Effective 21-07-2026 · Version 1.0

Data Processing Addendum

Provider (Processor): ERPflow OÜ, a private limited company incorporated under the laws of the Republic of Estonia (registry code: 17201984) (the "Provider" or "Processor").

Customer (Controller): the legal person, or the self-employed person acting in the course of its trade, business, or profession, that has accepted the General Terms and Conditions of Service (the "GTC") or a separate order form referencing this DPA (the "Customer" or "Controller"). The Service is offered on a business-to-business basis only (GTC clause 1.2); it is not offered to consumers within the meaning of Directive 2011/83/EU or the Estonian Consumer Protection Act.

Supplements: GTC v1.0, clause 10.3

1. Purpose, scope, and status

1.1. This Data Processing Addendum (the "DPA") sets out the terms on which the Provider processes personal data on behalf of the Customer in the course of providing the Service (as defined in the GTC). It gives effect to Article 28(3) of Regulation (EU) 2016/679 ("GDPR") and, where applicable, the equivalent provisions of the Estonian Personal Data Protection Act and the UK GDPR.

1.2. This DPA forms part of the Agreement between the parties. Terms capitalised but not defined here have the meaning given to them in the GTC.

1.3. Roles. In respect of Customer Personal Data (as defined in clause 2 below):

  • (a) the Customer acts as controller (GDPR art. 4(7)), unless it discloses in writing that it is a processor acting on behalf of a further controller, in which case clause 12 (Customer as processor) applies; and
  • (b) the Provider acts as processor (GDPR art. 4(8)).

1.4. Each party is responsible for its own compliance with applicable data-protection law. Nothing in this DPA shifts liability that mandatory law places on the Customer as controller.

1.5. B2B warranty. The Customer warrants that it is entering into the Agreement in the course of its trade, business, craft, or profession, and not as a consumer. Consumer-protection statutes and consumer-specific rights do not apply to the Agreement or this DPA. Nothing in this DPA is intended to create rights for consumers.

1.6. Order of precedence. In case of conflict, this DPA prevails over the GTC and the Acceptable Use Policy ("AUP") in respect of the processing of Customer Personal Data. The order of precedence in GTC clause 18.2 otherwise applies.

2. Definitions

"Customer Personal Data" means personal data (GDPR art. 4(1)) contained in Customer Data (as defined in the GTC) that the Provider processes on behalf of the Customer under the Agreement.

"Data Protection Law" means the GDPR, the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus), Directive 2002/58/EC (as amended), the UK GDPR and Data Protection Act 2018 (where applicable), and any other national or EU law on the protection of natural persons in the processing of personal data that applies to a party's processing under the Agreement.

"Data Subject", "personal data", "personal data breach", "processing", "processor", "controller", "sub-processor", "supervisory authority", and related terms have the meanings given in the GDPR.

"SCCs" means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

"Sub-processor" means any third party engaged by the Provider to process Customer Personal Data on behalf of the Customer.

"Third Country" means a country outside the European Economic Area that is not the subject of an adequacy decision under GDPR art. 45.

3. Subject-matter and details of processing

3.1. The subject-matter, nature, purpose, duration, categories of data, and categories of Data Subjects are as set out in Annex I to this DPA. Annex I forms an integral part of the DPA and may be updated only as expressly agreed by the parties or as required by law.

3.2. The Customer determines the purposes and means of the processing. The Provider processes Customer Personal Data only on documented instructions from the Customer, which are given by:

  • (a) the acceptance of the GTC and this DPA;
  • (b) the Customer's configuration and use of the Service (including the modules the Customer enables and the data the Customer uploads or generates through the Service); and
  • (c) any additional written instructions (email is sufficient) that are compatible with the functionality of the Service.

3.3. If the Provider believes that an instruction infringes Data Protection Law, it will inform the Customer without undue delay (GDPR art. 28(3), second sub-paragraph). The Provider may suspend the execution of the affected instruction until the Customer confirms or amends it.

3.4. If, exceptionally, EU or Member State law requires the Provider to process Customer Personal Data other than on the Customer's instructions, the Provider will inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest (GDPR art. 28(3)(a)).

4. Duration and deletion

4.1. This DPA takes effect on the earlier of (a) the Customer's acceptance of the GTC and (b) the first processing of Customer Personal Data by the Provider under the Agreement, and remains in force until all Customer Personal Data has been deleted or returned in accordance with this clause 4.

