Legal
Data processing addendum
Last updated 26 August 2026
This data processing addendum (the “DPA”) forms part of the terms of service between you (the “Customer”) and MODLL PTY LTD trading as FloConnector (“FloConnector”, “we”, “us”). It applies wherever FloConnector processes personal data on your behalf in providing the service, and it governs in place of the terms if the two conflict on data protection.
The short version. When your AI client calls a platform you connected, we relay the call and the result. Any personal data in that flow is yours, we process it only on your instruction, and we do not keep it. This document is the contract that says so in the form Article 28 of the GDPR requires, names every sub-processor we use, commits us to a 48-hour breach notification, and attaches the standard contractual clauses that make transfers to Australia lawful. You accept it when you accept our terms. You do not need to sign anything, though we will countersign a copy if your own compliance process needs one.
1. Definitions
“GDPR” means Regulation (EU) 2016/679. “UK GDPR” means the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of the European Union (Withdrawal) Act 2018, read with the Data Protection Act 2018. “Data Protection Law” means the GDPR, the UK GDPR, the Australian Privacy Act 1988 (Cth), and any other data protection law applicable to a party’s processing under this DPA.
“Controller”, “processor”, “data subject”, “personal data”, “processing” and “personal data breach” have the meanings given in the GDPR. “Customer Personal Data” means personal data contained in or derived from the platforms you connect to the service, which FloConnector processes on your behalf. “Sub-processor” means a third party engaged by FloConnector to process Customer Personal Data. “SCCs” means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021. “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0, in force 21 March 2022.
2. Roles of the parties
2.1 Where we are your processor
In relaying calls between your AI client and the platforms you connect, FloConnector acts as a processor and you act as the controller of Customer Personal Data. Where you are yourself a processor acting for another controller, for example an agency operating a workspace on behalf of a client, FloConnector acts as your sub-processor and you warrant that you have the authority to engage us on that controller’s behalf.
2.2 Where we are a controller
FloConnector is an independent controller, not your processor, in respect of: account and identity data for the people who register and are invited to your workspaces; authentication, session and security records; billing and plan records; the metadata-only tool-call log described in our privacy policy; and support correspondence. We process that data for the purposes set out in the privacy policy, and this DPA does not apply to it.
2.3 Connected platforms are not our sub-processors
The platforms you choose to connect, for example Xero, QuickBooks or ServiceM8, are not FloConnector sub-processors. They are your own service providers, under your own agreements with them, and they process your data under your relationship rather than ours. FloConnector’s role is to reach them at your instruction using the credentials and scopes you grant. Our sub-processors are only the providers listed in Annex III, which are the ones that help us run FloConnector itself.
3. Subject matter and details of processing
The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are set out in Annex I. Processing continues for the term of your agreement with us and ends as described in clause 11.
4. Processing on documented instructions
4.1 Your instructions
FloConnector processes Customer Personal Data only on your documented instructions, including in relation to transfers to a third country, unless required to do otherwise by law to which we are subject. In that case we will inform you of the legal requirement before processing, unless the law prohibits it on important grounds of public interest.
4.2 What counts as an instruction
Your instructions are: this DPA; the terms of service; and your configuration of the service. Specifically, connecting a platform, granting scopes to that connection, enabling a tool on a profile, assigning a member to a profile, and authorising an AI client against an endpoint each constitute a documented instruction to process Customer Personal Data in the manner those settings describe. A tool call made by an AI client you have authorised, using a tool you have enabled, on a connection you have created, is processing on your instruction.
Any other instruction must be agreed in writing, and we may charge for work that falls outside the service as configured.
4.3 Unlawful instructions
FloConnector will immediately inform you if, in our opinion, an instruction infringes Data Protection Law, and may suspend the affected processing until the instruction is withdrawn, amended or confirmed.
4.4 No independent use
We do not sell Customer Personal Data, use it for our own purposes, or use it to train, fine-tune or evaluate any artificial intelligence or machine-learning model. The aggregated statistics described in our privacy policy are derived solely from the metadata-only tool-call log referred to in clause 2.2, and never from Customer Personal Data.
