Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the agreement between the Customer and Studio Phoenix Limited (NZ company number 7857036, NZBN 9429047886629), trading as FlowSign ("FlowSign"), for use of the FlowSign service (the "Agreement"). It sets out how FlowSign processes personal information on the Customer's behalf.
This DPA applies automatically to every paid Customer. If you need a signed counterpart for your records, email legal@flowsign.app.
1. Definitions
- Customer Personal Information means personal information that the Customer, or its users and signers, submit to the FlowSign service.
- Agency, Individual, Personal Information, Privacy Breach have the meanings given in the Privacy Act 2020 (NZ).
- Data Subject / Controller / Processor / Personal Data have the meanings given in the EU General Data Protection Regulation and the UK GDPR, where those laws apply.
- Sub-processor means a third party engaged by FlowSign to process Customer Personal Information.
- Applicable Privacy Laws means the Privacy Act 2020, and any other data-protection or privacy law that applies to a party's processing of Customer Personal Information.
2. Roles of the parties
For the purposes of the Privacy Act 2020, the Customer is the agency that collects and holds Customer Personal Information; FlowSign holds it on the Customer's behalf and under the Customer's instructions. Where the GDPR or UK GDPR applies, the Customer is the controller and FlowSign is the processor.
FlowSign will only process Customer Personal Information to provide the service and support under the Agreement, to meet its own legal obligations, and as otherwise instructed in writing by the Customer. The Customer's configuration of the service and use of its features constitutes such instructions.
3. Nature and purpose of processing
- Subject matter: provision of the FlowSign electronic-signature and document platform.
- Duration: for the term of the Agreement, plus any retention period agreed in it or required by law.
- Purpose: to enable the Customer to send, sign, manage and store documents, and to record the audit trail.
- Categories of Data Subject: the Customer's users; signers, recipients and other parties to documents the Customer sends.
- Categories of Personal Information: contact details (name, email, phone), account and authentication data, signature images, field values entered into documents, IP addresses and device information, and any personal information contained in the documents themselves.
4. Customer obligations
- The Customer will only submit personal information to FlowSign that it is lawfully entitled to submit, and will make sure any notice or consent required for the processing is in place.
- The Customer is responsible for its own compliance with Applicable Privacy Laws, including any obligations owed to Data Subjects it collects information from.
- The Customer will not use FlowSign to process special categories of data (for example health information, government identifiers, financial account numbers, or biometric identifiers) except where the service is intended for such use and appropriate safeguards are configured.
5. Confidentiality and staff
FlowSign will limit access to Customer Personal Information to personnel who need it to provide the service, will bind those personnel to confidentiality, and will train them on their obligations under this DPA.
6. Security
FlowSign will implement and maintain reasonable technical and organisational measures to protect Customer Personal Information against loss and unauthorised access, use, modification or disclosure. These measures are described in our Privacy Policy and include encryption in transit and at rest through our infrastructure providers, access controls with mandatory two-factor authentication for administrative access, application-layer tenant isolation on all customer-scoped queries, scoped signed URLs for object storage, and an audit log of security-relevant events.
7. Sub-processors
The Customer authorises FlowSign to engage the sub-processors listed on our Sub-processors page, and any additional sub-processors added under this section, to process Customer Personal Information.
FlowSign will impose written obligations on each sub-processor that are no less protective than those in this DPA, and remains responsible for its sub-processors' performance. When FlowSign engages a new sub-processor that will handle Customer Personal Information, it will update the sub-processors page and notify Customers by email at least 30 days in advance at the address the Customer has nominated for that purpose. Customers may object by email to legal@flowsign.app within that window; if the objection cannot be resolved, the Customer may terminate their subscription for convenience, and FlowSign will refund any prepaid fees for the terminated period on a pro-rata basis.
8. Overseas processing
Where FlowSign transfers Customer Personal Information outside New Zealand, it will do so only where an exception under Information Privacy Principle 12 applies - in most cases IPP 12(1)(f), on the basis that the recipient is bound by written contract to protect the information at a standard comparable to the Privacy Act 2020, or IPP 12(1)(c), where the recipient is subject to a privacy law with comparable safeguards. The IPP 12 basis for each current sub-processor is disclosed on our Sub-processors page. Where the GDPR or UK GDPR applies to a transfer, the parties will enter into the applicable standard contractual clauses (or equivalent transfer mechanism) by reference; a request for a signed copy can be sent to legal@flowsign.app.
9. Assistance with Data Subject rights
FlowSign provides functionality in the product that allows Customers to access, export, correct and delete Customer Personal Information they administer. Where the Customer requires additional assistance to respond to a Data Subject request or a request under IPP 6 or IPP 7 that it cannot fulfil through the product, FlowSign will provide reasonable assistance at no charge, unless the requests are manifestly excessive.
If FlowSign receives a request from a Data Subject or the Office of the Privacy Commissioner that relates to Customer Personal Information, FlowSign will pass the request to the Customer without undue delay and will not itself respond except to confirm receipt or as legally required.
10. Privacy breach notification
If FlowSign becomes aware of a Privacy Breach affecting Customer Personal Information, it will notify the Customer without undue delay (and in any event within 72 hours of becoming aware, or sooner if reasonably necessary to allow the Customer to meet its own obligations under Part 6 of the Privacy Act 2020) and will provide the information the Customer reasonably needs to meet those obligations, including a description of the breach, the categories and approximate number of Data Subjects affected, likely consequences, and the measures FlowSign has taken or proposes to take.
11. Deletion and return
At the end of the Agreement, FlowSign will make Customer Personal Information available for export for a reasonable period, and will then delete it in accordance with the retention schedule described in the Privacy Policy, except where retention is required by law.
12. Audits and compliance
FlowSign will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA. Where the Customer's regulator, or Applicable Privacy Laws, require an on-site audit, the parties will agree the scope, timing and confidentiality arrangements in advance. Audits under this clause may take place no more than once in any 12-month period, on at least 30 days' written notice, and are subject to reasonable confidentiality obligations. FlowSign may charge its reasonable costs of accommodating an audit that goes beyond providing information.
13. General
- If there is any conflict between this DPA and the Agreement, this DPA prevails as to the processing of personal information.
- Except as amended by this DPA, all terms of the Agreement remain in force.
- This DPA is governed by the same law as the Agreement, or in the absence of a governing-law clause, by New Zealand law.
- Questions or requests under this DPA should be sent to legal@flowsign.app.
14. Contact
Studio Phoenix Limited trading as FlowSign · New Zealand · legal@flowsign.app
NZBN 9429047886629 · NZ Company 7857036 · Companies Register