FLOWLOGIC

legal // data processing agreement

Data Processing Agreement

Last updated: July 19, 2026

This Data Processing Agreement (“DPA”) supplements the Terms of Serviceand applies whenever you (“Controller”) use your FlowLogic hosted engine to process personal data, with FlowLogic, operated by Furkan Güven (“Processor”), acting on your behalf under Art. 28 GDPR. It is incorporated into the Terms automatically — no signature is required.

1. Subject matter and duration

The Processor operates a dedicated, single-tenant automation engine on which the Controller builds and runs automations. Processing lasts for the term of the subscription plus the 14-day wind-down period, after which all data is deleted (Section 7).

2. Nature and purpose of processing

Hosting, executing, backing up, and restoring the Controller’s automation flows and the data those flows process. The Processor does not use Controller data for its own purposes and has engine telemetry to the upstream software vendor disabled.

3. Categories of data and data subjects

Determined by the Controller’s flows — typically contact and business data of the Controller’s own customers, leads, and staff (names, email addresses, message content, CRM records). The Controller is responsible for ensuring a lawful basis for the data it processes and for not processing special-category data without appropriate safeguards.

4. Processor obligations

  • Process personal data only to operate the Service and on the Controller’s documented instructions;
  • Ensure persons authorised to access data are bound by confidentiality;
  • Implement technical and organisational measures per Art. 32 GDPR, including: single-tenant isolation per customer, EU (Germany) hosting, HTTPS-only access, firewalled servers with key-only SSH, encryption at rest of stored connection credentials with envelope key management, tested backups, and intrusion mitigation (fail2ban, automatic security updates);
  • Assist the Controller with data-subject rights requests and Art. 32–36 obligations, taking into account the nature of processing;
  • Notify the Controller without undue delay after becoming aware of a personal data breach affecting their engine;
  • Make available information reasonably necessary to demonstrate compliance with Art. 28.

5. Sub-processors

The Controller grants general authorisation for the sub-processors listed in the Privacy Policy. The Processor will announce additions that touch personal data in advance, giving the Controller the opportunity to object; continued use after the notice period constitutes acceptance.

6. International transfers

Engine data is stored in Germany. Operational/administrative access by the Processor from outside the EEA, and any sub-processor transfers, are protected by the EU Standard Contractual Clauses (Module 2, controller-to-processor), which are deemed incorporated into this DPA where required.

7. Deletion and return

During the 14-day wind-down after subscription end, the Controller may request an export of flow data. Afterwards the engine server and its data are permanently destroyed; backups age out within 7 days. Earlier deletion may be requested at any time.

8. Liability

Liability under this DPA follows the limitations in the Terms of Service, except where the GDPR mandates otherwise.