Last updated: March 6, 2025
Important: This Data Processing Agreement (DPA) forms part of the Terms of Service between Flowziac and our customers. It outlines our obligations as a data processor under GDPR and other data protection laws. The DPA includes the EU Standard Contractual Clauses (SCCs) for international data transfers.
**Last Updated:** March 6, 2025
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Flowziac Technologies Private Limited ("Processor") and the customer ("Controller") regarding the processing of personal data through Flowziac's WhatsApp automation platform and services ("Services"). This DPA is effective as of the date of acceptance of the Terms of Service.
**1.1 "Applicable Data Protection Law"** means:
**1.2 "Controller"** means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
**1.3 "Data Subject"** means an identified or identifiable natural person whose personal data is processed.
**1.4 "GDPR"** means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
**1.5 "Personal Data"** means any information relating to a Data Subject that is processed by Processor on behalf of Controller through the Services.
**1.6 "Processing"** means any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
**1.7 "Processor"** means Flowziac Technologies Private Limited, the natural or legal person, public authority, agency, or other body which processes personal data on behalf of the Controller.
**1.8 "Security Incident"** means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
2.1 Controller Responsibilities
The Controller shall:
2.2 Processor Responsibilities
Processor shall:
3.1 Scope of Processing
Processor is authorized to process personal data solely to:
3.2 Instructions
Controller's initial instructions are set forth in the Terms of Service and Service documentation. Controller may provide additional instructions through:
Processor will not process personal data for any other purpose without Controller's prior written authorization.
3.3 International Data Transfers
Personal data may be transferred to and processed in countries outside the Controller's jurisdiction, including India, the United States, and other locations where Processor's service providers operate. Processor ensures appropriate safeguards for such transfers:
4.1 Technical and Organizational Measures
Processor implements and maintains appropriate technical and organizational measures to protect personal data, including:
4.1.1 Access Controls
4.1.2 Data Protection
4.1.3 Infrastructure Security
4.1.4 Monitoring and Logging
4.1.5 Data Management
4.1.6 Personnel
4.1.7 Incident Response
4.2 Regular Assessment
Processor will:
5.1 Authorized Sub-processors
Processor may engage sub-processors to assist in providing the Services. Current sub-processors include:
| Sub-processor | Services | Location | Data Transfer Mechanism |
|---------------|----------|----------|------------------------|
| Amazon Web Services (AWS) | Cloud hosting | USA/Global | SCCs |
| Google Cloud Platform | Analytics, monitoring | USA/Global | SCCs |
| WhatsApp (Meta) | Message delivery | USA/Global | SCCs |
| Paddle | Billing & subscriptions | USA/Global | SCCs |
| SendGrid/Mailgun | Email notifications | USA | SCCs |
5.2 New Sub-processors
Processor will notify Controller at least 30 days before engaging any new sub-processor. Controller may object to such engagement in writing within 15 days of notification, providing reasonable grounds for objection. If Controller objects, Processor will either not engage the sub-processor or provide alternative arrangements.
5.3 Sub-processor Obligations
All sub-processors are bound by written agreements that impose:
Processor remains liable to Controller for sub-processor compliance.
6.1 Assistance Obligations
Processor shall provide reasonable assistance to Controller to fulfill its obligations under Applicable Data Protection Law regarding Data Subject rights, including:
6.2 Request Handling
Upon receiving a Data Subject request from Controller, Processor will:
6.3 Direct Requests
If Processor receives a Data Subject request directly, it will:
7.1 Notification Requirements
Processor will notify Controller without undue delay and in any event within 72 hours of becoming aware of a Security Incident affecting personal data.
7.2 Notification Content
The notification will include:
7.3 Cooperation
Processor will:
8.1 DPIA Assistance
If Controller is required to conduct a DPIA under Applicable Data Protection Law, Processor will provide reasonable assistance, including:
8.2 Prior Consultation
If Controller is required to consult a supervisory authority prior to processing, Processor will cooperate with such consultation and provide necessary information.
9.1 Upon Termination
Upon termination of the Terms of Service or upon Controller's request, Processor will:
9.2 Retention Beyond Deletion
Processor may retain personal data longer if required to:
Such retained data will remain subject to this DPA and will be deleted as soon as retention is no longer required.
10.1 Audit Rights
Controller may audit Processor's compliance with this DPA:
10.2 Scope of Audit
The audit may include:
10.3 Alternative: Third-Party Certifications
Instead of an audit, Controller may accept:
Processor will provide such documentation upon request.
10.4 Confidentiality
Audit findings are confidential and may only be shared with Controller's advisors and as required by law.
11.1 Maintenance
Processor maintains records of processing activities performed on behalf of Controller, including:
11.2 Access
Controller may access these records upon reasonable request to verify Processor's compliance with this DPA.
12.1 Personnel Confidentiality
Processor ensures that all personnel with access to personal data are bound by confidentiality obligations.
