Updated 8 July 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Servicebetween JKOVE Oy (Business ID 3111634-8, Finland) ("Provider") and the customer using the Flovei service ("Customer"). It applies to the extent the Customer enters personal data concerning its own clients, prospects, or other contacts ("Customer Data") into the service.
For Customer Data, the Customer acts as the data controller — or, where the Customer processes the data on behalf of another controller, as a processor, in which case the Provider acts as a sub-processor — within the meaning of the EU General Data Protection Regulation (2016/679, "GDPR"). The Customer warrants that it has the authorizations required from the relevant controller to engage the Provider. For the Customer's own account and service usage data, the Provider acts as an independent controller as described in the Privacy Policy.
Subject matter and purpose: hosting, storage, organization, display, and transmission of Customer Data as necessary to provide the service to the Customer. The Provider does not process Customer Data for its own purposes.
Nature of processing: collection on the Customer's instruction, storage, retrieval, display to the Customer, and erasure.
Duration: the term of the agreement, plus the deletion period described in section 9.
Types of personal data: contact and identification details of the Customer's clients and contacts (such as names, telephone numbers, and email addresses), and related notes, activity, and scheduling information the Customer enters into or connects to the service.
Categories of data subjects: the Customer's clients, prospective clients, and other professional contacts; participants of events the Customer connects to the service.
Special categories of data: the service is not intended for the processing of special categories of personal data (GDPR art. 9), and the Customer agrees not to enter such data into the service.
The Provider processes Customer Data only on the Customer's documented instructions, including with regard to transfers to third countries, unless required to do otherwise by EU or member state law — in which case the Provider informs the Customer of that legal requirement before processing, unless the law prohibits this. The agreement, this DPA, and the Customer's use of the service's features constitute the documented instructions. Where the Customer processes Customer Data on behalf of another controller, the Customer is responsible for ensuring that its instructions to the Provider are consistent with that controller's instructions. The Provider will immediately inform the Customer if, in its opinion, an instruction infringes the GDPR. For clarity, the Provider does not use Customer Data to train artificial intelligence or machine learning models.
The Provider ensures that all persons authorized to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. The Provider treats Customer Data as the Customer's confidential information regardless of the nature of the Customer's business. This confidentiality obligation survives the termination of the agreement.
The Provider implements appropriate technical and organizational measures, including:
The Customer grants a general authorization to use the sub-processors listed at flovei.com/subprocessors. The Provider imposes data protection obligations on each sub-processor equivalent to those in this DPA and remains fully liable to the Customer for the performance of its sub-processors. The Provider gives at least 30 days' prior notice of the addition or replacement of sub-processors; the Customer may object on reasonable data protection grounds, in which case the parties will seek a solution in good faith and, failing that, the Customer may terminate the agreement.
Customer Data is stored within the EU, and the service's server functions and error monitoring data reside within the EU. Sub-processors do not store Customer Data outside the EU/EEA; processing outside the EU/EEA is limited to ancillary functions such as delivery of transactional emails to users and bot protection. Transactional emails are sent to service users and do not contain Customer Data, and error monitoring masks user-entered content in error recordings and is configured to limit personal data in diagnostic events. Where a sub-processor nevertheless processes personal data outside the EU/EEA, the transfer is based on the European Commission's Standard Contractual Clauses (2021/914) and/or the EU-U.S. Data Privacy Framework, as set out in the sub-processor list.
Taking into account the nature of the processing, the Provider assists the Customer with appropriate technical and organizational measures in fulfilling the Customer's obligations to respond to data subject requests (access, rectification, erasure, restriction, portability, objection) and in ensuring compliance with the Customer's obligations under GDPR articles 32-36 (security, breach notifications, data protection impact assessments, and prior consultation), insofar as the information is available to the Provider.
The Provider notifies the Customer of a personal data breach concerning Customer Data without undue delay and in any event within 72 hours of becoming aware of it, providing the information reasonably required for the Customer to meet its own notification obligations.
Upon termination of the agreement, the Provider deletes Customer Data within 30 days, or returns it to the Customer in a commonly used electronic format upon request made before deletion — unless EU or member state law requires continued storage. The Customer can also delete Customer Data during the term through the service's own functions. Backup copies containing Customer Data expire and are overwritten on a rolling basis, at the latest within 90 days of deletion. On request, the Provider confirms deletion in writing.
The Provider makes available to the Customer the information necessary to demonstrate compliance with article 28 and allows for audits. Audit requests are primarily satisfied through written documentation and summaries of the Provider's security measures. Where these are not reasonably sufficient, the Customer or an independent auditor mandated by it may conduct an audit at most once per year, with at least 30 days' notice, during normal business hours, at the Customer's expense, and without access to other customers' data. On the Customer's request, the same audit rights are made available to a competent supervisory authority. Where the Customer processes Customer Data on behalf of another controller, the Customer may exercise these audit and information rights on that controller's behalf, or extend them to that controller.
The liability provisions of the Terms of Service apply to this DPA. In the event of a conflict between this DPA and the Terms of Service with respect to the processing of Customer Data, this DPA prevails.