Document ID: O-02
Agreement version: 2026-08-22.1
Version and date: 2026-08-22.1 - 22 August 2026
Processor: FlowDule ApS, CVR 46273397, Syrenvænget 8, 8362 Hørning
Contact: privacy@flowdule.com - security incidents are to be reported immediately via the designated security channel
Function of the agreement: This agreement satisfies the minimum contractual requirements in Article 28(3) to (4) GDPR. It becomes customer-specific and operationally complete only together with the completed Customer Annex A, the version-bound TOMs annex and the accepted sub-processor list.
1. Parties, entry into force and basis of the agreement
The agreement is entered into between the undertaking or sole trader that subscribes to FlowDule (“the controller”) and FlowDule ApS (“the processor”). It forms an integral part of the customer’s agreement for FlowDule and applies from the documented acceptance or from the later date stated in Customer Annex A.
Only a person who is documented as authorised to bind the controller may accept the agreement and the annexes. FlowDule records at least the customer, the accepter, the authority, the versions, the document hash, the method and the time. Material changes are notified in accordance with section 16 and may be accepted actively in the platform or by continued use after the effective date.
The agreement governs solely FlowDule’s processing on behalf of the controller. FlowDule’s processing for its own contractual, invoicing, user administration, support, security and statutory purposes is described in FlowDule’s privacy policy and falls outside this agreement.
2. Subject matter and duration of the processing
FlowDule makes available a multi-tenant SaaS platform with the modules selected by the controller, for example booking, client administration, health records and documentation, communication, payment, webshop/event, reporting and optional AI assistance.
The processing lasts for as long as FlowDule provides the service, and for the controlled export, return, erasure and backup period after termination. Purposes, modules, data subjects, data categories, processing locations and retention are set out in Customer Annex A.
3. Nature and purpose of the processing
The processing may comprise collection, recording, organisation, storage, retrieval, display, adaptation, transmission on instructions, restriction, export and erasure. The purpose is solely to provide, secure, maintain and support the functions that the controller has ordered and instructed.
FlowDule must not use the customer’s client or health record data for marketing, general product analysis, model training or other secondary purposes of its own. Operational telemetry may be used only for FlowDule’s own security and operational purposes, where it does not involve reuse of the customer’s content and the processing has an independent lawful basis.
4. Data subjects and personal data
| Category | Expected content |
|---|---|
| Data subjects | The customer’s clients, patients or users; the customer’s practitioners, employees and administrators; relevant contact persons. Minors, guardians and powers of attorney may be covered only following separately approved instructions and technical activation. |
| Ordinary personal data | Identity and contact details, appointments, attendance, purchases and payment, correspondence, user and device data as well as activity and audit metadata. |
| Special categories | Health data and other sensitive content in record notes, plans, measurements, reports, attachments, images, audio or transcription, where the customer enables the relevant features. |
| Criminal convictions/offences | Not a separately planned category, but may occur in the customer’s free text. May be processed only where the customer documents a lawful basis and a need. |
The final delimitation is made in Customer Annex A. The customer must not enable a category or group of data subjects that is not covered by the accepted instructions.
5. Documented instructions
FlowDule processes personal data solely on documented instructions from the controller, including in relation to transfers to third countries. The instructions consist of this agreement, Customer Annex A, the customer’s accepted configurations and subsequent written directions that FlowDule has accepted.
-
Where EU law or Danish law requires processing outside the instructions, FlowDule informs the customer of the requirement before the processing, unless the law prohibits such information on important grounds of public interest.
-
FlowDule informs the customer immediately if, in FlowDule’s assessment, an instruction infringes GDPR or other data protection law, and may suspend the action concerned while the parties clarify the matter.
-
New modules, AI use cases, data categories, regions or purposes are not automatically covered. They require updated instructions and, where the change is material, new acceptance.
6. The controller’s obligations
The controller determines the purposes and the essential means and is responsible for ensuring that the instructions and the processing are lawful. This includes, among other things, the basis for processing under Articles 6 and 9, national legal bases, the duty to provide information, data subject rights, professional record keeping and retention requirements, user management and any consents.
The customer must select the correct professional profile. A self-employed psychotherapist is not, by virtue of the title alone, covered by the record keeping rules that apply to authorised healthcare professionals. Where the customer is an authorised healthcare professional or covered by special rules, the relevant profile and retention must be documented before production use.
7. Confidentiality and access
FlowDule ensures that persons with access to personal data are subject to appropriate confidentiality and process the data only on instructions. Access is granted on the basis of a work-related need, least privilege and personal identity, and is reviewed regularly.
