Penzago Data Processing Addendum

Version 1.1 — Effective August 9, 2026

This Data Processing Addendum (this "DPA") is incorporated into the Master Subscription Agreement (the "MSA") between GETREFLOW LLC ("Penzago") and the customer identified on the applicable Order Form ("Customer") and applies whenever Penzago processes Personal Information on Customer's behalf in providing the Service. This DPA is accepted by Customer's execution of an Order Form referencing the MSA; a countersigned copy is available on request to hello@getreflow.ai. Penzago is a service of GETREFLOW LLC (d/b/a Penzago). In the event of conflict on data-protection matters, this DPA prevails over the MSA.

1. Definitions and Roles

1.1 "Personal Information," "Business," "Service Provider," "Processor," "Controller," "Sale," "Share," "Business Purpose," and "Consumer" have the meanings given in Applicable Privacy Law. "Applicable Privacy Law" means U.S. federal and state privacy laws applicable to the Personal Information processed under the Agreement, including the California Consumer Privacy Act as amended by the CPRA and its regulations ("CCPA"), and the comprehensive privacy laws of other U.S. states in effect from time to time (including the Virginia CDPA, Colorado CPA, Connecticut CTDPA, Texas TDPSA, and, when effective, other enacted state privacy laws).

1.2 Roles. For Personal Information of Consumers processed through the Service (lead records, message content, appointment details, form submissions), Customer is the Business/Controller and Penzago acts as Customer's Service Provider/Processor. For Customer's own account data (login identities, billing, configuration, usage records), Penzago is an independent Business/Controller and processes it as described in the Penzago Privacy Policy.

1.3 Processing details. The subject matter, nature, purposes, duration, data categories, and data subjects of processing are described in Exhibit A.

2. Processing Restrictions (CCPA Service-Provider Terms)

Penzago certifies that it understands and will comply with the following restrictions, which are intended to satisfy Cal. Civ. Code §1798.140(ag) and 11 CCR §7051:

  • (a) Penzago processes Personal Information only for the limited and specified Business Purposes of providing the Service described in Exhibit A, and for no other commercial purpose;
  • (b) Penzago will not sell or share Personal Information;
  • (c) Penzago will not retain, use, or disclose Personal Information outside the direct business relationship with Customer or for any purpose other than the Business Purposes, except as permitted by Applicable Privacy Law (including security, defending legal claims, and legal compliance);
  • (d) Penzago will not combine Personal Information received from Customer with Personal Information received from another business or collected from its own interactions with Consumers, except as permitted by Applicable Privacy Law for the Business Purposes (Customer acknowledges that, to honor a Consumer's deletion request, the Service's erasure machinery identifies and scrubs that Consumer's records across all businesses on the platform — a use permitted as compliance with legal obligations; messaging opt-out suppression itself is maintained per business program);
  • (e) Penzago will notify Customer promptly if it determines it can no longer meet its obligations under Applicable Privacy Law, and in that event Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Information;
  • (f) Customer may take reasonable and appropriate steps to ensure Penzago uses Personal Information consistently with Customer's obligations, including the audit rights in §9; and
  • (g) Penzago grants Customer the rights, and undertakes the duties, required of processor contracts under the other Applicable Privacy Laws, including: a duty of confidentiality on all persons processing the data (§5.4), engagement of subprocessors only under written contracts imposing equivalent obligations (§4), deletion or return of Personal Information at the end of services (§8), reasonable demonstration of compliance (§9), and reasonable cooperation with Customer's data-protection assessments.

3. Consumer Rights Assistance

3.1 Deletion. The Service provides built-in machinery for honoring Consumer deletion requests, including per-person erasure across message conversations and appointment records and an erasure fan-out that propagates deletion to Customer's connected CRM where supported. Customer is responsible for receiving and verifying Consumer requests directed to Customer; Penzago will execute verified requests Customer submits through the Service or to hello@getreflow.ai within thirty (30) days.

3.2 Access, correction, portability. Penzago will provide reasonable assistance, through the Service's export tooling and on written request, to enable Customer to respond to Consumer access, correction, and portability requests within the timelines of Applicable Privacy Law.

3.3 Opt-out records. Records of Consumer opt-outs from text messaging (suppression list entries) are retained indefinitely notwithstanding deletion requests, as processing necessary to comply with legal obligations — deleting them would cause the Consumer to be messaged again.

