Data Processing Addendum

Version: 2026-08-08
Effective date: August 8, 2026

This Data Processing Addendum (“DPA”) forms part of the Infer by Flow7 Terms of Service, a signed order, or another agreement that incorporates it (“Agreement”).

This DPA is between the business customer identified in the applicable account, order, or Agreement (“Customer”) and the legal person or entity identified in the current Legal Operator Notice (“Infer”). It applies when Infer processes Customer Personal Data on behalf of Customer in connection with the Service.

1. Definitions

“Applicable Data Protection Law” means privacy, data-protection, and data-security law applicable to the processing under the Agreement, including where applicable the GDPR, UK GDPR, Swiss Federal Act on Data Protection, California Consumer Privacy Act as amended, and other U.S. state privacy laws.

“Customer Personal Data” means personal data contained in Customer Content that Infer processes on Customer’s behalf. It excludes account, billing, fraud, security, support, tax, sanctions, and direct-relationship data that Infer processes as controller or business as described in the Privacy Notice.

“Data Subject,” “Controller,” “Processor,” “Business,” “Service Provider,” “Sell,” “Share,” and “Processing” have the meanings assigned by Applicable Data Protection Law. “Subprocessor” means a third party engaged by Infer to process Customer Personal Data on Customer’s behalf.

“Security Incident” means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Infer. It does not include unsuccessful attempts or events that do not compromise Customer Personal Data.

2. Roles and scope

Customer is the Controller or Processor that determines the lawful purpose and instructions for Customer Personal Data. Infer is Customer’s Processor or Subprocessor.

For California and similar U.S. state laws, Infer is a Service Provider or Processor and will process Customer Personal Data only for the limited and specified business purposes in the Agreement and this DPA. Infer will not:

Account, billing, payment, fraud, sanctions, security, support, and compliance data that Infer determines the purposes and means of processing is governed by the Privacy Notice and is outside the processor scope of this DPA.

3. Customer instructions

Infer will process Customer Personal Data only on documented instructions from Customer, including instructions expressed through:

Infer may process Customer Personal Data where law requires. Unless legally prohibited, Infer will notify Customer before that processing.

Customer is responsible for:

Infer will promptly inform Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law, unless prohibited from doing so. Infer may suspend the affected processing while the parties address the issue.

4. Processing details

The subject matter, duration, nature, purpose, data types, and Data Subjects are described in Annex 1.

Infer’s application does not intentionally persist prompt/request content in its inference database. Standard and no-training response bodies may be retained for idempotent replay for up to approximately 24 hours. Zero-retention response bodies are not persisted for replay. Operational metadata, accounting receipts, security evidence, and legally required records may be retained under the Privacy Notice and Annex 1.

Customer acknowledges that the selected model-processing supplier and underlying provider receive Customer Personal Data necessary to execute the request. Provider practices can differ by route. Infer will make route privacy/retention information reasonably available through the Service, model registry, Documentation, or Subprocessor Notice.

5. Confidentiality and personnel

Infer will ensure that personnel authorized to process Customer Personal Data:

Infer will not disclose Customer Personal Data to a third party except as permitted by the Agreement, this DPA, Customer’s instructions, or law.

6. Security

Infer will maintain technical and organizational measures appropriate to the risk, taking into account the state of the art, implementation cost, processing nature and scope, and risks to individuals. Current measures are described in Annex 2.

Infer may update measures as technology and risk evolve, provided the overall level of protection is not materially reduced during the Agreement.

Customer is responsible for securely configuring its workspace, users, API keys, spend limits, applications, endpoints, data minimization, and downstream access.

7. Subprocessors

Customer gives Infer general written authorization to engage the categories and named Subprocessors described in the Subprocessor Notice, including infrastructure, payment, transactional email, identity, security, model gateway, and underlying model providers.

Infer will:

Customer may object within 15 calendar days after notice on reasonable data-protection grounds. The parties will try in good faith to resolve the objection through an alternative route, configuration, or other reasonable measure. If no reasonable alternative exists, Infer may disable the affected feature or Customer may terminate the affected processing and receive a refund of eligible unused paid credit.

Customer’s affirmative selection of a model or route after the relevant model provider and privacy terms are presented constitutes specific authorization for that model-processing provider in addition to the general authorization above.

8. Data Subject requests

Taking into account the nature of processing, Infer will provide reasonable assistance to Customer with requests to access, correct, delete, restrict, object, or port Customer Personal Data.

If Infer receives a request concerning Customer Personal Data for which Customer is the Controller, Infer may direct the requester to Customer and notify Customer when reasonably identifiable and lawful. Infer will not independently respond on the merits unless Customer authorizes it or law requires.

Customer remains responsible for verifying the requester, determining the response, and meeting statutory deadlines. Assistance beyond standard self-service functionality may be subject to reasonable fees if the request is unusually burdensome, unless law prohibits a fee.

9. Security Incidents

Infer will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data. Notification will be sent to the account security/privacy contact or another designated contact.

To the extent reasonably available, the notice will describe:

Infer may provide information in phases and may delay information when a law-enforcement authority lawfully requires. Notification is not an admission of fault or liability.

Infer will take reasonable steps to contain, investigate, remediate, and mitigate the Security Incident and will reasonably cooperate with Customer’s legally required assessment and notification. Customer is responsible for notices to regulators or Data Subjects unless law assigns that duty to Infer.

10. Assessments, consultations, and records

Taking into account the nature of processing and information available to Infer, Infer will provide reasonable assistance with:

Infer will maintain records required of a Processor under Applicable Data Protection Law.

