Terms of Use (Global)
Looking for Terms of Use (North America)? Click here
Version August, 2026
These Terms of Use (the “Terms”) together with the order form and other documents referenced herein, constitute the legally binding agreement (the “Agreement”) between (1) Oneflow AB, a Swedish public limited company (publ.) with registration number 556903-2989 with its registered office in Stockholm, Sweden (“Oneflow”); and (2) you, the business customer whose details are specified in connection with entering into the Agreement with Oneflow (“Customer” or “You“/”Your”), (together referred to as the “Parties” and individually as a “Party”).
The Agreement governs Customer’s access to and use of the Oneflow platform (the “Service“), whether or not an order form has been executed. Where an order form has been executed, the order form forms part of and is incorporated into the Agreement.
By executing an order form with Oneflow referencing these Terms, or when the Service is otherwise first signed up for on behalf of the Customer by any individual acting for the Customer, such individual represents and warrants that the Customer agrees to be bound by the Agreement. The individual accepting the Terms represents that it has the authority to act on Customer’s behalf.
- STRUCTURE OF THE AGREEMENT
1.1 Agreement components: The Agreement consists of, as applicable, (i) an order form and all documents referenced therein; (ii) these Terms; (iii) the Service Level Agreement (“SLA”), as available here; (iv) the Data Processing Agreement; and (v) applicable Service descriptions (as available at https://oneflow.com).
1.2 Order of precedence: In case of any inconsistencies, the documents shall take precedence in the order presented above. However, the Data Processing Agreement (where applicable) takes precedence over any other document concerning Personal Data or its processing as defined in the GDPR.
1.3 Definition of Service: The Service consists of the web-based applications, the application program interface (API), any documentation, object code, modifications, or fixes thereto, as well as any executable version of computerized software system provided by Oneflow in relation to this Agreement.
1.4 Accuracy: You agree to provide accurate and complete information to Oneflow and to promptly notify Oneflow of any changes including ensuring that the Customer has registered and maintains valid and monitored contact information in the designated contact fields provided within Oneflow’s platform.
1.5 Other purchase terms: Your standard purchase related documentation or procurement terms that have not been expressly listed in the Agreement and agreed in writing between the Parties do not apply. - YOUR USE OF THE SERVICE
2.1 You are responsible for:
(a) Maintaining equipment, software, and communication services required to use the Service.
(b) Maintaining the security of Your IT environment.
(c) All actions via Your user account(s), whether authorized by You or not except to the extent caused by Oneflow’s breach of this Agreement.
(d) Making sure to keep all login credentials such as usernames and passwords secure and immediately notify Oneflow of any suspected or confirmed unauthorized use.
2.2 Each purchased seat constitutes a license for use by one named individual user only. The Customer is responsible for assigning each seat to a specific, identifiable individual with unique login credentials.
2.3 You are not allowed to share seats or login credentials between multiple individuals and you must ensure that the total number of individual users never exceeds the maximum number of purchased seats from Oneflow.
2.4 You may reassign a purchased seat to a different individual within the scope of seats covered by Your order form. - USAGE RESTRICTIONS
3.1 You may not (i) sell, resell, or lease the Service to any third party; (ii) reverse engineer, decompile or create derivative works of the Service, or attempt or assist anyone else to do so, unless and to the extent that such actions are strictly necessary to achieve interoperability with another independently created computer program, as permitted by mandatory provisions of applicable law (iii) access or attempt to access Service unless lawfully authorized to do so, (iv) use the Service to transmit or store any malicious code, (v) access the Services to create a competitive product or for purposes of monitoring availability, performance or functionality, or for any other benchmarking or competitive purposes without Oneflow’s prior written consent (vi) interfere with the integrity or performance of the Services, (vii) remove or alter any proprietary materials or trademarks from the Services, or (viii) use the Service to transmit any defamatory, unlawful, fraudulent or obscene materials or otherwise use the Service in a way that threatens to harm the Service.
3.2 You warrant that You will promptly take measures to prevent and stop any unauthorized activity aimed at extracting or copying data from the Service if Oneflow reasonably determines that such activity affects the use, profitability, or effectiveness of the Service. - THIRD-PARTY APPLICATIONS
4.1 “Third-Party Applications” means online, web-based applications, and offline software products or services that are (a) provided by third parties, (b) interoperate with Oneflow, and (c) may be either separate or conjoined with Oneflow whether or not such are indicated by Oneflow as being Third-Party Applications. For the avoidance of doubt, available integrations in Oneflow which are managed by You and require a separate agreement between You and the integration provider are not considered Third Party Applications. If a Third-Party Application is a sub-processor, what’s stated in the Data Processing about sub-processors applies.
4.2 Oneflow may provide tools through the Service that enable You to export information, including User Data, to Third Party Applications, including through features that allow You to link Your account in Oneflow with an account in the Third-Party Applications. By using one of these tools, You agree that Oneflow may transfer that information to the applicable Third-Party Application. Third-Party Applications are not under Oneflow’s control, and, to the fullest extent permitted by law, Oneflow is not responsible for any Third-Party Application’s use of Your exported information. The Service may also contain links to third-party websites. Linked websites are not under Oneflow’s control, and Oneflow is not responsible for their content. - PRICES AND PAYMENT
5.1 Oneflow agrees to provide the Service and You agree to pay for the Service as applicable. Your payment obligations will enter into force on the date stated in the order form. Unless otherwise expressly agreed in the order form, all fees for the Service are invoiced and payable annually in advance. You agree to pay by the means of payment offered by Oneflow and in the currency stated on the invoice. Fees are non-refundable and non-cancellable except as required by law.
