Flowsell, Inc.
Version 1.1 · Published 11 August 2026 · Effective 1 September 2026
This Data Processing Agreement (the “DPA”) is a public offer (publichnaya oferta) made by Flowsell, Inc., a corporation incorporated under the laws of the State of Delaware, United States of America, with its principal place of business at 1 Western Avenue, Suite 712, Boston, MA 02134, United States of America (“Flowsell” or the “Processor”), to any legal entity or individual entrepreneur that uses the Flowsell service (the “Customer” or the “Company”).
Flowsell and the Customer are each a “party” and together the “parties”.
A. Acceptance. This offer is accepted, and this DPA becomes binding between Flowsell and the Customer, upon the earliest of: (i) the Customer creating an account for the Flowsell service; (ii) the Customer connecting a booking or CRM system (including Altegio) to the Flowsell service; or (iii) the Customer otherwise beginning to use the Flowsell service. Acceptance of this offer constitutes acceptance in full and without reservation; partial acceptance is not permitted.
B. Identification of the Customer. The Customer is identified by the registration data provided in its Flowsell account (legal name, registration number, registered address, contact email and, where applicable, the details of its Article 27 representative), together with any order form or invoice issued to it. Those data complete the “data exporter” fields of Annex I and of the Standard Contractual Clauses referred to in clause 11. The Customer is responsible for keeping those data accurate and up to date.
C. Relationship to other documents. This DPA is a standalone agreement. It applies in addition to, and is not replaced by, the Flowsell terms of service, public offer, order form or subscription agreement under which the Customer receives the Flowsell service (together, the “Principal Agreement”). Where this DPA and the Principal Agreement conflict on a matter of personal-data protection, this DPA prevails.
D. Amendments. Flowsell may amend this DPA. Flowsell shall publish the amended version at the address at which this document is published and notify the Customer by email to the address in its account at least thirty (30) calendar days before the amended version takes effect. If the Customer does not agree to the amendment, it may terminate the Services without penalty before the effective date of the amendment, with a pro-rata refund of prepaid fees for the unused period; continued use of the Services after that date constitutes acceptance of the amended version. Each version remains published with its version number and effective date.
E. Countersigned copy. A Customer that requires a signed bilateral copy may request one at dm@flowsell.ai. Flowsell will return the same text, executed by both parties using the countersignature sheet in Annex V. A countersigned copy does not alter the terms of this DPA.
F. Scope. This DPA applies to all Processing of Personal Data carried out by Flowsell on behalf of the Customer in the provision of the Services, regardless of whether the Customer is subject to the GDPR. Where the Customer is not subject to EU, UK or Swiss data protection law, clauses 11 (International data transfers) and Annex IV apply only to the extent relevant.
Flowsell provides an automation platform that connects to the Customer’s booking or CRM system (including Altegio) and sends appointment reminders, confirmations, cancellation notices, review requests, retention and promotional messages to the Customer’s clients over WhatsApp and Telegram, and provides related analytics and reporting (the “Services”).
In providing the Services Flowsell Processes Personal Data on behalf of the Customer. The Customer is the Controller and Flowsell is a processor in respect of that Personal Data.
This DPA is entered into to satisfy the requirements of Article 28(3) GDPR.
THE TERMS OF THE OFFER ARE AS FOLLOWS:
1.1 In this DPA:
“Company Personal Data” means any Personal Data Processed by a Contracted Processor on behalf of the Customer pursuant to or in connection with the Principal Agreement.
“Contracted Processor” means the Processor or a Subprocessor.
“Data Protection Laws” means, as applicable to either party, (a) EU Data Protection Laws; (b) the UK GDPR and the UK Data Protection Act 2018; (c) the Swiss Federal Act on Data Protection; and (d) any other applicable law relating to the protection of Personal Data, including, where applicable, the Law of the Republic of Kazakhstan No. 94-V “On Personal Data and Its Protection”.
“EEA” means the European Economic Area.
“EU Data Protection Laws” means EU Regulation 2016/679 (“GDPR”) and any implementing or supplementing national legislation of an EEA Member State.
