Data Processing Addendum
Last updated: October 2, 2026
This Data Processing Addendum ("DPA") forms part of the Floxar Terms of Service (floxar.com/legal/terms) or other agreement under which Floxar, Inc. ("Floxar") provides the Service to Customer (the "Agreement"). Capitalized terms not defined here have the meaning given in the Agreement.
1. SCOPE
1.1 This DPA applies when Floxar processes Customer Personal Data on Customer's behalf in providing the Service.
1.2 It is accepted with the Agreement and needs no separate signature. Customer may request a countersigned copy from legal@floxar.com.
1.3 Personal data in Vault Data, as defined in the Secrets Vault Terms, is governed by the data processing terms of the Secrets Vault Terms instead of this DPA.
2. DEFINITIONS
"Customer Personal Data" means personal data in Customer Content that Floxar processes on Customer's behalf.
"Data Protection Law" means all laws on the processing of personal data that apply to a party's processing under the Agreement, including, where applicable, the EU General Data Protection Regulation ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act and other U.S. state privacy laws.
"Security Incident" means a breach of Floxar's security leading to the accidental or unlawful destruction, loss or alteration of, or unauthorized disclosure of or access to, Customer Personal Data. Unsuccessful attempts that do not compromise Customer Personal Data, such as port scans, denied requests or failed sign-in attempts, are not Security Incidents.
"Sub-processor" means a third party engaged by Floxar to process Customer Personal Data on its behalf.
"SCCs" means the standard contractual clauses for transfers of personal data to third countries adopted by European Commission Implementing Decision (EU) 2021/914.
"Controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in the GDPR, and "business", "service provider", "sell" and "share" the meanings given in the California Consumer Privacy Act.
3. ROLES
3.1 For Customer Personal Data, Customer is the controller (or a processor acting for its own controllers) and Floxar is Customer's processor or service provider.
3.2 Each party will comply with the Data Protection Law that applies to it.
3.3 Floxar is an independent controller of personal data it processes for its own purposes: account, sign-in and billing information; communications with Customer and its Users; Usage Data; and its legitimate business operations, namely security, fraud and abuse prevention, compliance with law, and developing and improving the Service and its features, including its AI features. Floxar processes that data as described in its Privacy Policy and as Data Protection Law permits.
4. CUSTOMER'S OBLIGATIONS
4.1 Customer is responsible for having a lawful basis for the processing it instructs, for giving any notices and obtaining any consents Data Protection Law requires, and for the accuracy and lawfulness of Customer Personal Data.
4.2 Customer will not submit special categories of personal data or data subject to heightened regulatory requirements except as the Agreement permits.
5. INSTRUCTIONS
5.1 Floxar will process Customer Personal Data only on Customer's documented instructions, which consist of the Agreement, this DPA and Customer's configuration and use of the Service, unless required to do otherwise by law, in which case Floxar will inform Customer of that requirement before processing unless the law prohibits it.
5.2 Floxar will inform Customer if, in its opinion, an instruction infringes Data Protection Law.
6. CONFIDENTIALITY
Floxar will ensure that its personnel authorized to process Customer Personal Data are bound by confidentiality obligations.
7. SECURITY
7.1 Floxar will implement and maintain the technical and organizational measures described in Annex 2, appropriate to the risk of the processing.
7.2 Floxar may update those measures as technology and threats change, provided the overall security of the Service is not materially reduced.
8. SUB-PROCESSORS
8.1 Customer gives Floxar general authorization to engage Sub-processors. The current list is maintained at floxar.com/legal/subprocessors (Annex 3).
8.2 Floxar will update that list, and notify Customer's Administrators or offer a subscription to updates on that page, at least 15 days before a new Sub-processor processes Customer Personal Data, or sooner where reasonably necessary for urgent security or legal reasons.
8.3 Customer may object to a new Sub-processor on reasonable data protection grounds by writing to legal@floxar.com within the notice period; otherwise the Sub-processor is deemed approved. If the parties cannot resolve an objection in good faith, Customer may terminate the affected part of the Service as its sole remedy.
8.4 Floxar will impose on each Sub-processor data protection obligations no less protective than those in this DPA and remains responsible for its Sub-processors' performance of them.
9. DATA SUBJECT REQUESTS
9.1 The Service lets Customer access, correct, export and delete Customer Personal Data. Where Customer cannot fulfil a data subject's request with those features, Floxar will provide reasonable assistance at Customer's request.
9.2 If Floxar receives a request from a data subject about Customer Personal Data, it will refer the data subject to Customer and will not respond itself except to do so or as required by law.
9.3 Floxar may charge reasonable fees for assistance beyond what Data Protection Law requires it to provide.
10. SECURITY INCIDENTS
10.1 Floxar will notify Customer's Administrators without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident.
10.2 The notice will describe, as far as the information is available, the nature of the Security Incident, the categories and approximate number of data subjects and records affected, its likely consequences, and the measures taken or proposed. Floxar may provide information in phases as it becomes available.
10.3 Floxar's notice of or response to a Security Incident is not an acknowledgement of fault or liability. Customer is responsible for any notifications it must make to supervisory authorities and data subjects.
11. IMPACT ASSESSMENTS AND CONSULTATIONS
Taking into account the nature of the processing and the information available to it, Floxar will provide reasonable assistance with Customer's data protection impact assessments and prior consultations with supervisory authorities, primarily by making available the information described in Section 13.
12. DELETION AND RETURN
12.1 During the term, Customer may export and delete Customer Personal Data using the features of the Service.
12.2 Within 30 days after the Agreement ends, Floxar will delete Customer Personal Data, except where law requires it to be retained. Copies in backups are deleted as those backups expire in their ordinary cycle and remain protected under this DPA until then.