5.2 If You pay by invoice, payment is due thirty (30) days from the invoice date. By paying for the Service by card, You authorize Oneflow to automatically charge the Service fee on the final day of Your current payment cycle, together the Last Day of Payment, unless agreed otherwise. If You do not have sufficient available funds on Your card to cover the transaction on the Last Day of Payment, we will make another attempt to charge the fee on the card a few days later. If You still do not have sufficient funds on Your card Oneflow reserves the right to send You an invoice of the total sum owed to Oneflow.
5.3 To ensure a balance between the fees and the Service, Oneflow may adjust its fees for the Service annually upon renewal with approx. thirty (30) days’ prior notice. Adjustments shall not exceed the greater of (i) five percent (5%) or (ii) the change in the Swedish CPI.
5.4 All prices are exclusive of applicable VAT. You are responsible for all VAT and related liability. We will only charge VAT when required to do so. If You are required by law to withhold any taxes, You must provide us with an official tax receipt or any other appropriate documentation to ensure that we can handle the VAT correctly.
5.5. If payment is late or incomplete, Oneflow is entitled to charge interest on overdue payment in accordance with the Swedish Interest Act (SFS: 1975:635) or a debt collection fee according to applicable laws. In addition to any other available remedies under the Agreement, if full payment is not received within ten (10) days from the Last Day of Payment, Oneflow may suspend the Service or terminate the Agreement with immediate effect. - USER DATA
6.1 You hold all rights, including intellectual property rights, to Your Data. “Your Data” means all content, Personal Data, and other data or information processed and/or submitted directly or indirectly by You or on Your behalf (with or without Your permission) in relation to Your use of the Service.
6.2 You grant Oneflow a worldwide, transferable, non-exclusive, royalty-free, revocable license to use Your Data (excluding any Personal Data as defined in and covered by the Data Processing Agreement) for the limited purposes of i) operating, protecting, developing, customizing, and improving the Service for You, ii) creating anonymised and aggregated data insights that cannot be reverse-engineered to identify You or any individual for the purpose of improving the core functionality of the Service and creating new services.
6.3 The license You give us allows us to store, reproduce, use and display to You, modify and create derivative works of and permit our service providers to process Your Data solely to provide our Service, to prevent or address service or technical problems or at Your request in connection with customer support matters.
6.4. You also grant Oneflow a royalty-free, worldwide, transferable, sub-licensable, irrevocable, and perpetual license to use and/or incorporate into the Service or any other product of Oneflow, any suggestions, enhancement requests, recommendations, or other feedback provided by You relating to the operation of Oneflow. The license includes the right to modify and further develop any of the aforesaid. Any sub-licensee shall have the corresponding rights, as decided by Oneflow. - INTELLECTUAL PROPERTY RIGHTS
7.1 Subject to Your complete and ongoing compliance with these Terms Oneflow grants You a limited, non-exclusive, non-transferable, non-sublicensable, revocable license to access and use the Service. Oneflow or its third-party licensors hold all rights, including all current and future intellectual property rights, related to the Service and any therein included visual interfaces, graphics, design, compilation, information, data, computer code (including source code or object code), products, software, services, promotional content, patents, copyrights, trade secrets, design rights, moral rights, trademarks and all other elements of the Service provided by Oneflow. Oneflow reserves all rights to the materials not granted expressly in these Terms.
7.2 Nothing in this Agreement shall be interpreted as a transfer of any Party’s rights, or part thereof, to the other Party unless specifically agreed. Should the Service in any way require Oneflow’s use of intellectual property rights held by You or Your licensor(s), Oneflow is granted a non-exclusive license by You to utilize such intellectual property rights for the said purpose for as long as the Service is provided to You.
7.3 You are encouraged to publicly state that You use the Service. However, neither of the Parties may remove, change, or in any other way misuse the trademark of the other Party in any way.
7.4 We are proud of our customers and by signing this Agreement, You give us the right to use Your name or logo in sales and marketing materials. If You do not want us to use Your name or logo, please send an e-mail to customersuccess@oneflow.com and we will make sure not to use Your name or logo. - CONFIDENTIAL INFORMATION
8.1 “Confidential Information” means all confidential and proprietary information of a party, whether orally or in writing, that is designated as confidential or that reasonably should be understood to be confidential given the nature of the information and the circumstances of disclosure, including the Terms of this Agreement, the Services, documentation, business and marketing plans, technology and technical information, product designs, and certification and business processes. Confidential Information shall not include any information that is or becomes generally known to the public without breach of any obligation owed to the other Party; (ii) was publicly known prior to its disclosure without breach of any confidential obligation; (iii) was independently developed by the other Party without breach of any confidentiality obligation; or (iv) is received from a third party without breach of any confidentiality obligation.
8.2 No Party shall disclose any Confidential Information for any purpose outside the scope of this Agreement, except with the other Party’s prior written consent. The Receiving Party shall protect the confidentiality of the Confidential Information in the same manner that it protects the confidentiality of its own confidential information of like kind (but in no event using less than reasonable care). Parties shall promptly notify the other Party if it becomes aware of any actual or reasonably suspected breach of Confidential Information.
8.3 If a Party is compelled by law, court order, regulatory, judicial, governmental or similar body, taxation authority or stock market regulations to disclose Confidential Information, it shall provide the other Party with prior notice of such disclosure (to the extent reasonable and legally permitted) and reasonable assistance, at the other Party’s cost, if the other party wishes to contest the disclosure.
