Contents

DATA PROCESSING AGREEMENT

Public Offer

Flowsell, Inc.

Version 1.1 · Published 11 August 2026 · Effective 1 September 2026


This Data Processing Agreement (the “DPA”) is a public offer (publichnaya oferta) made by Flowsell, Inc., a corporation incorporated under the laws of the State of Delaware, United States of America, with its principal place of business at 1 Western Avenue, Suite 712, Boston, MA 02134, United States of America (“Flowsell” or the “Processor”), to any legal entity or individual entrepreneur that uses the Flowsell service (the “Customer” or the “Company”).

Flowsell and the Customer are each a “party” and together the “parties”.

OFFER AND ACCEPTANCE

A. Acceptance. This offer is accepted, and this DPA becomes binding between Flowsell and the Customer, upon the earliest of: (i) the Customer creating an account for the Flowsell service; (ii) the Customer connecting a booking or CRM system (including Altegio) to the Flowsell service; or (iii) the Customer otherwise beginning to use the Flowsell service. Acceptance of this offer constitutes acceptance in full and without reservation; partial acceptance is not permitted.

B. Identification of the Customer. The Customer is identified by the registration data provided in its Flowsell account (legal name, registration number, registered address, contact email and, where applicable, the details of its Article 27 representative), together with any order form or invoice issued to it. Those data complete the “data exporter” fields of Annex I and of the Standard Contractual Clauses referred to in clause 11. The Customer is responsible for keeping those data accurate and up to date.

C. Relationship to other documents. This DPA is a standalone agreement. It applies in addition to, and is not replaced by, the Flowsell terms of service, public offer, order form or subscription agreement under which the Customer receives the Flowsell service (together, the “Principal Agreement”). Where this DPA and the Principal Agreement conflict on a matter of personal-data protection, this DPA prevails.

D. Amendments. Flowsell may amend this DPA. Flowsell shall publish the amended version at the address at which this document is published and notify the Customer by email to the address in its account at least thirty (30) calendar days before the amended version takes effect. If the Customer does not agree to the amendment, it may terminate the Services without penalty before the effective date of the amendment, with a pro-rata refund of prepaid fees for the unused period; continued use of the Services after that date constitutes acceptance of the amended version. Each version remains published with its version number and effective date.

E. Countersigned copy. A Customer that requires a signed bilateral copy may request one at dm@flowsell.ai. Flowsell will return the same text, executed by both parties using the countersignature sheet in Annex V. A countersigned copy does not alter the terms of this DPA.

F. Scope. This DPA applies to all Processing of Personal Data carried out by Flowsell on behalf of the Customer in the provision of the Services, regardless of whether the Customer is subject to the GDPR. Where the Customer is not subject to EU, UK or Swiss data protection law, clauses 11 (International data transfers) and Annex IV apply only to the extent relevant.

BACKGROUND

  1. Flowsell provides an automation platform that connects to the Customer’s booking or CRM system (including Altegio) and sends appointment reminders, confirmations, cancellation notices, review requests, retention and promotional messages to the Customer’s clients over WhatsApp and Telegram, and provides related analytics and reporting (the “Services”).

  2. In providing the Services Flowsell Processes Personal Data on behalf of the Customer. The Customer is the Controller and Flowsell is a processor in respect of that Personal Data.

  3. This DPA is entered into to satisfy the requirements of Article 28(3) GDPR.

THE TERMS OF THE OFFER ARE AS FOLLOWS:


1. DEFINITIONS AND INTERPRETATION

1.1 In this DPA:

“Company Personal Data” means any Personal Data Processed by a Contracted Processor on behalf of the Customer pursuant to or in connection with the Principal Agreement.

“Contracted Processor” means the Processor or a Subprocessor.

“Data Protection Laws” means, as applicable to either party, (a) EU Data Protection Laws; (b) the UK GDPR and the UK Data Protection Act 2018; (c) the Swiss Federal Act on Data Protection; and (d) any other applicable law relating to the protection of Personal Data, including, where applicable, the Law of the Republic of Kazakhstan No. 94-V “On Personal Data and Its Protection”.

“EEA” means the European Economic Area.

“EU Data Protection Laws” means EU Regulation 2016/679 (“GDPR”) and any implementing or supplementing national legislation of an EEA Member State.

“Restricted Transfer” means a transfer (including remote access) of Company Personal Data from the EEA, the United Kingdom or Switzerland to a Contracted Processor or other recipient located in a third country, where that particular recipient is not itself covered by an adequacy decision applicable to it (for the avoidance of doubt, Commission Implementing Decision (EU) 2023/1795 covers only recipients that are actively certified under the EU–U.S. Data Privacy Framework), and any onward transfer of such data.

