Data Processing Addendum
Version: 2026-08-08
Effective date: August 8, 2026
This Data Processing Addendum (“DPA”) forms part of the Infer by Flow7 Terms of Service, a signed order, or another agreement that incorporates it (“Agreement”).
This DPA is between the business customer identified in the applicable account, order, or Agreement (“Customer”) and the legal person or entity identified in the current Legal Operator Notice (“Infer”). It applies when Infer processes Customer Personal Data on behalf of Customer in connection with the Service.
1. Definitions
“Applicable Data Protection Law” means privacy, data-protection, and data-security law applicable to the processing under the Agreement, including where applicable the GDPR, UK GDPR, Swiss Federal Act on Data Protection, California Consumer Privacy Act as amended, and other U.S. state privacy laws.
“Customer Personal Data” means personal data contained in Customer Content that Infer processes on Customer’s behalf. It excludes account, billing, fraud, security, support, tax, sanctions, and direct-relationship data that Infer processes as controller or business as described in the Privacy Notice.
“Data Subject,” “Controller,” “Processor,” “Business,” “Service Provider,” “Sell,” “Share,” and “Processing” have the meanings assigned by Applicable Data Protection Law. “Subprocessor” means a third party engaged by Infer to process Customer Personal Data on Customer’s behalf.
“Security Incident” means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Infer. It does not include unsuccessful attempts or events that do not compromise Customer Personal Data.
2. Roles and scope
Customer is the Controller or Processor that determines the lawful purpose and instructions for Customer Personal Data. Infer is Customer’s Processor or Subprocessor.
For California and similar U.S. state laws, Infer is a Service Provider or Processor and will process Customer Personal Data only for the limited and specified business purposes in the Agreement and this DPA. Infer will not:
- sell or share Customer Personal Data;
- retain, use, or disclose Customer Personal Data outside the direct business relationship except as permitted by law;
- combine Customer Personal Data with personal data received from another person or collected from Infer’s own consumer interactions except as permitted by law to provide, secure, or improve the Service without building cross-customer profiles from prompt content; or
- use Customer Personal Data for cross-context behavioral advertising.
Account, billing, payment, fraud, sanctions, security, support, and compliance data that Infer determines the purposes and means of processing is governed by the Privacy Notice and is outside the processor scope of this DPA.
3. Customer instructions
Infer will process Customer Personal Data only on documented instructions from Customer, including instructions expressed through:
- API requests, prompts, files, tool definitions, and parameters;
- the selected model, routing tier, privacy/retention mode, and account settings;
- workspace configuration and authorized users;
- support requests;
- the Agreement and Documentation; and
- instructions required to delete, return, secure, or assist with Customer Personal Data.
Infer may process Customer Personal Data where law requires. Unless legally prohibited, Infer will notify Customer before that processing.
Customer is responsible for:
- the lawfulness, fairness, and transparency of its instructions;
- a valid legal basis and required notices or consents;
- honoring Data Subject rights;
- data accuracy, minimization, and retention choices;
- ensuring its users are authorized;
- selecting a model, route, and privacy mode appropriate for the data; and
- complying with restrictions on special-category, sensitive, children’s, biometric, health, criminal, financial-authentication, or government-identifier data.
Infer will promptly inform Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law, unless prohibited from doing so. Infer may suspend the affected processing while the parties address the issue.
4. Processing details
The subject matter, duration, nature, purpose, data types, and Data Subjects are described in Annex 1.
Infer’s application does not intentionally persist prompt/request
content in its inference database. Standard and
no-training response bodies may be retained for idempotent
replay for up to approximately 24 hours. Zero-retention
response bodies are not persisted for replay. Operational metadata,
accounting receipts, security evidence, and legally required records may
be retained under the Privacy Notice and Annex 1.
Customer acknowledges that the selected model-processing supplier and underlying provider receive Customer Personal Data necessary to execute the request. Provider practices can differ by route. Infer will make route privacy/retention information reasonably available through the Service, model registry, Documentation, or Subprocessor Notice.
5. Confidentiality and personnel
Infer will ensure that personnel authorized to process Customer Personal Data:
- are bound by contractual or statutory confidentiality duties;
- receive appropriate privacy and security obligations;
- access Customer Personal Data only as necessary for their role; and
- are subject to appropriate access controls and disciplinary consequences.
