Data Processing Agreement
CySo Solutions Ltd · Last updated: 10 October 2026
1. What this agreement is, and when it applies
1.1 This Data Processing Agreement ("DPA") is between CySo Solutions Ltd, Republic of Cyprus ("CySo", "we", "us") and the business or individual that holds a CySo Flow account ("Customer", "you"). It gives effect to Article 28(3) of Regulation (EU) 2016/679 ("GDPR").
1.2 This DPA is incorporated into the CySo Flow Terms of Service by reference and forms part of them. It applies automatically from the moment you first use the Service. You do not need to sign it or ask for it.
1.3 Where this DPA and the Terms of Service conflict on a matter of data protection, this DPA prevails.
1.4 If you require your own processor agreement instead, contact [email protected]. We will consider it. Until one is agreed and signed, this DPA governs, so that processing never takes place without a written agreement in force.
2. Roles of the parties
2.1 For all personal data you enter into, upload to, or generate within the Service — your customers, your employees, your suppliers, and everything recorded about them — YOU are the controller and CySo is your processor.
2.2 For the personal data CySo needs in order to operate its own business — your name and contact details as our customer, our invoices to you, your support correspondence, and the security and error logs of your use of the Service — CySo is the controller. That processing is described in our Privacy Policy and is outside the scope of this DPA.
2.3 Nothing in this DPA makes CySo a joint controller with you, and CySo does not process the data covered by §2.1 for any purpose of its own.
3. Subject matter, duration, nature and purpose
3.1 Subject matter. The provision of the CySo Flow business management service.
3.2 Duration. For as long as you hold an account, plus the closure period in §10 (including, for a lapsed account, §10.2A).
3.3 Nature and purpose. Storing, organising, retrieving, displaying, transmitting, backing up and erasing the personal data you place in the Service, so that the Service can perform the functions you use it for — invoicing, quotations, scheduling, job and workshop records, stock, purchasing, accounting, payroll, time and attendance, the staff portal, the customer portal, document generation, and the email, SMS, banking, storage and AI integrations you choose to enable.
3.4 Categories of data subject. Your customers and their contacts; your employees, technicians and other staff; your suppliers and their contacts; students, parents and children where you use the Academy module; and any individual who appears in a record, a photograph or a signature you capture.
3.5 Types of personal data. Names; postal and email addresses; telephone numbers; job titles and employment details; salary, pay-rate, tax and social-insurance data where you use Payroll; working hours, clock-in and clock-out times and GPS coordinates where you use Time & Attendance; vehicle and equipment details; photographs, which may incidentally show people; handwritten signatures; free-text notes; financial records including invoices, quotations, payments and bank transaction lines; and identifiers you assign.
3.6 Special category data. The Service is not designed for, and must not be used to record, data within Article 9 GDPR (including health data) unless you have separately agreed that use with us in writing. Sick-leave records in Time & Attendance may reveal health information; where you use them, that processing is on your instruction and under your controllership, and you are responsible for its lawful basis under Article 9.
4. Our obligations as processor
4.1 Instructions (Art. 28(3)(a)). We process the personal data covered by this DPA only on your documented instructions. Your instructions are these terms, this DPA, and your operation of the Service’s features. We will not process it for any other purpose, and we will not sell it, rent it, share it, or use it to train any machine-learning model.
4.2 If we believe an instruction infringes the GDPR or other EU or Member State data protection law, we will tell you and may suspend the affected processing until it is resolved.
4.3 Where EU or Member State law requires us to process the data other than on your instruction, we will inform you of that requirement before processing, unless the law forbids us from doing so on important grounds of public interest.
4.4 Confidentiality (Art. 28(3)(b)). Every person we authorise to access the data is bound by a duty of confidentiality, and access is limited to those who need it to operate, support or secure the Service.
5. Security measures (Art. 28(3)(c) and Art. 32)
5.1 The measures below are the ones actually in place. They are stated so you can assess them; they are not a warranty that no incident can occur.
5.2 Encryption in transit. All traffic between your browser and the Service, and between the Service and its infrastructure providers, uses TLS. HTTP Strict Transport Security is enforced.
5.3 Encryption at rest. Database and object storage are encrypted at rest by the underlying infrastructure providers using keys they manage.
5.4 Tenant isolation. Each customer’s records are stored under a separate tenant path and access is enforced server-side by database security rules, not by the application alone. Those rules deny by default: a request that matches no explicit permission is refused.
5.5 Access control within your account. You decide which of your people can see which modules and records, through the Service’s roles and per-area permissions. Sensitive areas fail closed — an unrecognised area is denied rather than allowed.
5.6 Authentication. Sign-in is handled by Firebase Authentication. Passwords are stored and verified there and are never visible to us. Email address verification is required for accounts created from 2026 onwards.
5.7 Stored third-party credentials. Credentials you connect — email (SMTP) passwords, SMS and messaging tokens, banking and cloud-storage authorisations, AI API keys — are encrypted before being written to our key-value store and are never returned to the browser.
5.8 Segregation of duties for public links. Documents shared with your customers for approval, booking or intake are served through opaque single-purpose tokens that expire, and grant access to one document rather than to your account.
5.9 Logging. Actions taken within an account are recorded in an activity log available to you. Application errors are captured by an error-monitoring service we host on our own infrastructure.
5.10 Backups. The Service is backed up off-site. Backups are encrypted and are overwritten on a rolling schedule not exceeding 90 days.
5.11 Testing. Changes are gated on an automated test suite covering the security rules and the tenant-isolation boundary, run against a database emulator before any rules change is published.
