Legal

Data Processing Agreement.

The terms under which RowFold processes personal data on your behalf — what we may do with it, who else touches it, how it is protected, and what happens when you leave.

Version 1.0 · Last updated · August 29, 2026 · Questions · privacy@rowfold.com
This one is already in force — you do not need to sign it. Unlike our Business Associate Agreement, which covers health data and is executed by both parties before it operates, this DPA forms part of the Terms of Service and applies automatically to every customer whose use of RowFold involves personal data. That is deliberate: the law requires these terms to be in place for all such processing, so making them conditional on asking would leave most customers with no agreement at all. If your procurement process needs a countersigned copy on your paper, email privacy@rowfold.com.

01How this applies

This Data Processing Agreement (the "DPA") is incorporated into the Terms of Service between you and RowFold LLC and applies whenever we process personal data on your behalf in providing the Service. Where this DPA and the Terms conflict on the handling of personal data, this DPA governs; on everything else, the Terms govern.

It is written to satisfy Article 28 of the UK and EU General Data Protection Regulation. Customers not subject to those regimes are welcome to rely on it anyway — we do not operate two standards of care and have no interest in maintaining two documents.

Reader's note — why there is no signature block: Article 28(9) requires these terms to be in writing, "including in electronic form", and accepting the Terms of Service is that. A DPA you have to request is a DPA most people never get, which protects nobody. The countersigned copy is available because procurement teams often need one for their own files, not because it changes what applies to you.

02Definitions

"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" have the meanings given in the GDPR. "Customer Personal Data" means personal data contained in Your Content, as that term is defined in the Terms — that is, the data you put into your workspaces. "Data Protection Law" means the EU GDPR (Regulation 2016/679), the UK GDPR and Data Protection Act 2018, and any other privacy law applicable to our processing under this DPA. "SCCs" means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914. "Subprocessor" means a third party engaged by us to process Customer Personal Data.

03Roles & scope

For the content in your workspaces, you are the Controller and we are the Processor. You decide what personal data to put into RowFold, why, and who may see it; we process it to run the Service for you.

For your own account and our marketing site, we are the Controller — the names and email addresses of your workspace members, billing contacts, support conversations, and usage data about how the product is used. That processing is described in the Privacy Policy and is not governed by this DPA.

The subject matter, duration, nature, purpose, data types and categories of data subject are set out in Annex I.

What you are responsible for. You warrant that you have a lawful basis for the personal data you put into RowFold and for instructing us to process it, that you have given data subjects whatever notice their law requires, and that your instructions do not require us to break the law. We cannot assess the lawfulness of data we cannot see the context for.

04Our instructions

We process Customer Personal Data only on your documented instructions, including as to international transfers, unless required otherwise by law — in which case we will tell you before processing, unless that law forbids us from telling you.

Your instructions are: the Terms, this DPA, and the operations you carry out through the Service itself. Configuring an automation, running an import, sending a form, granting a permission or asking an AI feature a question are all instructions; you do not need to send us anything separately for them to count as one.

We will tell you if we think an instruction breaks Data Protection Law, and may suspend the processing concerned until it is resolved. We do not sell personal data, we do not use it for advertising, and we do not use Customer Personal Data to train, fine-tune or improve any general-purpose artificial-intelligence model — our own or anyone else's.

05Confidentiality

Everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality, by contract, and access is limited by role to those who need it to operate or support the Service. That obligation survives the end of their engagement with us.

06Security

We implement appropriate technical and organisational measures to protect Customer Personal Data, taking account of the state of the art, the cost of implementation, and the nature and risk of the processing, as required by Article 32. Those measures are described in Annex II and in more detail on the security page.

What we do not have, stated here rather than found later. RowFold holds no SOC 2 report and no ISO 27001 certification, has not had a third-party penetration test, offers no customer-managed encryption keys and no choice of data region, and does not offer a contractual uptime guarantee. The compliance page is the full account. If any of those is a gating requirement for you, it is better learned now than at renewal.