8.4 Upon any termination of this Agreement, the Parties shall continue to maintain the confidentiality of the Confidential Information as long as it remains confidential and, upon request, return to the Disclosing Party or destroy all materials containing such Confidential Information. - CHANGES
9.1 You may at any time choose to upgrade or downgrade Your Subscription Plan directly through the Service or by contacting Oneflow. A downgrade will come into effect at the time of the next renewal date of Your Subscription Plan provided that Your request is made within the notice period stated in the Order Form. Otherwise, the downgrade will take effect as of the second renewal date from Your request.
9.2 Oneflow reserves the right to make improvements, additions, and changes, or to remove functions of the Service at Oneflow’s own discretion provided that such changes do not materially reduce the overall functionality of the Service such as resulting in a significant degradation of the Service’s core functionality. Where such modification, although unlikely, removes a material function of the Service, You may terminate the Agreement with immediate effect. Oneflow will post information on relevant changes on its website https://oneflow.com.
9.3 Oneflow also reserves the right to make changes, amendments, and updates to these Terms. Such changes, updates, or amendments will have effect thirty (30) days after Oneflow’s notification. You are entitled to terminate the Agreement with immediate effect would said change, in Your reasonable opinion, imply a material change to our Agreement. Disputes arising under these Terms will be resolved in accordance with the version of these Terms that was in effect at the time the dispute arose. This clause does not relate to price updates under clause 5.3. - PERSONAL DATA
10.1 The Parties have agreed that the attached Data Processing Agreement shall be included in the Agreement where the GDPR is applicable for the Processing of Personal Data under the Agreement. In the event You are not subject to GDPR, the Data Processing Agreement shall apply only to the extent legally required. The Data Processing Agreement shall remain effective independently of the Agreement for as long as Oneflow processes Personal Data on behalf of You. - INDEMNIFICATION
11.1 You shall indemnify, release and hold harmless Oneflow and its licensors and suppliers from and against any direct loss or liability cost relating to any claim or demand made by any third party due to or arising out of Your wrongful access or misuse of the Services or Your infringement of any intellectual property or another right of any person or entity.
- LIMITATION OF LIABILITY
12.1 To the fullest extent permitted by law, in no event will the Oneflow entities be liable to You for any indirect, incidental, special, consequential, or punitive damages (including damages for loss of profits, goodwill, or any other intangible loss) arising out of or relating to Your access to or use of, or Your inability to access or use, the service or any materials or content on or available through the Service, whether based on warranty, contract, tort (including negligence), statute, or any other legal theory, and whether or not any Oneflow entity has been informed of the possibility of damage.
12.2 To the fullest extent permitted by law, our aggregated liability under these Terms will not exceed the amount paid by You to us hereunder during the twelve (12) month period immediately preceding the event(s) giving rise to such liability.
12.3 To the fullest extent permitted by law, in no event will You be liable to Oneflow for any indirect, incidental, special, consequential, or punitive damages (including damages for loss of profits, goodwill, or any other intangible loss) arising out of or relating to Your access to or use of, or Your inability to access or use, the Service or any materials or content on or available through the service, whether based on warranty, contract, tort (including negligence), statute, or any other legal theory, and whether or not You have been informed of the possibility of damage.
12.4 To the fullest extent permitted by law, Your aggregated liability under these Terms will not exceed one hundred thousand (100 000) SEK or sums paid to us for the Service during the period of twelve (12) months preceding the claim whichever is lowest.
12.5 You agree that this limitation of liability represents a reasonable allocation of risk and is a fundamental element of the basis of the bargain between Oneflow and You.
12.6 Neither Party is liable for damages unless the other Party notifies the liable Party about it in writing no later than 90 days after the actual damage or loss was noticed or should have been noticed, however no later than six (6) months from when the damage occurred.
12.7 The limitations of liability set forth herein shall not apply in cases of gross negligence or willful misconduct. - THIRD-PARTY INFRINGEMENTS
13.1 Oneflow represents that the Service, to the best of Oneflow’s knowledge, does not infringe any third-Party intellectual property rights or any other rights of a third party. Oneflow shall defend or settle any claim made against You based on Your use of the Service, or part thereof, infringing any such Third Party’s intellectual property rights. Oneflow’s obligations in accordance with this clause are subject to You only having used the Service in accordance with the conditions outlined in the Agreement and shall only apply for such claims by third parties in Your country.
13.2 Oneflow’s liability under this section only applies provided that You, without undue delay, notifies Oneflow in writing of the claims brought against You, allows Oneflow to control the defense and to solely decide in all related settlement negotiations, and acts in accordance with Oneflow’s instructions and cooperates with and assists Oneflow to the extent reasonably requested by Oneflow.
13.3 Subject to the conditions under this section, Oneflow shall be liable for such damages, liabilities, costs, or expenses awarded in a final judgment or settlement which has been approved in writing by Oneflow.
13.4 If it is finally determined that there is an infringement of a Third Party’s intellectual property rights for which Oneflow is liable under these Terms, Oneflow shall at its own discretion procure for You the right to continued use of the Service modify the Service so that it does not infringe replace the Service, or part thereof, with an equivalent Service which does not infringe or cancel the Service and repay the fees that You have paid for the Service without interest and with deduction of any reasonable benefit You might have had from the Service.
13.5 With respect to Third Party Applications, Oneflow’s liability for errors or intellectual property infringements is restricted to an obligation to report the fault/infringement to the relevant third supplier immediately. Oneflow shall implement any potential solution from the third supplier, provided this can be done without material negative interference with the Service.
13.6 This section constitutes the entire obligation of Oneflow towards You with respect to any infringement in a third party’s intellectual property rights. Oneflow shall have no liability to the extent the claim arises from (i) Your Data, (ii) modifications not made by Oneflow, or (iii) combination with third party products not provided by Oneflow.
