This Data Processing Addendum ("DPA") amends and forms part of the written agreement between Customer and FlexOps, LLC ("FlexOps") (collectively, "the parties") for the provision of services to Customer (the "Agreement"). This DPA prevails over any conflicting term of the Agreement but does not otherwise modify the Agreement.
- 1. Definitions
- “Controller”, “Data Subject”, “Processing”, “Processor”, “Service Provider”, “Supervisory Authority”
- “Data Protection Law”
- “Data Subject Rights”
- “Restricted Data Transfer”
- “Personnel”
- “Personal Data”
- “Personal Data Breach”
- “Sell”
- “Sensitive Data”
- “Services”
- “Share”
- “Subprocessor”
- “Standard Contractual Clauses (SCCs)”
- “UK Addendum”
- 2. Roles
- 3. Scope
- 4. Instructions
- 5. Customer Responsibilities
- 6. Personnel and Subprocessing
- 7. Restricted Data Transfers
- 8. Security and Personal Data Breaches
- 9. Assistance
- 10. Accountability
- 11. Audit
- 12. Liability
- 13. Confidentiality
- 14. Analytics
- 15. Notifications
- 16. Term and Duration
- 17. Modification
- 18. Invalidity and Severability
- Annex I — Description of Processing
- Annex II — Technical & Organizational Measures
- Annex III — Subprocessors
- 19. Contact Us
1. Definitions
In this DPA:
“Controller”, “Data Subject”, “Processing”, “Processor”, “Service Provider”, “Supervisory Authority”
Have the meanings given to them under Data Protection Law.
“Data Protection Law”
Means:
- GDPR (EU 2016/679) and all laws of the EU, EEA, Member States, Switzerland, UK
- Relevant U.S. federal & state privacy laws (including CCPA/CPRA)
- All laws implementing or supplementing the above
“Data Subject Rights”
Includes rights of access, rectification, erasure, restriction, portability, objection, and freedom from automated decision-making.
“Restricted Data Transfer”
An international transfer prohibited without safeguards such as SCCs.
“Personnel”
Any natural person acting under FlexOps’ authority.
“Personal Data”
Information defined as personal data under applicable Data Protection Law that FlexOps Processes on behalf of Customer.
“Personal Data Breach”
Unauthorized destruction, loss, alteration, disclosure, or access to Personal Data for which FlexOps is responsible. Does not include unsuccessful attempts such as:
- Failed login attempts
- Pings
- Port scans
- DoS attacks
- General network attacks
“Sell”
Selling, renting, releasing, disclosing, or otherwise making Personal Data available for monetary or valuable consideration.
“Sensitive Data”
Special category or sensitive personal data requiring enhanced protections.
“Services”
All services/products provided under the Agreement, including:
- Delivery of Services
- Related rights/obligations
- Maintaining records
- Legal or regulatory compliance
“Share”
Disclosure of Personal Data to third parties for targeted advertising across services.
“Subprocessor”
A Processor engaged by FlexOps.
“Standard Contractual Clauses (SCCs)”
EU Commission SCCs (2021/914), as amended or replaced.
“UK Addendum”
UK IDTA Addendum to SCCs.
Capitalized terms not defined here follow the Agreement.
2. Roles
If Data Protection Law applies:
- FlexOps acts as a Processor on behalf of Customer.
- Under CCPA/US state laws, FlexOps acts as a Service Provider. This applies whether Customer is a Controller or a Processor for a third-party Controller.
3. Scope
This DPA applies to all Processing of Personal Data by FlexOps in connection with the Agreement.
Annex I contains:
- Subject matter
- Nature & purpose
- Types of Personal Data
- Data Subject categories
4. Instructions
FlexOps will only Process Personal Data to provide the Services.
FlexOps certifies that it will not:
- Sell or Share Personal Data
- Process Personal Data outside the business relationship
- Process for purposes other than providing the Services (unless legally required)
- Combine Customer Personal Data with unrelated datasets
Customer instructions are contained in:
- Annex I
- The Agreement
- Any statements of work
Customer may issue additional written instructions. FlexOps may charge reasonable fees to comply.
Disclosure of Personal Data by Customer is not consideration under the Agreement.
5. Customer Responsibilities
Customer is responsible for:
- Lawfulness of Processing
- Providing notices & obtaining consents
- Ensuring transfer & collection of Personal Data complies with law
- Ensuring instructions comply with law
- Configuring security settings appropriate to the Personal Data
6. Personnel and Subprocessing
6.1 Confidentiality
FlexOps ensures all Personnel are bound by confidentiality obligations.
