Data processing agreement
Last updated: 16 Aug 2026
Parties and status
This agreement is between the customer organisation that holds a FloraPass account (the controller) and the company identified on the legal notice page (the processor). It applies whenever the processor processes personal data on the controller's behalf, and it forms part of the Terms of service.
Accepting the Terms of service accepts this agreement, so no signature is needed for it to take effect. A controller whose own procurement process requires a countersigned copy — or an equivalent document on its own paper — can request one from support@florapass.eu.
The processor is a separate and independent controller for account, security and service-administration data, as set out in the Privacy notice. This agreement does not cover that processing.
Subject matter, duration, nature and purpose
Subject matter and purpose. Providing the FloraPass service: creating, issuing, printing, verifying, voiding and retaining EU plant-passport records and the operator, supplier and recipient information attached to them. The aggregate, anonymous scan statistics FloraPass shows the controller about its own passports contain no personal data; the underlying verification-page visit data is processed by FloraPass as a controller in its own right, as described in the privacy notice, and is therefore outside the processing this agreement governs.
Nature of the processing. Collection, storage, structuring, retrieval, rendering to labels and documents, transmission to the people the controller shares a passport with, and erasure — all by automated means.
Duration. For as long as the controller holds a FloraPass account, plus the retention period in “Deletion and return” below.
Categories of data subject. The controller's own users and staff; contact persons at the controller's suppliers; and contact persons at the recipients of the controller's consignments.
Types of personal data. Names, business contact details and business addresses; user account identifiers and authentication state; operator registration codes; and any personal data the controller chooses to enter into free-text traceability fields. The controller must not enter special categories of personal data under Art. 9 GDPR, and the service is not designed to hold them.
Processing on documented instructions
The processor processes personal data only on the controller's documented instructions, including as to transfers to a third country. The controller's use of the service, together with the Terms of service and this agreement, constitutes those instructions. If the processor is required by Union or Member State law to process on another basis, it will inform the controller before processing unless that law prohibits it. The processor will inform the controller if, in its opinion, an instruction infringes data-protection law.
Confidentiality
The processor ensures that every person authorised to process the controller's personal data is bound by an obligation of confidentiality, and grants access only to those who need it to operate, secure or support the service.
Security of processing
The processor implements appropriate technical and organisational measures under Art. 32, including: separation of each customer's records so one tenant cannot read another's; encryption of data in transit; storage of passwords and API-key secrets in non-reversible form only; access limited to named administrators using multi-factor authentication; encrypted off-site backups; an append-only audit log of privileged administrative actions; and logging and monitoring of the production environment. The measures are reviewed as the service changes, and may be improved provided the level of protection is not reduced.
Sub-processors
The controller gives general written authorisation for the processor to engage sub-processors. The current sub-processors, what each one does and where it is located are published on the sub-processor page, which forms part of this agreement.
The processor will give at least 30 days' notice by email to the account address before a new or replacement sub-processor begins processing, and the controller may object on reasonable data-protection grounds within that period; the objection procedure and its termination-and-refund remedy are set out on that page. The processor imposes on each sub-processor data-protection obligations no less protective than those in this agreement, and remains fully liable to the controller for the sub-processor's performance.
International transfers
The application, database, backups and operational logs remain in the European Union. Where a sub-processor is established outside the EU or EEA — currently email delivery, and payment processing by onward transfer — the transfer is made under the European Commission's standard contractual clauses, together with the technical measures described above. Each such transfer and its safeguard is identified on the sub-processor page.
Assisting with data-subject rights
Taking into account the nature of the processing, the processor assists the controller by appropriate technical and organisational measures in responding to requests to exercise rights under Chapter III GDPR — access, rectification, erasure, restriction, portability and objection. The service provides the controller with direct access to, and the ability to correct or remove, the records in its own tenant, subject to the immutability of issued passports described in the Terms of service. If a data subject contacts the processor directly about data in a controller's tenant, the processor will not respond substantively and will refer the request to the controller without undue delay.
Breach notification and other assistance
The processor notifies the controller without undue delay after becoming aware of a personal data breach affecting the controller's data, with the information reasonably available to it and further information as it emerges. Taking into account the nature of the processing and the information available to it, the processor also assists the controller in complying with Arts. 32 to 36 — security, breach notification to the supervisory authority and to data subjects, data protection impact assessments and prior consultation.
Deletion and return
On termination of the account the processor deletes or returns the controller's personal data at the controller's choice, and deletes existing copies, except where Union or Member State law requires continued storage. That exception is not theoretical here: plant-passport traceability records must be retained under the applicable plant-health rules for at least three years, so issued and voided passport records and the traceability data attached to them are retained for that period and then deleted. During that period they are kept for that legal purpose only and are not otherwise processed.
An authenticated user can submit a password-verified erasure request from Account settings at any time; completion anonymises sign-in, profile, tenant and operator identity and revokes active credentials, within the same retention exception.
Information and audits
The processor makes available to the controller the information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, conducted by the controller or an auditor it mandates. In the first instance the processor will answer a reasonable written information request. An on-site audit may be requested no more than once in any twelve-month period, on at least 30 days' written notice, during business hours, without unreasonable disruption to the service, subject to confidentiality, and at the controller's cost unless the audit reveals material non-compliance.
Liability and order of precedence
Liability under this agreement is subject to the limitations in the Terms of service, except where those limitations cannot lawfully be applied to data-protection obligations. If this agreement conflicts with the Terms of service on the processing of personal data, this agreement controls; where the standard contractual clauses apply to a transfer, those clauses control over both.