- PERFORMANCE UNDERTAKINGS
14.1 Use of the Service: Oneflow undertakes to ensure that the Service will perform materially in accordance with the applicable Service functionality, performance standards and purpose agreed between the Parties in the Agreement. Except as agreed in the Agreement, Oneflow disclaims all warranties, whether expressed or implied, relating to the Service and all materials and content available through the Service, including any implied warranty of merchantability and fitness for a particular purpose. This means that Oneflow only warrants that the operation of the site, Service, and software will meet requirements agreed upon between the Parties in this Agreement. Oneflow is only responsible for information expressly stated in writing in the Agreement.
14.2 Use of Test Environments: Oneflow may, at its sole discretion, provide the Customer with access to non-production environments, such as test, beta, pre-release, or “sandbox” versions of the Service (collectively “Test Environments“). Customer acknowledges and agrees that:
(a) Test Environments are provided for evaluation and testing purposes only and are not intended for production use, processing of sensitive data, or any business-critical activities.
(b) Test Environments are provided “AS IS” and “WITH ALL FAULTS”, without any warranties or performance undertakings of any kind, whether express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, reliability, or accuracy.
(c) To the fullest extent permitted by law, Oneflow shall have no liability whatsoever for any damages, losses, costs, or expenses (including but not limited to loss of data, loss of profit, or business interruption) arising out of or in connection with the Customer’s use of, or inability to use, any Test Environment. - FORCE MAJEURE
15.1 Neither Party shall be liable for any failure or delay in the performance of its obligations under the Agreement to the extent such failure or delay is caused by an event or circumstance beyond that Party’s reasonable control such as but not limited to war, natural disaster, internet failures, cyberattacks, utility failures, government actions (a ‘Force Majeure Event’), provided that the affected Party promptly notifies the other Party of the Force Majeure Event.
15.2 The affected Party’s obligations shall be suspended for the duration of the Force Majeure Event and shall be resumed as soon as the Force Majeure Event has ceased. During such period, the affected Party shall not be liable for any damages, penalties, or other additional compensation resulting from the delay or non-performance caused by the Force Majeure Event. - TERM AND TERMINATION
16.1 The Service is provided on a subscription basis by the Subscription Plan or such other trial period or free subscription period applicable for Your use of the Service as stated in Your order form (where applicable) . Unless otherwise specifically agreed in the order form, Your Subscription Plan will automatically renew until terminated by one of the Parties by the Terms of this Agreement.
16.2 Unless otherwise specifically agreed in the order form, either Party may terminate the Subscription Plan by sending an email to the other Party with a notice period of three (3) months for contracts with a duration of a year or longer (termination email to Oneflow must be sent to support@oneflow.com). The termination will have effect from the date when Your Subscription Plan would otherwise have been renewed, subject to such termination being made within the notice period applicable for Your Subscription Plan.
16.3 You shall not be entitled to recover any excess amount paid in advance unless the Agreement is terminated by Oneflow, and the termination was caused by actions outside of Your control.
16.4 Either Party is entitled to terminate the Agreement with immediate effect where the other Party has committed a material breach of the Agreement and does not rectify such breach within 15 days of the other Party giving written notice thereof, where the other party is declared insolvent, is subject of an application or order for bankruptcy or company reorganization, suspends payments or otherwise can be presumed to be insolvent. Either Party also has the right to terminate the Agreement or if the other Party has or is affected by financial sanctions or trade embargoes. - CONSEQUENCES OF TERMINATION
17.1 Unless otherwise agreed between the Parties, Oneflow may, upon the termination of the Subscription Plan, automatically move You to a free subscription of the Service.
17.2 Oneflow lets You retrieve or delete Your Data currently in Oneflow’s possession through the Service in such generally accepted format as provided by Oneflow from time to time. If this Agreement is terminated or otherwise expires for any reason, You shall promptly return to Oneflow or destroy any Confidential Information, or other materials in Your possession belonging to Oneflow and all rights and licenses granted to You by Oneflow under this Agreement shall terminate, where applicable.
17.3 All provisions of this Agreement that by their nature should survive termination shall survive termination, including, without limitation, confidentiality, ownership provisions, warranty disclaimers, indemnity, limitations of liability, and miscellaneous provisions.
- MISCELLANEOUS
18.1 Oneflow is entitled to engage subcontractors for the performance of its obligations under this Agreement. Oneflow is responsible for the subcontractors’ work as for its own work. For the avoidance of doubt, subcontractors acting as sub-processors to Oneflow shall be handled by the Data Processing Agreement.
18.2 The Agreement forms the parties’ entire understanding of all the questions related to the Service. All written or oral representations or warranties prior to the Agreement are replaced by the Agreement.
18.3 The Agreement may not be assigned to a third party without the other Party’s prior written approval unless it is to a company within the same group. Oneflow is however entitled to assign the Agreement to a third party in connection with a transfer of Oneflow’s business or a part thereof.
18.4 Both Parties guarantee that the execution and delivery of, and the performance obligations under this Agreement, will not result in a violation or breach of any applicable law or regulations.
18.5 In the event the Agreement consists of any translated versions of order forms, documents, or any related materials, these Terms and Oneflow´s English versions of such material shall take precedence and be considered the governing version.
- GOVERNING LAW AND DISPUTES
19.1 This Agreement is governed by Swedish law.
19.2 Any dispute, controversy, or claim arising out of or in connection with this Agreement, or the breach, termination, or invalidity thereof, shall be finally settled by arbitration administered by the Arbitration Institute of the Stockholm Chamber of Commerce.
