Cargando tu información...
Cargando tu información...
Article 28 GDPR and Article 33 LOPDGDD. Last updated: September 2026
Translation provided for convenience
This English version of the Data Processing Agreement is provided for convenience only. In the event of any discrepancy or inconsistency between this translation and the Spanish version, the Spanish version shall prevail. The Spanish version is available at immigraflow.io/es/encargo-tratamiento.
This contract governs the processing of personal data that the Provider carries out on behalf of the Firm when providing the ImmigraFlow service. It forms part of the Terms and Conditions (section 11), and capitalised terms (Platform, User, Firm's Client, Firm Data) have the meaning given to them in the Terms.
The contract is entered into by electronic means: the Firm accepts it by accepting the Terms when registering or contracting, and remains bound by it for as long as the Terms remain in force. This electronic form satisfies the written-form requirement of Article 28(9) of Regulation (EU) 2016/679 (GDPR).
The Provider will process, on behalf of the Firm, the personal data that the Firm, its Users or the Firm's Clients enter into the Platform, solely for the purpose of providing the service described in the Terms. This contract does not cover the data of the Firm's account and of its Users that the Provider processes as controller (subscription billing, commercial communications, support, analytics), which are governed by the Privacy Policy.
This processing agreement lasts as long as the contract under the Terms and, once that ends, for as long as the Provider retains the data under clause 15. The confidentiality and security obligations remain in force for as long as the Provider retains any Firm Data.
Purpose: managing the Firm's immigration case files and its relationship with its clients through the Platform.
Processing operations, depending on the functions the Firm uses:
The Firm decides what data it enters. Given the nature of the Platform, the following may be processed:
As controller, it is for the Firm to:
The Provider undertakes to:
The Provider applies technical and organisational measures appropriate to the risk, taking into account that the Platform processes identity documentation, data of minors, health data and criminal record data. The measures currently in place are:
The Provider reviews these measures and may update them, without lowering the level of protection they provide.
The Firm gives the Provider general written authorisation to engage the sub-processors listed below. The Provider imposes on each of them, by contract, the same data protection obligations it assumes under this contract, and is liable to the Firm for their compliance.
Before adding or replacing a sub-processor, the Provider will notify the Firm's administrators by email and update this page at least 30 days in advance. The Firm may object within that period on reasonable data protection grounds. If no solution is found, the Firm may terminate the contract before the change takes effect, and the Provider will refund the portion already paid for the period it will not enjoy.
| Sub-processor | Service and data | Location | Transfer safeguards |
|---|---|---|---|
| Supabase Supabase, Inc. | Database, user authentication and document storage. All Firm Data. | European Union: Paris, France (eu-west-3 region). Company established in the United States. | Data hosted in the EU. For any access the provider may need from outside the EEA: Standard contractual clauses of the European Commission (Implementing Decision (EU) 2021/914). |
| Vercel Vercel Inc. | Hosting and running of the application, content delivery network, and cookie-free traffic and performance measurement. The data travelling in each request to the Platform while it is being processed, and technical operating logs. | European Union: server functions run in Paris (cdg1 region), alongside the database. The content delivery network is worldwide. Vercel Inc. is a United States entity. | Standard contractual clauses of the European Commission (Implementing Decision (EU) 2021/914). |
| OpenRouter OpenRouter, Inc. | Gateway that routes each artificial intelligence request to the model provider. The content sent to each AI function: text and images of documents, case file data, messages being translated and questions to the assistant. | United States. | Standard contractual clauses of the European Commission (Implementing Decision (EU) 2021/914). |
| Proveedores de modelos de IA a través de OpenRouter Google (Gemini), Anthropic (Claude, servido por Anthropic o Amazon Bedrock), OpenAI (embeddings) y Mistral AI (OCR) | Execution of the AI models: Google (Gemini) for document reading and text tasks; Anthropic (Claude) as an alternative and for translating messages; OpenAI to convert regulatory look-up queries into vectors; Mistral AI to recognise the text of scanned PDFs when the first reading fails; and Anthropic (Claude) as an alternative for reading images and PDFs. The same data OpenRouter receives for each request. | United States or the European Union, depending on the provider OpenRouter assigns to each request. | Every request requires OpenRouter to route it only to providers that do not retain the data or use it to train models. In addition, the terms of OpenRouter's contract with each provider apply. |
