1. Roles and scope
For personal data that Flowmynt processes on the Client's behalf ("Client Personal Data"), the Client is the controller (or data fiduciary) and Flowmynt is the processor (or data processor). Where the Client is itself a processor for its own customers, Flowmynt is a sub-processor and the Client warrants that its controller has authorised the engagement.
This DPA does not apply to personal data that Flowmynt processes for its own purposes, which is described in the Privacy Policy.
2. Details of processing
- Subject matter: configuration, integration, implementation, maintenance and support of the Software and connected customer journeys, including WhatsApp and other channels.
- Duration: the term of the relevant Order plus any wind-down period in Section 10.
- Nature and purpose: connecting the Client's systems, Providers and messaging channels; presenting customer journeys; passing payment requests, statuses and receipts between the Client's systems, Providers and customers; diagnosing and fixing issues.
- Categories of data subjects: the Client's customers and prospective customers, beneficiaries of payments, the Client's staff and contractors.
- Categories of personal data: identifiers (name, phone number, WhatsApp number, email, customer or account reference), transaction data (amounts, references, statuses, payee details, invoice and instalment details), communication content within connected journeys, technical data (device, IP, logs). Card numbers and authentication secrets are not processed by Flowmynt; they are entered on Provider-hosted pages.
- Special categories of data: not intended. The Client must not submit special-category or criminal-offence data unless agreed in writing with additional safeguards.
3. Client obligations
The Client will: give documented, lawful instructions; ensure it has a lawful basis, required consents and notices for the processing and for the transfer of Client Personal Data to Flowmynt and to Providers; comply with its own obligations as controller; and not instruct Flowmynt to process data in a way that would breach applicable law.
4. Flowmynt obligations
Flowmynt will:
- Process Client Personal Data only on the Client's documented instructions, including the Order, this DPA and reasonable written instructions, unless required by law, in which case Flowmynt will inform the Client before processing unless the law prohibits it.
- Inform the Client if, in its opinion, an instruction infringes data protection law.
- Ensure that people authorised to process Client Personal Data are bound by confidentiality and receive appropriate training.
- Implement the technical and organisational measures in Annex 2 and maintain a level of security appropriate to the risk.
- Assist the Client, taking into account the nature of the processing, in responding to data subject requests and in meeting its obligations on security, breach notification, data protection impact assessments and prior consultation.
- Notify the Client without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Client Personal Data, with the information the Client needs to meet its own notification duties, and cooperate in the investigation and remediation.
- Keep records of processing activities carried out on behalf of the Client, where required by law.
- Not sell Client Personal Data or use it for its own purposes, including product analytics or training of models, without the Client's written consent.
5. Sub-processors
The Client authorises Flowmynt to engage the categories of sub-processor listed in Annex 3 and to engage Exekova to support delivery of the Services. Flowmynt will impose data protection obligations on each sub-processor that are no less protective than this DPA and remains liable for their performance.
Flowmynt will give the Client at least 30 days' written notice before adding or replacing a sub-processor. The Client may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, the Client may terminate the affected part of the Order and receive a pro-rated refund of prepaid Fees for the terminated Services.
Providers appointed by the Client, WhatsApp and Meta platforms and the Client's own hosting are not Flowmynt sub-processors; they are independent controllers or processors engaged by the Client.
6. International transfers
Flowmynt processes Client Personal Data in India and in the countries where its sub-processors operate. For transfers of personal data subject to the GDPR or UK GDPR from the EEA or the UK to a country without an adequacy decision, the parties enter into the European Commission Standard Contractual Clauses (Module Two or Module Three as applicable) and, for UK transfers, the UK International Data Transfer Addendum, which are incorporated by reference into this DPA with the Client as data exporter and Flowmynt as data importer. Annex 1 to this DPA serves as the Annex to those Clauses. Flowmynt will carry out transfer risk assessments and apply supplementary measures where needed.
7. Audits
Flowmynt will make available the information reasonably necessary to demonstrate compliance with this DPA, including summaries of its security measures and any third-party assessments it holds, and will allow audits, including inspections, conducted by the Client or an independent auditor mandated by the Client, no more than once in any 12-month period unless required by a supervisory authority or following a breach, on 30 days' notice, during business hours, under confidentiality and at the Client's cost. Audits must not compromise the security of other clients.
8. Data subject requests
Flowmynt will promptly forward to the Client any request received directly from a data subject relating to Client Personal Data and will not respond except to redirect the data subject to the Client, unless the Client instructs otherwise or the law requires.
9. Government and third-party requests
If Flowmynt receives a legally binding request for Client Personal Data from a public authority, it will notify the Client where legally permitted, challenge requests it reasonably believes to be unlawful, and disclose only the minimum data required.
10. Return and deletion
At the end of the Services, at the Client's choice, Flowmynt will return Client Personal Data in a commonly used format and delete existing copies within 30 days, unless applicable law requires storage, in which case Flowmynt will continue to protect the data and process it only for that purpose. Credentials and access granted to Flowmynt will be revoked or returned. Flowmynt will confirm deletion in writing on request.
11. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except that nothing limits a party's liability to data subjects or supervisory authorities under applicable data protection law.
12. Precedence and changes
If this DPA conflicts with the Terms of Service or an Order on a data protection matter, this DPA prevails. The Standard Contractual Clauses prevail over this DPA where they apply. Flowmynt may update this DPA to reflect changes in law or in the Services, with notice to the Client, provided that the changes do not reduce the protection of Client Personal Data.
Annex 1: Description of processing
Data exporter: the Client, as identified in the Order, acting as controller (or processor on behalf of its own controllers). Data importer: Flowmynt, contact sanjay@flowmynt.com, acting as processor. Data subjects, categories of data, sensitive data, frequency, nature, purpose and retention: as set out in Sections 2 and 10 of this DPA. Competent supervisory authority: the authority of the EEA member state or the UK in which the data exporter is established or represented.
Annex 2: Technical and organisational measures
- Governance: a named security owner (the founder), documented policies, periodic risk assessments, and an information security programme designed to meet ISO/IEC 27001 controls and SOC 2 trust services criteria.
- Access control: least-privilege, role-based access; multi-factor authentication on all business, cloud and code accounts; individual credentials; prompt revocation on role change or exit; secrets stored in a secrets manager, never in code or chat.
- Encryption: TLS 1.2 or higher for data in transit; encryption at rest for managed storage and devices; keys managed by the platform provider or a key management service.
- Payment data: card numbers, CVVs and authentication codes are never collected or stored by the Software; customers authorise on Provider-hosted pages, keeping the Software outside PCI DSS cardholder data scope, and Provider strong customer authentication is used where required (PSD2).
- Data minimisation and retention: only the fields required for the agreed journey are processed; logs and diagnostic data are pseudonymised where practical and retained for defined periods.
- Secure development: version control, code review, dependency and vulnerability management, separation of test and production, test data that is synthetic or masked.
- Operations: monitoring, logging of administrative access, backups with tested restoration, change management and patching within defined timeframes.
- Incident response: documented procedure, 48-hour notification to the Client, post-incident review and corrective actions.
- People: confidentiality agreements, security awareness for everyone with access, background checks where permitted by law.
- Vendors: due diligence, written data-processing terms and periodic review of sub-processors.
Annex 3: Sub-processor categories
Flowmynt currently uses sub-processors in these categories: cloud hosting and content delivery; email, calendar and document collaboration; source-code hosting and continuous integration; monitoring and error reporting; and Exekova for development and delivery support. The current named list, with locations, is available on request from sanjay@flowmynt.com and will be provided with each Order.
Data Processing Addendum of Flowmynt. Effective 22 September 2026.