Data Processing Agreement

Data Processing Agreement

Last Updated: May 18, 2026 11:35

This Data Processing Agreement ("Agreement") is entered into between:

BUYER/USER, as defined in the iflows.com Terms and Conditions, in its capacity as data controller, hereinafter referred to as "CONTROLLER"

and

SELLER, iFlows Technologies Srl, with its registered office at B-dul Metalurgiei 99-99b, Bucharest, 041837, Romania, Tax ID 46179401 and registration number J40/9774/2022, in its capacity as processor, hereinafter referred to as "PROCESSOR",

collectively referred to as the "Parties".

I. SUBJECT MATTER OF THE AGREEMENT

This agreement sets out the conditions under which PROCESSOR processes personal data on behalf of the Controller, in connection with the SERVICE provided through the iflows.com platform.

This agreement is concluded in accordance with Article 28 of Regulation (EU) 2016/679 ("GDPR").

II. ROLES OF THE PARTIES

CONTROLLER determines the purposes and means of processing personal data.

PROCESSOR processes data only on the basis of documented instructions from CONTROLLER and solely for the purpose of providing the SERVICE.

III. DURATION OF PROCESSING

Personal data is processed for the duration of the contractual relationship between the Parties and thereafter only for as long as necessary for:

  • compliance with legal obligations;
  • resolution of any disputes;
  • data backup and recovery;
  • deletion or return of data upon the Controller's request.

IV. NATURE AND PURPOSE OF PROCESSING

Processing may include, without limitation:

  • collection;
  • recording;
  • organization;
  • structuring;
  • storage;
  • adaptation;
  • consultation;
  • use;
  • transmission;
  • synchronization;
  • deletion;
  • destruction.

The purpose of processing is the provision, administration, maintenance and improvement of the SOFTWARE, including automations, integrations with third-party services, technical support and operational functionalities.

V. CATEGORIES OF DATA PROCESSED

Depending on use of the SERVICE, the following categories of data may be processed:

  • first and last name;
  • email address;
  • phone number;
  • company data;
  • account identifiers;
  • technical data and logs;
  • IP addresses;
  • content entered into the platform by the Controller;
  • other data uploaded or managed through the SERVICE.

VI. CATEGORIES OF DATA SUBJECTS

Data may relate to the following categories of data subjects:

  • customers of CONTROLLER;
  • suppliers of CONTROLLER;
  • platform users;
  • employees or collaborators;
  • business partners;
  • prospects and business contacts;
  • other persons whose data is entered into the platform by CONTROLLER.

VII. OBLIGATIONS OF THE PROCESSOR

The Processor undertakes to:

  1. process data only on the basis of documented instructions from the Controller;
  2. ensure confidentiality of persons authorized to process the data;
  3. implement appropriate technical and organizational measures for data protection;
  4. limit access to data to authorized personnel only;
  5. assist the Controller, to the extent possible, in handling requests from data subjects;
  6. support the Controller in fulfilling obligations regarding data security and incident notification;
  7. delete or return data upon termination of the contractual relationship, upon the Controller's request;
  8. make available to the Controller reasonable information necessary to demonstrate compliance with GDPR.

VIII. SUB-PROCESSORS

CONTROLLER authorizes PROCESSOR to use sub-processors for the provision of the SERVICE, including providers of:

  • hosting;
  • SMS;
  • messaging;
  • cloud infrastructure;
  • email;
  • analytics and monitoring;
  • payment processing;
  • integrated third-party services.

PROCESSOR shall impose on sub-processors data protection obligations at least equivalent to those set out in this agreement.

The updated list of sub-processors may be published on iflows.com or made available to CONTROLLER upon request.

IX. INTERNATIONAL TRANSFERS

Where data is transferred outside the European Economic Area, PROCESSOR shall ensure appropriate safeguards in accordance with GDPR, including:

  • adequacy decisions;
  • standard contractual clauses;
  • other legally recognized mechanisms.

X. DATA SECURITY

The Processor shall implement reasonable and appropriate technical and organizational measures commensurate with the risk, including:

  • access control;
  • secure authentication;
  • encryption in transit, where applicable;
  • data backup and recovery;
  • monitoring and logging;
  • protection against unauthorized access;
  • internal confidentiality policies.

XI. SECURITY INCIDENTS

PROCESSOR shall inform CONTROLLER without undue delay after becoming aware of a personal data breach affecting CONTROLLER's data.

The notification shall include, to the extent possible:

  • the nature of the incident;
  • categories of data affected;
  • measures taken or proposed;
  • information necessary to assess the impact.

XII. RIGHTS OF DATA SUBJECTS

Where PROCESSOR receives a request directly regarding exercise of a data subject's rights, it shall forward the request to CONTROLLER without undue delay.

CONTROLLER remains responsible for handling such requests.

XIII. AUDIT AND COMPLIANCE

CONTROLLER may request reasonable information to verify compliance with the obligations set out in this agreement.

Any audit shall be conducted with prior notice and in a manner that does not affect the security, confidentiality or operation of the SERVICE.

XIV. DELETION OR RETURN OF DATA

Upon termination of the contractual relationship, CONTROLLER may request:

  • return of the data; or
  • deletion thereof.

PROCESSOR shall carry out deletion within a reasonable period, except where retention of data is required by law or necessary for secure temporary backups.

XV. LIABILITY

Each Party is liable for breach of obligations incumbent upon it under this agreement and applicable data protection legislation.

XVI. PRECEDENCE

In the event of a conflict between this agreement and other contractual documents between the PARTIES, the provisions of this agreement shall prevail with respect to the protection of personal data.

XVII. APPLICABLE LAW

This agreement is governed by Romanian law and applicable European Union legislation on data protection.

XVIII. ANNEX – PROCESSING DETAILS

Service

Use of the iflows.com platform

Purpose of processing

Provision of digital services, automations, integrations and functionalities offered through the iflows.com platform.

Duration of processing

For the duration of the contractual relationship between the PARTIES.

Categories of data

  • contact data;
  • account data;
  • technical data;
  • content entered into the platform;
  • other data managed by CONTROLLER through the SERVICE.

Categories of data subjects

  • users;
  • customers;
  • employees;
  • collaborators;
  • business contacts;
  • other persons whose data is managed by CONTROLLER.

Security measures

  • access control;
  • encryption;
  • backup;
  • monitoring;
  • internal confidentiality policies;
  • appropriate technical and organizational measures.