HomeLegalData Processing Agreement

Data Processing Agreement

This Data Processing Agreement (DPA) governs the processing of personal data by GLOBIZS on behalf of organizations utilizing Flozo, in accordance with GDPR Article 28 and global privacy standards.

Effective:March 31, 2025
Last Updated:September 16, 2026
Platform:iOS, Android & Web
View on App Store

Enterprise Data Protection Addendum

This Data Processing Agreement (“DPA”) forms an integral part of the Flozo Terms of Service between GLOBIZS Web Solutions (“Processor”) and the customer organization (“Controller”). It sets forth rigorous technical and contractual guarantees safeguarding all customer personal data processed through Flozo.
01

Purpose, Scope & Applicability

This DPA applies to the processing of personal data by Flozo in connection with providing organization-scoped communication, chat relay, media hosting, and user directory services.

This DPA satisfies the formal requirements of Article 28 of the General Data Protection Regulation (GDPR / UK GDPR), and constitutes a binding service provider agreement under the California Consumer Privacy Act (CCPA / CPRA).

02

Roles of the Parties

Customer is Data Controller

The Customer determines the purposes and means of processing personal data within its workspace, including employee invites, channel access, and message retention rules.

Flozo (GLOBIZS) is Data Processor

Flozo processes personal data solely on behalf of, and pursuant to the documented instructions of, the Customer, to provide and maintain the workspace platform.

03

Categories of Data & Data Subjects

The types of personal data and categories of data subjects processed under this DPA comprise:

  • Data Subjects: Employees, contractors, collaborators, and administrators authorized by the Customer to access the Flozo organization workspace.
  • Identity & Contact Data: Full name, telephone number, corporate email address, profile avatar, job designation, department.
  • Communications & Payloads: Direct messages, channel discussions, files, audio recordings, images, reaction emojis, and task allocations.
  • Technical Telemetry: Device identifiers, OS versions, FCM / APNs push notification tokens, IP addresses, and session timestamps.
04

Processor Obligations

As Data Processor, GLOBIZS covenants that it shall:

Documented Instructions Only

Process personal data solely on documented instructions from the Controller, unless required to do so by applicable statutory law.

Personnel Confidentiality

Ensure that all personnel authorized to access customer data have committed themselves to confidentiality agreements or are under an appropriate statutory obligation of confidentiality.

No Commercial Exploitation

Not sell, rent, release, disclose, or transfer personal data for monetary or other valuable consideration, nor use customer data for any third-party marketing.

Assistance to Controller

Provide reasonable assistance to the Controller in responding to regulatory inquiries and data protection impact assessments (DPIAs).

05

Technical & Organizational Measures (TOMs)

GLOBIZS implements and maintains appropriate technical and organizational safeguards to ensure a level of security appropriate to the risk, including:

🔒 Cryptographic ProtectionTLS 1.2 or higher for all data in transit; AES-256 encryption at rest for databases and backups; secure enclaves (Keychain / Keystore) on client devices.
🛡️ Access Controls & SegregationMulti-tenant data isolation; role-based access control (RBAC); strict principle of least privilege with mandatory multi-factor authentication for engineers.
⚡ Resiliency & BackupsAutomated daily encrypted snapshots with geo-redundant storage and tested disaster recovery failover workflows.
🔍 Vulnerability AssessmentsContinuous automated code vulnerability scanning, dependency checks, and regular third-party security evaluations.
06

Authorized Sub-Processors

The Controller provides general authorization for Flozo to engage the sub-processors listed below to support the infrastructure. Flozo imposes data protection terms on each sub-processor no less protective than those set forth in this DPA.

Sub-ProcessorActivity / ScopeLocationTransfer Mechanism
Google LLC (Firebase)Push message delivery, performance telemetry & crash analyticsUnited States / GlobalStandard Contractual Clauses (SCCs)
Apple Inc. (APNs)Apple Push Notification service dispatch for iOS devicesUnited StatesStandard Contractual Clauses (SCCs)

Flozo will notify Customer at least 30 days prior to onboarding any new critical sub-processor, providing the Controller opportunity to review and object on valid data protection grounds.

07

Assistance with Data Subject Rights

Flozo provides self-service tools and technical interfaces allowing Controllers to fulfill their obligations to respond to Data Subject requests (Access, Correction, Portability, Erasure).

In accordance with Apple App Store Review Guideline 5.1.1(v), individual users can also directly initiate complete account and credential deletion in-app via Settings → Account → Delete My Account.

08

Security Incident & Breach Notification

In the event of a confirmed Personal Data Breach affecting Customer data, GLOBIZS shall notify the Controller without undue delay (and in any event within 48 to 72 hours of becoming aware of the breach).

The notification will describe the nature of the incident, affected data categories, estimated number of data subjects, likely consequences, and the remediation measures undertaken or proposed.

09

Data Return & Permanent Deletion

Upon termination of Customer's workspace or upon written request by the Controller, GLOBIZS shall securely delete all Customer personal data from active server databases within 30 days, unless applicable statutory law requires further retention.

10

International Data Transfers (SCCs)

Where the performance of services involves cross-border transfers of personal data originating from the EEA, Switzerland, or the UK to countries not deemed adequate by the European Commission, the parties agree that the European Commission's Standard Contractual Clauses (Module 2: Controller-to-Processor) shall apply.

11

Audits & Compliance Reviews

Upon reasonable prior written notice, GLOBIZS shall make available to Customer information necessary to demonstrate compliance with this DPA, and allow for reasonable audits or inspections conducted by Customer or an independent auditor.

12

DPO Contact & Inquiries

For DPA execution, custom enterprise terms, or data protection officer inquiries, please contact:

GLOBIZS — Data Protection Office

Enterprise Compliance & Security Assurance

Effective March 31, 2025 · © 2026 GLOBIZS. All rights reserved.
contact@globizs.com
Flozo Cosmic Background
Flozo

Ready to bring your organization together?