11. Audits and information

Infer will make available information reasonably necessary to demonstrate compliance with this DPA, which may include security documentation, summaries, questionnaires, certifications, penetration-test summaries, or independent audit reports when available.

Once per 12-month period, or after a material Security Incident or regulator request, Customer may request a remote audit concerning Customer Personal Data. Customer must:

An on-site audit is available only when remote materials are insufficient to satisfy a legal requirement and subject to reasonable security and confidentiality controls.

12. Deletion and return

During the term, Customer may use available controls or submit an instruction to delete Customer Personal Data, subject to technical feasibility, route/provider constraints, and law.

After termination or account closure, Infer will delete or return Customer Personal Data within a reasonable period, ordinarily 30 days, unless:

Retained data will remain protected and will not be used for another purpose. Customer is responsible for exporting outputs or data it needs before closure.

13. International transfers

13.1 EEA transfers

If Customer Personal Data protected by the GDPR is transferred to Infer or a Subprocessor in a country without an applicable adequacy decision, the European Commission Standard Contractual Clauses issued under Decision 2021/914 (“EU SCCs”) are incorporated as follows:

If the parties’ roles require another SCC module, that module applies to the extent necessary to create a lawful transfer.

13.2 UK transfers

For Restricted Transfers subject to the UK GDPR, the EU SCCs as incorporated above apply together with the then-current UK International Data Transfer Addendum issued by the UK Information Commissioner. The parties are identified by the Agreement and Legal Operator Notice, the selected modules are those above, and either party may end the Addendum if a lawful replacement mechanism is implemented.

13.3 Switzerland

For Swiss transfers, references in the EU SCCs to the GDPR and EU law include the Swiss Federal Act on Data Protection where applicable; references to Member State include Switzerland for affected Data Subjects; and the competent authority is the Swiss Federal Data Protection and Information Commissioner where required.

13.4 Supplementary measures

Infer will use reasonable supplementary measures appropriate to the route and risk, which may include encrypted transport, access control, data minimization, short response retention, zero-retention routing, contractual restrictions, and review of government-access requirements.

Customer acknowledges that an inference request necessarily requires the selected model processor to access the submitted content in intelligible form while executing the request.

14. U.S. state privacy terms

To the extent U.S. state privacy law applies to Customer Personal Data:

The parties acknowledge that Customer discloses Customer Personal Data to Infer only for the limited and specified purposes in the Agreement and this DPA.

15. Liability and precedence

The liability limitations and exclusions in the Agreement apply to this DPA, including the data-protection/confidentiality super-cap stated in the Terms, except to the extent Applicable Data Protection Law prohibits a limitation.

If this DPA conflicts with the Agreement concerning Customer Personal Data, this DPA controls. The EU SCCs or another mandatory transfer instrument control over inconsistent provisions to the extent of the protected transfer.

16. Duration and termination

This DPA begins when Infer first processes Customer Personal Data and continues until processing ends. Provisions that must survive to protect retained data, complete deletion, handle a Security Incident, or comply with law remain effective.

17. Contact

Infer’s legal name and postal address are stated in the Legal Operator Notice.

Annex 1 — Processing description

A. Parties

Data exporter: Customer identified in the account, order, or Agreement.
Data importer: Infer operator identified in the Legal Operator Notice.
Data importer location: United States, with processing by authorized Subprocessors in locations described in the Subprocessor Notice and model registry.

B. Subject matter and purpose

Authentication, routing, third-party generative-AI inference, output delivery, temporary idempotent replay where enabled, usage measurement, receipts, support, security, abuse prevention, and related service operation.

C. Duration

The Service term plus the limited retention, deletion, backup, legal-hold, and compliance periods described in the Privacy Notice and this DPA.

D. Nature of processing

Receiving, transmitting, organizing, transforming as technically necessary, making available to the selected model processor, generating and returning output, temporarily storing output where enabled, measuring metadata, securing, deleting, and supporting Customer Personal Data.

E. Data Subjects

Customer personnel, contractors, customers, prospects, end users, website visitors, patients/clients only where contractually approved, and other persons whose data Customer elects to submit.

F. Personal-data categories

Identifiers, contact information, communications, documents, prompts, files, application data, user-generated content, professional or organization information, support information, and other personal data selected by Customer.

Customer must not submit payment authentication data, passwords, private keys, API secrets, protected health information subject to HIPAA, children’s data, biometric templates, government authentication credentials, or other highly sensitive data unless an additional written agreement expressly permits it.

G. Special-category data

Not intended for ordinary self-service processing. If Customer submits special-category, sensitive, or criminal-offence data without express approval, Customer remains responsible for the legal basis and the submission may be rejected, filtered, or deleted.

H. Frequency

Continuous or intermittent, as initiated by Customer’s API requests and account use.

I. Retention

Annex 2 — Technical and organizational measures

Infer’s measures include, as appropriate:

1. Access and identity

2. API and secret protection

3. Encryption and transport

4. Data minimization and retention

5. Financial integrity and fraud

6. Supplier and route integrity

7. Availability and resilience

8. Development and operations

Annex 3 — Approved Subprocessors

The current list and categories are incorporated from the Subprocessor Notice, including Stripe/Link, Resend, Google OAuth when used, Cloudflare when enabled, infrastructure providers, OpenRouter, Havenbyte LLC d/b/a ModelFlare, and the underlying model providers selected by Customer.