FLIPFLOW DATA PROCESSING ADDENDUM
Effective Date: 1 May 2026
This Data Processing Addendum (“DPA”) forms part of and is incorporated into the Master Subscription Agreement (“MSA”) entered into between Flipflow Data Analytics, S.L. (“Processor”) and the Customer identified in the applicable Order Form (“Controller”).
To the extent Flipflow processes Personal Data on behalf of Customer in connection with the Services, the parties agree as follows.
With respect to the processing of Personal Data, this DPA shall prevail over the MSA and the applicable Order Form to the extent of any conflict.
1. DEFINITIONS
Terms not defined in this DPA shall have the meanings assigned to them in the MSA.
The terms:
- Controller
- Processor
- Data Subject
- Personal Data
- Processing
- Supervisory Authority
- Personal Data Breach
shall have the meanings assigned to them under applicable Data Protection Laws.
“Data Protection Laws” means all applicable laws governing the processing of Personal Data, including:
- Regulation (EU) 2016/679 (“GDPR”);
- Spanish Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights (“LOPDGDD”);
- the UK GDPR and the UK Data Protection Act 2018;
- the Swiss Federal Act on Data Protection (“FADP”), where applicable;
- applicable national legislation implementing or supplementing such laws.
“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission pursuant to Implementing Decision (EU) 2021/914.
“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner’s Office (version B1.0, in force 21 March 2022, as amended or replaced).
2. SUBJECT MATTER AND DURATION
This DPA governs the processing of Personal Data by Flipflow in connection with the provision of the Services.
This DPA shall remain effective for the duration of the MSA and for so long as Flipflow processes Personal Data on behalf of Customer.
3. PROCESSING INSTRUCTIONS
Flipflow shall process Personal Data only on documented instructions from Customer unless otherwise required by applicable law.
Customer’s use of the Services, configuration of the Services and instructions communicated through the Services shall constitute Customer’s documented instructions to Flipflow.
Where applicable law requires Flipflow to process Personal Data outside Customer’s instructions, Flipflow shall inform Customer unless prohibited by law.
Flipflow shall immediately inform Customer if, in its opinion, an instruction infringes applicable Data Protection Laws.
4. NATURE AND PURPOSE OF PROCESSING
Flipflow may process Personal Data solely for the purpose of:
- providing the Services;
- administering Customer accounts;
- providing support services;
- maintaining, securing and improving the Services;
- complying with legal obligations.
5. CATEGORIES OF PERSONAL DATA
Depending on Customer’s use of the Services, Personal Data may include:
- names;
- surnames;
- business email addresses;
- business contact information;
- job titles;
- user identifiers;
- authentication information;
- activity logs;
- Personal Data uploaded by Customer.
6. CATEGORIES OF DATA SUBJECTS
Data Subjects may include:
- Customer employees;
- Authorized Users;
- contractors;
- suppliers;
- partners;
- business contacts;
- other individuals whose Personal Data Customer chooses to process through the Services.
7. PROCESSOR OBLIGATIONS
Flipflow shall:
- process Personal Data only in accordance with Customer instructions;
- ensure personnel are subject to confidentiality obligations;
- implement appropriate technical and organizational measures;
- taking into account the nature of the processing and the information available to Flipflow, provide reasonable assistance to Customer in fulfilling its obligations under Articles 32 to 36 GDPR, including security of processing, breach notification, data protection impact assessments and prior consultation with Supervisory Authorities;
- notify Customer of Personal Data Breaches as required by this DPA;
- maintain records of processing activities where required by law.
8. SECURITY MEASURES
Flipflow shall maintain technical and organizational measures designed to protect Personal Data against unauthorized access, accidental loss, destruction, alteration or disclosure.
Security measures are described in the Security Addendum available at:
https://www.flipflow.io/en/security
The Security Addendum shall constitute Annex II to this DPA for the purposes of the Standard Contractual Clauses.
9. SUBPROCESSORS
9.1 General Authorization
Customer grants Flipflow a general written authorization to engage subprocessors in accordance with this Section 9.
9.2 Equivalent Obligations
Flipflow shall impose data protection obligations on subprocessors that are substantially equivalent to those contained in this DPA, and shall remain liable to Customer for the performance of the subprocessor’s obligations.
