Legal

8Dflow Data Processing, Security & Subprocessors

Effective date:
29 June 2026
Last updated:
20 July 2026
Version:
1.1

This page explains how 8Dflow processes customer personal data, the security measures we use, our approach to subprocessors, international transfers, and data deletion or return.

It includes our Data Processing Addendum, which applies where 8Dflow processes personal data on behalf of a Customer under applicable data protection laws.

This page forms part of our Terms of Service.

1. Plain-English overview

8Dflow is browser-based workflow and documentation software for manufacturing quality activities such as 8D reports, NCRs, SCARs, corrective actions, evidence tracking, owners, due dates, approvals, and customer-facing PDF exports.

Customers may enter information into 8Dflow that includes personal data, such as names, email addresses, roles, comments, ownership assignments, approval records, workflow history, and attachments.

This page explains the terms that apply when 8Dflow processes that personal data for a Customer.

This page should be read together with our Terms of Service, Privacy Policy, Privacy Collection Notice, Cookie Notice, Acceptable Use Policy, and Support Policy where applicable.

2. Data Processing Addendum

This Data Processing Addendum applies when:

  • a Customer uses 8Dflow;
  • Customer Data includes personal data; and
  • 8Dflow processes that personal data on behalf of the Customer under applicable data protection laws.

If this Data Processing Addendum conflicts with the Terms of Service in relation to the processing of Customer Personal Data, this Data Processing Addendum controls for that processing.

3. Definitions

In this page:

“Customer” means the organisation that creates an account, starts a trial, purchases a subscription, or otherwise uses 8Dflow.

“Services” means the 8Dflow software, applications, website, and related services we make available. Where the context refers to the product or service, references to “8Dflow” mean the Services.

“Customer Data” means information, content, files, records, comments, attachments, evidence, reports, user details, workflow history, and other materials submitted to or created in 8Dflow by a Customer or its Users.

“Customer Personal Data” means personal data included in Customer Data that 8Dflow processes on behalf of a Customer.

“Data Processing Addendum” or “DPA” means the data processing terms set out on this page.

“Data Protection Laws” means applicable privacy, data protection, and data security laws that apply to the processing of Customer Personal Data.

“EEA” means the European Economic Area.

“EU GDPR” means Regulation (EU) 2016/679.

“EU SCCs” means the European Commission’s standard contractual clauses for international transfers of personal data, as updated or replaced from time to time.

“European Data Protection Laws” means the EU GDPR, UK GDPR, Swiss FADP, and related privacy or data protection laws that apply to Customer Personal Data.

“Personal Data” means information relating to an identified or identifiable individual, or any similar term under applicable Data Protection Laws.

“Personal Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.

“Process” and “processing” mean any operation performed on Personal Data, such as collection, hosting, storage, retrieval, organisation, use, transmission, disclosure, restriction, deletion, or return.

“Restricted Transfer” means a transfer of Customer Personal Data from the EEA, UK, or Switzerland to a country or recipient that requires a transfer safeguard under applicable European Data Protection Laws.

“Subprocessor” means a third-party service provider engaged by 8Dflow to process Customer Personal Data on behalf of a Customer.

“Swiss FADP” means the Swiss Federal Act on Data Protection, where applicable.

“Technical and Organisational Measures” means measures designed to protect Customer Personal Data, taking into account the nature, scope, context, and purposes of processing and the risks involved.

“UK Addendum” means the UK International Data Transfer Addendum to the EU SCCs, or any replacement approved under UK Data Protection Laws.

“UK GDPR” means the UK General Data Protection Regulation as defined in the UK Data Protection Act 2018.

4. Roles of the parties

For Customer Personal Data, the Customer is generally the controller, business, or equivalent decision-maker under applicable Data Protection Laws.

8Dflow is generally the processor, service provider, or equivalent service provider processing Customer Personal Data on behalf of the Customer.

Where the Customer acts as a processor for another controller, 8Dflow may act as a subprocessor to the Customer.

8Dflow may also process some personal data for its own business purposes, such as website operation, account administration, billing, security, analytics, product communications, marketing where permitted, and support. That processing is described in our Privacy Policy.

