Flowtly – Data Processing Agreement

Current version privacy_last_updated_label 2026-09-23.

1. General provisions and subject matter

This Data Processing Agreement ("DPA") is entered into between the Organisation using the Flowtly Platform, acting as data controller within the meaning of Article 4(7) of Regulation (EU) 2016/679 of 27 April 2016 ("GDPR") ("Controller"), and Flowtly Prosta Spółka Akcyjna, with its registered office in Warsaw (01-194), ul. Młynarska 8/12, Poland, entered in the Register of Entrepreneurs of the National Court Register under KRS 0001188143, NIP 5273180297, REGON 542625051 ("Flowtly" or "Processor"), acting as data processor within the meaning of Article 4(8) GDPR.

The DPA elaborates on the Parties' obligations regarding the processing of personal data referred to in § 11 of the Flowtly Platform Terms and Conditions ("Data security"), and applies to every processing of personal data that Flowtly carries out on behalf of, and on the documented instructions of, the Controller in connection with providing access to the Platform. The DPA does not alter the liability rules and limitations set out in § 12 of the Terms — see Section 13.

The DPA implements the requirements of Article 28 GDPR and is available at this page in the version identified in the revision history (Section 13). The DPA applies to an Organisation using the Platform on the same basis as the Terms — as in force for that Organisation — refer to this document. The Polish-language version of this document is the binding version; this English translation is provided for convenience.

2. Definitions

Capitalised terms not defined in this DPA have the meaning given to them in the Flowtly Platform Terms and Conditions. For the purposes of this DPA:

  • GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data;
  • Controller — the Organisation as data controller within the meaning of Article 4(7) GDPR, acting through persons authorised to represent it; this is distinct from the "Account Administrator" role under the Terms, which denotes a Platform user role, not data-controller status;
  • TOMs (Technical and Organisational Measures) — the measures described in Flowtly's "Technical and Organisational Measures" document, which forms Annex 1 to this DPA;
  • Sub-processor — another processor to whom Flowtly further entrusts the processing of personal data in order to perform this DPA;
  • Personal data breach — a breach within the meaning of Article 4(12) GDPR.

3. Duration of processing

This DPA applies for the term of the agreement for access to the Platform between the Controller and Flowtly under the Terms and Conditions, and expires when that agreement terminates or expires, subject to any provisions which by their nature continue to apply after termination, including the obligation to delete or return data described in Section 11.

4. Nature, purpose and scope of processing; categories of data and data subjects

Nature and purpose of processing. Flowtly processes personal data solely to provide the Controller with access to the Platform, in accordance with the Terms and Conditions and the Controller's documented instructions. Processing operations include in particular: collecting, storing, retrieving, modifying, exporting and deleting data within the Organisation Account, carried out in connection with the Platform's HR and payroll, project, billing and invoicing functionality — which are tools supporting the Organisation's management of those areas, not an accounting tool, per § 12(2) of the Terms — as well as storing data on servers managed by Flowtly, technical support, and ensuring the security and continuity of the Platform.

Categories of data subjects include in particular: the Controller's employees and collaborators, Users and Account Administrators, contractors and their representatives, job candidates — to the extent the Controller uses the relevant Platform functionality — and other natural persons whose data the Controller or its Users enter into the Platform in connection with its use.

Categories of personal data include in particular: identification and contact data, HR and employment data (including remuneration, working time, leave records), billing and invoicing data, contractor data, and — to the extent the Controller lawfully enters them into the Platform, where necessary for obligations under labour or social security law — special categories of data referred to in Article 9 GDPR (e.g. health data in the context of sick leave, trade union membership). Responsibility for the legal basis for entering such data into the Platform rests with the Controller. The detailed scope of data categories matches the scope described in the Privacy Policy.

