# FLXR — Data Processing Addendum (TEMPLATE / DRAFT)

**Version 0.1 (Draft)**  
**Status: PENDING LEGAL REVIEW — NOT AN EXECUTED OR FINAL AGREEMENT**

> **TEMPLATE — PENDING LEGAL REVIEW.**
>
> This document is a structural draft for counsel. It contains unresolved `[TBD]` placeholders
> (including **legal entity**, **sub-processor list**, and **jurisdiction**), has not been
> approved by a lawyer, and **creates no binding obligations** until completed, reviewed, and
> signed by both parties.
>
> **Harold: this needs a lawyer's pass before publishing or offering for signature.**
> Tracker ticket: **WEB-061** (status: blocked — legal review).
>
> After legal approval, customers may request an executed copy via
> `[TBD: official DPA contact email]`.

---

## 1. Parties and Roles

This Data Processing Addendum ("DPA") forms part of the agreement between
**[TBD: FLXR legal entity name and registered address]** ("FLXR", "Processor") and the customer
identified in the signature block ("Customer") governing Customer's use of the FLXR services
(the "Agreement").

With respect to Personal Data processed under this DPA: (a) where Customer is a business
processing its own data, Customer acts as **Controller** and FLXR acts as **Processor**;
(b) where Customer is an agency processing Personal Data on behalf of its own clients, Customer
acts as **Processor** for those clients and FLXR acts as **Sub-processor**. Customer warrants
that it has the authority and a lawful basis to engage FLXR in either capacity.

## 2. Scope, Nature and Purpose of Processing

FLXR processes Personal Data solely to provide the services described in the Agreement: an AI
marketing agent platform that discovers relevant social-media conversations, generates proposed
engagement content for human approval, captures and manages leads, schedules and publishes
Customer-approved content, and provides related analytics and reporting.
[TBD: confirm full processing scope with counsel (email campaigns, etc.)]

Processing is performed on Customer's documented instructions as expressed through the Agreement,
this DPA, and Customer's configuration and use of the services. FLXR does not sell Personal Data.
[TBD: AI-training / model-improvement statement — confirm with vendors and counsel before any
customer-facing version]

**Duration:** the term of the Agreement, plus the deletion window in Section 9.

## 3. Categories of Data and Data Subjects

**Data subjects:** Customer's authorized users and team members; Customer's (or its clients')
prospective customers and leads identified from public social-media conversations; other data
subjects whose Personal Data Customer submits to the services.
[TBD: finalize data-subject categories with counsel]

**Categories of Personal Data:** account data (name, email, authentication identifiers); public
social-media profile data and public post content of identified leads; lead contact details
entered or captured by Customer; usage and technical data (IP address, device information, log
data).
[TBD: finalize personal-data categories with counsel]

**Special categories:** the services are not designed to process special-category (sensitive)
data, and Customer agrees not to submit it.

## 4. Processor Obligations

FLXR shall:

- process Personal Data only on Customer's documented instructions, unless required by law (in
  which case FLXR will notify Customer unless legally prohibited);
- ensure persons authorized to process Personal Data are bound by confidentiality obligations;
- implement and maintain the technical and organizational measures described in Section 6;
- assist Customer, taking into account the nature of processing, in responding to data-subject
  requests (Section 7) and in meeting Customer's security, breach-notification, and
  impact-assessment obligations;
- delete or return Personal Data at termination (Section 9); and
- make available information reasonably necessary to demonstrate compliance with this DPA
  (Section 11).

## 5. Sub-processors

Customer provides general authorization for FLXR to engage sub-processors solely as needed to
deliver the services. The authorized sub-processor schedule is:

**[TBD: complete sub-processor list — legal entity names, purposes, and processing locations]**

FLXR will provide notice of intended additions or replacements at least
[TBD: notice period, e.g. 30 days] in advance, during which Customer may object on reasonable
data-protection grounds. FLXR remains responsible for its sub-processors' performance under this
DPA.

