Article 28 processor terms and our sub-processor list.
Effective: 2026-06-08 · Owner: security@nexflow.run
This page is the customer-facing summary of the data processing addendum NexFlow offers. A countersigned DPA is available on request at security@nexflow.run for customers who need one for their own compliance review.
Roles
For data uploaded to your workspace or pulled in via your OAuth integrations, you are the data controller and NexFlow is the data processor under GDPR Article 28. For your own account and billing data NexFlow is a joint controller with you.
Scope of processing
NexFlow processes your data only to deliver the service you purchased: running the agent fleet, producing audit outputs, executing approved doer work, and the operational logging required to bill and support the engagement.
Security
We apply TLS 1.2 or higher in transit, encryption at rest on Supabase, row-level security on every public-schema table, MFA on every operator account, and a documented incident response plan. The full SOC 2 control mapping is shared under NDA on request.
Breach notification
We notify you within 72 hours of confirmed detection of any security event that affects your data, in line with GDPR Article 33. Supervisory authority notification follows where EU data subjects are affected.
Active sub-processors
We notify customers at least 30 days before adding a new sub-processor that touches workspace data. Current list:
| Vendor | Purpose | Data | Region | Attestation |
|---|---|---|---|---|
| Anthropic | LLM inference for every NexFlow agent. | Redacted prompts containing transcript excerpts, ticket titles, PR descriptions, and aggregated metrics. Zero-data-retention is enabled on the production key. | United States | SOC 2 Type II, GDPR DPA, HIPAA-eligible under signed BAA. |
| Supabase | Primary application database, auth, and storage. | All structured workspace data: account records, transcripts, contracts, audit outputs, agent task ledgers. | United States (AWS us-east-1) | SOC 2 Type II, GDPR DPA, HIPAA under signed BAA. |
| Render | Application hosting and cron orchestration. | In-memory request handling only. Secrets are env vars; logs stream to the platform. | United States (Oregon) | SOC 2 Type II, GDPR DPA. |
| GitHub | Source control and CI for the NexFlow application code base. | Application source code only. No customer raw data is stored on GitHub. | United States (multi-region) | SOC 2 Type II, GDPR DPA. |
| Stripe | Billing and payment processing. | Customer billing contact, subscription state, invoices. Payment card data is held by Stripe directly under PCI DSS Level 1. | United States (with EU subsidiaries for EU customers) | PCI DSS Level 1, SOC 1 / SOC 2, GDPR DPA. |
| Resend | Transactional email delivery for verifications, password resets, and notifications. | Recipient email addresses and the body of transactional messages we send to you. | United States | SOC 2 Type II, GDPR DPA. |
| Twilio | SMS notifications for approvals and deliverable handoffs. | Phone numbers and SMS message bodies. | United States (us1) | SOC 2 Type II, HIPAA-eligible under signed BAA, GDPR DPA. |
| Sentry | Application error monitoring. | Stack traces and request metadata. PII scrubbing is applied before send and we exclude bodies that may contain customer payloads. | United States | SOC 2 Type II, GDPR DPA. |
| PostHog | Product analytics keyed by workspace identifier. | Anonymized event stream identified by tenant ID, never by raw email. | United States | SOC 2 Type II, GDPR DPA. |
| Plausible | Cookieless web analytics on the marketing site. | Aggregated page-view counts. No cookies, no cross-site identifiers. | European Union | GDPR by design. |
| Better Stack | Uptime monitoring and log aggregation for the platform. | Application logs that may include redacted request metadata. No raw customer payloads. | European Union | SOC 2 Type II, GDPR DPA. |
International transfers
Where your data crosses borders we rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. Our sub-processors have either committed to these clauses or operate solely in the same jurisdiction as you.
Termination and deletion
On termination of the engagement we delete or return your data per the schedule documented in the privacy policy. Backup copies expire within the additional 90 day window required by our retention runbook.
Contact
Sub-processor questions, DPA countersignature: security@nexflow.run.