19.3 The Rules for Expedited Arbitrations shall apply, unless the Stockholm Chamber of Commerce in its discretion determines, taking into account the complexity of the case, the amount in dispute, and other circumstances, that the Arbitration Rules shall apply. In the latter case, the Stockholm Chamber of Commerce shall also decide whether the Arbitral Tribunal shall be composed of one or three arbitrators.
19.4 The seat of arbitration shall be Stockholm, Sweden. The language to be used in the arbitral proceedings shall be English.
19.5 All information about the arbitration proceedings and the award thereof shall be considered confidential information about this Agreement and be kept in strict confidence of the Party for an indefinite time.
Data processing Agreement (DPA)
- GENERAL
1.1 Where applicable, this Data Processing Agreement (below “DPA”) is entered into between the Customer (as defined in the Agreement) hereinafter referred to as the “Data Controller” and Oneflow, (in its capacity as the Data Processor), each a “Party” and together the “Parties”.
1.2 The Parties have entered into an Agreement regarding Oneflow’s provision of Services to the Customer under which Oneflow will process personal data on behalf of the Data Controller. The Parties enter into this DPA to ensure that such processing is conducted lawfully, transparently, securely and in compliance with Data Protection Laws. - DEFINITIONS
The terms used in this DPA have the meaning stated below, unless the circumstances clearly require otherwise. Terms used in this DPA not defined herein have the meaning set forth in Data Protection Laws or the Agreement as applicable.
“Agreement” the written agreement entered into between Oneflow and the Data Controller governing the Data Controller’s access to and use of the Oneflow platform (the “Service”).
“Data Protection Laws” refers to all privacy and personal data legislation of a EU Member State or in EU law along with any other obligations directly applicable to data processors under local data protection legislation applicable to the Parties’ activities under this DPA.
“GDPR” means the regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
“Subprocessor” refers to a natural or legal person, public authority, agency or other body which, in the capacity of subcontractor to Oneflow, processes personal data on behalf of the Data Controller. The term Subprocessor has the same meaning as “another processor” referred to under the GDPR.
“Supervisory Authority” means the Swedish Authority for Privacy Protection (IMY) and, where applicable, other competent supervisory authority which, by virtue of law, exercises supervision over the Parties’ activities.
“Third Country(ies)” means any country that is not a member of the European Union (EU) or the European Economic Area (EEA) which has not been deemed to ensure an adequate level of data protection by the European Commission pursuant Articles 44-50 (Chapter V) of the GDPR.
- DATA CONTROLLER OBLIGATIONS
3.1 The Data Controller determines and controls what Personal Data is processed by the Service and agrees to comply with its obligations as a Data Controller under Data Protection Laws. The Data Controller is responsible for assessing Oneflow’s technical and organization measures as appropriate for the types of Personal Data Data Controller wishes to process by its use of the Services and confirms that it has provided notice and obtained all consents (where applicable) and rights necessary for Oneflow to process Personal Data pursuant to this DPA.
3.2 The Data Controller is responsible for registering and maintaining a valid and monitored email address in the designated contact field provided under ‘data management’ within Oneflow’s platform (“Notification Email”). The Notification Email will be used by Oneflow for all notices and communications under the DPA, including, without limitation, notifications regarding Sub-processors, personal data breaches, security incidents, amendments, and any other notices required under Data Protection Laws. The Data Controller is solely responsible for ensuring that the Notification Email remains accurate, current, accessible, and actively monitored at all times.
3.3 Oneflow is deemed to have fulfilled any notification obligation under this DPA upon sending the relevant notice to the Notification Email. The Data Controller acknowledges and agrees that Oneflow has no obligation to verify receipt, use alternative contact methods, or resend notices due to an incorrect, outdated, inaccessible, or unmonitored email address maintained by the Data Controller. Any failure by the Data Controller to receive a notice as a result of not maintaining a valid and monitored Notification Email registered in the Oneflow platform does not affect the validity, effectiveness, or timing of such notice. - ONEFLOW DATA PROCESSOR OBLIGATIONS
4.1 Oneflow will process Personal Data under this DPA only on behalf of and in accordance with the Data Controller’s documented instructions as set out in this DPA including Sub-appendix 1 and the Agreement for the purposes of: (i) providing the Services and performing its obligations under the Agreement; and (ii) complying with applicable laws to the extent required for Oneflow’s processing activities. The Parties acknowledge and agree that this DPA and the Agreement set out the Data Controller’s complete and final documented instructions to Oneflow in relation to Oneflow’s processing of Personal Data on Data Controller’s behalf. Oneflow is not required to comply with any additional or separate instructions unless such instructions are agreed in writing and signed by both Parties as an amendment to this DPA and/or the Agreement.
4.2 If Oneflow is required to process the Personal Data processed under this DPA for purposes related to fulfilling legal obligations under Data Protection Laws to which Oneflow is subject and such purposes can not be regarded as covered by the Data Controller’s instructions, Oneflow undertakes to inform the Data Controller before such processing, unless Oneflow is prohibited to do so under applicable laws or instructions from government authority. - SUB-PROCESSING
5.1 Authorized Sub-processors. The Data Controller agrees that Oneflow may engage Sub-processors to process Personal Data on the Data Controller’s behalf. The Sub-processors currently engaged by Oneflow and authorized by the Data Controller are listed at https://oneflow.com/legal/gdpr. By signing this Agreement the Data Controller accepts the current Sub-processors.
