Application and parties
This DPA (version 2026-10-02.1), including its standard processing schedule and default arrangements below, forms part of a service agreement when expressly incorporated and accepted by the customer and the person or entity providing the service under the Flowpane name. The accepted order, beta agreement or written confirmation identifies the parties, their notice contacts, the service and the applicable DPA version. Ordinary use within the standard scope does not require a separately drafted customer processing schedule.
The current service processing record identifies the applicable subprocessors, processing locations, transfer arrangements, security implementation and backup cycle. Flowpane must supply and confirm that record before the relevant processing begins. It may be shared across customers using the same service arrangements; customer-specific variations must be recorded separately. These contractual obligations do not by themselves certify a control or establish that an unavailable feature is operational.
Data protection law means the UK GDPR and Data Protection Act 2018 and, where applicable to the processing, the EU GDPR and other applicable data-protection law. Controller, processor, personal data, processing and personal data breach have their meanings under that law. Customer personal data means personal data processed by Flowpane on the customer's documented instructions under the agreed service.
Controller and processor roles
For customer personal data, the customer is the controller and Flowpane is its processor. Where an agency or other customer acts as a processor for a client controller, Flowpane acts as that customer's subprocessor; the customer must have the controller's authorisation and pass on lawful instructions and the required contractual protections. The appropriate roles depend on the actual activity, not the plan name or workspace structure.
The customer is responsible for the lawfulness of its collection and instructions, necessary permissions and notices, recipient access and responding to individuals as controller. Flowpane is responsible for its processor obligations. Flowpane's own website enquiries, commercial administration and other processing for its own purposes are described in the Privacy notice, and are not converted into processing on the customer's behalf by this DPA.
Standard processing schedule
Subject matter and purpose: providing the customer-authorised website governance service and supporting its use. Operations may include receiving, recording, organising, storing, retrieving, assessing and presenting site evidence, generating agreed outputs, sharing them with authorised users, and returning or deleting data. Only the functions included in the agreed service and documented instructions are authorised; this description does not activate an unavailable function.
Data categories may include authorised user and recipient names and contact details, organisation and workspace identifiers, site URLs and verification records, governance observations, publicly accessible website material containing personal data, customer-submitted records, and support diagnostics necessary to investigate that customer's service. Public availability does not remove the need to assess personal-data handling.
Data subjects may include the customer's and its clients' authorised users, report recipients, support contacts and people identified in the website material or records the customer instructs Flowpane to process. These categories apply only to the extent included in the customer's actual authorised use. Special-category data, criminal-offence data and other material requiring additional protections are outside the standard scope unless separately agreed with suitable safeguards.
Duration: the authorised service period, followed only by the return, deletion and legally required retention arrangements below. During the service, any expressly agreed plan or record-specific retention limit applies; otherwise data is retained only for as long as necessary for the documented service purpose. The customer's rights include giving lawful instructions, requesting assistance, obtaining compliance information and choosing return or deletion. Its obligations include establishing lawful authority, access permissions and instructions appropriate to the agreed scope.
Documented instructions
Flowpane will process customer personal data only on the customer's documented instructions, including instructions about international transfers, unless applicable law requires otherwise. The accepted agreement, agreed configuration and authorised requests within its scope provide those instructions. Additional instructions must be recorded in writing; material changes to the service or scope require agreement before implementation.
Flowpane will inform the customer before legally required processing or disclosure unless the law prohibits that notice. Flowpane will promptly inform the customer if, in its opinion, an instruction infringes applicable data-protection law, and may pause the affected processing while it is clarified. Flowpane will not sell customer personal data or process it for an unrelated advertising purpose under this DPA.
Customer personal data must not be used to train a general-purpose model under these standard instructions. Any separately proposed training purpose requires expressly disclosed and agreed authority and a suitable legal basis before it occurs. Where an authorised AI-assisted function involves a provider, the applicable subprocessor, transfer and processing arrangements must be confirmed first. The AI and ML declaration supplies general context, not a blanket zero-retention or provider guarantee.
