This Data Processing Agreement ("DPA") forms part of the agreement between Daring Flow ("Processor") and the customer entity identified in the associated account ("Controller"), and supplements the Terms of Service and Privacy Policy for the Ogadu service.
This DPA applies where the Controller uses Ogadu to process personal data of individuals (such as the Controller's own customers, employees, students, or other data subjects) and where such processing is subject to the EU General Data Protection Regulation (GDPR), UK GDPR, or other applicable data protection legislation that requires a data processing agreement.
This DPA is intended for business customers who require a formal data processing agreement for GDPR or UK GDPR compliance purposes.
To request a signed copy of this DPA, contact us at contact@ogadu.com.
In this DPA:
3.1 The parties acknowledge that in relation to the processing of personal data of the Controller's end users and third parties within the Service:
3.2 In relation to Daring Flow's own users' account data and billing data (collected by Daring Flow for its own operational purposes), Daring Flow acts as a data controller in its own right, as described in the Privacy Policy.
3.3 This DPA applies to Personal Data that the Controller uploads, inputs, or generates within the Ogadu Service in connection with the Controller's own business operations.
The Controller represents and warrants that:
Daring Flow agrees to:
6.1 Personal Data processed under this DPA is stored primarily in the EU (AWS Frankfurt region).
6.2 Where Personal Data is transferred outside the EU/EEA (for example, through globally distributed infrastructure of AWS or Stripe), such transfers are subject to appropriate safeguards including Standard Contractual Clauses (SCCs) and applicable transfer mechanisms maintained by those providers.
6.3 To the extent that Daring Flow transfers Personal Data from the EU/EEA to Australia, such transfer is subject to the EU Standard Contractual Clauses, which are hereby incorporated by reference into this DPA. The parties agree to execute any required SCC documentation upon request.
Primary data location: AWS eu-central-1 (Frankfurt, Germany). We configure our infrastructure to use EU-based resources wherever possible.
The Controller grants general authorisation to Daring Flow to engage the following sub-processors:
| Sub-processor | Purpose | Data Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, hosting, and AI model inference via Amazon Bedrock | Primarily EU (Frankfurt) |
| Stripe, Inc. | Payment processing | United States |
8.1 Upon request and within 30 days, Daring Flow will provide reasonable assistance to help the Controller respond to Data Subject requests, including:
8.2 The Controller acknowledges that many Data Subject rights (access, deletion, export) can be exercised directly by the user or by the Controller using the Service's built-in administrative features.
Daring Flow implements and maintains the following technical and organisational security measures:
| Category | Measure |
|---|---|
| Encryption in transit | TLS encryption for all data transmissions |
| Encryption at rest | Encryption applied to stored data |
| Access control | Role-based access controls (Admin, Editor, Reader) |
| Network security | Application infrastructure runs within a private network |
| AI data protection | Amazon Bedrock does not store or log prompts and does not use customer data for model training |
| Personnel access | Access to production systems restricted to authorised personnel only |
| Incident response | Breach notification procedures as described in Section 5.6 |
10.1 This DPA is effective from the date the Controller first uses the Service and continues until the earlier of:
10.2 Upon termination, Daring Flow will delete Personal Data in accordance with Section 5.8, subject to any legal retention obligations.
This DPA is governed by the laws of New South Wales, Australia, unless mandatory provisions of EU or UK data protection law require otherwise. The parties submit to the jurisdiction of the courts of New South Wales.
In the event of conflict between this DPA and the Terms of Service or Privacy Policy, this DPA shall prevail in respect of the processing of Personal Data subject to GDPR or UK GDPR.
For all DPA-related enquiries, to request a signed copy, or to exercise rights under this DPA:
DPA enquiries, signed copy requests, and data protection matters
contact@ogadu.com