Data Processing Agreement
Last updated: June 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between FlexOrch (“Processor”) and the customer entity using the FlexOrch services (“Controller”) and governs the processing of Personal Data by FlexOrch on behalf of Customer.
1. Definitions
"Agreement" means the FlexOrch Terms of Service, Order Form, subscription agreement or other written agreement between Customer and FlexOrch.
"Customer Data" means documents, files, extracted fields, generated datasets, metadata and other data submitted to or generated through the Services by or on behalf of Customer.
"Personal Data" means any information relating to an identified or identifiable natural person, as defined under applicable data protection laws.
"Processing" means any operation performed on Personal Data, including collection, upload, storage, extraction, structuring, masking, scoring, transformation, export, deletion or retrieval.
"Services" means the FlexOrch platform, APIs, SDKs, document processing pipelines, privacy masking tools, quality scoring tools, dataset export tools and related services.
"Data Protection Laws" means applicable privacy and data protection laws, including, where applicable, the GDPR, UK GDPR, KVKK and related implementing regulations.
"GDPR" means Regulation (EU) 2016/679.
"KVKK" means Turkish Law No. 6698 on the Protection of Personal Data.
"Sub-processor" means any third party engaged by FlexOrch to process Personal Data on behalf of Customer in connection with the Services.
2. Roles of the Parties
Customer is the Controller of Personal Data contained in Customer Data. Customer determines the purposes and means of Processing.
FlexOrch acts as Processor and processes Personal Data only on behalf of Customer and only in accordance with Customer's documented instructions, this DPA, the Agreement and applicable Data Protection Laws.
Customer is responsible for ensuring that it has a lawful basis for uploading, submitting and processing Personal Data through the Services.
3. Scope and Purpose of Processing
FlexOrch processes Personal Data solely for the purpose of providing the Services to Customer, including:
- receiving and processing uploaded documents;
- extracting structured information from documents;
- detecting and masking sensitive or personal data fields;
- generating quality scores, metadata and processing lineage;
- creating structured datasets for AI, analytics, RAG, fine-tuning or automation workflows;
- exporting data in supported formats;
- providing API, SDK, dashboard, billing, support and security functionality;
- maintaining system integrity, abuse prevention, logging and troubleshooting.
FlexOrch shall not process Personal Data for its own independent purposes except where required by law or expressly permitted under the Agreement.
4. Customer Instructions
Customer instructs FlexOrch to process Customer Data as necessary to provide the Services.
Customer may provide additional documented instructions through configuration settings, workspace settings, API requests, order forms, support requests or written communication.
FlexOrch shall promptly inform Customer if, in FlexOrch's reasonable opinion, an instruction infringes applicable Data Protection Laws.
5. Categories of Personal Data
The Personal Data processed may include, depending on Customer's use of the Services:
- names and surnames;
- email addresses;
- phone numbers;
- physical addresses;
- national identification numbers;
- tax identification numbers;
- employee, contractor or customer identifiers;
- financial, invoice, payment or purchase order data;
- contract-related personal data;
- HR, payroll or recruitment-related data;
- document metadata;
- any other Personal Data contained in documents uploaded by Customer.
Customer controls which data is submitted to the Services.
6. Categories of Data Subjects
Data Subjects may include, depending on Customer's use of the Services:
- Customer's employees;
- contractors;
- suppliers;
- customers;
- end users;
- business contacts;
- legal representatives;
- applicants or candidates;
- other individuals whose Personal Data appears in Customer documents.
7. Duration of Processing
FlexOrch processes Personal Data for the duration of the Agreement and only as long as necessary to provide the Services, unless a longer retention period is required by law or requested by Customer.
Upon termination of the Agreement or upon Customer's written request, FlexOrch will delete or return Customer Data in accordance with the Agreement, product functionality and applicable retention policies.
8. Confidentiality
FlexOrch shall ensure that persons authorized to process Personal Data are bound by confidentiality obligations or are subject to appropriate statutory confidentiality obligations.