9.3 Subprocessor List and Advance Notice
A current list of subprocessors is maintained at:
https://www.flipflow.io/en/subprocessors
Flipflow shall notify Customer of any intended addition or replacement of a subprocessor at least thirty (30) days before the new subprocessor processes Customer Personal Data.
Notice shall be provided through the notification mechanism described in the Subprocessor List, including email notification to Customers subscribed to subprocessor updates.
Customer is responsible for subscribing to such notifications; the subscription mechanism is available at the URL above and upon request to privacy@flipflow.io.
9.4 Objections
Customer may object to a new subprocessor on reasonable data protection grounds by providing written notice within thirty (30) days following the notification referred to in Section 9.3.
The parties shall discuss the objection in good faith and Flipflow may propose commercially reasonable alternatives.
If the parties cannot reasonably resolve the objection, Customer may terminate the affected Services, and Flipflow shall refund the prepaid subscription fees corresponding to the unused portion of the then-current Subscription Term for the terminated Services, in accordance with Section 23.6 of the MSA.
10. INTERNATIONAL TRANSFERS
10.1 Transfer Mechanisms
Where Personal Data is transferred outside the European Economic Area, the United Kingdom or Switzerland to a country not recognized as providing an adequate level of protection, the parties shall rely on the following transfer mechanisms, in the following order of preference:
- an adequacy decision of the European Commission (or, as applicable, of the UK or Swiss authorities), including the EU-U.S. Data Privacy Framework where the data importer holds a valid, active certification covering the relevant data;
- the Standard Contractual Clauses, as implemented in Section 10.2; or
- any other lawful transfer mechanism under applicable Data Protection Laws.
10.2 Incorporation of the Standard Contractual Clauses
Where the SCCs apply to a transfer from Customer to Flipflow, the parties agree that the SCCs are hereby incorporated into this DPA and completed as follows:
- Module Two (Controller to Processor) applies where Customer acts as Controller; Module Three (Processor to Processor) applies where Customer acts as Processor on behalf of a third-party Controller;
- Clause 7 (Docking Clause) is included;
- Clause 9(a): Option 2 (general written authorisation) applies, with a notice period of thirty (30) days as set forth in Section 9.3;
- Clause 11(a): the optional language regarding independent dispute resolution bodies is not included;
- Clause 17: Option 1 applies, and the SCCs shall be governed by the laws of Spain;
- Clause 18(b): disputes shall be resolved before the courts of Madrid, Spain;
- Annex I.A and I.B are completed with the information set forth in Annex 1 to this DPA; Annex I.C: the competent Supervisory Authority is the Spanish Data Protection Authority (Agencia Española de Protección de Datos, AEPD), unless otherwise determined under Clause 13;
- Annex II is completed by reference to the Security Addendum;
- Annex III is completed by reference to the Subprocessor List.
10.3 UK and Swiss Transfers
For transfers subject to the UK GDPR, the SCCs as implemented above shall apply as amended by the UK Addendum, with Table 1 completed with the parties’ details in Annex 1, Tables 2 and 3 completed by reference to Sections 10.2 and 8, and Table 4 permitting either party to end the UK Addendum as set out in its Section 19.
For transfers subject to the FADP, the SCCs shall apply with the adaptations required by the Swiss Federal Data Protection and Information Commissioner (FDPIC), including that references to the GDPR shall be understood as references to the FADP, the competent supervisory authority shall be the FDPIC, and data subjects in Switzerland may enforce their rights in Switzerland.
10.4 Onward Transfers
Flipflow shall ensure that onward transfers to subprocessors located outside the EEA, the UK or Switzerland are subject to a valid transfer mechanism in accordance with this Section 10.
11. DATA SUBJECT RIGHTS
Taking into account the nature of the processing, Flipflow shall provide reasonable assistance to Customer in responding to requests relating to:
- access;
- rectification;
- erasure;
- restriction;
- portability;
- objection.
Customer remains responsible for responding to Data Subject requests.
If Flipflow receives a request directly from a Data Subject relating to Customer Personal Data, Flipflow shall, where legally permitted, promptly forward the request to Customer without responding to it directly.
12. PERSONAL DATA BREACHES
In the event of a Personal Data Breach affecting Customer Personal Data, Flipflow shall:
- notify Customer without undue delay and in any event within seventy-two (72) hours after becoming aware of the Personal Data Breach;
- provide the information reasonably available at the time of notification regarding the nature of the incident, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed, supplementing such information in phases as it becomes available;
- provide reasonable cooperation to Customer in connection with Customer’s notification obligations under Articles 33 and 34 GDPR;
- document the Personal Data Breach and the remediation measures adopted.
