Fluxion
ProductFluxion OSIntegrationsSecurityPricing
PrivacyTermsDPA

Data Processing Addendum

How Fluxion processes data on your behalf as a processor — roles, safeguards, sub-processors and the commitments that come with them.

Last updated
12 January 2026
Effective
1 February 2026
Entity
Fluxion, Inc.
Contents
  • 1Definitions
  • 2Roles of the parties
  • 3Scope and nature of processing
  • 4Sub-processors
  • 5Security measures
  • 6Data-subject requests
  • 7Personal data breach notification
  • 8Return and deletion of data
  • 9Audits and assessments
  • 10International transfers
  • 11Contact and execution
1

Definitions

Terms including “controller”, “processor”, “data subject”, “personal data”, “processing” and “supervisory authority” have the meanings given to them in Applicable Data Protection Law. “Customer Personal Data” means personal data contained in the sources you connect to Fluxion and processed by Fluxion on your behalf.

“Applicable Data Protection Law” means the EU General Data Protection Regulation (2016/679), the UK GDPR and Data Protection Act 2018, the Swiss FADP, and applicable US state privacy laws, each as amended.

This Addendum forms part of, and is subject to, the Terms of Service between the parties. In the event of conflict on the subject of data processing, this Addendum controls.

2

Roles of the parties

In short

You decide what happens to the data. We only do what you instruct.

Summary only — the clause below is what binds

In respect of Customer Personal Data, you are the controller and Fluxion is the processor. Where you are yourself a processor for a third-party controller, Fluxion is a sub-processor and your instructions must be consistent with that controller’s.

Fluxion processes Customer Personal Data only on your documented instructions. Connecting a source, asking a question of the product, and configuring your workspace each constitute a documented instruction. Fluxion will inform you if, in its opinion, an instruction infringes Applicable Data Protection Law.

In respect of account data and usage data processed to operate and improve the service, Fluxion acts as a controller, as described in the Privacy Policy.

3

Scope and nature of processing

ItemDetail
Subject matterProvision of the Fluxion service
DurationFor the term of the subscription, plus the deletion window in section 8
NatureReading, computing, storing, generating explanations, and deletion
PurposeProducing business metrics, briefs and answers for the controller
Categories of data subjectThe customer’s employees, contractors, customers and contacts
Categories of personal dataNames, business contact details, transaction records, calendar and email metadata
Special category dataNone requested or required; not knowingly processed
Annex I — details of processing

Fluxion holds read-only scopes on connected sources and has no write path to them. Processing does not include automated decision-making producing legal or similarly significant effects on data subjects.

4

Sub-processors

In short

A short, published list. You get notice before it changes, and a right to object.

Summary only — the clause below is what binds

You grant Fluxion general authorisation to engage the sub-processors listed below. Each is bound by a written agreement imposing data-protection obligations no less protective than those in this Addendum, and Fluxion remains fully liable for their performance.

Sub-processorPurposeLocation
Amazon Web ServicesCloud hosting and storageUnited States, European Union
Enterprise LLM providerModel inference under zero-retention termsUnited States
StripePayment processingUnited States
Error monitoring vendorFault diagnosis, excluding connected-source contentsEuropean Union
Transactional email vendorService notifications and briefsUnited States
Current sub-processors

Fluxion will give at least 30 days’ notice before adding or replacing a sub-processor. You may object on reasonable data-protection grounds within that period, in which case the parties will work in good faith to find an alternative; if none is available, you may terminate the affected service without penalty.

5

Security measures

Fluxion implements and maintains appropriate technical and organisational measures under Article 32 GDPR, including at minimum:

  • Encryption of Customer Personal Data in transit (TLS 1.3) and at rest (AES-256).
  • Per-workspace isolation with dedicated encryption keys.
  • Read-only integration architecture with no write path to connected systems.
  • Role-based access control, least privilege, and mandatory multi-factor authentication for personnel.
  • Audit logging of access to Customer Personal Data, exposed to the controller in-product.
  • Confidentiality obligations and security training for all personnel with access.
  • Documented backup, business-continuity and incident-response procedures, tested periodically.
  • Vulnerability management, dependency scanning and independent penetration testing.

Measures may be updated over time provided the overall level of security is not reduced.

6

Data-subject requests

In short

If someone exercises their rights against you, we help you answer them.

Summary only — the clause below is what binds

Taking into account the nature of the processing, Fluxion will assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise data-subject rights.

Where a data subject contacts Fluxion directly in respect of Customer Personal Data, Fluxion will not respond substantively but will forward the request to you without undue delay.

7

Personal data breach notification

Fluxion will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data.

The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the full detail is not available at the time, it will be provided in phases without undue further delay.

8

Return and deletion of data

In short

Disconnect and it goes. Leave and it all goes within 30 days.

Summary only — the clause below is what binds

You may export Customer Personal Data at any time during the subscription and for 30 days after termination. On your written request, or on termination, Fluxion will delete Customer Personal Data within 30 days.

Disconnecting an individual source revokes Fluxion’s credentials immediately and triggers deletion of the data derived from it within 30 days. Backups are purged on their ordinary rotation, not exceeding 90 days.

Fluxion may retain Customer Personal Data to the extent required by law, in which case it will continue to protect it and process it only for the purpose requiring retention.

9

Audits and assessments

Fluxion will make available all information reasonably necessary to demonstrate compliance with this Addendum, including its most recent third-party audit reports and penetration-test summaries, subject to confidentiality undertakings.

Where those materials are insufficient, you may conduct an audit no more than once in any twelve-month period, on at least 30 days’ written notice, during business hours, and in a manner that does not disrupt Fluxion’s operations or compromise the confidentiality of other customers’ data. Each party bears its own costs.

10

International transfers

Where Fluxion transfers Customer Personal Data out of the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, the transfer is governed by the European Commission’s Standard Contractual Clauses (Module Two, controller to processor), which are incorporated into this Addendum by reference, together with the UK International Data Transfer Addendum where applicable.

Fluxion will conduct and document transfer impact assessments as required and will implement supplementary measures where necessary. EU data residency is available on eligible plans.

11

Contact and execution

To execute a countersigned copy of this Addendum, write to legal@fluxion.co with your legal entity name, registered address and signatory details, and we will return an executed copy.

Fluxion’s data protection contact can be reached at privacy@fluxion.co. Security matters, including vulnerability disclosure, should be directed to security@fluxion.co.

Questions about this document
  • Legallegal@fluxion.co
  • Privacyprivacy@fluxion.co
  • Securitysecurity@fluxion.co
Related documents
  • Privacy Policy→
  • Terms of Service→
  • Security overview→

This document is a template prepared for design purposes. It is not legal advice, and final wording must be provided by counsel before it is relied upon.

Fluxion

An intelligence layer above your business data. Serious, precise, engineered — for founders, not governments.

PRODUCTProductFluxion OSIntegrationsSecurityPricing
COMPANYAboutCareersContactPress
LEGALPrivacyTermsSecurityDPA
© 2026 Fluxion — all systems nominalBUILT FOR FOUNDERS