Data Processing Agreement (DPA)
Standard Contractual Clauses (SCCs) & GDPR Subprocessor Terms • August 2026
1. Scope and Applicability
This Data Processing Agreement ("DPA") supplements the Flixil Terms of Service and applies to the processing of personal data in connection with the provision of the Flixil AI infrastructure and observability platform under EU GDPR, UK GDPR, and CCPA regulations.
2. Technical & Organizational Measures (TOMs)
Flixil implements state-of-the-art security measures to safeguard customer data:
- AES-256-GCM Encryption at Rest: Master provider credentials and database backups are encrypted with hardware-grade cryptographic nonces.
- TLS 1.3 Encryption in Transit: All HTTP and SSE telemetry connections enforce modern cryptographic ciphers and HSTS.
- PostgreSQL Row-Level Security (RLS): Cryptographically enforced database kernel isolation between customer workspaces.
- Zero Prompt Retention: User prompts and completions are strictly processed in volatile memory and never persisted.
3. Authorized Subprocessors
Flixil utilizes the following infrastructure subprocessors:
4. Executing an Enterprise DPA
Enterprise customers requiring countersigned Standard Contractual Clauses (SCCs) or custom data localization guarantees can request an executable PDF agreement by contacting flixilsupport@gmail.com.
5. Security Incident and Personal Data Breach
Flixil maintains technical and organisational measures designed to protect personal data processed on behalf of customers. However, no information system or transmission over the Internet can be guaranteed to be completely secure.
If Flixil becomes aware of a confirmed personal data breach affecting personal data processed on behalf of a customer, Flixil will notify the affected customer without undue delay, where required by applicable law and subject to applicable confidentiality, security, and legal restrictions.
Flixil will take reasonable steps to investigate the incident, mitigate its effects, and cooperate with the customer as reasonably necessary to satisfy applicable data-protection obligations.
Nothing in this DPA excludes or limits any obligation or liability that cannot lawfully be excluded or limited under applicable data-protection law.
6. Customer Responsibilities
The customer is responsible for:
- determining the lawful basis and purposes for processing personal data;
- providing appropriate notices to data subjects;
- obtaining any required consents or authorisations;
- configuring Flixil appropriately for its intended use;
- determining what personal data is submitted to the Flixil platform;
- maintaining the security of its accounts, devices, integrations, and credentials;
- promptly revoking or rotating credentials that it believes have been compromised; and
- ensuring that its use of Flixil complies with applicable laws and regulations.
The customer must not submit personal data to Flixil where such submission would violate applicable law or the rights of a third party.
7. API Keys and Credentials
Customers are responsible for the confidentiality and appropriate use of their API keys, Flix Keys, authentication credentials, and credentials for third-party AI providers.
Where a credential is compromised through circumstances attributable to the customer, its personnel, users, devices, systems, integrations, or other third parties under its control, the customer is responsible for promptly revoking and replacing the affected credential.
Flixil will apply the security measures described in this DPA to credentials under its control. To the maximum extent permitted by applicable law, Flixil will not be responsible for losses resulting from a customer's failure to secure, revoke, or rotate compromised credentials, or from circumstances outside Flixil's reasonable control.
Nothing in this section excludes or limits liability that cannot lawfully be excluded or limited.
8. Subprocessors
Flixil may engage subprocessors to provide hosting, database, authentication, storage, infrastructure, monitoring, security, and other services necessary to operate the Flixil platform.
Flixil will require subprocessors that process customer personal data to undertake data-protection and confidentiality obligations appropriate to the services they provide.
Flixil will maintain an up-to-date list of authorized subprocessors and, where required by applicable law or the applicable customer agreement, provide notice of material changes to subprocessors.