🌊
GetFlowSuite
Data Processing Agreement v1.0
Effective date: 11 April 2026 Governed by: EU GDPR (Regulation 2016/679)

Plain English summary: When you use GetFlowSuite, you share employee data with us (names, email addresses, work hours). This agreement sets out exactly how we handle that data, what we promise to do with it, and what rights you have. It is legally required under GDPR Article 28.

1. Parties

This Data Processing Agreement ("DPA") is entered into between:

This DPA forms part of and is incorporated into the GetFlowSuite Terms of Service. By using GetFlowSuite, the Client agrees to the terms of this DPA.

2. Definitions

Terms used in this DPA have the meaning given to them in EU Regulation 2016/679 ("GDPR"). In addition:

3. Subject Matter and Nature of Processing

GetFlowSuite processes Personal Data on behalf of the Client solely to provide the Services. The processing is necessary for the performance of the contract between the parties.

3.1 Categories of data subjects

3.2 Categories of personal data processed

Data TypePurposeTool
Full nameEmployee identification and displayAll tools
Email addressAuthentication, notifications, account setupAll tools
Work hours loggedTimesheet management and reportingTimeFlow
Project allocationsCapacity planningResourceFlow
Desk/resource bookingsOffice resource managementOfficeFlow
Labour cost dataProject financial managementCostFlow
Hourly ratesCost calculation for approved timesheetsCostFlow / TimeFlow

3.3 Duration of processing

GetFlowSuite processes Personal Data for the duration of the Client's active subscription. Upon termination, data is retained for 30 days to allow export, then deleted. See Section 9.

4. Obligations of GetFlowSuite (Processor)

GetFlowSuite shall:

5. Obligations of the Client (Controller)

The Client shall:

6. Security Measures

GetFlowSuite implements the following technical and organisational measures:

7. Sub-processors

The Controller provides general authorisation for GetFlowSuite to engage the following sub-processors. GetFlowSuite will notify the Controller of any intended changes to this list with at least 14 days' notice, giving the Controller the opportunity to object.

Sub-processorRoleData processedLocation
Google Firebase / Firestore
Google LLC
Database, authentication, cloud functions All personal data EU (europe-west1, Belgium)
Netlify
Netlify, Inc.
Frontend hosting and CDN IP addresses (request logs only) Global CDN / US
Twilio SendGrid
Twilio Inc.
Transactional email delivery Email addresses, name (first name only) US (SCCs in place)
Stripe
Stripe, Inc.
Payment processing Billing email, subscription status US / EU (SCCs in place)

All sub-processors outside the EEA (SendGrid, Stripe, Netlify) operate under Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring an adequate level of data protection for international transfers.

8. Data Subject Rights

Employees have the following rights under GDPR that the Controller is responsible for fulfilling:

GetFlowSuite will assist the Controller in responding to data subject requests within the timeframes required by GDPR (one month).

9. Data Retention and Deletion

10. Personal Data Breach Notification

In the event of a personal data breach, GetFlowSuite shall:

Breach notifications should be sent to the Controller's registered email address. The Controller should report suspected breaches to contact@getflowsuite.com.

11. Audit Rights

The Controller has the right to audit GetFlowSuite's compliance with this DPA. In practice, this means:

12. Governing Law

This DPA is governed by the laws of Poland. Any disputes shall be subject to the jurisdiction of the courts of Kraków, Poland, without prejudice to the Controller's right to lodge a complaint with their national supervisory authority (e.g. the ICO in the UK, UODO in Poland, or the relevant DPA in their member state).

13. Changes to this DPA

GetFlowSuite may update this DPA from time to time. Material changes will be notified to the Controller by email at least 30 days before they take effect. Continued use of the Services after that date constitutes acceptance of the updated DPA. The Controller may terminate the Services if they do not accept the updated terms.

14. Contact

For all data protection enquiries, requests, or to exercise rights under this DPA:

GetFlowSuite — Data Protection
Łukasz Biniecki
Unruga 65a, 30-394 Kraków, Poland
Email: contact@getflowsuite.com
Response time: within 5 business days