Infer will not disclose Customer Personal Data to a third party except as permitted by the Agreement, this DPA, Customer’s instructions, or law.
6. Security
Infer will maintain technical and organizational measures appropriate to the risk, taking into account the state of the art, implementation cost, processing nature and scope, and risks to individuals. Current measures are described in Annex 2.
Infer may update measures as technology and risk evolve, provided the overall level of protection is not materially reduced during the Agreement.
Customer is responsible for securely configuring its workspace, users, API keys, spend limits, applications, endpoints, data minimization, and downstream access.
7. Subprocessors
Customer gives Infer general written authorization to engage the categories and named Subprocessors described in the Subprocessor Notice, including infrastructure, payment, transactional email, identity, security, model gateway, and underlying model providers.
Infer will:
- impose data-protection obligations on a Subprocessor that are materially protective of Customer Personal Data and consistent with this DPA;
- remain responsible to Customer for the Subprocessor’s performance of those obligations to the extent required by law and the Agreement;
- provide at least 30 calendar days’ notice before a new direct Subprocessor begins processing Customer Personal Data, when reasonably practicable; and
- provide notice as soon as reasonably practicable for an urgent change required by security, law, provider availability, or service continuity.
Customer may object within 15 calendar days after notice on reasonable data-protection grounds. The parties will try in good faith to resolve the objection through an alternative route, configuration, or other reasonable measure. If no reasonable alternative exists, Infer may disable the affected feature or Customer may terminate the affected processing and receive a refund of eligible unused paid credit.
Customer’s affirmative selection of a model or route after the relevant model provider and privacy terms are presented constitutes specific authorization for that model-processing provider in addition to the general authorization above.
8. Data Subject requests
Taking into account the nature of processing, Infer will provide reasonable assistance to Customer with requests to access, correct, delete, restrict, object, or port Customer Personal Data.
If Infer receives a request concerning Customer Personal Data for which Customer is the Controller, Infer may direct the requester to Customer and notify Customer when reasonably identifiable and lawful. Infer will not independently respond on the merits unless Customer authorizes it or law requires.
Customer remains responsible for verifying the requester, determining the response, and meeting statutory deadlines. Assistance beyond standard self-service functionality may be subject to reasonable fees if the request is unusually burdensome, unless law prohibits a fee.
9. Security Incidents
Infer will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data. Notification will be sent to the account security/privacy contact or another designated contact.
To the extent reasonably available, the notice will describe:
- the nature of the Security Incident;
- affected data and Data Subject categories;
- likely consequences;
- measures taken or proposed; and
- a contact for follow-up.
Infer may provide information in phases and may delay information when a law-enforcement authority lawfully requires. Notification is not an admission of fault or liability.
Infer will take reasonable steps to contain, investigate, remediate, and mitigate the Security Incident and will reasonably cooperate with Customer’s legally required assessment and notification. Customer is responsible for notices to regulators or Data Subjects unless law assigns that duty to Infer.
10. Assessments, consultations, and records
Taking into account the nature of processing and information available to Infer, Infer will provide reasonable assistance with:
- data-protection impact assessments;
- prior consultation with a regulator;
- records of processing; and
- Customer’s demonstration of compliance.
Infer will maintain records required of a Processor under Applicable Data Protection Law.
11. Audits and information
Infer will make available information reasonably necessary to demonstrate compliance with this DPA, which may include security documentation, summaries, questionnaires, certifications, penetration-test summaries, or independent audit reports when available.
Once per 12-month period, or after a material Security Incident or regulator request, Customer may request a remote audit concerning Customer Personal Data. Customer must:
- give at least 30 days’ notice unless urgent law requires less;
- use an independent auditor bound by confidentiality;
- avoid access to other customers’ data, supplier confidential information, and security-sensitive details;
- minimize disruption; and
- bear its costs and Infer’s reasonable costs for assistance beyond standard materials.
An on-site audit is available only when remote materials are insufficient to satisfy a legal requirement and subject to reasonable security and confidentiality controls.
12. Deletion and return
During the term, Customer may use available controls or submit an instruction to delete Customer Personal Data, subject to technical feasibility, route/provider constraints, and law.
After termination or account closure, Infer will delete or return Customer Personal Data within a reasonable period, ordinarily 30 days, unless:
- the data was already subject to a shorter retention period;
- law requires retention;
- a payment, fraud, sanctions, security, audit, legal-hold, or dispute record must be preserved; or
- data remains in a backup until the ordinary backup cycle removes it.
