Definitions
Terms including “controller”, “processor”, “data subject”, “personal data”, “processing” and “supervisory authority” have the meanings given to them in Applicable Data Protection Law. “Customer Personal Data” means personal data contained in the sources you connect to Fluxion and processed by Fluxion on your behalf.
“Applicable Data Protection Law” means the EU General Data Protection Regulation (2016/679), the UK GDPR and Data Protection Act 2018, the Swiss FADP, and applicable US state privacy laws, each as amended.
This Addendum forms part of, and is subject to, the Terms of Service between the parties. In the event of conflict on the subject of data processing, this Addendum controls.
Roles of the parties
You decide what happens to the data. We only do what you instruct.
Summary only — the clause below is what bindsIn respect of Customer Personal Data, you are the controller and Fluxion is the processor. Where you are yourself a processor for a third-party controller, Fluxion is a sub-processor and your instructions must be consistent with that controller’s.
Fluxion processes Customer Personal Data only on your documented instructions. Connecting a source, asking a question of the product, and configuring your workspace each constitute a documented instruction. Fluxion will inform you if, in its opinion, an instruction infringes Applicable Data Protection Law.
In respect of account data and usage data processed to operate and improve the service, Fluxion acts as a controller, as described in the Privacy Policy.
Scope and nature of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the Fluxion service |
| Duration | For the term of the subscription, plus the deletion window in section 8 |
| Nature | Reading, computing, storing, generating explanations, and deletion |
| Purpose | Producing business metrics, briefs and answers for the controller |
| Categories of data subject | The customer’s employees, contractors, customers and contacts |
| Categories of personal data | Names, business contact details, transaction records, calendar and email metadata |
| Special category data | None requested or required; not knowingly processed |
Fluxion holds read-only scopes on connected sources and has no write path to them. Processing does not include automated decision-making producing legal or similarly significant effects on data subjects.
Sub-processors
A short, published list. You get notice before it changes, and a right to object.
Summary only — the clause below is what bindsYou grant Fluxion general authorisation to engage the sub-processors listed below. Each is bound by a written agreement imposing data-protection obligations no less protective than those in this Addendum, and Fluxion remains fully liable for their performance.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Cloud hosting and storage | United States, European Union |
| Enterprise LLM provider | Model inference under zero-retention terms | United States |
| Stripe | Payment processing | United States |
| Error monitoring vendor | Fault diagnosis, excluding connected-source contents | European Union |
| Transactional email vendor | Service notifications and briefs | United States |
Fluxion will give at least 30 days’ notice before adding or replacing a sub-processor. You may object on reasonable data-protection grounds within that period, in which case the parties will work in good faith to find an alternative; if none is available, you may terminate the affected service without penalty.
Security measures
Fluxion implements and maintains appropriate technical and organisational measures under Article 32 GDPR, including at minimum:
- Encryption of Customer Personal Data in transit (TLS 1.3) and at rest (AES-256).
- Per-workspace isolation with dedicated encryption keys.
- Read-only integration architecture with no write path to connected systems.
- Role-based access control, least privilege, and mandatory multi-factor authentication for personnel.
- Audit logging of access to Customer Personal Data, exposed to the controller in-product.
- Confidentiality obligations and security training for all personnel with access.
- Documented backup, business-continuity and incident-response procedures, tested periodically.
- Vulnerability management, dependency scanning and independent penetration testing.
Measures may be updated over time provided the overall level of security is not reduced.
Data-subject requests
If someone exercises their rights against you, we help you answer them.
Summary only — the clause below is what bindsTaking into account the nature of the processing, Fluxion will assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise data-subject rights.
Where a data subject contacts Fluxion directly in respect of Customer Personal Data, Fluxion will not respond substantively but will forward the request to you without undue delay.
Personal data breach notification
Fluxion will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the full detail is not available at the time, it will be provided in phases without undue further delay.
Return and deletion of data
Disconnect and it goes. Leave and it all goes within 30 days.
Summary only — the clause below is what bindsYou may export Customer Personal Data at any time during the subscription and for 30 days after termination. On your written request, or on termination, Fluxion will delete Customer Personal Data within 30 days.
Disconnecting an individual source revokes Fluxion’s credentials immediately and triggers deletion of the data derived from it within 30 days. Backups are purged on their ordinary rotation, not exceeding 90 days.
Fluxion may retain Customer Personal Data to the extent required by law, in which case it will continue to protect it and process it only for the purpose requiring retention.
Audits and assessments
Fluxion will make available all information reasonably necessary to demonstrate compliance with this Addendum, including its most recent third-party audit reports and penetration-test summaries, subject to confidentiality undertakings.
Where those materials are insufficient, you may conduct an audit no more than once in any twelve-month period, on at least 30 days’ written notice, during business hours, and in a manner that does not disrupt Fluxion’s operations or compromise the confidentiality of other customers’ data. Each party bears its own costs.
International transfers
Where Fluxion transfers Customer Personal Data out of the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, the transfer is governed by the European Commission’s Standard Contractual Clauses (Module Two, controller to processor), which are incorporated into this Addendum by reference, together with the UK International Data Transfer Addendum where applicable.
Fluxion will conduct and document transfer impact assessments as required and will implement supplementary measures where necessary. EU data residency is available on eligible plans.
Contact and execution
To execute a countersigned copy of this Addendum, write to legal@fluxion.co with your legal entity name, registered address and signatory details, and we will return an executed copy.
Fluxion’s data protection contact can be reached at privacy@fluxion.co. Security matters, including vulnerability disclosure, should be directed to security@fluxion.co.