5. Confidentiality
FloConnector ensures that every person authorised to process Customer Personal Data is bound by an enforceable obligation of confidentiality, whether contractual or statutory, that survives the end of their engagement. Access is limited to personnel who need it to deliver, secure or support the service, and is granted on a least-privilege basis.
6. Security
FloConnector implements and maintains the technical and organisational measures set out in Annex II, taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as required by Article 32 of the GDPR. We may update those measures over time provided the level of security is not materially reduced.
7. Sub-processors
7.1 General authorisation
You give FloConnector general written authorisation to engage sub-processors. Those engaged as at the date of this DPA are listed in Annex III.
7.2 Notice of change and right to object
We will give you at least 30 days’ notice before a new sub-processor begins processing Customer Personal Data, by updating Annex III and notifying the email address on your account. You may object on reasonable data protection grounds within that period. If we cannot provide a reasonable alternative, you may terminate the affected connections or your subscription without penalty, and we will refund any prepaid fees covering the period after termination.
7.3 Flow-down and our liability
We impose on each sub-processor, by written contract, data protection obligations no less protective than those in this DPA. Where a sub-processor fails to fulfil its data protection obligations, FloConnector remains fully liable to you for the performance of that sub-processor’s obligations, as required by Article 28(4) of the GDPR. Nothing in this DPA, our terms, or our privacy policy operates to transfer that liability to a sub-processor or to limit it, and any statement to the contrary is of no effect.
7.4 Composio
For connectors delivered through Composio, request and response data passes through Composio’s infrastructure to reach the platform, and Composio retains request and response payloads under its own retention practices. Composio is a sub-processor for the purpose of this DPA and clause 7.3 applies to it in full. Our natively integrated connectors, listed in the service, call the platform directly and do not involve Composio. If your data cannot be routed through a sub-processor that retains payloads, use a native connector or contact us before connecting.
7.5 Infrastructure provider exception
One sub-processor does not meet clause 7.3, and we disclose it rather than imply otherwise. Our infrastructure provider, identified in Annex III, offers no separate data processing agreement. It operates under its published terms of service, privacy policy and security statement, which commit it to taking all reasonable measures to protect personal information from misuse, loss, unauthorised access, modification and disclosure, and to physical and access controls at its data centres. Our servers sit in ISO 27001 certified facilities operated by NEXTDC; that certification belongs to the facility operator, not to our provider, and we do not present it as the provider’s own. Those published terms do not contain the full set of obligations set out in clause 7.3.
We rely on the following, each of which is true independently of that provider’s terms:
- The provider is established in Australia and our production infrastructure is located there, so no restricted international transfer arises from this relationship.
- Vendor credentials are sealed with AES-256-GCM in our application before they reach the provider’s storage.
- Database backups are encrypted before leaving our server, under a key that is not held on that server and is never given to the provider.
- No customer platform data is persistently stored, so the provider’s storage holds no such records at rest.
The provider’s unencrypted exposure is therefore limited to data held transiently in memory while a request is being served. We keep this under review, and will seek processor terms or move to a provider that offers them if that assessment changes.
8. Assistance with data subject rights
Taking into account the nature of the processing, FloConnector assists you by appropriate technical and organisational measures, insofar as possible, to fulfil your obligation to respond to requests to exercise data subject rights under Chapter III of the GDPR.
Because we do not retain Customer Personal Data, a data subject’s records ordinarily live only in the platform you connected, and a request is answered there rather than by us. Where a request nonetheless requires our involvement, we will respond to your reasonable request for assistance without undue delay and at no charge for the first request in any 12-month period. If a data subject contacts us directly, we will not respond substantively except to confirm the request has been referred to you, and we will forward it promptly.
9. Personal data breach
FloConnector notifies you of a personal data breach affecting Customer Personal Data without undue delay and in any event within 48 hours of becoming aware of it, to the email address on your account. The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the full picture is not available within 48 hours we will notify within that period on the basis of what is known and supplement it in phases.
We will assist you in meeting your own obligations under Articles 33 and 34 of the GDPR. We will not notify a supervisory authority or any data subject about a breach affecting Customer Personal Data on your behalf unless you instruct us to or we are required to by law.
