Back to Home
F1
FLOWOF1
Legal Document

Data Processing Addendum

Standard DPA for enterprise customers subject to data protection regulations

Licensor

O and P Advisory Services, LLC

Version

1.0

Effective Date

June 25, 2026

Enterprise Document

This Data Processing Addendum ("DPA") is incorporated into and forms an integral part of the End User License Agreement ("EULA") between O and P Advisory Services, LLC ("FLOWOF1") and the enterprise customer ("Customer"). This DPA applies to the processing of Personal Data by FLOWOF1 on behalf of Customer. Enterprise customers may execute a signed version of this DPA by contacting us at privacyflowof1@oandpadvisoryservices.com.

1. Definitions

Capitalized terms used but not defined in this DPA have the meanings given to them in the EULA or Privacy Policy. The following terms have the meanings set out below:

  • "Applicable Data Protection Laws" means all laws and regulations applicable to the processing of Personal Data under the EULA, including, as applicable, the EU General Data Protection Regulation (Regulation 2016/679) ("GDPR"), the California Consumer Privacy Act as amended by the CPRA ("CCPA"), the UK GDPR, and any equivalent U.S. state or federal data protection laws.
  • "Controller" means the entity that determines the purposes and means of the processing of Personal Data. For purposes of this DPA, Customer is the Controller of Customer Personal Data.
  • "Processor" means the entity that processes Personal Data on behalf of the Controller. For purposes of this DPA, FLOWOF1 is the Processor of Customer Personal Data.
  • "Customer Personal Data" means Personal Data that is processed by FLOWOF1 on behalf of Customer pursuant to the EULA and this DPA, as further described in Annex 1 (Description of Processing).
  • "Personal Data" means any information relating to an identified or identifiable natural person, as defined under Applicable Data Protection Laws.
  • "Sub-Processor" means any third party engaged by FLOWOF1 to process Customer Personal Data on behalf of Customer.
  • "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries pursuant to the GDPR, as approved by the European Commission, and any equivalent transfer mechanism adopted under Applicable Data Protection Laws.
  • "Supervisory Authority" means an independent public authority established by an EU Member State, the UK, or any other competent data protection regulator.

2. Roles and Scope of Processing

FLOWOF1 acts as a Processor processing Customer Personal Data on behalf of Customer, who acts as the Controller. FLOWOF1 shall process Customer Personal Data only for the purposes described in the EULA, this DPA, and as instructed by Customer in writing.

FLOWOF1 shall not process Customer Personal Data for any other purpose, including its own commercial purposes, except as required by Applicable Data Protection Laws. FLOWOF1 is not a Controller of Customer Personal Data.

The scope of Customer Personal Data, categories of data subjects, processing purposes, and retention periods are set out in Annex 1 (Description of Processing).

3. FLOWOF1 Obligations

FLOWOF1 shall, with respect to its processing of Customer Personal Data:

  • Process Customer Personal Data only on documented instructions from Customer, including with regard to transfers of Personal Data to a third country, unless required to do so by Applicable Data Protection Laws, in which case FLOWOF1 shall inform Customer of that legal requirement before processing (unless prohibited by law).
  • Ensure that persons authorized to process Customer Personal Data are subject to confidentiality obligations or are under an appropriate statutory obligation of confidentiality.
  • Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Section 5 (Security Measures) and the Security Overview.
  • Assist Customer, insofar as possible, in fulfilling Customer's obligations to respond to requests from data subjects exercising their rights under Applicable Data Protection Laws.
  • Assist Customer in ensuring compliance with obligations regarding security breach notification, data protection impact assessments, and prior consultation with Supervisory Authorities.
  • At Customer's written direction, delete or return Customer Personal Data at the end of the provision of services, and delete existing copies, unless Applicable Data Protection Laws require storage.
  • Make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, as described in Section 8 (Audits).

4. Sub-Processors

Customer acknowledges and agrees that FLOWOF1 may engage Sub-Processors to process Customer Personal Data on its behalf. FLOWOF1 maintains a current list of authorized Sub-Processors, available at the Sub-Processor List page.

