---
title: Data Processing Addendum
description: Discover the key provisions and responsibilities of the Controller and Processor in this data processing agreement.
---

[Skip to content](https://www.zapflow.com/legal/dpa#main-content)

[![Zapflow logo](https://www.zapflow.com/hubfs/Zapflow_logotype_black_RGB-1.svg "Zapflow logo")](https://www.zapflow.com)

 Products ▾

[**Front office**](https://www.zapflow.com/front-office)

[Deal flow management](https://www.zapflow.com/front-office/deal-flow-management)

[Fundraising management](https://www.zapflow.com/front-office/fundraising)

[**Investor relations / IR**](https://www.zapflow.com/investor-relations)

[CRM](https://www.zapflow.com/investor-relations/crm)

[LP portal & reporting](https://www.zapflow.com/investor-relations/lp-portal-and-reporting)

[Capital calls & distribution notices](https://www.zapflow.com/investor-relations/capital-call-distribution-notices)

[**Compliance**](https://www.zapflow.com/compliance)

[KYC & AML](https://www.zapflow.com/compliance/kyc-aml-sanction-list-monitoring)

[Risk management](https://www.zapflow.com/compliance/risk-management)

[**Portfolio management**](https://www.zapflow.com/portfolio-management)

[Portfolio monitoring](https://www.zapflow.com/portfolio-management/monitoring)

[Holdings](https://www.zapflow.com/portfolio-management/holdings)

 Resources ▾

Resources

[News & Blog](https://www.zapflow.com/resources/news-blog)

[Security](https://www.zapflow.com/security)

[Features](https://www.zapflow.com/features-and-integrations)

[Integrations](https://www.zapflow.com/features-and-integrations#feature-integrations)

[Customer stories](https://www.zapflow.com/customer-stories)

[Help center ⟶](https://help.zapflow.com/en)

[Pricing](https://www.zapflow.com/pricing)

- [Book a demo](https://www.zapflow.com/book-a-demo)
- [Login](https://app.zapflow.com/login)

- [Book a demo](https://www.zapflow.com/book-a-demo)
- [Login](https://app.zapflow.com/login)

# Data Processing Appendix

**1. Purpose and scope**  
This Data Processing Appendix ("Appendix") forms part of the Zapflow Terms of Service and the Service Order Form between Zapflow Oy (Zapflow Ltd), business ID 2689962-4 ("Zapflow"), and the customer named in the Service Order Form ("Customer"). These documents together are the "Agreement".

This Appendix applies when Zapflow processes personal data on behalf of Customer to provide the Service. It sets out the terms required by Article 28 of the GDPR.

This Appendix contains standard terms that apply to all customers. Customer-specific data protection requirements must be agreed in a separate data processing agreement signed by both parties ("Separate DPA"). Examples include fixed breach notification deadlines, specific hosting locations, extended audit rights, processing of special categories of personal data, and requirements arising from sector-specific regulation such as DORA.

This Appendix does not cover personal data that Zapflow processes as a controller, such as data relating to account administration, billing, customer communications and the use of Zapflow's websites. That processing is described in the Zapflow Privacy Policy.

 

**2. Definitions**  
Capitalised terms not defined in this Appendix have the meanings given in the Agreement.

\* "GDPR" means Regulation (EU) 2016/679 (General Data Protection Regulation).

\* "Data Protection Laws" means the GDPR and any national laws supplementing it that apply to the processing, including the Finnish Data Protection Act (1050/2018).

\* "Customer Personal Data" means personal data that Zapflow processes on behalf of Customer under the Agreement.

\* "Sub-processor" means a third party engaged by Zapflow that processes Customer Personal Data.

\* "Personal Data Breach" means a personal data breach, as defined in the GDPR, affecting Customer Personal Data.

\*  "Controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in the GDPR.

 

**3. Roles of the parties**  
\* Customer is the controller and Zapflow is the processor of Customer Personal Data.

\* If Customer processes Customer Personal Data on behalf of another controller (for example a fund, an affiliate or a client), Customer confirms that it has that controller's authorisation to engage Zapflow. Zapflow then acts as Customer's sub-processor, and Customer remains Zapflow's sole point of contact.

\* The subject matter, nature, purpose and duration of the processing, and the categories of personal data and data subjects, are described in Annex 1.

