Legal
Data Processing Agreement
Last updated August 22, 2026
This Data Processing Agreement ("DPA") forms part of the OptimaFlo Terms of Service, or of any signed agreement between you and OptimaFlo, LLC that refers to it. It sets out how we process personal data contained in your Customer Data on your behalf. It applies automatically and does not need a signature. If your procurement process requires a countersigned copy, email evan.rosa@optimaflo.io with the subject "DPA".
HOW THIS DPA WORKS
In Short: This DPA applies whenever we process personal data inside the Customer Data you connect to or create in the Services. You are the controller of that data. We are your processor.
Parties
"OptimaFlo," "we," "us," and "our" mean OptimaFlo, LLC, a Delaware limited liability company located at 18310 Montgomery Village Ave, Gaithersburg, MD 20879, United States. "Customer," "you," and "your" mean the person or entity that accepted the Agreement.
When it applies
This DPA applies to our processing of Personal Data contained in Customer Data on your behalf in the course of providing the Services. Our processing of Account Data (your name, login email, billing details, and how you use the Services) is described in our Privacy Policy. For Account Data we act as an independent controller (or "business"), and this DPA does not apply to it.
Order of precedence
On matters of data protection, this DPA prevails over the rest of the Agreement. Where the Standard Contractual Clauses or the UK Addendum apply, they prevail over this DPA. Everything else in the Agreement, including its limitation of liability, continues to apply.
How it is accepted
This DPA is incorporated into the Agreement and takes effect on the date you accept the Agreement or first use the Services, whichever is earlier. Where you are a processor acting for your own controllers, you confirm that your controllers have authorized this DPA and the Sub-processors in Annex III.
DEFINITIONS
Capitalized terms not defined here have the meaning given in the Agreement.
- "Agreement" means the OptimaFlo Terms of Service, or the signed order form or enterprise agreement between you and us that refers to this DPA.
- "Customer Data" has the meaning in the Terms of Service: the data you connect to or process through the Services and what the Services create from it, such as tables, pipelines, query results, dashboards, and data-quality results.
- "Personal Data" means any information relating to an identified or identifiable natural person that is contained in Customer Data. In the CCPA context it includes "personal information."
- "Data Protection Laws" means all laws that apply to the processing of Personal Data under this DPA, including, where applicable, the GDPR, the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), and US State Privacy Laws.
- "GDPR" means Regulation (EU) 2016/679. "UK GDPR" means the GDPR as it forms part of the law of the United Kingdom.
- "US State Privacy Laws" means the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA") and other comprehensive US state privacy laws, to the extent they apply to the processing.
- "Controller," "Processor," "Data Subject," "Processing," "Personal Data Breach," and "Supervisory Authority" have the meanings in the GDPR. Under US State Privacy Laws, "Controller" includes "business," "Processor" includes "service provider" and "contractor," and "Data Subject" includes "consumer."
- "Sub-processor" means a third party we engage to process Personal Data on your behalf.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0, in force 21 March 2022.
- "Restricted Transfer" means a transfer of Personal Data that is subject to the GDPR, the UK GDPR, or the FADP to a country that the relevant law does not recognize as providing adequate protection, where the transfer would be prohibited without a lawful transfer mechanism.
- "Services" has the meaning in the Agreement.
ROLES AND INSTRUCTIONS
Roles. You are the Controller of Personal Data in Customer Data, or a Processor acting on behalf of your own Controllers. We are your Processor.
Documented instructions. We process Personal Data only on your documented instructions. Your instructions are: (a) the Agreement and this DPA; (b) the configuration choices you make in the Services, such as which sources you connect, which pipelines, transformations, dashboards, data-quality checks, and AI features you run, and which users you invite; and (c) any other written instruction that we agree to in writing.
Unlawful instructions. We will tell you if we believe an instruction breaches Data Protection Laws, unless the law prohibits us from doing so. We are not required to check whether your instructions are lawful.
Details of processing. The subject matter, nature, purpose, and duration of the processing and the categories of Data Subjects and Personal Data are described in Annex I.
YOUR RESPONSIBILITIES
- Lawfulness. You are responsible for the lawfulness of the Personal Data you connect and of your instructions, including having a lawful basis, giving any required notices, obtaining any required consents, and honoring Data Subject rights.
- Sensitive data. The Services are not designed for special categories of data, health data regulated by HIPAA, payment card data, or data about children. Do not connect such data unless a separate signed agreement between you and us says otherwise.
- BYOC. In a bring-your-own-cloud (BYOC) deployment the data plane runs in your own Google Cloud or AWS account. You control that account and are responsible for its security configuration, access control, and backups, and for your agreement with that cloud provider.
- Your own vendors. Your cloud provider, the warehouses, databases, and APIs you connect, and any AI provider key you configure yourself are your vendors. They are not our Sub-processors.
- Your users. You are responsible for the people you invite to your organization and workspaces, the roles you give them, and the security of their credentials.
CONFIDENTIALITY
We ensure that the people we authorize to process Personal Data are bound by written confidentiality obligations or are under an appropriate statutory duty of confidentiality, access only the Personal Data they need, and process it only to provide, secure, and support the Services.
SECURITY
We implement and maintain the technical and organizational measures described in Annex II. We may update those measures from time to time, but not in a way that materially lowers the overall level of protection during the term of the Agreement.
You are responsible for the security of what is under your control: your users' credentials and two-factor authentication enrollment, the roles and permissions you assign, your BYOC cloud account, and the sources you connect.
SUB-PROCESSORS
In Short: You give us general permission to use the Sub-processors in Annex III. We give you 30 days' notice before adding a new one, and you can object.
Authorization. You authorize us to engage the Sub-processors listed in Annex III. The current list is also published at optimaflo.io/subprocessors and in our Privacy Policy.
Notice of changes. We will give you at least 30 days' notice before a new Sub-processor processes Personal Data, by email to the owners and admins of your organization or by a notice in the Services, and we will update Annex III. If we must replace a Sub-processor urgently to protect the security or continuity of the Services, we will notify you as soon as reasonably possible.
Objection. If you object to a new Sub-processor on reasonable data protection grounds within the notice period, we will work with you in good faith to address your concern. If we cannot, you may terminate the affected Services by written notice before the change takes effect, and we will refund any prepaid fees for the remainder of the term of those Services.
Flow-down. We impose data protection obligations on each Sub-processor that are at least as protective as those in this DPA, to the extent applicable to the service the Sub-processor performs, and we remain responsible to you for their performance.
DATA SUBJECT REQUESTS
Self-service. The Services let you query, correct, export, and delete Customer Data yourself: you can delete tables, pipelines, and workspaces, and in a BYOC deployment the data stays in your own account. You should use these features to respond to Data Subject requests where they suffice.
Requests sent to us. If a Data Subject contacts us directly about Personal Data in Customer Data, we will not respond except to direct them to you, unless the law requires otherwise, and where the request identifies you we will pass it to you without undue delay.
Assistance. Taking into account the nature of the processing, we will provide reasonable assistance with appropriate technical and organizational measures so you can meet your obligations to respond to Data Subject requests. For assistance beyond what the Services already provide, we may charge a reasonable fee where the law allows.
IMPACT ASSESSMENTS AND CONSULTATION
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with data protection impact assessments and with prior consultation of a Supervisory Authority, to the extent you cannot obtain the necessary information from this DPA, our Privacy Policy, and Annex II.
PERSONAL DATA BREACH
In Short: If a breach affects Personal Data in your Customer Data, we tell you without undue delay, and in any event within 72 hours of becoming aware of it.
Notice. We will notify you without undue delay, and in any event within 72 hours after becoming aware of a Personal Data Breach affecting Personal Data in Customer Data. We send the notice to the email addresses of the owners and admins of your organization.
Content. The notice will describe, to the extent known at the time: the nature of the breach; the categories and approximate number of Data Subjects and records concerned; the likely consequences; and the measures we have taken or propose to take. We may provide this information in phases as it becomes available.
Cooperation. We will cooperate reasonably with your investigation and with any notifications you must make. Our notice is not an admission of fault or liability. Unsuccessful attempts, such as port scans, failed logins, and blocked attacks that do not result in unauthorized access to Personal Data, are not Personal Data Breaches.
AI FEATURES AND MODEL PROVIDERS
In Short: AI features send the model provider only what it needs to answer. Under our agreements with the providers, that data is not used to train their models. We never use Customer Data to train AI models.
What is sent. When you or your users use AI features (the Manager and the specialist AI roles, SQL generation, dashboard generation, and data-quality rule generation), we send the AI model the information it needs to answer: the request, the names and types of the relevant tables and columns, and, where the feature needs it, query results or samples from Customer Data. AI features process Customer Data only when you or your users invoke them.
Who receives it. Depending on the feature, the request goes to Anthropic, OpenAI, or Google, each listed in Annex III. Under our agreements with these providers, data sent through their APIs is not used to train their models.
