Data Processing Agreement - Reflow

Data Processing Agreement

Last updated: 9/15/2025

This Data Processing Agreement ("DPA") is entered into on the Effective Date, by and between Customer ("Controller") and Company ("Processor").

This DPA is incorporated into and part of the Terms of Service ("TOS") between the Controller and Processor (collectively, the "Parties"). This DPA reflects the Parties' rights and obligations with respect to Personal Data Processed as part of the Services (all as defined below). In the event of a conflict between the terms of this DPA and the TOS with respect to the subject matter herein, the terms of this DPA govern. Any prior data protection agreements between the Parties are superseded and replaced by this DPA in their entirety. All capitalized terms not defined in this DPA will have the meaning given to them in the TOS.

1. Definitions

For the purposes of this DPA, the following terms shall have the meanings specified below:

2. Purpose

The purpose of this DPA is to define the conditions under which the Processor shall process Personal Data on behalf of the Controller.

3. Compliance with Laws

The Controller has sole responsibility for the quality and accuracy of the Personal Data and how it acquired such data. The Controller is also responsible for complying with transparency and consent requirements for the collection, use, and transfer of the Personal Data.

4. Ownership of Data

As between the Parties, all Personal Data processed by the Processor in performing the Services shall remain the property of the Controller.

5. Duration of Processing

Processing obligations under this DPA will begin on the Effective Date and run until the end of the Processor's provision of Services to the Controller.

6. Types of Data

The Processor will process the categories of Personal Data provided by the Controller as set forth in Schedule 1.

7. Instructions for Processing

The Processor shall only process Personal Data in accordance with this DPA, including specific instructions set forth in Schedule 2.

8. Data Subject's Rights

The Processor shall promptly notify the Controller of any requests from a Data Subject to exercise their rights under applicable data privacy laws and shall assist the Controller in responding to a Data Subject's request as provided in the processing instructions, Schedule 2.

9. Data Protection Impact Assessments

The Processor shall assist the Controller in performing data protection impact assessments. At the Controller's request, the Processor shall provide all necessary information the Controller needs to meet their data protection assessment obligations, including but not limited to information about data transmittal, data storage, methods of processing, encryption, and data destruction.

10. Confidentiality

Both Parties agree to maintain the confidentiality of Personal Data and not to disclose such data except as expressly permitted under these Terms. The Processor shall ensure that all personnel authorized to process Personal Data are subject to binding confidentiality obligations.

11. Liability

Subject to the limitations of liability in the TOS, the Parties agree to indemnify one another against any claims, including but not limited to damages and fines, arising out of their respective breaches of these Terms.

12. Data Security

The Processor shall, at all times, implement and maintain appropriate technical and organizational security measures to ensure a level of security appropriate to the risk to protect the Personal Data against accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure, or access.

13. Breach Notification

The Processor shall promptly notify the Controller of a Breach Event involving the Controller's data.

14. Limitations on Use

The Processor shall not use or authorize the use of the Personal Data for any purpose other than those outlined in this DPA or for purposes other than performing its obligations under the TOS. The Processor is prohibited from: selling or sharing Personal Data it collects pursuant to the TOS with the Controller; retaining, using, or disclosing the Personal Data for any purpose other than the specified business purpose(s) or as otherwise permitted; retaining, using, or disclosing the Personal Data for any commercial purpose other than the business purpose(s) specified in this DPA, including the specific instructions set forth in Schedule 2; and retaining, using, or disclosing the Personal Data outside the direct business relationship between the Processor and Controller.

15. Subcontractor Requirements

Company makes available the current list of Subprocessors used by Company to process Personal Data at trust.reflow.ai/subprocessors ("Subprocessor List"). The Subprocessor List as of the date of first use of the Services by Customer is hereby authorized and in any event shall be deemed authorized by Customer as updated unless Customer provides a written reasonable objection within thirty (30) calendar days following the signing of this DPA or notification of an update to the Subprocessor List. In order to receive notification concerning the intention of including a new Subprocessor into the Subprocessor List, please subscribe by sending an email to hello-at-reflow-dot-ai of your request to receive notifications of any new Subprocessors used to process Personal Data. Once subscribed, Company shall provide notification of any new Subprocessors before authorizing such new Subprocessors to process Personal Data in connection with the provision of the Services.

16. Destruction or Return of Data

The Processor agrees to, at the Controller's choice, securely delete or return the Personal Data within ten (10) business days upon the Controller's written request at any time during the TOS term or upon termination or expiration of the TOS except to the extent that storage of any such data is required by applicable law (and, if so, the Processor shall inform the Controller of any such requirement and shall securely delete such data as soon as it is permitted to do so under applicable law). Controller acknowledges and agrees that any deletion by Processor is irreversible and such deleted data will be unrecoverable. Upon Controller’s request, Processor may enable the periodic deletion of certain locally stored data (e.g. screenshot and audio) at the organization or user level or upload such locally stored data to secure Processor or Subprocessor servers for processing or storage to enable continuity of service features.

SCHEDULE 1

Dependent on the specific features and Services provided by Processor, the following types of Personal Data may be processed under the DPA and the categories of Data Subjects are as follows:

Categories of Data Subjects may include:

Categories of Data:

SCHEDULE 2

Specific Processing Instructions: