Legal
Data processing agreement
How Nexfloe processes personal data inside Customer Data as a processor: scope, security, sub-processors, data subject requests, breach notification and deletion.
Last updated
This data processing agreement forms part of the subscription agreement between you and Nexfloe Technologies Private Limited. It applies where Customer Data contains personal data. Where you need it signed as a standalone document, email the address at the foot of this page and we will countersign the same terms.
1. Roles
You are the Data Fiduciary under the Digital Personal Data Protection Act, 2023 and, where the GDPR applies, the Controller. Nexfloe Technologies Private Limited is the Data Processor. You decide why and how personal data is processed. We process it only on your documented instructions, of which this agreement and the subscription agreement are the standing set.
2. Subject matter and duration
The subject matter is the provision of the FleekERP platform. Processing lasts for the term of the subscription agreement and the deletion period that follows it.
3. Nature and purpose of processing
Hosting, storage, structuring, retrieval, display and backup of Customer Data so that your people can plan, record and report manufacturing work, and so that we can support you when you ask.
4. Categories of data subject and personal data
| Data subjects | Personal data |
|---|---|
| Your employees: operators, supervisors, quality staff | Name, employee code, role, shift, login identifier, the production entries they make and the time of each |
| Your office users | Name, work email, phone, role, authentication data, audit trail of actions |
| Your customer and vendor contacts | Name, company, work email, phone, where you enter them as master data |
We do not ask for, and the platform is not designed to hold, special category or sensitive personal data. Do not enter health, biometric, financial account or government identifier data unless it has been agreed with us in writing first.
5. Our obligations
- Process personal data only on your documented instructions, including for transfers, unless required by law, in which case we tell you first unless the law forbids it.
- Ensure people authorised to process personal data are bound by confidentiality.
- Implement the technical and organisational measures described in the security section below and on our security page.
- Respect the conditions in clause 7 before engaging a sub-processor.
- Assist you, so far as is reasonable, with data subject requests, impact assessments and consultations with a regulator.
- Delete or return personal data at the end of the service as set out in clause 11.
- Make available the information reasonably needed to show these obligations are met.
6. Security measures
Encryption in transit and at rest, role-based access control with least privilege, multi-factor authentication for administrative access, segregated environments, centralised logging with alerting, regular backups with restore testing, vulnerability management, and background-checked personnel under confidentiality obligations. The security page describes these in more detail.
We hold no security or privacy certification today. Our controls are designed against the Digital Personal Data Protection Act, 2023, the GDPR where it applies, and the OWASP Top 10, and our cloud provider holds ISO 27001 and SOC 2 for the infrastructure layer. ISO 27001 certification of Nexfloe's own management system is in progress.
7. Sub-processors
You give general authorisation for the sub-processors below. We impose data protection obligations on each that are no less protective than these, and we remain liable to you for their performance. We give at least 30 days' notice before adding or replacing one. If you reasonably object on data protection grounds within that period, and we cannot offer an alternative, you may terminate the affected part of the service and receive a pro rata refund of prepaid fees.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, storage and backup of the platform | India |
| Resend | Transactional email for website enquiries and platform notifications | United States |
| Google (Analytics, Tag Manager) | Aggregate website traffic measurement, subject to consent | United States |
8. Data subject and data principal requests
The platform lets you find, correct, export and delete records yourself, which is the fastest route for most requests. Where you cannot, we assist within a reasonable time. If a data subject contacts us directly about your data, we do not respond on your behalf beyond telling them to contact you, and we notify you promptly.
9. Personal data breach
We notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your Customer Data, with the nature of the breach, the categories and approximate number of records, the likely consequences and the measures taken. We report to the Data Protection Board of India as required, and where the GDPR applies we support your obligations under Articles 33 and 34. Notification is not an admission of fault.
10. Audit
On reasonable written notice, no more than once a year unless a regulator requires otherwise, we provide the information needed to demonstrate compliance with this agreement and, where that is not enough, allow an audit by you or an independent auditor bound by confidentiality. Audits are at your cost, during business hours, and conducted so as not to disrupt the service or other customers.
11. Return and deletion
You may export personal data throughout the term and for 30 days after termination. We delete it from live systems within 60 days of termination and from backups within a further 90 days, unless retention is required by law, in which case we keep only what is required, for only as long as required, and continue to protect it under these terms.
12. International transfers
The platform and Customer Data are hosted in India. Two sub-processors above are outside India and process limited data, as described. Where personal data of EEA or UK individuals is transferred out of those regions, the transfer relies on the European Commission's Standard Contractual Clauses or the UK Addendum, which are incorporated into this agreement by reference and prevail over it in the event of conflict.
13. Liability
Liability under this agreement is subject to the limitation of liability in the subscription agreement. Nothing here limits a data subject's rights or any liability that cannot be limited by law.
14. Contact
Nexfloe Technologies Private Limited, Chennai, Tamil Nadu, India. Email info@fleekerp.com. Phone +91 99411 11019.
Grievance Officer: K. Silambarasan, Grievance Officer and Data Protection Contact. Email grievance@fleekerp.com. We acknowledge within 48 hours and respond within 30 days, as required by the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines) Rules, 2021.