12.2 Business Confidentiality
Both parties agree to keep confidential all information disclosed in connection with this DPA, except as required by law or to fulfill obligations under this DPA.
13.1 Liability Cap
Processor's total liability for any breach of this DPA shall not exceed the total fees paid by Controller to Processor in the 12 months preceding the incident.
13.2 Data Protection Liabilities
Notwithstanding the above, liability for violations of data protection laws may be subject to statutory limits as defined by Applicable Data Protection Law.
13.3 Indemnification
Processor shall indemnify Controller against third-party claims arising from Processor's breach of this DPA, provided that:
This DPA is governed by the same law as the Terms of Service. Any dispute arising from this DPA shall be resolved in accordance with the dispute resolution provisions in the Terms of Service.
15.1 Term
This DPA is effective as of the effective date of the Terms of Service and remains in effect for as long as Processor processes personal data on behalf of Controller.
15.2 Survival
Provisions that by their nature should survive termination shall survive, including:
16.1 Order of Precedence
In case of conflict between the Terms of Service and this DPA, this DPA shall prevail with respect to data protection matters.
16.2 Amendments
Any amendment to this DPA must be in writing and signed by both parties. Processor may update this DPA to reflect changes in Applicable Data Protection Law with 30 days' notice.
16.3 No Third-Party Beneficiaries
This DPA is solely for the benefit of the parties and does not confer rights on third parties, including Data Subjects.
16.4 Entire Agreement
This DPA, together with the Terms of Service and Privacy Policy, constitutes the entire agreement between the parties regarding data processing matters.
For data protection inquiries, privacy concerns, or to exercise Data Subject rights:
Flowziac Technologies Private Limited
Data Protection Officer
Email: dpo@flowziac.com
Address: [Your Company Address]
---
The parties agree that transfers of personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to Processor's facilities shall be governed by the European Commission's Standard Contractual Clauses for Processors (SCCs), as set forth in Commission Implementing Decision (EU) 2021/914.
The SCCs are incorporated by reference into this DPA. The parties complete the required information as follows:
Module Three (Controller-to-Processor)
Optional Clauses:
The SCCs shall be interpreted in conjunction with this DPA. In case of conflict, the SCCs shall prevail.
---
B.1 Data Security
B.2 Access Control
B.3 Infrastructure
B.4 Monitoring and Logging
B.5 Development and Testing
B.6 Personnel
B.7 Business Continuity
B.8 Data Minimization
B.9 Sub-processor Management
---
C.1 Data Categories Processed
C.2 Special Categories of Data
Processor does not intentionally process special categories of personal data (sensitive data) unless explicitly declared by Controller with appropriate safeguards and legal basis. Controller warrants that it will not upload or process sensitive personal data without:
C.3 Children's Data
Controller must not process personal data of children under the age of 16 (or lower age as defined by Applicable Data Protection Law) without verifiable parental consent. Controller is responsible for implementing age verification mechanisms and obtaining necessary consents.
---
D.1 Core Processing Activities
Processor is authorized to perform the following processing activities:
D.2 Retention Periods
D.3 Data Location
Primary data storage: AWS regions in [specify regions, e.g., Asia Pacific (Mumbai), US East (N. Virginia)]
Backup storage: AWS regions in [specify regions]
Sub-processor data: As per sub-processor locations in Section 5
D.4 Purposes of Processing
D.5 Data Subject Categories
---
Controller represents and warrants that:
E.1 Lawful Basis
Controller has obtained all necessary consents, provided appropriate privacy notices, and established a lawful basis for processing personal data through the Services.
E.2 Data Accuracy
Controller is responsible for the accuracy, quality, and completeness of all personal data provided to Processor.
E.3 Compliance
Controller shall use the Services in compliance with all Applicable Data Protection Laws, including but not limited to:
E.4 Sensitive Data
Controller will not process sensitive personal data (special categories) without explicit consent and prior written notification to Processor.
E.5 International Transfers
Controller has appropriate legal mechanisms in place for international transfers of personal data to Processor, including Standard Contractual Clauses where required.
E.6 Data Subject Communications
Controller is responsible for all communications with Data Subjects regarding their personal data. Processor will not communicate directly with Data Subjects except as instructed by Controller or required by law.
E.7 Data Protection Officer
Controller has appointed a Data Protection Officer or equivalent responsible for data protection matters, with contact details provided to Processor.
---
The parties confirm that they have entered into this DPA in accordance with the requirements of the GDPR and other Applicable Data Protection Laws. The SCCs are fully incorporated and binding upon the parties.
Party Details:
Controller:
Processor:
---
Execution
By accepting the Terms of Service and using the Services, the parties agree to be bound by this DPA. No separate signature is required.
For any questions regarding this DPA, contact dpo@flowziac.com.
This DPA is automatically incorporated into our Terms of Service for all customers who process personal data through our platform.