Data Processing Agreement
Data-processing addendum applicable when FlowMRR processes personal data on behalf of its customers.
Last updated: September 14, 2026
1. Scope and roles
This Data Processing Agreement (“DPA”) supplements the terms applicable to the FlowMRR service. It applies when Flow-MRR processes personal data on a customer’s behalf while providing the service.
The customer acts as controller. Flow-MRR, a French simplified joint-stock company with a sole shareholder (SASU) registered with the Paris Trade and Companies Register (RCS Paris) under number 109 145 771, acts as processor under Article 28 GDPR. This DPA is incorporated into the terms accepted when using or subscribing to the service.
2. Instructions, processing purpose and duration
Documented instructions
Flow-MRR processes personal data only on the customer’s documented instructions, as set out in this DPA, the features configured in FlowMRR, and the customer’s subsequent written instructions, unless required otherwise by law.
Purpose, nature and duration
Processing consists of collecting, hosting, organising, analysing, displaying and returning data needed to provide the service: Stripe revenue analytics, revenue movements, retention, forecasting, cash flow and recovery. Processing continues for the contractual relationship and for the periods needed for offboarding, security and applicable legal obligations.
Data subjects and data categories
Data subjects may include the customer’s authorised users, prospects, customers, subscribers, billing contacts and payers. Data may include identifiers, business contact details, Stripe account data, subscription, billing, payment, activity and correspondence information associated with the features enabled by the customer.
3. Flow-MRR obligations
Confidentiality and security
Flow-MRR ensures that persons authorised to process personal data are bound by confidentiality obligations. Flow-MRR implements appropriate technical and organisational measures, taking account of the state of the art, implementation costs, the nature of processing and risks to data subjects.
Customer assistance
Taking into account the nature of processing and information available, Flow-MRR reasonably assists the customer with data-subject-rights requests, data-protection impact assessments, prior consultations and GDPR security obligations. Requests received directly from a data subject are forwarded to the customer unless Flow-MRR is legally required to respond directly.
Personal data breaches
Flow-MRR notifies the customer without undue delay after becoming aware of a personal data breach affecting data processed on its behalf. Flow-MRR provides reasonably available information to help the customer meet its notification obligations.
4. Other processors
The customer authorises Flow-MRR to engage other processors to provide, secure and improve the service. Flow-MRR imposes data-protection obligations on them that are materially equivalent to those in this DPA.
As of the date of this DPA, the other processors are: Supabase (database and backups, Paris region, EU), Railway (application hosting), Vercel (frontend hosting), Brevo (transactional email, EU) and Amazon Web Services (file storage, eu-west-3 region). Stripe acts as the data source on the customer’s behalf, not as a processor of Flow-MRR.
If there is a material change to the categories of other processors used for the service, Flow-MRR will notify the customer with reasonable notice. The customer may object on legitimate data-protection grounds; the parties will then seek a reasonable solution. If none is possible, the customer may terminate the affected part of the service before the change without penalty for the unused period.
5. International transfers
When a transfer of personal data outside the European Economic Area is necessary, Flow-MRR implements a GDPR-valid transfer mechanism and appropriate safeguards.
6. Anonymised data and internal analysis
Flow-MRR may create and use irreversibly aggregated and anonymised data derived from service use for internal analysis, service improvement, security, statistics and market analysis. This data does not identify the customer, data subjects, or account-specific Stripe information.
Flow-MRR does not sell customer personal data, data from connected Stripe accounts, or data that identifies the customer or its users. Anonymised data is no longer personal data where it cannot reasonably be used to reidentify an individual.
7. Security measures
Flow-MRR maintains technical and organisational measures appropriate to the risk, including access management based on least privilege, user authentication, confidentiality of transmissions, security logging where necessary, incident-management procedures, and measures designed to preserve data availability and integrity. These measures are reviewed as the service and risks evolve.
8. Audit, return and deletion
Audit
Flow-MRR makes available information reasonably necessary to demonstrate compliance with this DPA. An audit may be requested once in any twelve-month period with reasonable advance notice, during business hours and subject to appropriate confidentiality and security requirements.
End of service
At the end of the service, Flow-MRR deletes or returns personal data in line with available functionality and the customer’s instructions, unless retention is required by applicable law. Active data is retained for the contractual relationship; backups are deleted according to applicable security and retention cycles. Irreversibly aggregated and anonymised data may be retained.
Contact: support@flow-mrr.com.