This Data Processing Addendum applies only to Customer Personal Data that 8Dflow processes on behalf of a Customer.

5. Customer instructions

8Dflow will process Customer Personal Data only:

  • to provide, maintain, secure, support, and improve 8Dflow;
  • according to the Terms of Service, this Data Processing Addendum, and any applicable order form;
  • according to documented Customer instructions;
  • for international transfers authorised under this Data Processing Addendum;
  • as otherwise required by applicable law.

The Customer instructs 8Dflow to process Customer Personal Data as necessary to provide 8Dflow and related hosting, storage, support, security, maintenance, troubleshooting, communication, billing-support, backup, deletion, export, and service-improvement activities.

If 8Dflow believes a Customer instruction infringes applicable Data Protection Laws, 8Dflow may notify the Customer unless prohibited by law.

6. Customer responsibilities

The Customer is responsible for:

  • ensuring it has a lawful basis to collect, use, upload, process, and share Customer Personal Data through 8Dflow;
  • providing any required privacy notices to Users, employees, contractors, suppliers, customers, and other individuals;
  • obtaining any required consents or permissions;
  • deciding what Customer Personal Data is submitted to 8Dflow;
  • ensuring Customer Personal Data is accurate, appropriate, and limited to what is needed;
  • responding to privacy and data protection requests from individuals where the Customer controls the relevant Customer Personal Data;
  • ensuring Users comply with the Terms of Service and Acceptable Use Policy;
  • not submitting prohibited or unsupported data to 8Dflow;
  • ensuring Customer Personal Data is collected and processed lawfully before it is submitted to 8Dflow;
  • ensuring Customer Personal Data is not excessive for the Customer’s use of 8Dflow;
  • ensuring Users do not submit prohibited, unsupported, secret credential, highly sensitive, or highly regulated data;
  • using available product settings, roles, permissions, and exports appropriately;
  • complying with applicable European Data Protection Laws where they apply to the Customer.

8Dflow is not responsible for the Customer’s internal privacy notices, legal basis, consents, data-entry practices, or decisions about what Customer Personal Data to include in 8Dflow.

7. 8Dflow processing obligations

8Dflow will:

  • process Customer Personal Data only for the purposes described in this Data Processing Addendum, the Terms of Service, and applicable Customer instructions;
  • ensure people authorised to process Customer Personal Data are subject to confidentiality obligations;
  • use Technical and Organisational Measures designed to protect Customer Personal Data;
  • assist the Customer with reasonable requests relating to Customer Personal Data where required by applicable Data Protection Laws and this Data Processing Addendum;
  • use Subprocessors only as described in this Data Processing Addendum;
  • impose appropriate written data protection obligations on Subprocessors that process Customer Personal Data;
  • notify affected Customers of Personal Data Breaches as described below;
  • delete or return Customer Personal Data as described in this Data Processing Addendum and the Terms of Service;
  • make available reasonable information needed to demonstrate compliance with this Data Processing Addendum, subject to the audit and information-request limitations below.

8. Nature and purpose of processing

8Dflow processes Customer Personal Data to provide browser-based manufacturing quality workflow and documentation software.

Processing activities may include:

  • hosting;
  • storage;
  • retrieval;
  • organisation;
  • display;
  • transmission;
  • search;
  • export;
  • backup;
  • support;
  • troubleshooting;
  • security monitoring;
  • account administration;
  • deletion;
  • service maintenance;
  • service improvement using aggregated or de-identified information that does not identify the Customer, Users, individuals, or confidential business information.

8Dflow does not independently decide the content of Customer Data entered by Customers or Users.

