Legal

Data processing agreement.

How Floatless processes end-customer data on your behalf: roles, security measures, sub-processors, and breach notification.

Data Processing Agreement

Last updated: September 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you and Floatless Inc. ("Floatless", "we", "us", or "our"). It applies where Floatless processes personal data on your behalf when you use our Services. By using the Services, you agree to this DPA.


1. Roles of the parties

TL;DR: For your end-customer billing data, you are the controller and we are the processor. For your own account data, we are the controller.

  • Merchant (you): You are the data controller for the personal data of your end customers that you submit to the Services (names, emails, billing addresses, tax status, and related billing details). You determine the purposes and means of that processing.
  • Floatless (us): We act as the data processor for end-customer data, processing it only on your instructions as described in this DPA. For your own account data (your identity, business info, and usage of our dashboard), Floatless acts as the data controller and handles it as described in our Privacy Policy.

You are responsible for ensuring you have a lawful basis for sharing end-customer data with us and for informing your end customers about how their data is processed.


2. Subject matter and duration

TL;DR: This DPA covers the processing we perform to run billing for you, for as long as you use the Services.

  • Subject matter: The processing of personal data as necessary to provide the Services — generating invoices, calculating taxes, facilitating payments, sending invoice emails on your behalf, performing compliance checks, and providing support.
  • Duration: For the term of your account under the Terms of Service, plus any retention period required by law after termination.

3. Processing instructions

TL;DR: We only process data to provide the Services, and we will tell you if an instruction looks unlawful.

Floatless processes personal data only on documented instructions from you, which are set out in the Terms of Service, this DPA, and your configuration of the Services. We will:

  • Process end-customer data solely for the purpose of providing the Services.
  • Not sell your data or share it with third parties except as described in this DPA and the Privacy Policy.
  • Immediately inform you if, in our opinion, an instruction infringes applicable data protection law.
  • Notify you if we become unable to meet our obligations under this DPA.

4. Confidentiality

TL;DR: Our people can only access data when their job requires it, and they are bound by confidentiality.

Floatless ensures that all personnel authorized to process personal data:

  • Are bound by confidentiality obligations, contractual or statutory.
  • Access personal data only as necessary to perform their role (for example, a support engineer debugging an invoice issue you reported).
  • Receive appropriate training on data handling and security practices.

5. Security measures

TL;DR: Encryption in transit and at rest, strict access controls, and audit logging.

Floatless implements industry-standard technical and organizational measures, including:

  • Encryption in transit: All data sent between your browser (or your servers, for API traffic) and ours is encrypted via TLS 1.3.
  • Encryption at rest: Sensitive database fields and backups are encrypted on disk.
  • Access controls: Internal access to customer data is restricted to employees with a specific business need, following least-privilege principles.
  • Audit logging: Access to production systems is logged so administrative actions can be traced and reviewed.
  • No raw cards: We never touch or store raw credit card numbers. Payment details are tokenized directly by Stripe.

6. Sub-processors

TL;DR: We run on Render and Supabase, protect traffic with Cloudflare, and process money with Stripe.

You authorize Floatless to engage the following sub-processors to assist in providing the Services. The Privacy Policy sub-processors section is the authoritative, current list of our sub-processors:

| Provider | Purpose | Location | |---|---|---| | Render | Cloud hosting | USA | | Supabase | Database storage | USA | | Stripe | Payment processing & identity verification | USA | | Cloudflare | DNS, CDN, and DDoS protection | Global |

Floatless will notify you of changes to the sub-processor list by updating the Privacy Policy. If you object to a new sub-processor on reasonable data protection grounds, contact us and we will work with you in good faith to resolve the concern.


7. Data subject requests

TL;DR: If your customers ask you about their data, we will help you answer.

Because you are the controller for end-customer data, your end customers should direct their data subject requests (access, correction, deletion, portability, or objection) to you. If Floatless receives a request from one of your end customers directly, we will:

  • Not respond to the substantive request ourselves, unless legally required to do so.
  • Notify you of the request so you can respond.

Where you need our assistance to fulfil a request — for example, retrieving or deleting end-customer data held in the Services — contact us at [email protected] and we will assist you without undue delay.


8. Personal data breach notification

TL;DR: If we have a breach affecting your data, we will tell you without undue delay.

If Floatless becomes aware of a personal data breach affecting personal data processed under this DPA, we will notify you without undue delay after becoming aware of it. Where possible, the notification will include the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures we have taken or propose to take to address it. You remain responsible for notifying your own regulators and end customers where the law requires you to do so.


9. Deletion and return on termination

TL;DR: When you leave, your data is deleted — except records the law makes us keep.

Upon termination or expiry of your account, the deletion terms in our Privacy Policy apply:

  • You can request full data deletion, and we will purge your data within 60 days.
  • Specific financial records that we are legally required to retain (for example, for tax authorities) are kept for the legally mandated period.
  • Encrypted backups are retained for 30 days for disaster recovery, after which they age out.

If you require your data in an exportable format before termination, you can retrieve it from the Services or contact us for assistance.


10. Data transfers and location

TL;DR: Your data is hosted as described in the Privacy Policy.

As described in the Privacy Policy, personal data is hosted by our infrastructure providers in the United States, and traffic is protected through Cloudflare's global network. Floatless remains responsible for the personal data it transfers to its sub-processors and will ensure they provide an adequate level of protection.


11. Governing law

TL;DR: Same legal framework as our Terms of Service.

This DPA is governed by the laws of Canada and the province of Ontario, consistent with the Governing Law section of our Terms of Service, without regard to conflict of laws provisions.


Contact

Questions about this DPA can be directed to our Data Protection Officer at [email protected].