Our Role as Data Processor
When you use FlowSyniq to conduct outbound outreach campaigns, we act as a Data Processor, processing personal data on your behalf. You, as the business operator using the platform, are the Data Controller.
Controller vs. Processor
As the Data Controller, you are legally responsible for establishing a valid lawful basis for processing your prospect data, complying with GDPR obligations toward data subjects, and ensuring your outreach lists were lawfully obtained.
FlowSyniq provides a Data Processing Agreement (DPA) available upon request at legal@flowsyniq.com for customers requiring one under GDPR Article 28.
Lawful Basis for Processing
FlowSyniq processes personal data for its own internal platform operations under the following GDPR lawful bases:
- Contractual Necessity (Art. 6(1)(b)): Processing required to deliver the Service, manage billing, and provide customer support.
- Legitimate Interests (Art. 6(1)(f)): Product analytics, fraud prevention, security monitoring, and platform improvement.
- Legal Obligation (Art. 6(1)(c)): Tax records, financial reporting, and responding to lawful government requests.
- Consent (Art. 6(1)(a)): Optional analytics and marketing communications where we rely on your explicit opt-in.
Data Subject Rights
FlowSyniq provides tools and processes to help you fulfill your GDPR data subject rights obligations. We support the following rights:
| Right | GDPR Article | How to Exercise |
|---|---|---|
| Right of Access | Article 15 | Email privacy@flowsyniq.com |
| Right to Rectification | Article 16 | Update in account settings or via support |
| Right to Erasure | Article 17 | Account deletion request via support portal |
| Right to Restrict Processing | Article 18 | Contact privacy@flowsyniq.com |
| Right to Data Portability | Article 20 | Export tools available in account dashboard |
| Right to Object | Article 21 | Contact privacy@flowsyniq.com |
International Data Transfers
Where personal data of EU/EEA data subjects is transferred to countries not deemed adequate by the European Commission, FlowSyniq implements appropriate safeguards:
- Standard Contractual Clauses (SCCs): We rely on EU Commission-approved SCCs per GDPR Article 46(2)(c) for transfers to our US-based infrastructure providers.
- Adequacy Decisions: Where applicable, we transfer data to countries with an EU adequacy decision.
- Sub-Processor Agreements: All sub-processors (e.g., Stripe, AWS) are GDPR-compliant and bound by appropriate DPAs.
Data Breach Notification
FlowSyniq maintains a documented incident response plan for personal data breaches. In the event of a breach affecting your data:
- We will notify you without undue delay and within 72 hours of becoming aware of the breach (GDPR Article 33).
- Notification will include: nature of the breach, categories and approximate number of data subjects affected, likely consequences, and remediation measures taken.
- You remain responsible for notifying your supervisory authority and affected data subjects where required under GDPR Article 33 and 34.
Your Obligations
As the Data Controller, you are responsible for notifying your relevant supervisory authority within 72 hours of a breach becoming known, where applicable under GDPR Article 33.