We may update our security measures over time, provided the level of protection is not reduced.

07Subprocessors

You give us general authorisation to engage Subprocessors. The current list, what each one does and what data it touches, is published on the compliance page, which is the authoritative version — see Annex III.

Before adding a new category of Subprocessor we will update that list. If you object to a new Subprocessor on reasonable data-protection grounds, tell us at privacy@rowfold.com within 30 days; we will work with you to find an alternative, and if we cannot, you may terminate the affected part of the Service and receive a pro-rata refund of anything paid for it in advance.

We impose data-protection obligations on every Subprocessor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.

08Data subject rights

The Service is built so that most of this needs nothing from us. Access, correction, export and deletion are self-service — an administrator can do all four from within the workspace, which is faster than any request process we could operate.

Where a data subject contacts us directly about data in your workspaces, we will not respond to the substance ourselves; we will tell them to contact you, and pass the request on where we can identify you as the controller. Where you need help we cannot provide through the product, we will give reasonable assistance, taking into account the nature of the processing.

09Breaches & assessments

Personal Data Breach. We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and in any event within 72 hours. The notice will describe, so far as we know it at the time: the nature of the breach and the categories and approximate number of data subjects and records involved; the likely consequences; and the measures taken or proposed. We will supplement it as we learn more, and we will not delay an initial notification in order to send a complete one.

The 72 hours is measured from our awareness, not yours, and it is set there because your own obligation under Article 33 runs to 72 hours from your awareness — a slower processor commitment would consume the whole of your window before you knew there was one.

Assessments. We will give you reasonable assistance with data protection impact assessments and any prior consultation with a Supervisory Authority, to the extent the processing relates to the Service and the information is not otherwise available to you — in practice, the security, compliance and privacy pages answer most of what an assessment asks, and we will complete a questionnaire where they do not.

10International transfers

RowFold is operated from the United States and all Customer Personal Data is stored there. There is no EU or UK data residency option. Using the Service therefore involves a transfer out of the EEA and the UK.

Where Data Protection Law requires a transfer mechanism, the SCCs are incorporated into this DPA and apply as follows: Module Two (controller to processor) where you are a controller, and Module Three (processor to processor) where you are yourself a processor acting for another controller. For transfers subject to the UK GDPR, the SCCs apply as varied by the UK International Data Transfer Addendum. Where the SCCs require a selection, the parties agree: docking clause applies; option 2 general written authorisation for subprocessors, with the notice period in section 07; the governing law and forum are those of Ireland for EU transfers and of England and Wales for UK transfers; and Annexes I, II and III of the SCCs are populated by sections 13, 14 and 15 of this DPA respectively.

If a transfer mechanism is invalidated, we will work with you in good faith to put a valid alternative in place.

11Audits & information

We will make available the information reasonably necessary to demonstrate compliance with Article 28 and allow for and contribute to audits.

In practice that means documentation and questions rather than a report, because there is no audit report to hand you — see section 06. Send a security questionnaire to security@rowfold.com and we will complete it; the answers will be self-attested and will say "no" where the answer is no.

Where that is genuinely insufficient for your regulator, you may audit us on 30 days' written notice, no more than once in any 12 months (unless required more often by a Supervisory Authority or following a Personal Data Breach), during business hours, without unreasonable disruption, subject to confidentiality, and at your own cost.

12Return & deletion

At any time during your subscription you can export Your Content yourself; you do not need to ask.

On termination we will, at your election, return or delete Customer Personal Data. Deletion follows the timelines published in the Privacy Policy: content is removed from active systems within 30 days of account deletion and from backups within 90 days. Certain records — billing and security logs — are retained for up to seven years where law requires it, and this DPA continues to apply to them for as long as we hold them.

