Data Processing Agreement
Article 28 terms under which CrewFlow processes personal data on behalf of your organisation, including sub-processors and security measures.
Version —
1. Roles
Your organisation is the controller of workforce personal data. CrewFlow is the processor and processes that data only on your documented instructions, which are given through your use of the Platform and any written instruction to support.
2. Subject matter and duration
Processing continues for the duration of your subscription plus the retention period configured on your organisation. Categories of data subject include your workers, your staff and your clients' site contacts.
3. Security measures
CrewFlow maintains, at minimum:
- Row level security enforcing organisation isolation on every tenant table.
- Private, organisation-scoped storage buckets with signed, time-limited access URLs.
- Immutable database-trigger audit logging of every create, update and archive.
- Encryption in transit (TLS 1.2+) and at rest.
- Least-privilege access for support staff, with access logged.
- Daily automated backups with periodic restore verification.
4. Sub-processors
CrewFlow uses the following sub-processors:
- Cloud database, authentication and object storage provider — hosting, EU region.
- AI model provider — document extraction, EU/US with standard contractual clauses.
- Transactional email provider — invitations and notifications.
- Payment provider — subscription billing and invoicing.
5. Assistance
CrewFlow assists you in responding to data subject requests through self-service export and erasure tooling, and will notify you without undue delay, and in any case within 48 hours, of becoming aware of a personal data breach affecting your data.
6. Return and deletion
On termination you may export all data for 30 days. After that, or on an earlier erasure instruction, CrewFlow deletes the data including from backups within the backup rotation window.
7. Audit
CrewFlow will make available the information necessary to demonstrate compliance with Article 28 and will accept one controller audit per year on reasonable notice.