DPA overview
Status: public overview, not a signed agreement. A Data Processing Agreement agreed in writing with the customer takes priority over this overview.
1. Purpose
When an organisation uses Fleksi to process personal data for its own purposes, the organisation normally acts as controller and Fleksi acts as processor.
This page explains the current baseline of personal-data processing. It does not replace a Data Processing Agreement agreed in writing with the customer, which addresses Article 28 of the GDPR and takes priority.
2. Processing description
The processing is:
| Subject | Provision, operation, security, support and maintenance of the Fleksi SaaS Service |
|---|---|
| Duration | The service term and the applicable return and deletion period |
| Nature | Collection, recording, organisation, storage, retrieval, consultation, transmission, backup, restriction, export and deletion |
| Purpose | Providing and securing the Service and following the customer's documented instructions |
| Data subjects | Customer personnel, contractors, applicants, customer and supplier contacts, end customers, site contacts and other persons whose data the customer lawfully submits |
| Data | Identity, contact, professional, account, access, project, scheduling, communication, document and other customer-selected fields |
| Sensitive data | Not intended unless a specific use and suitable safeguards are expressly agreed |
An agreement with the customer narrows this description to the data and functions actually used.
3. Instructions and responsibility
Fleksi will process Customer Personal Data only on the customer's documented instructions, including the agreement, normal use of the Service, configuration choices and support requests.
If law requires other processing, Fleksi will inform the customer in advance unless law prohibits the notice. Fleksi will inform the customer if it believes an instruction infringes applicable data-protection law.
The customer is responsible for its instructions, lawful basis, notices to data subjects and the legality and accuracy of Customer Personal Data.
4. Confidentiality and security
People authorised to process Customer Personal Data are bound by confidentiality and receive access only as needed.
Fleksi maintains security measures appropriate to the risks, such as:
- access control and least privilege;
- authentication and privileged-access protection;
- secure transmission and appropriate encryption;
- tenant and environment separation;
- logging, monitoring and vulnerability management;
- backup, restoration and resilience;
- secure development, change and patch management;
- personnel confidentiality and security awareness;
- incident response and documentation; and
- secure deletion and media handling.
Fleksi will not claim a certification that has not been independently verified.
5. Subprocessors
The customer will give general written authorisation for the subprocessors needed to provide the Service. Fleksi will:
- maintain a list identifying the subprocessor, service and relevant country or processing region;
- give advance notice of a new or replacement subprocessor where practicable;
- allow an objection on reasonable data-protection grounds;
- impose materially equivalent data-protection obligations; and
- remain responsible as required by the GDPR and DPA.
If a reasonable objection cannot be resolved, the affected feature or part of the Service can be discontinued.
6. International transfers
The order and subprocessor list will identify the agreed primary hosting region and relevant support or supplier locations.
Customer Personal Data will not be transferred outside the European Economic Area except under the customer's documented instructions and a lawful transfer mechanism where required. This may include an adequacy decision or the European Commission's standard contractual clauses with supplementary safeguards.
7. Assistance
Taking account of the processing and information available, Fleksi will provide reasonable assistance with:
- requests to exercise data-subject rights;
- security and personal-data-breach obligations;
- data-protection impact assessments and prior consultation; and
- information reasonably needed to demonstrate compliance.
Fleksi will not answer a data subject on the customer's behalf unless instructed or legally required.
8. Personal data breaches
Fleksi notifies the customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Available information needed for the customer's obligations is provided, and further information may follow in phases.
Fleksi will take reasonable steps to contain, investigate, mitigate and document the incident. Notice is not an admission of fault.
The GDPR's 72-hour period concerns a controller's required notification to a supervisory authority. It is not a waiting period for a processor to notify its customer.
9. Return and deletion
At the end of the Service, the customer may choose return or deletion of Customer Personal Data except where law requires retention. The baseline is a 30-day exit period followed by deletion or anonymisation from active systems normally within 90 days. Protected backup copies are removed through the normal backup cycle.
Retained data remains protected and isolated from ordinary use and is processed only for the legally required purpose.
10. Information and audits
Fleksi makes available information reasonably needed to demonstrate compliance. The normal sequence is:
- current security and compliance documentation;
- a reasonable questionnaire;
- independent reports or certifications when available; and
- an audit where the earlier material is insufficient or an incident or authority request reasonably justifies it.
Audits are subject to reasonable notice, confidentiality, security, scope and frequency controls and must not compromise another customer's data.
11. Priority
A Data Processing Agreement agreed in writing with the customer takes priority over this overview. Material reductions in agreed protection are not made during a fixed subscription term without a lawful basis and the agreed contractual remedy.
Questions about data processing can be submitted through the contact form on Fleksi.io.