“Restricted Transfer” means a transfer (including remote access) of Company Personal Data from the EEA, the United Kingdom or Switzerland to a Contracted Processor or other recipient located in a third country, where that particular recipient is not itself covered by an adequacy decision applicable to it (for the avoidance of doubt, Commission Implementing Decision (EU) 2023/1795 covers only recipients that are actively certified under the EU–U.S. Data Privacy Framework), and any onward transfer of such data.
“SCCs” means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (controller to processor) where the Customer is a controller, or Module Three (processor to processor) where the Customer acts as a processor for a third-party controller. The full text is published in the Official Journal of the European Union, L 199, 7 June 2021, and is available at eur-lex.europa.eu.
“Services” has the meaning given in Recital (A).
“Subprocessor” means any third party appointed by or on behalf of the Processor to Process Personal Data on behalf of the Customer in connection with the Principal Agreement. Individual natural persons engaged directly by the Processor (whether as employees or as individual contractors) who Process Company Personal Data solely under the Processor’s authority and instructions and under confidentiality obligations equivalent to those in clause 3 are not Subprocessors, but are persons acting under the authority of the Processor within the meaning of Article 29 GDPR; the countries from which they access Company Personal Data are disclosed in clause 11.2.
“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A(1) of the Data Protection Act 2018, version B1.0.
1.2 The terms “Commission”, “Controller”, “Data Subject”, “Member State”, “Personal Data”, “Personal Data Breach”, “Processing”, “Processor” and “Supervisory Authority” have the meanings given in the GDPR, and their cognate terms shall be construed accordingly.
1.3 In the event of a conflict, the following order of precedence applies: (a) the SCCs (as completed in Annex IV); (b) this DPA; (c) the Principal Agreement.
2.1 Roles of the parties. The parties acknowledge that, in respect of Company Personal Data, the Customer is the Controller (or, where the Customer itself acts on behalf of another controller, a processor) and Flowsell is a processor.
2.2 Instructions. The Processor shall Process Company Personal Data only on documented instructions from the Customer, including with regard to transfers of Company Personal Data to a third country, unless required to do so by Union or Member State law to which the Processor is subject; in such a case, the Processor shall inform the Customer of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest. (Article 28(3)(a) GDPR.)
2.3 Documented instructions. The Customer’s complete and final instructions are set out in this DPA (including Annex I), the Principal Agreement, and the configuration, settings, message templates, scenarios, triggers and audience segments that the Customer or its authorised users set or approve within the Flowsell interface or API. The Customer may issue additional written instructions at any time; where an additional instruction requires changes to the Services, the parties shall agree on any reasonable adjustment of fees and timelines.
2.4 Unlawful instructions. The Processor shall immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other Data Protection Laws, and may suspend the affected Processing until the instruction is confirmed, amended or withdrawn. (Article 28(3), final paragraph, GDPR.)
2.5 Customer warranties. The Customer warrants and represents that:
it has a valid legal basis under Article 6 GDPR for all Processing it instructs, including for direct-marketing, promotional and bulk messaging campaigns, and has obtained and can evidence any consent required under Directive 2002/58/EC (ePrivacy), the applicable national implementing law, and the applicable messaging-platform policies (including the WhatsApp Business Messaging Policy) before instructing the Processor to send messages to a Data Subject;
it has provided Data Subjects with all information required by Articles 13 and 14 GDPR, including information about the use of the Processor and of the messaging channels;
where the Customer instructs the Processing of Personal Data revealing health or other special categories of data within the meaning of Article 9(1) GDPR — which may occur where the Customer operates a dental clinic, medical centre or similar establishment and appointment, service or category names disclose information about a Data Subject’s health — the Customer has a valid condition under Article 9(2) GDPR (in practice, explicit consent under Article 9(2)(a)) and has instructed the Processor accordingly; and
the Company Personal Data it makes available to the Processor is accurate, lawfully obtained, and limited to what is necessary for the Services.
2.6 Processor undertakings. The Processor shall comply with all Data Protection Laws applicable to it in the Processing of Company Personal Data and shall not sell Company Personal Data, use it for its own advertising purposes, or use it to train generally available machine-learning or artificial-intelligence models. The Processor may Process anonymised or aggregated data derived from Company Personal Data for the purposes of operating, securing, benchmarking and improving the Services, provided that such data can no longer be attributed to an identified or identifiable natural person.
2.7 Scope. Annex I sets out the subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects, as required by Article 28(3) GDPR.
