Legal

Data Processing Addendum (DPA)

Terms for TumiFlow's processing of personal data on behalf of business customers.

Effective date: September 30, 2026Last updated: September 30, 2026

1. Purpose and application

This Data Processing Addendum forms part of the Terms of Service or another agreement between TumiFlow and the customer when TumiFlow processes personal data on the customer's behalf through the service. It applies only to that processing and does not replace obligations that apply to either party in another role.

2. Roles

Where applicable, the customer acts as the controller, business, or equivalent party that determines the purposes and means of processing customer business data. TumiFlow acts as the processor, service provider, or equivalent party for that data. Each party remains responsible for obligations that apply to it under applicable data-protection law. TumiFlow may act independently as controller for account administration, security, fraud prevention, support, billing, and legal compliance.

3. Processing details

Subject matter
Providing TumiFlow and the features, support, security, and integrations selected by the customer.
Duration
For the term of the service agreement and the limited retention period described in the Privacy Policy, unless law requires longer retention.
Nature and purpose
Hosting, organizing, transmitting, retrieving, securing, supporting, and deleting data; operating CRM, Inbox, appointments, tasks, funnels, automations, AI-assisted features, billing, and authorized integrations.
Data subjects
Customer users, employees, contractors, leads, contacts, customers, message participants, appointment attendees, form submitters, and other people whose information the customer processes.
Data categories
Identity and contact information, account and role data, business records, communications, appointments, form submissions, notes, preferences, billing references, technical events, and other data submitted or connected by the customer.

4. Customer instructions and obligations

TumiFlow will process customer personal data only on documented instructions from the customer, including the customer's configuration and authorized use of the service, unless applicable law requires otherwise. If legally permitted, TumiFlow will inform the customer of a conflicting legal requirement.

The customer will provide lawful instructions; maintain required notices, consents, and legal bases; use appropriate settings and permissions; respond to data subjects where it is responsible; and avoid submitting data that TumiFlow is not authorized or reasonably designed to process.

5. Confidentiality

TumiFlow will limit access to customer personal data to people and service providers who need it for authorized service, support, security, or legal duties and who are subject to appropriate confidentiality obligations. The customer is responsible for confidentiality obligations applicable to its users.

6. Security

TumiFlow will maintain reasonable technical and organizational measures appropriate to the service and risk, which may include authenticated access, workspace isolation, role-based permissions, server-side credential handling, protected secret storage where implemented, audit and security controls, backup or recovery controls, and payment processing by payment providers. No security measure eliminates all risk, and this DPA does not claim a certification TumiFlow has not obtained.

7. Subprocessors

The customer authorizes TumiFlow to use subprocessors to provide infrastructure, authentication, security, billing, support, and authorized integrations. Current categories and named providers are listed on the public Subprocessors page. TumiFlow remains responsible for its subprocessors' processing to the extent required by applicable law and will impose appropriate data-protection obligations.

Customer-selected BYOP AI providers and other providers independently connected by the customer are also subject to the customer's direct agreement with that provider. The customer instructs TumiFlow to transmit necessary data to those providers when using the integration.

8. Data-subject requests

Taking into account the nature of processing, TumiFlow will provide reasonable assistance with eligible requests for access, correction, deletion, restriction, objection, or portability when the customer cannot fulfill the request through available features. TumiFlow may require verification and may charge reasonable costs where permitted for unusually burdensome requests.

9. Security incidents

TumiFlow will notify affected customers without undue delay after confirming a personal-data breach involving customer personal data where notification is required by applicable law. Notice may describe the nature of the incident, likely consequences, measures taken or proposed, and a contact point as information becomes available. Notification is not an admission of fault or liability.

10. Return, deletion, and retention

On termination and written request, TumiFlow will delete or return eligible customer personal data within a reasonable period, unless applicable law requires retention. Data may remain temporarily in protected backups until ordinary deletion cycles complete. Billing, security, fraud, dispute, and legal records may be retained as reasonably necessary or legally required.

11. International transfers

Personal data may be processed in countries where TumiFlow or a relevant subprocessor operates. Where an applicable law requires a transfer mechanism, the parties will cooperate in good faith to use an appropriate contractual or legal safeguard. The customer is responsible for evaluating transfers to providers it independently selects and connects.

12. Information and review

TumiFlow will make reasonably available information needed to demonstrate the obligations in this DPA, subject to confidentiality, security, and proportionality. Any audit or assessment request must avoid compromising other customers, security, or provider confidentiality and may be satisfied with documentation or an independent report if one later becomes available.

13. Priority and contact

If this DPA conflicts with the Terms of Service regarding processing covered by this DPA, this DPA controls to the extent of the conflict. Mandatory law controls over both. Data-protection questions may be sent to tumiflow.support@gmail.com. Customers with jurisdiction-specific requirements should obtain legal advice and may contact TumiFlow to discuss an appropriate written addendum.

Questions about this document?

Email TumiFlow: tumiflow.support@gmail.com