Last updated: October 10, 2025
This Data Processing Agreement ("DPA") forms part of our service agreement and governs the processing of personal data in accordance with GDPR and other applicable data protection laws.
"Controller" means the natural or legal person who determines the purposes and means of processing personal data.
"Processor" means DynoFlows, acting on behalf of the Controller to process personal data.
"Personal Data" has the meaning set out in applicable Data Protection Laws.
"Data Protection Laws" means all applicable data protection and privacy laws, including GDPR, CCPA, and other relevant regulations.
"Data Subject" means an identified or identifiable natural person.
This DPA applies when DynoFlows processes personal data on behalf of the Customer in the provision of cybersecurity services, including:
The Customer acts as Data Controller and:
DynoFlows acts as Data Processor and:
Subject Matter:
Cybersecurity services and threat monitoring
Duration:
For the term of the service agreement
Nature and Purpose:
Email security, DNS protection, threat analysis
Categories of Data:
Email metadata, DNS records, IP addresses, log data
Data Subjects:
Employees, customers, email recipients
Processing Activities:
Collection, analysis, storage, deletion
DynoFlows may engage sub-processors to assist in providing services. Current sub-processors include:
| Sub-processor | Service | Location |
|---|---|---|
| Cloudflare | CDN, security, and performance services | United States, EU |
| Railway | Backend hosting and infrastructure | United States |
| Google Cloud Platform | Analytics and monitoring services | United States, EU |
We will notify customers of any changes to sub-processors with at least 30 days' notice.
When personal data is transferred outside the EEA, we ensure adequate protection through:
DynoFlows will assist the Customer in fulfilling data subject rights requests, including:
Response time: Within 30 days of receiving a valid request from the Customer.
In the event of a personal data breach, DynoFlows will:
DynoFlows will:
Personal data will be processed only for the duration necessary to fulfill the purposes outlined in this DPA:
Upon termination, all personal data will be deleted or returned within 90 days unless legal retention requirements apply.
Each party's liability under this DPA shall be subject to the limitation of liability provisions in the main service agreement. DynoFlows will indemnify the Customer against fines imposed by supervisory authorities due to DynoFlows' non-compliance with this DPA, subject to the Customer's cooperation in defense of such claims.
Data Protection Officer: dpo@dynoflows.com
Legal Department: legal@dynoflows.com
Security Team: security@dynoflows.com
Business Address:
DynoFlows Data Protection Team
[Business Address - To be updated]