feature by complai

Data Processing Addendum

flmnt LLC Last updated July 31, 2026

1. Parties and role

This Data Processing Addendum ("DPA") forms part of the Terms of Service (or a signed agreement referencing it) between flmnt LLC and the customer. It applies where Customer Content contains personal data protected by data protection law: the customer is the controller (or a processor acting for another controller), and flmnt is the processor. For account, billing, and usage data, flmnt is an independent controller as described in the Privacy Policy, and this DPA does not apply.

2. Details of processing

Subject matter Hosting and processing of Customer Content in the Feature service.
Duration The term of the agreement, plus the deletion windows in Section 8.
Nature and purpose Storage, organization, and display of specifications, contracts, runs, and evidence records; derivation and verification of attestation records; workspace collaboration and notification delivery.
Categories of data Whatever personal data the customer chooses to include in Customer Content — typically names, email addresses, and identifiers of the customer's personnel appearing in specs, evidence, and audit trails.
Data subjects The customer's personnel, contractors, and other individuals appearing in Customer Content.

3. Instructions

flmnt processes Customer Content only on the customer's documented instructions — the agreement, this DPA, and the customer's use of the service's controls — unless required by law (in which case flmnt informs the customer, unless the law forbids it). flmnt will inform the customer if, in its opinion, an instruction violates data protection law.

4. Confidentiality

Persons flmnt authorizes to process Customer Content are bound by confidentiality obligations and access it only as needed to provide the service.

5. Security

flmnt implements appropriate technical and organizational measures, including:

  • encryption of data in transit;
  • role-based access control and least-privilege access to production systems;
  • isolated environments and audit trails for administrative access;
  • a tamper-evident, hash-chained evidence ledger that makes alteration of attestation records detectable;
  • vendor security review for the subprocessors below.

6. Subprocessors

The customer authorizes the subprocessors below. flmnt will give notice (by updating this page and notifying account owners) before adding or replacing a subprocessor; the customer may object on reasonable data-protection grounds within 30 days, in which case the parties will seek a solution and the customer may terminate the affected service if none is found.

Subprocessor Purpose Location
Amazon Web Services, Inc. Cloud hosting, storage, identity infrastructure, and email delivery (SES) United States
Stripe, Inc. Payment processing and billing United States
Vercel Inc. Hosting of the public website United States

Identity providers the customer's users choose for sign-in (Google, GitHub, GitLab) act as independent services, not as flmnt's subprocessors.

7. Assistance

Taking into account the nature of the processing, flmnt assists the customer with data subject requests (the service's export, correction, and deletion controls are self-service where possible), with security-of-processing obligations, and with data protection impact assessments where required. flmnt will notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Content, with the information the customer needs for its own notifications.

8. Deletion and return

During the term, the customer can export Customer Content through the service's signed-export facility. On termination or on the customer's instruction, flmnt deletes Customer Content — account-initiated deletion carries a 7-day cooling-off window, after which erasure is permanent. Hash-chained attestation records are retained only in a form carrying opaque identifiers, with the personal data that linked them to individuals removed, to preserve the integrity of the evidence ledger; residual copies in backups are deleted on the backup rotation schedule.

9. Audits

flmnt makes available the information reasonably necessary to demonstrate compliance with this DPA, including summaries of security measures and subprocessor arrangements, and will respond to reasonable written security questionnaires no more than once annually. Where the customer's law requires an audit beyond this, the parties will agree on scope, timing, and a mutually acceptable independent auditor.

10. Liability and order of precedence

Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. If this DPA conflicts with the Terms regarding the processing of personal data in Customer Content, this DPA controls.

11. Contact

Questions and notices under this DPA: privacy@mmmnt.ai.