 

**4. Customer's responsibilities**  
Customer is responsible for:

\*  having a lawful basis for the processing and providing the information required by Data Protection Laws to data subjects;

\* ensuring that its instructions to Zapflow comply with Data Protection Laws;

\* the accuracy and lawfulness of Customer Personal Data and the means by which it was obtained;

\* ensuring that its Users use the Service in line with the Agreement and this Appendix;

\* the access rights it grants to Users and the settings it applies in the Service; and

\* informing Zapflow without undue delay if it becomes aware of errors or irregularities in the processing.

Customer must not submit special categories of personal data (Article 9 GDPR) or personal data relating to criminal convictions and offences (Article 10 GDPR) to the Service, unless agreed in a Separate DPA.

 

**5. Processing on instructions**  
\* Zapflow processes Customer Personal Data only on Customer's documented instructions, including with regard to transfers outside the European Economic Area (EEA), unless required to do so by EU or Member State law. In that case Zapflow will inform Customer of the legal requirement before processing, unless that law prohibits it.

\* Customer's instructions are the Agreement, including this Appendix, and Customer's and its Users' use and configuration of the Service. Further instructions must be in writing and consistent with the Agreement. Instructions that go beyond the Service's standard functionality require prior written agreement and may be subject to additional fees.

\* Zapflow will inform Customer without delay if, in its opinion, an instruction infringes Data Protection Laws. Zapflow may suspend the affected processing until Customer confirms or changes the instruction, and is not liable for any resulting failure to provide the affected part of the Service.

\* Zapflow does not process Customer Personal Data for its own purposes. Zapflow may create aggregated and anonymised data that no longer identifies any individual or Customer, as permitted by the Agreement.

 

**6. Confidentiality**  
\* Zapflow ensures that everyone authorised to process Customer Personal Data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality.

\* Zapflow limits access to Customer Personal Data to personnel who need it to provide, support, maintain or secure the Service.

 

**7. Security**  
\* Zapflow implements appropriate technical and organisational measures to protect Customer Personal Data as required by Article 32 of the GDPR, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks to data subjects.

\* The baseline measures are described in Annex 2. Zapflow may update the measures over time, provided that the overall level of security is not reduced.

\* Customer is responsible for the security of its own systems and devices, its Users' credentials, and the access rights it grants within the Service.

 

**8. Sub-processors**

\* Customer gives Zapflow a general authorisation to engage Sub-processors. The current Sub-processors are listed in Annex 3.

\* Zapflow will inform Customer of any intended addition or replacement of a Sub-processor at least 30 days before the change takes effect, by email to Customer's contact on record or by notice in the Service.

\* Customer may object to the change on reasonable data protection grounds by written notice within that period. The parties will discuss the objection in good faith. If it cannot be resolved, Customer may terminate the affected part of the Service by written notice before the change takes effect and will receive a refund of any prepaid fees for the period after termination.

\* Zapflow will impose on each Sub-processor, by written contract, the same data protection obligations as those set out in this Appendix.

Third-party services enabled by Customer:

\* If Customer or its Users connect the Service to third-party applications, integrations, data sources or AI providers of Customer's choice (for example through APIs or MCP connections), those providers are not Zapflow's Sub-processors.

\* Any data transferred to those services is transferred on Customer's instruction, and Customer is responsible for its own arrangements with those providers.

 

**9. Transfers outside the EEA**  
Zapflow hosts Customer Personal Data in data centres located in the EEA. Certain add-on services may require transfering Customer Personal Data outside the EEA. only where the transfer complies with Chapter V of the GDPR, for example on the basis of an adequacy decision (including the EU-U.S. Data Privacy Framework for certified recipients) or the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914.

 

**10. Assistance to Customer**  
Data subject requests  
\* Taking into account the nature of the processing, Zapflow assists Customer by appropriate technical and organisational measures, insofar as possible, in responding to requests from data subjects exercising their rights under Data Protection Laws.

\* The Service allows Customer to access, correct, export and delete Customer Personal Data.

\* If Zapflow receives a request directly from a data subject, Zapflow will forward it to Customer without undue delay and will not respond to it, other than to refer the data subject to Customer, unless required by law.

Other assistance  
\* Zapflow provides reasonable assistance to Customer in meeting its obligations under Articles 32 to 36 of the GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to Zapflow.

\* Unless prohibited by law, Zapflow will inform Customer of any request from a supervisory authority or other public authority concerning Customer Personal Data.

