▸ legal // data processing agreement
Data Processing Agreement
Last updated: July 19, 2026
This Data Processing Agreement (“DPA”) supplements the Terms of Serviceand applies whenever you (“Controller”) use your FlowLogic hosted engine to process personal data, with FlowLogic, operated by Furkan Güven (“Processor”), acting on your behalf under Art. 28 GDPR. It is incorporated into the Terms automatically — no signature is required.
1. Subject matter and duration
The Processor operates a dedicated, single-tenant automation engine on which the Controller builds and runs automations. Processing lasts for the term of the subscription plus the 14-day wind-down period, after which all data is deleted (Section 7).
2. Nature and purpose of processing
Hosting, executing, backing up, and restoring the Controller’s automation flows and the data those flows process. The Processor does not use Controller data for its own purposes and has engine telemetry to the upstream software vendor disabled.
3. Categories of data and data subjects
Determined by the Controller’s flows — typically contact and business data of the Controller’s own customers, leads, and staff (names, email addresses, message content, CRM records). The Controller is responsible for ensuring a lawful basis for the data it processes and for not processing special-category data without appropriate safeguards.
4. Processor obligations
- Process personal data only to operate the Service and on the Controller’s documented instructions;
- Ensure persons authorised to access data are bound by confidentiality;
- Implement technical and organisational measures per Art. 32 GDPR, including: single-tenant isolation per customer, EU (Germany) hosting, HTTPS-only access, firewalled servers with key-only SSH, encryption at rest of stored connection credentials with envelope key management, tested backups, and intrusion mitigation (fail2ban, automatic security updates);
- Assist the Controller with data-subject rights requests and Art. 32–36 obligations, taking into account the nature of processing;
- Notify the Controller without undue delay after becoming aware of a personal data breach affecting their engine;
- Make available information reasonably necessary to demonstrate compliance with Art. 28.
5. Sub-processors
The Controller grants general authorisation for the sub-processors listed in the Privacy Policy. The Processor will announce additions that touch personal data in advance, giving the Controller the opportunity to object; continued use after the notice period constitutes acceptance.
6. International transfers
Engine data is stored in Germany. Operational/administrative access by the Processor from outside the EEA, and any sub-processor transfers, are protected by the EU Standard Contractual Clauses (Module 2, controller-to-processor), which are deemed incorporated into this DPA where required.
7. Deletion and return
During the 14-day wind-down after subscription end, the Controller may request an export of flow data. Afterwards the engine server and its data are permanently destroyed; backups age out within 7 days. Earlier deletion may be requested at any time.
8. Liability
Liability under this DPA follows the limitations in the Terms of Service, except where the GDPR mandates otherwise.