Data Processing Addendum
Last updated: May 2026
This Data Processing Addendum ("DPA") forms part of the Master Subscription Agreement, Terms of Service, or other written or electronic agreement between Flitch Solutions Pty Ltd ABN 57 682 821 512 of 191 St Georges Terrace, Perth, WA 6000, Australia ("Flitch", "we", "us", or "our") and the customer (the "Agreement") for the provision of the Flitch services (the "Services"). This DPA reflects the parties' agreement on the processing of Personal Data in connection with the Customer's use of the Services. If there is any conflict between this DPA and the Agreement, this DPA prevails on matters of data protection.
1. Definitions
Capitalised terms not defined here have the meaning given in the Agreement.
- "Applicable Data Protection Law" means all laws and regulations applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR"), the UK Data Protection Act 2018 and UK GDPR ("UK GDPR"), the Swiss Federal Act on Data Protection ("FADP"), the California Consumer Privacy Act ("CCPA"), and the Australian Privacy Act 1988 (Cth) including the Australian Privacy Principles ("APPs").
- "Customer Personal Data" means Personal Data that Flitch processes on behalf of the Customer in connection with the Services.
- "Personal Data", "Controller", "Processor", "Data Subject", "Processing" (and cognate forms), "Standard Contractual Clauses" ("SCCs"), and "Sub-processor" have the meanings given in Applicable Data Protection Law.
- "Restricted Transfer" means a transfer of Customer Personal Data from a jurisdiction with data-export restrictions to a jurisdiction that has not received an adequacy decision under Applicable Data Protection Law.
- "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data while processed by Flitch or a Sub-processor.
- "Sub-processor List" means the list of Sub-processors published at flitch.io/sub-processors.
2. Roles and Scope
2.1 The Customer is the Controller (or processor acting on behalf of a third-party controller) of Customer Personal Data. Flitch is the Processor (or sub-processor) of Customer Personal Data.
2.2 The subject-matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects are described in Annex I.
2.3 This DPA applies only to Flitch's processing of Customer Personal Data on behalf of the Customer. It does not apply to Personal Data for which Flitch is the Controller (for example, account administrator contact details used to manage the Customer's subscription), which is governed by Flitch's Privacy Policy.
3. Processing of Customer Personal Data
3.1 Documented instructions. Flitch will process Customer Personal Data only on documented instructions from the Customer, including with regard to Restricted Transfers, unless required to do so by law. The Agreement, this DPA, and the Customer's use of the Services through their configuration constitute the Customer's documented instructions.
3.2 Lawful instructions. The Customer is responsible for ensuring that its instructions comply with Applicable Data Protection Law. Flitch will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.
3.3 Confidentiality of personnel. Flitch will ensure that persons authorised to process Customer Personal Data are bound by appropriate obligations of confidentiality.
4. Customer Data is Not Used to Train AI or Machine-Learning Models
4.1 Flitch does not use Customer Personal Data, query results, schemas, prompts, or any output derived from the Customer's use of the Services to train, fine-tune, or otherwise improve any artificial intelligence or machine-learning model, whether operated by Flitch or by any third party.
4.2 Where the Services use third-party AI providers (currently Anthropic and Google. See Sub-processor List), Customer Personal Data sent to those providers is processed under the providers' commercial API terms which prohibit the use of inputs for model training. Flitch will maintain Zero Data Retention or equivalent arrangements with AI Sub-processors where commercially available.
4.3 Flitch may use aggregated, de-identified telemetry about Service usage (volume, latency, error rates) for the operation and improvement of the Services, provided such telemetry cannot reasonably be used to identify any Data Subject.
5. Sub-processors
5.1 General authorisation. The Customer grants Flitch general authorisation to engage Sub-processors to process Customer Personal Data, subject to this Section 5.
5.2 Current Sub-processors. The current list of Sub-processors is maintained at flitch.io/sub-processors and is incorporated by reference into this DPA.
