Data Processing Addendum

Effective 8 August 2026 · Last updated 8 August 2026

How we handle personal information that we process on your behalf when your organization uses CrowFlo. This forms part of the Terms of Service and applies automatically to business customers; you do not need to sign it.

1. Scope and how this fits together

This Data Processing Addendum (the “DPA”) forms part of the Terms of Service between DocuSkill LLC (“DocuSkill”, “we”) and the business customer agreeing to them (“Customer”, “you”). It applies where we process Personal Information on your behalf in providing CrowFlo.

It applies automatically to business customers on a standard subscription; you do not need to sign it separately. If you have a separately signed master services agreement, statement of work or order form containing data-protection terms, those control to the extent they conflict with this DPA.

Terms defined in the Terms of Service and the Privacy Policy have the same meaning here. “Personal Information” means information relating to an identified or identifiable individual that we process on your behalf as part of the Customer Content.

This DPA is written for the offering as it stands: CrowFlo is provided to business customers in the United States, and it addresses the United States state privacy laws that govern that offering. If we extend the Service to another region, this DPA will be extended with the terms and the transfer mechanism that region requires before we launch there, rather than adjusted afterwards.

2. Our roles

For Customer Content, you are the business or controller and we are the service provider or processor. We process Personal Information only on your documented instructions.

Your instructions are: the Terms of Service, this DPA, the configuration choices you make in the product, and any further written instruction we agree to. Using a feature is an instruction to perform it - enabling an AI feature instructs us to send the relevant context to an AI provider, and enabling an integration instructs us to exchange data with it.

For account, billing, security, product-usage and diagnostic information we act as an independent business or controller, as described in clause 2 of the Privacy Policy. This DPA does not apply to that processing.

We will tell you if, in our opinion, an instruction infringes applicable privacy law, and may pause the affected processing until it is resolved.

3. Service provider commitments

These are the commitments US state privacy laws require of a service provider, and we make them expressly. We will not:

  • sell or share Personal Information, as those terms are defined by applicable law;
  • retain, use or disclose Personal Information for any purpose other than performing the Service and the business purposes set out in Annex A, or as otherwise permitted by law;
  • retain, use or disclose Personal Information outside the direct business relationship between us; or
  • combine Personal Information received from you with information received from another source, except where applicable law expressly permits a service provider to do so.

We certify that we understand these restrictions and will comply with them. If we determine that we can no longer meet them, we will notify you promptly, and you may take reasonable steps to stop and remediate the unauthorized processing.

You may take reasonable and appropriate steps to confirm that we use Personal Information consistently with your obligations under applicable law, as described in clause 9.

4. Your responsibilities

You are responsible for: the accuracy and lawfulness of the Personal Information you put into CrowFlo; having the authority, notices, consents and lawful basis to provide it; configuring access permissions within your organization; and responding to individuals whose information appears in your projects.

You must not submit special-category or highly sensitive information - health, biometric, genetic, precise geolocation, government identifiers, financial account data, or information about criminal offences - unless a separately signed agreement expressly permits it and describes the safeguards that apply.

Where you enable an AI feature or an integration, you are responsible for deciding that the resulting processing is appropriate for the information involved.

5. Confidentiality and personnel

We limit access to Personal Information to personnel who need it to provide or support the Service, and those personnel are bound by confidentiality obligations.

People at DocuSkill may access customer content where necessary to provide support, investigate a fault, or respond to a security incident, as described in clause 6.3 of the Privacy Policy. We do not currently operate formal background screening or a documented training programme, and we would rather say so than imply controls we do not have.

6. Security

We maintain technical and organizational measures designed to protect Personal Information. The measures currently in place are those described in clause 13 of the Privacy Policy: encryption of traffic in transit, AES-GCM encryption at rest for secrets, role-based access control within each organization, audit logging of changes to project records, and support for single sign-on and directory synchronization.

We may update these measures, and will not materially reduce the overall level of protection during your subscription.