10. Data protection impact assessments
FloConnector provides reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 of the GDPR, taking into account the nature of the processing and the information available to us. Annex II and our published documentation are ordinarily sufficient for this purpose.
11. Deletion and return
Customer Personal Data is not retained in the ordinary course. It is relayed and discarded, and any dataset loaded into the temporary in-memory analytics workspace is discarded when that workspace expires. There is therefore normally no stored Customer Personal Data to return or delete at the end of the service.
On termination or expiry of your agreement, and at your choice, FloConnector will delete or return any Customer Personal Data then held and delete existing copies within 30 days, unless Union, Member State, UK or Australian law requires storage. Absent an instruction from you within 30 days of termination, we will delete. Vendor credentials are deleted on disconnection or account closure. Encrypted offsite backups are overwritten on their retention cycle, which does not exceed 90 days, and remain subject to this DPA until they are.
12. Audits and information
FloConnector makes available to you all information reasonably necessary to demonstrate compliance with Article 28 of the GDPR, and allows for and contributes to audits, including inspections, conducted by you or an auditor you mandate.
In the first instance we satisfy this by providing, on request and no more than once in any 12-month period: the measures in Annex II, our current sub-processor list, and a completed security questionnaire in a reasonable industry format. FloConnector does not currently hold a SOC 2 or ISO 27001 certification, and we say so plainly rather than pointing you at a report that does not exist. Where that documentation is insufficient for your compliance obligations, or following a personal data breach, you may conduct or mandate an on-site or remote audit on 30 days’ written notice, during business hours, subject to reasonable confidentiality undertakings and without access to the data or systems of our other customers. You bear your own costs, and we may charge a reasonable fee for audits beyond the first in any 12-month period.
13. International transfers
13.1 Where we are
FloConnector is established in Australia, and our production infrastructure is located in Sydney, New South Wales, in a NEXTDC facility. Australia is not the subject of an adequacy decision under Article 45 of the GDPR or of UK adequacy regulations. Transfers of Customer Personal Data from the EEA or the UK to FloConnector are therefore made under the safeguards in this clause.
13.2 EEA transfers
Where Data Protection Law of the EEA applies to a transfer, the SCCs are incorporated into this DPA and apply as set out in Annex IV. Module Two (controller to processor) applies where you are a controller. Module Three (processor to processor) applies where you are a processor acting for another controller. Annexes I, II and III of this DPA serve as Annexes I, II and III of the SCCs.
13.3 UK transfers
Where the UK GDPR applies to a transfer, the SCCs apply as amended by the UK Addendum, completed as set out in Annex IV. The parties acknowledge the transfer standard as amended by Schedule 7 of the Data (Use and Access) Act 2025.
13.4 Execution
You enter into this DPA, including the SCCs and the UK Addendum, by accepting our terms of service, which Article 28(9) of the GDPR permits to be done in electronic form. Where your own compliance process requires an executed copy, email support@floconnector.com and we will provide a countersigned PDF at no charge.
13.5 Transfer assessment
FloConnector maintains a transfer impact assessment covering transfers to Australia and the onward transfers in Annex III, and makes it available on request under clause 12. Australian law does not impose data-access obligations on FloConnector comparable to those considered in Schrems II, and we have received no government request for Customer Personal Data. We will inform you if we become legally able to say that has changed.
14. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions in the terms of service, except that nothing in those limitations excludes or limits: our liability under clause 7.3 for the performance of a sub-processor’s obligations; or any liability that cannot be excluded or limited under Data Protection Law, including the rights of data subjects under Article 82 of the GDPR.
15. General
This DPA takes effect when you accept our terms of service and continues for as long as we process Customer Personal Data. If any provision of the SCCs conflicts with another provision of this DPA or of our terms, the SCCs prevail. Otherwise this DPA prevails over the terms and the privacy policy on data protection. Changes to this DPA follow clause 14 of the terms of service, except that a change reducing your protections requires your agreement. Governing law is as stated in the terms of service, save that the SCCs are governed by the law specified in Annex IV.
Annex I. Description of processing
A. Parties
Data exporter (controller, or processor where clause 2.1 applies): the Customer, being the account holder identified in FloConnector’s records, whose activities relevant to the transfer are its use of FloConnector to connect its business platforms to an AI client. Contact details are those held on the Customer’s account.
