Legal
Data Processing Agreement
Last updated: August 28, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Foreflag Intelligence ("Processor") and a customer ("Controller") for the Foreflag platform, where Foreflag processes personal data on the customer's behalf. A signed version is available on request.
1. Scope and roles
This DPA applies to the processing of personal data by Foreflag on behalf of the customer in the course of providing the Foreflag platform. The customer is the controller of the personal data; Foreflag acts as processor, except for the limited account and billing data for which Foreflag acts as an independent controller under its Privacy Policy.
2. Subject matter, duration, and purpose
- Subject matter. Processing of data the customer connects to or uploads into the Foreflag platform, including portfolio, monitoring, and related business data that may contain personal data.
- Duration. For the term of the customer agreement, plus any deletion period described below.
- Nature and purpose. Hosting, storage, analysis, and generation of monitoring outputs and alerts, solely to provide the contracted services.
- Categories of data subjects. Individuals whose personal data appears in the customer's connected data sources, such as portfolio company executives, contacts, or deal counterparties.
- Types of personal data. Names, professional contact details, roles, and business information contained in the customer's data. The customer instructs us not to process special categories of personal data.
3. Processor obligations
Foreflag will:
- Process personal data only on the customer's documented instructions, including this DPA and the customer's configuration of the platform, unless required by law.
- Ensure that persons authorized to process personal data are bound by confidentiality obligations.
- Implement and maintain appropriate technical and organizational security measures as described in this DPA.
- Assist the customer, where reasonably possible, in responding to data subject requests and in meeting its obligations regarding security, breach notification, and impact assessments.
- Notify the customer without undue delay after becoming aware of a personal data breach affecting the customer's data.
- At the customer's choice, delete or return personal data at the end of the engagement, unless retention is required by law.
4. Security measures
Foreflag maintains technical and organizational measures appropriate to the nature of the data, including:
- Encryption of data in transit using industry-standard transport security.
- Access controls limiting data access to authorized personnel on a need-to-know basis.
- Logical separation of customer data within the platform.
- Monitoring and logging of system access.
- Vendor due diligence for infrastructure and service providers.
We may update these measures over time, provided the overall level of protection is not materially reduced.
5. Sub-processors
The customer authorizes Foreflag to engage sub-processors to support the services, such as cloud hosting, database, and email delivery providers, under written contracts imposing data protection obligations no less protective than this DPA. A current list of material sub-processors is available on request at raphael@getforeflag.com. We will give advance notice of new sub-processors, and the customer may object on reasonable data protection grounds; the parties will then work in good faith toward a resolution.
6. International transfers
Where personal data is transferred outside the EEA, the UK, or Switzerland, Foreflag will ensure an appropriate transfer mechanism is in place, such as an adequacy decision or standard contractual clauses.
7. Audits
Upon reasonable prior written notice, and no more than once per year unless required by a supervisory authority or following a breach, the customer may audit Foreflag's compliance with this DPA through questionnaires and documentation. On-site audits, where justified, will be conducted in a manner that minimizes disruption and protects other customers' data.
8. Liability and term
Each party's liability under this DPA is subject to the limitations set out in the customer agreement. This DPA remains in effect for the term of the customer agreement and terminates when Foreflag ceases to process personal data on the customer's behalf.
9. Contact and execution
To request a countersigned copy of this DPA or the current sub-processor list, contact raphael@getforeflag.com.
