GDPR & CCPA/CPRA CompliantVersion v2.0.0 • Data Processor Agreement
Platform Privacy Policy & Data Protection Agreement
Learn how BoFlows protects enterprise data sovereignty. We act strictly as a Data Processor under GDPR Art. 28, utilize Zero-Knowledge AES-256-GCM encryption, disclose all trusted infrastructure subprocessors, and enforce automatic cryptographic data erasure.
1. Data Controller vs. Data Processor Designation (GDPR & CCPA)
BoFlows acts in distinct legal capacities depending on the context of data processing:
1.1 Data Processor / Service Provider:
With respect to all business data, client records, patient information, employee details, invoices, and files submitted to your workspace by you or your users ("Customer Data"), Customer is the Data Controller (under the European Union General Data Protection Regulation / UK GDPR) or Business (under the California Consumer Privacy Act / CPRA). BoFlows acts strictly as a Data Processor or Service Provider, processing Customer Data solely on Customer's documented instructions to provide the Services.
1.2 Data Controller:
BoFlows acts as a Data Controller only with respect to basic account registration credentials, direct billing contact information, and platform telemetry collected directly from account owners.
2. Categories of Information Collected & Processed
We collect and process the following categories of data:
• Account & Identity Information: Names, corporate email addresses, company name, phone numbers, and workspace role assignments.
• Billing & Transactional Information: Payment method metadata, billing addresses, and payment transaction IDs (cardholder PAN and CVV data is processed directly by Stripe).
• Workspace Operational Data: Project details, client CRM contacts, tasks, time entries, invoices, and scheduling records.
• System Telemetry & Logs: IP addresses, browser user agent, login timestamps, API access logs, and error telemetry.
• Optional Workforce Telemetry: Desktop activity metrics, time logs, and geolocation check-in coordinates when enabled by workspace administrators.
3. Verified Subprocessor Transparency Directory
BoFlows engages trusted third-party infrastructure subprocessors to deliver the platform. Each subprocessor is bound by strict Data Processing Addenda (DPAs) and industry security standards:
1. Supabase, Inc. (United States / European Union):
Role: Managed PostgreSQL database, session authentication, encrypted object storage, and real-time messaging.
Security: SOC2 Type II, ISO 27001, encrypted at rest and in transit.
2. Stripe, Inc. (United States / Global):
Role: Payment processing gateway, PCI-DSS Level 1 tokenized billing, recurring subscription lifecycle management.
Security: PCI-DSS Level 1 Certified Service Provider.
3. Groq, Inc. (United States):
Role: Stateless ultra-low latency Large Language Model (LLM) inference engine for autonomous AI assistant commands and natural language provisioning.
Data Policy: Zero Data Retention (ZDR); customer business data is processed ephemerally in volatile memory and is NEVER retained, logged, or used for model training.
4. Resend, Inc. (United States):
Role: Transactional email delivery service for magic link authentications, invoice dispatches, and system notifications.
Security: TLS 1.3 in-transit encryption, SOC2 aligned.
4. Zero-Knowledge Application-Layer Encryption & Key Custody
4.1 Cryptographic Isolation:
For enterprise and absolute privacy workspaces, BoFlows implements Zero-Knowledge Application-Layer Encryption utilizing AES-256-GCM authenticated encryption. Payloads are encrypted and decrypted exclusively in the client's browser or device prior to network transmission.
4.2 Zero Access Guarantee:
Because encryption keys are held exclusively in the customer's browser session or local key store, BoFlows engineers, database administrators, and automated backend systems cannot read, decrypt, inspect, or disclose encrypted tenant records.
4.3 Customer Key Custody:
Customer is solely responsible for backing up and maintaining the master recovery passphrase. If this passphrase is lost, the data is mathematically unrecoverable.
5. Data Retention, Portability & Cryptographic Erasure
5.1 Data Retention Schedule:
Active workspace data is retained for the duration of the customer's subscription. Upon workspace cancellation or termination, BoFlows maintains a thirty (30) day grace period during which the customer may export their workspace data.
5.2 Permanent Cryptographic Erasure:
Following the 30-day grace period, all customer database schemas, files, and backups are permanently and cryptographically purged from production databases and backup snapshots within sixty (60) days.
5.3 Data Portability & Web Decryptor:
Customer maintains the perpetual right to export Customer Data in standardized machine-readable formats (CSV, JSON). For zero-knowledge encrypted vaults, BoFlows provides an open-source, client-side browser decryptor tool allowing customers to decrypt their data locally without platform lock-in.
6. International Data Transfers & Standard Contractual Clauses (SCCs)
Where personal data originating from the European Economic Area (EEA), United Kingdom, or Switzerland is transferred to servers or subprocessors located in the United States or other jurisdictions, BoFlows ensures adequate protection through:
a) The European Commission's approved Standard Contractual Clauses (SCCs / Module 2 and Module 3);
b) The UK International Data Transfer Addendum;
c) Robust supplementary technical and organizational security measures, including AES-256 encryption at rest and TLS 1.3 in transit.
7. Data Subject Rights (GDPR & CCPA/CPRA)
Under applicable data protection laws, individuals have specific legal rights regarding their personal data:
• Right of Access & Portability: Request confirmation of data processing and obtain an export copy of personal records.
• Right to Rectification: Correct inaccurate, out-of-date, or incomplete records.
• Right to Erasure ("Right to be Forgotten"): Request permanent deletion of personal data where no statutory retention obligations apply.
• Right to Restrict or Object: Restrict processing or object to automated decision-making.
Data Subject Requests for Workspace Records:
Because BoFlows is a Data Processor for customer workspace data, individuals whose records are stored in a customer's workspace (patients, clients, employees) should direct their requests directly to the Customer (the Data Controller). BoFlows will assist Customer in fulfilling valid Data Subject Requests.
8. Security Safeguards, SOC2 Alignment & Incident Notification
8.1 Technical and Organizational Safeguards:
BoFlows implements defense-in-depth technical safeguards:
• AES-256 encryption for all data at rest and TLS 1.3 for all data in transit;
• Multi-tenant Row-Level Security (RLS) isolating all database operations by tenant organization ID;
• Mandatory role-based access control (RBAC) and optional multi-factor authentication (MFA);
• Automated vulnerability scanning and continuous dependency auditing.
8.2 Incident Notification Protocol:
In the event of a confirmed Security Incident resulting in unauthorized access, exposure, or compromise of unencrypted Customer Data, BoFlows will notify affected Customer administrators without undue delay and within seventy-two (72) hours of becoming aware of the incident, providing detailed information regarding the nature, scope, and remedial actions taken.