FLIPFLOW SECURITY ADDENDUM
Effective Date: 1 May 2026
This Security Addendum describes the administrative, organizational and technical measures implemented by Flipflow Data Analytics, S.L. (“Flipflow”) in connection with the provision of its Services.
This Security Addendum forms part of the contractual framework governing Customer’s use of the Services and should be read together with the applicable Master Subscription Agreement (“MSA”), Data Processing Addendum (“DPA”) and Service Level Agreement (“SLA”).
This Security Addendum constitutes Annex II (Technical and Organizational Measures) to the DPA for the purposes of the Standard Contractual Clauses.
1. INFORMATION SECURITY PROGRAM
Flipflow maintains an information security program, implemented as part of an Information Security Management System (ISMS) certified under ISO/IEC 27001:2022, designed to protect the confidentiality, integrity and availability of Customer Data and the Services.
The program is periodically reviewed and updated based on operational requirements, evolving threats, applicable legal obligations and industry-recognized security practices.
2. ACCESS CONTROL
2.1 Least Privilege
Access to production systems and Customer Data is granted on a least-privilege basis.
Personnel are only granted access required for the performance of their responsibilities.
2.2 Authentication
Multi-Factor Authentication (MFA) is required for access to critical systems and administrative environments, except where equivalent controls are provided through approved Single Sign-On (SSO) mechanisms.
2.3 Access Reviews
Access rights are reviewed periodically and upon changes in role, employment status or operational need.
Access privileges are revoked when no longer required.
2.4 Password Management
Credentials are managed in accordance with internal security policies and generally accepted industry practices.
3. ORGANIZATIONAL SECURITY
3.1 Confidentiality Obligations
Personnel with access to Customer Data are subject to confidentiality obligations.
3.2 Security Awareness
Flipflow provides ongoing security awareness and security-related guidance to relevant personnel.
3.3 Device Management
Flipflow maintains centralized management controls for corporate devices used to access production systems and Customer Data.
Such controls may include:
- device encryption;
- operating system updates;
- endpoint protection;
- remote access controls;
- device inventory management;
- device compliance controls.
4. DATA PROTECTION MEASURES
4.1 Encryption in Transit
Data transmitted between Customer and the Services is protected using industry-standard encryption protocols, including TLS.
4.2 Encryption at Rest
Customer Data stored by Flipflow is protected using encryption technologies appropriate to the storage environment.
4.3 Data Segregation
Logical controls are implemented to prevent unauthorized access between customer environments.
5. INFRASTRUCTURE SECURITY
5.1 Cloud Infrastructure
The Services are hosted on infrastructure provided by established cloud service providers.
5.2 Monitoring
Flipflow maintains monitoring systems designed to detect operational anomalies, availability issues and security events.
5.3 Vulnerability Management
Security vulnerabilities are assessed and remediated according to severity, risk and business impact.
5.4 Logging and Audit Trails
Flipflow maintains logging and monitoring mechanisms designed to support:
- security monitoring;
- incident investigation;
- operational oversight;
- troubleshooting activities.
5A. INDEPENDENT SECURITY TESTING
Flipflow shall engage a qualified independent third party to perform a penetration test of the Services at least once per calendar year.
Upon Customer’s written request and subject to confidentiality obligations, Flipflow shall make available an executive summary of the most recent penetration test, including the scope of the test and the status of remediation of material findings.
Detailed technical findings, exploitation details and internal security documentation shall not be disclosed.
6. BACKUP AND RECOVERY
6.1 Backups
Flipflow performs regular backups of production environments and critical business data in accordance with internal operational requirements.
6.2 Recovery Procedures
Recovery procedures are periodically reviewed and maintained.
6.3 Recovery Objectives
Unless otherwise specified in an applicable Order Form:
Recovery Time Objective (RTO):
60 minutes
Recovery Point Objective (RPO):
24 hours
Recovery objectives represent operational targets and not service guarantees.
7. INCIDENT MANAGEMENT
7.1 Incident Response
Flipflow maintains procedures for the identification, assessment, containment, remediation and resolution of security incidents.