5.2 Sub-processor Obligations. Oneflow undertakes to: (i) enter into a written agreement with the Sub-processor imposing data protection terms that require the Sub-processor to protect the Personal Data to the standard required by Data Protection Laws to at least similar level to this DPA; and (ii) remain responsible for its compliance with the obligations of this DPA and for any acts or omissions of the Sub-processor that cause Oneflow to breach any of its obligations under this DPA.
5.3 Changes to Sub-processors. Oneflow will provide the Data Controller reasonable advance notice if it adds or removes Sub-processors. Oneflow will send an e-mail to the Data Controller’s Notification Email from legal@oneflow.com. Oneflow will also update the information on https://oneflow.com/legal/gdpr.
5.4 Objection to Sub-processors. The Data Controller may object in writing to Oneflow’s appointment of a new Sub-processor on reasonable grounds relating to data protection by notifying Oneflow promptly in writing within fourteen (14) calendar days of posting.
5.5 The Data Controller’s notice in accordance with Section 5.4. Such notice must explain the reasonable grounds for the objection. In such event, the Parties agree to discuss such concerns in good faith with a view to achieving a commercially reasonable resolution. If this is not possible, either Party may terminate the applicable Services that cannot be provided by Oneflow without the use of the objected-to-new Sub-processor.
- SECURITY
6.1 Security Measures. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Oneflow confirms that it has implemented and will maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including Oneflow’s security standards described on https://oneflow.com/security/, always including at least:
(a) pseudonymisation and encryption of personal data;
(b) ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
(c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; and
(d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.
6.2 Confidentiality of Processing. Oneflow undertakes to ensure that any person who is authorized by Oneflow to process Personal Data has committed themselves to an appropriate obligation of confidentiality (whether a contractual or statutory obligation).
6.3 Data Breach Response. Upon becoming aware of a Data Breach Oneflow undertakes to notify the Data Controller without undue delay.
6.4 Updates to Security Measures. The Data Controller acknowledges that the Security Measures are subject to technical progress and development and that Oneflow may update or modify the Security Measures from time to time provided that such updates and modifications do not result in the degradation of the overall security of the Services purchased by the Data Controller. - SECURITY REPORTS AND AUDITS
7.1 Oneflow will maintain records of its security standards including any applicable certifications and/or external reports. Oneflow will provide written responses (on a confidential basis) to all reasonable requests for information made by the Data Controller, including responses to information security and audit questionnaires, that the Data Controller (acting reasonably) considers necessary to confirm Oneflow’s compliance with this DPA, provided that the Data Controller may not exercise this right more than once per year.
7.2 Oneflow will also allow for and contribute to reasonably requested audits, including inspections, conducted by the Data Controller or another auditor mandated by the Data Controller subject to appropriate confidentiality obligations. Any such audit must be limited to information and systems relevant for verifying Oneflow’s compliance with this DPA and must be carried out in a manner that safeguards the confidentiality, integrity, and security of Oneflow’s systems, data of other customers, and Oneflow’s trade secrets and other proprietary information.
7.3 The Data Controller will reimburse Oneflow for its reasonable costs in relation to this clause.
- INTERNATIONAL TRANSFER
8.1 Oneflow may not transfer or authorize the transfer of Personal Data to countries outside the EEA except as permitted under this DPA. For the avoidance of doubt, the Data Controller’s execution of this DPA constitutes its prior written authorization of the Sub-processors identified pursuant to Section 5, including any international transfers of Personal Data undertaken by such Sub-processors in accordance with this DPA and applicable Data Protection Laws. If Personal Data is transferred from the EEA, Switzerland or the United Kingdom to a jurisdiction that does not benefit from an adequacy decision or an adequacy regulation in force under applicable Data Protection Laws, Oneflow will ensure that an appropriate transfer mechanism is implemented and maintained as required under applicable Data Protection Laws, including where applicable the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, the UK International Data Transfer Agreement (IDTA), or any successor transfer mechanism approved by the relevant competent authority. - RETURN OR DELETION OF DATA
9.1 Upon deactivation of the Services, all Personal Data will be handled in accordance with the clause on termination in the Agreement. This includes a choice for the Data Controller to instruct Oneflow to return the Personal Data to the Data Controller or request that Oneflow securely deletes the Personal Data unless Data Protection Laws require continued storage of the Personal Data. - COOPERATION
10.1 Oneflow will, taking into account the nature of the processing, provide reasonable cooperation to assist the Data Controller by appropriate technical and organizational measures, in so far as is possible, to respond to any requests from individuals or applicable data protection authorities relating to the processing of Personal Data under the Agreement.
10.2 If any such request is made directly to Oneflow, Oneflow will re-direct such communication to the Data Controller. If Oneflow is required to respond to such a request, Oneflow will promptly notify the Data Controller and provide it with a copy of the request unless legally prohibited from doing so.
10.3 To the extent Oneflow is required under Data Protection Law, Oneflow will provide reasonable assistance and reasonably requested information regarding Oneflow’s processing of Personal Data under the Agreement to support the Data Controller in complying with its obligations under Articles 32-36 GDPR e.g. assist the Data Controller with information necessary for the Data Controller’s data protection impact assessments or prior consultations with data protection authorities related to its use of the Services where required by applicable law.
10.4 Oneflow is entitled to compensation in accordance with Oneflow’s at any time current price list for work performed in accordance with the obligations under this DPA that goes beyond necessary work performed to fulfil Oneflow’s obligations under Data Protection Laws.
- LIABILITY
11.1 If a Party breaches this DPA or Data Protection Laws, such Party undertakes to indemnify the other Party for any damage caused by the breach. However, this does not apply if the negligent Party can show that it is in no way responsible for the event, act or omission that caused the other Party damage, such as that the claim could not have been avoided by fulfilling the Party’s obligations under this DPA, Data Protection Laws or by the instructions issued by the Data Controller.
