Data Processing Agreement

This DPA governs Floov’s processing of personal data on behalf of customers using forms, responses, files, and connected delivery features.

Last updated:

1. Parties, Scope, and Legal Effect

This Data Processing Agreement (“DPA”) is between the customer that has accepted the Floov Terms or a separately signed order (“Customer”) and FLOOV S.R.L., CUI 54655476, Trade Register J2026030772003, Romania (“Floov”).

It is incorporated into the Terms of Service and applies whenever Floov processes personal data on Customer’s behalf in providing the service (“Controller Data”). Customer is the controller and Floov is the processor, except where Customer is itself a processor, in which case Customer is the processor and Floov is its sub-processor. Each party will comply with data-protection law applicable to its role, including Regulation (EU) 2016/679 (“GDPR”).

This electronic DPA is a binding written agreement under Article 28 GDPR. It starts when Customer accepts the Terms or first instructs Floov to process Controller Data and ends after Floov has completed the return or deletion obligations below. A signed agreement or order prevails over this DPA only to the extent it expressly identifies and replaces a provision. This DPA prevails over conflicting general Terms for Controller Data.

2. Processing Details

Annex 1 describes the subject matter, duration, nature, purposes, personal-data types, and data-subject categories required by Article 28(3). Customer controls form fields, collection notices, workflows, retention, members, recipients, and integrations. Customer’s configuration and ordinary documented use of Floov are instructions to process Controller Data.

3. Documented Instructions and Compliance

Floov will:

  • process Controller Data only on Customer’s documented instructions, including transfers, unless EU or Member State law requires other processing;
  • if legally required to process without an instruction, inform Customer before doing so unless that law prohibits notice for an important public-interest reason;
  • immediately inform Customer if, in our opinion, an instruction infringes the GDPR or other applicable EU or Member State data-protection law, and may pause the affected processing while the parties resolve it;
  • ensure persons authorised to process Controller Data have committed to confidentiality or are under an appropriate statutory duty and receive access only as needed for their role; and
  • not sell Controller Data, use it for cross-context behavioural advertising, or combine it with data obtained for another customer except as instructed or permitted by law.

Customer warrants that its instructions are lawful; its notices and legal bases are sufficient; it has authority over Controller Data; and it will not instruct Floov to process data in violation of law. Customer must minimise fields and access, configure appropriate retention, protect account credentials, and obtain consent for sensitive data, children’s data, marketing, cookies, or tracking where required. Customer must not place real respondent or customer records, secrets, credentials, confidential material, or sensitive personal data in an AI generation or edit instruction unless that processing is strictly necessary, lawful, and covered by appropriate safeguards.

4. Security and Personal-Data Breaches

Taking account of the state of the art, implementation cost, nature, scope, context, and purposes, and risks to people, Floov implements the technical and organisational measures in Annex 3 to provide a level of security appropriate to risk, in accordance with Article 32 GDPR. Customer is responsible for assessing whether those measures and its configuration meet its specific risks.

After becoming aware of a personal-data breach affecting Controller Data, Floov will notify Customer without undue delay at the account owner’s email. As information becomes available, notice will describe the nature of the incident, affected data and approximate scale where known, likely consequences, measures taken or proposed, and a contact point. Information may be supplied in phases. Floov will take reasonable steps to contain, investigate, mitigate, remediate, and document the incident and will reasonably assist Customer with Articles 33 and 34 obligations.

Floov’s notice is not an admission of fault or liability. Customer remains responsible for determining whether and when to notify an authority or data subject. Customer must notify Floov promptly of compromised credentials, unlawful access, or a breach in Customer-controlled systems that affects Floov.

5. Data-Subject Rights, DPIAs, and Regulators

Considering the nature of processing and information available, Floov will provide reasonable assistance so Customer can:

  • respond to requests under GDPR Chapter III, including access, correction, deletion, restriction, objection, and portability;
  • meet security, breach-notification, and data-subject communication duties under Articles 32–34;
  • conduct a data-protection impact assessment under Article 35; and
  • consult a supervisory authority under Article 36.

