Legal
Data processing addendum
Our processor obligations under the GDPR.
Last updated 5 September 2026
In short
When FlowFinds handles personal data belonging to your business — your buyers’ orders, the email they send to your support address, your contacts — you are the controller and we are your processor. This addendum is the Article 28 GDPR contract that governs that. It applies automatically to every business account and does not need to be signed separately; ask [email protected] if you require a counter-signed copy.
In substance: we process only on your instructions, we keep it confidential, we bind our sub-processors to the same terms, we help you answer your data subjects and your regulator, and we return or delete the data when you leave.
The summary is not the agreement. Where it and a numbered clause differ, the clause governs.
Contents
- Definitions and relationship
- Subject matter of the processing
- Our obligations
- Security
- Sub-processors
- International transfers
- Assistance to you
- Personal data breach
- Return and deletion
- Audit
- Liability and governing law
1. Definitions and relationship
- Controller, processor, data subject, personal data, processing — as defined in the GDPR (Regulation (EU) 2016/679).
- Customer Personal Data — personal data contained in customer content that we process on your behalf in providing FlowFinds.
- Agreement — the commercial terms of service or other agreement under which we provide FlowFinds to you.
- Sub-processor — a third party engaged by us to process Customer Personal Data.
1.1 You are the controller of Customer Personal Data and we are the processor. This addendum forms part of the Agreement and prevails over it on the subject of data protection.
1.2 Where we process personal data about your account, your users and your payments for our own purposes, we act as controller and the privacy policy governs instead.
2. Subject matter of the processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the FlowFinds commerce agent platform. |
| Duration | The term of the Agreement, plus the deletion period in clause 9. |
| Nature and purpose | Hosting, storage, generation of storefront content, order tracking, satisfaction sampling, and operating the support agent on your inbound email. |
| Types of personal data | Buyer name, email address, delivery address, order contents and value, correspondence with your support address, satisfaction responses, and any personal data you choose to place in store or campaign content. |
| Categories of data subject | Your buyers, your enquirers, your staff and your suppliers’ contacts. |
| Special category data | Not requested and not required. Do not place special category data or criminal offence data into FlowFinds. |
3. Our obligations
3.1 We process Customer Personal Data only on your documented instructions, which are given by the Agreement and by your use of the product’s features, unless EU or member state law requires otherwise — in which case we tell you first, unless that law forbids it.
3.2 We tell you if, in our opinion, an instruction infringes data protection law.
3.3 Everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality and has access only where their role requires it.
3.4 We do not use Customer Personal Data for our own purposes, do not sell it, and do not use it to train models.
4. Security
4.1 We implement appropriate technical and organisational measures under Article 32 GDPR, taking account of the state of the art, cost, and the risk to data subjects. The measures actually in force are described at security, and that page states plainly which formal certifications we do and do not hold.
4.2 Measures include encryption of data in transit, tenant isolation so one account’s work is not reachable from another, credentials held outside the application and never written into generated output, least-privilege administrative access, and logging of administrative action.
4.3 We review these measures as the service changes, and may update them provided security is not materially reduced.
5. Sub-processors
5.1 You give general authorisation for us to engage sub-processors. The current list, with each one’s role and country of establishment, is at sub-processors.
5.2 We give at least 30 days’ notice before adding or replacing a sub-processor. Subscribe on that page to receive the notice by email.
5.3 You may object on reasonable data protection grounds within that period. We will work with you to find an alternative; if none is available, you may terminate the affected service and receive a refund of the unused period.
5.4 We impose on every sub-processor obligations no less protective than these, as set out in the sub-processor terms, and we remain fully liable to you for their performance.
6. International transfers
6.1 Customer Personal Data is stored on infrastructure we operate in the European Union.
6.2 Where a sub-processor is outside the EEA, the transfer is made under the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914), Module Three where we act as processor and the recipient is a further processor, or under an adequacy decision covering that recipient.
6.3 We carry out a transfer risk assessment before relying on the clauses, and apply supplementary measures where the assessment shows they are needed.
7. Assistance to you
7.1 Where a data subject contacts us directly about Customer Personal Data, we do not answer on your behalf; we forward the request to you promptly.
7.2 We provide the tools to export, correct and delete Customer Personal Data in the product. Where those tools do not cover a request, we give reasonable assistance to help you meet your obligations under Articles 12 to 22.
7.3 We assist you with data protection impact assessments and prior consultations under Articles 35 and 36, so far as the information is within our knowledge.
8. Personal data breach
8.1 We notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting Customer Personal Data.
8.2 The notification describes the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once, we provide it in phases without further delay.
8.3 We do not notify your data subjects or your supervisory authority on your behalf unless you instruct us to in writing.
9. Return and deletion
9.1 You may export Customer Personal Data at any time during the term.
9.2 On termination we delete Customer Personal Data within 30 days, unless you ask in writing within that period for it to be returned first.
9.3 Copies present in encrypted backups are deleted on the backup rotation described at data handling and retention, and remain subject to this addendum until they are.
9.4 We retain data beyond these periods only where EU or member state law requires it, and then only for that purpose.
10. Audit
10.1 We make available the information necessary to demonstrate compliance with Article 28, including our current security description and sub-processor list.
10.2 You may audit once in any twelve-month period, on 30 days’ written notice, during business hours, under confidentiality, and without access to other customers’ data. You bear your own costs, and ours where an audit is repeated within the period at your request.
10.3 We do not hold a SOC 2 or ISO 27001 report and will not offer one in place of an audit until we do. Where we obtain one, we will offer it as a first response to an audit request and say so on security.
11. Liability and governing law
11.1 Liability under this addendum is subject to the limitations in the Agreement, except where the GDPR does not permit that.
11.2 This addendum is governed by Hungarian law, and disputes are resolved as the Agreement provides.
11.3 If a clause of this addendum conflicts with the Standard Contractual Clauses where those apply, the Standard Contractual Clauses prevail.
Questions about this document
Write to [email protected]. For a privacy request specifically, use [email protected], which reaches the same people faster. Every other document in this set is listed on the legal index, and the plain-English explanations of how we operate are under trust.