+971 600 521 335 sales@flowdocs.co

FlowDocs Data Processing Addendum (DPA)

Global business customer data processing terms with GCC regional coverage

Processor

FlowBe FZE trading as FlowDocs.

FlowBe FZE trading as FlowDocs. FlowDocs is a product of FlowBe FZE (SRTIP Licence 4157, Sharjah Research Technology and Innovation Park, Sharjah, United Arab Emirates). FlowDocs is a trade name of FlowBe FZE; the contracting party is FlowBe FZE.

Registered details SRTIP Licence 4157, Sharjah Research Technology and Innovation Park, Block B-B21-121, Sharjah, United Arab Emirates
Version 18 September 2026
Underlying Agreement FlowDocs Master SaaS Terms of Service (https://flowdocs.co/terms) and applicable Order
Scope Customer Personal Data processed by FlowDocs on the Customer’s behalf

This DPA forms part of the Contract and applies when FlowDocs Processes Customer Personal Data as a Processor, service provider or contractor for a business Customer. It is designed for international use, including the Gulf Cooperation Council states, the EEA, the United Kingdom, Switzerland and the United States. It does not displace mandatory local requirements or a signed country-specific addendum.

1 Definitions and Scope

1.1. “Applicable Data Protection Law” means privacy, data-protection and data-security law binding on the Processing, including where applicable the UAE PDPL; Saudi PDPL and transfer regulations; Bahrain Law No. 30 of 2018; Oman Royal Decree No. 6 of 2022 and its Executive Regulation; Qatar Law No. 13 of 2016; Kuwait CITRA data-privacy regulations; EU GDPR; UK GDPR and Data Protection Act 2018; Swiss Federal Act on Data Protection; CCPA; and successor or implementing measures.

1.2. “Controller”, “Processor”, “Process”, “Personal Data”, “Data Subject”, “Personal Data Breach” and “Supervisory Authority” have the meanings in Applicable Data Protection Law. “Customer Personal Data” means Personal Data Processed by FlowDocs on the Customer’s behalf through the Services. “Subprocessor” means a third party engaged to Process Customer Personal Data for FlowDocs.

1.3. The Customer is ordinarily Controller and FlowDocs Processor for Customer Personal Data. FlowDocs is an independent Controller for its own contracting, account, security, billing and business-contact processing described in the Privacy Notice (https://flowdocs.co/privacy_policy). If Customer is a Processor, FlowDocs is its subprocessor and Customer confirms it has the Controller’s authority to appoint FlowDocs.

1.4. This DPA prevails over the Master Terms only for Processing of Customer Personal Data. Mandatory transfer terms prevail over inconsistent commercial terms. All liability remains governed by the single aggregate cap in the Master Terms unless mandatory law prohibits that limitation.

2 Processing Instructions and Customer Duties

2.1. FlowDocs will Process Customer Personal Data only on documented instructions in the Contract, Customer configuration and authorised support requests, unless law requires otherwise. Where lawful, FlowDocs will inform Customer before required Processing. FlowDocs may suspend an instruction it reasonably believes unlawful while the parties clarify it.

2.2. Customer will provide lawful instructions, identify applicable local requirements, maintain a lawful basis, give required notices, obtain permissions, honour Data Subject rights, minimise data and avoid uploading data prohibited by the Contract. Customer is responsible for the legality, accuracy and retention settings of Customer Personal Data.

2.3. Customer will not submit special-category, sensitive, health, biometric, criminal, payment-card, government-classified or regulated-sector data unless expressly supported in the Order and the parties have documented additional safeguards. Customer will not use the Services to make solely automated decisions producing legal or similarly significant effects unless expressly agreed.

3 Details of Processing

3.1. Subject matter and purpose: hosting and operating FlowDocs ticketing, document, request and approval workflows; authenticating Users; enabling collaboration; securing, supporting and troubleshooting the Services; delivering service communications; and following authorised Customer instructions.

3.2. Duration: the Contract term and the retrieval, deletion and backup periods in Section 9. Processing frequency is continuous or as initiated by Users and configured workflows.

