes Customer Data. The Controller may object on reasonable data protection grounds within that period. The parties will work in good faith to resolve the objection, and if they cannot, the Controller may terminate the affected part of the Agreement without penalty and receive a refund of fees paid for the unused remainder of the applicable Subscription Term.
6. International transfers
6.1 FlowQi operates separate EU and US data clusters. Which cluster holds Customer Data follows the contracting entity under Article 2.1 of the Terms, and matches Schedule B.7 of the Terms. For customers contracting with FlowQi Nederland B.V. or FlowQi International B.V., Customer Data is hosted in the EU/EEA, primarily Supabase (Frankfurt, Germany) and DigitalOcean (Amsterdam, the Netherlands), with additional EU infrastructure from Scaleway (France). For customers contracting with FlowQi, Inc., Customer Data is hosted in the United States. Customers established in Türkiye pick their contracting entity when they create their account and therefore pick their cluster; section 6.3 covers the KVKK.
Some sub-processors operate globally. Where personal data is transferred outside the EEA or the UK, FlowQi relies on an appropriate transfer mechanism, namely:
- the EU Standard Contractual Clauses (2021/914) (“EU SCCs”), incorporated by reference for restricted transfers from the EEA;
- the UK International Data Transfer Addendum (IDTA) for restricted transfers from the UK; and
- where applicable, an adequacy decision or another valid mechanism under Chapter V GDPR.
6.2 For the EU SCCs: Module Two (controller to processor) or Module Three (processor to processor) applies as relevant; the Controller is the data exporter and FlowQi, or the relevant entity, is the data importer; the optional docking clause applies; the governing law and forum are those of the Netherlands, or as required by the SCCs; and Annexes I to III of this DPA populate the SCC annexes. In a conflict, the SCCs prevail over this DPA on transfer matters.
6.3 Türkiye (KVKK). Where the Controller is established in Türkiye, or the processing is subject to the Turkish Personal Data Protection Law no. 6698 ("KVKK"), Schedule E of the Terms applies in addition to this DPA and prevails to the extent necessary to comply with mandatory Turkish data protection law. Personal data subject to the KVKK is not transferred outside Türkiye solely on the basis of the EU SCCs. The parties use a mechanism recognised under Turkish law: a Kurul adequacy decision, the applicable Kurul standard contract, approved binding corporate rules, or another lawful mechanism under the KVKK. Where a standard contract is used, the responsible party notifies the Kurul within 5 business days of full execution; absent a designation in that contract, the data exporter is responsible.
7. Return and deletion
On termination or expiry of the Services, FlowQi will make Customer Data available for export for 30 days, after which FlowQi will delete or de-identify personal data within 90 days, except for backup copies that are deleted in accordance with FlowQi’s standard backup retention cycle, and unless retention is required by law. The same 30 and 90 day windows apply to an expired trial, counted from the end of the trial period, and to a Free Plan account closed after twelve months without a sign-in. FlowQi’s in-product lifecycle, from trash to archive to restore to permanent deletion, lets the Controller manage deletion during the term.
8. Audits
FlowQi will make available the information reasonably necessary to demonstrate compliance with this DPA. The parties will first seek to satisfy audit requests through documentation, security summaries, certifications and third-party audit reports. On-site or technical audits are permitted only where reasonably necessary and are subject to reasonable confidentiality, security and access restrictions. Where such an audit is justified, the Controller, or an independent auditor bound by confidentiality, may audit FlowQi no more than once per calendar year, and additionally after a personal data breach materially affecting the Controller’s Customer Data, on reasonable prior notice, during business hours, and without unreasonably disrupting FlowQi’s operations. This section does not limit the powers of a competent supervisory authority.
9. Breach notification
FlowQi will notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Data. This is the window committed in Article C.11 of the Terms, and again in Article E.6 for customers subject to the KVKK. It is deliberately tighter than the 72 hours Article 33 GDPR gives the Controller towards its own supervisory authority, so that the Controller has time to act.
FlowQi will provide the information reasonably available to it to help the Controller meet its own obligations under Articles 33 and 34, including, as available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.
10. Liability and order of precedence
Liability under this DPA is subject to the limitations in the Agreement. This DPA prevails over the rest of the Agreement on personal data matters, and the EU SCCs prevail over this DPA on transfer matters. For customers subject to the KVKK, Schedule E of the Terms prevails to the extent set out in Article E.5.
Annex I. Description of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the FlowQi cloud platform, including CRM, projects, tasks and related modules |
| Duration | The term of the Agreement plus the export and deletion periods in section 7 |
| Nature and purpose | Hosting, storage and processing of Customer Data to deliver, support, secure and maintain the Services |
| Types of personal data | Account and contact details (names, business email, phone), authentication data, CRM records (contacts, organisations, notes), project and task content, time entries, usage, log and metadata, and any other personal data the Controller chooses to submit |
| Special categories | Not intended. FlowQi has not designed the Services for special category data (Article 9), criminal offence data (Article 10), medical data, or other high-risk personal data. The Controller must not submit such data unless separately agreed in writing and lawful, and is responsible for any such data it chooses to submit. For customers subject to the KVKK, Article E.7 of the Terms defines the relevant categories |
| Categories of data subjects | The Controller’s personnel and authorised users; the Controller’s own customers, contacts, suppliers and prospects entered into the Services |
| Frequency | Continuous, for the duration of the Agreement |
Annex II. Technical and organisational measures
- Encryption of personal data in transit (TLS) and at rest.
- Access control: role-based permissions across CRM, projects and administration; per-workspace scoping; a protected super-admin role; least-privilege internal access; single sign-on via Google, Microsoft, or email and password.
- Authentication: multi-factor authentication available and enforceable at workspace level; password reset and account recovery flows.
- Logging and monitoring: activity logging, including a record of who archived or deleted items; security monitoring.
- Data lifecycle and recovery: trash, archive, restore and permanent deletion model; daily backups of the production database retained for at least 30 days, stored encrypted in the region of the cluster they were taken from; resilience measures.
- Segregation: separate production, staging and development environments.
- Organisational: confidentiality obligations for staff; vendor and sub-processor due diligence; vulnerability management and patching; a documented incident response process.
- Pseudonymisation and minimisation where appropriate.
- Certifications: ISO 27001 and SOC 2 programmes are in progress. Neither certification is held as at the effective date of this DPA, and FlowQi does not offer either as available documentation until it is certified.
Annex III. Sub-processors
The current list is published at flowqi.com/legal/subprocessors, which forms part of this DPA, and is available on request at legal@flowqi.com. That page also records where each sub-processor processes data and which transfer safeguard applies.
Questions about this DPA: legal@flowqi.com · FlowQi, Australiëlaan 5, 3526 AB Utrecht, the Netherlands