Design Buddy
Data processing terms
Binding processor terms for business customers whose workspace content contains personal data.
Effective August 3, 2026 · version 2026-08-03
01Parties and effect
These data processing terms (“DPA”) form part of the terms of servicebetween the customer (“Customer”) and Workflow Corporation, an Iowa corporation(“Processor”) whenever Processor processes personal data in Customer Content on Customer’s behalf. No separate signature is required.
Customer is the controller or a processor authorized by the controller. If Customer is a processor, these terms also apply between Customer and Processor as required for subprocessing, and Customer confirms that its instructions are authorized by the controller.
02Processing details
- Subject and purpose: providing, securing, maintaining, and supporting Design Buddy under Customer’s account.
- Duration: the term of Customer’s use plus the period required to return, delete, back up, or lawfully retain data.
- Nature: collecting, recording, organizing, storing, retrieving, rendering, transmitting, sharing at Customer’s direction, exporting, backing up, deleting, and troubleshooting.
- Data subjects: Customer personnel, workspace invitees and members, contacts represented in Customer Content, public-link recipients, and other people whose data Customer submits.
- Personal data: identifiers and contact details; account, membership, and support data; design text and metadata; images, fonts, signatures, comments, prompts, provider output, uploads, and technical usage data.
- Sensitive data: not intentionally required. Customer must not submit regulated or sensitive data unless its use is lawful and the service and contract are appropriate for it.
03Documented instructions
Processor will process personal data only on Customer’s documented instructions, including these terms, Customer’s use and configuration of the service, support requests, and any signed order. Processor may process data where required by law and will inform Customer before doing so unless prohibited.
Processor will promptly tell Customer if an instruction appears to violate applicable data-protection law. Processor is not required to follow an instruction that would violate law or the rights of another person.
04Confidentiality and personnel
Processor ensures that personnel authorized to process personal data are bound by confidentiality obligations and receive access only as needed for their responsibilities. Access is removed when no longer required.
05Security measures
- Encryption in transit and provider-managed encryption at rest.
- Strong password hashing, signed session tokens, and role-based workspace access.
- Tenant-scoped storage paths and authorization checks on workspace and upload operations.
- Cryptographically random public share links that can be revoked; a link grants access only to the design it names.
- Secrets managed outside source code, restricted production identities, security headers, request validation, dependency review, and operational logging.
- Backups and export mechanisms, change review, tests, and procedures for investigating and responding to incidents.
06Subprocessors
Customer authorizes Processor to use subprocessors needed to operate the service. Subprocessors are bound by data-protection duties no less protective than the relevant duties in this DPA. Processor remains responsible for their performance to the extent required by law.
- Google Cloud: application hosting, Cloud SQL for account and tenancy records, object storage, networking, and operational logs in the United States.
- Resend, when configured: transactional account and invitation email.
- OpenAI or Anthropic, when configured and invoked: text assistance.
- OpenAI, Replicate, or Stability AI, when configured and invoked: image generation or supported image editing.
Processor will give notice of a new subprocessor through the service or the account email before the new provider begins materially different processing. Customer may object on reasonable data-protection grounds within 15 days. The parties will work in good faith on an alternative; if none is reasonably available, Customer may stop the affected feature or terminate the service.
07Assistance and data-subject requests
Taking into account the nature of processing, Processor will provide reasonable assistance with data-subject requests, security obligations, breach notifications, impact assessments, and regulator consultations. If a data subject contacts Processor about Customer-controlled data, Processor will direct the request to Customer unless legally required to respond.
Customer is responsible for responding to requests and for using available account, export, correction, revocation, and deletion functions. Additional assistance outside normal support may be charged at agreed reasonable rates.
08Personal data incidents
Processor will notify Customer without undue delay after confirming a breach of security that causes accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer personal data.
Notice will include the known nature and scope, likely consequences, measures taken or proposed, and a contact for follow-up. Information may be supplied in phases. Notice is not an admission of fault, and Customer is responsible for notices to individuals and authorities unless law assigns that duty to Processor.
09Return and deletion
During the term, Customer may export workspace content using the service’s backup and export functions. On verified written request following termination, Processor will delete Customer personal data from active systems unless law requires retention. Copies in protected backups are isolated from ordinary use and deleted through the normal backup lifecycle. Processor may retain records necessary to establish compliance, prevent fraud, or resolve disputes, subject to continuing protection.
10International transfers
Processing is principally in the United States. Where Customer personal data subject to the EEA GDPR is transferred to a country without an adequacy decision, the parties incorporate the European Commission’s 2021 Standard Contractual Clauses, Module Two (controller to processor) or Module Three (processor to processor), as applicable. The optional docking clause applies; Clause 17 selects Irish law and Clause 18 selects the courts of Ireland.
For UK restricted transfers, the UK International Data Transfer Addendum is incorporated with the information in this DPA completing its tables. For Swiss transfers, references to the GDPR are read to include the Swiss Federal Act on Data Protection and Switzerland is the competent jurisdiction where required.
11Information and audits
Processor will provide information reasonably necessary to demonstrate compliance. No more than once each year, unless a confirmed incident or regulator requires otherwise, Customer may request a remote audit on reasonable notice. An on-site audit is available only where remote materials are insufficient and must avoid unreasonable disruption, exposure of other customers’ data, and security risks.
Customer bears its audit costs and Processor may charge reasonable costs for unusually burdensome assistance. Auditors must be independent, qualified, and bound by confidentiality.
12Liability, priority, and contact
The liability limits in the terms apply to this DPA to the maximum extent permitted by law. If this DPA conflicts with the terms on processing personal data, this DPA controls; the applicable Standard Contractual Clauses control over both where they say they do.
Privacy and DPA requests may be sent to support@workflowcorp.com.
Workflow Corporation, an Iowa corporation
210 Emerson Pl, Suite 300, Davenport, IA 52801, United States
support@workflowcorp.com · +1 (563) 275-6409