No training. We do not use Customer Data to train AI models, whether our own or a third party's.
Traces. We record traces of AI-feature requests in Braintrust so we can debug problems and improve quality. We keep these traces only as long as needed for that purpose.
Your own provider key. If your organization configures its own AI provider key, requests go to that provider under your own agreement with it. In that case the provider is your vendor, not our Sub-processor.
RETURN AND DELETION
During the term. You can export Customer Data at any time using the export features in the Services. You can delete a table, pipeline, or workspace from within the Services. Deleting a workspace deletes the Customer Data it holds.
BYOC. In a BYOC deployment, Customer Data at rest stays in your own cloud account throughout. When the Agreement ends we stop accessing that account, the data remains yours, and you delete it on your own schedule. We delete the metadata we hold as described below.
After the Agreement ends. You have 30 days to export any remaining Customer Data, as set out in the Agreement. After that window we delete Personal Data in Customer Data from our active systems within 30 days, and from backups as those backups expire in the ordinary course. Where the law requires us to keep some of it longer, we keep it confidential and process it only for that purpose.
Confirmation. On your written request we will confirm in writing that deletion has been completed.
AUDITS AND INFORMATION
Information. We will make available the information reasonably necessary to demonstrate compliance with our obligations under Article 28 of the GDPR and equivalent provisions of other Data Protection Laws. This includes this DPA, Annex II, our Privacy Policy, and written answers to reasonable security questionnaires, no more than once in any 12-month period unless a Personal Data Breach or a Supervisory Authority requires otherwise. Where we hold third-party audit reports or certifications, we will provide them on request under confidentiality.
Audits. If that information is not sufficient to meet a requirement of Data Protection Laws, you, or an independent auditor you appoint who is bound by confidentiality and is not our competitor, may audit our compliance with this DPA: no more than once in any 12-month period, on at least 30 days' written notice, during normal business hours, at your cost, and in a manner that does not unreasonably disrupt our business or put other customers' data at risk. Audit findings are confidential. We are not required to give access to Sub-processor premises, but we will help you obtain Sub-processor audit information where we can.
INTERNATIONAL TRANSFERS
In Short: Our control plane runs in the United States. For transfers from the EEA, the UK, and Switzerland we rely on the Standard Contractual Clauses, the UK Addendum, and the Swiss adaptations set out below.
Where processing happens. Our control plane is hosted in the United States on Fly.io and Supabase. Our Sub-processors and their locations are listed in Annex III. In a BYOC deployment the data plane runs in your own cloud account.
Transfers from the EEA
For Restricted Transfers subject to the GDPR, the SCCs are incorporated into this DPA by reference. Module Two (controller to processor) applies where you are a Controller. Module Three (processor to processor) applies where you are a Processor. You are the "data exporter" and we are the "data importer." The SCCs are completed as follows:
- Clause 7 (docking clause) applies.
- Clause 9: Option 2 (general written authorization) applies, with the 30-day notice period in Section 7 of this DPA.
- Clause 11(a): the optional language does not apply.
- Clause 13: the competent Supervisory Authority is determined as set out in Annex I, Part C.
- Clause 17: Option 1 applies. The SCCs are governed by the law of Ireland.
- Clause 18(b): disputes are resolved by the courts of Ireland.
- Annexes I, II, and III of the SCCs are completed by Annexes I, II, and III of this DPA.
Each party's acceptance of the Agreement is treated as signature of the SCCs.
Transfers from the United Kingdom
For Restricted Transfers subject to the UK GDPR, the UK Addendum is incorporated into this DPA by reference and amends the SCCs as set out in the UK Addendum. The Addendum is completed as follows: Table 1 (parties) is completed with the details in Annex I, Part A; Table 2 (selected SCCs) refers to the SCCs as completed above; Table 3 (appendix information) refers to Annexes I, II, and III of this DPA; and for Table 4, either party may end the UK Addendum as set out in section 19 of the UK Addendum.
Transfers from Switzerland
For Restricted Transfers subject to the FADP, the SCCs apply with these adaptations: references to the GDPR are read as references to the FADP; the competent Supervisory Authority is the Swiss Federal Data Protection and Information Commissioner; and the term "member state" is not interpreted to exclude Data Subjects in Switzerland from suing for their rights in Switzerland.
Government requests and other mechanisms
If we receive a legally binding request from a public authority for Personal Data, we will notify you unless the law prohibits it, challenge the request where we reasonably can, and disclose only the minimum required. If a transfer mechanism we rely on is invalidated, or a new one becomes available (such as an adequacy decision or a certification), we may rely on that mechanism and we will work with you in good faith to agree any replacement measures needed.