3.1 The Processor shall take reasonable steps to ensure the reliability of any of its employees, agents or contractors who may have access to Company Personal Data, ensuring in each case that access is strictly limited to those individuals who need to know or access the relevant Company Personal Data for the purposes of the Principal Agreement.
3.2 The Processor shall ensure that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality that survive the termination of their engagement. (Article 28(3)(b) GDPR.)
3.3 The Processor shall provide its personnel with appropriate training on data protection and information security, and shall maintain a documented access-control policy with periodic review of access rights.
4.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to that risk, including as appropriate the measures referred to in Article 32(1) GDPR.
4.2 The technical and organisational measures implemented by the Processor are described in Annex II. The Processor may update those measures from time to time provided that the updates do not result in a material reduction of the overall level of security.
4.3 In assessing the appropriate level of security, the Processor shall take account in particular of the risks presented by Processing, in particular from a Personal Data Breach.
5.1 General written authorisation. The Customer grants the Processor general written authorisation to engage Subprocessors for the performance of the Services. The Subprocessors engaged as at the effective date of this version are listed in Annex III and are authorised by the Customer on acceptance of this offer.
5.2 Changes. The Processor shall inform the Customer of any intended addition or replacement of a Subprocessor at least thirty (30) calendar days in advance, by email to the address in the Customer’s account. The Processor also maintains a current list at https://flowsell.me/legal/subprocessors, but publication alone does not replace the specific written notice required by Clause 9(a), Option 2 of the SCCs. The Customer may object to the change on reasonable data-protection grounds within that period. If the parties cannot resolve the objection in good faith within thirty (30) days of the objection, the Customer may terminate the affected part of the Services without penalty, with a pro-rata refund of prepaid fees for the unused period. (Article 28(2) GDPR.)
5.3 Flow-down. The Processor shall enter into a written contract with each Subprocessor that imposes data-protection obligations that are no less protective than those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures. Where a Subprocessor is located outside the EEA, the Processor shall put in place an appropriate transfer mechanism under Chapter V GDPR. (Article 28(4) GDPR.)
5.4 Liability. The Processor remains fully liable to the Customer for the performance of each Subprocessor’s data-protection obligations.
6.1 Taking into account the nature of the Processing, the Processor shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Customer’s obligation to respond to requests to exercise Data Subject rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection, and rights relating to automated decision-making). (Article 28(3)(e) GDPR.)
6.2 The Processor shall:
promptly, and in any event within five (5) business days, notify the Customer if a Contracted Processor receives a request from a Data Subject relating to Company Personal Data;
not respond to that request except on the documented instructions of the Customer or as required by applicable law, in which case the Processor shall, to the extent permitted, inform the Customer before responding; and
make available to the Customer the self-service functions of the Services (including search, export, correction and deletion of a client record and unsubscribe/opt-out handling) so that the Customer can respond to routine requests directly.
6.3 Assistance beyond the self-service functions and beyond a reasonable volume of requests may be charged at the Processor’s then-current professional-services rates, notified in advance.
7.1 The Processor shall notify the Customer without undue delay, and in any event within forty-eight (48) hours, upon becoming aware of a Personal Data Breach affecting Company Personal Data, providing the Customer with sufficient information to allow it to meet any obligations to report or inform Data Subjects under Articles 33 and 34 GDPR. (Article 28(3)(f) GDPR.)
7.2 The notification shall, to the extent then known, describe: the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and the name and contact details of the Processor’s contact point. Where the information cannot be provided at the same time, it shall be provided in phases without further undue delay.
7.3 The Processor shall co-operate with the Customer and take such reasonable commercial steps as are directed by the Customer to assist in the investigation, mitigation and remediation of each such Personal Data Breach, and shall document all Personal Data Breaches.
7.4 The Processor’s notification of or response to a Personal Data Breach shall not be construed as an acknowledgement of any fault or liability.
8.1 The Processor shall provide reasonable assistance to the Customer with any data protection impact assessments and prior consultations with Supervisory Authorities which the Customer reasonably considers to be required by Articles 35 or 36 GDPR, in each case solely in relation to Processing of Company Personal Data by, and taking into account the nature of the Processing and information available to, the Contracted Processors. (Article 28(3)(f) GDPR.)