> **Working inventory for counsel (not a final schedule).** Product engineering maintains a
> provisional vendor inventory (Firebase/GCP, Vercel, Stripe, email, AI providers, monitoring,
> etc.) for counsel to validate. Until that schedule is completed and approved, do not treat any
> informal list as the contractual sub-processor annex. See `docs/VERIFY_SECURITY_DPA.md`.

## 6. Security Measures

FLXR implements and maintains technical and organizational measures appropriate to the risk,
including (as further described at https://flxr.ai/security):

- **Tenant isolation:** owner-scoped customer data; Firestore rules require Firebase
  Authentication matching the data owner for client access paths; privileged operations via a
  trusted server layer.
- **Encryption in transit:** TLS/HTTPS; HSTS on production web responses.
- **Encryption at rest:** cloud-provider default encryption; application-layer encryption
  (AES-256-GCM) for certain stored social-platform session credentials.
- **Access control:** authenticated accounts; TOTP two-factor authentication for FLXR
  administrator accounts.
  [TBD: describe customer-facing access controls counsel is comfortable publishing]
- **Payment isolation:** card data processed by Stripe; not stored on FLXR systems.
- **Human-in-the-loop:** agent-proposed posts/replies require human approval before publishing
  (subject to Customer-configured workflows).

[TBD: full technical and organizational measures schedule — counsel to align with actual controls]

## 7. Data-Subject Rights

Taking into account the nature of the processing, FLXR will assist Customer by appropriate
technical and organizational measures in fulfilling Customer's obligation to respond to
data-subject requests (access, rectification, erasure, restriction, portability, objection), to
the extent applicable. If a data subject contacts FLXR directly regarding Customer's data, FLXR
will forward the request to Customer without undue delay and will not respond on Customer's
behalf except as instructed or required by law.
[TBD: assistance SLAs / process details — legal review]

## 8. Personal Data Breach Notification

FLXR will notify Customer without undue delay, and no later than
[TBD: notification window, e.g. 72 hours] after becoming aware of a Personal Data Breach
affecting Customer Personal Data. The notification will describe, to the extent known, the nature
of the breach, the categories and approximate number of data subjects and records concerned,
likely consequences, and measures taken or proposed. FLXR will cooperate with Customer's
reasonable investigation and Customer's own notification obligations.

## 9. Deletion or Return on Termination

Upon termination or expiry of the Agreement, FLXR will, at Customer's choice, delete or return
Customer Personal Data within [TBD: deletion / return window, e.g. 30/60/90 days], and delete
existing copies, unless applicable law requires continued storage (for example, billing records),
in which case such data remains protected under this DPA and is isolated from further processing
except as required by law.
[TBD: self-serve deletion process wording — confirm with product + counsel]

## 10. International Transfers

Where processing involves a transfer of Personal Data originating from the EEA, UK, or
Switzerland to a country without an adequacy decision, the parties will rely on appropriate
safeguards as determined by counsel — for example Standard Contractual Clauses and related
addenda, incorporated by reference as required — together with supplementary measures where
appropriate.
[TBD: transfer mechanism, SCC modules, and transfer impact assessment — legal review required]

## 11. Audits and Information

FLXR will make available to Customer information reasonably necessary to demonstrate compliance
with this DPA, and will allow for and contribute to audits on terms to be agreed.
[TBD: audit frequency, notice, confidentiality, and cost allocation — legal review]

## 12. Liability

Each party's liability arising out of or related to this DPA is subject to the exclusions and
limitations of liability set out in the Agreement.
[TBD: liability cap and carve-outs — legal review required]

## 13. Governing Law and Jurisdiction

This DPA is governed by **[TBD: governing law]**. The courts of
**[TBD: jurisdiction / venue]** shall have exclusive jurisdiction over disputes arising out of or
in connection with this DPA, subject to any mandatory local law protections for data subjects.

## 14. Signatures

**Not for signature — template pending legal review. Do not execute this form.**

**FLXR (Processor)**  
Entity: [TBD: legal entity]  
Name / Title: ____________________  
Signature: ____________________  
Date: ____________________

**Customer (Controller / Processor)**  
Entity: ____________________  
Name / Title: ____________________  
Signature: ____________________  
Date: ____________________