Retained data will remain protected and will not be used for another purpose. Customer is responsible for exporting outputs or data it needs before closure.
13. International transfers
13.1 EEA transfers
If Customer Personal Data protected by the GDPR is transferred to Infer or a Subprocessor in a country without an applicable adequacy decision, the European Commission Standard Contractual Clauses issued under Decision 2021/914 (“EU SCCs”) are incorporated as follows:
- Module Two applies when Customer is a Controller and Infer is a Processor.
- Module Three applies when Customer is a Processor and Infer is a Subprocessor.
- Clause 7 (docking) applies.
- Clause 9 uses Option 2 (general written authorization), with the notice period in Section 7.
- Clause 11 optional language does not apply.
- Clause 17 is governed by the law of the EU Member State in which the Customer/exporter is established; if the exporter is not established in an EU Member State, Irish law applies.
- Clause 18 selects the courts of the Member State identified under Clause 17.
- Annexes I through III are completed by this DPA, Annex 1, Annex 2, and the Subprocessor Notice.
If the parties’ roles require another SCC module, that module applies to the extent necessary to create a lawful transfer.
13.2 UK transfers
For Restricted Transfers subject to the UK GDPR, the EU SCCs as incorporated above apply together with the then-current UK International Data Transfer Addendum issued by the UK Information Commissioner. The parties are identified by the Agreement and Legal Operator Notice, the selected modules are those above, and either party may end the Addendum if a lawful replacement mechanism is implemented.
13.3 Switzerland
For Swiss transfers, references in the EU SCCs to the GDPR and EU law include the Swiss Federal Act on Data Protection where applicable; references to Member State include Switzerland for affected Data Subjects; and the competent authority is the Swiss Federal Data Protection and Information Commissioner where required.
13.4 Supplementary measures
Infer will use reasonable supplementary measures appropriate to the route and risk, which may include encrypted transport, access control, data minimization, short response retention, zero-retention routing, contractual restrictions, and review of government-access requirements.
Customer acknowledges that an inference request necessarily requires the selected model processor to access the submitted content in intelligible form while executing the request.
14. U.S. state privacy terms
To the extent U.S. state privacy law applies to Customer Personal Data:
- the business purposes are providing, securing, supporting, debugging, measuring, and maintaining the Service and complying with law;
- Infer will not sell or share Customer Personal Data;
- Infer will not retain, use, or disclose it outside the direct business relationship except as legally permitted;
- Customer may take reasonable and appropriate steps to help ensure Infer uses data consistently with Customer’s obligations;
- Infer will notify Customer if it determines it can no longer meet applicable Service Provider or Processor obligations; and
- Customer may take reasonable steps to stop and remediate unauthorized use.
The parties acknowledge that Customer discloses Customer Personal Data to Infer only for the limited and specified purposes in the Agreement and this DPA.
15. Liability and precedence
The liability limitations and exclusions in the Agreement apply to this DPA, including the data-protection/confidentiality super-cap stated in the Terms, except to the extent Applicable Data Protection Law prohibits a limitation.
If this DPA conflicts with the Agreement concerning Customer Personal Data, this DPA controls. The EU SCCs or another mandatory transfer instrument control over inconsistent provisions to the extent of the protected transfer.
16. Duration and termination
This DPA begins when Infer first processes Customer Personal Data and continues until processing ends. Provisions that must survive to protect retained data, complete deletion, handle a Security Incident, or comply with law remain effective.
17. Contact
- Privacy and DPA notices:
privacy@flow7.org - Security incidents:
security@flow7.org - Legal notices:
legal@flow7.org
Infer’s legal name and postal address are stated in the Legal Operator Notice.
Annex 1 — Processing description
A. Parties
Data exporter: Customer identified in the account,
order, or Agreement.
Data importer: Infer operator identified in the Legal
Operator Notice.
Data importer location: United States, with processing
by authorized Subprocessors in locations described in the Subprocessor
Notice and model registry.
B. Subject matter and purpose
Authentication, routing, third-party generative-AI inference, output delivery, temporary idempotent replay where enabled, usage measurement, receipts, support, security, abuse prevention, and related service operation.
