NexlyFlow
  • Data
  • How it works
  • Contact
  • Compliance
  • FAQ
  • Pricing
Log in Get Started Free
  • Data
  • How it works
  • Contact
  • Compliance
  • FAQ
  • Pricing
Log in Get Started Free
NexlyFlowNexlyFlow
DataHow it worksComplianceFAQPricingHelpContact
Log inStart Free Trial
NexlyFlow

Data Processing Agreement

Our standard DPA for enterprise customers - download, sign, and return.

Privacy PolicyTerms of ServiceRefund PolicyData DeletionSecurityDPAContactHelp Center

Template · version 1.0 · 10 September 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between NexlyFlow Pte. Ltd. (UEN 202632611H) (“NexlyFlow”, the “Processor”) and the customer identified in the signature block (“Customer”, the “Controller”) for the use of the NexlyFlow platform (the “Service”).

1. Scope and roles

Customer is the controller of the personal data it uploads to or generates in the Service (contact names, business email addresses, phone numbers, message content and related metadata, “Customer Data”). NexlyFlow processes Customer Data only as a processor, on Customer’s documented instructions, which are: to provide, secure and support the Service as described in the documentation and this DPA.

2. Processing details

  • Subject matter: B2B outreach, conversation handling and contact management.
  • Duration: the term of the subscription plus the deletion grace period.
  • Nature and purpose: storing contacts, sending and receiving emails and WhatsApp messages on Customer’s behalf, drafting text with AI at Customer’s request, reporting.
  • Data subjects: Customer’s prospects, customers, and Customer’s own staff using the Service.
  • Categories: business contact details, company details, communication content and history, engagement events (opens, replies), consent and opt-out records.

3. NexlyFlow’s obligations

  1. Process Customer Data only on Customer’s instructions; inform Customer if an instruction appears to breach applicable law.
  2. Ensure staff with access are bound by confidentiality and access only what their role requires; log platform-staff access.
  3. Implement the technical and organisational measures described in Annex 1 (and at nexlyflow.com/security).
  4. Engage sub-processors only as listed in Annex 2; give Customer at least 30 days’ notice of additions by email, during which Customer may object on reasonable grounds.
  5. Assist Customer, at reasonable cost where the request is extensive, with data-subject requests (access, correction, erasure, objection) and with data-protection impact assessments.
  6. Notify Customer of a personal-data breach affecting Customer Data without undue delay and within 72 hours of confirmation, with the information reasonably needed for Customer’s own notifications.
  7. On termination, allow Customer to export Customer Data for 30 days, then delete it from production and let it rotate out of backups on the backup retention schedule, unless retention is required by law.
  8. Make available the information reasonably necessary to demonstrate compliance and allow audits by Customer or an independent auditor mandated by Customer, no more than once a year unless required by a supervisory authority, on 30 days’ notice and subject to confidentiality.

4. Customer’s obligations

Customer warrants that it has a lawful basis to contact each data subject through the Service (including compliance with the Singapore PDPA and Spam Control Act, and any applicable Do Not Call requirements), that it records that basis in the Service where the Service asks for it, and that its instructions comply with applicable law.

5. International transfers

Customer Data is hosted in Malaysia. Transfers to sub-processors outside Malaysia and Singapore (Annex 2) are covered by the sub-processor’s standard contractual protections; NexlyFlow will provide details on request.

6. Liability and precedence

Liability under this DPA is subject to the limitations in the main agreement. In case of conflict, this DPA prevails over the main agreement on the subject of personal data.

Annex 1 – Security measures (summary)

  • TLS for all connections; encryption at rest for mailbox credentials and messaging tokens.
  • Tenant isolation at the application and database-query level.
  • Role-based access (Owner / Admin / Agent) with Owner-controlled permissions and launch approval.
  • Workspace security log of sign-ins and permission changes; per-message delivery and consent trail.
  • Daily database and file backups, retained 10 days, stored in Malaysia.
  • Emergency stop for outbound sending; rate limits and bounce protection.
  • Regular security patching; continuous server monitoring.

Annex 2 – Sub-processors

Sub-processor Purpose Location
Hostinger International Ltd. Hosting, backups Malaysia (data centre)
Meta Platforms, Inc. WhatsApp Cloud API Global
OpenAI, L.L.C. AI text generation (API; no training on customer data) United States
Stripe, Inc. Payment processing Global
Google LLC Optional sign-in Global

Signatures

For NexlyFlow Pte. Ltd.

Name: ______________________
Title: ______________________
Date: ______________________
Signature: __________________

For Customer (company name & UEN): __________________

Name: ______________________
Title: ______________________
Date: ______________________
Signature: __________________

NexlyFlow

NexlyFlow Pte. Ltd.
UEN 202632611H

B2B outreach, built on comprehensive, up-to-date business data.

Product

Lead LibraryContactOutreach EngineComplianceHelp Center

Company

Privacy PolicyTerms of ServiceRefund PolicySecurityDPAEmail: info@nexlyflow.com
© 2026 NexlyFlow Pte. Ltd. All rights reserved.
Contains information from ACRA datasets accessed via data.gov.sg under the Singapore Open Data Licence v1.0. NexlyFlow Pte Ltd is not affiliated with, or endorsed by, ACRA or the Singapore Government.
NexlyFlow

One platform. Every channel. Smarter growth.

Product

  • Features
  • Pricing
  • Integrations
  • Changelog

Solutions

  • B2B SaaS
  • E-commerce
  • Agencies
  • Enterprise

Company

  • About
  • Blog
  • Careers
  • Contact

Nexly AI Lead Generation System

Privacy Policy Terms of Service Refund Policy Security DPA Cookie Policy