5. Processor's obligations

Flowtly undertakes to:

  1. process personal data only on the Controller's documented instructions — including with regard to transfers of personal data to a third country or an international organisation — unless required to do so by Union or Member State law to which Flowtly is subject, in which case Flowtly will inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest;
  2. ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (see Section 7);
  3. implement and maintain the technical and organisational measures described in the TOMs, in accordance with Article 32 GDPR (see Section 8);
  4. comply with the conditions for engaging Sub-processors described in Section 9;
  5. provide the Controller with the assistance described in Section 10;
  6. after the end of the provision of processing-related services, delete or return to the Controller all personal data and delete existing copies, in accordance with Section 11, unless Union or Member State law requires storage of the personal data;
  7. make available to the Controller all information necessary to demonstrate compliance with the obligations set out in Article 28 GDPR, and allow for and contribute to audits, including inspections, in accordance with Section 11.

6. Controller's instructions

The Terms and Conditions, the configuration of the Platform, and the way the Controller and Users it authorises use the Platform, are treated as the Controller's documented instructions, as are separate instructions sent in documentary form (including e-mail) to business.support@flowtly.eu. The Controller is responsible for the lawfulness of the instructions it issues. If, in Flowtly's assessment, an instruction from the Controller infringes the GDPR or other data protection law, Flowtly will inform the Controller of this without delay.

7. Confidentiality

Flowtly ensures that only persons authorised by Flowtly have access to personal data, to the extent necessary to perform their duties, and that such persons are bound by an obligation of confidentiality regarding personal data, including after their employment or engagement with Flowtly ends.

8. Security of processing (Article 32 GDPR)

Flowtly implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk of the processing, taking into account the state of the art, the cost of implementation, the nature, scope, context and purposes of processing, and the risk to the rights and freedoms of natural persons. The current description of these measures is Flowtly's "Technical and Organisational Measures" document, which forms Annex 1 to this DPA.

Flowtly will not lower the overall level of security of processing described in the TOMs during the term of this DPA (the "no-downgrade commitment"); replacing a given measure with another that provides an equivalent or higher level of protection is not a downgrade. Every change to the TOMs — including any such replacement — is recorded as a new, dated version in the revision history available on that document's page, so the version of the TOMs in force on any given processing date can always be established from that history.

9. Sub-processing (Sub-processors)

The Controller grants Flowtly general written authorisation to engage Sub-processors to perform this DPA (Article 28(2) GDPR). Flowtly enters into an agreement with each Sub-processor that imposes on it the same data protection obligations as apply to Flowtly under this DPA, including as regards technical and organisational measures. Flowtly remains fully liable to the Controller for the performance of a Sub-processor's data protection obligations, in accordance with Article 28(4) GDPR.

Flowtly notifies the Controller of any intended addition or replacement of Sub-processors at least 30 days in advance, identifying the new Sub-processor and the scope of its activity, and giving the Controller the opportunity to object to that change. Objections, with reasons based on legitimate data protection grounds, are sent to business.support@flowtly.eu within 30 days of notification; failure to object within that period is treated as acceptance of the change. Flowtly will not begin processing the Controller's personal data through a new Sub-processor before the objection period has elapsed, or, if a timely objection is raised, before it has been resolved. In the event of a justified objection that cannot otherwise be accommodated, the Parties will agree in good faith on how to proceed, including, if necessary, terminating the services agreement to the extent it would require use of that Sub-processor.

Sub-processors currently engaged, consistent with the Platform's Privacy Policy:

Sub-processorProcessing scopeProcessing location
Google Cloud (Google Ireland Limited)Platform hosting and cloud infrastructureEU (europe-west1, Belgium)
StripePayment processingEU / outside the EEA, depending on the operation
KontomatikBank data integrationPoland (EU)
Functional Software, Inc. (Sentry)System error monitoringUnited States
Anthropic, PBCProcessing of document content for AI-based features (document analysis, assistant)United States
Postmark (ActiveCampaign, Inc.)Sending transactional email (invoices, reminders, notifications)United States

The list above reflects the state as of the publication date of the relevant version of this DPA and is updated in accordance with the process described above. The current Sub-processor list is also available on request, sent to the address above.

10. Assistance to the Controller; personal data breaches

Exercise of data subject rights. Taking into account the nature of the processing, Flowtly assists the Controller, insofar as possible — through appropriate technical and organisational measures available on the Platform and through support requested at the address in Section 6 — to fulfil its obligation to respond to requests from data subjects exercising their rights under Chapter III GDPR.