9. Processing details schedule

ItemDetails
Subject matterProviding browser-based manufacturing quality workflow and documentation software.
DurationThe Customer’s subscription or trial term, plus any export, deletion, backup, legal, security, billing, or retention period described in the Terms of Service, Privacy Policy, or this Data Processing Addendum.
Nature of processingHosting, storage, retrieval, organisation, display, transmission, search, export, backup, support, troubleshooting, security monitoring, account administration, deletion, service maintenance, and service improvement using aggregated or de-identified information that does not identify the Customer, Users, individuals, or confidential business information.
PurposeProviding, maintaining, securing, supporting, troubleshooting, and improving 8Dflow.
Data subjectsCustomer Users, administrators, employees, contractors, supplier contacts, customer contacts, reviewers, approvers, and people referenced in 8D reports, NCRs, SCARs, corrective actions, evidence, comments, attachments, or workflow records.
Personal data categoriesNames, email addresses, job titles, roles, company names, user account details, ownership assignments, due dates, comments, approval records, workflow history, activity history, customer or supplier contact details, attachments, support information, and other personal data entered by Customers or Users.
Sensitive or special category dataNot intended for sensitive health information, highly sensitive personal information, special category data, classified information, payment card data, secret credentials, or export-controlled technical data unless expressly supported by 8Dflow in writing.

10. Categories of personal data

Customer Personal Data may include:

  • names;
  • email addresses;
  • job titles;
  • roles;
  • company names;
  • user account details;
  • ownership assignments;
  • due dates;
  • comments;
  • approval records;
  • workflow history;
  • activity history;
  • customer or supplier contact details;
  • attachments;
  • other personal data entered by Customers or Users into 8Dflow.

The exact Customer Personal Data processed depends on what the Customer and its Users choose to enter.

11. Categories of individuals

Customer Personal Data may relate to:

  • Customer Users;
  • Customer administrators;
  • employees;
  • contractors;
  • supplier contacts;
  • customer contacts;
  • reviewers;
  • approvers;
  • people referenced in 8D reports, NCRs, SCARs, corrective actions, evidence, comments, attachments, or workflow records.

12. Prohibited and unsupported data

Customers and Users must comply with the Prohibited Data section of our Acceptable Use Policy. That section contains the primary list of data that must not be submitted to or stored in 8Dflow unless we expressly agree in writing.

For the purposes of this Data Processing Addendum, 8Dflow is also not intended for special category data under European Data Protection Laws unless we expressly support that use in writing.

Without limiting the Acceptable Use Policy, 8Dflow is not intended for highly regulated, highly sensitive, special category, export-controlled, classified, payment-card, or secret credential data unless we expressly support that use in writing.

The Customer is responsible for determining whether Customer Personal Data is appropriate for use with 8Dflow.

13. Technical and Organisational Measures

8Dflow uses reasonable technical and organisational measures designed to protect Customer Personal Data against unauthorised access, loss, misuse, disclosure, alteration, and destruction, taking into account the nature, scope, context, and purposes of processing and the risks involved.

Measures may include, as applicable to the service:

  • access controls for authorised personnel;
  • role-based access controls within the product where available;
  • authentication controls;
  • encryption in transit;
  • reasonable protections for data storage;
  • logging and monitoring for security and operational purposes;
  • backup and recovery processes;
  • measures designed to support confidentiality, integrity, availability, and resilience of the service;
  • processes designed to restore access to Customer Personal Data after certain technical or operational incidents;
  • vulnerability management appropriate to the stage and nature of the service;
  • confidentiality obligations for personnel with access to Customer Personal Data;
  • vendor review for service providers that process Customer Personal Data;
  • incident response procedures;
  • deletion or return processes for Customer Personal Data.

No online service can guarantee complete security.

Customers remain responsible for managing their own users, permissions, devices, networks, passwords, authentication practices, exports, downloaded files, internal security procedures, and access to Customer Data under their control.

14. Personal Data Breaches

If 8Dflow becomes aware of a Personal Data Breach affecting Customer Personal Data, we will notify affected Customers without undue delay, taking into account applicable law, the needs of any investigation, security measures, and the information reasonably available to us.

We will use reasonable efforts to provide an initial notice without undue delay and, where feasible, within 72 hours after becoming aware of a Personal Data Breach affecting Customer Personal Data, recognising that complete information may not be available at the time of initial notice.

