Data Processing Agreement
Last updated October 10, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the customer (“Controller”) and North Foundry, operator of WebflowX (“Processor”). It applies when we process personal data in a customer’s workspace on their behalf. To have a countersigned copy for your records, email hello@northfoundry.co with your company name and signatory.
1. Scope and roles
The customer decides what personal data goes into its workspace and is the controller. We are the processor and process that data only to provide the Service, on the customer’s documented instructions, which are the Terms, this DPA and the customer’s use of the product’s settings. For account and billing data about the customer’s own staff, we act as a controller under the Privacy Policy.
2. Details of processing
- Subject matter and duration: providing the Service for as long as the workspace exists, plus the deletion periods in section 8.
- Nature and purpose: storing, transmitting and displaying messages, files, tasks, notes, documents and meeting records; real-time collaboration; notifications; AI summaries and writing help when a user requests them.
- Data subjects: the customer’s members, guests and anyone they communicate with in the workspace.
- Types of data: names, email addresses, profile details, content that users enter, and meeting audio and transcripts. The customer must not put special categories of data into the Service unless it has a lawful basis and accepts the risk.
3. Our obligations
- Process personal data only on the customer’s instructions, and tell the customer if an instruction appears to break data protection law.
- Keep people who can access the data under a duty of confidentiality.
- Apply the measures in section 5.
- Help the customer respond to access, correction, deletion and export requests. Owners and admins can export workspace data in the product, and we assist where the product cannot.
- Help the customer with impact assessments and regulator inquiries, taking into account the information available to us.
4. Subprocessors
The customer authorises the providers on the subprocessor list. We bind each of them to data protection terms no less protective than this DPA and remain responsible for their performance. We add a subprocessor to the list before it handles customer data. A customer may object on reasonable data protection grounds within 30 days of notice; if we cannot resolve the objection, the customer may terminate the affected plan and receive a refund of prepaid fees for the remaining period.
5. Security
We maintain the measures described on the Security page, including server-side permission checks, encryption in transit, two-step verification, rate limiting, an audit log and secrets held outside the code. We do not hold a SOC 2 or ISO 27001 certification; see Trust. We may update measures if the overall level of protection is not reduced.
6. Personal data breaches
We notify the customer without undue delay after confirming a breach affecting its personal data, and in any case within 72 hours of confirmation, with the information we have about what happened, what data is affected and what we are doing about it.
7. International transfers
Workspace data is stored in the United States and some subprocessors process data in other countries. Where the law requires a transfer mechanism, the parties rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where relevant), which are incorporated into this DPA by reference on request with a countersigned copy. We do not offer a choice of region today.
8. Return and deletion
The customer can export its data at any time. When a workspace is deleted its content is removed. Copies in backups and logs expire on the providers’ regular schedules. Where the law requires us to keep data, we keep only that data and protect it under this DPA.
9. Audits
On written request, no more than once a year unless there has been a breach, we answer a reasonable security questionnaire and provide the documentation we have. Because we hold no independent audit report, on-site audits are agreed case by case, at the customer’s cost, during business hours and without access to other customers’ data.
10. Liability and order of precedence
Liability under this DPA is subject to the limits in the Terms. If this DPA conflicts with the Terms on the processing of personal data, this DPA prevails.