Legal Document
Data Processing Addendum
Standard DPA for enterprise customers subject to data protection regulations.
Licensor
O and P Advisory Services, LLC
Version
1.0
Effective Date
August 26, 2026
End User License Agreement
This DPA forms part of the EULA
Sub-Processor List
Authorized third-party processors
Security Overview
Technical and organizational measures
Request a signed DPA
privacyflowofkanban@oandpadvisoryservices.com
Enterprise Document
This Data Processing Addendum ("DPA") is incorporated into and forms an integral part of the End User License Agreement ("EULA") between O and P Advisory Services, LLC ("FLOWOFKANBAN") and the enterprise customer ("Customer"). This DPA applies to the processing of Personal Data by FLOWOFKANBAN on behalf of Customer. Enterprise customers may execute a signed version of this DPA by contacting privacyflowofkanban@oandpadvisoryservices.com.
1. Definitions
Capitalized terms used but not defined in this DPA have the meanings given to them in the EULA or Privacy Policy. The following terms have the meanings set out below:
- "Applicable Data Protection Laws" means all laws and regulations applicable to the processing of Personal Data under the EULA, including, as applicable, the EU General Data Protection Regulation (Regulation 2016/679) ("GDPR"), the California Consumer Privacy Act as amended by the CPRA ("CCPA"), the UK GDPR, and any equivalent U.S. state or federal data protection laws.
- "Controller" means the entity that determines the purposes and means of the processing of Personal Data. Customer is the Controller of Customer Personal Data.
- "Processor" means the entity that processes Personal Data on behalf of the Controller. FLOWOFKANBAN is the Processor of Customer Personal Data.
- "Customer Personal Data" means Personal Data processed by FLOWOFKANBAN on behalf of Customer pursuant to the EULA and this DPA, as further described in Annex 1.
- "Personal Data" means any information relating to an identified or identifiable natural person, as defined under Applicable Data Protection Laws.
- "Sub-Processor" means any third party engaged by FLOWOFKANBAN to process Customer Personal Data on behalf of Customer.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries pursuant to the GDPR, as approved by the European Commission, and any equivalent transfer mechanism adopted under Applicable Data Protection Laws.
- "Supervisory Authority" means an independent public authority established by an EU Member State, the UK, or any other competent data protection regulator.
2. Roles and Scope of Processing
FLOWOFKANBAN acts as a Processor processing Customer Personal Data on behalf of Customer, who acts as the Controller. FLOWOFKANBAN shall process Customer Personal Data only for the purposes described in the EULA, this DPA, and as instructed by Customer in writing.
FLOWOFKANBAN shall not process Customer Personal Data for any other purpose, including its own commercial purposes, except as required by Applicable Data Protection Laws. FLOWOFKANBAN is not a Controller of Customer Personal Data.
The scope of Customer Personal Data, categories of data subjects, processing purposes, and retention periods are set out in Annex 1 (Description of Processing).
3. FLOWOFKANBAN Obligations
FLOWOFKANBAN shall, with respect to its processing of Customer Personal Data:
- Process Customer Personal Data only on documented instructions from Customer, including with regard to transfers to a third country, unless required to do so by Applicable Data Protection Laws, in which case FLOWOFKANBAN shall inform Customer of that legal requirement before processing (unless prohibited by law).
- Ensure that persons authorized to process Customer Personal Data are subject to confidentiality obligations or are under an appropriate statutory obligation of confidentiality.
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Section 5 and the Security Overview.
- Assist Customer, insofar as possible, in fulfilling Customer's obligations to respond to requests from data subjects exercising their rights under Applicable Data Protection Laws.
- Assist Customer in ensuring compliance with obligations regarding security breach notification, data protection impact assessments, and prior consultation with Supervisory Authorities.
- At Customer's written direction, delete or return Customer Personal Data at the end of the provision of services, and delete existing copies, unless Applicable Data Protection Laws require storage.
- Make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, as described in Section 8.
4. Sub-Processors
Customer acknowledges and agrees that FLOWOFKANBAN may engage Sub-Processors to process Customer Personal Data on its behalf. FLOWOFKANBAN maintains a current list of authorized Sub-Processors on the Sub-Processor List page, incorporated herein by reference.
FLOWOFKANBAN shall provide Customer with at least thirty (30) calendar days' prior written notice of any intended addition or replacement of a Sub-Processor, thereby giving Customer the opportunity to object. Customer may object by notifying FLOWOFKANBAN in writing within thirty (30) calendar days of receiving the notice, providing reasonably detailed grounds for the objection.
If FLOWOFKANBAN engages a Sub-Processor, FLOWOFKANBAN shall impose on that Sub-Processor, by way of a written contract, data protection obligations that are substantially similar to those set out in this DPA. FLOWOFKANBAN remains fully liable to Customer for the performance of each Sub-Processor's data protection obligations.
5. Security Measures
FLOWOFKANBAN shall implement and maintain appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk of processing Customer Personal Data, including as appropriate:
- Encryption of Customer Personal Data in transit using TLS 1.2+ and at rest where stored in the Platform database.
- Pseudonymization and data minimization techniques where applicable to the processing activity.
- Ability to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems and services.
- Ability to restore the availability of and access to Customer Personal Data in a timely manner in the event of a physical or technical incident.
- Regular testing, assessing, and evaluating of the effectiveness of technical and organizational measures.
- Role-based access controls and row-level tenant isolation limiting access to Customer Personal Data to authorized personnel and users on a need-to-know basis.
- Secure development lifecycle practices including code review and vulnerability scanning.
