# Data Processing Agreement

Standard terms for personal data processed on a customer's instructions, with the processing details confirmed for the agreed service.

Updated: 2 October 2026

## Application and parties

This DPA forms part of a service agreement only when expressly incorporated and accepted by the customer and the person or entity providing the service under the Flowpane name. That agreement must identify both parties, their notice contacts and the applicable version of these terms. Publication, a workspace invitation or a beta application alone is not acceptance. Contact hello@flowpane.com to complete the processing details and obtain the agreement applicable to your use.

Before processing begins under this DPA, the parties must confirm the processing scope described below and record the applicable security measures, subprocessors, processing locations, transfer arrangements and retention and backup-deletion periods. These details may be recorded in the accepted agreement and its schedules. This public document is not a completed customer-specific schedule, a signed agreement or evidence that every described arrangement is currently operational.

Data protection law means the UK GDPR and Data Protection Act 2018 and, where applicable to the processing, the EU GDPR and other applicable data-protection law. Controller, processor, personal data, processing and personal data breach have their meanings under that law. Customer personal data means personal data processed by Flowpane on the customer's documented instructions under the agreed service.


## Controller and processor roles

For customer personal data, the customer is the controller and Flowpane is its processor. Where an agency or other customer acts as a processor for a client controller, Flowpane acts as that customer's subprocessor; the customer must have the controller's authorisation and pass on lawful instructions and the required contractual protections. The appropriate roles depend on the actual activity, not the plan name or workspace structure.

The customer is responsible for the lawfulness of its collection and instructions, necessary permissions and notices, recipient access and responding to individuals as controller. Flowpane is responsible for its processor obligations. Flowpane's own website enquiries, commercial administration and other processing for its own purposes are described in the [Privacy notice](/privacy), and are not converted into processing on the customer's behalf by this DPA.


## Processing description and scope

Subject matter and purpose: providing the customer-authorised website governance service and supporting its use. Operations may include receiving, recording, organising, storing, retrieving, assessing and presenting site evidence, generating agreed outputs, sharing them with authorised users, and returning or deleting data. Only the functions included in the agreed service and documented instructions are authorised; this description does not activate an unavailable function.

Data categories may include authorised user and recipient names and contact details, organisation and workspace identifiers, site URLs and verification records, governance observations, publicly accessible website material containing personal data, customer-submitted records, and support diagnostics necessary to investigate that customer's service. Public availability does not remove the need to assess personal-data handling.

Data subjects may include the customer's and its clients' authorised users, report recipients, support contacts and people identified in the website material or records the customer instructs Flowpane to process. The parties must narrow these categories to the actual use. Special-category data, criminal-offence data and other material requiring additional protections are outside the standard scope unless separately agreed with suitable safeguards.

Duration: the authorised service period, followed only by the return, deletion and legally required retention arrangements below. The customer-specific schedule must record the applicable evidence, diagnostic and backup periods. The customer's rights include giving lawful instructions, requesting assistance, obtaining compliance information and choosing return or deletion. Its obligations include establishing lawful authority, access permissions and instructions appropriate to the agreed scope.


## Documented instructions

Flowpane will process customer personal data only on the customer's documented instructions, including instructions about international transfers, unless applicable law requires otherwise. The accepted agreement, agreed configuration and authorised requests within its scope provide those instructions. Additional instructions must be recorded in writing; material changes to the service or scope require agreement before implementation.

Flowpane will inform the customer before legally required processing or disclosure unless the law prohibits that notice. Flowpane will promptly inform the customer if, in its opinion, an instruction infringes applicable data-protection law, and may pause the affected processing while it is clarified. Flowpane will not sell customer personal data or process it for an unrelated advertising purpose under this DPA.

Customer personal data must not be used to train a general-purpose model under these standard instructions. Any separately proposed training purpose requires expressly disclosed and agreed authority and a suitable legal basis before it occurs. Where an authorised AI-assisted function involves a provider, the applicable subprocessor, transfer and processing arrangements must be confirmed first. The [AI and ML declaration](/ai-ml) supplies general context, not a blanket zero-retention or provider guarantee.


## Confidentiality and security

Flowpane will ensure that anyone it authorises to process customer personal data is subject to confidentiality obligations or an appropriate statutory duty, and that access is limited to what is necessary for their authorised purpose. Confidentiality continues after access ends.

Flowpane will implement and maintain technical and organisational measures appropriate to the processing risk and required by applicable data-protection law. The agreed security schedule must describe the measures for access control, confidentiality, integrity and resilience, encryption or pseudonymisation where appropriate, recovery, and regular assessment of effectiveness. It must reflect the measures actually applicable to the service. Any certification or independent assurance must be identified separately in the agreed record.


