Skip to content
louflow

In effect from August 14, 2026

Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the LouFlow Terms of Service at https://louflow.com/terms (the "Agreement") between LouFlow LLC ("LouFlow", "Processor") and the customer identified in the Agreement ("Customer", "Controller"). It applies where LouFlow processes Personal Data on Customer's behalf and Data Protection Laws apply to that processing.

How this DPA takes effect. It is incorporated into the Agreement automatically and requires no signature. Customer accepts it by accepting the Agreement. If your procurement process requires a countersigned copy, complete the details in Annex I and email a signed version to legal@louflow.com; we will return an executed counterpart.

In case of conflict, this DPA prevails over the Agreement with respect to the processing of Personal Data. The Standard Contractual Clauses prevail over this DPA where they apply.

1. Definitions

"Data Protection Laws" means all laws applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018 ("UK GDPR"), the Swiss Federal Act on Data Protection ("FADP"), and US state privacy laws including the California Consumer Privacy Act as amended ("CCPA").

"Personal Data" means personal data, personal information, or equivalent as defined in Data Protection Laws, contained in Customer Data and processed by LouFlow on Customer's behalf.

"Customer Data" has the meaning given in the Agreement, and includes Flows, screenshots, recordings, annotations, and account information submitted through the Platform.

"Data Subject", "Controller", "Processor", "Processing", "Supervisory Authority", and "Personal Data Breach" have the meanings given in the GDPR.

"Sub-processor" means a third party engaged by LouFlow to process Personal Data.

"Standard Contractual Clauses" or "SCCs" means the clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

"UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0 in force 21 March 2022.

"Restricted Transfer" means a transfer of Personal Data from the EEA, UK, or Switzerland to a country not benefiting from an adequacy decision.

2. Roles and Scope

2.1 Allocation of roles. With respect to Personal Data in Customer Data, Customer is the Controller and LouFlow is the Processor. Where Customer is itself a processor acting for a third-party controller, LouFlow is a sub-processor, and Customer warrants that it has authority to enter into this DPA on that controller's behalf.

2.2 LouFlow as Controller. LouFlow acts as an independent Controller for a limited set of data: account registration details used to administer the customer relationship, billing information, and product usage telemetry used to secure and improve the Platform. That processing is governed by the LouFlow Privacy Policy at https://louflow.com/privacy, not by this DPA.

2.3 Screen capture — allocation of responsibility. Customer acknowledges that the Platform captures screen content and that Personal Data relating to individuals other than Customer's own users may be captured in Flows. Customer alone determines what is recorded. Customer is responsible for establishing a lawful basis for that capture, for providing any notice required to those individuals, and for using the Platform's redaction tools where appropriate. LouFlow does not inspect, classify, or filter the contents of Flows.

2.4 Prohibited data. Customer will not submit to the Platform, and will use reasonable measures to prevent capture of, data subject to sector-specific regimes that the Platform is not designed to support — including protected health information under HIPAA, cardholder data under PCI DSS, and information subject to ITAR or export-controlled classification. LouFlow has no obligations under those regimes and disclaims liability arising from such submission.

3. Processing of Personal Data

3.1 Documented instructions. LouFlow will process Personal Data only on Customer's documented instructions, including with regard to Restricted Transfers, unless required to do otherwise by applicable law. This DPA, the Agreement, and Customer's configuration and use of the Platform constitute Customer's complete documented instructions.

3.2 Unlawful instructions. LouFlow will inform Customer if, in its opinion, an instruction infringes Data Protection Laws, unless prohibited from doing so by law. LouFlow may suspend processing of the affected instruction until it is amended or confirmed.

3.3 Details of processing. The subject matter, duration, nature, purpose, categories of Personal Data, and categories of Data Subjects are set out in Annex I.

3.4 Customer obligations. Customer warrants that it has a lawful basis for the processing it instructs, has provided all notices and obtained all consents required, and that its instructions comply with Data Protection Laws. Customer is responsible for the accuracy and legality of the Personal Data it submits.

3.5 No sale or independent use. LouFlow will not sell Personal Data, will not share it for cross-context behavioral advertising, will not retain, use, or disclose it for any purpose other than performing the services or as otherwise permitted by Data Protection Laws, and will not combine it with data received from other sources except as permitted by the CCPA. LouFlow does not use Customer Data to train artificial intelligence or machine learning models. LouFlow certifies that it understands and will comply with these restrictions.

4. Confidentiality

LouFlow will ensure that personnel authorized to process Personal Data are bound by written confidentiality obligations or an appropriate statutory duty of confidentiality, receive training appropriate to their role, and are granted access only to the extent necessary to perform their duties.