3.3. Data types may include business identity and contact data; Microsoft tenant, Entra and account identifiers; authentication events; tickets, documents, forms, approvals, messages, comments and attachments; IP, device and browser data; configuration; usage, security and audit logs; support chat messages.

3.4. Data Subjects may include Customer employees, contractors, agents, Users, business contacts and external individuals who submit information through Customer-configured forms. Customer determines whether and how such external collection is lawful.

4 Confidentiality and Security

4.1. FlowDocs will ensure persons authorised to Process Customer Personal Data are bound by confidentiality and receive access only as needed. It will maintain risk-appropriate technical and organisational measures designed to protect confidentiality, integrity, availability and resilience.

4.2. Measures include, as applicable to components FlowDocs controls: industry-standard encryption in transit; encryption at rest through the hosting platform; role-based and least-privilege access; authentication and access review; environment and tenant separation; logging and monitoring; vulnerability and change management; backup and recovery controls; incident-response procedures; and subprocessor due diligence.

4.3. Customer acknowledges that security is shared. Customer is responsible for Microsoft tenant controls, User access, endpoints, data classification, configuration, exports and independent backups. No measure makes an internet service completely secure.

5 Subprocessors

5.1. Customer grants general written authorisation for the subprocessors in FlowDocs’ current public subprocessor register (https://flowdocs.co/subprocessors). FlowDocs will impose materially equivalent data-protection duties and remains responsible for their Processing to the extent required by Applicable Data Protection Law, subject to the Master Terms.

5.2. FlowDocs will give at least fifteen business days’ direct written notice, normally by email, before a new subprocessor begins materially different Processing. Customer may object within ten business days on reasonable documented data-protection grounds. FlowDocs may avoid the subprocessor, offer a reasonable alternative or permit termination of the affected Service with a pro-rata refund of prepaid unused Fees as the exclusive contractual remedy.

5.3. Infrastructure changes within an approved provider do not require separate notice if they do not materially change purpose, data categories, location risk or security. FlowDocs will maintain an accurate list of the entities actually used. The entities disclosed as of this version are listed below.

Subprocessor

Purpose

Processing locations

Microsoft Corporation and affiliates

Azure hosting and database; Teams platform; Entra authentication; marketplace services where used

UAE North (customer data and backups); customer Microsoft 365 tenant region (Teams and Entra services)

Twilio Inc. SendGrid

Transactional and service email where enabled

United States and other disclosed service locations

HubSpot Inc.

CRM, customer support and marketing systems where enabled

United States, EEA and other disclosed service locations

Zapier Inc.

Workflow integrations, enabled only where the Customer connects them

United States

Crisp IM SARL (Crisp)

Support chat widget on the Support link

European Union (France)

 

6 Data Subject Requests and Assistance

6.1. Taking account of the nature of Processing, FlowDocs will provide reasonable assistance for Customer to respond to Data Subject requests. Unless law requires otherwise, FlowDocs will refer a requester concerning Customer Personal Data to Customer and will not independently satisfy the request without Customer instructions.

6.2. FlowDocs will reasonably assist with security, breach response, impact assessments, consultations and records required by Applicable Data Protection Law. Assistance beyond standard product functionality may be charged at agreed rates, except to the extent made necessary by FlowDocs’ breach of this DPA.

7 Personal Data Breaches

7.1. FlowDocs will notify Customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data and will provide available information reasonably needed for Customer’s legal assessment. An initial notice may be incomplete and supplemented as facts become available.

7.2. Notification is not an admission of fault. Customer is responsible for notices to authorities and Data Subjects unless Applicable Law directly requires FlowDocs to notify. FlowDocs will take reasonable steps to contain, investigate and remediate a breach within its control.

8 Audits and Information

8.1. FlowDocs will provide information reasonably necessary to demonstrate compliance, normally through current policies, questionnaires, summaries and available independent reports. References to SOC 2, ISO 27001 or other certification apply only if FlowDocs actually holds the stated current report or certification.

8.2. Customer may request one audit per twelve months and an additional audit after a material breach or binding authority request. Audits require at least thirty days’ notice, occur during business hours, use an independent qualified auditor bound by confidentiality, avoid access to other customers, source code and security-sensitive material, and are at Customer’s cost unless the audit establishes a material FlowDocs breach.

