Data Processing Agreement
This Data Processing Agreement ("DPA") is entered into between TransactionFlow, LLC, a Georgia limited liability company ("Processor," "we," "us," or "our"), and the Customer/Beta Tester as defined in the corresponding agreement subscribing to the TransactionFlow platform ("Controller," "you," or "your"). This DPA supplements and is incorporated into the TransactionFlow Terms of Service, accessible at https://transactionflow.com/terms-of-service, and Beta Tester Agreement, if applicable to you (collectively, the “Terms”).
This DPA establishes the terms under which TransactionFlow processes personal data on behalf of its users in connection with TransactionFlow’s platform (the “Platform”) services. This DPA is intended for use by brokerage accounts and enterprise subscribers who require a formal data processing agreement, but its principles apply to all TransactionFlow users.
1. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person that is processed by TransactionFlow in connection with the Platform services, including but not limited to names, email addresses, phone numbers, property addresses, and financial transaction details.
"Processing" means any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, combination, restriction, erasure, or destruction.
"Controller" means the entity (you, the subscriber) that, solely during such time as it maintains an active account with the Platform, determines the purposes and means of the processing of Personal Data through the Platform.
"Processor" means TransactionFlow LLC, which processes Personal Data on behalf of the Controller.
"Sub-Processor" means any third party engaged by TransactionFlow to process Personal Data on behalf of the Controller.
"Platform Data" means aggregated, anonymized, and de-identified data derived from the use of the Platform that cannot reasonably be used to identify any individual. Platform Data is owned by TransactionFlow as outlined in the Terms of Service.
2. Scope and Purpose of Processing
TransactionFlow processes Personal Data solely for the following purposes:
- Providing and maintaining the Platform services, including transaction management, CRM functionality, AI-powered assistance through Flow-AI (an AI agent within the Platform), and communication tools.
- Processing payments and managing subscriptions through our payment processor (Stripe).
- Providing customer support and resolving technical issues.
- Improving and optimizing the Platform, including through the creation of aggregated, anonymized Platform Data.
- Communicating with you about your account, service updates, and Platform features.
- Complying with applicable legal obligations.
3. Categories of Personal Data Processed
| Data Category | Examples |
|---|---|
| User Account Data | Name, email, phone, license number, brokerage affiliation, billing information |
| Transaction Data | Property addresses, transaction details, contract dates, closing information, financial calculations |
| Client Data | Client names, contact information, property preferences, communication history stored by the user |
| Communication Data | Emails, messages, and communications sent or received through Platform tools |
| Usage Data | Login activity, feature usage, interaction patterns, device and browser information |
| Financial Data | Commission tracking, expense records, per-deal P&L data entered by the user |
4. Obligations of TransactionFlow as Processor
TransactionFlow agrees to:
- Process Personal Data only in accordance with documented instructions from the Controller, except where required by applicable law.
- Ensure that persons authorized to process Personal Data have committed to confidentiality obligations.
- Implement appropriate technical and organizational security measures to protect Personal Data, including encryption at rest and in transit, access controls, regular security assessments, and incident response procedures.
- Assist the Controller in responding to data subject access requests, deletion requests, and other rights exercised under applicable data protection laws.
- Notify the Controller without undue delay (and in any event within 72 hours) upon becoming aware of a Personal Data breach.
- Upon termination of services, delete or return all Personal Data to the Controller as requested, subject to the data retention terms outlined in the Terms and Section 8 of this DPA.
- Make available to the Controller all information necessary to demonstrate compliance with this DPA.
5. Obligations of the Controller
The Controller agrees to:
- Ensure that it has a lawful basis and all required consents for the collection and transfer of Personal Data to TransactionFlow.
- Provide all necessary notices to, and where required obtain all necessary consents from, data subjects whose Personal Data is processed through the Platform.
- Ensure that its use of the Platform complies with all applicable data protection laws and the TransactionFlow Acceptable Use Policy.
- Promptly notify TransactionFlow of any data subject requests received directly that relate to TransactionFlow’s processing activities.