6. Personal Data Breach
FLOWOFKANBAN shall notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
Such notification shall describe: (a) the nature of the breach including, where possible, the categories and approximate number of data subjects and records concerned; (b) the likely consequences of the breach; and (c) the measures taken or proposed to address the breach and mitigate its adverse effects.
FLOWOFKANBAN shall cooperate with Customer and take reasonable steps to investigate, mitigate, and remediate the breach, and shall document all Personal Data Breaches, including facts relating to the breach, its effects, and remedial action taken. Customer is responsible for notifying the relevant Supervisory Authority and affected data subjects as required under Applicable Data Protection Laws; FLOWOFKANBAN shall provide reasonable assistance in fulfilling such obligations.
7. Data Subject Rights
FLOWOFKANBAN shall provide reasonable assistance to Customer, taking into account the nature of the processing, by appropriate technical and organizational measures, insofar as possible, to fulfill Customer's obligation to respond to requests from data subjects exercising their rights under Applicable Data Protection Laws, including rights of access, rectification, erasure, restriction, portability, and objection.
If FLOWOFKANBAN receives a request directly from a data subject concerning Customer Personal Data, FLOWOFKANBAN shall promptly forward the request to Customer and shall not respond to the request itself except to confirm receipt and to direct the data subject to Customer, unless otherwise required by Applicable Data Protection Laws.
8. Audits and Certifications
Upon Customer's reasonable written request, and no more than once per twelve (12)-month period (except where required by a Supervisory Authority or following a Personal Data Breach), FLOWOFKANBAN shall make available information reasonably necessary to demonstrate compliance with this DPA, including responses to a reasonable security questionnaire and available third-party attestations or certifications once obtained.
Any on-site audit shall be subject to reasonable advance notice, confidentiality obligations, mutually agreed scope and timing, and shall be conducted in a manner that does not disrupt FLOWOFKANBAN's operations or compromise the security or confidentiality of other customers' data. Customer bears the costs of any audit it requests.
9. International Data Transfers
The Platform and its Sub-Processors are located in the United States. Where Customer Personal Data originating in the EEA, the United Kingdom, or Switzerland is transferred to FLOWOFKANBAN in a country not subject to an adequacy decision, such transfer is made pursuant to the Standard Contractual Clauses, which are hereby incorporated by reference, with FLOWOFKANBAN acting as data importer and Customer as data exporter (Module Two: Controller to Processor).
FLOWOFKANBAN shall implement supplementary technical, contractual, and organizational measures — including encryption in transit and at rest and access controls — designed to protect transferred Customer Personal Data. FLOWOFKANBAN shall notify Customer if it becomes subject to a legally binding request for disclosure of Customer Personal Data by a public authority, unless prohibited from doing so by law.
10. Data Deletion and Return
Upon termination or expiration of the EULA, FLOWOFKANBAN shall, at Customer's written direction, delete or return all Customer Personal Data in its possession or control, and delete existing copies, unless retention is required by Applicable Data Protection Laws.
Customer may export Customer Personal Data using the export features available in the Platform prior to deletion. Deletion performed at Customer's request is permanent and irreversible.
11. CCPA and U.S. State Law Provisions
To the extent the CCPA applies, FLOWOFKANBAN acts as a "service provider" and shall: (a) not sell or share Customer Personal Data; (b) not retain, use, or disclose Customer Personal Data for any purpose other than performing the services specified in the EULA, or as otherwise permitted by the CCPA; (c) not combine Customer Personal Data with personal information received from other sources, except as permitted by the CCPA; and (d) notify Customer if it determines it can no longer meet these obligations.
FLOWOFKANBAN shall provide the same or equivalent protections in respect of any other applicable U.S. state privacy law.
12. Liability
Each party's liability arising out of or relating to this DPA is subject to the limitations and exclusions of liability set out in the EULA, and any reference to the liability of a party means the aggregate liability of that party under the EULA and this DPA combined.
13. Governing Law and Dispute Resolution
This DPA is governed by the same governing law and dispute-resolution provisions set out in the EULA, except where Applicable Data Protection Laws require otherwise (including with respect to the Standard Contractual Clauses, which are governed as provided therein).
14. Order of Precedence
In the event of a conflict between this DPA and the EULA with respect to the processing of Personal Data, this DPA shall control. In the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses shall control.
Annex 1 — Description of Processing
| Item | Description |
|---|---|
| Subject matter | Provision of the FLOWOFKANBAN Material Replenishment Platform to Customer under the EULA. |
| Duration | The Subscription Term, plus any post-termination export window, until deletion or return of Customer Personal Data. |
| Nature and purpose | Hosting, storage, processing, transmission, and display of Customer Personal Data as necessary to operate the Platform, authenticate users, generate Outputs, maintain audit trails, provide support, and secure the service. |
| Categories of data subjects | Customer's Authorized Users — including tenant admins, board owners, team leads (supervisors), contributors (operators and material handlers), and viewers. |
| Categories of Personal Data | Name, business email address, company name, role designation, display name, avatar URL (if provided), handler zone assignment, authentication and session metadata, IP address, device and browser data, activity timestamps, and actor names recorded in audit and history records. |
| Special categories of data | None. Customer shall not submit special categories of Personal Data (as defined under GDPR Article 9) to the Platform. |
| Frequency of processing | Continuous, for the duration of the Subscription Term. |
| Sub-Processors | As listed on the Sub-Processor List page, incorporated by reference. |
| Retention | For the duration of the Subscription Term, and thereafter until deletion at Customer's request or as required by law. Audit and history records are append-only during the Subscription Term. |
© 2026 O and P Advisory Services, LLC — All Rights Reserved.
FLOWOFKANBAN Data Processing Addendum — Version 1.0 — Effective August 26, 2026