Data Processing Addendum

Data Processing Addendum

Effective date: 9 September 2026 Version: 1.1.0

This Data Processing Addendum (“DPA”) forms part of the Terms of Use between Flyb Digital Solutions, LLC (“FlyB”, “Processor”) and the customer accepting them (“you”, “Controller”).

It applies where, in your use of the Services, you process personal data that is subject to the GDPR, the UK GDPR, the Swiss nFADP, the LGPD, PIPEDA, the CCPA/CPRA or a comparable data-protection law. It takes effect automatically on your acceptance of the Terms of Use — no signature is required, though a countersigned copy is available on request to [email protected].

Where this DPA conflicts with the Terms of Use or the Privacy Policy on a matter of processing Customer Personal Data, this DPA prevails.


1. Definitions

“Customer Personal Data” means personal data contained in Customer Content that FlyB processes on your behalf — principally the data of your leads, customers, blog members, booking guests and form respondents.

“Controller”, “Processor”, “Sub-processor”, “Data Subject”, “Personal Data Breach” and “Processing” have the meanings given in the GDPR. Under the LGPD, “Controller” corresponds to controlador and “Processor” to operador. Under the CCPA/CPRA, FlyB is a Service Provider.

Terms not defined here have the meaning given in the Terms of Use.


2. Roles and scope

YouFlyB
Customer Personal DataControllerProcessor, acting on your documented instructions
Account data (your registration, billing, telemetry and support records)Data subject / counterpartyIndependent controller, governed by the Privacy Policy — this DPA does not apply

2.1 Subject matter and duration

The subject matter is FlyB’s provision of the Services. Processing lasts for the term of the Terms of Use, plus the retention periods in section 10.

2.2 Nature and purpose

Hosting, storage, organisation, retrieval, transmission, analysis and deletion of Customer Personal Data, as necessary to provide the Services you have chosen: the CRM, forms, calendars and booking, e-mail sending and campaigns, blogs, tracked URLs, analytics, checkout records and the public API.

2.3 Categories of data subject

Your leads, prospects, customers, booking guests, form respondents, blog members and comment authors, anyone who exchanges WhatsApp messages with a number you connect, and the visitors to the sites you publish.

2.4 Categories of personal data

Identity and contact details (name, e-mail, phone, company); postal address; custom fields you define; commercial data (deals, orders, payment records, subscriptions); booking data and the answers to your booking questions, including the guest’s answer — and when they gave it — to whether they agree to receive the booking’s confirmation and reminders on WhatsApp; communication records (e-mails sent, opened, bounced, unsubscribes, and clicks on the e-mail buttons you mark as tracked); tags, CRM positions and movement history; technical and approximate-location data derived from the visit that produced the contact; blog membership, posts and comments; the content of the WhatsApp conversations carried on any number you connect, together with the phone numbers, WhatsApp profile names and delivery receipts that accompany them — and, for a number linked through WhatsApp Web whose online status you switch on, whether the contacts it follows are online and when they were last seen; and the data the Services derive from the above on your instruction — the member of your team a contact is assigned to, and the lead score and its history of awarded points, produced by scoring rules you configure, the FlyB Hunt AI scores of the contacts analysed by the Hunt Rules you write, and the probabilities returned by the AI conditions of the CRM automations you write, for the messages and the contacts they judged.

2.5 Special categories

The Services are not intended for special categories of personal data (GDPR Article 9), sensitive personal data (LGPD Article 5, II) or the data prohibited by Terms of Use, section 11.3. You must not place such data in the Services. Where you do so regardless, you do it at your own risk and remain solely responsible for it.


3. Your obligations as Controller

You warrant and undertake that:

  1. you have a valid legal basis for every processing operation you instruct, including for every recipient of every e-mail or message you send;
  2. you have given data subjects the information the law requires, and have obtained any consent required;
  3. your instructions to FlyB, including your configuration of the Services, comply with applicable law — this includes any scoring, ranking or other profiling of Customer Personal Data you configure, for which you are the controller;
  4. you will not import purchased, rented, leased or scraped contact lists;
  5. you have implemented appropriate measures in your own organisation, including managing your team’s permissions and revoking access when it is no longer needed; and
  6. you will respond to data subjects exercising their rights in relation to Customer Personal Data, using the tools the Services provide.