3.4 Requests received by Penzago. If a Consumer submits a rights request directly to Penzago identifying Customer's program, Penzago will forward it to Customer without undue delay, except that Penzago may honor opt-out and erasure requests directly through the Service's suppression and erasure machinery.

4. Subprocessors

4.1 Authorization. Customer authorizes the subprocessors listed in Exhibit C. Penzago will bind each subprocessor by written contract to data-protection obligations no less protective than this DPA, and remains responsible for their performance.

4.2 Changes. Penzago will give Customer at least thirty (30) days' notice (by email to the contact of record) before adding or replacing a subprocessor that processes Consumer Personal Information. If Customer reasonably objects on data-protection grounds and the parties cannot resolve the objection within the notice period, Customer may terminate the affected portion of the Service under MSA §7.2 without penalty.

5. Security

5.1 Penzago implements and maintains the technical and organizational measures described in Exhibit B, which the parties agree provide a level of security appropriate to the risk of the processing.

5.2 Penzago will not materially degrade the Exhibit B measures during the Term.

5.3 Access to Personal Information is limited to personnel and subprocessors who need it to provide the Service.

5.4 All persons authorized to process Personal Information are bound by written or statutory duties of confidentiality.

6. Security Incidents

6.1 Notice. Penzago will notify Customer without undue delay, and in any event within seventy-two (72) hours, after confirming a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Information processed on Customer's behalf (a "Security Incident"). Notice will describe, to the extent known: the nature and scope of the incident, the categories and approximate volume of affected records, the measures taken or planned, and a contact point.

6.2 Allocation. Customer, as the Business/Controller, is responsible for determining whether and how to notify Consumers and regulators, and Penzago will provide reasonable cooperation and information to support those determinations. Penzago will not notify Customer's Consumers directly unless required by law or agreed with Customer.

6.3 Unsuccessful attempts (blocked attacks, scans) that do not result in unauthorized access are not Security Incidents.

7. Recorded Conversations and AI Processing

7.1 Disclosed processing. The Service stores SMS/RCS conversation content (application-encrypted at rest) and processes conversation content through third-party AI providers under commercial terms that prohibit training on the data, in order to generate responses on Customer's behalf. The Service's AI responder identifies itself as automated in the conversation.

7.2 Allocation of communication-recording compliance. Penzago is responsible for the in-conversation disclosures the Service itself makes. Customer is responsible for the disclosures and consents required at its own touchpoints — its websites, forms, phone greetings, and any representation it makes to Consumers about how their communications are handled — including any notice required by applicable communication-recording and wiretap laws (such as CIPA in California and analogous two-party-consent statutes) for conversations Consumers initiate with Customer's numbers before an in-conversation disclosure can occur. Each party will maintain its respective disclosures and will promptly implement reasonable disclosure changes the other identifies as legally necessary.

7.3 Liability for claims arising from a party's failure to make the disclosures allocated to it in §7.2 falls within that party's indemnity under MSA §11 as applicable.

8. Retention, Return, and Deletion

8.1 In-service retention. Consumer conversation data handled by the Service's messaging features is retained for ninety (90) days from first contact, after which message content is automatically purged and identifiers are anonymized, as disclosed in the Penzago Privacy Policy. Web-chat conversation records follow the retention schedule disclosed in the Privacy Policy.

8.2 Return. During the Term and during the seven (7) day post-termination grace period, Customer may export its data through the Service's export tooling (delivered as time-limited secure download links) or request an export in a portable, machine-readable format.

8.3 Deletion. Following the grace period after termination, Penzago deletes Customer's stored credentials and OAuth tokens, removes Customer's workflows from the automation engine, deletes or de-identifies Consumer Personal Information processed on Customer's behalf, and cancels the billing subscription. Penzago may retain: (a) suppression/opt-out records (§3.3); (b) billing and audit records required for legal, accounting, and dispute-defense purposes; and (c) de-identified data — in each case protected under this DPA for as long as retained.

9. Audit and Demonstration of Compliance

On written request no more than once in any twelve (12) month period (and additionally following a Security Incident), Penzago will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of its security measures, its subprocessor list, and the compliance attestations of its infrastructure providers (whose data centers maintain SOC 2 compliance). Audits are records-based; on-site inspection is not included for the Service's multi-tenant infrastructure. Customer bears its own audit costs.

