Skip to content

Data processing agreement

Last updated

Draft — not yet legally reviewed

This document is a structural scaffold, not legal advice, and it is excluded from search indexing until it is finished. Placeholders are written in angle brackets and must be replaced before launch. Have a qualified lawyer review it before taking payment from customers.

Where you use TreeFlow to process personal data of your own customers or staff, you act as controller and we act as processor. Article 28 GDPR requires a written agreement between us.

When you need this

If the content you put into TreeFlow includes personal data — interview notes naming individuals, for example, or customer quotes that identify someone — you need a data processing agreement with us before that processing begins.

Subject matter and duration

<Describe the processing: hosting and making available the workspace content you enter, for the duration of the subscription.>

Nature and purpose of processing

<Storage, retrieval, backup and deletion of customer content in order to provide the service.>

Categories of data subjects and personal data

<Typically: your employees who hold accounts, and any individuals referenced in the content you enter.>

Technical and organisational measures

<Describe the measures actually in place: encryption in transit and at rest, access control, tenant isolation, backups, logging, incident response. Do not list measures you have not implemented.>

Subprocessors

We use the subprocessors listed on the subprocessors page. <State how customers are notified of changes and how they may object.>

How to conclude the agreement

<Describe the process: a downloadable PDF to countersign, acceptance during checkout, or a clause incorporated into the terms.>

Other legal documents