6.2 Authorized Subprocessors
Customer authorizes:
- Subprocessors listed in Annex III
- Subprocessors added under Section 6.3
6.3 New Subprocessors
FlexOps will notify Customer before adding new Subprocessors. Customer may object on reasonable grounds relating to Data Protection Law within 30 days.
If objection cannot be resolved:
- FlexOps may propose an alternative
- If no resolution is possible, FlexOps may terminate the Agreement immediately
- Customer must pay for Services rendered to date
6.4 Subprocessor Agreements
FlexOps will impose substantially similar obligations on Subprocessors. FlexOps remains fully liable for their performance.
6.5 Subprocessor Contracts Upon Request
FlexOps will provide copies of Subprocessor contracts (commercially sensitive portions may be redacted).
7. Restricted Data Transfers
7.1 EEA Transfers — SCCs Module 2
By agreeing to the DPA, the parties conclude SCCs (Module 2 — Controller → Processor). Key elements:
- Exporter: Customer
- Importer: FlexOps
- Clause 7 docking clause: Implemented
- Clause 9(a) option 2: 30 days
- Clause 11(a) optional clause: Struck
- Clause 17: Irish law
- Clause 18(b): Irish courts
- Annexes I–III apply
7.2 UK Transfers — UK Addendum
The UK Addendum is incorporated by reference. Details correspond to SCCs Module 2 mapping.
8. Security and Personal Data Breaches
FlexOps implements industry-appropriate technical and organizational measures, including those in Annex II.
8.2 Data Breach Notification
FlexOps will notify Customer without undue delay. Notification does not imply fault or liability.
8.4 Customer Responsibilities
Customer must comply with laws relating to:
- Notification of individuals
- Notification of regulators
- Investigation procedures
9. Assistance
FlexOps will assist Customer with:
- Data Subject Rights
- Responding to Data Subject inquiries
- Supervisory Authority inquiries
- DPIAs
- Prior consultations
- Data breach notifications
FlexOps will notify Customer if it:
- Receives Data Subject inquiries
- Receives government/legal requests
- Must disclose Personal Data due to legal obligations
- Cannot comply with Data Protection Law
FlexOps requires Customer authorization before responding unless prohibited by law.
10. Accountability
Customer may take action to remediate unauthorized Processing.
FlexOps will notify Customer if instructions violate law and may suspend Processing until resolved.
11. Audit
- One audit per year, upon written request
- FlexOps may object to unsuitable auditors
- Must be during business hours and minimally disruptive
- SOC 2 / ISO / similar reports may substitute
- Customer pays audit costs
- Audit reports are confidential
12. Liability
Liability is limited to the caps in the Agreement.
13. Confidentiality
FlexOps will maintain strict confidentiality of all Personal Data.
14. Analytics
FlexOps may create aggregated, de-identified data derived from Processing and use it for legitimate business purposes, provided that such data cannot reasonably be used to identify Customer, any Data Subject, or any shipment recipient. FlexOps will not use Customer Personal Data to train machine-learning models made available to other customers.
15. Notifications
Notifications will be made as agreed in the Agreement or via the standard point of contact.
16. Term and Duration
Upon termination or request:
- FlexOps will return or delete Personal Data
- FlexOps will certify deletion within 30 days if requested
17. Modification
Only a written amendment signed by both parties may modify this DPA.
18. Invalidity and Severability
Invalid provisions do not affect the remainder. All other provisions stay in force.