5.3 Change notification. At least fifteen (15) days before enabling any new Sub-processor or replacing an existing Sub-processor, Flitch will update the Sub-processor List and notify the Customer by email to the administrator address on file, or by such other reasonable means as Flitch may select.
5.4 Objection. The Customer may object to a proposed change on reasonable data-protection grounds by notice to Flitch within ten (10) days of the change notification. The parties will work together in good faith to resolve the objection. If they cannot resolve the objection within thirty (30) days, the Customer may terminate the affected portion of the Services on written notice, with a pro-rata refund of any pre-paid fees for the unused portion of the Services.
5.5 Sub-processor obligations. Flitch will impose on each Sub-processor data protection obligations no less protective than those in this DPA. Flitch remains liable to the Customer for the acts and omissions of its Sub-processors.
6. International Data Transfers
6.1 Restricted Transfers from the EEA. Where Flitch processes Customer Personal Data originating from the European Economic Area ("EEA") in a country that has not received an adequacy decision from the European Commission, the parties incorporate the SCCs adopted by the European Commission in Decision 2021/914 of 4 June 2021 (the "EU SCCs"), which are deemed entered into and executed by both parties on the effective date of the Agreement, with:
- Module Two (Controller to Processor) applying where the Customer is a Controller, and Module Three (Processor to Processor) applying where the Customer is a Processor;
- In Clause 7, the optional docking clause does not apply;
- In Clause 9, Option 2 (General Written Authorisation) applies with the notice period in Section 5.3 of this DPA;
- In Clause 11, the optional independent dispute resolution mechanism does not apply;
- In Clauses 17 and 18, the governing law and forum are those of Ireland;
- Annex I, II, and III are as set out in this DPA.
6.2 Restricted Transfers from the United Kingdom. Where Flitch processes Customer Personal Data originating from the United Kingdom in a country that has not received an adequacy decision under UK GDPR, the parties incorporate the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (the "UK Addendum"), which is deemed entered into and executed by both parties on the effective date of the Agreement, appended to the EU SCCs referenced in Section 6.1.
6.3 Restricted Transfers from Switzerland. Where Flitch processes Customer Personal Data originating from Switzerland in a country that has not received adequacy recognition under the FADP, the EU SCCs apply with the following amendments:
- References to "Regulation (EU) 2016/679" or "GDPR" are interpreted as references to the FADP;
- References to "Member State" are interpreted to include Switzerland;
- The supervisory authority is the Swiss Federal Data Protection and Information Commissioner ("FDPIC");
- The governing law and forum are those of Switzerland to the extent required by the FADP.
6.4 Customer obligations. The Customer represents and warrants that it has the legal basis under Applicable Data Protection Law to transfer Customer Personal Data to Flitch and to authorise onward transfers to the Sub-processors listed in the Sub-processor List.
7. Security
7.1 Technical and organisational measures. Flitch will implement and maintain the technical and organisational measures described in Annex II, designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
7.2 Updates. Flitch may update its technical and organisational measures from time to time provided that any update does not materially diminish the protection of Customer Personal Data.
8. Security Incidents
8.1 Notification. Flitch will notify the Customer without undue delay when feasible, but no later than seventy-two (72) hours, after becoming aware of a Security Incident affecting Customer Personal Data.
8.2 Contents of notification. The notification will include, to the extent then known:
- the nature of the Security Incident;
- the categories and approximate number of Data Subjects and records affected;
- the likely consequences;
- the measures taken or proposed to address the Security Incident and mitigate adverse effects.
8.3 Cooperation. Flitch will reasonably assist the Customer in meeting any notification or other obligations that the Customer may have under Applicable Data Protection Law in respect of the Security Incident.
8.4 No admission. Flitch's notification of, or response to, a Security Incident is not an acknowledgement of any fault or liability on Flitch's part.
