Skip to main content

Addendum 1 — Data Processing Addendum

Version: 5 July 2026

Effective date: 5 July 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service for FlowForth. It applies where Vanderstraeten Serge BV processes personal data on behalf of a Customer as processor within the meaning of the GDPR.

For details of how personal data is handled in connection with the Service, see the Privacy Policy.

1. Parties and Roles

For the processing covered by this DPA, the Customer is the controller and Provider is the processor, unless the parties expressly agree otherwise in writing.

The Customer determines the purposes and means of processing. Provider processes personal data only on documented instructions from the Customer, including as described in the Terms of Service, this DPA, the Privacy Policy, the order form, user settings and configurations selected by the Customer.

2. Subject Matter, Duration, Nature and Purpose

The subject matter of the processing is the provision of the Service, including planning, invoicing, communication, automated reminders, customer/employee management, support, integrations and related operational functionality.

The duration of the processing is the duration of the Customer's use of the Service and any additional retention period required for deletion, export, backup, legal compliance, dispute resolution or security purposes.

The nature and purpose of the processing include hosting, storing, organising, retrieving, transmitting, displaying, securing, backing up, supporting, troubleshooting and otherwise processing personal data to provide the Service.

3. Categories of Data Subjects

Depending on the Customer's use of the Service, data subjects may include the Customer's employees, workers, contractors, representatives, clients, prospects, suppliers, invoice recipients, contact persons, website or communication recipients, and other individuals whose data is entered into or processed through the Service.

4. Categories of Personal Data

The personal data processed may include names, business contact details, addresses, phone numbers, email addresses, employee planning data, work assignments, customer records, supplier records, invoice data, VAT and Peppol identifiers, payment status, communication content, message metadata, support data, account data, technical logs and other data entered by or on behalf of the Customer.

5. Special Categories of Data

The Service is not intended for processing special categories of personal data, such as health data, biometric data, data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership or sexual orientation. The Customer must not upload such data unless it has a valid legal basis and has ensured that the Service and contractual arrangements are suitable for that processing.

6. Provider Obligations

Provider shall:

  • process personal data only on documented instructions from the Customer, unless required by applicable law
  • ensure that persons authorised to process personal data are bound by confidentiality obligations
  • implement reasonable technical and organisational measures appropriate to the risk
  • assist the Customer, taking into account the nature of the processing and information available to Provider, with data subject requests where reasonably possible
  • assist the Customer with security, breach notification, data protection impact assessments and consultations with authorities where legally required and reasonably possible
  • make available information reasonably necessary to demonstrate compliance with this DPA
  • notify the Customer if Provider believes an instruction infringes applicable data protection law
  • delete or return personal data after the end of the provision of the Service, subject to legal retention obligations, backup retention and legitimate business needs

7. Customer Obligations

The Customer shall:

  • ensure that all personal data provided to Provider has been collected and processed lawfully
  • have a valid legal basis for the processing
  • provide all required notices to data subjects
  • obtain consents where required, including for automated messaging, WhatsApp, email, SMS or marketing communications
  • ensure that its use of the Service complies with privacy, ePrivacy, labour, employment, consumer protection, tax and accounting laws
  • configure the Service lawfully and use appropriate access rights
  • respond to data subject requests where the Customer is the controller
  • ensure that instructions to Provider are lawful and documented

8. Sub-Processors

The Customer authorises Provider to engage sub-processors to provide, secure, support and improve the Service. Sub-processors may include hosting providers, cloud infrastructure providers, messaging providers, email providers, SMS providers, WhatsApp/Meta services, Peppol access points, analytics and monitoring providers, customer support tools and payment or accounting integration providers.

Provider shall ensure that sub-processors are subject to data protection obligations that are no less protective than those required by this DPA, to the extent applicable to the services provided by the sub-processor.

A current list of the sub-processors engaged by Provider is available on the Sub-processors page.

Provider may update its sub-processors from time to time. Where required by applicable law, Provider will provide appropriate notice or make information about sub-processors available to the Customer. The Customer may object to a new sub-processor on reasonable data protection grounds.

9. International Transfers

Where processing involves transfers of personal data outside the European Economic Area, Provider shall ensure that appropriate safeguards are used where required, such as adequacy decisions, Standard Contractual Clauses or other lawful transfer mechanisms.

10. Security Measures

Provider shall maintain reasonable technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures may include access controls, authentication, role-based permissions, encryption in transit where appropriate, logging, backups, secure hosting, confidentiality measures, supplier due diligence and incident response procedures.

The Customer acknowledges that security is a shared responsibility and must maintain secure credentials, devices, configurations, user permissions and internal procedures.

11. Personal Data Breach

Provider shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data. The notification shall include information reasonably available to Provider to assist the Customer in meeting its own breach notification obligations.

Provider may investigate, contain and remediate the incident before providing full details if necessary to protect the Service, other customers or security-sensitive information.

12. Data Subject Requests

Where Provider receives a request from a data subject relating to personal data processed on behalf of the Customer, Provider may refer the request to the Customer unless legally required to respond directly.

Taking into account the nature of the processing, Provider shall reasonably assist the Customer in responding to data subject requests, insofar as this is possible through the Service or available information.

13. Audits and Compliance Information

Provider shall make available information reasonably necessary to demonstrate compliance with this DPA. Audits or inspections must be reasonable, limited to what is necessary, subject to confidentiality, and must not compromise the security, confidentiality or rights of Provider, other customers or third parties.

Where possible, Provider may satisfy audit requests by providing summaries, policies, security information, certifications, questionnaires or other compliance documentation instead of onsite audits.

14. Deletion and Return of Data

Upon termination of the Service, Provider shall delete or return personal data processed on behalf of the Customer, at the Customer's choice where technically and commercially reasonable, unless applicable law requires retention or continued retention is reasonably necessary for legal, security, backup or dispute resolution purposes.

Backup copies may remain for a limited period until overwritten or deleted in accordance with Provider's backup retention practices, provided they remain protected and are not actively processed except for restoration, legal compliance, security or continuity purposes.

15. Liability

The liability limitations in the Terms of Service apply to this DPA to the maximum extent permitted by law. Nothing in this DPA limits liability where such limitation is not permitted by applicable law.

16. Order of Precedence

In case of conflict between this DPA and the Terms of Service, this DPA prevails for data processing matters. In all other matters, the Terms of Service remain applicable.

17. Contact

For privacy and data protection matters, contact Vanderstraeten Serge BV at support@flowforth.app.

Vanderstraeten Serge BV Zwaantje 22, 9940 Evergem, Belgium Email: support@flowforth.app Company number: 0886.954.241 VAT number: BE0886.954.241