Floov provides self-service response export, deletion, role, and account controls. If a data subject contacts Floov about Controller Data, we will not independently respond beyond confirming receipt or identifying Customer unless Customer instructs us or law requires it. We will forward the request where we can identify the relevant Customer. Additional bespoke assistance may be charged at reasonable documented cost when permitted, unless it is required because Floov breached this DPA.

6. Sub-processors

Customer gives general written authorisation for Floov to engage the sub-processors in Annex 2. Floov will bind each sub-processor by written data-protection obligations that provide at least the protection required for the processing entrusted to it. Floov remains responsible to Customer for a sub-processor’s performance of those obligations as required by Article 28(4).

Before a material new sub-processor begins processing Controller Data, Floov will update Annex 2 and provide advance notice to the account owner where required. Customer may object on reasonable, data-protection grounds by emailing [email protected] within 15 days after notice. The parties will try in good faith to use a reasonable alternative. If none is available, either party may terminate only the affected feature or service without penalty for the unused prepaid affected period. An objection does not relieve Customer of charges accrued before termination.

A webhook or third-party integration selected and independently controlled by Customer, including Make, Zapier, Mailchimp, or HubSpot, is a recipient engaged on Customer’s instruction, not a Floov-selected sub-processor. Customer is responsible for contracting with and assessing that recipient.

7. International Transfers

Floov will not transfer Controller Data to a country outside the EEA without Customer’s instruction and a lawful transfer mechanism. This may include an adequacy decision, the EU–US Data Privacy Framework for an eligible certified recipient, or the European Commission’s 2021 Standard Contractual Clauses (“SCCs”), together with supplementary measures where needed.

If Customer is established in the EEA and Floov later processes Controller Data as an importer in a third country without an adequacy decision, Module Two of the SCCs (controller to processor), or Module Three where Customer is a processor, is incorporated by reference. The docking clause applies; optional Clause 11 does not; general authorisation and the 15-day objection period above apply under Clause 9; Romania is the governing Member State under Clause 17; Romanian courts are selected under Clause 18; and Annexes 1–3 of this DPA complete the corresponding SCC annexes. The SCCs prevail over a conflict.

Floov will reasonably assist with transfer-impact information about its processing and providers. Customer is responsible for transfer safeguards for destinations it configures.

8. Return and Deletion

During the service, Customer can export form responses in supported formats and download authorised files. Before deleting an account or content, Customer should export anything it wants to retain.

On termination or Customer’s documented request, Floov will, at Customer’s choice where technically available, return or delete Controller Data and delete existing copies, unless applicable law requires retention. Self-service deletion removes active database access immediately. Associated storage objects enter a durable deletion queue and are retried until the storage provider confirms deletion. Backups and security logs may remain isolated until their ordinary expiry and will not be restored for ordinary service use. Legally retained data remains protected and is processed only for that legal purpose.

9. Information, Compliance, and Audits

Floov will make available information reasonably necessary to demonstrate compliance with Article 28 and this DPA, including this DPA, security descriptions, sub-processor information, and appropriate independent reports or summaries when available.

If that information is insufficient, Customer or an independent, non-competing auditor bound by confidentiality may audit the relevant controls no more than once in a 12-month period, with at least 30 days’ written notice, during normal business hours, and without accessing another customer’s data or compromising security. The frequency and notice limits do not apply after a substantiated incident or where a supervisory authority requires otherwise.

Audits should use remote document review first. Customer bears its audit costs and reimburses Floov’s reasonable costs for unusually burdensome assistance, unless the audit identifies a material Floov breach. Audit findings are Floov confidential information. Floov will cooperate with competent supervisory authorities as required.

10. Duration, Liability, Changes, and Contact

This DPA continues while Floov processes Controller Data. Liability is governed by the Terms or a separately signed agreement, subject to liability that data-protection law does not permit the parties to exclude or limit. No limitation changes either party’s direct responsibility to a data subject or supervisory authority under applicable law.

We may update this DPA for legal or technical changes. We will not materially reduce the protection of Controller Data during a current paid term without notice, unless required by law or needed for urgent security. Romanian law governs this DPA, without prejudice to the GDPR, SCCs, or mandatory data-protection law.

DPA, sub-processor, and privacy requests: [email protected]. Security reports: [email protected].