12.3 Floxar will confirm deletion in writing on request.
13. INFORMATION AND AUDITS
13.1 Floxar will make available the information reasonably necessary to demonstrate compliance with this DPA, including this DPA, Annex 2, and the security documentation Floxar makes generally available. Responses to Customer-specific security questionnaires are provided where Customer's plan, Order Form or Master Agreement includes them, or otherwise at Floxar's discretion and reasonable fees.
13.2 Where Data Protection Law gives Customer an audit right that this information cannot satisfy, Floxar will permit an audit by Customer or an independent auditor bound by confidentiality, on at least 30 days' written notice, no more than once every 12 months, during business hours, limited to Floxar's processing of Customer Personal Data, conducted so as not to disrupt Floxar's operations, and at Customer's expense, including Floxar's reasonable costs of supporting it. Audit results are Floxar's confidential information.
14. INTERNATIONAL TRANSFERS
14.1 Floxar processes Customer Personal Data in the United States and in other locations where Floxar or its Sub-processors operate, as listed on the Sub-processors page.
14.2 To the extent Customer Personal Data subject to the GDPR is transferred to Floxar in a country without an adequacy decision, the SCCs are incorporated into this DPA and apply as follows: Module 2 where Customer is a controller and Module 3 where Customer is a processor; Customer is the data exporter and Floxar the data importer; Clause 7 applies; under Clause 9(a), Option 2 applies with the notice period in Section 8.2; the optional language in Clause 11 does not apply; under Clause 13, the supervisory authority is the one competent for the data exporter; under Clauses 17 and 18, the law and courts of Ireland apply; and Annexes I to III of the SCCs are completed by Annexes 1 to 3 of this DPA.
14.3 For transfers subject to the UK GDPR, the International Data Transfer Addendum issued by the UK Information Commissioner applies, completed with the information in this DPA. For transfers subject to Swiss law, the SCCs apply with the Swiss Federal Data Protection and Information Commissioner as the competent authority and references to the GDPR read as references to Swiss law.
14.4 If the SCCs conflict with this DPA, the SCCs prevail. If a transfer mechanism is invalidated, the parties will cooperate in good faith to adopt a valid replacement.
15. U.S. STATE PRIVACY LAWS
Where the California Consumer Privacy Act or a similar U.S. state law applies, Floxar processes Customer Personal Data as Customer's service provider or processor, only for the business purposes set out in the Agreement. Floxar will not sell or share Customer Personal Data; retain, use or disclose it outside the direct business relationship with Customer or for any purpose other than those business purposes, except as that law permits; or combine it with personal data from other sources, except as that law permits. Floxar will comply with the obligations that law places on service providers, and will notify Customer if it determines that it can no longer meet them.
16. LIABILITY
Each party's liability arising out of or relating to this DPA, including under the SCCs, is subject to the exclusions and limitations of liability in the Agreement, except where Data Protection Law or the SCCs do not permit them to apply.
17. TERM AND PRECEDENCE
17.1 This DPA applies for as long as Floxar processes Customer Personal Data.
17.2 If this DPA conflicts with the rest of the Agreement on the processing of personal data, this DPA prevails, subject to Section 1.3 and Section 14.4.
17.3 Floxar may update this DPA as the Agreement provides for changes to the Terms of Service, and will not make a change that materially reduces the protection of Customer Personal Data except as Data Protection Law requires.
ANNEX 1. DESCRIPTION OF PROCESSING
Subject matter and purpose: providing the Service under the Agreement: hosting, executing and analyzing Customer's workflows, including AI features and connections Customer configures.
Nature of processing: collection, storage, organization, retrieval, analysis, transmission to AI model providers and to systems Customer connects, and deletion.
Duration: the term of the Agreement plus the deletion period in Section 12.
Categories of data subjects: Customer's Users; individuals whose information Customer or its Users put into flows, bits, trails, references, recorded values, files or AI conversations; and individuals associated with agents and clients Customer connects.
Categories of personal data: names, email addresses and user identifiers; content of flows, bits, trails, references, recorded values and files; AI prompts and outputs; activity records of who did what and when; and network, device and request information processed for security and abuse prevention. Special categories of personal data are not intended to be processed, and Customer may submit them only as the Agreement permits.
Frequency of transfer: continuous, for the term of the Agreement.
ANNEX 2. TECHNICAL AND ORGANIZATIONAL MEASURES
- Access control. Access to the Service requires authentication; administrative access to production systems is limited to authorized personnel, protected by multi-factor authentication and granted on a least-privilege basis.
- Tenant isolation. Customer data is logically separated by account, and every request is authorized against the account and scope it targets.
- Encryption. Data is encrypted in transit using TLS and at rest using industry-standard encryption.
- Infrastructure. The Service runs on a major cloud provider's infrastructure, with its physical, environmental and network protections.
- Logging and monitoring. Floxar logs security-relevant events and monitors the Service for availability and security issues.
- Protective measures. Floxar applies rate limits, usage controls and other measures against abuse, which may be based on account, user, agent, credential, network address or other factors.
- Resilience and recovery. Floxar maintains backup and recovery capabilities for its own disaster recovery, and documented incident-response procedures.
- Secure development. Changes are released through version-controlled pipelines with automated checks.
- Personnel. Personnel with access to customer data are bound by confidentiality obligations.
- Sub-processors. Sub-processors are engaged under written data protection obligations.
ANNEX 3. SUB-PROCESSORS
The Sub-processors authorized by Customer are those listed at floxar.com/legal/subprocessors, as updated under Section 8.