Our notice may include, where reasonably available:

  • a description of the incident;
  • the categories of Customer Personal Data involved;
  • steps we have taken or plan to take;
  • steps we recommend the Customer take;
  • a contact point for follow-up.

Where information is not available at the same time, we may provide information in phases without undue further delay.

The Customer is responsible for determining whether regulator, supervisory authority, data-subject, customer, supplier, employee, contractor, or other third-party notices are required, unless applicable law states otherwise.

8Dflow will provide reasonable assistance with breach-related obligations where required by applicable Data Protection Laws and this Data Processing Addendum.

8Dflow is not required to notify Customers of unsuccessful security attempts, routine security events, or events that do not affect Customer Personal Data.

15. Subprocessors

The Customer gives 8Dflow general written authorisation to engage Subprocessors to process Customer Personal Data as needed to provide, host, secure, support, maintain, analyse, communicate about, bill for, or improve the service.

Subprocessors may include providers for:

  • cloud hosting;
  • database hosting;
  • file storage;
  • authentication;
  • payment processing;
  • transactional email;
  • customer support;
  • website analytics;
  • product analytics;
  • error monitoring;
  • security monitoring;
  • billing, subscription management, refunds, credits, chargebacks, and payment-status processing, where used;
  • AI-assisted drafting or summarisation features, if used.

8Dflow will require Subprocessors that process Customer Personal Data to be bound by written obligations that are substantially the same as the data protection obligations imposed on 8Dflow under this Data Processing Addendum, to the extent applicable to the Subprocessor’s processing.

8Dflow remains responsible for its Subprocessors’ processing of Customer Personal Data to the extent required by applicable Data Protection Laws.

16. Current providers and subprocessors

The following table lists 8Dflow’s current material providers and subprocessors. Providers may use their own subprocessors as described in their contractual and privacy documentation.

ProviderPurposeData scopeBroad processing locationRole or boundary
VercelPublic website and authenticated product hosting and application delivery.Customer Personal Data and request or technical information only as needed to deliver the hosted application.United States and other countries where Vercel or its subprocessors operate.Subprocessor for the hosted authenticated application.
SupabasePrimary database, authentication and file storage.Customer Data, Customer Personal Data, account information and authentication information.Sydney, Australia.Subprocessor.
ResendEarly-access, service and product transactional email.Recipient names, email addresses and service or transactional message content.United States.Service provider and, where it processes Customer Personal Data on 8Dflow’s behalf, Subprocessor.
StripeBilling and payment processing when paid subscriptions are offered.Billing, payment, invoice, tax and payment-status information. Report and workflow Customer Data is not intended to be sent to Stripe.United States and other countries where Stripe or its service providers operate.Payment processor or service provider. It is not intended to process Customer report or workflow records as a Subprocessor.
Google AnalyticsPublic marketing-site analytics only.Public website usage information. Customer Data is not intentionally sent.United States and other countries where Google or its service providers operate.Not intended to be a Customer Personal Data Subprocessor and not intended to run on authenticated product pages.
Vercel AnalyticsPublic marketing-site analytics only.Public website analytics information. Customer Data is not intentionally sent.United States and other countries where Vercel or its subprocessors operate.Not intended to be a Customer Personal Data Subprocessor and not intended to run on authenticated product pages.

No AI provider is used at launch. No separate helpdesk, error-monitoring provider, email-marketing provider, or advertising network is used at launch. Providers may use their own subprocessors as described in their contractual and privacy documentation.

17. Subprocessor updates and objections

8Dflow may update its Subprocessor list from time to time.

Where required by applicable Data Protection Laws, 8Dflow will provide notice of new material Subprocessors and give Customers an opportunity to object on reasonable data protection grounds.

Unless another period is stated in an order form or written agreement, Customers must submit any objection within 15 days after notice of the new material Subprocessor.

If a Customer reasonably objects to a new Subprocessor and the parties cannot resolve the objection, 8Dflow may, where practicable, avoid using the Subprocessor for that Customer, provide a reasonable workaround, or allow the Customer to terminate the affected subscription according to the Terms of Service and applicable law.

An objection must be based on reasonable data protection grounds, not general commercial preference.

