1Scope and parties
This Data Processing Addendum (“DPA”) is between Flowsier LLC, a Wyoming (United States) limited liability company (“SymoLink”, “we”) and the agency or business that accepted the SymoLink Terms of Service (“you”). It is part of the Terms and applies whenever we process personal data in your data (“Customer Personal Data”) while providing SymoLink. You accept it when you accept the Terms.
Words such as “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meanings in the EU General Data Protection Regulation (“GDPR”). “Data Protection Laws” means every privacy law that applies to the processing, including the GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended (“CCPA”) and other US state privacy laws, Canada’s PIPEDA, and the Philippine Data Privacy Act of 2012.
2Roles
- For Customer Personal Data, you are the controller and we are your processor.
- If you are an agency processing data for your clients, your clients are the controllers, you are their processor, and we are your sub-processor. You confirm that your clients have authorised you to appoint us, and you pass our help and notices on to them. We deal only with you, not with your clients.
- For our own account and billing data, we are a separate controller, as our Privacy Policy explains. This DPA does not cover that data.
- You are responsible for having a lawful basis, giving the notices and getting the consents your contacts need, including for texts, calls and call recording.
3Your instructions
We process Customer Personal Data only on your documented instructions. Your instructions are: the Terms and this DPA, the way you and your users set up and use SymoLink (for example connecting a CRM, turning on recording or AI summaries, linking a WhatsApp account, choosing sending limits), and any other written instruction we agree to. We do not process it for any other purpose, unless a law requires it; in that case we tell you first, unless the law forbids it. If we believe an instruction breaks Data Protection Laws, we will tell you.
When you connect a service you choose (your CRM, your mobile carrier, your own AI provider accounts, WhatsApp, or your own email or payment accounts), sending data to that service is your instruction. Those services are your own providers, not our sub-processors, and their terms are between you and them.
4Confidentiality
Only people who need it to run, secure or support SymoLink can access Customer Personal Data, and they are bound to keep it confidential. Our support team opens your account only while you allow it (Agency Settings → SymoLink support), and each visit is written in your audit log.
5Security
We take appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, change, disclosure or access, taking into account the risks and the state of the art. The measures we have in place today are in Annex 2. We may improve them over time, but we will not make them less protective overall.
You are responsible for the security of what you control: your users’ passwords, who you let in, your gateway phones and Boxes, your CRM and the services you connect.
6Sub-processors
- You give us general authorisation to use the sub-processors in Annex 3.
- Each sub-processor is bound by a written contract with data protection terms at least as protective as this DPA. We remain responsible to you for their work.
- Before we add or replace a sub-processor, we update Annex 3 and email account Owners at least 30 days ahead (sooner only in an emergency, such as a provider’s sudden failure).
- You can object on reasonable data protection grounds within that time by emailing [email protected]. We will try to find a solution. If we cannot, you may end the affected part of SymoLink and we will refund any fees paid in advance for it.
7Help with people’s requests
Much of what you need to answer requests from your contacts (to see, correct or delete their data) you can do yourself in the dashboard: find a contact and its messages and calls, delete messages and contacts, or delete a client account. If you need more help, we will help you within reason. If someone contacts us directly about Customer Personal Data, we will pass the request to you and not answer it ourselves, unless the law requires.
8Breach notice
If we become aware of a personal data breach affecting Customer Personal Data, we will tell you without undue delay, and in any case within 48 hours after we confirm it. We will email the account Owner and tell you, as far as we know them: what happened, the kinds and rough number of people and records affected, the likely effects, and what we have done and will do about it. We will add details as we learn them, take reasonable steps to contain the breach, and help you with any notice you must give to authorities or people. Telling you about a breach is not an admission of fault.
9Assessments and authorities
We will give you reasonable information to help with data protection impact assessments and prior consultations with supervisory authorities about SymoLink, and will cooperate with a supervisory authority when the law requires.
