This agreement (the “DPA”) forms part of our Terms of service for every business customer. It applies automatically when you create or use a workspace, so you don’t need to sign anything. If you would like a signed copy for your records, email privacy@companyflowhq.com.
1. Who is who
You are the business or organisation that holds a CompanyFlowHQ workspace (the “Customer”). You decide what personal data goes into your workspace and why, so you are the controller.
We are CompanyFlowHQ, 117 St Paul’s Avenue, Harrow, HA3 9PT, United Kingdom. We process that data only to provide the service to you, so we are your processor. If you are yourself a processor for someone else (for example, you handle data for your own clients), we act as your sub-processor and this DPA applies in the same way.
We are a controller, not a processor, for our own account, billing, support and website data about you and your team. That is covered by our Privacy notice, not this DPA.
2. Words used in this DPA
“UK GDPR”, “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings given in the UK GDPR. “Data Protection Law” means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and any law that replaces them. “Customer Personal Data” means personal data we process for you through your workspace.
3. Details of the processing
Subject matter and purpose
Providing the CompanyFlowHQ service you have chosen: CRM and lead management, bookings, email, SMS, WhatsApp and social messaging, marketing campaigns, quotes, invoices and e-signatures, client portals, team chat and boards, HR and staff management, reports, AI helpers, integrations, backups, security and support.
Nature of the processing
Collecting, storing, organising, displaying, searching, sending, receiving, analysing (for example lead scores and reports), backing up, restoring, exporting and deleting data, as you direct through the app.
Duration
For as long as you use the service, and afterwards only for the periods in section 11.
Types of data subjects
- Your leads, enquirers, clients, customers, students, patients and their contacts.
- Your staff, contractors, job applicants and former staff.
- People who message you, book with you, fill in your forms or visit your pages.
- Your suppliers, partners and other business contacts.
Types of personal data
- Contact and identity details: names, email addresses, phone numbers, postal addresses, company, job title, social media handles.
- CRM records: enquiries, notes, tasks, pipeline stages, deals, bookings, quotes, invoices, payments, signed documents, consent and marketing preferences.
- Messages: emails, text messages, WhatsApp and social messages, live chat and team chat, call details and any recordings you choose to make.
- Staff and HR data: employment details, contracts, pay and bank details, leave and sickness records, right-to-work and identity documents, identity numbers (such as passport, National Insurance, NHS number or UTR), emergency contacts, performance notes and approximate location if staff choose to share it.
- Files you upload: documents, images, attachments and signatures.
- Technical data: IP addresses, device and browser details, sign-in records and activity logs.
Special category and criminal offence data
You may choose to store special category data (for example health or sickness information in HR records) or criminal offence data (for example DBS check results). You are responsible for having a lawful basis and an appropriate policy document for it under the Data Protection Act 2018. The security measures in section 6 apply to it.
4. Your instructions
We process Customer Personal Data only on your documented instructions. Your instructions are these Terms and this DPA, and the choices you make in the app (such as sending a campaign, connecting an account or deleting a record). We will not use Customer Personal Data for our own purposes, sell it, or use it to train AI models.
If the law requires us to process Customer Personal Data in another way, we will tell you first unless the law forbids it. If we think an instruction breaks Data Protection Law, we will tell you straight away and may pause that processing until it is resolved.
You are responsible for the lawfulness of your instructions and of the data you put into CompanyFlowHQ, including having a lawful basis, giving people the information they are entitled to, and getting and recording consent for marketing where it is needed.
5. Confidentiality
Everyone we allow to process Customer Personal Data is bound by a duty of confidentiality. Access is limited to the people who need it. Our platform team sees workspace counts and billing details, not your leads, clients, staff or messages. We only look at workspace content when you ask us to help with it, to investigate a security incident, or when the law requires it.
6. Security
We take appropriate technical and organisational measures under UK GDPR Article 32. In particular:
- Encryption in transit and at rest. All traffic uses HTTPS (TLS). The database and file storage are encrypted at rest by Cloudflare.
- Extra encryption for secrets. Provider keys, access tokens, mailbox passwords and identity numbers are also encrypted by us with AES-256-GCM, with a fresh random value for each item and support for key rotation. They are never sent back to the browser.
- Encrypted backups. The whole database is backed up every night, encrypted with AES-256-GCM and checked with SHA-256 checksums.
- Two-step sign-in for everyone. Every staff user must use two-step sign-in (an authenticator app, emailed code or passkey), with recovery codes, new-device alerts and one-click sign-out of other devices. Passwords are stored only as salted one-way hashes.
