Data Processing Agreement

Last edit: 07/01/2026

Recitals

The CUSTOMER, depending on its activities, collects and processes personal data relating to different categories of data subjects (“Personal Data”) either as a Controller or as a Processor.

  • The CUSTOMER wishes to engage the COMPANY to provide the Services under the applicable Agreement.

  • For the purpose of performing the Services, the COMPANY may need to process the Personal Data.

  • The CUSTOMER and the COMPANY will only communicate and process Personal Data when this is necessary to achieve a clearly defined purpose compatible with Applicable Data Protection Legislation.

  • The purpose of this agreement is to provide a legal framework for the processing of Personal Data performed by the COMPANY on behalf of the CUSTOMER.

  • This agreement is thereafter referred to as the “Data Processing Agreement”, or “DPA” and is incorporated within the Agreement.

  • Capitalized terms not defined in the DPA shall have the meaning given to them by the GDPR.

I. General Data Processing Terms

The Parties acknowledge that, depending on the relevant processing activity, the CUSTOMER may act as a Controller, in which case the COMPANY acts as its Processor, or the CUSTOMER may act as a Processor on behalf of another Controller, in which case the COMPANY acts as a Sub-processor.

References in this DPA to instructions of the CUSTOMER shall, where applicable, include lawful instructions of the relevant Controller as communicated to the COMPANY through the CUSTOMER. Each Party shall comply with the obligations applicable to it under Applicable Data Protection Legislation in its respective role.

II. Description of the processing

The description of the processing is defined in ANNEX 1. 

III. Commencement and termination

  1. This DPA is entered for the same duration as the Agreement governing the Services provided by the COMPANY. Given the interdependence of this DPA and the Agreement, termination of the latter, for any reason whatsoever, shall result in the termination of this DPA.

  2. In case of a breach to the obligations set out in the DPA, each Party may terminate the DPA within the conditions of termination for breach defined in the Agreement.

IV. Controller and Processor obligations

IV. (a) CUSTOMER’s obligations

The CUSTOMER, in its capacity as Controller or Processor, is responsible for ensuring that the processing instructions it provides to the COMPANY are lawful and supported by an appropriate legal basis, and that required information has been provided to data subjects or the relevant Controller.

The CUSTOMER is responsible for the accuracy, quality and lawfulness of CUSTOMER Personal Data and for obtaining any authorization required from the relevant Controller where the CUSTOMER acts as a Processor.

In particular, the CUSTOMER must:

  • provide the COMPANY only with Personal Data that is relevant and necessary for the Services. The CUSTOMER shall not instruct the COMPANY to process special categories of Personal Data under Article 9 GDPR or personal data relating to criminal convictions and offences under Article 10 GDPR unless such processing is lawful, necessary for the Services and subject to appropriate safeguards. The CUSTOMER remains responsible for identifying such data and providing any additional documented instructions reasonably required;

  • collect under its liability, lawfully, fairly and in a transparent manner the CUSTOMER Personal Data provided to the COMPANY, for the performance of the Service, and in particular, to ensure the lawfulness of processing and the information due to data subjects;

  • maintain a record of processing activities carried out and more generally, comply with the principles of the Applicable Data Protection Legislation;

  • ensure, before and throughout the processing, compliance with the obligations set out in the Applicable Data Protection Legislation.

IV. (b) COMPANY’s obligations

When processing CUSTOMER Personal Data according to this DPA, the COMPANY undertakes to:

  • process CUSTOMER Personal Data only on the documented instructions of the CUSTOMER, as set out in the Order Form and this DPA, and as otherwise necessary for the COMPANY to provide the Services to the CUSTOMER or to comply with Applicable Data Protection Legislation unless the COMPANY is required to process CUSTOMER Personal Data for other legitimate purposes under applicable EU or EU Member State law or another particular non-EU applicable law, in which case the COMPANY shall notify the CUSTOMER of that legal requirement before such processing occurs or is permitted except where that law prohibits such notification on important grounds of public interest. Each of the parties agrees that any additional instructions outside the scope of the Agreement or this DPA will be mutually agreed between the parties;

  • ensure that all personnel authorized to process CUSTOMER Personal Data are subject to confidentiality obligations in respect of CUSTOMER Personal Data;

  • taking into account the nature of the processing, assist the CUSTOMER (at the CUSTOMER’s expense) by appropriate, technical and organizational measures, insofar as this is possible, for the fulfillment of the CUSTOMER’s obligations to respond to data subject data protection rights requests. The COMPANY shall not respond directly to a request from a data subject concerning data subjects’ personal data. However, the COMPANY shall notify the CUSTOMER if the COMPANY receives such a request;

  • taking into account the nature of the processing and the information available to the COMPANY, assist the CUSTOMER in ensuring compliance with its obligations under Articles 32 to 36 GDPR;

  • implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the nature, scope, context and purposes of the processing, in accordance with Article 32 GDPR;

  • at the choice of the CUSTOMER, delete or return all CUSTOMER Personal Data after the end of the provision of Services relating to the processing of CUSTOMER Personal Data, and delete existing copies unless EU or EU Member State law or another particular applicable law requires the COMPANY to retain such CUSTOMER Personal Data; and

  • notify the CUSTOMER without undue delay upon becoming aware of any personal data breach.

