Legal

Data Processing Addendum

Version 1.0 · September 21, 2026 · Applies to every customer account

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Flex Services, LLC ("Flex", "we") and the business that holds a Flex on the Job account ("Customer", "you"). It sets out how we process the personal data you put into Flex on your behalf.

The short version. You own the data and decide what happens to it; we process it only to run Flex for you. We use a short, published list of sub-processors, encrypt in transit and at rest for backups, tell you within 72 hours if there's a breach, and delete everything within 90 days of closure. This DPA applies automatically — nothing to sign. If your procurement process needs a countersigned copy, email security@flexonthejob.com and we'll return one within five business days.

1. Definitions

2. Roles

You are the Controller (or Business) of Customer Data. Flex is the Processor (or Service Provider). Where Flex processes data about your account holders for its own purposes — billing, security logging, support correspondence — Flex is a Controller of that data and the Privacy Policy applies.

3. Instructions and purpose

We process Customer Data only (a) to provide, secure, support and improve the Services as described in the Terms and in your configuration of the product, (b) as you or your users instruct through the product, API or support requests, and (c) as required by law, in which case we'll tell you first unless the law forbids it. We do not sell Customer Data, share it for cross-context behavioural advertising, combine it with data from other customers, or use it to train machine-learning models. If we think an instruction breaks the law, we'll say so and may pause it.

4. Confidentiality and personnel

Only staff and contractors who need production access to operate the Services have it. They are bound by written confidentiality obligations, and access is individually credentialed and logged. Staff access to a customer's data is limited to what a support request or an operational task requires.

5. Security measures

We maintain the technical and organisational measures described on the Security page, which forms part of this DPA. In summary:

We may improve these measures over time; we won't materially weaken them during your subscription.

6. Sub-processors

You authorise the sub-processors below. We'll post any addition to this list and to the Privacy Policy at least 14 days before it processes Customer Data, and email account administrators when the addition would see your business data (not just billing or support metadata). If you object on reasonable data-protection grounds and we can't resolve it, you may cancel and section 5 of the Terms (refunds) applies.

Sub-processorPurposeLocationData
Our U.S. hosting providerServers that run the app, API and databaseUnited StatesAll Customer Data, at rest and in transit
Cloudflare, Inc.DNS, inbound email routing, encrypted off-site backup storageUnited States (global network)Encrypted database backups; email to our support addresses
Stripe, Inc.Payments and invoicingUnited StatesBilling contact, company name, plan; card data goes directly to Stripe
Zoho CorporationOutbound transactional emailUnited StatesRecipient address and the message we send
Brevo (Sendinblue SAS)Demo requests and enquiries from the marketing websiteEuropean UnionWhat is typed into the website contact form only
Google LLCreCAPTCHA on website formsUnited StatesIP address and interaction signals on pages with a form; no Customer Data
Intuit Inc. (QuickBooks)Only if you export to or connect QuickBooksUnited StatesThe invoices and customers you choose to send

7. Data location and transfers

Customer Data is stored and processed in the United States. If you are subject to the GDPR or UK GDPR, transfers to Flex are made under the EU Standard Contractual Clauses (Module 2, controller-to-processor) and the UK International Data Transfer Addendum, which are incorporated by reference with Flex as data importer, Customer as data exporter, this DPA as the description of processing, and section 5 as the technical and organisational measures. Ask security@flexonthejob.com for a completed, signed copy.

8. Data subject requests

Account administrators can view, correct, export and delete most personal data directly in the product. If a data subject contacts us directly about Customer Data, we'll refer them to you and, where lawful, tell you they asked. We'll help you respond to access, correction, deletion, portability and objection requests within the timeframes the law gives you, at no charge for reasonable volumes.

9. Security incidents

If we confirm a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Customer Data, we'll notify your account administrators by email within 72 hours of confirmation with what we know: what happened, what data and organizations are affected, what we've done and what we recommend you do. We'll update you as we learn more and post a summary on status.flexonthejob.com. Notification is not an admission of fault.

10. Audit and assistance

Once per year, or after a security incident affecting you, you may ask us to complete your security questionnaire and provide the evidence behind the Security page (architecture description, backup and access-control practices, sub-processor list, penetration-test summary once we have one). We have not undergone a SOC 2 or ISO 27001 audit and will say so rather than imply one. On-site audits are available on 30 days' notice, at your cost, during business hours and under confidentiality, where a questionnaire and documentary evidence are insufficient for a legal requirement you tell us about. We'll help with data protection impact assessments and regulator consultations to the extent the information is available only to us.

11. Return and deletion

While your account is open you can export everything at any time: every collection through the API with cursor paging, invoices as CSV, and a full account export on request to support@flexonthejob.com (delivered within 10 business days). After closure we delete or irreversibly anonymise Customer Data within 90 days; encrypted backups age out within a further 30 days. We keep billing records for as long as tax and accounting law requires. On request we'll confirm deletion in writing.

12. CCPA / CPRA

To the extent Customer Data includes personal information of California residents, Flex is a Service Provider: we process it only for the business purposes above, do not sell or share it, do not retain, use or disclose it outside the direct business relationship, and will notify you if we can no longer meet these obligations. We certify that we understand these restrictions.

13. Liability and precedence

Each party's liability under this DPA is subject to the limits in the Terms of Service. Where this DPA conflicts with the Terms on the processing of personal data, this DPA controls; where it conflicts with the Standard Contractual Clauses, the Clauses control.

14. Changes

We may update this DPA to reflect changes in law or in the Services. Material changes are emailed to account administrators at least 30 days before they take effect and the version and date at the top of this page are updated. Previous versions are available on request.

15. Contact

Flex Services, LLC · South Carolina, USA
Security and privacy: security@flexonthejob.com · General: support@flexonthejob.com

See also the Privacy Policy, the Terms of Service and the Security page.