FlexOrch shall limit access to Personal Data to personnel, contractors and Sub-processors who need access for the purpose of providing, securing, maintaining or supporting the Services.
9. Security Measures
FlexOrch shall implement appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. Such measures include:
- HTTPS/TLS encryption in transit;
- access controls for APIs and workspaces;
- API key-based authentication with SHA-256 hashing of stored credentials;
- tenant and workspace-level data separation;
- AES encryption of stored connector credentials;
- restricted production access;
- environment-specific secrets management;
- logging and monitoring of processing activities;
- data minimization controls;
- PII detection and masking capabilities;
- secure development and deployment practices;
- backup and recovery procedures.
FlexOrch may update its security measures from time to time, provided that such updates do not materially reduce the overall level of protection for Personal Data.
10. PII Detection and Masking
FlexOrch provides tools designed to help detect, classify and mask sensitive fields in documents and datasets.
Customer acknowledges that automated PII detection and masking tools may not identify all Personal Data in all circumstances. Customer remains responsible for reviewing outputs and determining whether exported datasets are appropriate for Customer's intended use.
FlexOrch does not guarantee that all Personal Data will be detected or removed from Customer Data.
11. AI Data Usage
FlexOrch does not use Customer documents or generated datasets to train public AI models.
Customer Data is processed only to provide the requested document processing, extraction, masking, quality scoring, dataset generation, export, support, security and maintenance functionality.
Where Customer enables a premium AI engine or a bring-your-own API key configuration, document content may be transmitted to the selected external AI provider in accordance with Customer's configuration. Customer is responsible for reviewing the relevant settings, data flows and the third-party provider's terms.
12. Sub-processors
Customer authorizes FlexOrch to engage Sub-processors to support the provision of the Services.
FlexOrch shall ensure that Sub-processors are subject to written obligations that provide a level of data protection substantially similar to this DPA.
A current list of Sub-processors is maintained at flexorch.com/legal/subprocessors and updated when material changes occur.
Customer may object to a new Sub-processor on reasonable data protection grounds. If the parties cannot resolve the objection, Customer may terminate the affected Services in accordance with the Agreement.
13. International Data Transfers
FlexOrch primarily uses EU-based infrastructure. Customer Data is hosted on servers located in Germany operated by Hetzner Online GmbH, which is subject to EU GDPR.
Where Personal Data is transferred outside the European Economic Area, Türkiye or another jurisdiction requiring transfer safeguards, FlexOrch shall ensure that an appropriate transfer mechanism is in place, such as:
- an adequacy decision;
- Standard Contractual Clauses adopted by the European Commission (Commission Implementing Decision (EU) 2021/914 of 4 June 2021);
- approved standard contracts under applicable local law;
- another lawful transfer mechanism recognized under applicable Data Protection Laws.
Where personal data is transferred internationally, FlexOrch ensures that appropriate safeguards are in place in compliance with applicable data protection laws. For details regarding specific transfer mechanisms, contact [email protected].
14. Data Subject Requests
If FlexOrch receives a request from a Data Subject relating to Personal Data processed on behalf of Customer, FlexOrch shall, where legally permitted, promptly notify Customer or direct the Data Subject to contact Customer.
Taking into account the nature of the Processing, FlexOrch shall provide reasonable assistance to Customer in responding to Data Subject requests, to the extent required by applicable Data Protection Laws.
15. Assistance with Compliance
Taking into account the nature of the Processing and the information available to FlexOrch, FlexOrch shall provide reasonable assistance to Customer with:
- security obligations;
- breach notification obligations;
- data protection impact assessments;
- prior consultations with supervisory authorities, where required;
- documentation of processing activities related to the Services.
Such assistance may be subject to reasonable fees where permitted under the Agreement.
16. Personal Data Breach
FlexOrch shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data.