5. Security

5.1 Technical and organisational measures. LouFlow will implement and maintain the measures described in Annex II, taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to Data Subjects.

5.2 Changes to measures. LouFlow may update its security measures provided the level of protection is not materially reduced.

5.3 Customer's own responsibilities. Customer is responsible for the security of its own systems and credentials, for configuring the Platform appropriately, for managing user access and permissions, and for deciding which Flows to publish. Publishing a Flow to a public link makes it accessible without authentication; this is a Customer-controlled disclosure, not a security failure of the Platform.

6. Sub-processors

6.1 General authorisation. Customer grants LouFlow general authorisation to engage Sub-processors, subject to this Section. The Sub-processors engaged as of the Effective Date are listed in Annex III.

6.2 Obligations flow-down. LouFlow will impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to Customer for each Sub-processor's performance.

6.3 New Sub-processors. LouFlow will notify account administrators by email at least thirty (30) days before a new Sub-processor begins processing Personal Data. Customer may object on reasonable data protection grounds within that period by writing to privacy@louflow.com, setting out the grounds. The parties will discuss in good faith. If no resolution is reached, Customer may terminate the affected subscription on written notice, with a prorated refund of prepaid fees for the unused remainder of the then-current billing period, as Customer's sole remedy.

6.4 Emergency replacement. Where a Sub-processor must be replaced urgently for security or continuity reasons, LouFlow may do so and will notify Customer as soon as practicable, with the objection right in Section 6.3 applying retrospectively.

7. Data Subject Rights

7.1 Self-service. The Platform enables Customer to access, correct, export, and delete Personal Data directly. Customer will use these functions to respond to Data Subject requests in the first instance.

7.2 Assistance. Taking into account the nature of the processing, LouFlow will assist Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests to exercise rights of access, rectification, erasure, restriction, portability, and objection.

7.3 Requests received directly. If LouFlow receives a request from a Data Subject relating to Customer's Personal Data, it will not respond substantively, will promptly forward the request to Customer, and will direct the Data Subject to Customer, unless legally required to respond.

7.4 Individuals appearing in Flows. Where an individual contacts LouFlow about their appearance in a published Flow, LouFlow will forward the request to the Customer controlling that Flow and will assist Customer in responding. LouFlow may unpublish or remove content directly where it reasonably believes the content is unlawful or where required by law, and will notify Customer.

7.5 Cost. Assistance under this Section is provided at no charge unless a request is manifestly unfounded, excessive, or requires engineering work materially beyond the Platform's standard functionality, in which case LouFlow may charge a reasonable fee agreed in advance.

8. Assistance with Compliance

LouFlow will provide Customer with reasonable assistance, taking into account the nature of processing and the information available to it, with data protection impact assessments and prior consultations with Supervisory Authorities under GDPR Articles 35 and 36, and will make available the information necessary to demonstrate compliance with Article 28.

9. Personal Data Breach

9.1 Notification. LouFlow will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer's Personal Data.

9.2 Content of notification. The notification will describe, to the extent known: the nature of the breach and the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address it and mitigate adverse effects; and a contact point for further information. Where information is not available at once, it will be provided in phases without undue delay.

9.3 Cooperation. LouFlow will take reasonable steps to contain and remediate the breach and will cooperate with Customer in any notification Customer must make to a Supervisory Authority or to Data Subjects.

9.4 No admission. Notification under this Section is not an acknowledgement of fault or liability.

9.5 Notification channel. Notice will be sent to the email addresses of Customer's account administrators. Customer is responsible for keeping those addresses current.

10. Deletion and Return

10.1 During the term. Customer may export or delete Personal Data at any time through the Platform.

10.2 On termination. LouFlow will delete Personal Data from live systems within thirty (30) days of account deletion, and from backups within ninety (90) days, unless applicable law requires longer retention. On written request made within the 30-day window, LouFlow will make Customer Data available for export.

10.3 Certification. LouFlow will certify deletion in writing on request.

10.4 Retained data. Where LouFlow retains Personal Data as required by law, it will continue to protect it under this DPA and will process it only to the extent and for the period required.

11. Audits

11.1 Documentation. LouFlow will make available to Customer, on request no more than once in any twelve (12) month period, the information necessary to demonstrate compliance with Article 28, including its current security documentation and the results of its most recent third-party security assessment where one has been conducted.