6. Sub-Processors
The Controller grants TransactionFlow general written authorization to engage Sub-Processors for the purpose of providing the Platform services. A current list of Sub-Processors shall be made available by TransactionFlow upon written request from active account holders. TransactionFlow will notify the Controller of any intended changes to its Sub-Processors, giving the Controller the opportunity to object in the following thirty (30) days. If the Controller reasonably objects to a new Sub-Processor, TransactionFlow will make commercially reasonable efforts to provide an alternative or allow the Controller to terminate the affected services. TransactionFlow will impose data protection obligations on each Sub-Processor no less protective than those set out in this DPA. TransactionFlow will impose data protection obligations on each Sub-Processor no less protective than those set out in this DPA.
7. Data Transfers
All Personal Data is stored and processed within the United States. If any processing occurs outside the United States in the future, TransactionFlow will ensure appropriate safeguards are in place in accordance with applicable data protection laws.
8. Data Retention and Deletion
Upon cancellation or termination of a user’s subscription, TransactionFlow will retain the user’s Personal Data for a period of 60 days to allow for account reactivation or data export. After the 60-day retention period, Personal Data will be securely deleted from active systems, with the following exceptions:
- Data required to be retained by applicable law, regulation, or legal process.
- Aggregated, anonymized Platform Data that cannot reasonably be used to identify any individual. As outlined in the Terms, Platform Data is owned by TransactionFlow and is not subject to deletion requests.
- Backup copies, which will be purged in accordance with TransactionFlow’s standard backup rotation schedule.
The Controller may request a data export at any time during the 60-day retention period by contacting [email protected].
9. Platform Data and Anonymized Data
The parties acknowledge and agree that TransactionFlow creates Platform Data by aggregating and anonymizing Personal Data and usage information across the Platform. Platform Data does not constitute Personal Data and is not subject to this DPA. TransactionFlow’s ownership and rights to Platform Data are governed by the Terms.
TransactionFlow employs industry-standard anonymization and aggregation techniques to ensure Platform Data cannot be used to re-identify any individual user or their clients. TransactionFlow will not attempt to re-identify anonymized data.
10. Security Measures
TransactionFlow implements and maintains appropriate technical and organizational measures to protect Personal Data, including but not limited to:
- Encryption of data in transit (TLS/SSL) and at rest.
- Access controls limiting Personal Data access to authorized personnel on a need-to-know basis.
- Regular security assessments and vulnerability testing.
- Employee confidentiality obligations and security training.
- Incident detection, response, and notification procedures.
- Regular data backup procedures.
11. Data Breach Notification
In the event of a Personal Data breach, TransactionFlow will notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach. The notification will include, to the extent available:
- A description of the nature of the breach, including the categories and approximate number of data subjects affected.
- The name and contact details of TransactionFlow’s designated point of contact.
- A description of the likely consequences of the breach.
- A description of the measures taken or proposed to address the breach and mitigate its effects.
TransactionFlow will cooperate with the Controller in investigating and responding to any data breach and will take commercially reasonable steps to mitigate the effects.
12. Liability; Limitations
To the maximum extent permitted by applicable law, TransactionFlow's total aggregate liability arising out of or in connection with this DPA, whether in contract, tort (including negligence), breach of statutory duty, or otherwise, shall not exceed the total amounts paid or payable by the Controller to the Processor under the Terms in the twelve (12) months preceding the event giving rise to the liability. In no event shall TransactionFlow be liable for any indirect, consequential, incidental, special, punitive, or exemplary damages, or for any loss of profits, revenue, business, or data, even if advised of the possibility of such damages. Nothing in this clause shall limit or exclude liability for fraud, willful misconduct, or any liability which cannot be limited or excluded by applicable law.
13. Governing Law and Dispute Resolution
This DPA shall be governed by and construed in accordance with the laws of the State of Georgia, without regard to its conflict of law principles. Any disputes arising under this DPA shall be resolved in accordance with the dispute resolution provisions of the TransactionFlow Terms.
14. Term and Termination
This DPA shall remain in effect for the duration of the Controller’s subscription to the Platform and shall automatically terminate when TransactionFlow ceases to process Personal Data on behalf of the Controller, subject to the data retention provisions in Section 8.
15. Contact Information
For questions about this Data Processing Agreement or to exercise any rights under this DPA, please contact:
TransactionFlow LLC
Email: [email protected]