11.2 The Parties’ right to compensation regarding claims from any person or data subject cov-ered by Article 82, is regulated in its entirety under Article 82 of the GDPR. This includes the right of the Party who paid full compensation for the damage suffered by a person or data subject to claim back from the other Party, if involved in the same Processing, the part of the compensation corresponding to that Party’s part of responsibility for the damage.
11.3 This section (11) survives the termination of this DPA. - GOVERNING LAW
12.1 This DPA is governed by and construed in accordance with the substantive law of Sweden notwithstanding the rules or principles of conflicts of law. Any dispute regarding interpretation or application of this DPA will be settled in accordance with the provisions on dispute resolution in the Agreement unless required otherwise by Data Protection Laws.
Sub-Appendix 1 – Instructions on processing of personal data
Purposes of the processing under this DPA. | Oneflow provides an end-to-end solution for contract and other document management. Personal data is processed for the purposes of providing, operating, securing, maintaining and improving the Service for the Data Controller, including enabling its users to create, upload, store, organize, review, negotiate, comment on, execute electronically, archive, search, analyze and otherwise manage contracts and related documents throughout their lifecycle. The Data Controller determines the categories of documents, content and personal data uploaded to and processed within the Service. Oneflow processes such personal data solely on behalf of and in accordance with Data Controller’s documented instructions as reflected in the Agreement, this DPA and the Data Controller’s use of the Service. Personal data may also be processed to administer Data Controller’s accounts and subscriptions, provide customer support, ensure information security, prevent fraud and misuse, comply with legal obligations, and maintain the business relationship between Data Controller and Oneflow. Oneflow may generate and use anonymized and aggregated data, statistics, benchmarks, analytics and insights derived from Data Controller’s use of the Service, provided that such data does not identify, and cannot reasonably be used to identify, Data Controller, any data subject or any individual. Such anonymized and aggregated data may be used for the purposes of Oneflow’s service improvement, product development, security monitoring, benchmarking, reporting and business analytics. |
Types of personal data. Oneflow may process the following categories of Personal Data on behalf of the Data Controller: | Account and user information, such as name, email address, telephone number, job title, employer, user credentials and other contact information relating to users of the Service. Information relating to counterparties, representatives, signatories, witnesses, advisors and other individuals identified in contracts, documents or communications processed through the Service. Electronic signatures, authentication data, audit trail information and transaction records generated through the use of the Service. Metadata (where defined as Personal Data) relating to documents and use of the Service, including document identifiers, timestamps, user actions, access logs and workflow information. Any Personal Data contained in contracts, attachments, correspondence, comments, notes or other content uploaded to, created within or otherwise processed through the Service by or on behalf of the Data Controller. |
Categories of data subjects. Personal Data processed by Oneflow on behalf of Data Controller may relate to: | Data Controller’s employees, officers, directors, consultants, contractors and other authorized users of the Service. Counterparties and prospective counterparties to contracts and transactions including representatives, employees, consultants, advisors and agents of such counterparties. Individuals identified, referenced or otherwise included in documents, contracts, attachments, correspondence or other content uploaded to or processed through the Service by Data Controller. |
Duration of the processing. | Oneflow processes Personal Data for the duration of the Agreement and thereafter until deletion or return of the Personal Data in accordance with Data Controller’s instructions, the Agreement and this DPA. The Data Controller controls the retention and deletion of its data in Oneflow through the functionality of the Service. Upon termination or expiration of the Agreement, Oneflow will delete or return Personal Data in accordance with the Agreement and this DPA, unless applicable law requires continued retention. Backup copies and residual data may be retained for a limited period in accordance with Oneflow’s backup, disaster recovery and record retention procedures, after which such data will be securely deleted or anonymized. |
Nature of the processing. | Collection, recording, organization, structuring, storage, hosting, adaptation, retrieval, consultation, use, disclosure by transmission, electronic signing, analysis, search, archiving, deletion and other processing operations necessary to provide the Service in accordance with Data Controller’s instructions as per this DPA and the Agreement. |
AI Functionality Appendix
Last updated January 2025
This AI Functionality Appendix (“AI Appendix”) is a supplement to, and shall be seen as an integral part of, Your Agreement with Oneflow. The additional terms in this AI Appendix apply to the extent Your use of the Services includes an “AI Feature”. By AI Feature(s) we mean an AI enabled feature from Oneflow whether in the Oneflow platform, via an API or otherwise. By using an Oneflow AI Feature You agree to the specific terms relevant for such AI Feature(s), as further described in this AI Appendix. If you do not agree to the terms in this AI Appendix, you must not use any of the AI Feature(s) and ensure that all AI Feature(s) are switched off in Your Oneflow account’s Data Management page. In case of discrepancies between the Terms and this AI Appendix, the AI Appendix takes precedence when it comes to issues related to AI Features.
