Skip to content
Data Processing Addendum

Data Processing Addendum

The terms under which we process personal data on your behalf. It meets GDPR Article 28, includes the EU Standard Contractual Clauses and the UK Addendum, and gives the commitments US state privacy laws require of a service provider.

Version 1.0 · Effective 6 October 2026

In plain words
  • You (the customer) decide what personal data goes into Falrow and why. We process it only to run Falrow for you, on your documented instructions.
  • We keep it confidential and secure, tell you about a breach within 48 hours, and help you answer requests from the people it concerns.
  • We use only the subprocessors listed, and tell you 30 days before adding one so you can object.
  • Data leaving the EU, UK or Switzerland is covered by the Standard Contractual Clauses, which are built into this document. You do not need to sign anything separately.
  • For California and other US states, we act as your service provider: no selling, no sharing, no use outside our contract with you.
  • Need a countersigned copy for your records? Email bas@falrow.com.

This summary helps you read the document. It is not part of it: where they differ, the sections below apply.

1.Scope and roles

This Data Processing Addendum ("DPA") forms part of the agreement between Spring Digital Commerce LLC ("Falrow") and the customer ("Customer") under the Terms of Service or another written agreement for the Falrow service (the "Agreement"). It applies whenever Falrow processes Customer Personal Data in providing the Service. It takes effect when the Customer accepts the Agreement, without a separate signature.

Roles. For Customer Personal Data, the Customer is the controller (or a processor acting for its own controllers, in which case Falrow is a sub-processor) and Falrow is the processor. For account, security and billing data that Falrow uses for its own purposes, described in the Privacy Policy, Falrow is an independent controller, and this DPA does not apply.

Definitions. "Customer Personal Data" means personal data in Customer Data. "Data Protection Laws" means all laws on the processing of personal data that apply to a party in its performance of the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), the California Consumer Privacy Act as amended ("CCPA") and other US state privacy laws. Terms such as controller, processor, processing, data subject, personal data breach and supervisory authority have the meanings given in the GDPR; "service provider", "sell" and "share" have the meanings given in the CCPA.

2.Processing on the Customer's instructions

Falrow will process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers, unless the law requires otherwise; in that case Falrow will tell the Customer before processing, unless the law prohibits it on important grounds of public interest. The Agreement, this DPA and the Customer's configuration and use of the Service (including the integrations, AI features and agents it enables) are the Customer's complete documented instructions. Additional instructions require written agreement.

Falrow will tell the Customer promptly if, in its opinion, an instruction infringes Data Protection Laws.

The Customer is responsible for the lawfulness of its instructions and of the Customer Personal Data, including having a legal basis and giving every notice and obtaining every consent needed, such as consent to recording meetings that are later imported into Falrow.

3.Details of the processing (Annex I)

ItemDescription
Data exporterThe Customer, as identified in the Agreement or its workspace settings. Contact: the workspace owner. Role: controller (or processor).
Data importerSpring Digital Commerce LLC, 2810 North Church Street, Wilmington, DE 19802, United States. Contact: bas@falrow.com. Role: processor (or sub-processor).
Data subjectsThe Customer's Users; the Customer's clients, prospects and their contacts; people named or quoted in tickets, comments, documents, meeting notes and Slack messages; meeting participants; any other individual whose data the Customer submits.
Categories of personal dataIdentification and contact data (name, email address, Slack user ID, avatar); professional data (company, role, capacity); content data (tickets, comments, documents, client records, meeting notes, transcripts and summaries, Slack message text); technical data (workspace activity log, session and token metadata, hashed IP addresses).
Special categoriesNone intended. The Customer agrees not to submit them except as agreed in writing. Restrictions and safeguards: the measures in Annex II.
FrequencyContinuous, for the term of the Agreement.
Nature of processingHosting, storage, organisation, retrieval, display, transmission to and from integrations the Customer enables, AI processing when AI features are enabled, backup, deletion.
PurposeProviding, securing and supporting the Service for the Customer under the Agreement.
Duration and retentionThe term of the Agreement plus the export period after termination (30 days, extendable once), then deletion from production within 30 days and from backups on their rolling cycle of no more than 35 days.
Sub-processor transfersAs listed in Annex III, for the same subject matter, nature and duration, limited to what each needs for its purpose.

4.Confidentiality of personnel

Falrow ensures that every person it authorises to process Customer Personal Data is bound by a duty of confidentiality, receives appropriate training, and has access only to the extent needed to provide, secure and support the Service.