18. International transfers

8Dflow is based in Australia, but Customer Personal Data may be processed in other countries by 8Dflow, its personnel, or its Subprocessors.

Those countries may have privacy and data protection laws that differ from the Customer’s country.

Where required by applicable Data Protection Laws, 8Dflow will use appropriate safeguards or lawful transfer mechanisms for international transfers of Customer Personal Data.

Where a Restricted Transfer requires the EU SCCs, UK Addendum, or another approved safeguard, 8Dflow and the Customer will enter into the applicable transfer addendum or approved mechanism during contracting. The applicable module selections, parties, annex information, governing law, forum, supervisory authority, and UK Addendum tables will be completed where required.

This public page does not, by itself, represent that the EU SCCs or UK Addendum have been completed for every Customer or transfer.

The parties will reasonably cooperate with transfer impact assessments, transfer risk assessments, and supplementary measures where required by applicable European Data Protection Laws.

19. Data subject requests

If 8Dflow receives a request from an individual relating to Customer Personal Data controlled by a Customer, 8Dflow may direct the individual to contact the Customer.

The Customer is responsible for responding to requests from individuals where the Customer controls the relevant Customer Personal Data.

8Dflow will not respond directly to a data subject request relating to Customer Personal Data except to direct the individual to the Customer, as required by law, or as instructed by the Customer.

Where required by applicable Data Protection Laws, 8Dflow will provide reasonable assistance without undue delay, taking into account the nature of the processing and information available to 8Dflow.

20. Government and legal requests

If 8Dflow receives a legal, regulatory, court, law enforcement, or government request for Customer Personal Data, we will handle the request in accordance with applicable law.

Where legally permitted and reasonably practicable, we will notify the affected Customer so the Customer may respond or object.

If legally permitted and reasonably practicable, 8Dflow will give the Customer enough information to allow the Customer to seek protective measures or object to the request.

8Dflow is not required to notify the Customer where prohibited by law or where notice would create legal, security, safety, or confidentiality risk.

8Dflow may disclose Customer Personal Data where required by law, court order, regulator, or valid legal process.

21. AI-assisted features

8Dflow does not currently offer AI-assisted features. No AI provider currently processes Customer Data or Customer Personal Data for an 8Dflow AI-assisted feature.

If AI-assisted features are offered in the future, they are designed as drafting and productivity aids only.

They are not designed to determine root cause, make quality decisions, approve corrective actions, verify effectiveness, decide containment, determine product release, certify compliance, replace human review, or replace qualified quality, engineering, regulatory, legal, supplier-management, or product-safety judgement.

Unless a product feature, order form, this Data Processing Addendum, or separate written agreement expressly states otherwise, 8Dflow does not use Customer Data to train third-party foundation models and does not permit third-party AI providers to use Customer Data to train their general models.

Unless a product feature, order form, this Data Processing Addendum, or separate written agreement expressly states otherwise, 8Dflow does not use Customer Data or Customer Personal Data to train 8Dflow proprietary artificial-intelligence or machine-learning models.

This does not prevent 8Dflow from using aggregated or de-identified information to understand, operate, secure, support, and improve the Services, provided that information does not identify a Customer, User, individual, or confidential business information.

To the extent information remains Customer Personal Data, processing remains subject to this Data Processing Addendum and applicable Customer instructions.

Where AI-assisted features involve third-party providers, those providers may be listed as Subprocessors where they process Customer Personal Data on behalf of 8Dflow.

If AI-assisted features or AI data-use practices materially change, 8Dflow will update this page and related legal pages where appropriate.

22. Deletion and return

During an active paid subscription, Customers may export only Customer Data made available through export features included in their plan. Export functionality may not include all Customer Data, attachments, workflow history, system information, logs, metadata, or configuration.

Customers must export any needed available Customer Data before the paid subscription period ends.

When the paid subscription period ends following termination or cancellation, access may be limited or disabled. No general post-termination access or self-service export period is guaranteed unless agreed in writing or required by law.

No 30-day paid post-termination export period applies as a default. Trial or free-plan data may be deleted or disabled after 30 days as described in the Terms of Service.