4.2. On termination of the Agreement (GTC clause 12.4), the Provider will, at the Customer's choice:

  • (a) return Customer Personal Data to the Customer in a commonly used, machine-readable format; or
  • (b) delete Customer Personal Data,

and delete existing copies, unless EU or Member State law requires storage of the personal data (GDPR art. 28(3)(g)).

4.3. Where the Customer does not make an election, the Provider will make the Customer Personal Data available for export for thirty (30) days from the effective date of termination (GTC clause 13.5), after which the Provider will delete Customer Personal Data from production systems within a further thirty (30) days. Deletion from encrypted, offline backups occurs in accordance with the Provider's backup rotation schedule (set out in Annex II) and will not exceed ninety (90) days unless a longer retention is required by law.

4.4. On request, the Provider will provide the Customer with a written confirmation of deletion.

5. Confidentiality

5.1. The Provider ensures that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (GDPR art. 28(3)(b)). Access to Customer Personal Data is restricted on a need-to-know basis and revoked promptly on change of role or termination of employment.

5.2. The Provider trains its personnel on data-protection and information-security requirements relevant to their role and re-trains them at least annually.

6. Security of processing

6.1. The Provider implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk (GDPR arts. 28(3)(c) and 32), taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing. The current measures are set out in Annex II and are reviewed at least annually.

6.2. The Provider will not materially reduce the overall level of security offered to the Customer during the term of the Agreement. Where the Provider replaces a measure, the replacement will provide substantially the same or a higher level of protection.

6.3. The Customer is responsible for the security measures implemented on its side, including the use of the Service's role, permission, and audit-log features, the security of the endpoints and networks from which its Authorised Users access the Service, and the management of its own credentials.

7. Sub-processing

7.1. General authorisation. The Customer grants the Provider a general written authorisation (GDPR art. 28(2)) to engage Sub-processors for the processing of Customer Personal Data, subject to this clause 7.

7.2. List and notice. The current list of Sub-processors is published at https://erpflow.ai/subprocessors and is set out for reference in Annex III. The Provider will provide the Customer with prior notice of any intended addition or replacement of a Sub-processor at least thirty (30) days before that Sub-processor begins to process Customer Personal Data. Notice may be given by email to the account email address or by in-product notification and/or subscription to a change feed.

7.3. Right to object. The Customer may object in writing to a proposed Sub-processor on reasonable data-protection grounds within the thirty-day notice period. The parties will discuss the objection in good faith. If the Provider cannot accommodate the objection, the Customer may terminate the affected part of the Service for cause under GTC clause 13.3(b) without penalty by giving written notice within a further fifteen (15) days.

7.4. Flow-down. The Provider imposes on each Sub-processor, by written contract, data-protection obligations that are substantially the same as those set out in this DPA, in particular in respect of confidentiality, security, sub-processing, assistance, breach notification, deletion, and international transfers (GDPR art. 28(4)).

7.5. Liability. The Provider remains fully liable to the Customer for the performance of its Sub-processors' obligations (GDPR art. 28(4)).

8. International transfers

8.1. Default: EU/EEA. The Provider processes Customer Personal Data within the European Economic Area (EEA) by default. Where Customer Personal Data is transferred to a Third Country, the Provider will ensure that at least one of the transfer mechanisms in GDPR chapter V is in place before the transfer.

8.2. SCCs. Where no adequacy decision applies (GDPR art. 45) and the transfer is not otherwise covered by an appropriate safeguard, the parties agree to enter into the SCCs on the following basis:

  • (a) Module Two (controller to processor) applies where the Customer is the controller and the Provider is the processor;
  • (b) Module Three (processor to processor) applies where the Customer is itself a processor (see clause 12) and the Provider is a sub-processor;
  • (c) the optional docking clause (clause 7) is enabled;
  • (d) in clause 9(a), option 2 applies with a change-notification period of thirty (30) days;
  • (e) in clause 11(a), the optional independent-dispute-resolution language is not selected;
  • (f) in clause 17, the governing law is the law of the Republic of Estonia;
  • (g) in clause 18(b), the forum is the courts of the Republic of Estonia;
  • (h) Annexes I, II, and III of the SCCs are populated by reference to Annexes I, II, and III of this DPA respectively; and
  • (i) where a specific Sub-processor requires the SCCs to be executed back-to-back, the Provider will enter into the SCCs with that Sub-processor on the same basis as above.