Compliance with Articles 32–36 GDPR. Flowtly assists the Controller in ensuring compliance with the obligations under Articles 32–36 GDPR, including the obligation to notify a personal data breach to the supervisory authority and the separate obligation to notify data subjects where a breach is likely to result in a high risk to their rights and freedoms, as well as data protection impact assessments and prior consultation with the supervisory authority, taking into account the nature of processing and the information available to Flowtly.

Personal data breaches. Flowtly notifies the Controller of a personal data breach it has identified without undue delay, and in any case no later than 48 hours after Flowtly becomes aware of it, without waiting for the full circumstances of the incident to be established. The initial notification includes the information set out in Article 33(3) GDPR to the extent available at the time, and is supplemented in stages as further circumstances are established. The 48-hour period is Flowtly's maximum contractual deadline for this initial notification and does not relieve Flowtly of the obligation to act without undue delay where that is possible sooner; it is independent of the 72-hour period within which the Controller, as data controller, must notify the breach to the supervisory authority under Article 33(1) GDPR, where notification is required.

11. End of processing; audits and inspections

End of processing. After the end of the provision of processing-related services, the Controller notifies Flowtly, in documentary form, within 30 days of that event, whether Flowtly is to delete or return the personal data; failure to notify within that period entitles Flowtly to delete the data. Flowtly carries out the chosen action — deletion from production systems, or return in a commonly used electronic format followed by deletion — within a reasonable period not exceeding 30 days from receiving the Controller's instruction, unless Union or Polish law requires Flowtly to retain the data further under a legal obligation binding on Flowtly directly (e.g. tax or accounting rules concerning Flowtly's own accounting records) — which does not extend to the Controller's own accounting records processed on the Platform. Backup copies containing deleted data remain protected in accordance with the TOMs and are overwritten in the ordinary backup rotation cycle described there, without restoring deleted data to the production system.

Audits and inspections. Flowtly makes available to the Controller all information necessary to demonstrate compliance with the obligations under Article 28 GDPR, and allows the Controller, or an auditor authorised by the Controller, to carry out audits, including inspections, of compliance of the processing with this DPA, and cooperates in their conduct. An audit is carried out after at least 30 days' prior written notice, during Flowtly's normal business hours, in a manner that is as unobtrusive as reasonably possible to Flowtly's business and that respects the confidentiality of information relating to Flowtly's other customers, no more than once per calendar year — these limits do not apply where the audit is carried out in connection with a reasonable suspicion of a personal data breach or other material non-compliance with this DPA, or at the request of a competent supervisory authority. Making information available under the first sentence is not limited to once per year.

12. International data transfers

Most processing of personal data takes place within the European Economic Area (EEA) — the Platform's infrastructure and its OCR document processing are maintained in the EU region of the provider named in Section 9. Three of the Sub-processors named in Section 9 — Functional Software, Inc. (operating as Sentry), Anthropic, PBC, and Postmark (ActiveCampaign, Inc.) — are based in the United States, outside the EEA. Flowtly ensures that transfers of personal data to these Sub-processors — and any other transfer of personal data outside the EEA that may occur in connection with the other Sub-processors or their own sub-processors — take place on the basis of an appropriate mechanism under Chapter V GDPR: in particular the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914 (under the module appropriate to the Flowtly–Sub-processor relationship), or — to the extent a given Sub-processor relies on it — the EU–U.S. Data Privacy Framework, supplemented, where a transfer impact assessment indicates it is necessary, by additional safeguards. Information on the mechanism applied to a given Sub-processor is made available to the Controller on request sent to the address in Section 6.

13. Liability and final provisions

The limitation of Flowtly's liability set out in § 12 of the Terms and Conditions ("Liability") applies accordingly to the processing of personal data under this DPA, to the extent legally permissible. This does not affect mandatory law, including: Article 82 GDPR as regards data subjects' claims against Flowtly, the powers of supervisory authorities under the GDPR, and the Polish Civil Code's rules on liability for damage caused intentionally.

Matters not regulated by this DPA are governed, as applicable, by the Terms and Conditions, including its provisions on governing law and dispute resolution. This DPA is governed by Polish law.

This document is the version published on 23 September 2026. The history of earlier versions, if any, is available below.