Data Processing Agreement (DPA)

This Data Processing Agreement (“Agreement”) forms part of the Terms of Service between Flat-Plan.com (“Processor”, “we”, “us”) and the customer using the Flat-Plan service (“Controller”, “Customer”).

This Agreement governs the processing of personal data in connection with the use of the Flat-Plan service.

1. Roles of the Parties

For the purposes of applicable data protection laws, including the General Data Protection Regulation (GDPR):

  • The Customer acts as the Data Controller.
  • Flat-Plan.com acts as the Data Processor.

The Customer determines the purposes and means of the processing of personal data, and Flat-Plan.com processes personal data solely on behalf of the Customer.

2. Subject Matter and Duration of Processing

Flat-Plan.com provides an online subscription-based software service which allows users to upload and store images, text, and other content.

Personal data will be processed for the duration of the Customer’s use of the Service and will be deleted or anonymized upon account termination, unless legal obligations require otherwise.

3. Nature and Purpose of Processing

Flat-Plan.com processes personal data only for the purpose of:

  • providing the Flat-Plan software service
  • maintaining and operating the platform
  • authenticating users
  • providing customer support
  • ensuring system security and preventing abuse

Flat-Plan.com does not use customer data for advertising or commercial resale.

4. Categories of Personal Data

Depending on how the Service is used, the following categories of data may be processed:

  • name
  • email address
  • account information
  • uploaded images
  • uploaded text content
  • technical log data

Flat-Plan.com does not intentionally collect sensitive personal data.

5. Categories of Data Subjects

Data subjects may include:

  • registered users of the Flat-Plan service
  • individuals whose information is uploaded by the Customer

6. Security Measures

Flat-Plan.com implements appropriate technical and organizational measures to protect personal data, including:

  • encrypted HTTPS connections
  • restricted server access
  • authentication and account security controls
  • regular system maintenance and monitoring

7. Subprocessors

Flat-Plan.com may use trusted third-party service providers to operate the platform.

Current subprocessors may include:

  • payment processing providers
  • hosting or infrastructure providers

These subprocessors process data only as necessary to provide the service and are required to maintain appropriate data protection safeguards.

Payment transactions are handled by:
FastSpring (authorized reseller and payment processor).

Flat-Plan.com does not store credit card information.

8. Confidentiality

Flat-Plan.com ensures that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

9. Assistance to the Controller

Flat-Plan.com will provide reasonable assistance to the Customer in fulfilling data protection obligations, including:

  • responding to data subject requests
  • maintaining security of processing
  • reporting data breaches where applicable

10. Data Deletion

Upon termination of the Customer’s account, personal data stored within the service will be deleted within a reasonable time period, unless retention is required by law.

Customers may also delete their data by removing it from their account within the service.

11. Changes

Flat-Plan.com may update this Data Processing Agreement from time to time. Continued use of the Service constitutes acceptance of the updated Agreement.

12. Contact

If you have any questions regarding this Agreement or data processing practices, please contact here.