The notification shall include, where available:
- a description of the nature of the breach;
- the categories and approximate number of affected Data Subjects;
- the categories and approximate number of affected records;
- the likely consequences of the breach;
- measures taken or proposed to address the breach;
- contact information for follow-up.
FlexOrch's notification of a breach shall not be construed as an admission of fault or liability.
17. Audit and Information Rights
FlexOrch shall make available information reasonably necessary to demonstrate compliance with this DPA.
Audits must be conducted with reasonable notice, during normal business hours, in a manner that does not disrupt FlexOrch's operations or compromise the security or confidentiality of other customers.
FlexOrch may satisfy audit requests by providing security documentation, policies, summaries, third-party reports, certifications or other evidence of compliance, where available.
18. Return or Deletion of Data
Upon termination of the Agreement or upon Customer's written request, FlexOrch shall delete or return Customer Data, unless retention is required by law or necessary for legitimate security, billing, dispute resolution or compliance purposes.
Deletion from backups may occur according to FlexOrch's backup lifecycle and retention schedule.
19. Customer Responsibilities
Customer is responsible for:
- determining whether the Services are appropriate for its intended processing activities;
- obtaining all required notices, consents and lawful bases;
- ensuring that Customer Data is accurate, lawful and appropriate for processing;
- configuring masking, retention and export settings;
- reviewing outputs before using generated datasets in downstream systems;
- complying with applicable Data Protection Laws.
20. Liability
The parties' liability under this DPA shall be governed by the liability provisions of the Agreement, unless otherwise required by applicable Data Protection Laws.
21. Conflict
In the event of a conflict between this DPA and the Agreement, this DPA shall control with respect to the processing of Personal Data.
If Standard Contractual Clauses or mandatory data transfer terms apply, those clauses shall prevail to the extent required by law.
22. Governing Law
This DPA shall be governed by the governing law specified in the Agreement, unless otherwise required by applicable Data Protection Laws or mandatory transfer mechanisms.
Annex 1 — Details of Processing
Subject Matter: Processing of business documents, structured data, extracted fields, metadata and generated datasets through the FlexOrch platform.
Duration: For the duration of the Agreement and any applicable retention period.
Nature and Purpose: Document upload, extraction, structuring, PII detection, masking, quality scoring, dataset generation, export, API access, support, security, troubleshooting and service maintenance.
Categories of Data Subjects: Customer employees, contractors, suppliers, customers, business contacts, applicants, end users and other individuals whose Personal Data appears in Customer documents.
Categories of Personal Data: Names, emails, phone numbers, addresses, national identifiers, tax identifiers, employee identifiers, financial data, invoice data, contract data, HR data, document metadata and other Personal Data submitted by Customer.
Special Categories of Data: The Services are not intended for processing special categories of Personal Data unless expressly agreed in writing. Customer is responsible for ensuring that such data is not uploaded unless Customer has a lawful basis and appropriate safeguards.
Annex 2 — Technical and Organizational Measures
Access Control: API key-based authentication; raw keys are never stored — only SHA-256 hashes. Workspace and tenant-level data separation. Role-based access controls for team workspaces. Restricted production system access.
Data Protection: HTTPS/TLS encryption for all data in transit. AES encryption (Fernet/AES-128-CBC + HMAC) for stored connector credentials. PII detection and masking across 46 personal data types. Data minimization by design. Customer-controlled deletion via API and dashboard.
Operational Security: Environment-specific secrets management. Containerized deployment with controlled access. Monitoring, structured logging and audit trail. Abuse prevention, rate limiting and IP-based blocking. Incident response procedures.
Infrastructure: Primary infrastructure: Hetzner Online GmbH, Germany (EU). Separation of application, database and processing layers. Automated daily database backups with 7-day retention.
Annex 3 — Sub-processors
A current and up-to-date list of Sub-processors is maintained at flexorch.com/legal/subprocessors. The list is updated when Sub-processors are added, changed or removed.
Request a Signed DPA
Enterprise customers requiring a countersigned DPA may request one by contacting [email protected]. Please include your company name and intended use case.