8.3. UK transfers. Where the UK GDPR applies to a transfer, the parties agree to the UK International Data Transfer Addendum to the SCCs (issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018), which is deemed executed by reference on the basis set out above.

8.4. Swiss transfers. Where the Swiss Federal Act on Data Protection applies to a transfer, the SCCs apply as amended by the guidance of the Swiss Federal Data Protection and Information Commissioner (in particular, references to the GDPR are read as references to the FADP, references to the EU are read to include Switzerland, and references to supervisory authorities include the FDPIC).

8.5. Supplementary measures. In light of the Schrems II judgment (C-311/18), the Provider carries out a transfer impact assessment before onboarding a Sub-processor in a Third Country and applies supplementary technical, contractual, and organisational measures (encryption in transit and at rest, key management outside the Third Country where feasible, robust access controls, and legal-request review) as appropriate to the risk.

9. Data-subject requests

9.1. Taking into account the nature of the processing, the Provider will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Customer's obligation to respond to requests to exercise Data-Subject rights under GDPR chapter III (GDPR art. 28(3)(e)).

9.2. Where a Data Subject submits a request directly to the Provider that relates to Customer Personal Data, the Provider will (a) not respond to the request itself except to acknowledge receipt and direct the Data Subject to the Customer, and (b) forward the request to the Customer without undue delay.

9.3. The Provider makes available to the Customer, through the Service, self-service functionality to support access, rectification, erasure, restriction, portability, and objection requests (for example, per-record data export, edit, delete, and audit trail). Where the Customer requires assistance beyond this functionality, the Provider will provide reasonable assistance and, for extraordinary requests, may charge on a time-and-materials basis at the Provider's then-current rates.

10. Personal-data breach notification

10.1. Notification to the Customer. The Provider will notify the Customer of a personal-data breach affecting Customer Personal Data without undue delay and in any event within seventy-two (72) hours of becoming aware of it (GTC clause 10.4; GDPR art. 33).

10.2. Content of notification. To the extent then known, the notification will include (a) a description of the nature of the breach, including where possible the categories and approximate number of Data Subjects and records concerned, (b) the name and contact details of the Provider's data-protection contact, (c) a description of the likely consequences of the breach, and (d) a description of the measures taken or proposed to address the breach, including, where appropriate, measures to mitigate its possible adverse effects. Where all information cannot be provided at once, information will be provided in phases without further undue delay.

10.3. Assistance. The Provider will assist the Customer in ensuring compliance with the Customer's obligations under GDPR arts. 33 and 34 (notification to supervisory authority and communication to Data Subjects), taking into account the nature of the processing and the information available to the Provider.

10.4. No admission. A notification under this clause 10 is not, and will not be construed as, an admission of fault or liability by the Provider.

11. Data-protection impact assessments and prior consultation

11.1. On reasonable request, and taking into account the nature of the processing and the information available to it, the Provider will assist the Customer in carrying out data-protection impact assessments (GDPR art. 35) and in any prior consultations with a supervisory authority (GDPR art. 36) that are required in connection with the Customer's use of the Service.

11.2. The Provider will make available to the Customer, on request, the information necessary to demonstrate compliance with GDPR art. 28 (GDPR art. 28(3)(h)), including through the security documentation set out in Annex II, third-party audit reports where available, and reasonable answers to security and compliance questionnaires.

12. Customer as processor

12.1. Where the Customer is itself a processor acting on behalf of a further controller (a "Third-Party Controller"), the Customer:

  • (a) warrants that it has all necessary authorisations from the Third-Party Controller to engage the Provider as a sub-processor, including under GDPR art. 28(2);
  • (b) will ensure that its own processing instructions to the Provider are consistent with the instructions of the Third-Party Controller; and
  • (c) will, on request, make available to the Third-Party Controller sufficient information regarding this DPA to enable the Third-Party Controller to satisfy itself of the Provider's compliance with GDPR art. 28(4).

12.2. In this scenario, references in this DPA to the Customer's rights and obligations as controller are read as references to the Customer's rights and obligations as processor vis-à-vis the Third-Party Controller. The Provider is not required to enter into a direct contractual relationship with the Third-Party Controller.