We do not currently hold a third-party security certification, and we do not claim formal vulnerability management or penetration-testing programmes. The measures listed above are what is in place. We will add to this clause as that changes rather than describe intentions as practices.

7. Security incidents

If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Information we process for you, we will notify you without undue delay, provide the information reasonably available to us, and keep you updated as we learn more.

We will take reasonable steps to contain and remediate the incident. Our notification is not an acknowledgment of fault or liability.

We will notify you no later than 72 hours after becoming aware of the incident.

8. Subprocessors

You authorize us to engage subprocessors to provide the Service. The current list is published at www.crowflo.com/subprocessors and identifies each subprocessor and what it does.

Each subprocessor is engaged under its own standard published terms rather than under an agreement we have negotiated, so we do not represent that they carry obligations equivalent to those in this DPA. We remain responsible to you for our own performance, and for the fact that we chose them.

AI providers are subprocessors and are listed. Where you configure your own provider credentials under Bring Your Own AI, that provider is not our subprocessor: you contract with it directly and its terms govern.

We give notice of a change to that list by updating the page, which shows when it last changed. We do not currently send individual notifications and do not offer a right to object to a particular subprocessor under standard terms; if that matters to you, raise it before signing and it can be dealt with in a negotiated agreement.

9. Assistance, audits and individual rights

We will provide reasonable assistance, at your expense where the effort is substantial, with: responding to requests from individuals exercising privacy rights; carrying out data-protection assessments; and consulting a regulator, where applicable law requires it.

If an individual contacts us directly about Personal Information in your projects, we will refer them to you rather than respond on your behalf, unless the law requires otherwise.

Standard terms do not include an audit right. We will respond in writing to reasonable questions about how we handle your information, but we do not undertake to complete security questionnaires on request, to provide a third-party audit report, or to host an on-site or remote audit. Audit rights are available in a negotiated enterprise agreement.

10. Deletion and return

On the end of your subscription, the retention and deletion process in clause 26 of the Terms of Service applies: account data may be deleted from primary systems at any time, with no undertaking to delete it by a particular date, and backups are overwritten in the ordinary cycle within 90 days of deletion. There is no retrieval period.

The only export in the product is a PDF of the project dashboard, so CrowFlo cannot return your data in a reusable form. You must maintain your own records of anything you need to keep, throughout your subscription rather than at the end of it.

We may retain Personal Information where applicable law requires, or for legal holds, fraud and security investigations, the preservation of evidence in a dispute, and financial record requirements. Retained information stays subject to this DPA.

11. Annex A - details of processing

Subject matter and duration

Provision of the CrowFlo project-management and project-intelligence platform, for the duration of your subscription and the retention period in clause 10.

Nature and purpose

Hosting, storing, organizing, indexing, analyzing and displaying Customer Content; deriving project relationships and project graphs; generating AI analysis, summaries, forecasts and recommendations you request; personalizing results for your organization; maintaining, securing, evaluating and improving the Service; supporting integrations you enable; and providing support.

Categories of individual

Your personnel and authorized users; and any individual named in the project information you submit, which typically includes assignees, owners, decision makers, meeting attendees and other project participants.

Categories of Personal Information

Identity and contact details (name, email, organization, role); professional and assignment information (tasks held, responsibilities, allocation, availability); content authored (comments, notes, descriptions, meeting notes); AI prompts and interactions; and inferences derived from the above, including project-graph relationships and analytical outputs such as forecasts and assessments about the work an individual holds.

CrowFlo does not currently ingest meeting audio recordings or machine-generated transcripts.

Sensitive information

None is intended or permitted. See clause 4.

12. General

Liability under this DPA is subject to the limitations in clause 28 of the Terms of Service.

If a provision of this DPA is held unenforceable, it is modified to the minimum extent necessary or severed, and the rest continues. Where this DPA conflicts with the Terms of Service on the processing of Personal Information, this DPA controls.

We may update this DPA to reflect changes in law or in the Service, on reasonable notice, and will not materially reduce your protections during your subscription. Questions: [email protected].