| Resend Resend, Inc. | Sending the Platform's emails (notices, invitations, reminders) and receiving replies to those emails. The address, name and content of each email. | European Union: Ireland (eu-west-1 region). Company established in the United States. | Sent from the EU. For access from outside the EEA: Standard contractual clauses of the European Commission (Implementing Decision (EU) 2021/914). |
| Stripe Stripe Payments Europe, Limited | Collecting the Firm's subscription payment and, when the Firm charges its clients with Stripe Connect, processing those payments. Name, email address, amount and description of each payment. Card data is collected directly by Stripe and the Provider does not see it. | Ireland, with processing in the United States by Stripe, Inc. | Standard contractual clauses of the European Commission (Implementing Decision (EU) 2021/914) and the EU-U.S. Data Privacy Framework. |
| Sentry Functional Software, Inc. | Logging of the application's technical errors and, when an error occurs in the browser, recording of the session with all text masked and images blocked. Technical error data (route, browser, stack trace). Identifying fields (passport, NIE, date of birth, address, phone, email) are removed before sending, but an error message may contain other case file data. | European Union: Germany (EU data region). Company established in the United States. | Data hosted in the EU. For access from outside the EEA: Standard contractual clauses of the European Commission (Implementing Decision (EU) 2021/914). |
| PostHog PostHog, Inc. | Analytics of Platform usage, only if the person accepts analytics cookies. Not loaded on the pages used by the Firm's Clients. Internal identifier of the User and the organisation, pages visited and interactions, which may include the visible text of elements clicked. | European Union: Frankfurt, Germany. Company established in the United States. | Data hosted in the EU. For access from outside the EEA: Standard contractual clauses of the European Commission (Implementing Decision (EU) 2021/914). |
| DigitalOcean DigitalOcean, LLC | Server running the WhatsApp channel integration. Only involved if the Firm enables that channel. Phone number, messages, attachments and metadata of the conversations of the linked number. | European Union: Frankfurt, Germany. Company established in the United States. | Data hosted in the EU. For access from outside the EEA: Standard contractual clauses of the European Commission (Implementing Decision (EU) 2021/914). |
These are not sub-processors of the Provider, because the Firm contracts or connects them with its own account and their processing is governed by the Firm's contract with each of them. The Platform sends or receives data from them only when the Firm enables the integration:
The Provider only transfers data outside the European Economic Area to the sub-processors listed in clause 10.2, on the terms indicated there: on the basis of a European Commission adequacy decision, such as the EU-U.S. Data Privacy Framework, or with the safeguards of Article 46 GDPR, such as standard contractual clauses. The Firm authorises these transfers by accepting this contract.
The Provider will notify the Firm, without undue delay and in any event within a maximum of 48 hours of becoming aware of it, of any personal data breach affecting Firm Data. The notification will be sent by email to the Firm's administrators and will include, to the extent known, the information required by Article 33(3) GDPR: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. If all the information cannot be provided at once, it will be provided in phases.
It is for the Firm to notify the breach to the Spanish Data Protection Agency and, where applicable, to the data subjects. The Provider will provide it with the assistance it needs to do so.
The Provider will give the Firm the information about the Platform and its security measures that it needs to carry out a data protection impact assessment and, where applicable, the prior consultation with the supervisory authority.
These same rules are set out in section 6 of the Terms.
The Provider will make available to the Firm all the information necessary to demonstrate compliance with this contract and with Article 28 GDPR. The Firm, or an independent auditor it appoints and who undertakes to keep confidentiality, may carry out audits and inspections. Unless there has been a security breach or a supervisory authority requires it, audits will be requested at least 30 days in advance, no more than once a year, will preferably be carried out through remote documentary review without affecting the security of other firms' data, and their cost will be borne by the Firm.
Each party is liable for its own breaches of data protection law under Article 82 GDPR. If the Provider were to process the data for its own purposes or in breach of the Firm's instructions, it will be regarded as controller of that processing (Article 28(10) GDPR). In the relationship between the parties, the limits set out in section 10 of the Terms apply, to the extent permitted by law.
In data protection matters, this contract prevails over any other provision of the Terms. It is governed by the GDPR, by Spanish Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD), and by Spanish law. For any dispute, the parties submit to the Courts of Madrid (Spain).
For any question about this contract, a personal data breach or the exercise of rights: hello@immigraflow.io.