Confidentiality and security
Flowpane will ensure that anyone it authorises to process customer personal data is subject to confidentiality obligations or an appropriate statutory duty, and that access is limited to what is necessary for their authorised purpose. Confidentiality continues after access ends.
Flowpane will implement and maintain technical and organisational measures appropriate to the processing risk and required by applicable data-protection law. The following standard security obligations apply, with the implementation appropriate to the agreed processing described in the service processing record. Any certification or independent assurance must be identified separately in that record.
- Restrict access to authorised identities and the permissions needed for the agreed purpose; protect credentials and revoke access when it is no longer authorised.
- Protect personal data during transmission and storage using encryption or equivalent measures appropriate to the risk, and limit unnecessary exposure through diagnostic records or support exchanges.
- Maintain appropriate separation of customer access, confidentiality, integrity, availability and resilience, with recovery arrangements proportionate to the service and processing risk.
- Assess the effectiveness of relevant safeguards, address identified weaknesses, and maintain appropriate incident, return and deletion procedures.
Subprocessors
Flowpane will engage a subprocessor for customer personal data only with the customer's prior specific or general written authorisation. The agreed subprocessor record must identify each provider's legal identity, function, relevant processing locations and applicable transfer arrangement. A general provider category on the public website does not replace that record. Request and confirm the record through the contact form before the proposed processing begins.
Under general written authorisation, Flowpane will give at least 30 calendar days' written notice of an intended subprocessor addition or replacement before the new processing begins. The customer may object on reasonable data-protection grounds within 14 calendar days of receiving the notice. The parties will seek a suitable alternative; if none is reasonably available, the customer may end the affected service before that processing begins without an early-termination charge, with a proportionate refund of prepaid unused fees for that affected service. No objection authorises unlawful processing. A binding specific-authorisation requirement remains applicable where agreed.
Flowpane will bind each subprocessor in writing to equivalent applicable data-protection obligations, obtain sufficient guarantees of appropriate measures, and remain responsible to the customer for the subprocessor's performance of those obligations.
Processing locations and international transfers
The agreed processing record must identify relevant storage, access and support locations. An interface region label does not itself establish contractual residency or exclude access from another country. Flowpane will not make a restricted transfer of customer personal data without the customer's documented authority and a lawful transfer basis.
Where required, the parties will identify and complete the applicable adequacy arrangement or recognised safeguards, including the appropriate standard contractual clauses and any UK transfer addendum or agreement, with required assessments and supplementary measures. No transfer instrument is incorporated merely by naming it here. Mandatory transfer terms take priority over conflicting terms in this DPA.
Rights requests and compliance assistance
Taking account of the processing and information available, Flowpane will provide appropriate assistance with individuals' rights requests and the customer's obligations for security, breach reporting, data-protection impact assessments and prior consultation with a supervisory authority. Flowpane will promptly refer a request about customer personal data to the customer and will not respond substantively on its behalf without instructions, unless legally required.
The parties will use their recorded contacts and agree practical arrangements for assistance. Any charge for exceptional work must be agreed in advance and must not prevent legally required assistance. The customer remains responsible for its controller decisions, applicable deadlines and communications; Flowpane remains responsible for its own legal duties.
Personal data breaches
Flowpane will notify the customer without undue delay after becoming aware of a personal data breach affecting customer personal data. The initial notice will provide available information about the nature of the breach, affected data and individuals, likely consequences, mitigation and a contact for follow-up. Information may be supplied in stages as it becomes available; investigation will not be used to postpone the initial notice unnecessarily.
Flowpane will take appropriate steps to contain, investigate and address the breach and assist the customer with its reporting duties. A breach notification is not by itself an admission of liability. No fixed 24-hour or 48-hour service deadline is promised unless separately agreed, and that does not relax the requirement to act without undue delay. This contractual incident duty is separate from the voluntary researcher reporting process in the Security disclosure policy.