9.1 At the choice of the Customer, the Processor shall delete, or return and then delete, all copies of Company Personal Data. Unless the Customer instructs earlier deletion in writing, the Processor shall carry out that deletion promptly after expiry of the export window in clause 9.2, and in any event within sixty (60) calendar days of the date of cessation of any Services involving the Processing of Company Personal Data (the “Cessation Date”). (Article 28(3)(g) GDPR.)
9.2 The Customer may request the export of Company Personal Data in a structured, commonly used, machine-readable format at any time during the term and for thirty (30) days after the Cessation Date. After that period, the Processor may delete the data.
9.3 The Processor may retain Company Personal Data to the extent required by Union or Member State law, and only to the extent and for such period as required by that law, and shall ensure the confidentiality of all such data and that it is Processed only as necessary for the purpose specified in that law.
9.4 Company Personal Data contained in encrypted backups shall be deleted in accordance with the Processor’s backup rotation cycle and in any event within ninety (90) days of the Cessation Date. Until deletion, such data remains protected by this DPA.
9.5 The Processor shall provide written certification of deletion to the Customer on request.
10.1 The Processor shall make available to the Customer on request all information necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections, by the Customer or an auditor mandated by the Customer in relation to the Processing of Company Personal Data. (Article 28(3)(h) GDPR.)
10.2 Information rights are satisfied in the first instance by the Processor providing: (a) its current security documentation and Annex II; (b) available certifications, penetration-test summaries and audit reports of its Subprocessors (including DigitalOcean’s SOC 2 report summaries and ISO/IEC 27001 certification, subject to the relevant provider’s terms); and (c) written responses to a reasonable security questionnaire.
10.3 Where the information provided under clause 10.2 is not sufficient to demonstrate compliance, the Customer may conduct an on-site or remote audit, subject to: thirty (30) days’ prior written notice; no more than once per calendar year (unless required by a Supervisory Authority or following a Personal Data Breach); conduct during normal business hours; a written confidentiality undertaking by the Customer and its auditor; the auditor not being a competitor of the Processor; and reasonable measures to avoid disruption to the Processor’s business and to the data of its other customers. Each party bears its own costs, save that the Customer shall reimburse the Processor’s reasonable costs for audits exceeding one per year.
11.1 Hosting location. Company Personal Data is stored at rest in the European Union, in DigitalOcean’s Frankfurt (FRA1) and/or Amsterdam (AMS3) regions, as further described in Annex I and Annex II.
11.2 Access from third countries. The Processor is established in the United States and its personnel and contractors, including in the Republic of Kazakhstan, may access Company Personal Data remotely for the purposes of providing, supporting, securing and maintaining the Services. Such remote access constitutes a Restricted Transfer.
11.3 Transfer mechanism. To the extent that any Processing under this DPA involves a Restricted Transfer, the parties enter into the SCCs on acceptance of this offer. The SCCs are incorporated into this DPA by reference, unaltered save for the completion of the optional clauses set out in Annex IV, and Annexes I, II and III of this DPA serve as Annexes I, II and III of the SCCs respectively. The Customer acts as data exporter and Flowsell as data importer.
11.4 United Kingdom and Switzerland. For transfers subject to the UK GDPR, the SCCs apply as amended by the UK Addendum, completed as set out in Annex IV. For transfers subject to Swiss law, references in the SCCs to the GDPR are to be understood as references to the Swiss Federal Act on Data Protection, the competent authority is the Swiss Federal Data Protection and Information Commissioner, and the term “Member State” shall not be interpreted so as to exclude Data Subjects in Switzerland from enforcing their rights in their place of habitual residence.
11.5 Transfer impact assessment. In accordance with Clause 14 of the SCCs, each party warrants that it has no reason to believe that the laws and practices of the country of destination applicable to the Processing prevent the data importer from fulfilling its obligations under the SCCs. The parties shall carry out and document a joint transfer impact assessment covering the transfers described in clause 11.2, taking into account the supplementary measures described in Annex II. The Processor shall provide the Customer with the information reasonably required for that assessment, shall make the documented assessment available to the Customer and, in accordance with Clause 14(d) of the SCCs, to the competent Supervisory Authority on request, and shall update it upon any material change.
