Data Processing Addendum
Effective date: September 29, 2026
This Data Processing Addendum ("DPA") forms part of the OutFlo Terms and Conditions between Tweaker Technologies Private Limited ("OutFlo") and the customer accepting those Terms ("Customer"). It applies when OutFlo processes personal data in Customer Data on Customer's behalf to provide the Services. If this DPA conflicts with the Terms on that processing, this DPA controls. OutFlo's handling of website visitor, billing, and support information for its own purposes is described in its Privacy Policy and is outside this DPA.
1. Roles and instructions
Customer determines the purposes and means of processing Customer Data and acts as controller (or, where Customer is itself a processor, as a processor acting for its controller). OutFlo acts as processor or subprocessor, respectively. Customer is responsible for giving lawful instructions, providing required notices, and establishing a valid basis for collecting and using Customer Data, including prospect data and outreach. OutFlo will process Customer Data only on Customer's documented instructions, including the Terms, this DPA, Customer's use of the Services, and other written instructions agreed by the parties, unless applicable law requires otherwise. OutFlo will inform Customer of such a legal requirement before processing unless legally prohibited. OutFlo will promptly tell Customer if, in its opinion, an instruction violates applicable data protection law.
2. Processing details
The subject matter is provision of OutFlo's outreach and related account services. Processing lasts for the subscription term and the deletion period in Section 7. Its nature includes receiving, storing, organizing, retrieving, transmitting, displaying, and deleting Customer Data as needed to provide the Services and follow Customer's instructions. The purpose is to operate the features Customer uses, including account connections, campaigns, prospect management, and messaging. Data subjects may include Customer's authorized users, prospects, contacts, and people appearing in connected accounts or conversations. Personal data may include names, business contact details, professional profiles, message and campaign content, account identifiers, and service activity. Customer will not submit sensitive or specially regulated data unless the parties expressly agree in writing.
3. Confidentiality and security
OutFlo will ensure people authorized to process Customer Data are subject to confidentiality obligations. OutFlo will implement appropriate technical and organizational measures for a level of security appropriate to the risk, including measures for access control, protection during transmission and storage, recovery from incidents, and regular assessment of effectiveness. Customer is responsible for securing its own accounts, credentials, devices, and instructions.
4. Subprocessors
Customer gives OutFlo general authorization to use subprocessors needed to provide the Services. OutFlo will impose written data-protection obligations on them that are no less protective than the obligations in this DPA and remains responsible for their performance. OutFlo will make its current subprocessor list available on request at team@outflo.io, give Customer notice before adding or replacing a subprocessor, and provide a reasonable opportunity to object on data-protection grounds. If the parties cannot resolve an objection, Customer may terminate the affected Service under the Terms. OutFlo will not disclose Customer Data to a third-party integration enabled by Customer except as instructed or authorized by Customer.
5. Assistance and incidents
Taking account of the nature of processing and information available to it, OutFlo will reasonably assist Customer in responding to requests by data subjects and in meeting applicable duties concerning security, breach notification, impact assessments, and consultation with regulators. If OutFlo receives a request concerning Customer Data, it will direct the requester to Customer where appropriate. OutFlo will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, provide information reasonably available to it, and cooperate in remediation. Customer remains responsible for determining whether and when to notify individuals or authorities.
6. International transfers
The parties will use a valid transfer mechanism where applicable law requires one for an international transfer of Customer Data. This DPA alone is not a set of EU Standard Contractual Clauses or another transfer mechanism. If such clauses are required for a particular transfer, the parties will execute the appropriate clauses and any required supplementary terms before that transfer.
7. Return, deletion, and retention
Customer may request return or deletion of Customer Data when the subscription ends. OutFlo will provide a reasonable opportunity to export available Customer Data before deletion. OutFlo may delete or irreversibly de-identify Customer Data beginning 30 days after the subscription ends and will do so no later than 12 months after it ends, including copies under OutFlo's control, unless applicable law requires a longer period. Where law requires retention, OutFlo will limit further processing to that purpose and delete the data when the legal requirement ends. OutFlo will inform Customer on request when deletion is complete. Customer should maintain its own backups; the Services are not an archive.
8. Demonstrating compliance
OutFlo will make information reasonably necessary to demonstrate compliance with this DPA available to Customer and allow and contribute to reasonable audits by Customer or an independent auditor, subject to confidentiality, security, and reasonable notice requirements. The parties will first use available documentation where it adequately addresses the request.
9. Contact
Questions, instructions, and notices under this DPA may be sent to team@outflo.io. Other commercial terms, including liability and governing law, remain as stated in the Terms unless mandatory data-protection law provides otherwise.