Data Processing Addendum
Effective August 23, 2026
These terms govern how FlowTaskGen LLC handles personal data that your company puts into NailWhale - most importantly, your customers' personal information. This addendum forms part of our Terms of Service and applies automatically; no signature is needed.
1. Roles
For the personal data your company puts into NailWhale about your own customers, employees and contacts, you are the controller and we are the processor. You decide what to collect and why; we hold and process it on your documented instructions.
Your instructions are: this addendum, our Terms of Service, and your ordinary use of the product’s features. We will not process that data for any other purpose. If we ever believe an instruction from you would break the law, we will tell you rather than quietly comply.
For your own account data - who at your company has a login - we are the controller, and our Privacy Policy governs it.
2. What is processed
- Categories of data subject: your customers (typically homeowners), your employees and subcontractors who use the service, and your business contacts.
- Categories of personal data: names, postal addresses, email addresses, telephone numbers, photographs of property, job and project details, contract values, payment records, notes, and the activity records showing which user did what.
- Special categories: none. The product is not designed to hold health, biometric or similarly sensitive data, and it should not be used for it.
- Duration: for as long as your subscription is active, plus the retention period in section 8.
3. Our obligations
- We process personal data only on your instructions, and only to provide the service.
- We do not sell it, and we do not use it for our own purposes - including training AI models.
- Everyone with access to it is bound by confidentiality obligations.
- We keep the security measures described in section 4, and we will not weaken them during the agreement.
- We help you meet your own obligations: responding to data subject requests, doing impact assessments, and dealing with regulators.
4. Security measures
- Isolation between customers is enforced by the database itself. Every record carries the company that owns it, and the access rules live next to the data rather than depending on application code remembering to filter.
- Encryption in transit for all connections, and encryption at rest by our database and hosting providers.
- Uploaded files are stored privately and are never publicly addressable. Access is through short-lived links scoped to the requesting user.
- Authentication with hashed passwords, rate-limited sign-in and password reset, and single-use links for invitations and resets.
- Production data is separated from development and testing environments, which hold no real customer data.
- Access to production systems is limited to personnel who need it to operate the service.
- Automated backups with point-in-time recovery on the production database.
- Activity records inside the product show which user made a change and when.
5. Personal data breaches
If we become aware of a breach affecting personal data we process for you, we will notify you without undue delay and in any case within 72 hours of becoming aware of it.
The notice will describe what happened, the categories and approximate volume of data involved, the likely consequences, and the steps we are taking. Where we cannot establish all of that at once, we will send what we have and follow up rather than waiting for a complete picture.
Notifying the relevant supervisory authority and the affected individuals is your decision as controller; we will give you what you need to make it.
6. Subprocessors
You give us general authorisation to engage the subprocessors listed below. Each is bound by written terms no less protective than these, and we remain responsible to you for their performance.
| Provider | What they do | What they can see | Where |
|---|---|---|---|
| Supabase | Database, authentication and file storage - where the application data lives | All customer data: jobs, clients, documents, photos, financial records, user accounts | United States |
| Vercel | Application hosting and delivery | Data in transit while a page is served, plus request logs (IP address, URL, timestamp) | United States |
| Resend | Sending transactional email - invitations, password resets, notification digests | Recipient name and email address, and the contents of that message | United States |
| Anthropic | AI drafting of proposal text, when a user chooses to use it | The job and scope details included in that specific drafting request | United States |
| Stripe | Subscription payments and billing | Billing contact and payment details, which are given directly to Stripe and never reach us | United States |
If we add or replace a subprocessor, we will tell you at least 30 days beforehand at the email address on your account. If you have a reasonable objection on data protection grounds, tell us and we will work to resolve it; if we cannot, you may cancel your subscription without penalty for the remainder of the term.
7. International transfers
The service is hosted in the United States, and the providers in section 6 process data there. If you are in a jurisdiction that restricts transfers abroad, that is what you are agreeing to when you use the service.
Where a transfer mechanism such as the EU Standard Contractual Clauses is required for your business, contact us and we will put one in place.
8. Return and deletion
You can export your data at any time while your subscription is active, and we will provide it in a machine-readable format on request.
When your subscription ends, we keep your data for 30 days so you can export it or reactivate, then delete it from live systems. Encrypted backups holding it expire on our providers’ ordinary retention cycle, after which it is gone from there too. If you want deletion sooner than 30 days, ask and we will do it.
9. Audits
On reasonable request, and no more than once a year unless a regulator or a breach requires otherwise, we will provide the information you reasonably need to confirm we are meeting this addendum - including a written description of our security measures and answers to a security questionnaire.
We are a small company and do not yet hold a SOC 2 or ISO 27001 certification. We would rather tell you that here than let you discover it during procurement.
10. Assisting with individuals' requests
If someone contacts us directly about data held in your workspace - a homeowner asking for a copy of their records or asking to be deleted - we will not act on it ourselves. We will pass it to you promptly, because that record is yours, and then help you carry out whatever you decide.
11. Order of precedence
If this addendum conflicts with the Terms of Service on the handling of personal data, this addendum wins. Everything else in the Terms stays as it is.
If your organisation needs a signed counterpart, or your own DPA reviewed, email hello@nailwhale.com and we will handle it properly rather than pointing you at this page.
Questions about this document: hello@nailwhale.com