Flowmingo Logo

Legal

Data Processing Agreement

Flowmingo — operated by Princep Pte. Ltd.

1. Scope and incorporation

1.1 This Data Processing Agreement ("DPA") is incorporated into and forms part of the Flowmingo Terms of Service (the "Agreement") between Princep Pte. Ltd. ("Flowmingo", "we") and the customer accepting those Terms ("Customer", "you"). By accepting the Agreement you accept this DPA. No separate signature is required.

1.2 This DPA applies to the extent Flowmingo processes Personal Data on your behalf in connection with the Services, and where such processing is subject to the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR") or the Singapore Personal Data Protection Act 2012.

1.3 In the event of a conflict, this DPA prevails over the Agreement in respect of the processing of Personal Data. Our Privacy Policy (https://flowmingo.ai/privacy-policy) describes our processing in full and is referred to throughout.

1.4 Terms not defined here have the meaning given in the Agreement or in the GDPR. "Candidate Data" means personal data relating to candidates that you collect through your hiring projects using the Services.

2. Roles of the parties

2.1 Where Flowmingo is your processor. For Candidate Data collected through your hiring projects — including CVs, pre-screening responses, written and video or audio interview responses, AI evaluation reports generated for you, and candidate information you upload — you are the controller and Flowmingo is your processor. We process that data only on your documented instructions, as set out in section 3.

2.2 Where Flowmingo is the controller. Flowmingo acts as controller, and not as your processor, for:

  • (a) the limited copy of Candidate Data we retain for platform security, quality assurance and legal compliance;
  • (b) evaluation reports and assessments purchased directly by a candidate from Flowmingo;
  • (c) your account, billing and payment data;
  • (d) technical data such as device information, IP addresses, identifiers, cookies and diagnostic logs; and
  • (e) any other processing described as controller processing in our Privacy Policy.

2.3 Our responsibility for our own processing. Where Flowmingo acts as controller under section 2.2, Flowmingo is responsible for establishing and maintaining its own legal basis for that processing directly with the data subject — including obtaining consent where consent is the applicable basis — and for responding to data subject requests concerning that processing. You are not required to provide, and we do not rely on, your legal basis for it. The legal bases we rely on are set out in our Privacy Policy.

2.4 Your responsibility. You are responsible for the lawfulness of the Candidate Data you collect through the Services, for providing any notice and obtaining any consent required from candidates for your own processing, and for issuing lawful instructions to us.

2.5 AI and model training. Flowmingo does not use Candidate Data processed on your behalf to train, fine-tune or develop artificial intelligence or machine learning models. The only licence Flowmingo takes for AI development purposes is over de-identified question templates, as set out in section 2 of the Agreement, which contain no Personal Data. Flowmingo's processing of the limited copy it holds as controller under section 2.2(a) is governed by section 2.3 and our Privacy Policy, and candidates may opt out of AI model improvement uses.

3. Processor obligations

Where Flowmingo acts as your processor, we will:

  • (a) process only on your instructions. We process Candidate Data only on your documented instructions, including as to international transfers, unless required otherwise by law — in which case we will inform you before processing, unless the law prohibits it. Your use of the Services, and the Agreement, constitute your initial documented instructions;
  • (b) ensure confidentiality. We limit access to personnel who need it to deliver the Services, and those personnel are bound by confidentiality obligations and receive data protection training;
  • (c) apply security measures in accordance with Article 32 GDPR, as described in Annex 3;
  • (d) engage sub-processors only in accordance with section 4;
  • (e) assist you with data subject rights, as described in section 6;
  • (f) assist you with security, breach notification and impact assessments under Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to us;
  • (g) delete or return Candidate Data in accordance with section 7; and
  • (h) make available information necessary to demonstrate compliance with this section, and allow for and contribute to audits, in accordance with section 8.

4. Sub-processors

4.1 You give general authorisation for Flowmingo to engage sub-processors. Our current sub-processors are listed in Annex 2.

4.2 We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible to you for their performance.

4.3 We will update Annex 2 whenever a sub-processor is added or replaced, and the current list is always available in the published version of this DPA. Such changes do not require your prior consent. You may object on reasonable data protection grounds, and we will work with you in good faith to address any objection.

5. International transfers

5.1 Candidate Data may be processed outside the European Economic Area, including by the sub-processors listed in Annex 2 and by Flowmingo group personnel in Singapore and Vietnam.

