Data Processing Agreement
Last updated: 12 August 2026
This agreement covers personal data that Flotto (“we”) processes on your behalf — the people who fill in the pages you publish. It forms part of the Terms of Service and applies automatically to every customer, so there is nothing to sign or request. It is made under the Digital Personal Data Protection Act, 2023 and, where it applies, Article 28 of the UK and EU GDPR.
1. Roles
You are the controller— the “Data Fiduciary” under the DPDP Act. You decide to run a page, what it asks for, and what happens to the answers. You confirm you have a lawful basis for collecting that data and have given people whatever notice the law requires.
We are the processor. We hold and move that data on your instructions and for no purpose of our own. We do not sell it, do not market to your leads, and do not use it to train machine-learning models. Data about your own account is different — there we are the controller, and our Privacy Policy covers it.
2. How we process it
We act only on your instructions; using the Service as documented is that instruction. We will tell you if we think an instruction breaks data protection law, unless we are legally prevented from doing so. Anyone with access is bound by confidentiality obligations and gets access only where their job requires it.
3. Security
We apply appropriate technical and organisational measures, set out in Annex 2. We may update them provided protection is not reduced.
4. Sub-processors
You authorise the providers in Annex 3. Each is bound by obligations no weaker than these, and we remain responsible to you for what they do. We will give you notice before adding a new one; you may object on reasonable data protection grounds within 14 days, and if we cannot resolve it you may stop using the affected part of the Service.
5. International transfers
Data may be processed outside your country. Transfers of UK or EEA data rely on an adequacy decision or, where none applies, the Standard Contractual Clauses or the UK Addendum. Transfers out of India follow section 16 of the DPDP Act.
6. Data subject requests
The Service provides you with the means to view, export and delete this data directly. Where an individual contacts us about data you control, we do not respond substantively; we refer them to you and inform you without undue delay.
7. Breaches, audits and assistance
If there is a personal data breach affecting your data, we will tell you without undue delay and give you what we know so you can meet your own obligations. We will also help, so far as is reasonable, with impact assessments and regulator queries.
We will provide the information you need to demonstrate compliance. Audits are limited to once a year — unless a regulator requires otherwise or a breach has occurred — need 30 days’ notice, and must not unreasonably disrupt the Service.
8. Deletion
When your subscription ends we delete this data, except where law requires us to keep it. You should export it before then. Deleting a page does not delete the records captured through it; those remain available to you until you delete them.
9. Liability and precedence
The liability limits in the Terms of Service apply here too. If this agreement and the Terms conflict on the processing of this data, this agreement wins. It is governed by the laws of India.
Annex 1 — Details of processing
| Subject matter | Hosting lead-capture pages and delivering what they collect |
| Duration | While your subscription is open, or until you delete the data |
| Nature and purpose | Storage, organisation, retrieval, transmission to your email platform, deletion |
| Data subjects | People who submit a page you publish |
| Categories of data | Email address; other fields your page asks for (commonly name); their answers; the tracked link they arrived through; derived country; broad device and browser type |
| Not retained | IP addresses — used momentarily to derive country and detect bots, then discarded |
| Special category data | Not requested by the Service. Do not configure pages to collect it |
Annex 2 — Security measures
- Encryption in transit across all interfaces, including hosted pages.
- Separation of customer environments at the application and database layers.
- Encryption at rest of third-party credentials you supply; never displayed in full or included in exports.
- Production data access limited to those who need it to run the Service.
- Automated bot detection on every capture form, and content screening before publication.
- Regular backups with restoration procedures.
Annex 3 — Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare | Hosting, edge delivery, file storage, bot protection | Global |
| Neon | Database (accounts, pages, captured leads) | United States |
| Paddle | Payments — merchant of record; handles billing and tax | United Kingdom / EU |
| Resend | Transactional email (account mail and delivery email) | United States |
| OpenRouter | AI page authoring and content-safety checks. Page content only — never captured leads | United States |
| Your email platform | Whichever provider YOU connect (Kit, Mailchimp, beehiiv, MailerLite, Brevo, ActiveCampaign). Leads are sent there at your instruction | Per provider |
The email platform is selected by you. Data is sent to it on your instruction, and that provider’s terms govern it from that point. The AI provider does not receive this data: it processes the page content you author, and not the information submitted through it.