13. Audits and inspections

13.1. On reasonable prior written notice (at least thirty (30) days, save in the case of a suspected breach or a demand from a supervisory authority), and no more than once per calendar year except where a supervisory authority requires otherwise, the Provider will allow for and contribute to audits, conducted by the Customer or an independent auditor mandated by the Customer (GDPR art. 28(3)(h)).

13.2. Audit modalities. Audits will be conducted:

  • (a) during the Provider's normal business hours;
  • (b) in a manner that does not interfere with the Provider's operations, its obligations of confidentiality to other customers, or the security or integrity of the Service; and
  • (c) subject to reasonable confidentiality undertakings by the auditor (which must not be a competitor of the Provider).

13.3. First response. The Provider may satisfy the Customer's audit right in the first instance by providing (a) the current version of the Provider's security documentation (Annex II), (b) responses to a reasonable security questionnaire, and (c) copies of any then-current third-party audit reports. Given the nature of the product, on-site inspections are not permitted.

13.4. Costs. Costs and expenses related to such audits shall be agreed in advance and fully covered by the Customer. Where an audit reveals a vulnerability, the Provider will remediate the vulnerability at its own expense.

14. Government access and law-enforcement requests

14.1. If the Provider receives a legally binding request from a public authority, including a judicial authority, for the disclosure of Customer Personal Data, the Provider will:

  • (a) review the legality of the request and, where lawful, challenge disproportionate or unlawful requests;
  • (b) provide only the minimum amount of information permitted, giving a reasoned interpretation of the request;
  • (c) notify the Customer of the request as soon as reasonably possible, so that the Customer can seek a protective order or equivalent remedy, unless prohibited by law from doing so; and
  • (d) keep records of the requests received, its responses, and the legal basis relied on, and make those records available to the Customer on request to the extent lawful.

14.2. Where the Provider is prohibited from notifying the Customer, it will use reasonable and lawful efforts to obtain the right to waive the prohibition, in order to communicate to the Customer as much information as it can and as soon as possible.

15. Liability

15.1. Liability under or in connection with this DPA is subject to the limitations and exclusions of liability in Section 14 of the GTC, save that (a) each party remains liable to Data Subjects and supervisory authorities to the extent required by GDPR arts. 82 and 83, and (b) nothing in this DPA excludes or limits liability that cannot be excluded or limited by mandatory law.

15.2. As between the parties, each party is liable for the fines and compensation imposed on it by a supervisory authority or court in proportion to its responsibility for the underlying non-compliance, applying the allocation principles of GDPR art. 82(4)–(5).

16. Term, changes, and survival

16.1. This DPA takes effect as set out in clause 4.1 and remains in force until terminated in accordance with the GTC or superseded by an updated DPA. Clauses that by their nature should survive termination (including clauses 4.2–4.4 (deletion), 5 (confidentiality), 8 (transfers, in respect of ongoing transfers that must be wound down), 10 (breach notification, for breaches discovered after termination that relate to the term), 13 (audits, for the period of one year after termination), 14 (government access), and 15 (liability)) will survive termination.

16.2. The Provider may update this DPA (a) to reflect a change in Data Protection Law or the guidance of a competent supervisory authority, or (b) to introduce a new EU-approved standard clause or code of conduct, or (c) to reflect operational changes that do not reduce the level of protection afforded to Customer Personal Data. Material changes will be notified in accordance with GTC clause 17.5.

17. Miscellaneous

17.1. Notices. Data-protection notices to the Provider must be sent to info@erpflow.ai. Notices to the Customer will be sent to the account email address on file.

17.2. Governing law and venue. This DPA is governed by the law of the Republic of Estonia and is subject to the venue provisions in GTC clause 18. The choice of law does not deprive Data Subjects of the protection of mandatory rules of the law of their habitual residence.

17.3. Language. This DPA is made available in English. English is the authoritative version. Any translation (including into Estonian or produced by machine) is provided for convenience only; in case of any discrepancy, the English text prevails.

17.4. Severability. If any provision of this DPA is held invalid or unenforceable, the remaining provisions will remain in full force, and the invalid provision will be replaced by a valid provision that most closely reflects the parties' original intent.