5.2 Where such a transfer is subject to GDPR Chapter V, it is made under an appropriate safeguard recognised by Article 46 — the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) — supported by a transfer impact assessment, together with the supplementary safeguards described in Annex 3.

6. Data subject requests

6.1 Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise data subject rights.

6.2 If we receive a request directly from a candidate that relates to data we process on your behalf, we will promptly forward it to you and will not respond to it ourselves except on your instruction or as required by law.

7. Deletion and return

7.1 You may delete Candidate Data, or instruct us to delete it, at any time through the Services or by written request.

7.2 On expiry or termination of the Agreement we will delete Candidate Data in accordance with the retention periods set out in our Privacy Policy, or return it to you if you so request before deletion, except where we are required by law to retain it or where we retain a limited copy as controller under section 2.2(a).

7.3 Any copies held in routine backups are deleted in the ordinary course of backup expiry and remain subject to this DPA until deleted.

8. Audit

8.1 On reasonable written request, and not more than once in any twelve-month period unless required by a supervisory authority, we will make available the information reasonably necessary to demonstrate our compliance with this DPA. We may satisfy this by providing documentation, policy summaries or responses to a security questionnaire.

8.2 Where that information is not sufficient, you may conduct or mandate an audit, on at least thirty days' written notice, during business hours, subject to confidentiality obligations and in a manner that does not unreasonably disrupt our operations or compromise the confidentiality of other customers' data.

9. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting Candidate Data processed on your behalf, and will provide the information reasonably available to us to assist you in meeting your own notification obligations. Where Flowmingo acts as controller, we notify the competent supervisory authority within 72 hours where notification is required under Article 33 GDPR.

10. General

10.1 Changes. We may update this DPA where required by law or to reflect changes to the Services. We will give reasonable prior notice of any material change through the Services or by email. If a material change adversely affects you and we cannot agree an alternative, you may terminate the affected Services.

10.2 Term. This DPA takes effect when you accept the Agreement and continues for as long as we process Candidate Data on your behalf.

10.3 Governing law. This DPA is governed by the laws of Singapore and subject to the jurisdiction provisions of the Agreement.

10.4 Contact. Data protection enquiries: compliance@flowmingo.ai

ANNEX 1 — Details of processing

Subject matter

Provision of the Flowmingo hiring and AI interview services

Duration

The term of the Agreement, plus the retention periods in our Privacy Policy

Nature and purpose

Hosting, storage, processing and analysis of candidate applications and interviews to deliver recruitment services to the Customer

Types of personal data

CV details (name, email, work and education history, contact details); pre-screening responses; written and video or audio interview responses; AI evaluation reports generated for the Customer; other information provided by candidates

Categories of data subjects

Job candidates applying to the Customer; the Customer's users

Retention

Candidate Data in your hiring projects: retained as long as you require, deleted on your instruction or two years after the account is closed and inactive. Reports or assessments purchased directly by a candidate: two years. Customer accounts: two years after closure. Billing records: up to seven years (legal obligation). Flowmingo's controller copy: deleted in accordance with statutory obligations or on a validated data subject request.

ANNEX 2 — Sub-processors

Sub-processor

Purpose

Google Cloud

Hosting and infrastructure

Cloudflare

Network, delivery and security

Stripe

Payment processing

HitPay

Payment processing

Google Analytics

Product analytics

Princep Vietnam JSC

Development, quality assurance and operational support

ANNEX 3 — Technical and organisational measures

Technical measures

  • Encryption of data in transit and at rest, and pseudonymisation of sensitive data
  • Role-based access limited to the minimum necessary, restricted to designated personnel
  • Access logging, with access reviews conducted quarterly
  • Regular penetration testing and security monitoring
  • Access minimisation and regional split-processing
  • Personnel bound by written confidentiality obligations

Organisational measures

Flowmingo maintains a documented data protection programme comprising:

  • A formally appointed data protection officer
  • A formally adopted Data Protection Policy
  • A Record of Processing Activities maintained under Article 30 GDPR
  • A documented data retention schedule
  • A documented breach response procedure, including notification to supervisory authorities within 72 hours where required under Article 33 GDPR
  • A documented data subject rights handling procedure and request register
  • Documented legitimate interest assessments for processing carried out on that basis
  • Data protection training for personnel, with completion records maintained
  • Sub-processor data protection terms managed in accordance with section 4

Summaries of these documents can be made available in accordance with section 8.