Data Processing Agreement
Last updated: September 2026
1. Parties, scope and status
This Data Processing Agreement ("DPA") is entered into between the customer organisation ("Controller", "you") and Kho’n Sul’t SRL, a private limited liability company incorporated under Belgian law, registered office Rue Victor Rauter 147, 1070 Anderlecht, Belgium, enterprise number 0846.631.440, VAT BE0846631440, contactable at contact@getflowr.app ("Processor", "we"). It forms part of the Terms of Service and applies whenever we process personal data on your behalf through Flowr.
Where you determine the purposes and means of processing personal data contained in your workspace, you act as Controller and we act as Processor. Where we process data for our own purposes — such as billing, account administration and securing the service — we act as controller and the Privacy Policy applies.
This DPA applies automatically to every customer whose organisation uses Flowr, and is incorporated into the Terms of Service. Where a negotiated agreement signed by both parties covers the same subject, that agreement prevails.
2. Subject matter, duration, nature and purpose
Subject matter: provision of the Flowr project controls service. Nature and purpose: hosting, storage, organisation, retrieval, transmission, backup and display of Customer Data so that you can plan, budget, report on and audit your projects, together with support and, where you enable it, AI-assisted drafting.
Duration: for as long as you have a workspace, and thereafter only as described in section 11.
3. Categories of data subjects and personal data
Categories of data subjects:
- your Authorised Users — employees, contractors and others you admit to the workspace
- individuals named in your project records, such as risk and issue owners, approvers and assigned resources
- your billing and administrative contacts
3.1 Categories of personal data
- identity and contact data: name, email address, authentication identifiers
- organisational data: organisation membership, access role, project responsibilities
- professional activity data: time recorded against tasks, leave, submissions and approvals, assignments and capacity
- content you enter that may name individuals: status commentary, risks, issues, lessons, closure records and business cases
- financial data relating to projects: rates, budgets, approvals and calculated costs
- audit records of who changed what and when
- billing identifiers held against the organisation
No special categories of personal data under Article 9 GDPR are required by the service. You should not enter them.
4. Documented instructions
We process personal data only on your documented instructions, which are given by the Terms of Service, this DPA, and your use of the service's features. We will not process it for any other purpose.
If we believe an instruction infringes the GDPR or other Union or Member State data protection law, we will inform you. If we are required by law to process beyond your instructions, we will inform you before doing so unless that law prohibits it.
5. Confidentiality
We ensure that persons authorised to process personal data are bound by an appropriate obligation of confidentiality, and that access is limited to those who need it to provide the service.
6. Security
We implement appropriate technical and organisational measures under Article 32. These currently include:
- logical separation of each organisation's data, with access enforced by role
- encryption in transit, and encryption at rest as provided by the hosting platform
- authentication through a dedicated identity provider, with administrator-managed roles
- application access to the database through a managed identity limited to reading and writing application data, without schema-modification rights
- database auditing enabled, with connections attributable to the application identity or to a named individual
- no standing human access to production customer data; exceptional access is authorised, time-limited, attributable and audited
- point-in-time database backups retained on a rolling seven-day window
- deployment through short-lived workload identities rather than stored long-lived credentials
Measures may change as the service develops; we will not reduce the overall level of security.
7. Subprocessors
You give general authorisation for us to engage subprocessors. The current list is published at getflowr.app/subprocessors and forms part of this DPA.
We will give notice before a new or replacement subprocessor begins processing. You may object on reasonable data protection grounds within thirty days; if we cannot resolve the objection, you may terminate the affected subscription without penalty for the unused remainder of the period.
We impose data protection obligations on each subprocessor no less protective than those in this DPA, and remain responsible to you for their performance.
8. International transfers
Production Customer Data is hosted in the European Union. Some subprocessors are established outside the EEA, or may access data from outside it; the subprocessor list identifies them.
Where personal data is transferred outside the EEA, we put in place an appropriate transfer mechanism under Chapter V of the GDPR — normally the European Commission's Standard Contractual Clauses — together with an assessment of the transfer, before the transfer takes place.
Development, maintenance and exceptional technical support are performed by Jilyss Advisory SARL in Morocco, which is not covered by an adequacy decision. There is no routine access to production Customer Data. Where exceptional technical access is required, it is authorised by us in advance, granted to a named individual for a limited period, recorded in our database audit log, and revoked on completion.
9. Assistance to the Controller
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures in fulfilling your obligation to respond to requests from data subjects exercising their rights. The service also lets an administrator access, correct, export and delete records directly.
If we receive a request from one of your data subjects, we will refer them to you rather than respond on your behalf, unless you instruct otherwise.
We assist you, taking into account the information available to us, with your obligations under Articles 32 to 36 — security, breach notification, data protection impact assessment and prior consultation.
10. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process on your behalf, and will provide the information reasonably available to us so that you can meet your own notification obligations.
Notification is not an acknowledgement of fault or liability.
11. Deletion and return
On termination, and at your choice, we delete or return the personal data we process on your behalf, and delete existing copies, unless Union or Member State law requires us to retain it. Contact us to exercise that choice.
The service provides organisation data export in JSON at any time, including before termination.
We do not currently operate an automatic deletion schedule for workspace data after a subscription ends. Data is retained until deletion is requested, or until we publish and implement a retention schedule, of which we will give notice. Point-in-time database backups are held for a rolling seven-day window and are overwritten in the normal course.
12. Audits and information
We make available to you the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
Audits are to be conducted on reasonable notice, no more than once in any twelve-month period except where required by a supervisory authority or following a personal data breach, during business hours, subject to confidentiality, and in a manner that does not disrupt the service or the data of other customers.
13. Order of precedence and contact
In case of conflict between this DPA and the Terms of Service, this DPA prevails in respect of the processing of personal data. A negotiated agreement signed by both parties prevails over both for the subject it covers.
For data protection questions, contact: contact@getflowr.app
The subprocessor list forms part of this agreement. See also the Terms of Service.