Support access to the customer’s content requires a specific case or other documented necessity, appropriate approval and logging. Emergency access must be time-limited, reviewed afterwards and closed immediately once the need has ceased.
8. Security of processing
FlowDule implements and maintains appropriate technical and organisational measures under Article 32, having regard to the nature, scope, context and purposes of the processing and to the risk. The binding measures are set out in the version- and hash-bound TOMs annex accepted with Customer Annex A.
-
access control, authentication, role and privilege management as well as logging and subsequent review
-
encryption in transit and, where relevant, at rest, key and secret management as well as environment separation
-
vulnerability, change, patch and supplier management
-
backup, restoration, continuity, erasure and documented controls
-
incident preparedness and regular testing and assessment of the effectiveness of the measures
Internal targets for backup, RPO, RTO or response times are not customer guarantees unless expressly incorporated into an accepted SLA or Customer Annex A. FlowDule must not describe a control as implemented until the evidence register shows that it actually works in production.
9. Assistance to the controller
Taking into account the nature of the processing and the information available to FlowDule, FlowDule assists the customer in fulfilling the obligations under Articles 12 to 23 and Articles 32 to 36.
-
Data subject rights: search, access, export, rectification, restriction and erasure, where the platform and the law permit. FlowDule does not respond to the data subject directly without the customer’s instructions.
-
Security and breaches: relevant technical information, incident data and remediation in accordance with section 11.
-
Impact assessment and prior consultation: product, security, supplier and processing information that the customer reasonably requires. FlowDule’s product DPIA does not replace the customer’s own assessment.
-
Requests from authorities: FlowDule informs the customer unless legally prohibited, and discloses data only on a valid legal basis and as narrowly as possible.
Ordinary, reasonable assistance is included. Disproportionately extensive special work may be invoiced following prior notice and acceptance, unless the need is due to FlowDule’s breach.
10. Sub-processors
The customer gives general written authorisation for the sub-processors set out in the accepted list. The list states at least the legal entity, service/purpose, data categories, processing countries, any third-country transfers and the basis for them.
FlowDule gives notice of a planned addition or replacement at least 30 days before it takes effect. The customer may raise a duly reasoned data protection objection within the deadline. The parties seek a reasonable solution; if no solution is found, the customer may terminate the affected service with effect from the date of the change and receive a proportionate refund of any unused prepayment for that part.
FlowDule enters into a written agreement imposing on the sub-processor at least the same relevant data protection obligations, and FlowDule remains fully liable to the customer for the sub-processor’s performance of them.
11. Personal data breaches
FlowDule informs the customer without undue delay after becoming aware of a breach concerning the customer’s personal data. The target is a first notification no later than 24 hours after internal confirmation; this target does not limit the requirement to notify without undue delay.
The notification is given in phases where necessary and contains, as far as possible, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed and a point of contact. FlowDule documents the incident and cooperates on containment and investigation.
As controller, the customer decides on notification to the Danish Data Protection Agency and communication to data subjects. FlowDule does not make the notification on the customer’s behalf without express written instructions.
12. Third-country transfers and access by authorities
As a general rule, the processing takes place within the EU/EEA in the regions set out in Customer Annex A and the sub-processor list. Remote access from a third country is also a transfer and must be covered by the instructions.
Any transfer without an adequacy decision requires a valid basis under Chapter V GDPR, normally the European Commission’s applicable standard contractual clauses, together with a documented transfer impact assessment and the necessary supplementary measures. FlowDule must not rely on general contractual wording alone where the actual supplier, support or access chain has not been verified.
Where FlowDule or a sub-processor receives a request from an authority, the validity and scope are examined, the customer is informed where lawful, and only what is necessary is disclosed. FlowDule documents the request and challenges disproportionate or unlawful demands where there are reasonable grounds to do so.
13. Audit, documentation and supervision
FlowDule makes available all information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the customer or by an independent auditor mandated by the customer.
Verification is carried out on a risk basis and normally begins with an updated TOMs annex, supplier and control material, test results and relevant independent reports. The customer may carry out a further audit once a year and, in addition, following a breach, an order from an authority or a documented specific suspicion of material non-compliance.
An audit is normally notified at least 30 days in advance, is limited to the customer’s processing and is carried out without access to other customers’ data, credentials or details that would create a new security risk. The customer bears reasonable separate costs, unless the audit reveals a material breach on FlowDule’s part. These limitations must not prevent a necessary audit or the powers of a competent authority.
14. Return, export and erasure
On termination, FlowDule erases or returns, at the customer’s choice, all personal data and existing copies, unless EU law or Danish law requires retention. The customer’s choice and any exceptions are documented.