11.2 On-site audits. Where the information provided under Section 11.1 is insufficient to demonstrate compliance, Customer may conduct an audit, subject to: at least thirty (30) days' prior written notice; conduct during normal business hours; no more than once in any twelve (12) month period unless required by a Supervisory Authority or following a Personal Data Breach; execution of a confidentiality undertaking; use of an independent auditor who is not a LouFlow competitor; scope limited to systems processing Customer's Personal Data; and no access to other customers' data, LouFlow's proprietary source code, or its internal security testing results.

11.3 Cost. Customer bears its own audit costs and will reimburse LouFlow's reasonable costs where an audit exceeds one business day.

12. International Transfers

12.1 Location of processing. Personal Data is processed in the United States. Payment data processed by Lavalane LTD remains in the European Union.

12.2 EU transfers. Where a Restricted Transfer from the EEA occurs, the SCCs are incorporated into this DPA by reference and apply as follows:

  • Module Two (Controller to Processor) applies, or Module Three (Processor to Processor) where Customer is itself a processor;

  • Clause 7 (docking clause) applies;

  • Clause 9: Option 2 (general written authorisation) applies, with a notice period of thirty (30) days as set out in Section 6.3;

  • Clause 11(a): the optional independent dispute resolution language does not apply;

  • Clause 13: the competent Supervisory Authority is that identified in Annex I;

  • Clause 17: Option 1 applies, and the governing law is the law of Ireland;

  • Clause 18(b): disputes will be resolved before the courts of Ireland;

  • Annexes I, II, and III to the SCCs are populated by Annexes I, II, and III to this DPA.

12.3 UK transfers. Where a Restricted Transfer from the UK occurs, the UK Addendum applies to the SCCs as incorporated above. For Table 1, the parties and details are those in Annex I. For Table 2, the version of the SCCs is that referenced in Section 12.2. For Table 3, the appendix information is Annexes I to III. For Table 4, neither party may terminate the Addendum under Section 19.

12.4 Swiss transfers. Where a Restricted Transfer from Switzerland occurs, the SCCs apply with these modifications: references to the GDPR are read as references to the FADP; the competent authority is the Federal Data Protection and Information Commissioner; the term "Member State" does not prevent Data Subjects in Switzerland from bringing proceedings in Switzerland; and the SCCs also protect the data of legal entities until the revised FADP no longer requires it.

12.5 Alternative mechanisms. If a transfer mechanism is invalidated or superseded, the parties will cooperate in good faith to implement a valid alternative. LouFlow may adopt a replacement mechanism, including certification under an adequacy framework, on notice to Customer.

12.6 Government access. LouFlow will notify Customer of any legally binding request from a public authority for disclosure of Personal Data, unless prohibited by law, will challenge requests it considers unlawful, and will disclose only the minimum necessary. LouFlow maintains that it has not received, and to the best of its knowledge is not subject to, any order requiring it to build a backdoor into the Platform.

13. CCPA and US State Laws

13.1 Service provider status. With respect to Personal Data subject to the CCPA, LouFlow is a service provider, and Customer is a business. LouFlow will process Personal Data only for the business purposes specified in the Agreement.

13.2 Restrictions. LouFlow will not sell or share Personal Data as those terms are defined in the CCPA; will not retain, use, or disclose it outside the direct business relationship or for any purpose other than the services; and will not combine it with personal information from other sources except as permitted. LouFlow will notify Customer if it determines it can no longer meet these obligations.

13.3 Other states. Where the comprehensive privacy laws of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, or comparable jurisdictions apply, LouFlow acts as a processor and will comply with the equivalent obligations of those laws, which this DPA is intended to satisfy.

14. Liability

Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Agreement. Nothing in this DPA limits any liability that cannot be limited under Data Protection Laws, including liability to Data Subjects under the third-party beneficiary provisions of the SCCs.

15. General

15.1 Term. This DPA takes effect on the Effective Date and continues until LouFlow ceases to process Personal Data on Customer's behalf. Sections that by their nature should survive will survive.

15.2 Amendments. LouFlow may amend this DPA where required to comply with Data Protection Laws, on thirty (30) days' notice. Amendments will not materially reduce the protections afforded to Personal Data.

15.3 Severability. If a provision is held invalid, the remainder continues in effect.

15.4 Governing law. Except as provided in Section 12.2 for the SCCs, this DPA is governed by the law stated in the Agreement.

15.5 Contact. Data protection matters: privacy@louflow.com. Security incidents: security@louflow.com.

ANNEX I — Description of Processing

A. List of Parties

Data exporter (Controller): the Customer identified in the Agreement. Contact: the account administrator email address on file. Activities: use of the LouFlow Platform to create, store, and share workflow documentation. Role: Controller (or Processor, where Module Three applies).

Data importer (Processor): LouFlow LLC Address: [ADDRESS], Wyoming, United States Contact: privacy@louflow.com Activities: provision of the LouFlow digital adoption platform. Role: Processor.