11.6 Government access requests. The Processor shall, to the extent legally permitted, notify the Customer of any legally binding request by a public authority for disclosure of Company Personal Data, shall challenge requests that are unlawful or overbroad, shall disclose only the minimum amount of data legally required, and shall maintain and publish records of such requests to the extent permitted by law.
11.7 Adequacy developments. Where a Contracted Processor relies on a certification under the EU–U.S. Data Privacy Framework or on any adequacy decision, and that certification or decision ceases to be valid or applicable, the SCCs incorporated under clause 11.3 shall apply automatically and without further action by the parties.
11.8 Successor transfer mechanism. If the SCCs are annulled, amended, replaced or otherwise cease to provide a valid basis for a Restricted Transfer, the parties shall without undue delay execute the replacement clauses adopted by the Commission or put in place an alternative transfer mechanism under Chapter V GDPR, including any additional supplementary measures required. Until such a mechanism is in place, the Processor shall, on the Customer’s written instruction, suspend the affected transfers, and the Customer may terminate the affected part of the Services without penalty.
12.1 Each party’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement, save that nothing in this DPA or the Principal Agreement limits either party’s liability towards Data Subjects under the SCCs or under Article 82 GDPR, or any liability that cannot be limited under applicable law.
12.2 Where one party has paid full compensation to a Data Subject for damage caused by Processing under this DPA, it is entitled to claim back from the other party that part of the compensation corresponding to the other party’s share of responsibility for the damage, in accordance with Article 82(5) GDPR. Administrative fines imposed under Article 83 GDPR are borne by the entity on which they are imposed and are not reallocated by this clause.
13.1 Term. This DPA takes effect on acceptance in accordance with paragraph A above and continues for as long as the Processor Processes Company Personal Data. Clauses which by their nature should survive (including clauses 2.6, 3, 7, 9, 10, 11, 12 and 13.2) survive termination for as long as the Processor retains any Company Personal Data, and thereafter to the extent necessary to give them effect.
13.2 Confidentiality. Each party shall keep confidential all information it receives from the other party under this DPA, subject to disclosure required by law or to a Supervisory Authority.
13.3 Records. The Processor shall maintain a record of all categories of Processing activities carried out on behalf of the Customer in accordance with Article 30(2) GDPR.
13.4 Notices and contacts. Notices under this DPA shall be in writing (email is sufficient) and sent:
13.5 Article 27 representative. Where required by Article 27 GDPR, the Processor shall designate in writing a representative in the Union and publish its identity and contact details at https://flowsell.me/legal/eu-representative.
13.6 Severability. If any provision of this DPA is held invalid or unenforceable, the remainder continues in full force and the parties shall replace the invalid provision with a valid one that most closely reflects its intent.
13.7 Assignment. The Customer may not assign this DPA separately from the Principal Agreement. Flowsell may assign this DPA to an affiliate or in connection with a merger, acquisition or sale of substantially all of its assets, on written notice to the Customer.
13.8 Language. This DPA is published in English. Any translation is provided for convenience only; in the event of a discrepancy, the English text prevails.
13.9 Electronic form. Acceptance under paragraph A and any countersigned copy under paragraph E may be effected electronically, and the parties agree not to contest the validity of this DPA on the ground that it was concluded in electronic form.
14.1 This DPA is governed by the laws of the State of Delaware, United States of America, excluding its conflict-of-laws rules and excluding the United Nations Convention on Contracts for the International Sale of Goods. The state and federal courts located in the State of Delaware have jurisdiction over any dispute arising from or in connection with this DPA.
14.2 Exception for the SCCs. Clause 14.1 does not apply to the SCCs. In accordance with Clause 17 of the SCCs, the SCCs are governed by the law of Ireland, and in accordance with Clause 18(b) of the SCCs any dispute arising from the SCCs shall be resolved by the courts of Ireland. Nothing in clause 14.1 restricts a Data Subject’s rights under Clause 18 of the SCCs, or a Data Subject’s right to bring proceedings in the Member State of his or her habitual residence.
14.3 Nothing in this clause 14 deprives a Data Subject or a Supervisory Authority of any right or remedy available under Data Protection Laws.
(This Annex also serves as Annex I to the SCCs.)
