Data Processing Agreement
Our standard DPA for enterprise customers - download, sign, and return.
Template · version 1.0 · 10 September 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between NexlyFlow Pte. Ltd. (UEN 202632611H) (“NexlyFlow”, the “Processor”) and the customer identified in the signature block (“Customer”, the “Controller”) for the use of the NexlyFlow platform (the “Service”).
1. Scope and roles
Customer is the controller of the personal data it uploads to or generates in the Service (contact names, business email addresses, phone numbers, message content and related metadata, “Customer Data”). NexlyFlow processes Customer Data only as a processor, on Customer’s documented instructions, which are: to provide, secure and support the Service as described in the documentation and this DPA.
2. Processing details
- Subject matter: B2B outreach, conversation handling and contact management.
- Duration: the term of the subscription plus the deletion grace period.
- Nature and purpose: storing contacts, sending and receiving emails and WhatsApp messages on Customer’s behalf, drafting text with AI at Customer’s request, reporting.
- Data subjects: Customer’s prospects, customers, and Customer’s own staff using the Service.
- Categories: business contact details, company details, communication content and history, engagement events (opens, replies), consent and opt-out records.
3. NexlyFlow’s obligations
- Process Customer Data only on Customer’s instructions; inform Customer if an instruction appears to breach applicable law.
- Ensure staff with access are bound by confidentiality and access only what their role requires; log platform-staff access.
- Implement the technical and organisational measures described in Annex 1 (and at nexlyflow.com/security).
- Engage sub-processors only as listed in Annex 2; give Customer at least 30 days’ notice of additions by email, during which Customer may object on reasonable grounds.
- Assist Customer, at reasonable cost where the request is extensive, with data-subject requests (access, correction, erasure, objection) and with data-protection impact assessments.
- Notify Customer of a personal-data breach affecting Customer Data without undue delay and within 72 hours of confirmation, with the information reasonably needed for Customer’s own notifications.
- On termination, allow Customer to export Customer Data for 30 days, then delete it from production and let it rotate out of backups on the backup retention schedule, unless retention is required by law.
- Make available the information reasonably necessary to demonstrate compliance and allow audits by Customer or an independent auditor mandated by Customer, no more than once a year unless required by a supervisory authority, on 30 days’ notice and subject to confidentiality.
4. Customer’s obligations
Customer warrants that it has a lawful basis to contact each data subject through the Service (including compliance with the Singapore PDPA and Spam Control Act, and any applicable Do Not Call requirements), that it records that basis in the Service where the Service asks for it, and that its instructions comply with applicable law.
5. International transfers
Customer Data is hosted in Malaysia. Transfers to sub-processors outside Malaysia and Singapore (Annex 2) are covered by the sub-processor’s standard contractual protections; NexlyFlow will provide details on request.
6. Liability and precedence
Liability under this DPA is subject to the limitations in the main agreement. In case of conflict, this DPA prevails over the main agreement on the subject of personal data.
Annex 1 – Security measures (summary)
- TLS for all connections; encryption at rest for mailbox credentials and messaging tokens.
- Tenant isolation at the application and database-query level.
- Role-based access (Owner / Admin / Agent) with Owner-controlled permissions and launch approval.
- Workspace security log of sign-ins and permission changes; per-message delivery and consent trail.
- Daily database and file backups, retained 10 days, stored in Malaysia.
- Emergency stop for outbound sending; rate limits and bounce protection.
- Regular security patching; continuous server monitoring.
Annex 2 – Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Hostinger International Ltd. | Hosting, backups | Malaysia (data centre) |
| Meta Platforms, Inc. | WhatsApp Cloud API | Global |
| OpenAI, L.L.C. | AI text generation (API; no training on customer data) | United States |
| Stripe, Inc. | Payment processing | Global |
| Google LLC | Optional sign-in | Global |
Signatures
| For NexlyFlow Pte. Ltd.
Name: ______________________ |
For Customer (company name & UEN): __________________
Name: ______________________ |
NexlyFlow