5.Security (Annex II)

Falrow implements and maintains the technical and organisational measures described on its Security page, which form Annex II of this DPA, to ensure a level of security appropriate to the risk as GDPR Article 32 requires. They include:

  • encryption of data in transit (TLS, with certificate verification on database connections) and at rest (provider-managed AES-256), and application-level AES-256-GCM encryption of integration secrets and API keys;
  • access control through four workspace roles enforced in one service layer for the web app, Slack, the REST API and every MCP tool; OAuth with read or write scopes and rotating refresh tokens; expiring workspace tokens stored only as hashes; revocable sessions;
  • password hashing by the authentication provider, sign-in throttling and rate limits keyed by hashed IP addresses;
  • tenant isolation in the database through row-level security and workspace scoping of every query;
  • a per-request content security policy, HSTS, bounded upload sizes and request deadlines;
  • logical separation of production from development, least-privilege staff access, and an audit log of changes within each workspace;
  • regular backups with integrity verification and tested restore procedures;
  • a documented incident response process and vulnerability disclosure channel.

Falrow may update these measures as long as the update does not materially reduce the overall level of protection.

6.Sub-processors (Annex III)

The Customer gives Falrow general authorisation to engage sub-processors. The sub-processors authorised at the effective date are:

Sub-processorPurposeLocation
Supabase, Inc.Primary PostgreSQL database, user authentication and password-recovery email deliveryEU: Frankfurt, Germany (AWS eu-central-1)
Railway CorporationApplication hosting: runs the Falrow web app, REST API, MCP server and background workersEU: Railway EU West region (Netherlands)
Resend, Inc.Transactional email: workspace invitations and account noticesUnited States
OpenRouter, Inc.AI gateway that routes requests from Falrow's AI features to the model provider below. Used only when AI features are enabled for the workspace and only for the request in progress.United States
Anthropic, PBCLarge language models (Claude) that power AI features, reached through OpenRouterUnited States
TypeSafeClassification model (Jev) that decides whether a Slack message is a to-do, reached through OpenRouter. Used only when Slack to-do capture is enabled.United States

Falrow will impose on each sub-processor, by written contract, data protection obligations that provide at least the same level of protection as this DPA, and remains fully liable to the Customer for each sub-processor's performance.

Changes. Falrow will notify the Customer of any intended addition or replacement of a sub-processor at least 30 days in advance, by email to workspace owners and by updating the Subprocessors page. The Customer may object on reasonable data protection grounds within that period. The parties will discuss the objection in good faith; if Falrow cannot offer a reasonable alternative, the Customer may terminate the affected part of the Service without penalty and receive a refund of prepaid fees for the remaining term. In an emergency, for example when a sub-processor must be replaced to keep the Service secure or available, Falrow may make the change with shorter notice and will explain why.

Services that the Customer itself chooses to connect, such as Slack, Sentry, meeting notetakers or an AI provider using the Customer's own key, are not sub-processors of Falrow. They process data under the Customer's own agreement with them.

7.Data subject requests

Taking into account the nature of the processing, Falrow will assist the Customer by appropriate technical and organisational measures in responding to requests from data subjects to exercise their rights. The Service lets the Customer find, correct, export and delete Customer Personal Data itself. If Falrow receives a request directly, it will not respond except to direct the person to the Customer, and will forward the request to the Customer within five business days where the Customer can be identified.

8.Personal data breaches

Falrow will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, to the extent then known, the nature of the breach including the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it and mitigate its effects, and a contact point for more information. Falrow will provide further information as it becomes available, take reasonable steps to contain and remediate the breach, and cooperate with the Customer's own notification obligations.

Notice of a breach is not an acknowledgement of fault or liability.

9.Impact assessments and consultations

Taking into account the nature of the processing and the information available to it, Falrow will provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities that relate to the Service, primarily by making the documentation on its legal pages available.

10.Return and deletion

On termination of the Agreement, the Customer may export Customer Personal Data during the export period described in the Terms of Service. After that period Falrow will delete Customer Personal Data, including copies, from production systems within 30 days, and it will be removed from backups as they expire on their rolling cycle of no more than 35 days, unless the law requires Falrow to keep it. Falrow will confirm deletion in writing on request.

11.Information and audits

Falrow will make available to the Customer all information necessary to demonstrate compliance with GDPR Article 28 and this DPA, and allow for and contribute to audits, including inspections, by the Customer or an independent auditor it mandates, as follows:

  • Falrow will answer a reasonable written security and privacy questionnaire once in any 12-month period, and provide relevant documentation, including any third-party audit reports it holds.
  • If that information is not sufficient to demonstrate compliance, or a supervisory authority requires it, or after a personal data breach, the Customer may carry out an audit on at least 30 days' notice, during business hours, at its own cost, no more than once a year unless required by a supervisory authority, by an auditor bound by confidentiality who is not a competitor of Falrow, and without access to other customers' data.