B. Description of Transfer

Categories of Data Subjects - Customer's employees, contractors, and authorized users - Customer's own customers, clients, and partners, where their data appears in captured screens - Individuals whose personal data is visible in systems documented by Customer - Viewers of published Flows

Categories of Personal Data - Identity and contact data: first name, last name, email address - Account data: profile details, team membership, role and permissions, authentication identifiers - Usage data: IP address, device and browser information, feature interactions, session timestamps - Content data: any personal data visible on screens captured by Customer, which may include names, email addresses, telephone numbers, account identifiers, transaction records, correspondence, and any other information displayed in the systems Customer documents - Support data: correspondence with LouFlow support

Special category data Not intentionally processed. Customer is instructed not to capture special category data. Where such data is nonetheless captured through screen recording, it is protected by the measures in Annex II; Customer remains responsible for the lawfulness of that processing.

Frequency of transfer: continuous, for the duration of the Agreement.

Nature and purpose: hosting, storage, transmission, display, backup, and deletion of Customer Data for the purpose of providing the Platform; provision of technical support; security monitoring.

Retention: as set out in Section 10 of this DPA and Section 9 of the Privacy Policy.

Sub-processors: see Annex III. Retention by Sub-processors matches the periods above.

C. Competent Supervisory Authority

The competent Supervisory Authority is determined by reference to Customer, as data exporter, in the following order:

  1. Where Customer is established in one or more EEA Member States: the Supervisory Authority of the Member State in which Customer is established. Where Customer is established in more than one Member State, the Supervisory Authority of the Member State in which Customer's main establishment in the EEA is located.

  2. Where Customer is not established in the EEA but has designated a representative under GDPR Article 27: the Supervisory Authority of the Member State in which that representative is established.

  3. Where neither applies — including where Customer falls within the scope of the GDPR under Article 3(2) without an EEA establishment or designated representative: the Irish Data Protection Commission, consistent with the choice of Irish law in Section 12.2 of this DPA.

Nothing in this Annex limits the competence of any Supervisory Authority under Article 55 or 56 of the GDPR, or the right of a Data Subject to lodge a complaint with the authority of their habitual residence or place of work.

For transfers from the UK: the Information Commissioner's Office. For transfers from Switzerland: the Federal Data Protection and Information Commissioner.

ANNEX II — Technical and Organisational Measures

Encryption - TLS 1.2 or higher for all data in transit - Encryption at rest for stored Customer Data, including Flows and screenshots - Passwords stored using a modern one-way hashing algorithm with per-user salt

Access control - Role-based access control with least-privilege defaults - Multi-factor authentication required for all staff with production access - Unique named accounts; no shared credentials - Access rights reviewed on role change and revoked on departure - Administrative access to production systems logged and retained for 12 months

System security - Network segregation between production and non-production environments - Regular patching of operating systems and dependencies - Automated dependency vulnerability scanning - Web application firewall and rate limiting

Data segregation - Logical separation of each customer's data - Access scoped by account and organisation identifiers at the application layer

Availability and resilience - Automated backups with defined recovery point and recovery time objectives - Redundant infrastructure across availability zones - Periodic restoration testing

Personnel - Confidentiality undertakings for all staff - Security and data protection training on onboarding and periodically thereafter - Background checks where permitted by law

Sub-processor management - Due diligence before engagement - Written data protection terms with each Sub-processor - Periodic review

Incident response - Documented incident response procedure with defined roles - 72-hour notification commitment under Section 9 - Post-incident review

Product-level controls available to Customer - Redaction and blurring tools for captured content, applied destructively to stored images - Access controls and permissions for Flows - Ability to unpublish public links - Export and deletion functions

ANNEX III — Sub-processors

Sub-processorPurposeLocation of processingPersonal Data involvedAmazon Web Services, Inc.Cloud infrastructure, hosting and storageUnited StatesAccount data, Flows, screenshots, logsMicrosoft CorporationCloud infrastructure, hosting and storage (Azure)United StatesAccount data, Flows, screenshots, logsMicrosoft CorporationProduct analytics and session recording (Clarity)United StatesUsage and interaction dataStripe, Inc.Payment processingUnited StatesBilling contact details, transaction dataLavalane LTDPayment processingCyprus, European UnionBilling contact details, transaction dataResend, Inc.Transactional email deliveryUnited StatesEmail address, message contentGoogle LLCAuthentication (optional social sign-in)United StatesName, email address, account identifierMicrosoft CorporationAuthentication (optional social sign-in)United StatesName, email address, account identifier