“SCCs” means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (controller to processor) where the Customer is a controller, or Module Three (processor to processor) where the Customer acts as a processor for a third-party controller. The full text is published in the Official Journal of the European Union, L 199, 7 June 2021, and is available at eur-lex.europa.eu.

“Services” has the meaning given in Recital (A).

“Subprocessor” means any third party appointed by or on behalf of the Processor to Process Personal Data on behalf of the Customer in connection with the Principal Agreement. Individual natural persons engaged directly by the Processor (whether as employees or as individual contractors) who Process Company Personal Data solely under the Processor’s authority and instructions and under confidentiality obligations equivalent to those in clause 3 are not Subprocessors, but are persons acting under the authority of the Processor within the meaning of Article 29 GDPR; the countries from which they access Company Personal Data are disclosed in clause 11.2.

“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A(1) of the Data Protection Act 2018, version B1.0.

1.2 The terms “Commission”, “Controller”, “Data Subject”, “Member State”, “Personal Data”, “Personal Data Breach”, “Processing”, “Processor” and “Supervisory Authority” have the meanings given in the GDPR, and their cognate terms shall be construed accordingly.

1.3 In the event of a conflict, the following order of precedence applies: (a) the SCCs (as completed in Annex IV); (b) this DPA; (c) the Principal Agreement.


2. PROCESSING OF COMPANY PERSONAL DATA

2.1 Roles of the parties. The parties acknowledge that, in respect of Company Personal Data, the Customer is the Controller (or, where the Customer itself acts on behalf of another controller, a processor) and Flowsell is a processor.

2.2 Instructions. The Processor shall Process Company Personal Data only on documented instructions from the Customer, including with regard to transfers of Company Personal Data to a third country, unless required to do so by Union or Member State law to which the Processor is subject; in such a case, the Processor shall inform the Customer of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest. (Article 28(3)(a) GDPR.)

2.3 Documented instructions. The Customer’s complete and final instructions are set out in this DPA (including Annex I), the Principal Agreement, and the configuration, settings, message templates, scenarios, triggers and audience segments that the Customer or its authorised users set or approve within the Flowsell interface or API. The Customer may issue additional written instructions at any time; where an additional instruction requires changes to the Services, the parties shall agree on any reasonable adjustment of fees and timelines.

2.4 Unlawful instructions. The Processor shall immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other Data Protection Laws, and may suspend the affected Processing until the instruction is confirmed, amended or withdrawn. (Article 28(3), final paragraph, GDPR.)

2.5 Customer warranties. The Customer warrants and represents that:

  1. it has a valid legal basis under Article 6 GDPR for all Processing it instructs, including for direct-marketing, promotional and bulk messaging campaigns, and has obtained and can evidence any consent required under Directive 2002/58/EC (ePrivacy), the applicable national implementing law, and the applicable messaging-platform policies (including the WhatsApp Business Messaging Policy) before instructing the Processor to send messages to a Data Subject;

  2. it has provided Data Subjects with all information required by Articles 13 and 14 GDPR, including information about the use of the Processor and of the messaging channels;

  3. where the Customer instructs the Processing of Personal Data revealing health or other special categories of data within the meaning of Article 9(1) GDPR — which may occur where the Customer operates a dental clinic, medical centre or similar establishment and appointment, service or category names disclose information about a Data Subject’s health — the Customer has a valid condition under Article 9(2) GDPR (in practice, explicit consent under Article 9(2)(a)) and has instructed the Processor accordingly; and

  4. the Company Personal Data it makes available to the Processor is accurate, lawfully obtained, and limited to what is necessary for the Services.

2.6 Processor undertakings. The Processor shall comply with all Data Protection Laws applicable to it in the Processing of Company Personal Data and shall not sell Company Personal Data, use it for its own advertising purposes, or use it to train generally available machine-learning or artificial-intelligence models. The Processor may Process anonymised or aggregated data derived from Company Personal Data for the purposes of operating, securing, benchmarking and improving the Services, provided that such data can no longer be attributed to an identified or identifiable natural person.

2.7 Scope. Annex I sets out the subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects, as required by Article 28(3) GDPR.


3. PROCESSOR PERSONNEL

3.1 The Processor shall take reasonable steps to ensure the reliability of any of its employees, agents or contractors who may have access to Company Personal Data, ensuring in each case that access is strictly limited to those individuals who need to know or access the relevant Company Personal Data for the purposes of the Principal Agreement.

