Data Processing Addendum
Processor: ADISH ESO LTD (Registration No. HE 437996), Agias Paraskevis 101, Bell View House 7, Germasogeia 4044, Limassol, Cyprus Controller: the business customer using LeadFlow Pro Contact: support@leadflowproapp.com Last updated: August 6, 2026
1. Scope
This Addendum forms part of the Terms of Service and applies where ADISH ESO LTD processes personal data on behalf of the customer ("Customer Data"). Where ADISH ESO LTD acts as a controller — account, subscription, support, security and marketing of LeadFlow Pro — the Privacy Policy applies instead.
2. Roles
- The customer is the controller of Customer Data: its clients, employees, technicians, jobs, messages and files.
- ADISH ESO LTD is the processor and processes Customer Data only on the customer's documented instructions, which include the customer's use of the service's features.
3. Duration
Processing lasts for the term of the subscription plus the deletion window described in section 8.
4. Nature and purpose
Hosting, storage, transmission, display, backup, mapping and routing, message delivery, payment facilitation, AI processing of submitted content, notification delivery, support and security.
5. Categories of data subjects
The customer's end customers and prospects; the customer's owners, employees, technicians and other team members; callers and message senders.
6. Types of personal data
Identity and contact details; service and billing addresses; geolocation of tracked owners and technicians; job, quote, invoice and payment records; notes and free-text content; photos, PDFs and attachments; SMS and MMS content and media; call audio, recordings and transcripts; device identifiers, push tokens, IP addresses and usage events.
7. Processor obligations
ADISH ESO LTD will:
- process Customer Data only on documented instructions;
- ensure personnel with access are bound by confidentiality;
- implement appropriate technical and organisational measures, including encryption in transit and at rest, row-level access isolation, private storage with short-lived signed links, and multi-factor authentication for administrative access;
- assist the controller with data-subject requests and impact assessments, taking into account the nature of the processing;
- notify the controller without undue delay after becoming aware of a personal data breach affecting Customer Data;
- make available information reasonably necessary to demonstrate compliance with this Addendum.
8. Deletion and return
On termination, or on the customer's account-deletion request, Customer Data is removed from active production systems within 30 days. Copies held by providers expire according to their own cycles and policies. Limited records may be retained where law requires.
9. Subprocessors
The customer grants general authorisation for the subprocessors listed in our Subprocessor List. ADISH ESO LTD imposes data-protection obligations on each subprocessor and remains responsible for their performance. Material changes are announced with reasonable prior notice.
10. International transfers
Where personal data is transferred outside the EEA or the UK, we rely on the transfer mechanism provided in the relevant provider's data processing terms.
11. Audits
The customer may request reasonable information about our compliance no more than once per year, subject to confidentiality. On-site audits are limited to cases where they are legally mandated, and are at the customer's cost.
12. Customer obligations
The customer warrants that it has a lawful basis and all required notices and consents for the data it enters, including workforce location tracking, call recording and marketing communications.
13. Liability
Liability under this Addendum is subject to the limitations set out in the Terms of Service.