FLOWOF1 shall provide Customer with at least thirty (30) calendar days' prior written notice of any intended addition or replacement of a Sub-Processor, thereby giving Customer the opportunity to object. Customer may object to such addition or replacement by notifying FLOWOF1 in writing within thirty (30) calendar days of receiving the notice, providing reasonably detailed grounds for the objection.

If FLOWOF1 engages a Sub-Processor, FLOWOF1 shall impose on that Sub-Processor, by way of a written contract, data protection obligations that are substantially similar to those set out in this DPA. FLOWOF1 remains fully liable to Customer for the performance of each Sub-Processor's data protection obligations.

The current list of authorized Sub-Processors, including their roles and processing locations, is maintained at the Sub-Processor List page and incorporated herein by reference.

5. Security Measures

FLOWOF1 shall implement and maintain appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk of processing Customer Personal Data, including as appropriate:

  • Encryption of Customer Personal Data in transit using TLS 1.2+ and at rest where stored in the Platform database.
  • Pseudonymization and data minimization techniques where applicable to the processing activity.
  • Ability to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems and services.
  • Ability to restore the availability of and access to Customer Personal Data in a timely manner in the event of a physical or technical incident.
  • Regular testing, assessing, and evaluating of the effectiveness of technical and organizational measures for ensuring the security of the processing.
  • Role-based access controls limiting access to Customer Personal Data to authorized personnel on a need-to-know basis.
  • Secure development lifecycle practices including code review and vulnerability scanning.

A comprehensive description of FLOWOF1's security practices is available in the Security Overview. In assessing the appropriate level of security, FLOWOF1 takes into account the risks presented by processing, in particular from accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Customer Personal Data.

6. Personal Data Breach

FLOWOF1 shall notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

Such notification shall describe: (a) the nature of the breach including, where possible, the categories and approximate number of data subjects and records concerned; (b) the likely consequences of the breach; and (c) the measures taken or proposed to address the breach and mitigate its adverse effects.

FLOWOF1 shall cooperate with Customer and take reasonable steps to investigate, mitigate, and remediate the breach. FLOWOF1 shall document all Personal Data Breaches, including facts relating to the breach, its effects, and remedial action taken.

Customer is responsible for notifying the relevant Supervisory Authority and affected data subjects, as required under Applicable Data Protection Laws. FLOWOF1 shall provide reasonable assistance to Customer in fulfilling such notification obligations.

7. Data Subject Rights

FLOWOF1 shall provide reasonable assistance to Customer, taking into account the nature of the processing, by appropriate technical and organizational measures, insofar as possible, to fulfill Customer's obligation to respond to requests from data subjects exercising their rights under Applicable Data Protection Laws, including rights of access, rectification, erasure, restriction, portability, and objection.

If FLOWOF1 receives a request directly from a data subject concerning Customer Personal Data, FLOWOF1 shall promptly forward the request to Customer and shall not respond to the data subject directly, except as required by Applicable Data Protection Laws.

8. Audits and Certifications

FLOWOF1 shall make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by Customer or another auditor mandated by Customer, subject to the following conditions:

  • Customer shall provide at least thirty (30) calendar days' prior written notice of any audit.
  • Audits shall be conducted during normal business hours and in a manner that does not interfere with FLOWOF1's business operations.
  • Customer shall ensure that any audit does not compromise the security, confidentiality, or integrity of other customers' data.
  • Audits shall be conducted no more than once per calendar year, unless required by a Supervisory Authority.
  • Any third-party auditor shall be subject to confidentiality obligations no less protective than those in this DPA.

In lieu of an on-site audit, FLOWOF1 may provide Customer with a current third-party audit report (such as a SOC 2 Type II or ISO 27001 certification), which Customer may rely on to the extent it addresses the scope of the audit.

9. International Data Transfers

To the extent that Customer Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country that has not been deemed to provide an adequate level of data protection, FLOWOF1 shall ensure that such transfer is made subject to appropriate safeguards.

Such safeguards may include the Standard Contractual Clauses adopted by the European Commission, the UK International Data Transfer Addendum, or any successor transfer mechanism approved under Applicable Data Protection Laws. FLOWOF1 shall provide Customer with a copy of the relevant transfer mechanism upon reasonable request.