4. FlyB’s obligations as Processor

FlyB will:

  1. Process only on your documented instructions. The Terms of Use, this DPA and your configuration and use of the Services constitute your complete documented instructions. FlyB will process for no other purpose, and will not sell or share Customer Personal Data, retain it outside the direct business relationship, or combine it with data from other sources except as permitted by the CCPA/CPRA.
  2. Tell you if an instruction appears unlawful. Where FlyB is required by law to process beyond your instructions, it will inform you first unless the law forbids it.
  3. Bind its personnel to confidentiality, and grant access on a least-privilege, need-to-know basis.
  4. Implement the security measures in section 5.
  5. Assist you as set out in sections 7, 8 and 9.
  6. Delete or return Customer Personal Data as set out in section 10.
  7. Make available the information necessary to demonstrate compliance, and submit to audits as set out in section 11.

5. Security

FlyB implements technical and organisational measures appropriate to the risk, including:

MeasureImplementation
Encryption in transitTLS on every connection to the Platform and to every integration
Encryption at restEncrypted storage volumes for the database, files and backups
Tenant isolationEvery query is scoped by organisation identifier; one customer’s data cannot be reached from another’s session or API key
Access controlRole- and permission-based access in the product; least-privilege access to production for FlyB personnel
Credential protectionAPI keys stored as encrypted fingerprints that cannot be read back; OAuth tokens and SMTP passwords encrypted and never exposed to client-side code; signed OAuth state parameters
Logging and monitoringAccess logging and monitoring for anomalous activity
ResilienceRegular encrypted backups for disaster recovery
Secure developmentParameterised database access, input validation, and content restrictions on customer-supplied HTML

FlyB may update these measures, provided the level of protection is not reduced.


6. Sub-processors

6.1 General authorisation

You give FlyB general authorisation to engage sub-processors. The current list is maintained at Sub-processors and forms part of this DPA.

6.2 Obligations imposed on sub-processors

FlyB engages each sub-processor under a written contract imposing data-protection obligations no less protective than those in this DPA, and remains fully liable to you for its performance.

6.3 Notice and objection

FlyB will update the sub-processor list before a new sub-processor begins processing, or as soon as reasonably practicable where the change is urgent and necessary to maintain the Services. You may subscribe to notifications by writing to [email protected] with the subject line “Sub-processor notifications”.

You may object to a new sub-processor on reasonable data-protection grounds within thirty (30) days of notice. We will work in good faith to find an alternative. If none is reasonably available, you may terminate the affected Services and receive a pro-rata refund of the unused prepaid term, as your sole remedy.

6.4 Services you connect yourself

Services you connect — your SMTP provider, your Stripe account, your Google account, WhatsApp, Make, OpenRouter, your own Google tags — are not FlyB sub-processors. Enabling one is your instruction to transmit data to it, and the provider then acts under its own terms as an independent controller or as your processor. FlyB is not responsible for its processing. See Sub-processors, section 2.

This is particularly important for OpenRouter, which the AI video and image generators reach directly from your browser, without the data passing through FlyB’s infrastructure at all.


7. Data subject rights

The Services give you the tools to access, correct, export and delete Customer Personal Data yourself, and to honour an objection to marketing through the unsubscribe mechanism.

Where a data subject contacts FlyB directly about Customer Personal Data, FlyB will not respond on the merits and will, without undue delay, direct them to you and forward the request where it can identify you.

Where you cannot fulfil a request using the Services, FlyB will provide reasonable assistance, taking into account the nature of the processing.


8. Personal data breach

FlyB will notify you of a Personal Data Breach affecting Customer Personal Data without undue delay after becoming aware of it, and in any event in time for you to meet your own notification obligations.

The notification will describe, so far as known: the nature of the breach and the categories and approximate number of data subjects and records affected; the likely consequences; the measures taken or proposed to address it and to mitigate its effects; and a contact point for further information. Where the information is not all available at once, it will be provided in phases.