3.2 The Processor shall ensure that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality that survive the termination of their engagement. (Article 28(3)(b) GDPR.)

3.3 The Processor shall provide its personnel with appropriate training on data protection and information security, and shall maintain a documented access-control policy with periodic review of access rights.


4. SECURITY

4.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to that risk, including as appropriate the measures referred to in Article 32(1) GDPR.

4.2 The technical and organisational measures implemented by the Processor are described in Annex II. The Processor may update those measures from time to time provided that the updates do not result in a material reduction of the overall level of security.

4.3 In assessing the appropriate level of security, the Processor shall take account in particular of the risks presented by Processing, in particular from a Personal Data Breach.


5. SUBPROCESSING

5.1 General written authorisation. The Customer grants the Processor general written authorisation to engage Subprocessors for the performance of the Services. The Subprocessors engaged as at the effective date of this version are listed in Annex III and are authorised by the Customer on acceptance of this offer.

5.2 Changes. The Processor shall inform the Customer of any intended addition or replacement of a Subprocessor at least thirty (30) calendar days in advance, by email to the address in the Customer’s account. The Processor also maintains a current list at https://flowsell.me/legal/subprocessors, but publication alone does not replace the specific written notice required by Clause 9(a), Option 2 of the SCCs. The Customer may object to the change on reasonable data-protection grounds within that period. If the parties cannot resolve the objection in good faith within thirty (30) days of the objection, the Customer may terminate the affected part of the Services without penalty, with a pro-rata refund of prepaid fees for the unused period. (Article 28(2) GDPR.)

5.3 Flow-down. The Processor shall enter into a written contract with each Subprocessor that imposes data-protection obligations that are no less protective than those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures. Where a Subprocessor is located outside the EEA, the Processor shall put in place an appropriate transfer mechanism under Chapter V GDPR. (Article 28(4) GDPR.)

5.4 Liability. The Processor remains fully liable to the Customer for the performance of each Subprocessor’s data-protection obligations.


6. DATA SUBJECT RIGHTS

6.1 Taking into account the nature of the Processing, the Processor shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Customer’s obligation to respond to requests to exercise Data Subject rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection, and rights relating to automated decision-making). (Article 28(3)(e) GDPR.)

6.2 The Processor shall:

  1. promptly, and in any event within five (5) business days, notify the Customer if a Contracted Processor receives a request from a Data Subject relating to Company Personal Data;

  2. not respond to that request except on the documented instructions of the Customer or as required by applicable law, in which case the Processor shall, to the extent permitted, inform the Customer before responding; and

  3. make available to the Customer the self-service functions of the Services (including search, export, correction and deletion of a client record and unsubscribe/opt-out handling) so that the Customer can respond to routine requests directly.

6.3 Assistance beyond the self-service functions and beyond a reasonable volume of requests may be charged at the Processor’s then-current professional-services rates, notified in advance.


7. PERSONAL DATA BREACH

7.1 The Processor shall notify the Customer without undue delay, and in any event within forty-eight (48) hours, upon becoming aware of a Personal Data Breach affecting Company Personal Data, providing the Customer with sufficient information to allow it to meet any obligations to report or inform Data Subjects under Articles 33 and 34 GDPR. (Article 28(3)(f) GDPR.)

7.2 The notification shall, to the extent then known, describe: the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and the name and contact details of the Processor’s contact point. Where the information cannot be provided at the same time, it shall be provided in phases without further undue delay.

7.3 The Processor shall co-operate with the Customer and take such reasonable commercial steps as are directed by the Customer to assist in the investigation, mitigation and remediation of each such Personal Data Breach, and shall document all Personal Data Breaches.

7.4 The Processor’s notification of or response to a Personal Data Breach shall not be construed as an acknowledgement of any fault or liability.


8. DATA PROTECTION IMPACT ASSESSMENT AND PRIOR CONSULTATION

8.1 The Processor shall provide reasonable assistance to the Customer with any data protection impact assessments and prior consultations with Supervisory Authorities which the Customer reasonably considers to be required by Articles 35 or 36 GDPR, in each case solely in relation to Processing of Company Personal Data by, and taking into account the nature of the Processing and information available to, the Contracted Processors. (Article 28(3)(f) GDPR.)