- Workspaces kept apart. Every request checks which workspace it belongs to before reading or changing anything, and this is tested automatically.
- Role permissions. You decide what each role can see and do, and can keep staff records private between teams.
- Audit log. Important actions, sign-ins and every time someone reveals a protected identity number are recorded with time, person and IP address, and kept for one year.
- Abuse protection. Rate limits on sign-in and public endpoints, Cloudflare Turnstile bot checks, hidden trap fields, file-type checks on uploads and safe display of incoming email.
We review these measures as the service and the risks change, and will not reduce the overall level of protection.
7. Sub-processors
You give us general written authorisation to use the sub-processors listed in the sub-processor list below. Before we add or replace a sub-processor, we will update this page and email the workspace owner at least 30 days in advance.
You may object on reasonable data-protection grounds by emailing privacy@companyflowhq.com within that 30-day period. We will try to find a solution, such as not using the new sub-processor for your data. If we can’t, you may end the affected service before the change takes effect and we will refund any fees you have paid in advance for the period after it ends.
We put a written contract in place with each sub-processor that gives Customer Personal Data the same level of protection as this DPA, and we remain responsible to you for their work.
Services you connect yourself (such as your own Google, Microsoft, Meta, Twilio or Stripe account, a mailbox, a social network or an automation tool) are chosen by you and work under your own agreement with that provider. We send them data only when you tell us to. They are listed below so you can see where data goes.
8. Helping you with people’s rights
We help you respond to people exercising their rights under Data Protection Law (access, correction, erasure, restriction, portability and objection). CompanyFlowHQ includes tools so you can do most of this yourself:
- Export one person’s data as a file from their record (Privacy (GDPR) section).
- Erase one person everywhere in the workspace (on their record, or Settings → Erase one person).
- Correct any record directly, and stop marketing through consent and unsubscribe settings.
- Download all your workspace data at any time (Settings → Your data).
If we receive a request directly from one of your data subjects, we will pass it to you without undue delay and will not answer it ourselves unless you ask us to.
9. Other help we give
Taking into account the information available to us, we will give you reasonable help with your duties on security, breach notification, data protection impact assessments and prior consultation with the Information Commissioner (UK GDPR Articles 32 to 36).
10. Personal data breaches
If we become aware of a personal data breach affecting Customer Personal Data, we will notify the workspace owner without undue delay and in any case within 48 hours of becoming aware of it. We will tell you, as far as we know at the time, what happened, the types and rough numbers of people and records involved, the likely consequences, and what we have done or propose to do. We will add further details as they become available, take reasonable steps to contain the breach, and help you meet your own duty to report to the Information Commissioner within 72 hours where required. Telling you about a breach is not an admission of fault.
11. Deleting or returning data
- While you are a customer, you can download all your data at any time from Settings → Your data, and delete individual records whenever you like.
- If your subscription ends (for example a trial is not converted, a payment fails or you cancel), the workspace becomes read-only for 90 days so you can still sign in and download everything. After that period we delete the workspace.
- If you ask us to delete the workspace (Settings → Your data → Request workspace deletion), we confirm the request comes from the owner and complete it within 30 days.
- Backups. Deleted data is not removed from existing backups straight away. Backups are kept on a rolling schedule of 30 daily, 12 monthly and 5 yearly copies, so deleted data leaves the last backup when that copy expires (at most five years later). Backups stay encrypted, are used only to recover from an incident, and if we ever restore one we will delete again any data you had already asked us to delete.
- Audit log entries are kept for one year and are written so they do not name your contacts.
We will keep data longer only where the law requires us to, and only for that purpose.
12. Information and audits
We will make available the information reasonably needed to show that we meet this DPA and UK GDPR Article 28, and answer reasonable security questionnaires. You (or an independent auditor you appoint who is bound by confidentiality) may audit our compliance once in any 12-month period, on at least 30 days’ written notice, during business hours and at your own cost. We may ask you to rely on existing reports or certifications (including those of our sub-processors, such as Cloudflare’s) where they answer your questions. These limits do not apply where the Information Commissioner requires an audit or after a personal data breach affecting your data.
13. International transfers
CompanyFlowHQ runs on Cloudflare’s global network, and some sub-processors are based in the USA, so Customer Personal Data may be processed outside the UK. We transfer it only where the UK has recognised the destination as adequate (including the UK Extension to the EU–US Data Privacy Framework for certified US companies), or under the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment and supplementary measures where needed. You authorise these transfers.