10Deletion and return
- While you use SymoLink: you can delete messages, contacts and whole client accounts at any time in the dashboard. Deletion is immediate in the live system.
- Call recordings and transcripts are deleted automatically after 90 days, or the period you choose.
- Phone health history is deleted after 7 days by default (you can choose 1 to 30).
- After a CRM removes the SymoLink app from a client account, we keep that account’s data for 30 days in case it is installed again. Then we delete its CRM connection and the CRM contact and conversation links. If the client account was created by that install and has no seats, phones or Boxes and no other connection left, we delete the whole client account with its messages, calls and contacts. An account still in use stays until you delete it.
- When your account ends, or when you ask us in writing, we delete Customer Personal Data within 30 days, unless a law requires us to keep part of it. Before then, you can keep copies of what you need; messages and calls are also in your CRM when it is connected.
- Backups: deleted data stays in our encrypted backups until they roll off, within 31 days. Backups are not used for anything except restoring the service.
- On request, we confirm in writing that deletion is done.
11Information and audits
We will make available the information reasonably needed to show that we meet this DPA, such as written answers to security questionnaires and a description of our measures. If that is not enough, or a supervisory authority requires it, you (or an independent auditor bound to confidentiality, not a competitor of ours) may audit our compliance once in any 12 months, with at least 30 days’ written notice, during business hours, without disrupting the service or seeing other customers’ data, and at your own cost.
12International transfers
Customer Personal Data is stored on our servers in Malaysia, with encrypted backups in Cloudflare’s Asia Pacific storage, and may be accessed from or processed in the other countries listed in Annex 3, including the United States, where Flowsier LLC is based. We transfer personal data only as Data Protection Laws allow.
- From the European Economic Area: where the transfer is to a country without an EU adequacy decision, the Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914 (“SCCs”) apply and are part of this DPA: Module Two (controller to processor) where you are a controller, and Module Three (processor to processor) where you are a processor. Clause 7 (docking) applies; under Clause 9 option 2 (general authorisation) applies with the notice period in section 6; the optional wording in Clause 11 does not apply; Clauses 17 and 18 are governed by and settled in the courts of Ireland. Annexes I and II of the SCCs are filled in by Annex 1 and Annex 2 of this DPA, and Annex III by Annex 3. The competent supervisory authority is the one that Clause 13 points to.
- From the United Kingdom: the UK International Data Transfer Addendum to the SCCs (version B1.0, issued by the Information Commissioner) applies, with the details above; either party may end it as its Section 19 allows.
- From Switzerland: the SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, and the Federal Data Protection and Information Commissioner as the supervisory authority.
- If the SCCs conflict with this DPA, the SCCs win. We use the same or equivalent safeguards with our sub-processors.
13US state privacy laws (CCPA)
Where the CCPA or a similar US state law applies, we are your service provider (or processor). We will not: sell or share Customer Personal Data; keep, use or disclose it for any purpose other than the business purposes in this DPA and the Terms, or outside our direct business relationship with you; or combine it with personal information we get from others, except as those laws allow. We will comply with those laws, give the same level of privacy protection they require, and tell you if we can no longer meet them. You may take reasonable steps to stop and fix unauthorised use. We certify that we understand and will comply with these restrictions.
14Liability, term and order
- Each party’s liability under this DPA is subject to the limits in the Terms, except where Data Protection Laws or the SCCs do not allow that.
- This DPA lasts as long as we process Customer Personal Data for you.
- If this DPA conflicts with the Terms, this DPA wins on personal data. If it conflicts with the SCCs, the SCCs win.
- We may update this DPA to follow changes in law or in SymoLink, as the Terms describe, but not to lower its protection for your data during your current subscription without your agreement, unless the law requires it.