9. DELETION OR RETURN OF COMPANY PERSONAL DATA

9.1 At the choice of the Customer, the Processor shall delete, or return and then delete, all copies of Company Personal Data. Unless the Customer instructs earlier deletion in writing, the Processor shall carry out that deletion promptly after expiry of the export window in clause 9.2, and in any event within sixty (60) calendar days of the date of cessation of any Services involving the Processing of Company Personal Data (the “Cessation Date”). (Article 28(3)(g) GDPR.)

9.2 The Customer may request the export of Company Personal Data in a structured, commonly used, machine-readable format at any time during the term and for thirty (30) days after the Cessation Date. After that period, the Processor may delete the data.

9.3 The Processor may retain Company Personal Data to the extent required by Union or Member State law, and only to the extent and for such period as required by that law, and shall ensure the confidentiality of all such data and that it is Processed only as necessary for the purpose specified in that law.

9.4 Company Personal Data contained in encrypted backups shall be deleted in accordance with the Processor’s backup rotation cycle and in any event within ninety (90) days of the Cessation Date. Until deletion, such data remains protected by this DPA.

9.5 The Processor shall provide written certification of deletion to the Customer on request.


10. AUDIT RIGHTS

10.1 The Processor shall make available to the Customer on request all information necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections, by the Customer or an auditor mandated by the Customer in relation to the Processing of Company Personal Data. (Article 28(3)(h) GDPR.)

10.2 Information rights are satisfied in the first instance by the Processor providing: (a) its current security documentation and Annex II; (b) available certifications, penetration-test summaries and audit reports of its Subprocessors (including DigitalOcean’s SOC 2 report summaries and ISO/IEC 27001 certification, subject to the relevant provider’s terms); and (c) written responses to a reasonable security questionnaire.

10.3 Where the information provided under clause 10.2 is not sufficient to demonstrate compliance, the Customer may conduct an on-site or remote audit, subject to: thirty (30) days’ prior written notice; no more than once per calendar year (unless required by a Supervisory Authority or following a Personal Data Breach); conduct during normal business hours; a written confidentiality undertaking by the Customer and its auditor; the auditor not being a competitor of the Processor; and reasonable measures to avoid disruption to the Processor’s business and to the data of its other customers. Each party bears its own costs, save that the Customer shall reimburse the Processor’s reasonable costs for audits exceeding one per year.


11. INTERNATIONAL DATA TRANSFERS

11.1 Hosting location. Company Personal Data is stored at rest in the European Union, in DigitalOcean’s Frankfurt (FRA1) and/or Amsterdam (AMS3) regions, as further described in Annex I and Annex II.

11.2 Access from third countries. The Processor is established in the United States and its personnel and contractors, including in the Republic of Kazakhstan, may access Company Personal Data remotely for the purposes of providing, supporting, securing and maintaining the Services. Such remote access constitutes a Restricted Transfer.

11.3 Transfer mechanism. To the extent that any Processing under this DPA involves a Restricted Transfer, the parties enter into the SCCs on acceptance of this offer. The SCCs are incorporated into this DPA by reference, unaltered save for the completion of the optional clauses set out in Annex IV, and Annexes I, II and III of this DPA serve as Annexes I, II and III of the SCCs respectively. The Customer acts as data exporter and Flowsell as data importer.

11.4 United Kingdom and Switzerland. For transfers subject to the UK GDPR, the SCCs apply as amended by the UK Addendum, completed as set out in Annex IV. For transfers subject to Swiss law, references in the SCCs to the GDPR are to be understood as references to the Swiss Federal Act on Data Protection, the competent authority is the Swiss Federal Data Protection and Information Commissioner, and the term “Member State” shall not be interpreted so as to exclude Data Subjects in Switzerland from enforcing their rights in their place of habitual residence.

11.5 Transfer impact assessment. In accordance with Clause 14 of the SCCs, each party warrants that it has no reason to believe that the laws and practices of the country of destination applicable to the Processing prevent the data importer from fulfilling its obligations under the SCCs. The parties shall carry out and document a joint transfer impact assessment covering the transfers described in clause 11.2, taking into account the supplementary measures described in Annex II. The Processor shall provide the Customer with the information reasonably required for that assessment, shall make the documented assessment available to the Customer and, in accordance with Clause 14(d) of the SCCs, to the competent Supervisory Authority on request, and shall update it upon any material change.

11.6 Government access requests. The Processor shall, to the extent legally permitted, notify the Customer of any legally binding request by a public authority for disclosure of Company Personal Data, shall challenge requests that are unlawful or overbroad, shall disclose only the minimum amount of data legally required, and shall maintain and publish records of such requests to the extent permitted by law.

