Data Processing Addendum
Last updated: July 17, 2026
This addendum forms part of the Terms of Servicebetween FlowPay ("Processor") and the customer ("Controller") whenever FlowPay processes personal data on the customer's behalf.
1. Roles and scope
For payer data the customer enters (party names, email addresses, invoice amounts and shares, and payment status), the customer is the controller and FlowPay is the processor. For the customer's own account data, FlowPay is an independent controller as described in the Privacy Policy. Stripe processes payment data under its own agreements with the customer.
2. Purpose and instructions
FlowPay processes payer data only to provide the Service: creating Stripe-hosted payment links, emailing each party its link and receipt, emailing a fresh link for the remaining balance after a partial payment, tracking per-party payment status, and maintaining invoice records. FlowPay acts on the customer's documented instructions given through the Service, unless law requires otherwise, in which case FlowPay will inform the customer unless prohibited.
3. Confidentiality and security
Persons authorized to process the data are bound by confidentiality. FlowPay implements appropriate technical and organizational measures: encryption in transit and at rest, least-privilege access to production systems, Stripe-hosted card processing (no card data on FlowPay systems), and US-region hosting on AWS.
4. Subprocessors
Current subprocessors, which the customer authorizes:
- Stripe, Inc.: payment processing and merchant onboarding
- Amazon Web Services, Inc.: hosting and email delivery
- Okta, Inc. (Auth0): authentication
- PostHog, Inc.: marketing-site analytics (receives no payer data)
FlowPay will give at least 14 days' notice before adding a subprocessor that processes payer data; the customer may object on reasonable data-protection grounds, and if unresolved may terminate the affected service.
5. Assistance and breach notification
FlowPay will assist the customer, taking into account the nature of processing, with data-subject requests and with the customer's obligations regarding security and breach notification. FlowPay will notify the customer without undue delay after becoming aware of a personal-data breach affecting payer data, with the information reasonably available at the time.
6. Audit information
FlowPay will make available information reasonably necessary to demonstrate compliance with this addendum and will cooperate with reasonable written audit inquiries from the customer or its regulator.
7. Return and deletion
On termination, FlowPay will delete payer data within 90 days except where retention is required by law. On written request before deletion, FlowPay will provide a copy of the customer's invoice records in a commonly used format. Payment records in the customer's own Stripe account are unaffected and remain with the customer.
8. Transfers
Data is processed in the United States. Where data-protection law requires a transfer mechanism for data originating elsewhere, standard contractual clauses are available on request. Signed copies of this addendum are also available on request at hello@takeflowpay.com.