C. Duration
The Service term plus the limited retention, deletion, backup, legal-hold, and compliance periods described in the Privacy Notice and this DPA.
D. Nature of processing
Receiving, transmitting, organizing, transforming as technically necessary, making available to the selected model processor, generating and returning output, temporarily storing output where enabled, measuring metadata, securing, deleting, and supporting Customer Personal Data.
E. Data Subjects
Customer personnel, contractors, customers, prospects, end users, website visitors, patients/clients only where contractually approved, and other persons whose data Customer elects to submit.
F. Personal-data categories
Identifiers, contact information, communications, documents, prompts, files, application data, user-generated content, professional or organization information, support information, and other personal data selected by Customer.
Customer must not submit payment authentication data, passwords, private keys, API secrets, protected health information subject to HIPAA, children’s data, biometric templates, government authentication credentials, or other highly sensitive data unless an additional written agreement expressly permits it.
G. Special-category data
Not intended for ordinary self-service processing. If Customer submits special-category, sensitive, or criminal-offence data without express approval, Customer remains responsible for the legal basis and the submission may be rejected, filtered, or deleted.
H. Frequency
Continuous or intermittent, as initiated by Customer’s API requests and account use.
I. Retention
- Inputs/prompts: transmitted for execution and not intentionally persisted in Infer’s application inference database.
- Standard/no-training response body: up to approximately 24 hours for idempotent replay.
- Zero-retention response body: not persisted for replay.
- Metadata and accounting/security records: retained under the Privacy Notice.
- Supplier retention: governed by the selected route, privacy mode, Model Terms, and Subprocessor arrangements.
Annex 2 — Technical and organizational measures
Infer’s measures include, as appropriate:
1. Access and identity
- role-based workspace and administrative access;
- least-privilege access practices;
- verified email before funding and API key activation;
- secure password hashing;
- secure, HttpOnly, SameSite session cookies;
- CSRF protections;
- OAuth state validation;
- multi-factor authentication for privileged systems where supported; and
- access revocation and account-state controls.
2. API and secret protection
- API keys displayed once and stored as secure hashes/prefixes rather than retrievable plaintext;
- key-level daily and monthly spend limits;
- rate limiting and abuse controls;
- key rotation/revocation;
- secret-management controls for provider and payment credentials; and
- prevention of secrets in ordinary logs where practicable.
3. Encryption and transport
- HTTPS/TLS for network transport;
- encryption at rest provided by managed infrastructure where applicable;
- signed Stripe webhook verification;
- authenticated supplier connections; and
- secure backup and administrative channels.
4. Data minimization and retention
- no intentional prompt/request persistence in Infer’s application inference database;
- approximately 24-hour maximum response replay for standard/no-training mode;
- no response-body replay storage in zero-retention mode;
- separation of inference content from accounting metadata where practicable;
- automated expiry/cleanup jobs; and
- legal holds and deletion controls.
5. Financial integrity and fraud
- idempotent payment and wallet handling;
- append-only or equivalent auditable ledger records;
- funding velocity, first-payment, balance, and top-up limits;
- payment-risk state and manual review for anomalous transactions;
- dispute and negative-balance locks;
- reconciliation of processor events and wallet entries; and
- sanctions, abuse, and fraud review controls.
6. Supplier and route integrity
- provider-health monitoring;
- price and model-integrity verification;
- route qualification and fallback controls;
- privacy/retention compatibility checks;
- First-Party Endpoint host locking without silent unrelated-host fallback; and
- supplier evidence and incident escalation.
7. Availability and resilience
- managed hosting and database resilience features;
- backups and restoration procedures appropriate to stored account/ledger data;
- monitoring, alerting, and incident response;
- rate limits and capacity controls; and
- route failover consistent with the selected tier and privacy settings.
8. Development and operations
- code review and controlled deployment practices;
- vulnerability and dependency remediation;
- separation of production and non-production access where practicable;
- logging and monitoring designed to avoid full prompt/response capture;
- incident-response and breach-assessment workflow; and
- vendor review proportionate to risk.
Annex 3 — Approved Subprocessors
The current list and categories are incorporated from the Subprocessor Notice, including Stripe/Link, Google OAuth when used, Cloudflare (including transactional email), infrastructure providers, OpenRouter, Havenbyte LLC d/b/a ModelFlare, and the underlying model providers selected by Customer.