Security, privacy and data
Review Scriboflow's DPA and subprocessors
Find Scriboflow's Data Processing Agreement and current provider register.
Last updated August 25, 2026
Scriboflow publishes its Data Processing Agreement, or DPA, and its current provider register for customer review.
Data Processing Agreement
The Data Processing Agreement describes how Scriboflow processes customer-controlled personal data when providing the service. It covers subjects including:
- The customer's and Scriboflow's data-protection roles
- Processing instructions and confidentiality
- Security measures
- Subprocessors and international transfers
- Data-subject requests
- Incident assistance
- Return and deletion of data
The DPA is incorporated into Scriboflow's Terms. A downloadable PDF is available from the DPA page.
When Scriboflow requires acceptance of a material legal revision, an organisation owner or admin who is authorised to act for the organisation can review the displayed documents and select Accept and continue. The acceptance is recorded for the organisation.
Subprocessors and other providers
The Subprocessor register identifies current providers and explains their purpose, relevant data categories, processing locations and safeguards. It distinguishes customer-data subprocessors from providers acting in other roles.
Use the public pages as the current source rather than keeping a separate copy of the provider list. For questions about the DPA, email privacy@scriboflow.com.
Related articles
Security, privacy and data
Where Scriboflow stores and processes data
Understand Scriboflow's primary database region and additional provider processing locations.
Security, privacy and data
Understand data retention and deletion
Learn what happens when data, an account or a Scriboflow subscription is deleted or ended.