FlowCrypt Data Processing Agreement (Free License)
Last updated: July 21, 2026
This Data Processing Agreement (“DPA”) supplements the FlowCrypt Terms of Use and FlowCrypt Free License. It applies when FlowCrypt a.s. (“FlowCrypt”, “we”) processes Customer Personal Data on behalf of a user or organization using FlowCrypt Email Encryption under the FlowCrypt Free License (“Customer”, “you”).
By using FlowCrypt Email Encryption under the Free License, you agree to this DPA where it applies. No separate signature is required.
1. Roles and scope
Roles. You act as Controller and FlowCrypt acts as Processor, service provider, contractor, or an equivalent role. “Customer Personal Data” means Personal Data that FlowCrypt processes on your behalf in connection with FlowCrypt Email Encryption. “Applicable Data Protection Laws” means all privacy and data protection laws applicable to that processing in any relevant jurisdiction. Other data-protection terms have the meanings given under those laws.
Processing details. Most encryption and decryption occurs locally on your device and falls outside this DPA where no Personal Data is transmitted to FlowCrypt. When you use FlowCrypt servers, FlowCrypt may process names, email addresses, public keys, IP addresses, security logs and diagnostic information and, when the password-protected messages feature is used, encrypted message payloads and basic operational metadata. Data subjects may include FlowCrypt users, persons identified in public keys, support contacts, and senders or recipients associated with password-protected messages.
Purpose and duration. FlowCrypt processes Customer Personal Data only to provide, maintain, troubleshoot, support and secure FlowCrypt Email Encryption; publish and retrieve public keys; deliver encrypted messages; prevent abuse and security incidents; and comply with law. Processing continues while you use the service and for any limited additional period required by law or FlowCrypt’s standard retention, backup and security practices.
FlowCrypt will not sell or share Customer Personal Data, or retain, use, disclose, or combine it for purposes outside those described in this DPA or outside its direct relationship with Customer, except as permitted by Applicable Data Protection Laws. FlowCrypt will provide the level of privacy protection required by those laws and notify Customer if it can no longer meet its obligations. Where required by law, Customer may take reasonable steps to verify compliance and stop or remediate unauthorized use.
2. Responsibilities
Customer responsibilities. You are responsible for having a lawful basis to process Customer Personal Data, providing all required privacy notices, responding to Data Subject requests where you act as Controller, and using FlowCrypt Email Encryption in compliance with Applicable Data Protection Laws.
FlowCrypt responsibilities. FlowCrypt will:
- process Customer Personal Data only on your documented instructions, including this DPA, the FlowCrypt Terms of Use, the FlowCrypt Free License, and your use of the service;
- ensure that persons authorized to process Customer Personal Data are subject to confidentiality obligations;
- maintain appropriate technical and organizational security measures;
- notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data; and
- provide reasonable assistance with Data Subject requests, security and breach obligations, data protection impact assessments, and consultations with supervisory authorities where required by Applicable Data Protection Laws.
If applicable law requires FlowCrypt to process Customer Personal Data other than on your instructions, FlowCrypt will notify you before processing unless legally prohibited. FlowCrypt will also inform you if, in its opinion, an instruction infringes Applicable Data Protection Laws.
For Free License users, compliance assistance may be provided through standard product features, public documentation and standard email support.
3. Security and Subprocessors
Security. FlowCrypt maintains appropriate technical and organizational measures designed to protect Customer Personal Data, including, where appropriate, encryption, access controls, logging, secure development practices, and incident-response procedures.
Subprocessors. You generally authorize FlowCrypt to engage third-party Subprocessors. FlowCrypt’s current Subprocessor list is available at https://flowcrypt.com/subprocessors
FlowCrypt will post intended additions or replacements on that page before the relevant Subprocessor begins processing Customer Personal Data and, where required by Applicable Data Protection Laws, allow you to object on reasonable data-protection grounds. If FlowCrypt cannot reasonably resolve an objection, you may stop using the affected service.
FlowCrypt will require each Subprocessor to protect Customer Personal Data through appropriate written data-protection obligations. FlowCrypt remains responsible for its Subprocessors’ performance to the extent required by Applicable Data Protection Laws.
4. International transfers and retention
International transfers. FlowCrypt and its Subprocessors may process Customer Personal Data in countries where they operate. Where Applicable Data Protection Laws require an international-transfer mechanism, FlowCrypt will use an appropriate mechanism, such as an adequacy decision, approved standard contractual clauses or another lawful transfer mechanism.
Retention and deletion. Password-protected messages expire and are deleted according to the applicable period described in the FlowCrypt Privacy Policy.
When your use of FlowCrypt Email Encryption ends, FlowCrypt will delete Customer Personal Data or, where available, allow you to retrieve it through standard product functionality before deletion, unless applicable law requires continued retention.
5. Audits and general terms
Audits. FlowCrypt will provide information reasonably necessary to demonstrate compliance with this DPA, normally through standard documentation and reasonable written responses. Custom compliance reviews, negotiated terms, and on-site audits are not included under the Free License unless required by Applicable Data Protection Laws or separately agreed in writing.
Precedence and liability. This DPA forms part of the FlowCrypt Terms of Use and FlowCrypt Free License. If there is a conflict regarding the processing of Customer Personal Data, this DPA prevails.
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the FlowCrypt Terms of Use and FlowCrypt Free License, unless prohibited by applicable law.
This DPA is governed by the governing law specified in the FlowCrypt Terms of Use, unless Applicable Data Protection Laws require otherwise.
Contact. Questions and notices regarding this DPA may be sent to dpo@flowcrypt.com