FLOWOF1 shall ensure that any Sub-Processor engaged to process Customer Personal Data in a third country is bound by equivalent transfer safeguards.

10. Data Deletion and Return

Upon termination or expiration of the EULA, or upon Customer's written request, FLOWOF1 shall, at Customer's choice, delete or return all Customer Personal Data, and delete existing copies, unless Applicable Data Protection Laws require storage.

FLOWOF1 shall complete such deletion or return within ninety (90) calendar days of the termination date or written request, and shall provide Customer with written confirmation of completion upon reasonable request.

FLOWOF1 may retain Customer Personal Data to the extent required by Applicable Data Protection Laws, provided that such retained data shall be subject to the confidentiality and security obligations of this DPA and shall not be processed for any other purpose.

11. CCPA and U.S. State Law Provisions

To the extent the CCPA or other U.S. state data protection laws apply to the processing of Customer Personal Data, the following additional terms apply:

  • FLOWOF1 is a "Service Provider" or "Processor" as those terms are defined under the CCPA.
  • FLOWOF1 shall process Customer Personal Data only for the limited and specified purposes set out in the EULA and this DPA, and shall not process Customer Personal Data for any commercial purpose other than providing the services.
  • FLOWOF1 shall not "sell" or "share" Customer Personal Data as those terms are defined under the CCPA.
  • FLOWOF1 certifies that it understands the restrictions set out in this Section and shall comply with them.
  • Customer has the right to take reasonable and appropriate steps to ensure that FLOWOF1 processes Customer Personal Data in a manner consistent with Customer's obligations under Applicable Data Protection Laws.
  • FLOWOF1 shall notify Customer if it determines that it can no longer meet its obligations under Applicable Data Protection Laws, in which case Customer may take reasonable and appropriate steps to stop and remediate the unauthorized use of Customer Personal Data.

12. Liability

Each party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the EULA. Any reference in the EULA to liability means the aggregate liability of the parties under the EULA and this DPA together.

The parties agree that the terms of this DPA are reasonable and reflect the relative risks and bargaining power of the parties.

13. Governing Law and Dispute Resolution

This DPA shall be governed by and construed in accordance with the same governing law as the EULA. Any disputes arising out of or related to this DPA shall be resolved in accordance with the dispute resolution provisions of the EULA, including binding arbitration where applicable.

Nothing in this DPA shall be construed to override or conflict with the EULA. In the event of a conflict between this DPA and the EULA with respect to data protection, this DPA shall control.

14. Order of Precedence

In the event of any conflict or inconsistency between this DPA and the EULA, this DPA shall prevail solely with respect to the processing of Customer Personal Data and data protection obligations. In the event of a conflict between this DPA and any other agreement between the parties regarding data protection, this DPA shall prevail.

This DPA is incorporated into and forms an integral part of the EULA. Capitalized terms used but not defined in this DPA have the meanings given to them in the EULA or Privacy Policy.

Annex 1 — Description of Processing

Categories of Data SubjectsCustomer's authorized end users (e.g., schedulers, operators, administrators), and any other individuals whose Personal Data is uploaded to the Platform by Customer.
Categories of Personal DataName, email address, role assignment, and authentication credentials. Customer may upload additional Personal Data into the Platform at its discretion, which FLOWOF1 processes on Customer's instructions.
Special Categories of DataFLOWOF1 is not designed to process special categories of Personal Data (e.g., health data, racial or ethnic origin, religious beliefs). Customer shall not upload such data to the Platform.
Processing PurposesProvision of the FLOWOF1 Business Modeling & Workflow Analysis Platform, including user authentication, scheduling data management, scenario modeling, billing, and security monitoring.
Processing DurationFor the term of the EULA, plus the period necessary for data deletion and return as described in Section 10.
Processing LocationCustomer Personal Data is processed in data centers located in the United States, with cloud infrastructure provided through authorized Sub-Processors.

© 2026 O and P Advisory Services, LLC — All Rights Reserved.

Data Processing Addendum — Version 1.0 — Effective: June 25, 2026