Data Processing Addendum
Last updated: October 2026
Purpose
This Data Processing Addendum (DPA) describes the terms under which Nexflow processes personal data on behalf of a customer organization using the platform.
Roles
The customer organization is the data controller for its own customers' and leads' information. Nexflow acts as a data processor, processing that data solely to provide the platform and solely on the customer's documented instructions.
Scope of processing
Nexflow processes the categories of personal data a customer enters into the platform (such as customer and lead contact information, service history, and activity records) for the duration of the customer's subscription.
Security measures
Processing is governed by the architectural controls described on our Security page, including row-level multi-tenant isolation, server-side authorization, encrypted connections, and least-privilege credential scoping.
Subprocessors
A current list of subprocessors involved in delivering the platform is maintained on our Subprocessors page. The customer consents to Nexflow's use of these subprocessors, subject to the notice process described there.
Assistance with data subject requests
Nexflow will provide reasonable assistance to a customer organization responding to a verified data subject request (such as access, correction, or deletion) concerning data the customer controls within the platform.
Deletion or return of data
Upon termination of a customer's subscription, data return and deletion timing are handled according to the applicable customer agreement and order form. Nexflow will work with the customer on a reasonable export or deletion request.
Requesting a signed DPA
If your organization requires a formally executed, counter-signed version of this DPA as part of your own compliance process, contact us through our Contact page.