9. Data Subject Rights
9.1 Flitch will, taking into account the nature of the processing, reasonably assist the Customer (including by appropriate technical and organisational measures) in responding to requests from Data Subjects to exercise their rights under Applicable Data Protection Law.
9.2 If Flitch receives a request from a Data Subject in respect of Customer Personal Data, it will direct the Data Subject to the Customer and notify the Customer without undue delay.
10. Data Protection Impact Assessments and Consultation
10.1 Flitch will provide reasonable assistance to the Customer in carrying out Data Protection Impact Assessments and consultations with supervisory authorities, taking into account the nature of the processing and information available to Flitch.
11. Audit
11.1 Audit rights. Flitch will make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA. On reasonable written notice (and no more than once per twelve-month period unless required by a supervisory authority or following a confirmed Security Incident), Flitch will permit the Customer or its appointed auditor (subject to reasonable confidentiality undertakings) to conduct audits of Flitch's data-protection practices.
11.2 Form of audit. Audits will be conducted during normal business hours, with reasonable advance notice (no less than thirty (30) days unless required by Applicable Data Protection Law), in a manner that does not unreasonably interfere with Flitch's business operations, and at the Customer's cost.
11.3 Alternative. Flitch may satisfy its audit obligations by providing the Customer with then-current third-party audit reports, certifications (SOC 2, ISO 27001, or equivalent) or sub-processor audit reports.
12. Return and Deletion of Customer Personal Data
12.1 On termination. On termination or expiry of the Agreement, the Customer may export Customer Personal Data through the standard Service functionality for a period of thirty (30) days following termination. After that period, Flitch will, within sixty (60) days, delete or return all Customer Personal Data in its possession or control, unless Applicable Data Protection Law requires storage of the Customer Personal Data.
12.2 Backups. Customer Personal Data residing in routine system backups will be deleted in accordance with Flitch's standard backup-rotation schedule and will not be restored or used for any purpose other than disaster recovery during the retention period.
13. Liability
13.1 Each party's total cumulative liability arising out of or related to this DPA is subject to the waivers, exclusions, and limitations of liability stated in the Agreement. Nothing in this Section 13 limits any liability that cannot be limited under Applicable Data Protection Law.
14. Term and Termination
14.1 This DPA takes effect on the effective date of the Agreement and continues until the Agreement terminates or expires, except that the provisions which by their nature should survive termination will so survive (including Sections 6 (Transfers), 8 (Security Incidents), 11 (Audit), 12 (Return/Deletion), 13 (Liability) and 14 (Survival)).
15. Australian Privacy Act 1988 (Cth)
15.1 Where the Customer is subject to the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs"), Flitch will handle Customer Personal Data consistently with the APPs in its capacity as a Processor, and assist the Customer in meeting its own APP obligations including in respect of APP 1 (open and transparent management), APP 6 (use and disclosure), APP 8 (cross-border disclosure), and APP 11 (security).
16. General
16.1 Order of precedence. If there is any conflict between this DPA and the Agreement, this DPA prevails on matters of data protection. If there is any conflict between this DPA and the EU SCCs or the UK Addendum, the EU SCCs or UK Addendum prevail.
16.2 Severability. If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions will continue in full force and effect.
16.3 No third-party beneficiaries. Except as expressly stated in the EU SCCs or the UK Addendum, this DPA does not create any third-party beneficiary rights.
16.4 Updates. Flitch may update this DPA from time to time. Material changes will be notified to the Customer's administrator address with at least thirty (30) days' advance notice. The current version is always available at flitch.io/dpa.
16.5 Counterparts and electronic acceptance. This DPA may be accepted electronically, including by clickwrap acceptance of the Agreement that incorporates this DPA by reference. A signed PDF copy is available on request to [email protected].
Annex I. Description of Processing
A. List of Parties
Data exporter (Controller): The Customer as identified in the Agreement.
Data importer (Processor): Flitch Solutions Pty Ltd, an Australian company.