9 Return Retention and Deletion

9.1. During the active term and any stated read-only period, Customer may use the export functions then available in the Services. Unless an Order expressly promises it, FlowDocs does not guarantee a single bulk export, a particular format or manual compilation of all records.

9.2. After expiry or termination, FlowDocs will delete or de-identify Customer Personal Data from active systems within ninety days after the applicable retrieval period, unless Customer validly requests earlier deletion or law requires retention. Only an authenticated Admin may instruct organisation-level deletion.

9.3. Backups are retained under documented cycles: database backups are kept for 14 days locally and 30 days in UAE North storage, then deleted or overwritten. Security logs, dispute material and legally required records may remain until no longer required under documented retention cycles, protected from ordinary use and deleted or de-identified when the applicable period ends. On reasonable request, FlowDocs will confirm completion of its standard deletion process, but need not certify deletion from systems it does not control beyond enforcing subprocessor obligations.

10 International Transfers

10.1. FlowDocs may Process Customer Personal Data in the locations disclosed in the subprocessor register. Customer authorises necessary transfers subject to this Section and remains responsible for identifying localisation restrictions specific to its sector or data. FlowDocs will not promise UAE, Saudi or other in-country residency unless stated in a signed Order.

10.2. For UAE transfers, the parties will use an adequacy ground, contract or other safeguard permitted by the UAE PDPL. For Saudi transfers, Customer as Controller will complete required assessments and the parties will use the Saudi standard contractual clauses or another approved safeguard where required. Bahrain, Oman, Qatar and Kuwait transfers will use approvals, adequacy, consent, contracts or other mechanisms required by the law binding on Customer.

10.3. For a restricted transfer subject to the EU GDPR, the 2021 EU Standard Contractual Clauses are incorporated by reference: Module Two applies to Controller-to-Processor transfers and Module Three to Processor-to-Processor transfers; Clause 7 applies; Option 2 in Clause 9 applies with the notice periods in Section 5; the optional language in Clause 11 does not apply; Ireland is the governing Member State and Irish courts have jurisdiction; and the annex information is supplied by Sections 3, 4, 5 and the parties’ Order and acceptance records.

10.4. For UK restricted transfers, the parties incorporate Part 2 Mandatory Clauses of the ICO Approved Addendum template B.1.0 in force 21 March 2022, as revised under its Section 18, with the EU SCC and DPA information completing its tables. For Swiss transfers, references in the EU SCCs adapt to the Swiss Federal Act on Data Protection and Swiss Data Subjects may enforce applicable rights.

10.5. Each exporter will complete any required transfer impact or risk assessment. The parties will implement supplementary measures reasonably required and may suspend an affected transfer if no lawful mechanism is available.

11 United States State Privacy Terms

11.1. To the extent FlowDocs Processes personal information for a Customer subject to the CCPA or similar US state law, FlowDocs acts as a service provider or processor. Customer discloses information only for the specific business purposes in Section 3.

11.2. FlowDocs will not sell or share Customer Personal Data; retain, use or disclose it outside the Contract and permitted legal purposes; combine it with information received from another person except as legally permitted; or use it for targeted or cross-context behavioural advertising. FlowDocs will provide required assistance and permit reasonable compliance monitoring consistent with Section 8.

12 Liability Term and Governing Terms

12.1. All claims, assistance costs, indemnity and liability under or relating to this DPA form part of, and do not increase or duplicate, FlowDocs’ single aggregate liability cap in Section 13 of the Master Terms. Nothing limits liability only to the extent limitation is prohibited by mandatory law or the unmodified EU SCCs or UK Addendum require otherwise.

12.2. This DPA begins with the Contract and continues until Customer Personal Data is deleted or returned. Confidentiality, transfer, deletion, audit and liability terms survive as needed. Governing law and courts are those in the Master Terms except where mandatory transfer clauses specify otherwise.

12.3. Data-protection contact: support@flowdocs.co. Legal notices: admin@flowdocs.co. FlowBe FZE, SRTIP Licence 4157, Sharjah Research Technology and Innovation Park, Block B-B21-121, Sharjah, United Arab Emirates.