NexFlow
Data processing addendum

Article 28 processor terms and our sub-processor list.

Effective: 2026-06-08 · Owner: security@nexflow.run

This page is the customer-facing summary of the data processing addendum NexFlow offers. A countersigned DPA is available on request at security@nexflow.run for customers who need one for their own compliance review.

Roles

For data uploaded to your workspace or pulled in via your OAuth integrations, you are the data controller and NexFlow is the data processor under GDPR Article 28. For your own account and billing data NexFlow is a joint controller with you.

Scope of processing

NexFlow processes your data only to deliver the service you purchased: running the agent fleet, producing audit outputs, executing approved doer work, and the operational logging required to bill and support the engagement.

Security

We apply TLS 1.2 or higher in transit, encryption at rest on Supabase, row-level security on every public-schema table, MFA on every operator account, and a documented incident response plan. The full SOC 2 control mapping is shared under NDA on request.

Breach notification

We notify you within 72 hours of confirmed detection of any security event that affects your data, in line with GDPR Article 33. Supervisory authority notification follows where EU data subjects are affected.

Active sub-processors

We notify customers at least 30 days before adding a new sub-processor that touches workspace data. Current list:

VendorPurposeDataRegionAttestation
AnthropicLLM inference for every NexFlow agent.Redacted prompts containing transcript excerpts, ticket titles, PR descriptions, and aggregated metrics. Zero-data-retention is enabled on the production key.United StatesSOC 2 Type II, GDPR DPA, HIPAA-eligible under signed BAA.
SupabasePrimary application database, auth, and storage.All structured workspace data: account records, transcripts, contracts, audit outputs, agent task ledgers.United States (AWS us-east-1)SOC 2 Type II, GDPR DPA, HIPAA under signed BAA.
RenderApplication hosting and cron orchestration.In-memory request handling only. Secrets are env vars; logs stream to the platform.United States (Oregon)SOC 2 Type II, GDPR DPA.
GitHubSource control and CI for the NexFlow application code base.Application source code only. No customer raw data is stored on GitHub.United States (multi-region)SOC 2 Type II, GDPR DPA.
StripeBilling and payment processing.Customer billing contact, subscription state, invoices. Payment card data is held by Stripe directly under PCI DSS Level 1.United States (with EU subsidiaries for EU customers)PCI DSS Level 1, SOC 1 / SOC 2, GDPR DPA.
ResendTransactional email delivery for verifications, password resets, and notifications.Recipient email addresses and the body of transactional messages we send to you.United StatesSOC 2 Type II, GDPR DPA.
TwilioSMS notifications for approvals and deliverable handoffs.Phone numbers and SMS message bodies.United States (us1)SOC 2 Type II, HIPAA-eligible under signed BAA, GDPR DPA.
SentryApplication error monitoring.Stack traces and request metadata. PII scrubbing is applied before send and we exclude bodies that may contain customer payloads.United StatesSOC 2 Type II, GDPR DPA.
PostHogProduct analytics keyed by workspace identifier.Anonymized event stream identified by tenant ID, never by raw email.United StatesSOC 2 Type II, GDPR DPA.
PlausibleCookieless web analytics on the marketing site.Aggregated page-view counts. No cookies, no cross-site identifiers.European UnionGDPR by design.
Better StackUptime monitoring and log aggregation for the platform.Application logs that may include redacted request metadata. No raw customer payloads.European UnionSOC 2 Type II, GDPR DPA.

International transfers

Where your data crosses borders we rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. Our sub-processors have either committed to these clauses or operate solely in the same jurisdiction as you.

Termination and deletion

On termination of the engagement we delete or return your data per the schedule documented in the privacy policy. Backup copies expire within the additional 90 day window required by our retention runbook.

Contact

Sub-processor questions, DPA countersignature: security@nexflow.run.