Costs  
\* Zapflow may charge reasonable fees for assistance that goes beyond the Service's standard functionality and support, unless the assistance is needed because of Zapflow's breach of this Appendix.

 

**11. Personal Data Breaches**  
Zapflow will notify Customer without undue delay after becoming aware of a Personal Data Breach.. The notification will include, to the extent available to Zapflow, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information may be provided in phases as it becomes available. Zapflow will take reasonable steps to contain, investigate and mitigate the breach.

Customer is responsible for notifying supervisory authorities and data subjects where required. Zapflow will not notify third parties of a breach affecting Customer Personal Data without Customer's consent, unless required by law.

Notification of a Personal Data Breach is not an admission of fault or liability by Zapflow.

 

**12. Audits and information**  
Zapflow makes available to Customer the information necessary to demonstrate compliance with Article 28 of the GDPR, primarily through written documentation, answers to reasonable security questionnaires and summaries of relevant policies.  If that information is not sufficient to demonstrate compliance, or if a supervisory authority requires it, Customer may audit Zapflow's compliance with this Appendix, including by inspection, either itself or through an independent auditor.

Audits are subject to the following conditions: i) Customer gives at least 30 days' written notice and a proposed scope; ii) audits take place no more than once in any 12-month period, unless following a Personal Data Breach or required by a supervisory authority; iii) audits take place during normal business hours and without unreasonable disruption to Zapflow's operations; iv) the auditor is bound by confidentiality and is not a competitor of Zapflow; v) Customer bears its own audit costs, and Zapflow may charge reasonable costs for its time unless the audit reveals a material breach of this Appendix by Zapflow; and vi) audits of Sub-processors are carried out in accordance with the Sub-processor's own audit terms, and Zapflow may meet the request by providing the Sub-processor's third-party audit reports or certifications.

Zapflow may withhold trade secrets, information about other customers and security-critical details, and may provide a summary of such information instead.

 

**13. Deletion and return of Customer Personal Data**  
\* During the term of the Agreement, Customer can export and delete Customer Personal Data using the Service's standard features. Customer should export any data it wishes to keep before the Agreement ends.

\* Zapflow will delete Customer Personal Data within 30 days after termination or expiry of the Agreement, unless EU or Member State law requires Zapflow to store it.

\* Copies in backups are deleted in line with Zapflow's standard backup cycle and remain protected under this Appendix until deleted.

\* Return of data in any format other than the Service's standard export features requires a separate agreement and may be subject to reasonable fees.

\* On request, Zapflow will confirm the deletion in writing.

 

**14. Liability**  
Each party's liability under this Appendix is subject to the limitations and exclusions of liability in the Agreement, except where Data Protection Laws require otherwise.

 

**15. Term, precedence and changes**  
This Appendix applies for as long as Zapflow processes Customer Personal Data under the Agreement. Provisions that by their nature are intended to continue survive termination. In the event of a conflict concerning the processing of Customer Personal Data, the following order of precedence applies: (1) a Separate DPA, if any; (2) this Appendix; (3) the rest of the Agreement.

Zapflow may update this Appendix to reflect changes in Data Protection Laws, regulatory guidance or the Service, following the procedure for changes to the Terms of Service. Updates will not materially reduce the level of protection for Customer Personal Data.

This Appendix is governed by the law and dispute resolution provisions of the Agreement.

 

**Annex 1. Details of processing**

Subject matter. Provision of the Zapflow Service to Customer under the Agreement.

Nature of the processing. Hosting and storage, organisation and structuring, retrieval and display, search, synchronisation with integrations enabled by Customer, backup and recovery, technical support, maintenance, security monitoring and deletion.

Purpose of the processing. To provide, support, maintain and secure the Service for Customer as described in the Agreement.

Duration of the processing. The term of the Agreement and the deletion period set out in Section 13.

Frequency Continuous, for the duration of the processing.

Categories of data subjects:  
\- Customer's Users, such as employees, partners and contractors authorised to use the Service.  
\- Customer's business contacts, such as representatives of target companies, portfolio companies, investors, co-investors, lenders, advisers, brokers, intermediaries and other counterparties.  
\- Other individuals whose personal data Customer or its Users enter into or synchronise with the Service, for example individuals mentioned in emails, meeting notes or documents.

