1. Scope and Applicability
This Data Processing Addendum ("DPA") supplements the Terms of Service between you ("Data Controller") and SegFlow AI LLC, a Texas limited liability company ("Data Processor"), and governs the processing of personal data in connection with the Service. This DPA applies when you provide personal data to us for processing through the SegFlow AI platform. This DPA is governed by the laws of the State of Texas, consistent with the governing-law provision of the Terms of Service.
You are the controller (and, under the CCPA, the business) for the property and client information you submit; we are the processor (and service provider) acting on your instructions.
2. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person that you provide through the Service.
"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
"Sub-processor" means any third party engaged by us to process Personal Data on your behalf.
3. Processing Purpose and Instructions
We will process Personal Data solely for the purpose of providing the Service as described in the Terms of Service. We will process Personal Data only in accordance with your documented instructions, unless required by applicable law to do otherwise.
How processing happens. Producing a study is automated: an intake pass, an author pass and an auditor pass, run by software. No employee of SegFlow AI LLC reviews a study before it is delivered to you. Beyond that automated processing, our staff access Personal Data only for support, security, billing, or at your request, and that access is logged.
4. Confidentiality
We ensure that everyone we authorize to process Personal Data is bound by written confidentiality obligations and has received confidentiality training. We will not disclose Personal Data to third parties except as necessary to provide the Service or as required by law.
5. Security Measures
We implement and maintain appropriate technical and organizational measures to protect Personal Data, including:
- TLS 1.2 or better for data in transit, and AES-256 encryption at rest as provided by our hosting and storage providers. SegFlow AI LLC does not add application-level encryption beyond these platform defaults.
- Role-based access controls with least-privilege principles
- Logging of administrative access to customer data
- Incident detection and response procedures
- Security training for everyone with access to production systems
- Data centers operated by providers that maintain SOC 2 Type II reports, available from those providers on request
6. Sub-processors
We engage the following categories of sub-processor to deliver the Service. Each is bound by a data processing agreement and processes data only as directed by SegFlow AI LLC.
| Category | Purpose | Location |
|---|---|---|
| Large language model provider | Intake, author and auditor passes that produce a study | United States |
| Cloud application hosting and CDN | Serving the web application | United States |
| Managed database | Study records, ledger data and review notes | United States |
| Background worker hosting | Running queued studies | United States |
| File storage | Uploaded files and delivered reports | United States |
| Payment processor | Card payments and receipts | United States |
| Transactional email provider | Receipts and study notifications | United States |
The current named list is available on request at admin@segflowai.com. We will notify customers of any new sub-processor at least 30 days before it begins processing Personal Data, by posting an update to this page and emailing the contact address on your account.
7. Data Subject Rights
We will assist you in responding to data subject requests to access, correct, delete, or port Personal Data, to the extent technically feasible and as required by applicable data protection law.
8. Data Breach Notification
In the event of a Personal Data breach, we will notify you without undue delay (and in any event within 72 hours of becoming aware of the breach) and provide sufficient detail for you to meet your own notification obligations under applicable law.
9. Data Transfers
Personal Data is processed in the United States. If Personal Data is transferred outside of your jurisdiction, we will ensure that appropriate safeguards are in place, such as Standard Contractual Clauses or other legally recognized transfer mechanisms.
10. Audit Rights
You may audit our compliance with this DPA, subject to reasonable notice and during normal business hours. We will provide reasonable cooperation and access to relevant information. Audits shall not unreasonably interfere with our operations.
11. Return and Deletion of Data
Upon termination of the Service, we will, at your election, return or delete all Personal Data within 90 days, except where retention is required by applicable law. We will certify deletion upon request.
Independently of termination, uploaded files and the copies derived from them are deleted 12 months after upload, without a reminder. The deliverables can be downloaded by you at any time before they are deleted.
12. Duration
This DPA remains in effect for the duration of our processing of Personal Data under the Terms of Service and will automatically terminate when we cease all processing of Personal Data on your behalf.
13. Contact
For DPA-related inquiries, contact us at admin@segflowai.com.