Legal

Data processing agreement

Last updated 16 September 2026

This Data Processing Agreement ("DPA") forms part of the PlugFlow terms of service between the Customer ("you", the controller / Data Fiduciary) and Sedulous Web ("PlugFlow", the processor / Data Processor). It applies whenever PlugFlow processes personal data on your behalf that is subject to the GDPR, the UK GDPR or India's Digital Personal Data Protection Act, 2023. It is accepted automatically when you create a workspace; a countersigned copy is available on request.

1. Definitions

"Personal Data", "processing", "controller", "processor", "data subject" and "supervisory authority" have the meanings given in the GDPR; "Data Fiduciary", "Data Processor", "Data Principal" and "Data Protection Board" have the meanings given in the DPDP Act. "Customer Data" means Personal Data that you or your Authors submit to PlugFlow.

2. Scope and details of processing

Subject matterCollection, moderation, storage and display of customer testimonials and related workspace administration.
DurationThe term of the Customer's account plus the deletion period in section 9.
Nature and purposeHosting collection forms; storing submissions; sending review-request emails on your instruction; rendering walls on your websites; exporting data; providing API access.
Categories of data subjectsYour team members; Authors who submit testimonials; your customers who receive review requests.
Categories of Personal DataName, email address, job title, company, profile and avatar URLs, testimonial text and rating, answers to custom questions, order references, consent text, consent timestamp and IP address, browser user-agent.
Special categoriesNone intended. You must not collect special-category data through PlugFlow.

3. Your obligations

  • You warrant that you have a lawful basis for the processing you instruct, including valid consent from Authors to publish their testimonials, and that your instructions comply with applicable law.
  • You are responsible for the accuracy of Customer Data, for configuring consent text, and for responding to Data Principal / data subject requests relating to your workspace.
  • You will provide any privacy notice required to Authors and customers receiving review requests.

4. Our obligations

  • Process Customer Data only on your documented instructions (given through the dashboard, API, plugins or in writing), unless required by law, in which case we will inform you where permitted.
  • Ensure staff with access are bound by confidentiality.
  • Implement the technical and organisational measures in section 7.
  • Assist you, taking into account the nature of processing, in fulfilling data subject requests and your obligations regarding security, breach notification and impact assessments.
  • Delete or return Customer Data at the end of the service as set out in section 9.
  • Make available the information necessary to demonstrate compliance and allow audits as set out in section 8.

5. Sub-processors

You authorise the sub-processors listed below. We will give at least 14 days' notice by email before adding or replacing a sub-processor; you may object on reasonable data protection grounds, in which case either party may terminate the affected service. We remain liable for our sub-processors' performance.

Sub-processorPurposeLocation
OVHcloudApplication servers, PostgreSQL database, background jobs and backupsCanada (Montreal)
CloudflareDNS, TLS, content delivery and DDoS protectionGlobal
RazorpaySubscription billing and payment processing, once paid plans are availableIndia
Transactional email provider (SMTP)Verification, password reset, review-request and notification emailsUnited States / EU
SentryError monitoring (technical diagnostics; no message content)United States / EU
LogRocketSession diagnostics for the dashboard (signed-in users only; inputs masked)United States

6. International transfers

Customer Data is stored in data centres operated by our hosting sub-processor OVHcloud in Montreal, Canada, and passes through Cloudflare's global network for DNS, TLS and content delivery. For data subject to the GDPR or UK GDPR we rely on the EU Standard Contractual Clauses (Module 3, processor to processor, and Module 2 where we act as your processor) and the UK International Data Transfer Addendum, supplemented by encryption in transit and at rest. For Indian Data Principals, transfers are made only to countries not restricted by the Central Government under section 16 of the DPDP Act.

7. Security measures

  • Encryption in transit (TLS 1.2+) and at rest (AES-256 on databases, backups and object storage).
  • Tenant isolation: every record carries a workspace identifier and all queries are scoped to the requesting workspace.
  • Role-based access in the dashboard; short-lived access tokens with revocable refresh tokens; API keys with scopes.
  • Argon2 password hashing; encrypted storage of third-party access tokens; secrets managed outside source control.
  • Audit logging of administrative actions; revision history for every testimonial edit.
  • Daily encrypted backups with a 35-day retention; tested restore procedure.
  • Vulnerability monitoring of dependencies; production access restricted to named staff with MFA.

8. Audits

On written request no more than once per year (or following a confirmed breach) we will provide our current security documentation and answers to a reasonable security questionnaire. Where this is insufficient to demonstrate compliance, you may conduct an audit through an independent auditor bound by confidentiality, at your cost, on 30 days' notice and during business hours.

9. Breach notification, deletion and return

  • We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting Customer Data, and provide the information reasonably needed for your own notifications.
  • You can export all Customer Data at any time from Settings → Danger zone (JSON) or via the API.
  • On deletion of a workspace or account, Customer Data is deleted from live systems within 30 days and from backups within a further 35 days, unless retention is required by law.

10. Liability and precedence

Liability under this DPA is subject to the limitations in the terms of service. If there is a conflict between this DPA and the terms, this DPA prevails for matters of data protection.

11. Contact

Data protection enquiries, requests for a signed copy of this DPA or for the Standard Contractual Clauses: [email protected].