14. Liability
Each party’s liability under this DPA is subject to the limits and exclusions in the Terms of service. Nothing in this DPA limits either party’s liability that cannot be limited by law, or the rights of data subjects under Data Protection Law.
15. Duration, precedence and law
This DPA lasts for as long as we process Customer Personal Data for you. Sections that by their nature should continue (such as confidentiality, deletion and liability) continue after it ends. If this DPA conflicts with the Terms on data protection, this DPA wins. It is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
We may update this DPA to reflect changes in law, in our sub-processors (following section 7) or in the service. We will give you at least 30 days’ notice of any change that materially reduces the protection of your data.
16. Sub-processor list
Always used
| Provider | What it does for us | Personal data it receives | Where |
|---|---|---|---|
| Cloudflare, Inc. | Hosting and running the app (Workers), the database (D1), file and media storage and encrypted backups (R2), live chat and mailbox sync (Durable Objects), AI helpers (Workers AI, models run on Cloudflare’s own network), bot checks (Turnstile), inbound email forwarding (Email Routing) and custom domains. | All workspace data: leads and clients, staff and HR records, messages, files, and the IP address and browser details of people using the app or your public pages. | Cloudflare’s global network, including the UK, EU and USA. Stored data may be held outside the UK. |
| Resend (Plus Five Five, Inc.) | Sending email: sign-in codes and alerts, notifications, emails to your clients (invoices, bookings, e-signature and portal links) when you haven’t connected your own mailbox, and email campaigns sent through CompanyFlowHQ’s sending account. | Recipient name and email address, subject, message content, and delivery, open, click, bounce and unsubscribe events. | USA. |
| Stripe (Stripe Payments UK Ltd / Stripe, Inc.) | Taking payment for your CompanyFlowHQ subscription. | Your billing contact’s name and email, your workspace ID and plan, and payment card details (entered directly with Stripe; we never see full card numbers). No lead, client or staff data. | UK, EU and USA. |
Only if you switch the feature on or connect the account
| Provider | What it does for us | Personal data it receives | Where |
|---|---|---|---|
| Google (Google LLC / Google Ireland Ltd) | Sign in with Google; Google Calendar sync; Google Analytics, Search Console, Business Profile and Google Ads reports and actions. | The connected person’s name and email; calendar events and booking details you sync; website, review and ad data you ask us to read or post. | USA, EU and elsewhere. |
| Microsoft (Microsoft Corporation / Microsoft Ireland Operations Ltd) | Sign in with Microsoft; Outlook / Microsoft 365 mailbox (read and send mail); Outlook calendar sync. | The connected person’s name and email; emails you send and receive through the connected mailbox; calendar events you sync. | USA, EU and elsewhere. |
| Meta (Meta Platforms Ireland Ltd / Meta Platforms, Inc.) | Facebook and Instagram pages and ads, Messenger and Instagram messages, WhatsApp Business messages, Threads posts, and Facebook lead forms. | Messages to and from your contacts, their names and phone numbers or profile IDs, lead-form answers, and the posts and ad details you publish. | USA, EU and elsewhere. |
| Twilio Inc. | Text messages (SMS) and phone calls. Normally your own Twilio account. | Recipient phone numbers, message content, call details and recordings if you turn recording on. | USA and elsewhere. |
| Stripe (your own account) | Card payments for your invoices, proposals and booking deposits, paid into your own Stripe account. | Your client’s name, email, the amount and what it is for. | UK, EU and USA. |
| Other services you link | Your own email provider (IMAP/SMTP mailbox) or Resend account; LinkedIn, X, Pinterest, Telegram, Bluesky, Mastodon, WordPress and Ceylon Chat for social posting; Zapier, Make and webhooks you set up; Companies House company look-ups. | Only what the connection needs: the posts, messages or records you choose to send, and for Companies House only the company number you look up. | Depends on the provider you choose. |
Some things happen without any personal data leaving CompanyFlowHQ: weather forecasts use rounded coordinates only (MET Norway), and public holiday dates use only a country code (Nager.Date). Push notifications to phones and browsers pass through the push service built into the device (Apple, Google, Mozilla or Microsoft) and are end-to-end encrypted, so that service cannot read them.
17. Contact
Questions about this DPA or about how we handle your data: email privacy@companyflowhq.com or write to CompanyFlowHQ, 117 St Paul’s Avenue, Harrow, HA3 9PT, United Kingdom. To report a security problem, email security@companyflowhq.com.