IV. (c) International transfers

  1. The COMPANY is authorized to transfer CUSTOMER Personal Data outside the European Economic Area (“EEA”) where necessary to provide the Services, including through the Subprocessors listed in Annex 1 of the then-current DPA published at https://mindflow.io/data-processing-agreement, as updated in accordance with Article 4.4 below.

  2. Any transfer of CUSTOMER Personal Data outside the EEA shall be governed by a binding data-processing arrangement and an applicable transfer mechanism, such as an adequacy decision or the Standard Contractual Clauses adopted by the European Commission, together with any supplementary measures reasonably required by Applicable Data Protection Legislation.

IV. (d) Sub-processors

  • The CUSTOMER provides a general authorization to the COMPANY to use third parties (“Subprocessors”) to process CUSTOMER Personal Data and perform the Services, including the Subprocessors listed in Annex 1 of the then-current DPA published at https://mindflow.io/data-processing-agreement.

  • The COMPANY will ensure that Sub-processors meet the requirements set out in the data protection obligations that protect CUSTOMER Personal Data to the same standard provided for by this DPA and, at a minimum, compliant with the requirements of the Applicable Data Protection Legislation and shall remain liable for a breach caused by a Sub-processor but only to the same extent that the COMPANY would be liable if it had provided the Services of the Sub-processor directly under the terms of this DPA.

  • The COMPANY may add or replace Subprocessors and shall inform the CUSTOMER of any intended addition or replacement. The CUSTOMER has thirty (30) calendar days from receipt of the notice to raise legitimate and documented objections relating to data protection. If an objection cannot reasonably be resolved, the Parties will work in good faith to identify a commercially reasonable alternative. If no reasonable alternative is available, either Party may terminate the affected Services on thirty (30) days’ notice.

IV. (e) CUSTOMER’s Audit Rights

The COMPANY shall make available to the CUSTOMER information reasonably necessary to demonstrate compliance with this DPA.

Where reasonably sufficient, the COMPANY may satisfy such requests by providing relevant independent certifications, third-party audit reports, penetration-test summaries or other appropriate compliance documentation, subject to confidentiality obligations.

Where such information is not reasonably sufficient to demonstrate compliance with the COMPANY’s obligations under Applicable Data Protection Legislation, the CUSTOMER may conduct, itself or through an independent auditor bound by confidentiality obligations, an audit relating to the processing of CUSTOMER Personal Data.

Except where required by a competent supervisory authority or following a material Personal Data Breach affecting CUSTOMER Personal Data, any such audit shall be conducted no more than once in any twelve-month period, be subject to reasonable prior written notice, take place during normal business hours, not unreasonably interfere with the COMPANY’s business or compromise the security or confidentiality of other customers, and be conducted at the CUSTOMER’s expense.

The COMPANY and the CUSTOMER shall cooperate in good faith regarding the reasonable scope and conduct of any such audit.

IV. (f) Suspension of Processing

The COMPANY is not responsible for independently determining the CUSTOMER’s legal basis or compliance in relation to the CUSTOMER’s use of the Services. However, where the COMPANY considers that a documented instruction of the CUSTOMER infringes Applicable Data Protection Legislation, the COMPANY shall inform the CUSTOMER without undue delay and may suspend the affected processing pending clarification or modification of the instruction.

The COMPANY will notify the CUSTOMER if it is no longer able to comply with Applicable Data Protection Legislation, this DPA or applicable Standard Contractual Clauses. The Parties will work in good faith to resolve the issue. If no reasonable resolution is available, either Party may terminate the affected Services in accordance with the Agreement.

IV. (g) Liability

Any claims brought in connection with this DPA will be subject to the limitations set out in the Agreement.

IV. (h) General Provisions

  • In the event of inconsistencies between the provisions of this DPA and the Agreement, the provisions of this DPA shall prevail with regard to the processing of CUSTOMER Personal Data. In the event of any conflict or inconsistency between this DPA and the SCCs, the SCCs shall prevail.

  • Capitalized terms not defined in this DPA shall have the meaning given to them in the Agreement.