Annex I — Details of processing

A. List of parties.

  • Data exporter (Controller): the Customer — a legal person, or a self-employed person acting in the course of its trade, business, or profession — as identified in the Agreement and in-product account records.
  • Data importer (Processor): ERPflow OÜ, registry code 17201984. Contact: info@erpflow.ai.

B. Description of processing.

  • Subject-matter: processing of Customer Personal Data to provide the ERPflow.ai Service (as defined in the GTC) — a business-management SaaS covering customers, suppliers, staff, quotes, invoices, products, vacations, and related records.
  • Duration: for the term of the Agreement, plus the deletion window set out in clause 4.
  • Nature and purpose: hosting, storage, retrieval, structuring, display, transmission (including to Third-Party Services enabled by the Customer), backup, and deletion of Customer Personal Data, and provision of features that operate on that data (workflows, notifications, PDF generation, exports, audit logs, and reporting).
  • Categories of Data Subjects: the Customer's employees, contractors, directors, and other Authorised Users; the Customer's own customers and prospects; the Customer's suppliers and their contacts; and any other natural persons whose personal data the Customer chooses to process through the Service.
  • Categories of personal data: identification and contact data (name, email, phone, postal address, tax and registry identifiers); professional data (role, employer, department); transactional data (quotes, invoices, payments, product configuration); HR-adjacent data limited to what the enabled modules require (e.g. vacation balances and requests where the HR/vacation module is enabled); usage and audit data (IP address, session identifiers, action logs). Special categories (GDPR art. 9) should not be uploaded (AUP §3.1(e)).
  • Frequency of transfer: continuous, for the duration of the Agreement.
  • Retention period: the term of the Agreement and the deletion windows set out in clause 4, subject to any longer retention required by law.

C. Competent supervisory authority.

  • Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia — as competent authority in respect of the Provider (GDPR art. 55).

Annex II — Technical and organisational measures

The Provider maintains a public, up-to-date description of the technical and organisational security measures applied to the Service at https://erpflow.ai/security (the "Security Page"). The Security Page describes the measures the Provider has implemented in respect of: (a) pseudonymisation and encryption of Personal Data in transit and at rest; (b) confidentiality, integrity, availability, and resilience of processing systems and services; (c) restoration of availability and access to Personal Data in a timely manner in the event of a physical or technical incident; (d) access control, authentication, and secrets management; (e) network and application security, including logging and monitoring; (f) personnel measures, including confidentiality obligations and security training; (g) sub-processor management; and (h) incident detection, response, and notification. These headings correspond to Article 32(1) GDPR and Annex II of the SCCs (Commission Implementing Decision (EU) 2021/914).

The Security Page forms part of this Annex II by reference. The Provider may update the measures published at the Security Page from time to time in line with evolving good industry practice, provided that the overall level of protection is not materially reduced and that any material reduction is notified to the Customer in advance in accordance with clause 5 (Security). On written request to info@erpflow.ai, the Provider will provide a dated PDF snapshot of the Security Page as at the date of the DPA, signed by an authorised representative, for the Customer's records.

Annex III — List of Sub-processors

The Provider maintains a public, up-to-date list of Sub-processors at https://erpflow.ai/subprocessors (the "Register"). The Register sets out, for each Sub-processor, its legal name, registered address, hosting location, the category of processing performed, the categories of Personal Data processed, and the transfer basis relied on for any transfer outside the EEA. The Register also identifies (i) federated sign-in providers that act as independent controllers when a data subject authenticates through them, and (ii) categories of Sub-processor that are wired into the Service architecture but are not currently engaged.

The Register forms part of this Annex III by reference. The Provider will update the Register and give notice of intended changes in accordance with clause 7.2 (List and notice); the Customer's right to object is set out in clause 7.3. The Customer is responsible for subscribing to change notifications published at the Register. On written request to info@erpflow.ai, the Provider will provide a dated PDF snapshot of the Register as at the date of the DPA, signed by an authorised representative, for the Customer's records.

Transfers to Sub-processors outside the EEA are governed by clause 8 (Module 2 SCCs; UK IDTA; Swiss FADP) and, where applicable, supplementary measures per clause 8.5.


Contact

info@erpflow.ai

免费起步,随业务成长。

在一个平台里经营整个公司,付的是创业者的价,不是大公司的价。

无需信用卡 · 无试用倒计时 · 数据全部可导出 · 随时可取消