Flipflow’s notification of or response to a Personal Data Breach shall not be construed as an acknowledgment of fault or liability.
13. GOVERNMENT REQUESTS
Where legally permitted, Flipflow shall use reasonable efforts to notify Customer before disclosing Customer Personal Data in response to governmental, regulatory or law enforcement requests, and shall disclose only the minimum amount of Personal Data legally required.
14. AUDITS
Flipflow shall make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and with Article 28 GDPR.
Flipflow may satisfy audit requests through:
- certifications;
- audit reports;
- security documentation;
- policies;
- equivalent compliance materials.
Where such documentation is not reasonably sufficient to demonstrate compliance, Customer (or an independent auditor appointed by Customer and not being a competitor of Flipflow, bound by confidentiality obligations) may conduct an audit, including an on-site inspection, subject to the following conditions:
- no more than one (1) audit per calendar year, except following a Personal Data Breach of which Flipflow has become aware or where required by a Supervisory Authority;
- at least thirty (30) days prior written notice;
- conducted during normal business hours and in a manner that does not unreasonably disrupt Flipflow’s operations;
- no access to information relating to other customers of Flipflow;
- Customer bears all costs associated with the audit.
Customer shall not conduct penetration testing, vulnerability scanning or intrusive testing of Flipflow systems without Flipflow’s prior written consent.
15. RETURN AND DELETION
Upon termination of the Services and at Customer’s choice, Flipflow shall:
- return Personal Data in a commonly used format; or
- securely delete Personal Data.
Upon Customer’s written request, Flipflow shall provide written certification of deletion.
Flipflow may retain Personal Data where and for as long as required by applicable law, and such retained data shall remain subject to the protections of this DPA.
16. AI PROCESSING
Where AI Features are used:
- Customer remains Controller of Personal Data submitted to AI Features;
- Flipflow acts as Processor when processing such Personal Data on Customer’s behalf;
- Customer Personal Data is not used to train any artificial intelligence or machine learning models, whether publicly available or internal;
- Customer is solely responsible for determining whether Personal Data submitted to AI Features is appropriate and lawful under applicable Data Protection Laws;
- AI-generated outputs may contain inaccuracies and should be independently reviewed by Customer;
- Customer may opt out of the processing of Customer Data by third-party AI and large language model providers integrated into the AI Features, through the configuration settings available in its account, as further described in the Security Addendum. Where such opt-out is enabled, Personal Data contained in the affected Customer Data shall not be transmitted to or processed by such third-party AI subprocessors.
17. LIABILITY
The liability of each party under this DPA shall be governed by the liability provisions contained in the MSA, including the enhanced liability cap for data protection obligations set forth in Section 20.3 of the MSA.
18. GOVERNING LAW
This DPA shall be governed by the same governing law and jurisdiction provisions contained in the MSA, without prejudice to Sections 10.2(e) and 10.2(f) with respect to the Standard Contractual Clauses.
ANNEX 1 – PROCESSING DETAILS
- List of Parties
- Data exporter: Customer, as identified in the applicable Order Form (Controller; or Processor under Module Three). Contact details: as set forth in the applicable Order Form.
- Data importer: Flipflow Data Analytics, S.L., Paseo de la Chopera 142, Bajo B, 28100 Alcobendas, Madrid, Spain (Processor). Contact: privacy@flipflow.io.
- Description of Transfer / Processing
- Subject Matter: Provision of SaaS market intelligence, retail intelligence, analytics and related services.
- Nature of Processing: Collection, storage, organization, analysis, transmission, retrieval and deletion.
- Purpose: Provision of the Services as described in Section 4.
- Categories of Data Subjects: As described in Section 6.
- Categories of Personal Data: As described in Section 5. No special categories of Personal Data are intended to be processed.
- Frequency of the transfer: Continuous, for the duration of the Services.
- Duration: For the duration of the Services and any retention period required by law.
- Competent Supervisory Authority
- Agencia Española de Protección de Datos (AEPD), unless otherwise determined under Clause 13 of the SCCs.
Annex II (Technical and Organizational Measures): as set forth in the Security Addendum available at https://www.flipflow.io/en/security.
Annex III (List of Subprocessors): as set forth in the Subprocessor List available at https://www.flipflow.io/en/subprocessors.