Template · Pending legal review · Not executed
Data Processing Addendum
Version 0.1 (Draft) — for counsel review only
1. Parties and Roles
This Data Processing Addendum (“DPA”) forms part of the agreement between [TBD: FLXR legal entity name and registered address] (“FLXR”, “Processor”) and the customer identified in the signature block (“Customer”) governing Customer's use of the FLXR services (the “Agreement”).
With respect to Personal Data processed under this DPA: (a) where Customer is a business processing its own data, Customer acts as Controller and FLXR acts as Processor; (b) where Customer is an agency processing Personal Data on behalf of its own clients, Customer acts as Processor for those clients and FLXR acts as Sub-processor. Customer warrants that it has the authority and a lawful basis to engage FLXR in either capacity.
2. Scope, Nature and Purpose of Processing
FLXR processes Personal Data solely to provide the services described in the Agreement: an AI marketing agent platform that discovers relevant social-media conversations, generates proposed engagement content for human approval, captures and manages leads, schedules and publishes Customer-approved content, and provides related analytics and reporting. [TBD: confirm full processing scope with counsel (email campaigns, etc.)]
Processing is performed on Customer's documented instructions as expressed through the Agreement, this DPA, and Customer's configuration and use of the services. FLXR does not sell Personal Data. [TBD: AI-training / model-improvement statement — confirm with vendors and counsel before any customer-facing version]
Duration: the term of the Agreement, plus the deletion window in Section 9.
3. Categories of Data and Data Subjects
Data subjects: Customer's authorized users and team members; Customer's (or its clients') prospective customers and leads identified from public social-media conversations; other data subjects whose Personal Data Customer submits to the services. [TBD: finalize data-subject categories with counsel]
Categories of Personal Data: account data (name, email, authentication identifiers); public social-media profile data and public post content of identified leads; lead contact details entered or captured by Customer; usage and technical data (IP address, device information, log data). [TBD: finalize personal-data categories with counsel]
Special categories: the services are not designed to process special-category (sensitive) data, and Customer agrees not to submit it.
4. Processor Obligations
FLXR shall:
- process Personal Data only on Customer's documented instructions, unless required by law (in which case FLXR will notify Customer unless legally prohibited);
- ensure persons authorized to process Personal Data are bound by confidentiality obligations;
- implement and maintain the technical and organizational measures described in Section 6;
- assist Customer, taking into account the nature of processing, in responding to data-subject requests (Section 7) and in meeting Customer's security, breach-notification, and impact-assessment obligations;
- delete or return Personal Data at termination (Section 9); and
- make available information reasonably necessary to demonstrate compliance with this DPA (Section 11).
5. Sub-processors
Customer provides general authorization for FLXR to engage sub-processors solely as needed to deliver the services. The authorized sub-processor schedule is: [TBD: complete sub-processor list — legal entity names, purposes, and processing locations].
FLXR will provide notice of intended additions or replacements at least [TBD: notice period, e.g. 30 days] in advance, during which Customer may object on reasonable data-protection grounds. FLXR remains responsible for its sub-processors' performance under this DPA.
Working inventory for counsel (not a final schedule)
Product engineering maintains a provisional vendor inventory (Firebase/GCP, Vercel, Stripe, email, AI providers, monitoring, etc.) for counsel to validate. Until that schedule is completed and approved, do not treat any informal list as the contractual sub-processor annex. See also docs/VERIFY_SECURITY_DPA.md.
6. Security Measures
FLXR implements and maintains technical and organizational measures appropriate to the risk, including (as further described on flxr.ai/security):
- Tenant isolation: owner-scoped customer data; Firestore rules require Firebase Authentication matching the data owner for client access paths; privileged operations via a trusted server layer.
- Encryption in transit: TLS/HTTPS; HSTS on production web responses.
- Encryption at rest: cloud-provider default encryption; application-layer encryption (AES-256-GCM) for certain stored social-platform session credentials.
- Access control: authenticated accounts; TOTP two-factor authentication for FLXR administrator accounts. [TBD: describe customer-facing access controls counsel is comfortable publishing]
- Payment isolation: card data processed by Stripe; not stored on FLXR systems.
- Human-in-the-loop: agent-proposed posts/replies require human approval before publishing (subject to Customer-configured workflows).
[TBD: full technical and organizational measures schedule — counsel to align with actual controls]
7. Data-Subject Rights
Taking into account the nature of the processing, FLXR will assist Customer by appropriate technical and organizational measures in fulfilling Customer's obligation to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection), to the extent applicable. If a data subject contacts FLXR directly regarding Customer's data, FLXR will forward the request to Customer without undue delay and will not respond on Customer's behalf except as instructed or required by law. [TBD: assistance SLAs / process details — legal review]
8. Personal Data Breach Notification
FLXR will notify Customer without undue delay, and no later than [TBD: notification window, e.g. 72 hours] after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed. FLXR will cooperate with Customer's reasonable investigation and Customer's own notification obligations.
9. Deletion or Return on Termination
Upon termination or expiry of the Agreement, FLXR will, at Customer's choice, delete or return Customer Personal Data within [TBD: deletion / return window, e.g. 30/60/90 days], and delete existing copies, unless applicable law requires continued storage (for example, billing records), in which case such data remains protected under this DPA and is isolated from further processing except as required by law. [TBD: self-serve deletion process wording — confirm with product + counsel]
10. International Transfers
Where processing involves a transfer of Personal Data originating from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties will rely on appropriate safeguards as determined by counsel — for example Standard Contractual Clauses and related addenda, incorporated by reference as required — together with supplementary measures where appropriate. [TBD: transfer mechanism, SCC modules, and transfer impact assessment — legal review required]
11. Audits and Information
FLXR will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits on terms to be agreed. [TBD: audit frequency, notice, confidentiality, and cost allocation — legal review]
12. Liability
Each party's liability arising out of or related to this DPA is subject to the exclusions and limitations of liability set out in the Agreement. [TBD: liability cap and carve-outs — legal review required]
13. Governing Law and Jurisdiction
This DPA is governed by [TBD: governing law]. The courts of [TBD: jurisdiction / venue] shall have exclusive jurisdiction over disputes arising out of or in connection with this DPA, subject to any mandatory local law protections for data subjects.
14. Signatures
Not for signature — template pending legal review. Do not execute this form.
FLXR (Processor)
Entity: [TBD: legal entity]
Name / Title: ____________________
Signature: ____________________
Date: ____________________
Customer (Controller / Processor)
Entity: ____________________
Name / Title: ____________________
Signature: ____________________
Date: ____________________