Enterprise Data Protection Addendum
This Data Processing Agreement (“DPA”) forms an integral part of the Flozo Terms of Service between GLOBIZS Web Solutions (“Processor”) and the customer organization (“Controller”). It sets forth rigorous technical and contractual guarantees safeguarding all customer personal data processed through Flozo.Purpose, Scope & Applicability
This DPA applies to the processing of personal data by Flozo in connection with providing organization-scoped communication, chat relay, media hosting, and user directory services.
This DPA satisfies the formal requirements of Article 28 of the General Data Protection Regulation (GDPR / UK GDPR), and constitutes a binding service provider agreement under the California Consumer Privacy Act (CCPA / CPRA).
Roles of the Parties
The Customer determines the purposes and means of processing personal data within its workspace, including employee invites, channel access, and message retention rules.
Flozo processes personal data solely on behalf of, and pursuant to the documented instructions of, the Customer, to provide and maintain the workspace platform.
Categories of Data & Data Subjects
The types of personal data and categories of data subjects processed under this DPA comprise:
- Data Subjects: Employees, contractors, collaborators, and administrators authorized by the Customer to access the Flozo organization workspace.
- Identity & Contact Data: Full name, telephone number, corporate email address, profile avatar, job designation, department.
- Communications & Payloads: Direct messages, channel discussions, files, audio recordings, images, reaction emojis, and task allocations.
- Technical Telemetry: Device identifiers, OS versions, FCM / APNs push notification tokens, IP addresses, and session timestamps.
Processor Obligations
As Data Processor, GLOBIZS covenants that it shall:
Process personal data solely on documented instructions from the Controller, unless required to do so by applicable statutory law.
Ensure that all personnel authorized to access customer data have committed themselves to confidentiality agreements or are under an appropriate statutory obligation of confidentiality.
Not sell, rent, release, disclose, or transfer personal data for monetary or other valuable consideration, nor use customer data for any third-party marketing.
Provide reasonable assistance to the Controller in responding to regulatory inquiries and data protection impact assessments (DPIAs).
Technical & Organizational Measures (TOMs)
GLOBIZS implements and maintains appropriate technical and organizational safeguards to ensure a level of security appropriate to the risk, including:
Authorized Sub-Processors
The Controller provides general authorization for Flozo to engage the sub-processors listed below to support the infrastructure. Flozo imposes data protection terms on each sub-processor no less protective than those set forth in this DPA.
| Sub-Processor | Activity / Scope | Location | Transfer Mechanism |
|---|---|---|---|
| Google LLC (Firebase) | Push message delivery, performance telemetry & crash analytics | United States / Global | Standard Contractual Clauses (SCCs) |
| Apple Inc. (APNs) | Apple Push Notification service dispatch for iOS devices | United States | Standard Contractual Clauses (SCCs) |
Flozo will notify Customer at least 30 days prior to onboarding any new critical sub-processor, providing the Controller opportunity to review and object on valid data protection grounds.
Assistance with Data Subject Rights
Flozo provides self-service tools and technical interfaces allowing Controllers to fulfill their obligations to respond to Data Subject requests (Access, Correction, Portability, Erasure).
In accordance with Apple App Store Review Guideline 5.1.1(v), individual users can also directly initiate complete account and credential deletion in-app via Settings → Account → Delete My Account.
Security Incident & Breach Notification
In the event of a confirmed Personal Data Breach affecting Customer data, GLOBIZS shall notify the Controller without undue delay (and in any event within 48 to 72 hours of becoming aware of the breach).
The notification will describe the nature of the incident, affected data categories, estimated number of data subjects, likely consequences, and the remediation measures undertaken or proposed.
Data Return & Permanent Deletion
Upon termination of Customer's workspace or upon written request by the Controller, GLOBIZS shall securely delete all Customer personal data from active server databases within 30 days, unless applicable statutory law requires further retention.
International Data Transfers (SCCs)
Where the performance of services involves cross-border transfers of personal data originating from the EEA, Switzerland, or the UK to countries not deemed adequate by the European Commission, the parties agree that the European Commission's Standard Contractual Clauses (Module 2: Controller-to-Processor) shall apply.
Audits & Compliance Reviews
Upon reasonable prior written notice, GLOBIZS shall make available to Customer information necessary to demonstrate compliance with this DPA, and allow for reasonable audits or inspections conducted by Customer or an independent auditor.
DPO Contact & Inquiries
For DPA execution, custom enterprise terms, or data protection officer inquiries, please contact:
Enterprise Compliance & Security Assurance