Data importer (processor): MODLL PTY LTD (ABN 79 639 342 484) trading as FloConnector, Victoria, Australia, whose activities relevant to the transfer are the provision of a hosted integration service that relays calls between the Customer’s AI client and the Customer’s connected platforms. Contact: support@floconnector.com.
B. Description of transfer
- Categories of data subjects. Determined by the Customer through its choice of connected platforms and enabled tools. Typically the Customer’s own customers, clients, contacts, leads, suppliers, contractors and employees whose records exist in those platforms.
- Categories of personal data. Determined by the Customer. Typically identifiers and contact details (name, email, phone, address), business and transactional records (invoices, quotes, jobs, bookings, orders, payments, timesheets), scheduling and location information, and free-text notes. The Customer controls this through the scopes it grants and the tools it enables.
- Special categories of data. The service is not designed for, and the Customer is not permitted to use it to process, special categories of personal data under Article 9 of the GDPR or data relating to criminal convictions and offences under Article 10, unless separately agreed in writing. Where such data nonetheless exists in a connected platform, the Customer is responsible for not exposing it through the tools it enables.
- Frequency of transfer. Continuous, on a request-by-request basis, initiated by the Customer’s authorised AI client.
- Nature and purpose of processing. Receiving a structured tool call, calling the Customer’s connected platform under the Customer’s credentials, relaying the result to the Customer’s AI client, and where a request requires analysis of a larger dataset, loading it into a temporary in-memory analytics workspace for the purpose of returning an aggregate. Processing operations are limited to transmission, transient storage in memory, and erasure.
- Retention. No persistent retention. Data is relayed and discarded on completion of the request. Data loaded into the temporary analytics workspace is erased when that workspace expires, which is approximately 10 minutes after it was last used.
- Duration of processing. For the term of the Customer’s agreement with FloConnector.
- Sub-processors. As listed in Annex III, for the duration and purpose stated there.
C. Competent supervisory authority
For transfers under the SCCs, the supervisory authority of the EEA Member State in which the data exporter is established, or, where the exporter is not established in the EEA, the supervisory authority of the Member State in which its Article 27 representative is established or in which the data subjects are located. For transfers under the UK Addendum, the Information Commissioner’s Office.
Annex II. Technical and organisational measures
FloConnector applies the following measures. They are described at a level that lets you assess them without disclosing detail that would itself create risk.
Minimisation by design
The service is a proxy. It maintains no persistent mirror of connected-platform data, so the largest category of personal data in the flow is never stored. Analytical workloads run in a temporary in-memory workspace that is discarded on expiry and never written to a persistent store. The interaction log records metadata only, never request or response payloads. FloConnector does not receive the prompts or conversation content of the Customer’s AI client.
Encryption
Vendor credentials are envelope-encrypted in the application with AES-256-GCM before they are written to the database, so the database holds ciphertext only. The key-encryption key is held in process configuration, never in the database, and is versioned so it can be rotated without a window in which credentials are unreadable. Session cookies, magic-link tokens and OAuth authorization codes are stored hashed, not encrypted, because they are verified rather than replayed. All traffic to the service is over TLS.
Access control
Every data-plane request requires a bearer token that is matched to a workspace and pinned to a specific endpoint. Access to a connection is granted per user by explicit assignment, not by role alone. The Customer controls which tools each connection exposes. Workspace isolation is enforced on every query and verified by a static check that fails the build if a workspace-scoped table is read or written without a workspace filter. Administrative access is limited to named personnel, granted on a least-privilege basis, and subject to the confidentiality obligation in clause 5.
Segregation
Data is logically segregated per workspace, and connection endpoints are scoped per profile. The control plane and the data plane run as separate processes.
Resilience, backup and restoration
Database backups are encrypted before leaving the server with a public key whose private half is not held on that server, then written to offsite object storage, so the storage provider holds ciphertext only. Backups are taken nightly with a retention ceiling of 90 days. Restoration is exercised by a documented restore drill against a scratch database, which includes verifying that the application can decrypt credentials from the restored data, because a restore that produces an undecryptable database is not a restore.