Data exporter (Customer)
| Name, registration number and address | As recorded in the Customer’s Flowsell account registration data and any order form or invoice issued to the Customer |
| Contact person | The contact name and email recorded in the Customer’s Flowsell account |
| Activities relevant to the transfer | Operation of a salon, barbershop, spa, dental clinic, medical centre or similar service business; use of the Flowsell service to communicate with its clients and analyse client retention |
| Role | Controller — Module Two of the SCCs applies. Where the Customer states in writing that it acts as a processor on behalf of a third-party controller, Module Three applies and the Customer shall notify Flowsell of the identity and contact details of that controller |
| Signature and date | Acceptance of this offer in accordance with paragraph A, on the date of that acceptance |
Data importer (Processor)
| Name | Flowsell, Inc. |
| Address | 1 Western Avenue, Suite 712, Boston, MA 02134, United States of America |
| Contact person | Data Protection contact — dm@flowsell.ai |
| Activities relevant to the transfer | Provision of the Flowsell messaging-automation and analytics service, including hosting, support, maintenance and security of the platform |
| Role | Processor |
| Signature and date | Publication of this offer, on the date stated at the head of this document |
Categories of Data Subjects
Categories of Personal Data
Sensitive data
The Services are not designed for the Processing of special categories of Personal Data. However, where the Customer operates a dental clinic, medical centre or comparable establishment, the name of a service or appointment category may reveal information concerning health within the meaning of Article 9(1) GDPR. Where this is the case:
Frequency of the transfer
Continuous, for the duration of the Principal Agreement (near real-time synchronisation with the Customer’s CRM and event-driven message delivery).
Nature and purpose of the Processing
Collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission by messaging channel, alignment, restriction, erasure and destruction of Company Personal Data, for the sole purpose of providing the Services: synchronising booking and client data from the Customer’s CRM; scheduling and delivering appointment reminders, confirmations and cancellation notices; collecting reviews and feedback; running retention and promotional campaigns configured by the Customer; handling opt-outs; and producing analytics and reports for the Customer.
Duration of the Processing
For the term of the Principal Agreement, plus the deletion periods set out in clause 9 (up to 60 days for production data after the Cessation Date; up to 90 days for encrypted backups).
Retention periods during the term
| Data category | Retention |
|---|---|
| Client profile and contact data | For as long as the record exists in the Customer’s CRM and the Customer’s account is active; deleted or updated on synchronisation when deleted in the CRM |
| Appointment, transaction and analytics data | 24 months rolling, or the shorter period configured by the Customer in its account settings |
| Message content and delivery or read status | 12 months rolling |
| Review and feedback data | 24 months rolling |
| Opt-out (unsubscribe) records | Retained for the term and after deletion of the underlying record, as necessary to honour the opt-out (suppression list, pseudonymised where possible) |
| Authorised-user technical and log data | 90 days |
The Customer may instruct shorter retention periods in writing at any time.
Subprocessors
As listed in Annex III, for the subject matter, nature and duration stated there.
The supervisory authority of the EEA Member State in which the Customer is established. Where the Customer is not established in the EEA but has designated a representative under Article 27 GDPR, the supervisory authority of the Member State in which that representative is established. Where neither applies, the supervisory authority of the Member State in which the Data Subjects whose Personal Data is transferred are located.
(This Annex also serves as Annex II to the SCCs. Article 32 GDPR.)
(This Annex also serves as Annex III to the SCCs. By accepting this offer the Customer authorises the Subprocessors listed below.)
| # | Subprocessor | Registered address | Processing activity | Location of Processing | Transfer mechanism |
|---|---|---|---|---|---|
| 1 | DigitalOcean, LLC | 105 Edgeview Drive, Suite 425, Broomfield, CO 80021, USA | Cloud infrastructure hosting: application servers, managed databases, object storage, backups, logging | Data at rest in the EU (Frankfurt FRA1 / Amsterdam AMS3); administrative and support access from the USA | SCCs incorporated in DigitalOcean’s Data Processing Agreement |
| 2 | WhatsApp Ireland Limited (Meta) | Merrion Road, Dublin 4, D04 X2K5, Ireland | Delivery of messages to Data Subjects over the WhatsApp Business Platform; delivery and read status | Ireland / EU, with onward transfers to Meta group entities in the USA | Meta intra-group transfer mechanism (SCCs) under the WhatsApp Business Data Processing Terms |
| 3 | Telegram (Telegram Messenger Inc. / Telegram FZ-LLC, Dubai, United Arab Emirates) | As stated in Telegram’s then-current terms | Delivery of messages to Data Subjects over the Telegram Bot API | United Arab Emirates / global infrastructure | See the note below. The Telegram channel is disabled by default for Customers subject to EU, UK or Swiss data protection law |
Note on Telegram. Telegram does not currently offer processing terms under Article 28 GDPR or standard contractual clauses for the Bot API. Because message delivery is continuous and systematic, the derogations in Article 49 GDPR are not available for it. The Telegram channel is therefore disabled by default for Customers subject to EU, UK or Swiss data protection law, and is activated only on the Customer’s express written instruction and on the basis of the Customer’s own assessment as Controller. Where the Customer instructs activation, the Customer accepts responsibility for that transfer as Controller.