- When using the Oneflow AI Features You agree, between You and Oneflow, that:
1.1 by “AI” we mean artificial intelligence;
1.2 such parts of Your Data which You provide to the AI Features (“Input”), and output You receive from the AI Features based on Your Input (“Output”) shall, to the extent permitted by law and where it can be reasonably regarded as directly attributable to You, be regarded as Your Data as per the definition in the Agreement;
1.3 You acknowledge and accept that Output generated by the AI Features is not human-generated and can not be assumed as unique for You. Other Oneflow customers and users may receive a similar output from the AI Features. Further You acknowledge and agree that Outputs are not, and shall not be considered to be, legal conclusions, legal advice, opinions or recommendations about your legal rights, remedies, defenses, options, selection of forms, or strategies, or as applying the law to the facts of Your particular situation.;
1.4 Oneflow must not use Your Data to train any AI models. Oneflow may only use Your Data for the purposes, explicitly agreed to in this AI Appendix or otherwise in writing, to comply with applicable laws, and to enforce Oneflow’s rights under the Agreement;
1.5 Oneflow may use feedback from Your usage of the AI Feature(s) (provided by Your users through the app or otherwise) to validate and improve the accuracy of our AI Features;
1.6 to the maximum extent permitted by law, the AI Features and Output is provided to You ‘as is’ without any warranties whether express, implied, statutory or otherwise;
1.7 You understand that AI Features may produce incorrect Output that does not accurately reflect real facts, numbers, circumstances, recommendations or laws (including advice from authorities). You are strongly advised to carry out human review of the Output to identify and correct any errors before using the Output for Your intended purposes;
1.8 You are responsible for ensuring that all use of the Oneflow AI Features by You and any of Your users is legal and in compliance with the Agreement, all applicable laws and regulations as well as any policies (external or internal) applicable for Your use of the AI Features;
1.9 Output must not be used to develop AI models or services that compete with the Oneflow Services;
1.10 You must not (and must ensure Your users do not) include any personal data of children under the age of 13 or the applicable age of digital consent in the Input;
1.11 if Oneflow is made aware that You use the AI Features in violation of the Agreement or in a manner which could pose a security risk to Oneflow or any third party, Oneflow has the right to suspend the Services for You and/or prevent You from using the relevant AI Feature and (if the violation or security risk is material) terminate the Agreement with You with immediate effect. The same rights for Oneflow applies if Oneflow reasonably suspects that You use the AI Features in violation of the Agreement and has contacted You to resolve such suspected violation in good faith but we have failed to resolve the matter with You within seven (7) days from the date You were informed of the suspected violation. Oneflow will reactivate Your access to the AI Feature(s) and Services if You make it probable that You have not used the AI Feature(s) in violation of the Agreement and there is no other reason for Oneflow to terminate the Agreement with You;
1.12 Oneflow may terminate Your access to AI Features immediately by giving notice to You if Oneflow deems that as necessary to comply with the law or government requests. The same right applies for Oneflow if changes in Oneflow’s relationships with third-party LLM suppliers means Oneflow can no longer provide the AI Feature(s) to You; and
1.13 any termination or suspension of AI Features under this AI Appendix does not entitle You to any compensation, claim, reduction, refund, or credit of fees.
- If You are using generative AI functionalities You agree that:
2.1 generative AI is based on third-party LLM supplier(s) technology which means that Your use of generative AI is also subject to the terms and usage policies of such third-party LLM supplier(s). Information on which third-party LLM supplier(s) are used and links to the relevant terms can always be found in Your Oneflow account’s Data Management page. When using generative AI, You acknowledge and agree to, in addition to the Agreement, comply with the applicable terms and policies of the third-party LLM supplier(s);
2.2 Your use of generative AI means You instruct Oneflow to send such parts of Your Data (prompts and highlighted text) used as Input from time to time relevant third-party LLM supplier(s) for processing in accordance with their terms and usage policies;
2.3 Oneflow has the right to analyze such parts of Your Data (prompts and highlighted text) used as Input for the purpose of improving Your use of our Services;
2.4 it is Your sole responsibility to ensure that Your use of generative AI functionalities, including the data used as Input to interact with generative AI, does not violate the Agreement or terms and usage policies of the third-party LLM supplier(s);
2.5 where Your use of generative AI involves processing of personal data as defined in the Regulation (EU) 2016/679 (General Data Protection Regulation / “GDPR”), You are responsible to ensure that such processing is lawful and in accordance with applicable Data Protection Laws;
2.6 any and all of Oneflow’s liability- and indemnification undertakings, confidentiality obligations and agreed service levels under Your Agreement with Oneflow are excluded in relation to Your use of generative AI functionalities;
2.7 We reserve the right to immediately cease Your use of generative AI if we identify any suspected or confirmed violation of the Agreement or the terms and policies of the third-party LLM supplier(s); and
2.8 When You use generative AI, Oneflow may continue to use the Input questions and Output responses to maintain Your history in generative AI in accordance with the third-party LLM supplier(s) then-current terms and policies.
- If you are using AI Review & Insights, AI Extract and/or AI Search You agree that:
3.1 AI Review & Insights is a Oneflow AI Feature that allows You to analyze the contents of a contract in Oneflow used as Input to identify business risks as set up by You in the Service;
3.2 AI Extract is a Oneflow AI Feature with which You can automatically extract key information (presented as Output) from imported contracts in Oneflow which You include as Input;
3.3 AI Search is a Oneflow AI Feature which purpose is to make it possible for You to query your contract library (where used as Input) in Oneflow for specific documents or answers found within Your documents in Oneflow;
3.4 Your use of AI Review & Insights, AI Extract and/or AI Search means that You instruct Oneflow to access and process the relevant contract content (Your Data) used as Input in its entirety for the purpose of and if deemed legitimately necessary to i) provide You with and support Your use of the applicable AI Feature(s); and ii) improve the quality of and validate Your Output; and
3.5 Your instruction per above shall be regarded as an instruction from You as the Controller to Oneflow as a data processor to, in accordance with and subject to, where applicable, the Oneflow Data Processing Agreement, process any such parts of Your Data used as Input which is personal data (as defined in the GDPR), for the limited purposes mentioned in clause 3.4 above.
PREVIOUS TERMS OF USE