For the CCPA, this section grants the Customer the right to take reasonable and appropriate steps to ensure that Falrow uses Customer Personal Data consistently with the Customer's obligations, and, on notice, to stop and remediate unauthorised use.

12.International transfers

Customer Data is hosted in the European Union. Falrow, a US company, and some sub-processors access or process it from the United States. Falrow will transfer Customer Personal Data out of the EEA, the UK or Switzerland only in compliance with Data Protection Laws.

EU Standard Contractual Clauses. To the extent the Customer's transfer of Customer Personal Data to Falrow is a restricted transfer under the GDPR, the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914 (the "SCCs") are incorporated into this DPA by reference and apply as follows: Module Two (controller to processor) where the Customer is a controller, and Module Three (processor to processor) where the Customer is a processor; the optional docking clause in Clause 7 applies; in Clause 9, Option 2 (general written authorisation) applies with the 30-day notice period in this DPA; the optional wording in Clause 11 does not apply; in Clause 13, the competent supervisory authority is the one determined under that Clause for the Customer; in Clauses 17 and 18, the SCCs are governed by the law of, and disputes are resolved by the courts of, Ireland; Annexes I, II and III are the corresponding sections of this DPA. The Customer and Falrow are treated as having signed the SCCs by accepting the Agreement.

United Kingdom. For restricted transfers under the UK GDPR, the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner (version B1.0, in force 21 March 2022) is incorporated. Table 1 is completed with the parties' details in Annex I; Table 2 with the modules and options above; Table 3 with Annexes I to III of this DPA; and in Table 4, either party may end the Addendum as set out in its Section 19.

Switzerland. For transfers subject to the FADP, the SCCs apply with these changes: references to the GDPR are to the FADP; the competent supervisory authority is the Federal Data Protection and Information Commissioner; references to "Member State" include Switzerland, so that data subjects in Switzerland can enforce their rights there.

Government access. Falrow will handle any request from a public authority for Customer Personal Data as described in its Legal Notices: it will challenge requests that are unlawful or overbroad, notify the Customer unless legally prohibited, and disclose only the minimum required.

If the SCCs or another transfer mechanism is invalidated or replaced, the parties will cooperate in good faith to adopt a valid alternative.

13.US state privacy laws

Where the CCPA or another US state privacy law applies to Customer Personal Data, Falrow acts as the Customer's service provider or processor, and:

  • will not sell or share Customer Personal Data;
  • processes it only for the specific business purpose of providing, securing and supporting the Service described in Annex I, and will not retain, use or disclose it for any other purpose, including any other commercial purpose, or outside the direct business relationship with the Customer;
  • will not combine it with personal data Falrow receives from or on behalf of another person, or collects from its own interactions with a consumer, except as the CCPA permits;
  • will comply with the CCPA and its regulations, and provide the same level of privacy protection the CCPA requires of the Customer, including reasonable security procedures under California Civil Code section 1798.81.5;
  • will notify the Customer if it determines it can no longer meet its obligations under the CCPA;
  • will enable the Customer to comply with consumer requests, as described in the Data subject requests section;
  • imposes a duty of confidentiality on each person processing the data, deletes or returns it at the end of the services as described above, makes available the information needed to demonstrate compliance, and allows reasonable assessments as described in the Information and audits section; and
  • engages subcontractors only under a written contract that imposes the same obligations, after notice to the Customer and an opportunity to object.

Falrow certifies that it understands and will comply with these restrictions.

14.Liability, precedence and duration

Each party's liability under this DPA is subject to the limitations in the Agreement, except where Data Protection Laws or the SCCs do not allow such limits.

If this DPA conflicts with the Agreement, this DPA prevails for the processing of Customer Personal Data. If the SCCs conflict with this DPA or the Agreement, the SCCs prevail.

This DPA remains in force for as long as Falrow processes Customer Personal Data. Falrow may update it to reflect changes in law, guidance or the Service, with the notice the Terms of Service require for material changes, but will not reduce the protection it gives without the Customer's agreement.

Who you contract with
Spring Digital Commerce LLC2810 North Church Street
Wilmington, DE 19802
United States
EIN 35-2886201bas@falrow.com
This versionVersion 1.0, effective 6 October 2026. Earlier versions are available on request from bas@falrow.com.All legal documents