Data Processing Addendum
Version 1.0 · September 21, 2026 · Applies to every customer account
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Flex Services, LLC ("Flex", "we") and the business that holds a Flex on the Job account ("Customer", "you"). It sets out how we process the personal data you put into Flex on your behalf.
1. Definitions
- Customer Data — everything you and your users enter into or upload to Flex: customers, jobs, invoices, inventory, users, notes, photos, and the personal data inside them (names, emails, phone numbers, addresses of your customers and staff).
- Personal Data, Processing, Controller, Processor, Data Subject and Sub-processor have the meanings given in applicable data protection law, including the GDPR, UK GDPR and the CCPA/CPRA (where "Processor" reads as "Service Provider").
- Services — Flex on the Job: the web app, API, MCP server, webhooks, sync service and companion desktop and mobile apps.
2. Roles
You are the Controller (or Business) of Customer Data. Flex is the Processor (or Service Provider). Where Flex processes data about your account holders for its own purposes — billing, security logging, support correspondence — Flex is a Controller of that data and the Privacy Policy applies.
3. Instructions and purpose
We process Customer Data only (a) to provide, secure, support and improve the Services as described in the Terms and in your configuration of the product, (b) as you or your users instruct through the product, API or support requests, and (c) as required by law, in which case we'll tell you first unless the law forbids it. We do not sell Customer Data, share it for cross-context behavioural advertising, combine it with data from other customers, or use it to train machine-learning models. If we think an instruction breaks the law, we'll say so and may pause it.
4. Confidentiality and personnel
Only staff and contractors who need production access to operate the Services have it. They are bound by written confidentiality obligations, and access is individually credentialed and logged. Staff access to a customer's data is limited to what a support request or an operational task requires.
5. Security measures
We maintain the technical and organisational measures described on the Security page, which forms part of this DPA. In summary:
- TLS 1.2+ with HSTS on every hostname; plain HTTP redirected; webhooks delivered only to HTTPS endpoints.
- Passwords as salted, iterated hashes (ASP.NET Core Identity); API keys as salted PBKDF2-SHA512 hashes, shown once.
- Every record carries its organization; every query, API call and MCP tool is filtered by the caller's organization on the server.
- Roles and more than 30 fine-grained permissions; API keys can never hold more than their creator.
- Job, stock and payment history with who-did-what; API and MCP request logs per key.
- Database snapshot before every production deployment; rolling encrypted off-site backups kept for up to 30 days.
- Signed webhooks (HMAC-SHA256); private and link-local delivery targets refused.
We may improve these measures over time; we won't materially weaken them during your subscription.
6. Sub-processors
You authorise the sub-processors below. We'll post any addition to this list and to the Privacy Policy at least 14 days before it processes Customer Data, and email account administrators when the addition would see your business data (not just billing or support metadata). If you object on reasonable data-protection grounds and we can't resolve it, you may cancel and section 5 of the Terms (refunds) applies.
| Sub-processor | Purpose | Location | Data |
|---|---|---|---|
| Our U.S. hosting provider | Servers that run the app, API and database | United States | All Customer Data, at rest and in transit |
| Cloudflare, Inc. | DNS, inbound email routing, encrypted off-site backup storage | United States (global network) | Encrypted database backups; email to our support addresses |
| Stripe, Inc. | Payments and invoicing | United States | Billing contact, company name, plan; card data goes directly to Stripe |
| Zoho Corporation | Outbound transactional email | United States | Recipient address and the message we send |
| Brevo (Sendinblue SAS) | Demo requests and enquiries from the marketing website | European Union | What is typed into the website contact form only |
| Google LLC | reCAPTCHA on website forms | United States | IP address and interaction signals on pages with a form; no Customer Data |
| Intuit Inc. (QuickBooks) | Only if you export to or connect QuickBooks | United States | The invoices and customers you choose to send |
7. Data location and transfers
Customer Data is stored and processed in the United States. If you are subject to the GDPR or UK GDPR, transfers to Flex are made under the EU Standard Contractual Clauses (Module 2, controller-to-processor) and the UK International Data Transfer Addendum, which are incorporated by reference with Flex as data importer, Customer as data exporter, this DPA as the description of processing, and section 5 as the technical and organisational measures. Ask security@flexonthejob.com for a completed, signed copy.
8. Data subject requests
Account administrators can view, correct, export and delete most personal data directly in the product. If a data subject contacts us directly about Customer Data, we'll refer them to you and, where lawful, tell you they asked. We'll help you respond to access, correction, deletion, portability and objection requests within the timeframes the law gives you, at no charge for reasonable volumes.
9. Security incidents
If we confirm a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Customer Data, we'll notify your account administrators by email within 72 hours of confirmation with what we know: what happened, what data and organizations are affected, what we've done and what we recommend you do. We'll update you as we learn more and post a summary on status.flexonthejob.com. Notification is not an admission of fault.
10. Audit and assistance
Once per year, or after a security incident affecting you, you may ask us to complete your security questionnaire and provide the evidence behind the Security page (architecture description, backup and access-control practices, sub-processor list, penetration-test summary once we have one). We have not undergone a SOC 2 or ISO 27001 audit and will say so rather than imply one. On-site audits are available on 30 days' notice, at your cost, during business hours and under confidentiality, where a questionnaire and documentary evidence are insufficient for a legal requirement you tell us about. We'll help with data protection impact assessments and regulator consultations to the extent the information is available only to us.
11. Return and deletion
While your account is open you can export everything at any time: every collection through the API with cursor paging, invoices as CSV, and a full account export on request to support@flexonthejob.com (delivered within 10 business days). After closure we delete or irreversibly anonymise Customer Data within 90 days; encrypted backups age out within a further 30 days. We keep billing records for as long as tax and accounting law requires. On request we'll confirm deletion in writing.
12. CCPA / CPRA
To the extent Customer Data includes personal information of California residents, Flex is a Service Provider: we process it only for the business purposes above, do not sell or share it, do not retain, use or disclose it outside the direct business relationship, and will notify you if we can no longer meet these obligations. We certify that we understand these restrictions.
13. Liability and precedence
Each party's liability under this DPA is subject to the limits in the Terms of Service. Where this DPA conflicts with the Terms on the processing of personal data, this DPA controls; where it conflicts with the Standard Contractual Clauses, the Clauses control.
14. Changes
We may update this DPA to reflect changes in law or in the Services. Material changes are emailed to account administrators at least 30 days before they take effect and the version and date at the top of this page are updated. Previous versions are available on request.
15. Contact
Flex Services, LLC · South Carolina, USA
Security and privacy: security@flexonthejob.com · General: support@flexonthejob.com
See also the Privacy Policy, the Terms of Service and the Security page.