Legal
Data Processing Agreement
Last updated: 30 March 2026 · Effective date: 30 March 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Makeshift Digital Oy (“Processor”, “we”) and the Customer (“Controller”, “you”) who has agreed to the Flowtusk Terms of Service. This DPA is entered into pursuant to Article 28 of the EU General Data Protection Regulation (GDPR) 2016/679.
By using the Flowtusk service, you agree to the terms of this DPA. This DPA applies to all processing of personal data that Flowtusk carries out on your behalf.
1. Definitions
Terms defined in the GDPR (e.g. “personal data”, “processing”, “data subject”, “supervisory authority”) carry the same meaning in this DPA. Additionally:
- Controller means the Customer, who determines the purposes and means of processing personal data.
- Processor means Makeshift Digital Oy, which processes personal data on behalf of the Controller.
- Sub-processor means any third party engaged by the Processor to process personal data.
- Services means the Flowtusk platform as described in the Terms of Service.
2. Processing Details
Subject matter and duration
The Processor shall process personal data for the duration of the Customer’s subscription to the Services.
Nature and purpose of processing
Flowtusk processes personal data submitted via Webflow forms on behalf of the Controller, for the purpose of routing, enriching, and delivering that data to connected CRM systems (e.g. HubSpot) and other integrations configured by the Controller.
Types of personal data
The categories of personal data processed depend entirely on what the Controller collects via their Webflow forms. These may include names, email addresses, phone numbers, company names, and any other fields the Controller configures.
Categories of data subjects
The data subjects are the Controller’s website visitors and form respondents (typically the Controller’s customers, leads, or contacts).
3. Obligations of the Processor
Makeshift Digital Oy shall:
- Process personal data only on documented instructions from the Controller, including with regard to international transfers, unless required to do so by EU or Finnish law.
- Ensure that persons authorised to process personal data are bound by confidentiality obligations.
- Implement appropriate technical and organisational security measures in accordance with Article 32 GDPR.
- Respect the conditions for engaging sub-processors as set out in this DPA.
- Assist the Controller in fulfilling its obligations to respond to data subject rights requests.
- Assist the Controller in ensuring compliance with Articles 32–36 GDPR (security, breach notification, DPIAs).
- At the Controller’s choice, delete or return all personal data upon termination of the Services, and delete existing copies unless EU or Finnish law requires storage.
- Make available all information necessary to demonstrate compliance and allow for audits.
4. Obligations of the Controller
The Controller warrants that:
- It has a valid legal basis under GDPR for collecting the personal data it routes through Flowtusk.
- It has provided appropriate privacy notices to data subjects whose data is processed via the Services.
- It shall notify Makeshift Digital Oy without undue delay if any instructions it provides would violate GDPR or other applicable law.
5. Sub-processors
The Controller provides general written authorisation for Makeshift Digital Oy to engage sub-processors. The current list of sub-processors is:
- Amazon Web Services (AWS) — cloud infrastructure, hosting, and data storage
- PostHog — product analytics and event tracking
We will inform the Controller of any intended changes to sub-processors with at least 14 days’ notice, giving the Controller the opportunity to object. Sub-processors are bound by data processing terms no less protective than this DPA.
6. Security Measures
Makeshift Digital Oy implements the following measures in accordance with Article 32 GDPR:
- Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256)
- Access controls and least-privilege principles for internal systems
- Regular security testing and vulnerability management
- Employee security awareness and confidentiality obligations
- Business continuity and data backup procedures
7. Data Subject Rights
If Makeshift Digital Oy receives a data subject request directly related to data processed on behalf of the Controller, we will promptly forward it to the Controller. We will provide reasonable assistance in fulfilling such requests as required under Articles 15–22 GDPR.
8. Personal Data Breaches
In the event of a personal data breach affecting Controller’s data, Makeshift Digital Oy will:
- Notify the Controller without undue delay and, where feasible, within 36 hours of becoming aware of the breach.
- Provide the information required under Article 33(3) GDPR to the extent available.
- Cooperate with the Controller in managing the breach and meeting notification obligations to the Finnish Data Protection Ombudsman and affected data subjects.
9. International Data Transfers
Makeshift Digital Oy primarily processes data within the EU/EEA. Where sub-processors are located outside the EU/EEA, transfers are governed by Standard Contractual Clauses (SCCs) or other GDPR-compliant transfer mechanisms.
10. Governing Law
This DPA is governed by the laws of Finland. Disputes arising from this DPA shall be subject to the exclusive jurisdiction of the Helsinki District Court.
11. Contact for Data Protection Enquiries
Makeshift Digital Oy — Data Protection
Business ID (Y-tunnus): 3429015-7
Eerinkatu 28, 00180 Helsinki, Finland
Email: hasan@flowtusk.com