Data Processing Agreement

Last updated: 12 August 2026

This agreement covers personal data that Flotto (“we”) processes on your behalf — the people who fill in the pages you publish. It forms part of the Terms of Service and applies automatically to every customer, so there is nothing to sign or request. It is made under the Digital Personal Data Protection Act, 2023 and, where it applies, Article 28 of the UK and EU GDPR.

1. Roles

You are the controller— the “Data Fiduciary” under the DPDP Act. You decide to run a page, what it asks for, and what happens to the answers. You confirm you have a lawful basis for collecting that data and have given people whatever notice the law requires.

We are the processor. We hold and move that data on your instructions and for no purpose of our own. We do not sell it, do not market to your leads, and do not use it to train machine-learning models. Data about your own account is different — there we are the controller, and our Privacy Policy covers it.

2. How we process it

We act only on your instructions; using the Service as documented is that instruction. We will tell you if we think an instruction breaks data protection law, unless we are legally prevented from doing so. Anyone with access is bound by confidentiality obligations and gets access only where their job requires it.

3. Security

We apply appropriate technical and organisational measures, set out in Annex 2. We may update them provided protection is not reduced.

4. Sub-processors

You authorise the providers in Annex 3. Each is bound by obligations no weaker than these, and we remain responsible to you for what they do. We will give you notice before adding a new one; you may object on reasonable data protection grounds within 14 days, and if we cannot resolve it you may stop using the affected part of the Service.

5. International transfers

Data may be processed outside your country. Transfers of UK or EEA data rely on an adequacy decision or, where none applies, the Standard Contractual Clauses or the UK Addendum. Transfers out of India follow section 16 of the DPDP Act.

6. Data subject requests

The Service provides you with the means to view, export and delete this data directly. Where an individual contacts us about data you control, we do not respond substantively; we refer them to you and inform you without undue delay.

7. Breaches, audits and assistance

If there is a personal data breach affecting your data, we will tell you without undue delay and give you what we know so you can meet your own obligations. We will also help, so far as is reasonable, with impact assessments and regulator queries.

We will provide the information you need to demonstrate compliance. Audits are limited to once a year — unless a regulator requires otherwise or a breach has occurred — need 30 days’ notice, and must not unreasonably disrupt the Service.

8. Deletion

When your subscription ends we delete this data, except where law requires us to keep it. You should export it before then. Deleting a page does not delete the records captured through it; those remain available to you until you delete them.

9. Liability and precedence

The liability limits in the Terms of Service apply here too. If this agreement and the Terms conflict on the processing of this data, this agreement wins. It is governed by the laws of India.

Annex 1 — Details of processing

Subject matterHosting lead-capture pages and delivering what they collect
DurationWhile your subscription is open, or until you delete the data
Nature and purposeStorage, organisation, retrieval, transmission to your email platform, deletion
Data subjectsPeople who submit a page you publish
Categories of dataEmail address; other fields your page asks for (commonly name); their answers; the tracked link they arrived through; derived country; broad device and browser type
Not retainedIP addresses — used momentarily to derive country and detect bots, then discarded
Special category dataNot requested by the Service. Do not configure pages to collect it

Annex 2 — Security measures

Annex 3 — Sub-processors

ProviderPurposeLocation
CloudflareHosting, edge delivery, file storage, bot protectionGlobal
NeonDatabase (accounts, pages, captured leads)United States
PaddlePayments — merchant of record; handles billing and taxUnited Kingdom / EU
ResendTransactional email (account mail and delivery email)United States
OpenRouterAI page authoring and content-safety checks. Page content only — never captured leadsUnited States
Your email platformWhichever provider YOU connect (Kit, Mailchimp, beehiiv, MailerLite, Brevo, ActiveCampaign). Leads are sent there at your instructionPer provider

The email platform is selected by you. Data is sent to it on your instruction, and that provider’s terms govern it from that point. The AI provider does not receive this data: it processes the page content you author, and not the information submitted through it.