Return, deletion and backups
At the end of the relevant service, the customer may request return of customer personal data in a reasonably usable electronic format or instruct secure deletion. The default period for requesting return is 30 calendar days after the service ends. Flowpane will complete a return request without undue delay and keep the affected data only for that purpose while the request is being completed. If no return request is received within that period, deletion is the default instruction. A customer's earlier lawful deletion instruction remains effective.
Unless a different lawful period is expressly agreed, Flowpane will delete customer personal data from active service systems within 30 calendar days after a deletion instruction, completion of the requested return, or expiry of the default return-request period, as applicable. Data retained solely during this exit process must be restricted to return, deletion, security and legal obligations. Flowpane will provide confirmation on request and identify legally required retention, where permitted.
Where immediate removal from a backup is not practicable, the documented backup cycle must be appropriate to the purpose and risk. Copies awaiting expiry must be protected and put beyond ordinary use, then deleted as soon as possible in that cycle and no later than 90 calendar days after deletion from active service systems, unless applicable law requires retention or a different lawful period was expressly agreed before processing. If a backup is restored for recovery, the required deletion must be reapplied. These are contractual exit obligations; they do not imply an automatic export or deletion interface.
Compliance information and audits
Flowpane will make available information necessary to demonstrate compliance with applicable processor obligations and allow and contribute to audits and inspections by the customer or its appointed auditor. The parties should first use relevant documentation and written responses where sufficient, and agree reasonable notice, scope, confidentiality and safeguards for any further inspection without disclosing another customer's data.
These practical arrangements must not obstruct legally required access, urgent investigation or a regulator's powers. Any agreed allocation of reasonable audit costs must not remove the audit right. No independent certification or completed external audit is asserted by this clause.
Default acceptance and variations
The standard schedule above and the applicable service processing record may be incorporated by reference into an accepted service order or beta agreement, or into written confirmation exchanged by the parties. That record must identify the customer, the Flowpane contracting party, the service, the DPA version and the customer notice contact. An authorised representative must accept for an organisation. No separate DPA signature is required where the parties have expressly accepted those incorporated terms.
Acceptance can be recorded by an electronic signature, an explicit agreement acceptance mechanism, or written confirmation, including email, that identifies the incorporated documents. Flowpane must retain a reproducible record of the version accepted and the acceptance. Browsing this page, submitting a beta enquiry, receiving a workspace invitation or merely using an account does not by itself establish that this acceptance step has occurred.
By expressly accepting this DPA and the identified subprocessor record, the customer gives general written authorisation for those listed subprocessors, subject to the advance-notice and objection procedure above. Acceptance is not blanket authorisation for unidentified providers, locations or restricted transfers. Any necessary transfer instrument must also be completed before the relevant transfer.
For ordinary service use, the default processing scope, security obligations, retention and exit process above apply without a bespoke schedule. A different processing purpose, sensitive-data requirement, fixed residency, retention period, subprocessor-authorisation model or other variation requires express written agreement before the affected processing begins. Mandatory data-protection and transfer requirements continue to apply.
Contacts, precedence and changes
Use the contact form for DPA requests, instructions and privacy questions, with the customer contact recorded in the accepted agreement. Report suspected vulnerabilities through the security reporting form. Contractual rights and duties survive termination to the extent required to protect retained data and complete return, deletion and compliance assistance.
The DPA takes priority over conflicting service terms on customer personal-data processing, subject to mandatory transfer clauses. The Terms of service govern other contractual matters and any lawful agreed liability limits; neither those limits nor this DPA restrict statutory rights or regulatory powers. Applicable law and dispute arrangements follow the accepted agreement and mandatory protections.
Material changes to this DPA or its processing scope require the agreement, notice and acceptance process in the existing customer agreement. Updating this page does not retrospectively obtain instructions, authorise a new subprocessor or establish customer acceptance. Confirm the applicable accepted version and service processing record for a particular account.