Annex 1: Processing Description

Description of processing under the Floov DPA
Subject matter Providing the Floov form-building, AI-assisted form creation and bounded field editing, hosting, response collection, collaboration, file, analytics, report, notification, support, and customer-configured integration service.
Duration The agreement term plus the limited deletion, backup, incident, and legal-retention period described above.
Nature and purpose Collection, recording, organisation, storage, validation, retrieval, display, analysis, generation of a proposed form blueprint or bounded field changes or additions, export, transmission, delivery, restriction, and deletion to provide features configured by Customer.
Data subjects Respondents, prospective respondents, Customer personnel and workspace members, Customer contacts, integration recipients, and other people whose data Customer submits.
Personal data Identity and contact data; form answers; free text; uploaded files; addresses; dates; preferences; ratings; employment or organisation data; AI generation or edit instructions, form preferences, bounded recent edit exchanges, bounded current-page editable values and optional selected-item identifiers, generated blueprints, and proposed field changes or additions where they contain personal data; technical, device, referral, campaign, and form-usage data; delivery and integration metadata; and any other field Customer configures.
Sensitive data Not required by Floov. Customer may configure fields that collect special-category or criminal-conviction data only where lawful and with appropriate safeguards. Customer must not collect authentication secrets or complete payment-card credentials through ordinary form fields and must not include sensitive data or credentials in an AI generation or edit instruction unless strictly necessary and lawful.
Frequency Continuous or intermittent, as Customer and respondents use the service.
Controller rights As stated in this DPA and the agreement, including configuration, access, export, correction, deletion, objection to new sub-processors, assistance, and audit rights.

Annex 2: Authorised Sub-processors

Floov authorised sub-processors
Sub-processor Service Controller Data involved
DigitalOcean Application and database infrastructure Controller Data processed in the Floov application and database
Amazon Web Services (S3) Object storage Response files, media, object keys, and metadata
Scaleway Transactional Email Email delivery Recipient addresses and notification or confirmation content configured by Customer
Reacher Email deliverability checks Email addresses selected for verification and verification results
Cloudflare Turnstile bot protection and edge security Network, browser, request, and challenge-verification signals
Google (Gemini API) AI-assisted form creation and bounded page-aware item editing Customer-provided generation or edit instruction, structured form preferences or bounded recent edit exchanges, bounded current-page editable values and optional selected-item identifier, Floov’s server instructions, and the generated blueprint or proposed item changes or additions, where these contain Controller Data

Annex 3: Technical and Organisational Measures

  • Access control: authenticated accounts, role-based workspace permissions, owner-gated response and file access, least-privilege operational access, and reauthentication for sensitive account changes.
  • Encryption and credentials: TLS/HTTPS in transit, one-way password hashing, private response-file objects, short-lived signed storage URLs, and secrets held outside source code through deployment configuration.
  • Application security: CSRF protection, HTTP-only and SameSite session cookies, input and upload validation, rate limits, bot protection, authorisation policies, immutable UUID storage keys, and atomic response persistence.
  • Availability and integrity: database transactions, queue retry and backoff, durable storage-deletion and hostname-cleanup outboxes, failure logging, and recovery procedures appropriate to the service.
  • Data minimisation and separation: tenant and workspace ownership controls, purpose-specific models, hidden credential fields, aggregate-only public reports, low-volume attribution suppression, event-property allowlists, and closed AI schemas that permit only form-generation inputs or bounded recent conversation and current-page editable context and exclude responses, files, credentials, and connected-account data.
  • Lifecycle controls: customer export and deletion tools, 90-day visitor campaign aggregate retention, no individual visitor-event records, expiring sessions and signed links, transactional deletion scheduling, provider deletion retries, encrypted AI form-creation content erased on cancellation, conversion, or expiry and otherwise no later than seven days, and encrypted field-edit content erased on a terminal outcome with unresolved proposals expiring within 24 hours and operational rows deleted after 30 days.
  • Testing and review: automated tests, dependency and framework security maintenance, code review and release validation, logging of security-relevant failures, and periodic review of measures and provider arrangements.
  • Personnel and incidents: confidentiality duties, need-to-know access, incident assessment and escalation, breach cooperation, and preservation of evidence where required.