10. Term and Miscellaneous

This DPA is effective as long as Penzago processes Personal Information on Customer's behalf and survives termination of the MSA until all such processing ends. This DPA is governed by the governing-law and liability provisions of the MSA, provided that nothing in this DPA limits either party's liability to Consumers or regulators where such limitation is prohibited by law.

Exhibit A — Processing Details

ItemDescription
Subject matterProvision of the Penzago automation platform: lead ingestion and routing, CRM synchronization, scheduling, and outbound/inbound messaging (SMS, RCS, voice, email, web chat) on Customer's behalf
DurationThe Term of the Agreement plus the post-termination grace and deletion periods in §8
Nature and purposesHosting and storage; lead capture and enrichment; workflow execution against Connected Accounts; generation and delivery of messages, including AI-generated conversational responses; appointment booking; analytics for Customer's dashboard; usage metering; compliance processing (opt-out suppression, quiet-hours deferral, consent recordkeeping)
Data subjectsCustomer's leads, prospective customers, and customers ("Consumers"); Customer's personnel who use the Service
Categories of Personal InformationIdentifiers (name, phone number, email, address); communications content (SMS/RCS/web-chat conversation transcripts, form submissions); commercial information (inquiry details, appointment and transaction details, estimated values); Internet activity (form-submission metadata); professional information incidentally contained in communications
Sensitive Personal InformationNot intentionally collected; may be incidentally contained in message content Consumers volunteer

Exhibit B — Security Measures

The following measures are implemented in the Service as of the version date of this DPA:

  1. Encryption in transit (TLS) for all Service traffic and encryption at rest (AES-256) for stored data; consumer conversation transcripts are additionally application-level encrypted (AES-256-GCM) before storage.
  2. Tenant isolation via database row-level security policies on all tenant tables; each customer's data is inaccessible to other customers at the database layer.
  3. Credential vaulting: OAuth tokens and platform credentials are stored in an encrypted vault, never in plaintext, and are deleted on disconnection or account deletion.
  4. Least-privilege access: role-based access control; service-role-only database functions for sensitive operations; platform-admin actions are gated and audit-logged.
  5. Audit logging with privacy-preserving design (subject-erasure audit records store hashed identifiers, not raw contact data).
  6. Automated retention enforcement: scheduled purge jobs enforce the 90-day conversation retention and web-chat retention horizons.
  7. Erasure machinery: per-person, cross-tenant erasure endpoints with CRM fan-out; idempotent, transactional deletion.
  8. Error-monitoring hygiene: PII scrubbing applied to error telemetry in all runtimes; session replay masking enabled.
  9. Abuse resistance: API rate limiting; webhook signature verification (HMAC and Ed25519 as applicable); circuit breakers around external providers; fail-closed messaging suppression and quiet-hours gates.
  10. Infrastructure: hosted on cloud providers whose data centers maintain SOC 2 compliance; the workflow engine is self-hosted on a private deployment behind authentication.
  11. AI data minimization: consumer phone numbers are structurally excluded from AI prompts; AI providers are bound by commercial terms prohibiting training on submitted content.

Exhibit C — Authorized Subprocessors

SubprocessorFunctionPersonal Information involved
SupabaseDatabase hosting, authentication, encrypted credential vaultAll stored Service data
VercelApplication hostingData in transit through the application
RailwayHosting of the self-hosted workflow-automation engine (Activepieces)Lead payloads processed by workflows
StripePayment processing and subscription managementCustomer billing data
TelnyxSMS/RCS/voice deliveryConsumer phone numbers and message content
MailgunTransactional and program email deliveryRecipient email addresses and message content
AnthropicAI language model provider (conversational features)Conversation content and business context sent per response (no phone numbers; no training; no post-response retention beyond short-lived operational logs)
OpenAIAI language model provider (content-generation features)Content-generation prompts (no consumer contact data; API data retained briefly for abuse monitoring only)
UpstashRate limiting and short-lived cachingPhone numbers in short-TTL capability caches
SentryError monitoringPII-scrubbed diagnostics
Google (Places API)Address autocompleteAddresses entered during data entry