Legal
Data processing agreement
Last updated 16 September 2026
This Data Processing Agreement ("DPA") forms part of the PlugFlow terms of service between the Customer ("you", the controller / Data Fiduciary) and Sedulous Web ("PlugFlow", the processor / Data Processor). It applies whenever PlugFlow processes personal data on your behalf that is subject to the GDPR, the UK GDPR or India's Digital Personal Data Protection Act, 2023. It is accepted automatically when you create a workspace; a countersigned copy is available on request.
1. Definitions
"Personal Data", "processing", "controller", "processor", "data subject" and "supervisory authority" have the meanings given in the GDPR; "Data Fiduciary", "Data Processor", "Data Principal" and "Data Protection Board" have the meanings given in the DPDP Act. "Customer Data" means Personal Data that you or your Authors submit to PlugFlow.
2. Scope and details of processing
| Subject matter | Collection, moderation, storage and display of customer testimonials and related workspace administration. |
|---|---|
| Duration | The term of the Customer's account plus the deletion period in section 9. |
| Nature and purpose | Hosting collection forms; storing submissions; sending review-request emails on your instruction; rendering walls on your websites; exporting data; providing API access. |
| Categories of data subjects | Your team members; Authors who submit testimonials; your customers who receive review requests. |
| Categories of Personal Data | Name, email address, job title, company, profile and avatar URLs, testimonial text and rating, answers to custom questions, order references, consent text, consent timestamp and IP address, browser user-agent. |
| Special categories | None intended. You must not collect special-category data through PlugFlow. |
3. Your obligations
- You warrant that you have a lawful basis for the processing you instruct, including valid consent from Authors to publish their testimonials, and that your instructions comply with applicable law.
- You are responsible for the accuracy of Customer Data, for configuring consent text, and for responding to Data Principal / data subject requests relating to your workspace.
- You will provide any privacy notice required to Authors and customers receiving review requests.
4. Our obligations
- Process Customer Data only on your documented instructions (given through the dashboard, API, plugins or in writing), unless required by law, in which case we will inform you where permitted.
- Ensure staff with access are bound by confidentiality.
- Implement the technical and organisational measures in section 7.
- Assist you, taking into account the nature of processing, in fulfilling data subject requests and your obligations regarding security, breach notification and impact assessments.
- Delete or return Customer Data at the end of the service as set out in section 9.
- Make available the information necessary to demonstrate compliance and allow audits as set out in section 8.
5. Sub-processors
You authorise the sub-processors listed below. We will give at least 14 days' notice by email before adding or replacing a sub-processor; you may object on reasonable data protection grounds, in which case either party may terminate the affected service. We remain liable for our sub-processors' performance.
| Sub-processor | Purpose | Location |
|---|---|---|
| OVHcloud | Application servers, PostgreSQL database, background jobs and backups | Canada (Montreal) |
| Cloudflare | DNS, TLS, content delivery and DDoS protection | Global |
| Razorpay | Subscription billing and payment processing, once paid plans are available | India |
| Transactional email provider (SMTP) | Verification, password reset, review-request and notification emails | United States / EU |
| Sentry | Error monitoring (technical diagnostics; no message content) | United States / EU |
| LogRocket | Session diagnostics for the dashboard (signed-in users only; inputs masked) | United States |
6. International transfers
Customer Data is stored in data centres operated by our hosting sub-processor OVHcloud in Montreal, Canada, and passes through Cloudflare's global network for DNS, TLS and content delivery. For data subject to the GDPR or UK GDPR we rely on the EU Standard Contractual Clauses (Module 3, processor to processor, and Module 2 where we act as your processor) and the UK International Data Transfer Addendum, supplemented by encryption in transit and at rest. For Indian Data Principals, transfers are made only to countries not restricted by the Central Government under section 16 of the DPDP Act.
7. Security measures
- Encryption in transit (TLS 1.2+) and at rest (AES-256 on databases, backups and object storage).
- Tenant isolation: every record carries a workspace identifier and all queries are scoped to the requesting workspace.
- Role-based access in the dashboard; short-lived access tokens with revocable refresh tokens; API keys with scopes.
- Argon2 password hashing; encrypted storage of third-party access tokens; secrets managed outside source control.
- Audit logging of administrative actions; revision history for every testimonial edit.
- Daily encrypted backups with a 35-day retention; tested restore procedure.
- Vulnerability monitoring of dependencies; production access restricted to named staff with MFA.
8. Audits
On written request no more than once per year (or following a confirmed breach) we will provide our current security documentation and answers to a reasonable security questionnaire. Where this is insufficient to demonstrate compliance, you may conduct an audit through an independent auditor bound by confidentiality, at your cost, on 30 days' notice and during business hours.
9. Breach notification, deletion and return
- We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting Customer Data, and provide the information reasonably needed for your own notifications.
- You can export all Customer Data at any time from Settings → Danger zone (JSON) or via the API.
- On deletion of a workspace or account, Customer Data is deleted from live systems within 30 days and from backups within a further 35 days, unless retention is required by law.
10. Liability and precedence
Liability under this DPA is subject to the limitations in the terms of service. If there is a conflict between this DPA and the terms, this DPA prevails for matters of data protection.
11. Contact
Data protection enquiries, requests for a signed copy of this DPA or for the Standard Contractual Clauses: [email protected].