Last updated: 2026-05-26

Data Processing Addendum

This page describes how Flicker thinks about its role when processing personal data on behalf of customers, and how to request a signed Data Processing Addendum ("DPA").

Requesting a signed DPA

If you require a signed Data Processing Addendum covering EU/UK Standard Contractual Clauses, contact legal@flickercloud.com. A counsel-reviewed DPA will be provided on request before any data subject to EU/UK GDPR is loaded.

Flicker will execute a customer-specific DPA on request before processing personal data subject to EU/UK GDPR. During the closed beta, we do not maintain a standing DPA template; new requests are handled case by case.

Roles

Where Flicker processes personal data on behalf of a customer, the customer is the Controller and Flicker is the Processor. Flicker treats the contents of customer databases as customer content processed under the customer's instructions; we do not inspect or determine the purposes of that data.

Subprocessors

We maintain a current subprocessor list at /security. New subprocessors will be added to that list before processing customer data; if you object, contact us within 14 days of the update to discuss.

Personal data breach

We will notify affected customers without undue delay after becoming aware of a confirmed personal data breach, and in any event consistent with applicable law.

Deletion

See the Security FAQ for current data deletion practices.

Contact

DPA inquiries: legal@flickercloud.com.