FlyB will not notify a regulator or a data subject on your behalf unless you ask it to or the law requires it.


9. Impact assessments and prior consultation

Taking into account the nature of the processing and the information available to it, FlyB will provide reasonable assistance with your data-protection impact assessments and with any prior consultation with a supervisory authority, in relation to the Services.


10. Retention, return and deletion

FlyB retains Customer Personal Data for as long as necessary to provide the Services, and thereafter as set out in Privacy Policy, section 11.

On termination, and on written request made within thirty (30) days, FlyB will provide a reasonable export of Customer Personal Data in a machine-readable format. After that period FlyB will delete it, except where retention is required by law, in which case FlyB will continue to protect it and process it only for the purpose requiring retention.

Residual copies may persist in encrypted backups for up to ninety (90) days before being overwritten in the ordinary backup cycle.


11. Audits

FlyB will make available the information reasonably necessary to demonstrate compliance with this DPA, ordinarily by providing documentation, security descriptions and written answers to a reasonable security questionnaire.

Where that is genuinely insufficient to meet a mandatory obligation of yours, you may conduct an audit, subject to: thirty (30) days’ written notice; no more than once in any twelve-month period, unless required by a supervisory authority or following a Personal Data Breach; being conducted during business hours, without unreasonable disruption; being subject to confidentiality; not extending to another customer’s data or to FlyB’s confidential commercial information; and being at your cost.


12. International transfers

Customer Personal Data is processed in the United States and in the other locations named in the Sub-processor list.

For transfers from the EEA, the parties adopt the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Two (Controller to Processor), incorporated by reference, with:

  • Clause 7 (docking) — applicable;
  • Clause 9 — Option 2, general written authorisation, with the notice period in section 6.3;
  • Clause 11 — the optional independent dispute-resolution body is not adopted;
  • Clause 17 — governed by the law of Ireland;
  • Clause 18 — the courts of Ireland;
  • Annex I — the parties are you (data exporter, Controller) and FlyB (data importer, Processor); the categories of data subject and data, and the nature and purpose of processing, are those in section 2; the frequency is continuous; the duration is that of the Terms of Use plus the retention periods in section 10; sub-processors are those listed at Sub-processors;
  • Annex II — the technical and organisational measures are those in section 5.

For transfers from the United Kingdom, the parties adopt the ICO’s International Data Transfer Addendum to the above Clauses. For transfers from Switzerland, the Clauses apply with references to the GDPR read as references to the nFADP and the Swiss FDPIC recognised as a competent authority.

For transfers from Brazil, the parties rely on the mechanisms permitted by Articles 33 to 36 of the LGPD, principally contractual clauses offering protection equivalent to the LGPD, and this DPA constitutes those clauses between the parties.

Where a transfer mechanism is invalidated, the parties will negotiate in good faith an alternative permitted by law.


13. CCPA / CPRA

For personal information subject to the CCPA/CPRA, FlyB is a Service Provider. FlyB will not: sell or share that information; retain, use or disclose it for any purpose other than performing the Services specified in the Terms of Use, or as otherwise permitted by the CCPA; retain, use or disclose it outside the direct business relationship between you and FlyB; or combine it with personal information received from another source, except as permitted by the CCPA.

FlyB certifies that it understands these restrictions and will comply with them, and will notify you if it determines it can no longer do so.


14. Liability

Each party’s liability under this DPA is subject to the exclusions and limitations in Terms of Use, section 17, except where a mandatory provision of applicable data-protection law provides otherwise. Nothing in this DPA limits a data subject’s rights under the Standard Contractual Clauses.


15. Term, changes and general

This DPA takes effect on your acceptance of the Terms of Use and continues until FlyB ceases to process Customer Personal Data.

FlyB may update this DPA where required by a change in law, in a transfer mechanism or in the Services, on the notice terms in Terms of Use, section 1.3. No change will reduce the protection afforded to Customer Personal Data.

If any provision is held invalid, it is severed and the remainder continues in force.


16. Contact

Data-protection matters: [email protected].

A countersigned copy of this DPA, and copies of the transfer terms referenced in section 12, are available on request to the same address.