  • Notices from the CUSTOMER under this DPA shall be sent to legal@mindflow.io. Notices from the COMPANY shall be sent to the CUSTOMER’s data-protection or notice contact stated in the Order Form or otherwise notified to the COMPANY in writing. An email notice is deemed received on the next Business Day after transmission, provided that the sender receives no delivery-failure notification.

  • In the event that any provision of this DPA be invalid or unenforceable, then the remainder of this DPA shall remain valid and in force. The invalid or unenforceable provision shall be either (i) amended as necessary to ensure its validity and enforceability while preserving the parties intentions as closely as possible or, if this is not possible, (ii) construed in a manner as if the invalid or unenforceable part had never been contained in this DPA.

  • This DPA shall inure to the benefit of and be binding upon the Parties and their respective permitted successors and assigns.

  • No modification of any provision of this DPA shall be binding unless it is evidenced in writing and duly executed by or on behalf of each of the parties to this DPA.

  • This DPA and all disputes arising from this DPA, whether contractual or non-contractual in nature, shall be governed by and construed under the laws of France. The parties irrevocably submit to the exclusive jurisdiction of the French courts concerning all matters arising out of or in connection with this DPA.

Annex 1 – Data processing details

I. COMPANY’S Governance

Data Protection Officer

Hugo David:
Hugo.david@mindflow.io

Representative

Fabrice Delhoste
Fabrice Delhoste — legal@mindflow.io

Customer Governance

The Customer’s data protection and operational contacts are those stated in the applicable Order Form or otherwise notified to Mindflow in writing.

II. Data Processing Details

Categories of Data Subjects

CUSTOMER employees; prospects; clients; users; and other data subjects whose Personal Data is submitted to or processed through the Services under the CUSTOMER’s instructions.

Categories of Personal Data

Identification and contact data; professional data; economic or financial data where submitted; connection and authentication data, including logs, user identifiers and identity-based credentials; API keys, access tokens or secret values where they contain or relate to Personal Data; and other Personal Data selected by the CUSTOMER.

Processing Operations

Collection; organisation and structuring; recording; storage; consultation and use; retrieval; disclosure or transmission; transformation; and erasure.

Purposes

User account creation; provision, operation, security and support of the Services; execution of workflows and agentic actions; onboarding and training; and compliance with the CUSTOMER’s documented instructions.

Duration and retention periods

User account data: for the active account and up to 90 days after account closure. Data processed to provide the Services: for the duration of the Agreement and up to 90 days thereafter. Support records: for the duration of the Agreement and up to 90 days after closure. Training records: for the duration of the relevant training and up to 90 days thereafter, unless a different period is agreed or required by law.

Transfer Outside the EEA

Mindflow is established in the EEA. Processing outside the EEA may occur through the authorised Subprocessors listed below, subject to appropriate safeguards.

III. Permitted Sub-contractors

Subprocessor

Purposes

Data / Processing

Location

Transfer Safeguards

Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg

aws-EU-privacy@amazon.com 

Hosting and cloud infrastructure

Customer Data, credentials, secrets, API keys and service data required to provide and secure the Services.

Germany and Ireland, unless otherwise stated in the Order Form.

Not applicable where processing remains in the EEA; otherwise applicable AWS safeguards.

Intercom R&D Unlimited Company

legal@intercom.io 

Customer support and service communications

Support communications and related account or diagnostic data, which may include Personal Data or Confidential Information supplied by the Customer.

United States and other locations identified in Intercom’s then-current subprocessor documentation; regional hosting may apply where configured.

EU–US Data Privacy Framework where applicable, with the EU Standard Contractual Clauses as a fallback or where otherwise required.

Amazon Web Services EMEA SARL — Amazon Bedrock, 38 Avenue John F. Kennedy, L-1855 Luxembourg

AI inference and agentic features through Amazon Bedrock

AI Inputs, AI Outputs and service data required for the selected AI Feature. Underlying model developers are not separately identified where they do not receive or have access to Customer inputs or outputs.

The AWS region selected for the Services.

Not applicable where processing remains in the EEA; otherwise applicable AWS safeguards.

OpenAI Ireland Ltd. and relevant Affiliates

legal@openai.com 

AI inference where the Customer selects an OpenAI model made available through a Mindflow-managed account or Mindflow AI Credits

AI Inputs, AI Outputs and service data required for the selected AI Feature.

As applicable under Mindflow’s account configuration and OpenAI’s then-current data processing and subprocessor documentation.

Applicable adequacy decision and/or EU Standard Contractual Clauses. OpenAI is not appointed by Mindflow as a Subprocessor where the Customer connects and uses its own OpenAI account or API key.