Legal

Data Processing Agreement

AgentFlow Enterprise can provide a DPA template for B2B customers. The template supports controller-processor review, and the final agreement should be reviewed and signed by both parties.

Template - legal review required

DPA template for business review.

The DPA is intended to support controller-processor review for business customers evaluating AgentFlow Enterprise.

This template is provided for business review and should be reviewed by legal counsel before signature.

This page describes implementation and vendor readiness. It is not a SOC 2, ISO 27001, penetration test, or legal compliance certification.

Public business identity

Vendor details used in the template.

Founder / operator
Ciprian Stefan Plesca
Business name
Xolo Go OÜ - Ciprian-Stefan Plesca
Registry code
14717109
VAT number
EE102156920
Address
Paju tn 1a, 50603 Tartu, Tartu Maakond, Estonia
Contact email
[email protected]

Business review

Parties

The DPA template identifies the customer legal entity and AgentFlow Enterprise, operated through Xolo Go OÜ - Ciprian-Stefan Plesca, using the public business identity shown on this page.

Controller / processor

Roles

The customer generally acts as controller for its lead, contact, and customer data. AgentFlow Enterprise / Xolo Go OÜ acts as processor where it processes personal data on the customer's behalf, subject to final legal review.

Lead operations

Subject matter of processing

Processing may support B2B lead capture, AI-assisted lead qualification, scoring, workflow routing, dashboard review, billing support, notifications, and configured integration handoffs.

Service term

Duration of processing

Processing should continue for the term of the customer relationship or the period defined in the signed agreement, including any reasonable transition, deletion, or return period.

Configured use

Nature and purpose of processing

The service processes data to operate the SaaS platform, authenticate users, maintain tenant records, qualify and route leads, support billing, and provide customer-requested integrations where configured.

B2B data

Categories of personal data

Typical categories include names, work email addresses, phone numbers, company details, lead message content, source attribution, qualification notes, AI scoring output, account identifiers, billing references, and support context.

Customer-defined

Categories of data subjects

Data subjects may include customer users, customer prospects, business contacts, leads, representatives, administrators, and support contacts submitted to or generated through the platform.

Implementation controls

Security measures

Security measures may include encrypted transport, server-side secrets, protected dashboard access, tenant-aware data handling, payment provider delegation, logging controls, environment separation, backup review, and operational monitoring where configured.

Vendor readiness

Subprocessors

The active subprocessor list depends on the customer's configuration and enabled features. Customers should review the public subprocessor page and any contract-specific vendor list before signature.

Customer review

International transfers / vendor terms

Transfers and processing locations depend on infrastructure regions, vendor terms, and account settings. Customers should review each vendor's data processing terms and selected regions before onboarding.

Assistance

Data subject requests

AgentFlow Enterprise can support reasonable controller requests to locate, export, correct, restrict, or delete relevant customer data according to the signed agreement and applicable configuration.

Access handling

Confidentiality

Personnel and service providers with access to customer data should be bound by confidentiality obligations or equivalent professional duties appropriate to the service.

Incident support

Breach assistance

The final DPA should define breach assessment, evidence capture, processor-to-controller communication, remediation support, and cooperation responsibilities without presenting this page as a contractual SLA.

End of service

Deletion or return of data

At termination or upon verified request, customer data should be returned, exported, or deleted according to the signed agreement, legal obligations, and configured retention schedules.

Reasonable review

Audit and cooperation

The template provides a cooperation path for reasonable security and processing review. Any audit scope, timing, confidentiality, and cost terms should be agreed in the final signed DPA.

Signed DPA

Contact and signature process

Business customers can request a signed DPA through the contact flow. The final agreement should be reviewed and signed by both parties before it is relied on.

Template status

Legal review disclaimer

This template is provided for business review and should be reviewed by legal counsel before signature. This is not legal advice.

Signature process

Contact AgentFlow Enterprise for a signed DPA.

Use the template for business review, then contact the team to confirm customer details, active subprocessors, any customer instructions, and signature requirements.