11.7 Adequacy developments. Where a Contracted Processor relies on a certification under the EU–U.S. Data Privacy Framework or on any adequacy decision, and that certification or decision ceases to be valid or applicable, the SCCs incorporated under clause 11.3 shall apply automatically and without further action by the parties.

11.8 Successor transfer mechanism. If the SCCs are annulled, amended, replaced or otherwise cease to provide a valid basis for a Restricted Transfer, the parties shall without undue delay execute the replacement clauses adopted by the Commission or put in place an alternative transfer mechanism under Chapter V GDPR, including any additional supplementary measures required. Until such a mechanism is in place, the Processor shall, on the Customer’s written instruction, suspend the affected transfers, and the Customer may terminate the affected part of the Services without penalty.


12. LIABILITY

12.1 Each party’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement, save that nothing in this DPA or the Principal Agreement limits either party’s liability towards Data Subjects under the SCCs or under Article 82 GDPR, or any liability that cannot be limited under applicable law.

12.2 Where one party has paid full compensation to a Data Subject for damage caused by Processing under this DPA, it is entitled to claim back from the other party that part of the compensation corresponding to the other party’s share of responsibility for the damage, in accordance with Article 82(5) GDPR. Administrative fines imposed under Article 83 GDPR are borne by the entity on which they are imposed and are not reallocated by this clause.


13. GENERAL TERMS

13.1 Term. This DPA takes effect on acceptance in accordance with paragraph A above and continues for as long as the Processor Processes Company Personal Data. Clauses which by their nature should survive (including clauses 2.6, 3, 7, 9, 10, 11, 12 and 13.2) survive termination for as long as the Processor retains any Company Personal Data, and thereafter to the extent necessary to give them effect.

13.2 Confidentiality. Each party shall keep confidential all information it receives from the other party under this DPA, subject to disclosure required by law or to a Supervisory Authority.

13.3 Records. The Processor shall maintain a record of all categories of Processing activities carried out on behalf of the Customer in accordance with Article 30(2) GDPR.

13.4 Notices and contacts. Notices under this DPA shall be in writing (email is sufficient) and sent:

  • to the Processor: Flowsell, Inc., 1 Western Avenue, Suite 712, Boston, MA 02134, USA — attn. Data Protection contact, dm@flowsell.ai;
  • to the Customer: the contact email recorded in the Customer’s Flowsell account.

13.5 Article 27 representative. Where required by Article 27 GDPR, the Processor shall designate in writing a representative in the Union and publish its identity and contact details at https://flowsell.me/legal/eu-representative.

13.6 Severability. If any provision of this DPA is held invalid or unenforceable, the remainder continues in full force and the parties shall replace the invalid provision with a valid one that most closely reflects its intent.

13.7 Assignment. The Customer may not assign this DPA separately from the Principal Agreement. Flowsell may assign this DPA to an affiliate or in connection with a merger, acquisition or sale of substantially all of its assets, on written notice to the Customer.

13.8 Language. This DPA is published in English. Any translation is provided for convenience only; in the event of a discrepancy, the English text prevails.

13.9 Electronic form. Acceptance under paragraph A and any countersigned copy under paragraph E may be effected electronically, and the parties agree not to contest the validity of this DPA on the ground that it was concluded in electronic form.


14. GOVERNING LAW AND JURISDICTION

14.1 This DPA is governed by the laws of the State of Delaware, United States of America, excluding its conflict-of-laws rules and excluding the United Nations Convention on Contracts for the International Sale of Goods. The state and federal courts located in the State of Delaware have jurisdiction over any dispute arising from or in connection with this DPA.

14.2 Exception for the SCCs. Clause 14.1 does not apply to the SCCs. In accordance with Clause 17 of the SCCs, the SCCs are governed by the law of Ireland, and in accordance with Clause 18(b) of the SCCs any dispute arising from the SCCs shall be resolved by the courts of Ireland. Nothing in clause 14.1 restricts a Data Subject’s rights under Clause 18 of the SCCs, or a Data Subject’s right to bring proceedings in the Member State of his or her habitual residence.

14.3 Nothing in this clause 14 deprives a Data Subject or a Supervisory Authority of any right or remedy available under Data Protection Laws.

ANNEX I — DESCRIPTION OF THE PROCESSING

(This Annex also serves as Annex I to the SCCs.)