13Annex I — the processing

Subject matterProvision of the RowFold workspace platform under the Terms of Service.
DurationThe term of your subscription, plus the retention periods in section 12.
Nature & purposeHosting, storage, structuring, retrieval, display, transmission, backup and deletion of the content you put into your workspaces, together with the features you choose to use on it — views, reports, dashboards, automations, forms, booking pages, email and SMS sending, the public API, and optional AI assistance.
Categories of data subjectDetermined by you. Typically your customers, prospects, employees, contractors, suppliers, patients or members — whoever you keep records about.
Types of personal dataDetermined by you, since you define the fields. Typically identifiers and contact details, employment or customer-relationship information, transaction and scheduling records, correspondence, and uploaded files.
Special category dataNot expected, and not to be stored without an appropriate agreement in place. Health data requires an executed BAA. Do not store payment card numbers or government data of any classification — see the compliance page.
FrequencyContinuous, for as long as the Service is in use.

14Annex II — security measures

The measures below are implemented today. The security page describes each in more detail and is incorporated here by reference; where it and this annex differ, this annex is the contractual commitment.

EncryptionTLS in transit, with HTTP redirected to HTTPS and HSTS in production. Encryption at rest for both the database (Azure Database for PostgreSQL) and file storage (Azure Blob Storage).
Access controlThree levels, each able to override the one above: workspace role, per-table access, and per-field access. A hidden field stays hidden on every path out of the database — through relations, reports, search, export and AI answers alike.
AuthenticationPasswordless sign-in links (256-bit tokens, stored hashed, 30-minute expiry, single use); optional two-factor authentication (TOTP, RFC 6238) which a workspace owner can require of everyone; Google and Microsoft single sign-on on the provider's verified subject identifier. Where passwords exist they are stored with PBKDF2-HMAC-SHA256, 100,000 iterations and a unique salt.
Secrets at restTwo-factor seeds and third-party OAuth tokens are encrypted in the database rather than merely stored in it.
Session securityHttpOnly, SameSite-restricted, secure cookies; sign-out-everywhere; email alerts on new-device sign-in and on security-setting changes.
Resilience to attackPer-endpoint rate limiting, per-account lockout after repeated failures, server-side antiforgery validation on state-changing requests, and browser hardening headers including a content-security policy.
File handlingUploads are never written to a publicly served directory and are readable only through an endpoint that checks permission on the owning record first. A file's URL is not a capability.
RecoverabilityRecords are soft-deleted to Trash rather than destroyed; changes are captured as events giving an audit trail of what changed and when; backups are maintained with the expiry window in section 12.
SegregationCustomer data is separated by workspace, and every query is scoped by membership; permissions are resolved once, server-side, and every surface reads that same resolved view.
PersonnelContractual confidentiality obligations and role-limited access, as in section 05.

15Annex III — subprocessors

The authoritative list — each Subprocessor, what it does, and what data it touches — is maintained on the compliance page and forms Annex III of this DPA and of the SCCs.

It is a link rather than a copy on purpose. A second list here would be a second thing to keep current, and the failure mode is not that it looks untidy — it is that a customer relies on whichever copy they happened to read. One list, in one place, updated before a new category is added.

16General

Liability under this DPA is subject to the limitations and exclusions in the Terms of Service. Precedence: for the processing of Customer Personal Data, this DPA controls over any conflicting term of the Terms; where the SCCs apply and conflict with this DPA, the SCCs control. Changes: we may update this DPA where required by law or to reflect a change in the Service, provided the change does not reduce the protection afforded to Customer Personal Data; material changes are communicated as set out in the Terms. Severability: if a provision is held invalid, the rest continues in force. Governing law follows the Terms of Service, except where section 10 specifies otherwise for transfers.

Questions about this DPA, or to request a countersigned copy: privacy@rowfold.com. Postal: RowFold LLC, 650 S Pearl St, Columbus, OH 43206.

Related: Privacy Policy · Compliance · Security · BAA · Terms of Service