15Annex 1: Details of processing
| Item | Details |
|---|---|
| Data exporter | You, the agency or business that accepted the Terms (contact: the account Owner). |
| Data importer | Flowsier LLC, operator of SymoLink. Contact: [email protected]. |
| Subject and purpose | Providing SymoLink: sending and receiving texts and calls through the customer’s gateway phones and Boxes, syncing them with the customer’s CRM, recording and summarising calls when switched on, showing phone health, keeping it secure, and supporting the customer. |
| Nature of processing | Collection through the CRM and phones, storage, organisation, sending to carriers and to services the customer connects, display in the dashboard, deletion. |
| People concerned | The customer’s (and its clients’) contacts, leads and customers who text or call or are texted or called; the customer’s users and staff whose names or numbers appear in messages and calls. |
| Kinds of personal data | Names, phone numbers and CRM contact and conversation IDs; message text, pictures and files; call details (numbers, times, length, outcome); call recordings, transcripts and summaries if switched on; WhatsApp messages if used; gateway phone data (SIM phone numbers and SIM serial numbers, carrier, SIM country, battery, signal, app version, a scrambled device ID); the CRM users a line or Box belongs to. |
| Special categories | None intended. Messages and calls may by chance contain any kind of information people choose to share; the customer decides what it sends and records. |
| How often | Continuously, while the customer uses SymoLink. |
| How long | For the life of the account, with the deletion periods in section 10. |
| Sub-processors | As in Annex 3, for hosting, network, email and payment. |
16Annex 2: Security measures
- Encryption in transit: HTTPS everywhere with HSTS; phones and Boxes connect over encrypted channels, and the Box checks our server’s certificate fingerprint before it connects.
- Encryption at rest: CRM tokens, linked WhatsApp sessions, saved keys and secrets, call recordings and transcripts are encrypted with AES-256-GCM, each item with its own key wrapped by a master key kept outside the database. Backups are encrypted with AES-256 before they leave the server.
- Access control: roles and permissions for every user; each agency’s data kept apart from every other agency’s, with automated tests of that separation; our support access only while the agency allows it, and audited.
- Sign-in protection: passwords stored as Argon2id hashes; lockout after repeated wrong passwords; the password asked again before sensitive actions; short-lived access tokens; sign-in limits per address; a mobile app password and one-time activation codes for linking phones.
- Network: provider and server firewalls; admin tools reachable only through Cloudflare’s protected login; rate limits on every API.
- Logging and monitoring: audit logs of important actions that the agency can read; server monitoring; logs that leave out passwords, tokens and secrets.
- Resilience: nightly encrypted database backups kept for 31 days off the server, with restore tests.
- Data minimisation: no location, IMEI, phone contacts or app lists are collected from gateway phones; the test system uses a scrubbed copy with fake phone numbers and no message text.
- People: access limited to those who need it, bound to confidentiality.
- Development: changes are tested and reviewed for security before release, and released to a test system first.
17Annex 3: Sub-processor list
| Sub-processor | Purpose | Data | Location |
|---|---|---|---|
| Hostinger | Virtual private server: database, application, call recordings | All Customer Personal Data | Malaysia |
| Cloudflare, Inc. | DNS, network proxy and secure tunnel to our servers; email routing for our domains; storage of encrypted backups (R2) | Traffic in transit (encrypted); encrypted backups | Worldwide network; backups in Asia Pacific; United States company |
| Resend | Sending account emails (sign-in, password, invitations, billing) | Users’ names and email addresses | Japan (sending region); United States company |
| Stripe, Inc. | Subscription billing and card payments for agencies and businesses | Billing contact, company name, payment details (held by Stripe) | United States and worldwide |
Not sub-processors: services you connect yourself (your CRM, mobile carriers, OpenAI and Anthropic when you add your own keys for call summaries, WhatsApp, and your own Resend, Stripe, PayMongo, PayPal or Xendit accounts). We send data to them only on your instruction (section 3).
Questions about this DPA: [email protected].
Flowsier LLC, a Wyoming (United States) limited liability company
Postal address: 5830 East 2nd Street, Casper, WY 82609, United States