US STATE PRIVACY LAWS
In Short: Under the CCPA and similar state laws we are your service provider. We do not sell or share Personal Data, and we use it only to provide the Services to you.
Where US State Privacy Laws apply, we act as your "service provider," "contractor," or "processor," and you disclose Personal Data to us only for the business purpose of providing the Services under the Agreement. We will:
- not sell or share Personal Data;
- not retain, use, or disclose Personal Data for any purpose other than the business purposes specified in the Agreement, including any commercial purpose other than providing the Services, or outside the direct business relationship between you and us;
- not combine Personal Data with personal information we receive from others or collect ourselves, except as permitted for service providers, such as to detect security incidents or protect against fraud;
- comply with the obligations that apply to us under US State Privacy Laws and provide the same level of privacy protection as those laws require of you;
- notify you if we determine we can no longer meet these obligations;
- allow you to take reasonable and appropriate steps to ensure we use Personal Data consistently with your obligations, and, on notice, to stop and remediate any unauthorized use; and
- not re-identify deidentified data we receive from you.
We certify that we understand and will comply with these restrictions. Sections 3, 5, 7, 8, 12, and 13 of this DPA also apply to the processing of Personal Data under US State Privacy Laws.
LIABILITY
Each party's liability arising out of or in connection with this DPA, including the SCCs and the UK Addendum to the extent permitted by them, is subject to the exclusions and limitations of liability in the Agreement, and the liability cap in the Agreement is a single aggregate cap across the Agreement and this DPA. Nothing in this DPA limits a party's liability to Data Subjects under the SCCs, or any liability that cannot be limited under Data Protection Laws.
TERM, CHANGES, GOVERNING LAW, AND CONTACT
Term. This DPA remains in effect for as long as we process Personal Data in Customer Data, including after the Agreement ends, until deletion is complete under Section 12.
Changes. We may update this DPA to reflect changes in Data Protection Laws or in an available transfer mechanism, to add or change Sub-processors under Section 7, or otherwise with at least 30 days' notice by email or by a notice in the Services. No update will reduce the level of protection for Personal Data. If an update materially and adversely affects you, you may terminate as set out in the Agreement.
Governing law. This DPA is governed by the law that governs the Agreement, except that the SCCs are governed by the law of Ireland as stated in Section 14, and the UK Addendum is governed by the laws of England and Wales.
Contact. For questions about this DPA, a countersigned copy, or Sub-processor notices, email evan.rosa@optimaflo.io or write to OptimaFlo, LLC, 18310 Montgomery Village Ave, Gaithersburg, MD 20879, United States.
ANNEX I: DESCRIPTION OF THE PROCESSING
A. List of parties
Data exporter: the Customer. Name, address, and contact details are those in your OptimaFlo account or in the signed order form. Activities: using the Services to connect, transform, query, and analyze Customer Data. Role: Controller (or Processor on behalf of your own Controllers).
Data importer: OptimaFlo, LLC, 18310 Montgomery Village Ave, Gaithersburg, MD 20879, United States. Contact: evan.rosa@optimaflo.io. Activities: providing the Services. Role: Processor.
B. Description of the transfer and processing
- Categories of Data Subjects. The people whose Personal Data is contained in the sources you connect. Depending on your sources, this may include your customers, prospects, end users, website visitors, employees, contractors, and suppliers. You determine the sources.
- Categories of Personal Data. Determined by the sources you connect. It may include identifiers and contact details, account and transaction records, usage and analytics data, device and online identifiers, location data, and free-text content.
- Sensitive data. None intended. The Services are not designed for special categories of data, HIPAA-regulated health data, payment card data, or data about children, and you agree not to connect such data unless a separate signed agreement says otherwise. If you do, your instructions and the measures in Annex II apply, and you are responsible for any additional safeguards.
- Frequency. Continuous during the term: pipelines run when you run them or on the schedules you set, and queries and AI features run when you or your users invoke them.
- Nature of the processing. Ingestion (reading from connected sources), storage (Iceberg tables in the data plane and metadata in the control plane), transformation (SQL pipelines from Raw to Clean to Ready), querying and analysis (including AI-assisted SQL, analysis, and dashboards), data-quality checks, visualization, export, and deletion.
- Purpose. To provide, secure, and support the Services you request, as instructed by you under the Agreement.
- Duration. The term of the Agreement plus the export and deletion period in Section 12.