7.2 Severity Assessment
Security incidents are assessed and prioritized according to severity and business impact.
7.3 Breach Notifications
Flipflow shall notify affected Customers of security incidents affecting Customer Data without undue delay after becoming aware of the incident.
Where the incident constitutes a Personal Data Breach affecting Customer Personal Data, notification shall be provided within the timeframe and with the content set forth in the Data Processing Addendum (in any event within seventy-two (72) hours after Flipflow becomes aware of the Personal Data Breach).
7.4 Cooperation
Flipflow shall provide reasonable information regarding:
- the nature of the incident;
- affected systems or data where known;
- remediation actions undertaken.
8. BUSINESS CONTINUITY
Flipflow maintains business continuity and disaster recovery measures designed to support continued operation of the Services during significant disruptions.
Such measures may include:
- infrastructure redundancy;
- backup systems;
- disaster recovery procedures;
- operational contingency plans.
8.1 Security Governance
Flipflow periodically reviews its security controls against applicable legal, contractual and industry requirements.
Flipflow continuously evaluates and enhances its information security program, including alignment with additional industry-recognized security and compliance frameworks such as SOC 2, where appropriate.
8.2 ISO/IEC 27001 Certification
Flipflow maintains an Information Security Management System (ISMS) certified under ISO/IEC 27001:2022 by an accredited certification body. The certification applies to the development and operation of Flipflow’s SaaS platform for retail market analysis and monitoring.
Flipflow shall use commercially reasonable efforts to maintain such certification (or an equivalent recognized standard) throughout the term, and shall notify Customer without undue delay if the certification is withdrawn or its scope materially reduced.
Upon reasonable written request, and subject to confidentiality obligations, Flipflow shall make available a copy of the current certificate or a summary of its scope. Detailed internal security documentation, including the Statement of Applicability, shall not be disclosed.
9. SUBPROCESSORS
Flipflow may engage subprocessors to support the provision of the Services.
A current list of subprocessors is available at:
https://www.flipflow.io/en/subprocessors
Flipflow requires subprocessors to maintain security measures appropriate to the services they provide.
10. ARTIFICIAL INTELLIGENCE SECURITY
Where AI Features are used:
- Customer Personal Data is not used to train any artificial > intelligence or machine learning models, whether publicly > available or internal;
- access to Customer Data is restricted to authorized systems and > personnel;
- AI providers are selected using commercially reasonable security and > compliance criteria;
- Customer remains responsible for reviewing and validating > AI-generated outputs before relying upon them for business, legal, > financial or operational decisions.
10.1 Third-Party AI Processing Opt-Out
Customer may elect, through the configuration settings available in its account, to opt out of the processing of Customer Data by third-party artificial intelligence and large language model providers integrated into the AI Features (including, without limitation, the AI subprocessors identified in the Subprocessor List).
Where such opt-out is enabled:
- the proprietary business data uploaded by Customer to the Platform > (Customer Data) shall not be transmitted to, or processed by, any > third-party AI or large language model provider integrated into > the AI Features;
- the opt-out applies prospectively, at the account or workspace > level, from the time it is enabled;
- the opt-out does not apply to information collected by Flipflow from > publicly available sources, which does not constitute Customer > Data;
- Customer acknowledges that, as a consequence of enabling the > opt-out, the AI Features and analytical capabilities that depend > on third-party AI processing may be unavailable or limited with > respect to the affected Customer Data.
Flipflow shall give effect to the opt-out configuration selected by Customer and shall maintain technical controls designed to ensure that opted-out Customer Data is not routed to third-party AI providers.
11. SECURITY CONTACT
Security-related inquiries may be directed to:
security@flipflow.io
General privacy-related inquiries may be directed to:
privacy@flipflow.io
12. CHANGES TO THIS SECURITY ADDENDUM
Flipflow may update this Security Addendum periodically to reflect changes in technology, operational practices, legal requirements or security measures.
Material reductions in security protections shall not apply during an active Subscription Term without Customer’s consent.
The current version shall remain available at:
https://www.flipflow.io/en/security