## Subprocessors

Flowpane will engage a subprocessor for customer personal data only with the customer's prior specific or general written authorisation. The agreed subprocessor record must identify each provider's legal identity, function, relevant processing locations and applicable transfer arrangement. A general provider category on the public website does not replace that record. Request and confirm the record through hello@flowpane.com before the proposed processing begins.

Under general written authorisation, Flowpane will notify the customer in advance of an intended addition or replacement and allow a reasonable opportunity to object on data-protection grounds before the new processing begins. The notice will identify the change and objection period. The parties will seek a suitable alternative; if none is reasonably available, they will agree how to end the affected service before that processing begins. A binding specific-authorisation requirement remains applicable where agreed.

Flowpane will bind each subprocessor in writing to equivalent applicable data-protection obligations, obtain sufficient guarantees of appropriate measures, and remain responsible to the customer for the subprocessor's performance of those obligations.


## Processing locations and international transfers

The agreed processing record must identify relevant storage, access and support locations. An interface region label does not itself establish contractual residency or exclude access from another country. Flowpane will not make a restricted transfer of customer personal data without the customer's documented authority and a lawful transfer basis.

Where required, the parties will identify and complete the applicable adequacy arrangement or recognised safeguards, including the appropriate standard contractual clauses and any UK transfer addendum or agreement, with required assessments and supplementary measures. No transfer instrument is incorporated merely by naming it here. Mandatory transfer terms take priority over conflicting terms in this DPA.


## Rights requests and compliance assistance

Taking account of the processing and information available, Flowpane will provide appropriate assistance with individuals' rights requests and the customer's obligations for security, breach reporting, data-protection impact assessments and prior consultation with a supervisory authority. Flowpane will promptly refer a request about customer personal data to the customer and will not respond substantively on its behalf without instructions, unless legally required.

The parties will use their recorded contacts and agree practical arrangements for assistance. Any charge for exceptional work must be agreed in advance and must not prevent legally required assistance. The customer remains responsible for its controller decisions, applicable deadlines and communications; Flowpane remains responsible for its own legal duties.


## Personal data breaches

Flowpane will notify the customer without undue delay after becoming aware of a personal data breach affecting customer personal data. The initial notice will provide available information about the nature of the breach, affected data and individuals, likely consequences, mitigation and a contact for follow-up. Information may be supplied in stages as it becomes available; investigation will not be used to postpone the initial notice unnecessarily.

Flowpane will take appropriate steps to contain, investigate and address the breach and assist the customer with its reporting duties. A breach notification is not by itself an admission of liability. No fixed 24-hour or 48-hour service deadline is promised unless separately agreed, and that does not relax the requirement to act without undue delay. This contractual incident duty is separate from the voluntary researcher reporting process in the [Security disclosure policy](/security-disclosure).


## Return, deletion and backups

At the end of the relevant service, Flowpane will, at the customer's choice, return customer personal data in an agreed reasonably usable format or securely delete it, and delete remaining copies unless applicable law requires retention. The parties must record the export arrangements and deletion periods in the customer-specific schedule. Flowpane will provide confirmation on request and identify legally required retention, where permitted.

Where immediate removal from a backup is not practicable, the agreed backup cycle must be appropriate to the purpose and risk. Retained copies must be protected, put beyond ordinary use and deleted as soon as possible within that cycle. If a backup is restored for recovery, the required deletion must be reapplied. Neither a disabled account nor a deleted interface record alone proves physical erasure.


## Compliance information and audits

Flowpane will make available information necessary to demonstrate compliance with applicable processor obligations and allow and contribute to audits and inspections by the customer or its appointed auditor. The parties should first use relevant documentation and written responses where sufficient, and agree reasonable notice, scope, confidentiality and safeguards for any further inspection without disclosing another customer's data.

These practical arrangements must not obstruct legally required access, urgent investigation or a regulator's powers. Any agreed allocation of reasonable audit costs must not remove the audit right. No independent certification or completed external audit is asserted by this clause.


## Contacts, precedence and changes

Use hello@flowpane.com for DPA requests, instructions and privacy questions, with the customer contact recorded in the accepted agreement. Suspected vulnerabilities may also be reported to security@flowpane.com. Contractual rights and duties survive termination to the extent required to protect retained data and complete return, deletion and compliance assistance.

The DPA takes priority over conflicting service terms on customer personal-data processing, subject to mandatory transfer clauses. The [Terms of service](/terms) govern other contractual matters and any lawful agreed liability limits; neither those limits nor this DPA restrict statutory rights or regulatory powers. Applicable law and dispute arrangements follow the accepted agreement and mandatory protections.

Material changes to this DPA or its processing scope require the agreement, notice and acceptance process in the existing customer agreement. Updating this page does not retrospectively obtain instructions, authorise a new subprocessor or establish customer acceptance. Confirm the applicable version and completed processing schedules before relying on the DPA for a particular account.