- Transfers to Sub-processors. As listed in Annex III, for the purposes stated there, for the same duration.
C. Competent Supervisory Authority
For transfers subject to the GDPR: the Supervisory Authority of the EU Member State in which you are established; if you are not established in the EU, the Supervisory Authority of the Member State in which your EU representative is established, or, failing that, of the Member State in which the Data Subjects whose Personal Data is transferred are located. For transfers subject to the UK GDPR: the UK Information Commissioner. For transfers subject to the FADP: the Swiss Federal Data Protection and Information Commissioner.
ANNEX II: TECHNICAL AND ORGANIZATIONAL MEASURES
These are the measures we maintain to protect Personal Data. They describe the Services as they operate today and are updated as the Services change, subject to Section 6.
- Architecture and data location. In a BYOC deployment the data plane (storage, compute, and orchestration) runs inside your own Google Cloud or AWS account and Customer Data at rest stays there; our control plane stores only the metadata needed to run the Services. Where you do not use BYOC, Customer Data is stored by us and our hosting providers in the United States. Each workspace has its own catalog and namespace, and access is scoped to the organization and workspace.
- Encryption. Data in transit between your browser and the Services, and between our services and Sub-processors, is encrypted with TLS. Control-plane data is encrypted at rest by our hosting providers. Workspace secrets and AI provider keys are encrypted at rest with symmetric encryption and decrypted only server-side when needed. In a BYOC deployment, encryption at rest for the data plane is provided by your cloud provider under your account's settings.
- Authentication. Users sign in with email and password or with Google. Two-factor authentication (TOTP) is available and users can enable it in their security settings. Sessions expire and are bound to a secure, HTTP-only cookie.
- Authorization. Role-based access within organizations and workspaces (owner, admin, member, viewer). Database row-level security policies scope records to the tenant they belong to.
- Cloud credentials. Where the provider supports it, we access your cloud account through identity federation (workload identity or cross-account roles) rather than long-lived keys. Where keys or secrets are needed, they are stored encrypted, accessed only by the services that need them, and masked in logs.
- Secrets management. Application secrets live in environment and secret managers, never in source code.
- Logging and monitoring. Error monitoring with default personal identifiers turned off, pipeline run logs, and traces of AI-feature requests, used to detect, diagnose, and fix problems.
- Availability and backups. Our hosting providers take routine backups of control-plane data. You are responsible for backups of the data you connect to or process through the Services, as set out in the Agreement.
- Secure development. All changes go through version control and review; automated tests, type checks, and lint run in continuous integration before deployment; development, staging, and production environments are separate.
- Personnel. Access to production systems is limited to personnel who need it for their role, under confidentiality obligations and least-privilege access.
- Sub-processor management. We assess Sub-processors before engaging them, bind them to data protection terms, and maintain the list in Annex III.
- Deletion. Deleting a workspace deletes the Customer Data it holds. End-of-term deletion follows Section 12.
- Incident response. We maintain a process to detect, assess, contain, and remediate security incidents, and to notify you as set out in Section 10.
ANNEX III: SUB-PROCESSORS
The Sub-processors below may process Personal Data contained in Customer Data. PostHog (product analytics) and Stripe (billing) process Account Data only, not Customer Data, and are listed at optimaflo.io/subprocessors and in our Privacy Policy. The page at optimaflo.io/subprocessors is the canonical, always-current list.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database and file storage for account, workspace, and pipeline metadata; control-plane storage. | United States |
| Fly.io, Inc. | Application hosting for the web app and API. | United States |
| Google Cloud (Google LLC) and Amazon Web Services, Inc. | Cloud infrastructure. In a BYOC deployment the data plane runs in your own account with that provider, not ours. | United States, or your own account |
| Anthropic, PBC | AI model provider for AI features. Receives the request, relevant table and column names and types, and, where the feature needs it, query results or samples. | United States |
| OpenAI, L.L.C. | AI model provider for AI features. Receives the request, relevant table and column names and types, and, where the feature needs it, query results or samples. | United States |
| Google LLC | AI model provider for AI features. Receives the request, relevant table and column names and types, and, where the feature needs it, query results or samples. | United States |
| Braintrust Data, Inc. | AI observability. Stores traces of AI-feature requests for debugging and quality. | United States |
| Functional Software, Inc. (Sentry) | Error monitoring. Error reports are sent with default personal identifiers turned off. | United States |
| Resend, Inc. | Transactional email: workspace invitations, alerts, and digests, which may include metadata such as table names and data-quality results. | United States |
We will update this list and give notice of changes as described in Section 7.