A. LIST OF PARTIES

Data exporter (Customer)

Name, registration number and address As recorded in the Customer’s Flowsell account registration data and any order form or invoice issued to the Customer
Contact person The contact name and email recorded in the Customer’s Flowsell account
Activities relevant to the transfer Operation of a salon, barbershop, spa, dental clinic, medical centre or similar service business; use of the Flowsell service to communicate with its clients and analyse client retention
Role Controller — Module Two of the SCCs applies. Where the Customer states in writing that it acts as a processor on behalf of a third-party controller, Module Three applies and the Customer shall notify Flowsell of the identity and contact details of that controller
Signature and date Acceptance of this offer in accordance with paragraph A, on the date of that acceptance

Data importer (Processor)

Name Flowsell, Inc.
Address 1 Western Avenue, Suite 712, Boston, MA 02134, United States of America
Contact person Data Protection contact — dm@flowsell.ai
Activities relevant to the transfer Provision of the Flowsell messaging-automation and analytics service, including hosting, support, maintenance and security of the platform
Role Processor
Signature and date Publication of this offer, on the date stated at the head of this document

B. DESCRIPTION OF TRANSFER / PROCESSING

Categories of Data Subjects

  • Clients and prospective clients of the Customer (recipients of appointment reminders, confirmations, review requests, retention and promotional messages);
  • Employees, practitioners and other staff of the Customer who are named in bookings, schedules or reports, and authorised users of the Customer’s Flowsell account.

Categories of Personal Data

  • Identifiers: first name, last name, internal client ID in the Customer’s CRM (Altegio) and in Flowsell;
  • Contact data: mobile telephone number, WhatsApp identifier, Telegram user ID or username, email address (where provided), preferred language;
  • Appointment data: date, time, status (booked, confirmed, cancelled, completed, no-show), branch or location, name of the service or service category, assigned staff member;
  • Transaction and value data: amount paid or payable, currency, discounts, loyalty balance, visit count, first and last visit date, lifetime value and derived retention segment;
  • Communication data: message content sent and received through WhatsApp and Telegram, delivery and read status, timestamps, opt-in and opt-out (unsubscribe) status, chat identifiers;
  • Feedback data: review ratings, free-text feedback, and whether the Data Subject followed a review link (Google Maps, 2GIS, Yandex Maps);
  • Technical and log data of authorised users: IP address, device and browser data, authentication and audit logs.

Sensitive data

The Services are not designed for the Processing of special categories of Personal Data. However, where the Customer operates a dental clinic, medical centre or comparable establishment, the name of a service or appointment category may reveal information concerning health within the meaning of Article 9(1) GDPR. Where this is the case:

  • the Customer shall ensure a valid condition under Article 9(2) GDPR (in practice, explicit consent) and shall so instruct the Processor in writing;
  • the Customer shall, wherever practicable, configure neutral service names and message templates that do not disclose the nature of the treatment;
  • the Processor applies the restrictions and safeguards set out in Annex II, including encryption at rest and in transit, strict role-based access control, need-to-know access limited to named support personnel, logging of all access, and shortened retention.

Frequency of the transfer

Continuous, for the duration of the Principal Agreement (near real-time synchronisation with the Customer’s CRM and event-driven message delivery).

Nature and purpose of the Processing

Collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission by messaging channel, alignment, restriction, erasure and destruction of Company Personal Data, for the sole purpose of providing the Services: synchronising booking and client data from the Customer’s CRM; scheduling and delivering appointment reminders, confirmations and cancellation notices; collecting reviews and feedback; running retention and promotional campaigns configured by the Customer; handling opt-outs; and producing analytics and reports for the Customer.

Duration of the Processing

For the term of the Principal Agreement, plus the deletion periods set out in clause 9 (up to 60 days for production data after the Cessation Date; up to 90 days for encrypted backups).

Retention periods during the term

Data category Retention
Client profile and contact data For as long as the record exists in the Customer’s CRM and the Customer’s account is active; deleted or updated on synchronisation when deleted in the CRM
Appointment, transaction and analytics data 24 months rolling, or the shorter period configured by the Customer in its account settings
Message content and delivery or read status 12 months rolling
Review and feedback data 24 months rolling
Opt-out (unsubscribe) records Retained for the term and after deletion of the underlying record, as necessary to honour the opt-out (suppression list, pseudonymised where possible)
Authorised-user technical and log data 90 days

The Customer may instruct shorter retention periods in writing at any time.

Subprocessors

As listed in Annex III, for the subject matter, nature and duration stated there.

