Data Processing Agreement (DPA)
This Data Processing Agreement governs the processing of personal data by BoFlows on behalf of the customer, in compliance with GDPR, CCPA, and SOC2 requirements.
1. Scope of Processing
BoFlows acts as a Data Processor for the 30+ core modules (CRM, HR, Finance, Inventory, etc.). The customer is the Data Controller. The Superadmin is responsible for configuring access rights via our Granular Role-Based Access Control (RBAC).
2. Immutable Audit Logs
To assist controllers with compliance, BoFlows maintains mandatory, immutable audit logs of all system mutations. These logs cannot be tampered with and are available for compliance reporting at any time.
3. Subcontractors & Vendor Rolodex
Customers may utilize the Vendor Rolodex module to onboard third-party freelancers. The customer is responsible for ensuring their own subcontractors agree to their internal processing terms before granting them access to BoFlows projects.