Where Data Protection Laws require deletion or return of Customer Personal Data, 8Dflow will comply with the Customer’s documented instruction, subject to applicable law, available functionality, security requirements, and written agreement. A required return obligation does not create a custom export or custom data-reconstruction obligation beyond available functionality unless agreed in writing.

Backups may persist temporarily under normal backup, security, legal-retention, and disaster-recovery practices.

23. Audit information

Where required by applicable Data Protection Laws, 8Dflow will make available reasonable information needed to demonstrate compliance with this Data Processing Addendum and applicable processor obligations.

This may include security summaries, policy summaries, subprocessor information, or written responses to reasonable security and privacy questions.

For self-service plans, audit rights are usually satisfied through written responses, policy summaries, security summaries, subprocessor information, and other reasonable documentation unless applicable law requires otherwise or 8Dflow expressly agrees in writing.

Any audit or information request must be reasonable, limited to what is required by applicable Data Protection Laws, and must not compromise the security, confidentiality, availability, or privacy of 8Dflow, other customers, or third parties.

24. Customer audits and questionnaires

8Dflow may respond to reasonable customer security or privacy questionnaires, depending on the Customer’s plan, the nature of the request, available information, and the stage of the commercial relationship.

Unless expressly agreed in writing, 8Dflow does not provide onsite audits, custom compliance reports, custom security assessments, or customer-specific audit rights for self-service plans.

Any audit, questionnaire, or information request must be reasonable, proportionate, limited to information needed for data protection compliance, and must not compromise the security, confidentiality, availability, or privacy of 8Dflow, other customers, Users, or third parties.

Nothing in this section limits rights that cannot lawfully be excluded under applicable Data Protection Laws.

25. Confidentiality

8Dflow will ensure that people authorised to process Customer Personal Data are subject to confidentiality obligations.

Customers are also responsible for maintaining the confidentiality of account credentials, exports, downloaded reports, shared PDFs, internal records, supplier information, customer information, and other Customer Data under their control.

26. Assistance with compliance

Where required by applicable Data Protection Laws, and taking into account the nature of the processing and information available to 8Dflow, we will provide reasonable assistance to Customers with:

  • security obligations;
  • data subject requests;
  • Personal Data Breach obligations;
  • deletion or return requests;
  • data protection impact assessments;
  • prior consultation with supervisory authorities where required by applicable Data Protection Laws;
  • information reasonably needed for privacy, security, or transfer assessments.

8Dflow does not provide legal, regulatory, engineering, quality-system, certification, audit, or compliance advice.

27. Limitation of liability

The limitation of liability in the Terms of Service applies to this Data Processing Addendum, except where applicable Data Protection Laws require otherwise.

Where the EU SCCs, UK Addendum, or mandatory Data Protection Laws apply and conflict with the limitation of liability in the Terms of Service, those mandatory terms control to the extent of the conflict.

Nothing in this Data Processing Addendum excludes, restricts, or modifies rights, remedies, liabilities, or obligations that cannot lawfully be excluded, restricted, or modified.

28. Changes to this page

8Dflow may update this Data Processing, Security & Subprocessors page from time to time.

If we make material changes, we will take reasonable steps to notify affected Customers where appropriate, such as by posting an updated version on our website, sending an email, or providing an in-product notice.

For existing paid subscriptions, changes that materially reduce Customer rights or materially increase Customer obligations under this Data Processing Addendum will not apply during the current paid subscription period unless:

  • the Customer agrees to the change;
  • the change is required by law;
  • the change is needed for security, privacy, fraud-prevention, misuse-prevention, operational, or service-protection reasons;
  • the change relates to a new feature, beta feature, optional feature, or new plan;
  • the change does not materially disadvantage the Customer.

The updated page will apply from the effective date stated on the updated page, except where applicable law requires a different process.

29. Contact

Questions about data processing, security, or subprocessors can be sent to:

8Dflow Pty Ltd
64A Burnett Street
Buderim QLD 4558
Australia
Email: legal@8dflow.com