Vendor credential handling
The Customer’s AI client never receives vendor credentials. Tokens are refreshed server-side, with concurrent refreshes coalesced so that single-use refresh tokens are not spent twice. Credentials are deleted on disconnection or account closure.
Logging and monitoring
Tool calls are logged as metadata, including which tool ran, on which connection, by which workspace member, when, and whether it succeeded. This supports security investigation and audit without retaining payloads. Authentication and administrative events are logged.
Testing and governance
Changes are reviewed before deployment and pass automated checks, including the workspace-scoping guard described above. Measures are reviewed at least annually and following any personal data breach. FloConnector does not currently hold a SOC 2 or ISO 27001 certification; see clause 12.
Measures applying to sub-processors
Sub-processors are engaged under written contracts imposing obligations no less protective than this DPA, are assessed before engagement, and are listed in Annex III.
Annex III. Sub-processors
The following sub-processors are authorised as at the date of this DPA. To be notified of changes, email support@floconnector.com with the subject “subprocessor notifications”.
| Sub-processor | Purpose | Processes Customer Personal Data | Location |
|---|---|---|---|
| Mammoth Media Pty Ltd, trading as Binary Lane | Infrastructure hosting for the application and database. No separate processor agreement; see clause 7.5 | In transit and in memory only. Nothing at rest is readable by the provider | Sydney, Australia (NEXTDC S1). ABN 51 101 844 955 |
| Composio | Managed connectivity and OAuth for non-native connectors. Retains request and response payloads under its own practices. See clause 7.4 | Yes, for connectors delivered through Composio only | Sampark Inc., Delaware, United States |
| Cloudflare R2 | Offsite storage of database backups, which are encrypted before leaving our server | Ciphertext only | Cloudflare, Inc., United States. Bucket region Oceania (OC) |
| Dodo Payments | Payment processing as Merchant of Record | No. Account and billing data only, for which we are a controller | Dodo Payments Inc., Delaware, United States. Processing in India (AWS ap-south-1) |
| Resend | Transactional email, including sign-in codes and notifications | No. Account contact data only | United States |
| Google (reCAPTCHA) | Abuse protection on sign-in pages | No. Sign-in page interaction data only | United States |
Connected platforms are not sub-processors. See clause 2.3.
Annex IV. Standard contractual clauses
A. EU standard contractual clauses
The SCCs are incorporated by reference and completed as follows.
- Module. Module Two (controller to processor) where the Customer is a controller. Module Three (processor to processor) where the Customer is a processor acting for another controller. Modules One and Four do not apply.
- Clause 7 (docking clause). Applies.
- Clause 9 (use of sub-processors). Option 2, general written authorisation. The notice period is 30 days, as set out in clause 7.2 of this DPA.
- Clause 11 (redress). The optional independent dispute resolution paragraph does not apply.
- Clause 17 (governing law). Option 1. The law of Ireland.
- Clause 18(b) (forum and jurisdiction). The courts of Ireland.
- Annex I.A (parties). As set out in Annex I.A of this DPA.
- Annex I.B (description of transfer). As set out in Annex I.B of this DPA.
- Annex I.C (competent supervisory authority). As set out in Annex I.C of this DPA.
- Annex II (technical and organisational measures). As set out in Annex II of this DPA.
- Annex III (list of sub-processors). As set out in Annex III of this DPA.
B. UK Addendum
The UK Addendum is incorporated by reference and completed as follows.
| UK Addendum table | Completed as |
|---|---|
| Table 1: Parties | As set out in Annex I.A of this DPA. Start date is the date the Customer accepted the terms of service. |
| Table 2: Selected SCCs, modules and selected clauses | The SCCs as completed in section A of this Annex IV. |
| Table 3: Appendix information | Annex 1A, 1B, II and III as set out in Annexes I, II and III of this DPA. |
| Table 4: Ending the Addendum when the Approved Addendum changes | Neither party may end the Addendum as set out in section 19 of the Addendum. |
16. Contact
Data protection enquiries, executed-copy requests, sub-processor notification sign-up, and audit requests: support@floconnector.com. FloConnector is operated by MODLL PTY LTD (ABN 79 639 342 484), Victoria, Australia.