Legal Policies

Data Processing Agreement (DPA)

Establishing the legal frameworks and GDPR-compliant processing guidelines for our AI agent and data ingestion workflows.

Last Updated: August 1, 2026

1. Purpose & Scope

This Data Processing Agreement ("DPA") governs the processing of personal data by xFlow as a Data Processor on behalf of the Client (the "Data Controller") when supplying custom AI development, integration, and platform services.

This DPA forms an integral part of the main Terms & Conditions and any applicable Statement of Work (SOW). We process customer and lead data solely for the purpose of providing, configuring, and supporting the contracted AI automation services, in strict compliance with the Controller's documented instructions.

2. Definitions

For the purposes of this agreement, capitalized terms shall have the meanings attributed to them under General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679):

  • "Data Controller" or "Controller": The entity that determines the purposes and means of processing personal data (the Client).
  • "Data Processor" or "Processor": The entity that processes personal data on behalf of the Controller (xFlow).
  • "Personal Data": Any information relating to an identified or identifiable natural person processed through the AI agents.
  • "Sub-processor": Any third-party service engaged by the Processor to assist in carrying out data processing operations.

3. Scope & Details of Processing

The details of the processing operations are as follows:

  • Subject Matter: Custom AI integrations, chatbot interactions, sales lead routing, and retrieval-augmented generation (RAG) training pipelines.
  • Duration: The term of the active service agreement plus the period until all customer data is deleted or returned.
  • Categories of Data Subjects: Client employees, website visitors, prospective customers, and end-users interacting with the AI agents.
  • Types of Personal Data: Name, contact details, email address, chat history logs, calendar metadata, and any information contained within client training manuals.

4. Obligations of the Processor

As the Data Processor, xFlow agrees to:

  • Process personal data only on documented, written instructions from the Controller, unless required to do so by applicable law.
  • Ensure that all personnel authorized to access and process the data have committed themselves to strict confidentiality agreements.
  • Assist the Controller, through appropriate technical measures, in responding to requests from data subjects exercising their GDPR rights (e.g., access, deletion, portability).
  • Inform the Controller immediately if, in our opinion, a processing instruction infringes on applicable data protection laws.

5. Sub-processors

The Controller grants general authorization to xFlow to engage Sub-processors to host databases, run LLM inference nodes, and direct messaging APIs.

Our primary Sub-processors include cloud servers (AWS, Vercel), databases (Supabase, MongoDB), and model endpoints (OpenAI, Anthropic, Google).

We impose data protection obligations on our Sub-processors that are at least as stringent as those set out in this DPA. We will notify the Controller of any intended changes or additions to our Sub-processor list, giving you the opportunity to object.

6. Technical & Organizational Security

Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk.

These security controls include SSL encryption for data in transit, AES-256 database encryption at rest, secure API endpoint tokenization, role-based access restrictions, and regular vulnerability checks on development platforms.

7. International Data Transfers

To provide stable, low-latency AI performance, we host systems and process API nodes using globally distributed servers.

If personal data originating in the European Economic Area (EEA), United Kingdom, or Switzerland is transferred outside these territories to a country without an adequacy decision, the parties agree to rely on the EU Standard Contractual Clauses (SCCs) to ensure a high standard of data compliance.

8. Data Breach Notification

In the event of a confirmed security incident resulting in the accidental, unauthorized, or unlawful destruction, loss, alteration, or disclosure of personal data processed under this agreement, xFlow will:

  • Notify the Controller without undue delay, and in any event within seventy-two (72) hours of becoming aware of the breach.
  • Provide detailed information regarding the nature of the breach, the affected data categories, and the corrective actions being taken.
  • Cooperate with the Controller to mitigate the impact and coordinate regulatory reports.

9. Deletion or Return of Data

Upon termination of our services, or upon request by the Controller, xFlow will, at the choice of the Controller, delete or return all personal data and existing copies to the Controller, unless storage is required by governing law.

10. Compliance Audits

xFlow shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA. We agree to allow for and contribute to audits or inspections conducted by the Controller or an independent auditor, up to once per calendar year, at the Controller's expense.

Need Help?

Have questions about our policies, terms, or how we handle your data? Reach out to our legal and support teams and we'll be happy to assist you.

Email Contacts

Business Address

Building C2, 1015, Surat IT Park,
Surat, Gujarat, India

Official Website: https://xflow.ai

Ready to automate your business?

Let's build an AI solution tailored to your business.

xFlow Assistant

Online

Hi there 👋

I'm the xFlow Assistant. Ask me anything about our agents, pricing, or how we work.