Annex I — Description of Processing
A. Parties
Customer = Controller (data exporter) FlexOps = Processor (data importer)
B. Description of Transfer
Subject Matter: FlexOps shipping, logistics, and supply chain services Duration: Term of Agreement Nature & Purpose: Provide Services (label generation, rate calculation, address validation, tracking, order and inventory management, analytics) Frequency: Continuous Categories of Data:
- Shipping data: sender and recipient names, addresses, phone numbers, package details
- Order data: order identifiers, line items, quantities, fulfillment status
- Tracking data: tracking numbers, carrier-provided shipment status events
- Inventory data: part numbers, quantities, warehouse locations, serial numbers
- Financial data: postage amounts, carrier charges, payment references (via Stripe)
- Authentication data: API key hashes, JWT claims, session tokens
- Operational metadata: IP addresses, user agents, correlation IDs, timestamps
- Abuse-prevention signals: IP addresses and network ranges, request-pattern fingerprints, registration domain age, and usage ratios, processed to detect coordinated multi-account abuse and automated quota evasion
Sensitive Data: None expected. FlexOps does not store credit card numbers or bank account details — payment processing is delegated to Stripe. FlexOps never stores passwords in plaintext: where a user signs in with a FlexOps password, only a salted, iterated one-way hash produced by ASP.NET Core Identity is stored; where the Customer federates sign-in through Microsoft Entra ID, no password of any form is stored by FlexOps. Data Subjects: Customer's end users, shipping recipients, warehouse personnel, account administrators
C. Supervisory Authority
Irish Data Protection Commission
Annex II — Technical & Organizational Measures
FlexOps implements the following technical and organizational measures to ensure the security and confidentiality of Personal Data:
Physical Access Control
- Secure data centers with restricted physical access
- 24/7 security monitoring and surveillance
- Access logs and visitor management systems
- Environmental controls (temperature, humidity, fire suppression)
Virtual Access Control
- Multi-factor authentication for all system access
- Role-based access controls (RBAC)
- Regular access reviews and credential rotation
- Network segmentation and firewalls
Data Access Control
- Principle of least privilege for all personnel
- Encrypted data transmission (TLS 1.2+)
- Encrypted data at rest
- Audit logging of all data access
Disclosure Control
- Confidentiality agreements with all personnel
- Secure communication channels
- Data loss prevention (DLP) measures
- Regular security training
Entry Control
- Identity verification for all system access
- Session management and timeout controls
- Intrusion detection and prevention systems
- Security incident response procedures
Availability Control
- Redundant systems and infrastructure
- Regular backups with tested recovery procedures
- Disaster recovery and business continuity plans
- 99.95% uptime target (as specified in the Agreement)
Separation Control
- Logical separation of Customer data
- Segregated processing environments
- Data isolation in multi-tenant systems
- Secure data deletion procedures
Annex III — Subprocessors
Verified against the running configuration on 20 August 2026.
Currently engaged
| Subprocessor | Location | Description |
|---|---|---|
| Microsoft Azure | United States / Global | Cloud hosting, compute, storage, Azure SQL Database, Azure Cache for Redis, Azure Service Bus, Azure Blob Storage, Azure Key Vault |
| Microsoft Entra ID | United States / Global | Federated sign-in, where the Customer chooses to use it. Not used for Customers signing in with a FlexOps password |
| Stripe | United States | Payment processing, billing, invoicing, subscription management |
| Google (Gmail / Google Workspace SMTP) | United States | Outbound transactional email — account verification, two-factor codes, usage and billing notifications |
| Google reCAPTCHA | United States | Spam and abuse protection on website forms |
| Google Analytics | United States | Website usage analytics (marketing site only) |
| Sentry | United States | Application error tracking and performance monitoring |
Configured but not currently enabled
Listed for transparency because credentials exist in configuration. No Personal Data is disclosed to these providers while they remain disabled, and Section 6.3 notice will be given before either is switched on.
| Provider | Location | Description | Status |
|---|---|---|---|
| Plaid | United States | Financial data connectivity and account verification | Disabled by feature flag |
| Twilio | United States | SMS notifications | No sending number configured |
Carriers — independent controllers, not subprocessors
Shipping carriers receive recipient names, addresses, and contact details in order to carry the shipment. They determine their own purposes and means for that data under their own terms of carriage, so they act as independent controllers rather than as FlexOps subprocessors. They are listed here because the disclosure matters regardless of the label.
| Carrier | Location | Data disclosed |
|---|---|---|
| United States Postal Service | United States | Sender and recipient name, address, contact details, package characteristics |
| FedEx | United States | Sender and recipient name, address, contact details, package characteristics |
| UPS | United States | Sender and recipient name, address, contact details, package characteristics |
Data is disclosed to a carrier only when the Customer requests an operation involving that carrier — a rate quote, an address validation, a label purchase, or a tracking lookup.
19. Contact Us
If you have questions about this Data Processing Addendum or our data processing practices, please contact us:
FlexOps, LLC
- Email: privacy@flexops.io
- Support: support@flexops.io
- Legal: legal@flexops.io
For general inquiries, you can also:
- Visit our Support Center
- Submit a support request
- Review our Terms of Service and Cookie Policy
Last Updated: August 20, 2026 Effective Date: April 21, 2023