Warden

Legal · DPA

Data Processing Agreement

Last updated · 14 June 2026

This Data Processing Agreement is part of the Warden terms of service. It applies whenever FlowVolt processes personal data on your behalf to deliver the Service. You are the controller. We are the processor. The rules below set out what each side does.

Controller

You (the Customer)

Processor

FlowVolt B.V.

Governing law

GDPR + Dutch law

Effective

From signup

Status: draft pending review by a Dutch IT/privacy lawyer. The DPA in this form is auto-accepted on signup; replace with the lawyer-reviewed version by 2026-08-02.

1. Scope and definitions

This DPA applies to all personal data we (the “Processor”) process on behalf of you (the “Controller”) in connection with Warden. Defined terms used here have the meaning given in the GDPR (Regulation (EU) 2016/679) unless explicitly redefined.

2. Subject matter and duration

Subject matter. Storage, indexing, retrieval, signing, and presentation of your AI agent register, audit log entries, intake answers, and EU AI Act dossier exports.

Duration. For as long as your Warden account is active, plus the deletion windows defined in section 9 below.

Nature and purpose. To deliver the Warden Service as described in the Terms of Service and to enable your compliance with the EU AI Act.

3. Categories of data and data subjects

The personal data processed under this DPA consists of:

Data subjects are typically your employees, your service providers’ employees, or the natural persons your AI agents interact with.

4. Our obligations as processor

4.1 Instructions

We process personal data only on your documented instructions, including with regard to transfers, unless required by EU or Dutch law. If we are required to act outside your instructions by law, we inform you before processing, unless that law prohibits us.

4.2 Confidentiality

We ensure that everyone authorised to process personal data has committed to confidentiality or is under a statutory obligation of confidentiality.

4.3 Security

We implement appropriate technical and organisational measures:

4.4 Sub-processors

You authorise the sub-processors listed in section 8 below. We give you at least thirty days’ notice before adding or replacing a sub-processor, by updating this page and emailing the notice to your billing email. You may object on reasonable grounds, in which case we work with you to find an alternative or you may terminate without penalty for the remaining prepaid period.

4.5 Data subject rights

We help you respond to data subject requests (access, rectification, erasure, portability, objection, restriction) by providing the technical means via the API and dashboard. We forward any request we receive directly from a data subject about your data to you within five business days.

4.6 Breach notification

If we become aware of a personal data breach affecting your data, we notify you without undue delay and in any event within forty-eight hours of becoming aware. The notification includes the nature of the breach, approximate categories and numbers of data subjects and records, the likely consequences, and the measures taken or proposed.

4.7 Audit

Once per twelve-month period, on at least thirty days’ notice and at your cost, you may commission an independent third-party audit to verify our compliance with this DPA. We cooperate in good faith and provide reasonable access. The auditor signs an NDA before any access is granted.

5. International transfers

Personal data is processed inside the European Union, primarily in Frankfurt, Germany. Where a sub-processor (Stripe; AI vendors via the integrations feature) transfers data outside the EU, the transfer is governed by Standard Contractual Clauses (Commission Decision 2021/914) and supplementary measures as required by the EDPB.

6. Your obligations as controller

7. Liability and indemnity

Each party’s liability under this DPA is governed by the Terms of Service, including the liability cap set out there. Nothing in this DPA limits liability for breach of GDPR for which the law does not allow limitation.

8. Sub-processors

The following sub-processors are authorised as of the last-updated date:

Each sub-processor is bound by a written contract containing data protection obligations no less protective than this DPA.

9. Deletion and return of data

On termination of your Warden account, we delete your personal data within thirty days, except for data we are required to retain by law (notably AI Act Article 26 audit logs, with a six-month minimum). On written request before deletion, we provide you a full export of your agent register, audit log, intake records, and dossier exports in machine-readable form.

10. Effective date and changes

This DPA takes effect on the day you sign up to Warden. Material changes are announced at least thirty days in advance by email to your billing email. The current version is always available at warden.flowvolt.io/dpa.

11. Contact

For DPA-related questions: privacy@flowvolt.nl.