Legal
Data Processing Agreement
The terms under which Fluidlee processes personal data on your behalf.
This Data Processing Agreement (“DPA”) forms part of the Terms of Service (or a signed Subscription Agreement) between the customer (“you”) and Fluidlee Ltd. (“Fluidlee”). It applies only to the platform, and only where Fluidlee processes personal data on your behalf when you use the Service. The public website involves no processing of personal data on your behalf and is outside this DPA.
1. Roles of the parties
For personal data contained in your Customer Data, you are the controller (or a processor acting for your own customers) and Fluidlee is the processor (or subprocessor). Each party will comply with the data-protection laws that apply to it, including the GDPR, UK GDPR, the Israeli Privacy Protection Law, and the CCPA/CPRA as applicable.
2. Scope and instructions
Fluidlee will process personal data only to provide the Service and only on your documented instructions — which include these Terms, your configuration of the Service, and your API calls — unless required to act otherwise by law, in which case we will inform you where permitted. The subject matter, duration, nature, and purpose of the processing, the types of personal data, and the categories of data subjects are set out in Annex I.
3. Confidentiality
Fluidlee ensures that personnel authorized to process personal data are bound by confidentiality obligations and access it only on a need-to-know basis.
4. Security
Fluidlee implements and maintains appropriate technical and organizational measures to protect personal data, as described in Annex II. These are described at the level of categories and standards; detailed configuration specifics are available under NDA on request.
5. Subprocessors
You give general authorization for Fluidlee to engage its subprocessors (see Annex III). A current list of the subprocessors that process Customer Data is available on request. Fluidlee imposes data-protection obligations on each subprocessor no less protective than those in this DPA, and remains responsible for their performance. We will give you advance notice of any new or replacement subprocessor (email us to subscribe to change notifications) and a reasonable opportunity to object on legitimate data-protection grounds.
6. Assisting you
Taking into account the nature of the processing, Fluidlee will assist you, by appropriate technical and organizational measures and insofar as possible, to:
- respond to requests from data subjects exercising their rights (access, rectification, erasure, portability, restriction, objection);
- ensure the security of processing, notify personal-data breaches, and carry out data protection impact assessments and prior consultations.
Because Fluidlee holds your Customer Data as a processor, requests that Fluidlee receives directly from your end users will be referred to you.
7. Personal data breaches
Fluidlee will notify you without undue delay after becoming aware of a personal-data breach affecting your Customer Data, and will provide the information you reasonably need to meet your own notification obligations.
8. International transfers
Where Fluidlee or its subprocessors process personal data outside the country of origin, Fluidlee will ensure an appropriate transfer mechanism is in place — such as the European Commission’s Standard Contractual Clauses (and the UK Addendum where relevant) — which are incorporated into this DPA by reference and prevail in case of conflict.
9. Return and deletion
On termination of the Service, Fluidlee will, at your choice, delete or return your Customer Data, and delete existing copies, within a reasonable period, unless law requires storage. Residual copies in backups are deleted on Fluidlee’s normal backup cycle.
10. Audits
Fluidlee will make available the information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate — subject to reasonable confidentiality, scope, frequency, and notice conditions. Where available, third-party reports or questionnaires may be provided to satisfy audit requests.
Annex I — Details of processing
- Subject matter: provision of the Fluidlee platform (a managed backend, API, rule engine, and audit trail).
- Duration: for the term of your subscription and any wind-down period.
- Nature and purpose: hosting, storing, structuring, transmitting, and otherwise processing Customer Data to operate the Service as configured by you.
- Types of personal data: as determined by you — the fields you define in your schema and the values your tenants and end users submit. Fluidlee does not require any particular personal data, and stores at most an opaque actor identifier about your end users.
- Categories of data subjects: as determined by you — typically your tenants and their end users.
Annex II — Technical and organizational measures
Fluidlee maintains measures including:
- Encryption in transit for data moving between you, the platform, and its subprocessors.
- Strong one-way hashing of passwords and secrets; API keys are stored only as hashes and shown once.
- Logical tenant isolation enforced at the database layer, with dedicated databases available on Enterprise.
- Access controls limiting personnel access to personal data on a need-to-know basis.
- Audit logging of changes to records, with retention scaled by plan tier.
- Rate limiting and abuse protections on the API.
- Secure development practices and managed secrets for platform infrastructure.
- Regular review of these measures. Detailed specifics are available under NDA.
Annex III — Subprocessors
A current list of the subprocessors that process Customer Data on your behalf — with each one’s purpose and location — is available on request. Email hello@fluidlee.com for the current list and to subscribe to change notifications.
Contact
To request a signed copy of this DPA, or with any question about it, email hello@fluidlee.com.