C. COMPETENT SUPERVISORY AUTHORITY

The supervisory authority of the EEA Member State in which the Customer is established. Where the Customer is not established in the EEA but has designated a representative under Article 27 GDPR, the supervisory authority of the Member State in which that representative is established. Where neither applies, the supervisory authority of the Member State in which the Data Subjects whose Personal Data is transferred are located.

ANNEX II — TECHNICAL AND ORGANISATIONAL MEASURES

(This Annex also serves as Annex II to the SCCs. Article 32 GDPR.)

1. Pseudonymisation and encryption

  • Encryption in transit: TLS 1.2 or higher for all connections to the platform, to the Customer’s CRM API (Altegio), to messaging APIs and between internal services.
  • Encryption at rest: full-disk and volume encryption (AES-256) on all servers, managed databases, object storage and backups.
  • Secrets and API keys (including Altegio and WhatsApp Business Platform credentials) are stored in a dedicated secret store, never in source code, and are rotated on personnel change and at least annually.
  • Passwords are stored only as salted hashes; no plaintext credentials are logged.
  • Data minimisation and pseudonymisation: internal analytics, monitoring and error-tracking use pseudonymised identifiers wherever technically possible.

2. Confidentiality, integrity, availability and resilience of systems

  • Hosting: DigitalOcean data centres in the European Union — Frankfurt (FRA1) and/or Amsterdam (AMS3). Physical security, environmental controls and 24/7 monitoring are provided by DigitalOcean and its data-centre operators.
  • Network security: private VPC networking between application and database tiers; databases are not exposed to the public internet; cloud firewalls with default-deny rules; SSH access by key only, no password authentication, restricted to an allow-list.
  • Access control: unique named accounts; role-based access control; least-privilege model; mandatory multi-factor authentication for all administrative and cloud-console access; quarterly review of access rights; revocation within 24 hours of termination of an engagement.
  • Segregation: Company Personal Data is logically segregated per customer (tenant) by account identifier, with access control enforced at the application layer.
  • Availability: automated daily backups of databases with point-in-time recovery; backups are encrypted and retained for 30 days; monitoring and alerting on availability, error rates and anomalous access; documented restore procedure tested at least annually.
  • Business continuity: documented recovery objectives — recovery time objective 24 hours, recovery point objective 24 hours.
  • Logging: centralised, tamper-resistant application, access and infrastructure logs, retained for 90 days, with alerting on privileged actions.
  • Change management: version control, peer review of code changes, separated development, staging and production environments; production data is not used in development or test environments.
  • Vulnerability management: automated dependency scanning and timely patching of operating systems and libraries.

3. Organisational measures

  • Data-protection and information-security policies approved by management and reviewed at least annually.
  • Record of processing activities under Article 30(2) GDPR maintained.
  • Confidentiality undertakings for all personnel and contractors; data-protection and security-awareness training on onboarding and annually thereafter.
  • Documented incident-response and Personal Data Breach procedure with defined roles, a 48-hour customer-notification target and post-incident review.
  • Supplier management: security and data-protection assessment of each Subprocessor before engagement; written data-processing terms with each Subprocessor; annual review.
  • Government-access request procedure: legal review, challenge of unlawful or overbroad requests, minimum necessary disclosure, customer notification where legally permitted.
  • Deletion procedure: documented process for the deletion and return of Company Personal Data in accordance with clause 9, including deletion from backups within the backup rotation cycle.
  • Clean-desk and device policy: full-disk encryption, screen lock, endpoint protection and remote wipe on all devices used to access Company Personal Data.

4. Measures for transfers to third countries

  • Data at rest remains in the European Union; access from the United States and the Republic of Kazakhstan is remote, logged and limited to named personnel with a support or engineering need.
  • No standing bulk export of Company Personal Data outside the European Union.
  • Supplementary measures as described in clauses 11.5 and 11.6.

ANNEX III — LIST OF SUBPROCESSORS

(This Annex also serves as Annex III to the SCCs. By accepting this offer the Customer authorises the Subprocessors listed below.)

