Dataflag Back to site

Data Processing Addendum

The controller-to-processor terms that apply when Dataflag processes personal data on your behalf.

Effective date: August 16, 2026

1. Scope and Roles

This Data Processing Addendum applies when Dataflag processes Customer Personal Data on behalf of Customer in connection with the Service. Customer is the controller or business, and Dataflag is the processor or service provider, unless applicable law requires another classification.

2. Processing Instructions

Dataflag will process Customer Personal Data only on Customer's documented instructions, including the Agreement, this DPA, Customer's use of the Service, and written instructions from authorized users. Dataflag will not process Customer Personal Data for Dataflag's own purposes except as expressly permitted by the Agreement and applicable law.

3. Processing Details

Subject matter Provision of the Dataflag vendor data-governance rating service.
Duration The subscription term plus the deletion and backup periods described in the Agreement and Privacy Notice.
Purposes Account administration, document intake, vendor monitoring, DGAIR rating generation, report generation, alerts, support, security, billing, auditability, and legal compliance.
Data subjects Customer users, invited users, notification recipients, billing contacts, support contacts, and individuals whose personal data may appear in Customer Content.
Personal data Account identifiers, contact information, authentication data, workspace records, Customer Content, uploaded files, prompts, outputs, AI-processing artifacts, billing metadata, support communications, security logs, and audit logs.
Sensitive data Customer must not submit sensitive personal data unless the Agreement or an order form expressly permits it.

4. Confidentiality

Dataflag will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and process Customer Personal Data only on a need-to-know basis.

5. Security Measures

Dataflag will maintain technical and organizational measures designed to protect Customer Personal Data, including:

  • encryption in transit;
  • encryption at rest;
  • role-based access controls;
  • authentication controls, including cookie security and CSRF protections for the web application;
  • token hashing and password hashing;
  • production access limited to authorized personnel;
  • audit logging for material administrative actions;
  • vulnerability and dependency management;
  • backup and recovery controls; and
  • incident-response procedures.

6. AI/ML Processing

Dataflag will not use Customer Personal Data or Customer Content to train, fine-tune, improve, or develop AI/ML models by default. Dataflag may send Customer Personal Data to AI/model providers only to provide the Service and only under written terms that prohibit training, fine-tuning, model improvement, reuse, sale, or retention beyond service provision and legal compliance.

7. Subprocessors

Customer authorizes Dataflag to use subprocessors listed on the Subprocessors page. Dataflag will impose written obligations on subprocessors that are at least as protective as this DPA for the processing they perform. Dataflag remains responsible for subprocessor performance as required by applicable law.

Dataflag will provide at least 30 days' advance notice before authorizing a new subprocessor that will process Customer Personal Data, unless emergency replacement is necessary to maintain service security or availability. Customer may object on reasonable data-protection grounds by contacting hello@dataflag.io.

8. Data Subject Requests

Dataflag will reasonably assist Customer in responding to data subject requests to access, correct, delete, restrict, or port Customer Personal Data. If Dataflag receives a request directly, Dataflag may redirect the requester to Customer unless legally required to respond.

9. Security Incidents

Dataflag will notify Customer without undue delay after confirming a Security Incident involving Customer Personal Data and will provide information reasonably available to help Customer meet legal obligations.

10. Return and Deletion

Upon Customer request or termination of the Service, Dataflag will return or export Customer Personal Data in a reasonably usable format and delete Customer Personal Data from active systems within 30 days. Backup copies will be overwritten or deleted within 90 days, unless retention is required by law, legal hold, security investigation, dispute resolution, or financial recordkeeping obligations.

11. Audits

Dataflag will make information reasonably necessary to demonstrate compliance with this DPA available to Customer, including summaries of relevant security measures, subprocessor information, and responses to reasonable security questionnaires. Any audit must protect Dataflag's security, confidentiality, and other customers' data.

12. International Transfers

Where required for international transfers of Customer Personal Data, the parties will rely on applicable standard contractual clauses or other lawful transfer mechanisms.

© 2026 Dataflag, Inc.
Terms of Service Privacy Notice Data Processing Addendum AI/Data Use Subprocessors