Data Processing Agreement
Last updated: August 17, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Moveflow Tech, Corp. (“Moveflow,” “Processor”) and the company that subscribes to Moveflow’s TMS Services (“Customer,” “Controller”) under the Moveflow Terms of Use (the “Agreement”). It applies where Moveflow processes personal information of Customer’s personnel (drivers, dispatchers, administrators) on Customer’s behalf. It does not apply to marketplace participants, for whom Moveflow is the controller as described in the Privacy Policy.
By subscribing to and using the TMS Services, Customer agrees to this DPA. A countersigned copy is available on request at info@moveflow.tech.
1. Scope and Roles
1.1 Roles. Customer is the controller (or “business”) of Customer Personal Data; Moveflow is the processor (or “service provider”).
1.2 “Customer Personal Data” means personal information of Customer’s personnel that Moveflow processes on Customer’s behalf through the TMS Services, including account and profile information, operational and assignment records, precise location data collected during work assignments, communications, and usage data.
1.3 Duration. This DPA applies for as long as Moveflow processes Customer Personal Data under the Agreement.
2. Processing Instructions
2.1 Moveflow will process Customer Personal Data only on Customer’s documented instructions — the Agreement, this DPA, and Customer’s configuration and use of the Services constitute those instructions — unless processing is required by law, in which case Moveflow will notify Customer unless prohibited.
2.2 Service-provider commitments (U.S. state privacy laws). Moveflow will not: sell Customer Personal Data or share it for cross-context behavioral advertising; retain, use, or disclose it for any purpose other than performing the Services (or as permitted by applicable law); retain, use, or disclose it outside the direct business relationship with Customer; or combine it with personal information from other sources except as permitted for service providers. Moveflow will notify Customer if it determines it can no longer meet these obligations, and Customer may take reasonable steps to stop and remediate unauthorized use.
3. Confidentiality
Moveflow ensures that persons authorized to process Customer Personal Data are bound by confidentiality obligations.
4. Security
Moveflow implements the technical and organizational measures described in Section 7 of the Privacy Policy, including encryption in transit, encryption at rest via cloud infrastructure providers, access controls scoped to the owning account and company, authentication through a dedicated identity provider, security logging, and a written Incident Response Plan. Moveflow may update these measures provided the overall level of protection is not materially reduced.
5. Sub-processors
5.1 Customer provides general authorization for the sub-processors listed at moveflow.tech/subprocessors.
5.2 Moveflow will provide thirty (30) days’ advance notice of additions or replacements by updating that page. Customer may object in writing on reasonable data-protection grounds within the notice period; if the parties cannot resolve the objection, Customer may terminate the affected Services.
5.3 Moveflow remains responsible for its sub-processors’ performance of data-protection obligations consistent with this DPA.
6. Data Subject Requests
Taking into account the nature of the processing, Moveflow will assist Customer by appropriate technical and organizational measures in responding to requests to exercise data subject rights. If a data subject request is made directly to Moveflow regarding Customer Personal Data, Moveflow will direct the requester to Customer and will not respond substantively except as required by law.
7. Security Incidents
Moveflow will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. Notice will describe, to the extent known, the nature of the incident, the categories and approximate number of affected individuals and records, the likely consequences, and the measures taken or proposed. Moveflow’s notification is not an acknowledgement of fault or liability.
8. Audits
On Customer’s reasonable written request (no more than once per year, absent a security incident), Moveflow will make available information reasonably necessary to demonstrate compliance with this DPA, which may take the form of written responses, summaries of security practices, and available third-party attestations. Audits will not require disclosure of other customers’ data or of information that would compromise Moveflow’s security.
9. Return and Deletion
Upon termination of the Services, Moveflow will, at Customer’s choice, delete or return Customer Personal Data, and delete existing copies, except where retention is required by law and except for backup copies, which persist for up to ninety (90) days in logically isolated form and are not restored to production except in disaster recovery, consistent with Section 5 of the Privacy Policy.
10. Liability and Order of Precedence
Liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. In the event of conflict between this DPA and the Agreement regarding the processing of Customer Personal Data, this DPA controls.
11. Governing Law
This DPA is governed by the laws of the State of Tennessee, consistent with the Agreement.
Contact: Moveflow Tech, Corp. · 801 W Clinch Ave, 7th Floor, The Sunsphere, Knoxville, TN 37902 · info@moveflow.tech · +1 (865) 297-7313