# Subprocessor Registered address Processing activity Location of Processing Transfer mechanism
1 DigitalOcean, LLC 105 Edgeview Drive, Suite 425, Broomfield, CO 80021, USA Cloud infrastructure hosting: application servers, managed databases, object storage, backups, logging Data at rest in the EU (Frankfurt FRA1 / Amsterdam AMS3); administrative and support access from the USA SCCs incorporated in DigitalOcean’s Data Processing Agreement
2 WhatsApp Ireland Limited (Meta) Merrion Road, Dublin 4, D04 X2K5, Ireland Delivery of messages to Data Subjects over the WhatsApp Business Platform; delivery and read status Ireland / EU, with onward transfers to Meta group entities in the USA Meta intra-group transfer mechanism (SCCs) under the WhatsApp Business Data Processing Terms
3 Telegram (Telegram Messenger Inc. / Telegram FZ-LLC, Dubai, United Arab Emirates) As stated in Telegram’s then-current terms Delivery of messages to Data Subjects over the Telegram Bot API United Arab Emirates / global infrastructure See the note below. The Telegram channel is disabled by default for Customers subject to EU, UK or Swiss data protection law

Note on Telegram. Telegram does not currently offer processing terms under Article 28 GDPR or standard contractual clauses for the Bot API. Because message delivery is continuous and systematic, the derogations in Article 49 GDPR are not available for it. The Telegram channel is therefore disabled by default for Customers subject to EU, UK or Swiss data protection law, and is activated only on the Customer’s express written instruction and on the basis of the Customer’s own assessment as Controller. Where the Customer instructs activation, the Customer accepts responsibility for that transfer as Controller.

Data source and integration (not a Subprocessor of the Processor)

Provider Address Role
Altegio Limited Ioanni Stylianou 6, 2nd floor, Flat/Office 202, 2003 Nicosia, Cyprus (EU) The Customer’s booking and CRM system. The Customer is Altegio’s customer and grants Flowsell API access to its own account. Altegio processes data under its own agreement with the Customer; Flowsell acts only as a recipient of data on the Customer’s instructions.

Duration of subprocessing: each Subprocessor Processes Company Personal Data for the term of the Principal Agreement and for the deletion periods set out in clause 9. Subject matter and nature of subprocessing: as stated in the “Processing activity” column above; no Subprocessor is authorised to Process Company Personal Data for any other purpose.

The current list of Subprocessors is maintained at https://flowsell.me/legal/subprocessors. Changes are notified in accordance with clause 5.2.

ANNEX IV — STANDARD CONTRACTUAL CLAUSES: COMPLETED OPTIONS

(Completion of Commission Implementing Decision (EU) 2021/914. The full text of the clauses is published in OJ L 199, 7.6.2021, and is incorporated by reference under clause 11.3 without amendment.)

Item Selection
Module Module Two (Controller to Processor) where the Customer acts as controller. Module Three (Processor to Processor) applies instead where the Customer has notified Flowsell in writing that it acts as a processor on behalf of a third-party controller.
Clause 7 — Docking clause Included.
Clause 9(a) — Use of subprocessors Option 2: General written authorisation. Notice period for changes: thirty (30) days (clause 5.2).
Clause 11(a) — Redress The optional independent dispute-resolution body paragraph is not included.
Clause 13 — Supervision Competent supervisory authority as identified in Annex I(C).
Clause 17 — Governing law Option 1: the law of Ireland.
Clause 18(b) — Choice of forum and jurisdiction The courts of Ireland.
Annex I Annex I of this DPA.
Annex II Annex II of this DPA.
Annex III Annex III of this DPA.
Period for return or deletion under Clause 8.5 / 16(d) As set out in clause 9.

UK Addendum (IDTA Addendum, version B1.0). Table 1: the parties and contact details as set out in Annex I. Table 2: the Approved EU SCCs as incorporated above, Module Two (or Module Three). Table 3: Annexes I, II and III of this DPA. Table 4: neither party may end the Addendum as set out in Section 19.

ANNEX V — COUNTERSIGNATURE SHEET (OPTIONAL)

This sheet is provided for Customers that require a signed bilateral copy of this DPA. Completing it does not alter the terms of the DPA, which apply from acceptance under paragraph A regardless of whether this sheet is signed. Requests: dm@flowsell.ai.

Customer (data exporter)

Legal name
Registration number
Registered address
Contact person and email
Role (tick one) ☐ Controller (SCC Module Two) ☐ Processor for a third-party controller (SCC Module Three)
Underlying controller (Module Three only)
Article 27 representative (if any)
Competent supervisory authority
For and on behalf of the Customer For and on behalf of Flowsell, Inc.
Signature: Signature:
Name: Name: Dauren Makenov
Title: Title: Chief Executive Officer
Date: Date:

Flowsell, Inc. · 1 Western Avenue, Suite 712, Boston, MA 02134, USA · dm@flowsell.ai

Version 1.1 · Published 11 August 2026 · Effective 1 September 2026 · Previous versions are archived at https://flowsell.me/legal/dpa/archive