Standard DPA for enterprise customers subject to data protection regulations
Licensor
O and P Advisory Services, LLC
Version
1.0
Effective Date
June 25, 2026
This Data Processing Addendum ("DPA") is incorporated into and forms an integral part of the End User License Agreement ("EULA") between O and P Advisory Services, LLC ("FLOWOF1") and the enterprise customer ("Customer"). This DPA applies to the processing of Personal Data by FLOWOF1 on behalf of Customer. Enterprise customers may execute a signed version of this DPA by contacting us at privacyflowof1@oandpadvisoryservices.com.
Capitalized terms used but not defined in this DPA have the meanings given to them in the EULA or Privacy Policy. The following terms have the meanings set out below:
FLOWOF1 acts as a Processor processing Customer Personal Data on behalf of Customer, who acts as the Controller. FLOWOF1 shall process Customer Personal Data only for the purposes described in the EULA, this DPA, and as instructed by Customer in writing.
FLOWOF1 shall not process Customer Personal Data for any other purpose, including its own commercial purposes, except as required by Applicable Data Protection Laws. FLOWOF1 is not a Controller of Customer Personal Data.
The scope of Customer Personal Data, categories of data subjects, processing purposes, and retention periods are set out in Annex 1 (Description of Processing).
FLOWOF1 shall, with respect to its processing of Customer Personal Data:
Customer acknowledges and agrees that FLOWOF1 may engage Sub-Processors to process Customer Personal Data on its behalf. FLOWOF1 maintains a current list of authorized Sub-Processors, available at the Sub-Processor List page.
FLOWOF1 shall provide Customer with at least thirty (30) calendar days' prior written notice of any intended addition or replacement of a Sub-Processor, thereby giving Customer the opportunity to object. Customer may object to such addition or replacement by notifying FLOWOF1 in writing within thirty (30) calendar days of receiving the notice, providing reasonably detailed grounds for the objection.
If FLOWOF1 engages a Sub-Processor, FLOWOF1 shall impose on that Sub-Processor, by way of a written contract, data protection obligations that are substantially similar to those set out in this DPA. FLOWOF1 remains fully liable to Customer for the performance of each Sub-Processor's data protection obligations.
The current list of authorized Sub-Processors, including their roles and processing locations, is maintained at the Sub-Processor List page and incorporated herein by reference.
FLOWOF1 shall implement and maintain appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk of processing Customer Personal Data, including as appropriate:
A comprehensive description of FLOWOF1's security practices is available in the Security Overview. In assessing the appropriate level of security, FLOWOF1 takes into account the risks presented by processing, in particular from accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Customer Personal Data.
FLOWOF1 shall notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
Such notification shall describe: (a) the nature of the breach including, where possible, the categories and approximate number of data subjects and records concerned; (b) the likely consequences of the breach; and (c) the measures taken or proposed to address the breach and mitigate its adverse effects.
FLOWOF1 shall cooperate with Customer and take reasonable steps to investigate, mitigate, and remediate the breach. FLOWOF1 shall document all Personal Data Breaches, including facts relating to the breach, its effects, and remedial action taken.
Customer is responsible for notifying the relevant Supervisory Authority and affected data subjects, as required under Applicable Data Protection Laws. FLOWOF1 shall provide reasonable assistance to Customer in fulfilling such notification obligations.
FLOWOF1 shall provide reasonable assistance to Customer, taking into account the nature of the processing, by appropriate technical and organizational measures, insofar as possible, to fulfill Customer's obligation to respond to requests from data subjects exercising their rights under Applicable Data Protection Laws, including rights of access, rectification, erasure, restriction, portability, and objection.
If FLOWOF1 receives a request directly from a data subject concerning Customer Personal Data, FLOWOF1 shall promptly forward the request to Customer and shall not respond to the data subject directly, except as required by Applicable Data Protection Laws.
FLOWOF1 shall make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by Customer or another auditor mandated by Customer, subject to the following conditions:
In lieu of an on-site audit, FLOWOF1 may provide Customer with a current third-party audit report (such as a SOC 2 Type II or ISO 27001 certification), which Customer may rely on to the extent it addresses the scope of the audit.
To the extent that Customer Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country that has not been deemed to provide an adequate level of data protection, FLOWOF1 shall ensure that such transfer is made subject to appropriate safeguards.
Such safeguards may include the Standard Contractual Clauses adopted by the European Commission, the UK International Data Transfer Addendum, or any successor transfer mechanism approved under Applicable Data Protection Laws. FLOWOF1 shall provide Customer with a copy of the relevant transfer mechanism upon reasonable request.
FLOWOF1 shall ensure that any Sub-Processor engaged to process Customer Personal Data in a third country is bound by equivalent transfer safeguards.
Upon termination or expiration of the EULA, or upon Customer's written request, FLOWOF1 shall, at Customer's choice, delete or return all Customer Personal Data, and delete existing copies, unless Applicable Data Protection Laws require storage.
FLOWOF1 shall complete such deletion or return within ninety (90) calendar days of the termination date or written request, and shall provide Customer with written confirmation of completion upon reasonable request.
FLOWOF1 may retain Customer Personal Data to the extent required by Applicable Data Protection Laws, provided that such retained data shall be subject to the confidentiality and security obligations of this DPA and shall not be processed for any other purpose.
To the extent the CCPA or other U.S. state data protection laws apply to the processing of Customer Personal Data, the following additional terms apply:
Each party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the EULA. Any reference in the EULA to liability means the aggregate liability of the parties under the EULA and this DPA together.
The parties agree that the terms of this DPA are reasonable and reflect the relative risks and bargaining power of the parties.
This DPA shall be governed by and construed in accordance with the same governing law as the EULA. Any disputes arising out of or related to this DPA shall be resolved in accordance with the dispute resolution provisions of the EULA, including binding arbitration where applicable.
Nothing in this DPA shall be construed to override or conflict with the EULA. In the event of a conflict between this DPA and the EULA with respect to data protection, this DPA shall control.
In the event of any conflict or inconsistency between this DPA and the EULA, this DPA shall prevail solely with respect to the processing of Customer Personal Data and data protection obligations. In the event of a conflict between this DPA and any other agreement between the parties regarding data protection, this DPA shall prevail.
This DPA is incorporated into and forms an integral part of the EULA. Capitalized terms used but not defined in this DPA have the meanings given to them in the EULA or Privacy Policy.
| Categories of Data Subjects | Customer's authorized end users (e.g., schedulers, operators, administrators), and any other individuals whose Personal Data is uploaded to the Platform by Customer. |
| Categories of Personal Data | Name, email address, role assignment, and authentication credentials. Customer may upload additional Personal Data into the Platform at its discretion, which FLOWOF1 processes on Customer's instructions. |
| Special Categories of Data | FLOWOF1 is not designed to process special categories of Personal Data (e.g., health data, racial or ethnic origin, religious beliefs). Customer shall not upload such data to the Platform. |
| Processing Purposes | Provision of the FLOWOF1 Business Modeling & Workflow Analysis Platform, including user authentication, scheduling data management, scenario modeling, billing, and security monitoring. |
| Processing Duration | For the term of the EULA, plus the period necessary for data deletion and return as described in Section 10. |
| Processing Location | Customer Personal Data is processed in data centers located in the United States, with cloud infrastructure provided through authorized Sub-Processors. |
End User License Agreement
Master agreement
Sub-Processor List
Authorized processors
Security Overview
Technical measures
© 2026 O and P Advisory Services, LLC — All Rights Reserved.
Data Processing Addendum — Version 1.0 — Effective: June 25, 2026