B. Description of Transfer
- Categories of Data Subjects: end users of the Customer's dashboards; the Customer's employees, contractors, and agents who access the Services; the Customer's customers or other individuals whose data is connected to Flitch through the Customer's data sources.
- Categories of Personal Data: identifiers (name, email, user ID); account and authentication metadata; any Personal Data contained in the Customer's connected data sources or queries (including pseudonymised commercial transaction data); dashboard content; usage logs.
- Sensitive data: not intended. If the Customer chooses to process special categories of Personal Data through the Services, the Customer remains responsible for ensuring lawful basis. Flitch applies the same security measures regardless of sensitivity.
- Frequency of transfer: continuous, for the duration of the Customer's subscription.
- Nature of processing: hosting, storage, retrieval, querying, caching, generation of dashboard code and visualisations, transmission to AI providers for content generation.
- Purpose of processing: provision of the Services as described in the Agreement.
- Period of retention: for the duration of the subscription. Cached data expires within five minutes. Query results held in the query cache table for the customer-configured refresh interval (default one hour). On termination, see Section 12.
- Sub-processor transfers: see flitch.io/sub-processors.
C. Competent Supervisory Authority
For EU and EEA transfers: the supervisory authority in the EEA Member State where the Customer is established, or where the Customer has appointed an EU representative, or where the relevant Data Subjects are located.
For UK transfers: the Information Commissioner's Office (ICO).
For Swiss transfers: the Federal Data Protection and Information Commissioner (FDPIC).
Annex II. Technical and Organisational Measures
Flitch maintains the following technical and organisational measures, which may be updated from time to time provided that no update materially diminishes the protection of Customer Personal Data.
- Encryption in transit: TLS 1.2+ on every external connection: user browser, data sources, AI providers, sub-processors. Internal cache traffic uses TLS via managed Valkey. No plaintext links anywhere on the data path.
- Encryption at rest: AES-256 across all persistent stores: application database (Neon Postgres), object storage (AWS S3), cache (managed Valkey with LUKS-encrypted disk). Source credentials are additionally AES-256-GCM encrypted at the application layer.
- Access control: role-based access (admin, editor, viewer) on every team-scoped resource. PostgreSQL Row-Level Security enforces multi-tenant isolation at the database layer in addition to application-level access checks.
- Authentication: Better Auth handles password, Google, and Microsoft sign-in, with multi-factor authentication available through Google and Microsoft. Sessions invalidated server-side on logout or rotation.
- Source credential handling: credentials for connected sources (warehouse OAuth tokens, API keys) are encrypted with AES-256-GCM in the application database. No raw credential is logged or returned through the API.
- Cache scope and lifetime: published dashboard query results are cached in managed Valkey (TLS 1.2+, AES-256 at rest via LUKS) with a 5-minute TTL. Cache is RAM-resident with periodic encrypted snapshots for durability.
- Processing isolation: dashboards render from compiled, static artifacts, so no live sandbox sits on your data. Server-side jobs such as PDF export run on dedicated workers and do not retain your data once the file is delivered.
- Logging and monitoring: auth events, team membership changes, dashboard CRUD, dataset operations, billing changes, AI generation events, and credential accesses are recorded server-side. Real-time alerting on anomalies.
- Personnel security: all personnel with access to Customer Personal Data are subject to background checks where permitted by law and confidentiality obligations.
- Vendor security: sub-processors are SOC 2 attested or equivalent.
- Backup and recovery: application database and object storage backed up by sub-processors with point-in-time recovery. Backup data is encrypted at rest.
- Vulnerability management: dependency scanning, periodic third-party security review (most recent: April 2026).
- Incident response: documented incident response process with on-call rotation.
For the most current security overview, see flitch.io/security or request the Flitch Data Security Overview PDF.
Annex III. Sub-processors
The current list of Sub-processors is maintained at flitch.io/sub-processors and is incorporated into this DPA by reference.
Contact
Questions about this DPA, or to request a counter-signed PDF copy: