Data Processing Addendum
The GDPR Article 28 terms that govern how Flowjat processes personal data on your behalf when you use the service.
Last updated: 26 juin 2026
This Data Processing Addendum (the “DPA”) forms part of the agreement between you (the “Customer”) and Guillaume SEVRIN (“Flowjat”, “we”, “us”) governing the use of the Flowjat service (the “Service”). It reflects the parties’ obligations under Article 28 of the EU General Data Protection Regulation (the “GDPR”) and, where applicable, the UK GDPR.
Where this DPA conflicts with the Terms of Service on the subject of personal data processing, this DPA prevails. Capitalised terms not defined here have the meaning given in the Terms of Service. For how we handle data in general, see our Privacy Policy.
1. Definitions
“Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject” and “Personal Data Breach” have the meanings set out in the GDPR. “Customer Personal Data” means Personal Data that Flowjat processes on the Customer’s behalf when providing the Service. “Sub-processor” means any third party engaged by Flowjat to process Customer Personal Data. “Applicable Data Protection Law” means the GDPR, the UK GDPR and any other data protection or privacy law applicable to a party’s processing of Customer Personal Data.
2. Roles of the parties
For the Customer Personal Data processed under the Service, the parties acknowledge that:
- the Customer is the Controller (or, where the Customer itself acts as a processor for a third party, a processor), and
- Flowjat is the Processor (or sub-processor), acting only on the Customer’s documented instructions.
Each party is responsible for complying with its own obligations under Applicable Data Protection Law. The Customer is responsible for ensuring it has a valid legal basis to collect the Customer Personal Data and to instruct Flowjat to process it — including the advertising-account and revenue data the Customer connects to the Service.
3. Subject-matter, duration, nature and purpose
The processing carried out by Flowjat is described below.
| Subject-matter | Processing of Customer Personal Data as necessary to provide the Flowjat ad copilot Service and the support requested by the Customer. |
|---|---|
| Duration | For the term of the agreement, plus the deletion/return period set out in Section 9. |
| Nature | Collection, storage, organisation, retrieval, analysis, and transmission of data through the Service — including unifying connected ad networks with developer revenue tools to compute return on ad spend and to generate plain-language recommendations. |
| Purpose | To operate, secure, maintain and improve the Service, to provide AI-assisted recommendations, and to provide customer support, all on the Customer’s instructions. |
Categories of Data Subjects
- The Customer’s users and team members who hold a Flowjat account.
- Individuals whose personal data may appear in connected advertising or revenue platforms to the extent the relevant provider exposes it through its API.
Types of Customer Personal Data
- Account data — name, email address, authentication identifiers, and workspace settings.
- Connected-platform data — campaign, spend and performance metrics, and revenue and subscription data pulled from the accounts the Customer connects (for example ad networks and tools such as Stripe, Paddle or RevenueCat). The Service is designed to work primarily with aggregated metrics rather than individual end-user records.
- Usage and support data — log data, diagnostics, and the content of support requests.
The Service is not intended for the processing of special categories of personal data (Article 9 GDPR), and the Customer must not submit such data to the Service.
4. Flowjat’s obligations as Processor
Flowjat shall:
- process Customer Personal Data only on the Customer’s documented instructions, including with regard to international transfers, unless required to do otherwise by law (in which case Flowjat will inform the Customer before processing, unless the law prohibits it);
- inform the Customer without undue delay if, in Flowjat’s opinion, an instruction infringes Applicable Data Protection Law;
- ensure that personnel authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality;
- implement and maintain the technical and organisational measures described in Section 7;
- respect the conditions for engaging Sub-processors set out in Section 5;
- taking into account the nature of the processing, assist the Customer with its obligations under Sections 6 and 8; and
- make available the information necessary to demonstrate compliance with Article 28 GDPR and allow for audits as described in Section 10.
5. Sub-processors
The Customer provides Flowjat with a general authorisation to engage Sub-processors to support the Service. Flowjat maintains a current list of Sub-processors, including each provider’s purpose and processing location, on its Sub-processors page.
Flowjat will impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and remains fully liable to the Customer for the performance of its Sub-processors’ obligations. Where the Customer connects a third-party advertising or revenue platform, that provider acts as an independent controller for its own purposes; the Customer’s relationship with that provider is governed by the provider’s own terms.
Flowjat will give the Customer notice of any intended addition or replacement of a Sub-processor, and the Customer may object on reasonable, data-protection grounds. If the parties cannot resolve an objection, the Customer may terminate the affected part of the Service.
6. Assistance with data-subject rights
Taking into account the nature of the processing, Flowjat will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law (access, rectification, erasure, restriction, portability and objection). Where a Data Subject contacts Flowjat directly, Flowjat will, without undue delay, forward the request to the Customer and not respond on the Customer’s behalf unless instructed to do so. Account holders can also manage much of their data directly within the Service.
7. Security measures
Taking into account the state of the art and the risks presented by the processing, Flowjat implements appropriate technical and organisational measures under Article 32 GDPR, including:
- encryption of Customer Personal Data in transit and at rest;
- role-based access controls, least-privilege access, and authentication for systems that process Customer Personal Data;
- isolation of customer workspaces and scoped, revocable credentials for connected platforms;
- logging, monitoring and regular review of access to production systems;
- secure development practices and dependency management for the application; and
- measures to restore availability and access to Customer Personal Data in a timely manner after an incident.
Flowjat is an early-stage product and continues to harden these measures as the Service grows; the current security contact and disclosure process are available at security@flowjat.com and on our Security page.
8. Personal Data Breach notification
Flowjat will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will, to the extent known and available, describe the nature of the breach, the likely consequences, the measures taken or proposed in response, and a contact point for more information. Flowjat will reasonably cooperate with the Customer so that the Customer can meet its own notification obligations to supervisory authorities and Data Subjects.
9. International data transfers
Flowjat hosts the core of the Service in the European Union (Front-end déployé sur Vercel. Back-end (authentification + base de données + Edge Functions) sur Supabase (offre managée, région Union européenne — eu-west-1).). Some Sub-processors are located outside the European Economic Area, as indicated on the Sub-processors page.
Where Customer Personal Data is transferred to a country that has not received an adequacy decision, the transfer is governed by an appropriate transfer mechanism under Chapter V of the GDPR — primarily the European Commission’s Standard Contractual Clauses (and, for UK data, the UK International Data Transfer Addendum), together with supplementary measures where required. By entering into this DPA, the parties agree to incorporate the applicable Standard Contractual Clauses by reference, with Flowjat acting as the data importer.
10. Audits
Flowjat will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, and will contribute to audits conducted by the Customer or an auditor it mandates. To minimise disruption, Flowjat may satisfy audit requests by providing relevant documentation and answering written questions. Where an on-site or further audit is genuinely required, the parties will agree in advance on reasonable scope, timing, confidentiality and cost, no more than once per year except after a confirmed Personal Data Breach or where required by a supervisory authority.
11. Deletion and return of data
On termination or expiry of the agreement, Flowjat will, at the Customer’s choice, delete or return all Customer Personal Data and delete existing copies, unless retention is required by law. The Customer may export its data before the end of the term. Unless the Customer requests return, Flowjat will delete Customer Personal Data within a commercially reasonable period after termination, subject to routine backup cycles after which residual copies are overwritten.
12. Liability and term
This DPA is effective for as long as Flowjat processes Customer Personal Data on the Customer’s behalf. Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
13. Signing a DPA with us
These terms apply to your use of the Service. If your organisation requires a countersigned copy of this DPA, or needs to negotiate specific clauses, contact us at legal@flowjat.com and we will arrange it. For privacy questions you can reach our team at privacy@flowjat.com or our data protection contact at dpo@flowjat.com.
Guillaume SEVRIN — France — contact via email for official correspondence.