Data source and integration (not a Subprocessor of the Processor)
| Provider | Address | Role |
|---|---|---|
| Altegio Limited | Ioanni Stylianou 6, 2nd floor, Flat/Office 202, 2003 Nicosia, Cyprus (EU) | The Customer’s booking and CRM system. The Customer is Altegio’s customer and grants Flowsell API access to its own account. Altegio processes data under its own agreement with the Customer; Flowsell acts only as a recipient of data on the Customer’s instructions. |
Duration of subprocessing: each Subprocessor Processes Company Personal Data for the term of the Principal Agreement and for the deletion periods set out in clause 9. Subject matter and nature of subprocessing: as stated in the “Processing activity” column above; no Subprocessor is authorised to Process Company Personal Data for any other purpose.
The current list of Subprocessors is maintained at https://flowsell.me/legal/subprocessors. Changes are notified in accordance with clause 5.2.
(Completion of Commission Implementing Decision (EU) 2021/914. The full text of the clauses is published in OJ L 199, 7.6.2021, and is incorporated by reference under clause 11.3 without amendment.)
| Item | Selection |
|---|---|
| Module | Module Two (Controller to Processor) where the Customer acts as controller. Module Three (Processor to Processor) applies instead where the Customer has notified Flowsell in writing that it acts as a processor on behalf of a third-party controller. |
| Clause 7 — Docking clause | Included. |
| Clause 9(a) — Use of subprocessors | Option 2: General written authorisation. Notice period for changes: thirty (30) days (clause 5.2). |
| Clause 11(a) — Redress | The optional independent dispute-resolution body paragraph is not included. |
| Clause 13 — Supervision | Competent supervisory authority as identified in Annex I(C). |
| Clause 17 — Governing law | Option 1: the law of Ireland. |
| Clause 18(b) — Choice of forum and jurisdiction | The courts of Ireland. |
| Annex I | Annex I of this DPA. |
| Annex II | Annex II of this DPA. |
| Annex III | Annex III of this DPA. |
| Period for return or deletion under Clause 8.5 / 16(d) | As set out in clause 9. |
UK Addendum (IDTA Addendum, version B1.0). Table 1: the parties and contact details as set out in Annex I. Table 2: the Approved EU SCCs as incorporated above, Module Two (or Module Three). Table 3: Annexes I, II and III of this DPA. Table 4: neither party may end the Addendum as set out in Section 19.
This sheet is provided for Customers that require a signed bilateral copy of this DPA. Completing it does not alter the terms of the DPA, which apply from acceptance under paragraph A regardless of whether this sheet is signed. Requests: dm@flowsell.ai.
Customer (data exporter)
| Legal name | |
| Registration number | |
| Registered address | |
| Contact person and email | |
| Role (tick one) | ☐ Controller (SCC Module Two) ☐ Processor for a third-party controller (SCC Module Three) |
| Underlying controller (Module Three only) | |
| Article 27 representative (if any) | |
| Competent supervisory authority |
| For and on behalf of the Customer | For and on behalf of Flowsell, Inc. |
|---|---|
| Signature: | Signature: |
| Name: | Name: Dauren Makenov |
| Title: | Title: Chief Executive Officer |
| Date: | Date: |
Flowsell, Inc. · 1 Western Avenue, Suite 712, Boston, MA 02134, USA · dm@flowsell.ai
Version 1.1 · Published 11 August 2026 · Effective 1 September 2026 · Previous versions are archived at https://flowsell.me/legal/dpa/archive