-
The customer may export data during the term of the agreement and for at least 30 calendar days after the agreed transition period. Formats, data categories, relations and metadata follow the Terms of Service and the applicable export description.
-
After the extraction period, production data is erased under controlled conditions. FlowDule issues a deletion receipt stating the customer, instruction/version, categories, time, responsible party, backup expiry and any lawful exceptions - without the deleted content.
-
Backup copies are erased through documented rotation. Until expiry they are isolated and subject to the same protection and must not be reintroduced into ordinary operation. On restore, the deletion ledger and valid legal holds are reapplied before the environment is opened.
-
FlowDule’s bookkeeping obligation may cover its own invoicing and accounting data, but does not in itself provide a basis for retaining the customer’s client or health record data.
15. AI features
AI features may process personal data only where the specific use case, model/supplier, data categories, region and retention have been enabled in Customer Annex A. Output is a draft that a competent user must actively review and approve before storage, communication or professional use.
AI must not make an independent diagnosis, triage, treatment decision, access decision or other automated individual decision. The customer’s client and health record data must not be used to train general models. FlowDule must be able to document supplier terms, data flows, retention and erasure before activation in production.
16. Amendments and order of precedence
FlowDule may propose amendments in response to legal, security or product changes. An amendment must not unilaterally expand purposes, data categories, AI use cases, regions or transfers, or lower the level of protection. Material changes are notified at least 30 days before they take effect. The controller may accept the change in the platform before that date or object to it. If the controller continues to use the platform after that date, that continued use is regarded as acceptance of the new version, and the acceptance is recorded with the version, the document hash and the time of the notice. If the controller does not wish to be bound, the affected parts of the agreement may be terminated with effect from the time at which the change would take effect.
| Priority | Document |
|---|---|
| 1 | Lawful specific written instructions that FlowDule has expressly accepted. |
| 2 | Customer Annex A with accepted choices, versions and hashes. |
| 3 | The accepted, version-bound TOMs annex. |
| 4 | This data processing agreement. |
| 5 | The Terms of Service and other product documentation. |
A later instruction takes precedence only within its express scope and must not require FlowDule to act unlawfully. In the event of a conflict concerning the processing of personal data, this agreement and the annexes prevail over the terms of service.
17. Liability, termination and governing law
The parties’ liability follows Article 82 GDPR and mandatory law. Any contractual limitations follow the Terms of Service, but cannot limit the rights of data subjects or authorities or derogate from liability that cannot lawfully be limited.
The agreement terminates when FlowDule no longer processes personal data on the customer’s behalf and all return, erasure and documentation obligations have been fulfilled. Provisions on confidentiality, audit, liability and documentation survive to the extent their purpose so requires.
The agreement is governed by Danish law. The venue follows the Terms of Service, without this limiting the powers of the Danish Data Protection Agency or other competent authorities.
Annex A - customer-specific documented instructions
The annex is completed and accepted per customer as part of onboarding and is stored together with the customer’s acceptance evidence. The template’s fields are shown below. A field that has not been completed and confirmed for the customer means that the processing in question is not approved for production.
| Field | Completed per customer |
|---|---|
| Customer, CVR/registration, country | Completed at onboarding |
| Accepter, role and authority | Completed at onboarding |
| DPA, TOMs and sub-processor list: version/hash | Completed at onboarding |
| Enabled modules and processing purposes | Completed at onboarding |
| Data subjects and data categories | Completed at onboarding |
| Professional profile, Article 6/9 and national legal bases | Completed at onboarding |
| Retention profile and documented justification | Completed at onboarding |
| AI use cases, model, human gate and retention | Not activated unless the customer has completed and accepted the field |
| Operational, support and AI regions | Completed at onboarding |
| Sub-processors, transfers and objections | Completed at onboarding |
| Minors, guardians, powers of attorney | Not covered unless the customer has completed and accepted the field |
| The customer’s privacy, security and DPO contacts | Completed at onboarding |
| Entry into force, proof of acceptance and next review | Completed at onboarding |
Annex B - technical and organisational measures
The accepted TOMs annex is identified by title, version and document hash in Annex A. The annex is provided to the customer on acceptance of the agreement and can be requested at any time via privacy@flowdule.com. The public Security description is informational only; in the event of a discrepancy, the accepted TOMs annex prevails.
Annex C - sub-processors and transfers
The accepted public sub-processor list is identified by version and hash in Annex A. Before use, FlowDule must verify the actual legal entity, service, purpose, data, region, support access, contract/DPA, transfer basis, TIA and relevant supplementary measures. A lack of evidence means that the supplier or the feature must not be activated with personal data.