Types of personal data  
\- Identification and contact details, such as name, title, organisation, email address, phone number and business address.  
\- Professional information, such as role, employer, work history and links to professional profiles.  
\- Relationship and interaction data, such as notes, activities, meeting records, email and calendar data synchronised through integrations, and links to deals, companies, properties or funds.  
\- Files and documents uploaded to the Service that contain personal data.  
\- User account and usage data, such as name, email address, role, access rights and log data (for example IP address, timestamps and actions taken).

The exact scope of Customer Personal Data is determined by Customer and its Users.

Special categories of personal data: None

 

**Annex 2. Technical and organisational measures**

Hosting. The Service is hosted on Amazon Web Services infrastructure in data centres located in the EEA (Ireland).

Encryption.  Data in transit is encrypted using TLS (HTTPS with HTTP Strict Transport Security). Data at rest is encrypted using AES-256.

Backups. Encrypted backups are taken regularly and stored in the EEA.

Access control. Access by Zapflow personnel to Customer Personal Data is limited to what is needed to provide, support, maintain and secure the Service, and is logged. Customer controls its Users' access to the Service through user roles and permissions.

Personnel: Zapflow personnel with access to Customer Personal Data are bound by confidentiality obligations.

Incident management. Zapflow maintains procedures to detect, respond to and notify Personal Data Breaches in accordance with Section 11.

Sub-processor management. Sub-processors are selected with regard to their security measures and are bound by written data protection terms in accordance with Section 8.

Deletion.  Customer Personal Data is deleted in accordance with Section 13.

Further information on Zapflow's security measures is available to Customer on request.

 

**Annex 3. Sub-processors**

Zapflow uses core Sub-processors for all customers. Optional Sub-processors process Customer Personal Data only if Customer or its Users enable the related feature, and only to the extent needed to provide that feature.

Core Sub-processors  
Amazon Web Services, Inc. - cloud hosting, storage and backups - EEA (Ireland)

Optional Sub-processors, used subject to Customer's choices  
\- Oneflow AB - electronic contract signing - EEA  
\- Docusign - electronic signatures - United States  
\- Twilio Inc. - \[SMS and messaging\] - United States  
\- Intercom R&D Unlimited Company - in-app support chat and service messages - EEA  
\- Nylas, Inc. - email and calendar synchronisation - United States  
\- Zefram - company data enrichment - EEA

Where Customer connects its own account with a provider (for example its own Oneflow or Docusign account), that provider acts under Customer's own agreement with it and is not a Zapflow Sub-processor (see Section 8).

 

### Ready to steramline your investment workflows?

[Get started now](https://www.zapflow.com/get-started-now)

##### Products

- [Deal flow](https://www.zapflow.com/front-office/deal-flow-management)
- [Fundraising](https://www.zapflow.com/front-office/fundraising)
- [Portfolio management](https://www.zapflow.com/portfolio-management/monitoring)
- [CRM](https://www.zapflow.com/investor-relations/crm)
- [KYC/AML](https://www.zapflow.com/compliance/kyc-aml-sanction-list-monitoring)
- [LP reporting](https://www.zapflow.com/investor-relations/lp-portal-and-reporting)

##### To Whom

- [Corporate](https://www.zapflow.com/to-whom/corporate-venture-capital)
- [Real estate](https://www.zapflow.com/to-whom/real-estate-investors)
- [Family offices](https://www.zapflow.com/to-whom/family-offices)
- [Fund of funds](https://www.zapflow.com/to-whom/fund-of-funds)
- [Limited Partners](https://www.zapflow.com/to-whom/limited-partners)
- [Private equity](https://www.zapflow.com/to-whom/private-equity)
- [Venture capital](https://www.zapflow.com/to-whom/venture-capital)

##### Resources

- [Blog](https://www.zapflow.com/resources/news-blog)
- [Security](https://www.zapflow.com/security)
- [Help center](https://help.zapflow.com/en)

##### Zapflow

- [About Us](https://www.zapflow.com/aboutus)
- [Contact Us](https://www.zapflow.com/about-us#contact-us)

##### Legal

- [GDPR](https://www.zapflow.com/legal/gdpr)
- [Terms of services](https://www.zapflow.com/legal/terms-of-services)
- [Privacy](https://www.zapflow.com/legal/privacy-policy)
- [Whistleblowing](https://www.zapflow.com/legal/whistleblowing)
- [DPA](https://www.zapflow.com/legal/dpa)

---

[Follow us on LinkedIn](https://www.linkedin.com/company/zapflow)