6. Sub-processors (Art. 28(2) and 28(3)(d))
6.1 You give general authorisation for us to engage sub-processors, subject to this section.
6.2 The current list of sub-processors, what each one does, and where it is located, is set out in Section 7 of our Privacy Policy at https://flow.cysosolutions.com/privacy. It is maintained there rather than duplicated here so that one list cannot fall behind the other.
6.3 We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
6.4 We will give you at least 30 days’ notice by email before adding or replacing a sub-processor that processes the data covered by §2.1. If you reasonably object on data protection grounds within that period, we will work with you to find a solution; if none is available, you may terminate the affected part of the Service without penalty and receive a pro-rated refund of any prepaid fees.
6.5 Integrations you choose to connect — your own cloud storage, your own email server, your own SMS or messaging provider, your own bank connection, your own AI API key — are not our sub-processors. They act on your authorisation, under your own account with them, and their terms apply to that processing directly.
7. International transfers
7.1 Database. Your records are stored in Google Cloud Firestore in the `eur3` multi-region, which comprises data centres in Belgium and the Netherlands. Records do not leave the European Union at rest.
7.2 Object storage. Files you upload — photographs, attachments and generated PDFs — are stored in Cloudflare R2 in a bucket created under Cloudflare’s EU jurisdiction. Objects in an EU-jurisdiction bucket are stored and processed within the European Union; this is enforced by Cloudflare, not merely a preference. Uploaded files therefore do not leave the EU at rest.
7.3 Edge processing. The Service runs on Cloudflare’s edge network, so an individual request may be handled by a server outside the EEA even though the data at rest does not leave it. That transit is covered by Cloudflare’s Data Processing Addendum and the European Commission’s Standard Contractual Clauses. It is processing in transit only: nothing is stored outside the EU.
7.4 Optional integrations. Where you enable an integration whose provider is outside the EEA — for example an SMS gateway or an AI provider — data you send through it is transferred under your own agreement with that provider. Those transfers are identified in Section 7 of the Privacy Policy.
8. Assisting you with data subject rights (Art. 28(3)(e))
8.1 The Service gives you the tools to answer most requests yourself, without contacting us: you can search, correct and delete any record; erase an individual customer together with their linked records; and export the whole account in a machine-readable format for a portability request.
8.2 Where a request cannot be satisfied with those tools, we will provide reasonable assistance, taking into account the nature of the processing and the information available to us.
8.3 If a request from one of your data subjects reaches us directly, we will not answer it on your behalf. We will pass it to you without undue delay and tell the individual that we have done so.
9. Breaches and assistance with Articles 32 to 36 (Art. 28(3)(f))
9.1 We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the data covered by §2.1.
9.2 The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where we cannot provide all of that at once, we will provide it in phases without undue delay.
9.3 Reporting a breach to a supervisory authority under Article 33, and to affected individuals under Article 34, is YOUR obligation as controller. We will give you the information you need to do it and will not make that report on your behalf.
9.4 We will provide reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36 in relation to the Service.
10. Deletion and return of data (Art. 28(3)(g))
10.1 You may export a complete copy of your data at any time from Settings → Data & Backup. This satisfies the "return" limb of Article 28(3)(g) and is available throughout the term.
10.2 On closure of your account — whether you close it yourself or we terminate it — your data remains available for export for 30 days, and you may reverse the closure at any point during that window.
10.2A Lapsed accounts. Where a subscription was cancelled for non-payment (or reversed by a chargeback) and the account then has no paid plan and nobody on it signs in for six months (Terms clause 4.8), the provision of the Service is treated as ended for Article 28(3)(g). We email the account address 30 days and 7 days before the closure date; the account is then closed under §10.2, with the same 30-day window to export your data or reverse the closure, and erased under §10.3, subject to §10.4. Signing in or subscribing again before the closure date keeps the account. This forms part of your documented instructions under §4.1.
10.3 At the end of that window we permanently erase every record, uploaded file, shared link and stored credential belonging to the account, together with the sign-in identity itself. This runs automatically and we retain no copy.
10.4 Only three categories survive: our own invoices to you and the related accounting records, which Cypriot tax law requires us to retain; the separate sign-in accounts of colleagues you invited, which belong to those individuals; and off-site backups, which are overwritten on their own rolling schedule and in any event within 90 days of closure.
10.5 We will confirm completion of the erasure in writing on request.
11. Audits and information (Art. 28(3)(h))
11.1 We will make available to you the information necessary to demonstrate compliance with Article 28, on written request to [email protected].
11.2 You may audit our processing, or appoint an independent auditor to do so, on 30 days’ written notice, no more than once in any 12-month period unless a breach or a supervisory authority requires otherwise. Audits take place during business hours, must not unreasonably disrupt the Service, and must not access any other customer’s data.
11.3 We may satisfy an audit request by providing a current third-party report or the documentation in §11.1 where that reasonably answers it.
12. Liability, term and governing law
12.1 The liability provisions of the Terms of Service apply to this DPA, save that nothing in them limits either party’s liability to a data subject under Article 82 GDPR.
12.2 This DPA takes effect on your first use of the Service and continues for as long as we process personal data on your behalf, including the closure period in §10.
12.3 This DPA is governed by the law of the Republic of Cyprus, and the courts of Nicosia have exclusive jurisdiction, subject to any mandatory rights a data subject has to bring proceedings elsewhere.
12.4 If any provision is held invalid, the remainder continues in force.
13. Contact
Data protection enquiries, audit requests, sub-processor objections and erasure confirmations: [email protected]
CySo Solutions Ltd, Republic of Cyprus.