CompanyFlowHQ legal

Data Processing Agreement

How we look after the personal data you keep in CompanyFlowHQ, as required by UK GDPR Article 28 and the Data Protection Act 2018.

Last updated 30 September 2026

1. Who is who

You are the business or organisation that holds a CompanyFlowHQ workspace (the “Customer”). You decide what personal data goes into your workspace and why, so you are the controller.

We are CompanyFlowHQ, 117 St Paul’s Avenue, Harrow, HA3 9PT, United Kingdom. We process that data only to provide the service to you, so we are your processor. If you are yourself a processor for someone else (for example, you handle data for your own clients), we act as your sub-processor and this DPA applies in the same way.

We are a controller, not a processor, for our own account, billing, support and website data about you and your team. That is covered by our Privacy notice, not this DPA.

2. Words used in this DPA

“UK GDPR”, “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings given in the UK GDPR. “Data Protection Law” means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and any law that replaces them. “Customer Personal Data” means personal data we process for you through your workspace.

3. Details of the processing

Subject matter and purpose

Providing the CompanyFlowHQ service you have chosen: CRM and lead management, bookings, email, SMS, WhatsApp and social messaging, marketing campaigns, quotes, invoices and e-signatures, client portals, team chat and boards, HR and staff management, reports, AI helpers, integrations, backups, security and support.

Nature of the processing

Collecting, storing, organising, displaying, searching, sending, receiving, analysing (for example lead scores and reports), backing up, restoring, exporting and deleting data, as you direct through the app.

Duration

For as long as you use the service, and afterwards only for the periods in section 11.

Types of data subjects

Types of personal data

Special category and criminal offence data

You may choose to store special category data (for example health or sickness information in HR records) or criminal offence data (for example DBS check results). You are responsible for having a lawful basis and an appropriate policy document for it under the Data Protection Act 2018. The security measures in section 6 apply to it.

4. Your instructions

We process Customer Personal Data only on your documented instructions. Your instructions are these Terms and this DPA, and the choices you make in the app (such as sending a campaign, connecting an account or deleting a record). We will not use Customer Personal Data for our own purposes, sell it, or use it to train AI models.

If the law requires us to process Customer Personal Data in another way, we will tell you first unless the law forbids it. If we think an instruction breaks Data Protection Law, we will tell you straight away and may pause that processing until it is resolved.

You are responsible for the lawfulness of your instructions and of the data you put into CompanyFlowHQ, including having a lawful basis, giving people the information they are entitled to, and getting and recording consent for marketing where it is needed.

5. Confidentiality

Everyone we allow to process Customer Personal Data is bound by a duty of confidentiality. Access is limited to the people who need it. Our platform team sees workspace counts and billing details, not your leads, clients, staff or messages. We only look at workspace content when you ask us to help with it, to investigate a security incident, or when the law requires it.

6. Security

We take appropriate technical and organisational measures under UK GDPR Article 32. In particular:

We review these measures as the service and the risks change, and will not reduce the overall level of protection.

7. Sub-processors

You give us general written authorisation to use the sub-processors listed in the sub-processor list below. Before we add or replace a sub-processor, we will update this page and email the workspace owner at least 30 days in advance.

You may object on reasonable data-protection grounds by emailing privacy@companyflowhq.com within that 30-day period. We will try to find a solution, such as not using the new sub-processor for your data. If we can’t, you may end the affected service before the change takes effect and we will refund any fees you have paid in advance for the period after it ends.

We put a written contract in place with each sub-processor that gives Customer Personal Data the same level of protection as this DPA, and we remain responsible to you for their work.

Services you connect yourself (such as your own Google, Microsoft, Meta, Twilio or Stripe account, a mailbox, a social network or an automation tool) are chosen by you and work under your own agreement with that provider. We send them data only when you tell us to. They are listed below so you can see where data goes.

8. Helping you with people’s rights

We help you respond to people exercising their rights under Data Protection Law (access, correction, erasure, restriction, portability and objection). CompanyFlowHQ includes tools so you can do most of this yourself:

If we receive a request directly from one of your data subjects, we will pass it to you without undue delay and will not answer it ourselves unless you ask us to.

9. Other help we give

Taking into account the information available to us, we will give you reasonable help with your duties on security, breach notification, data protection impact assessments and prior consultation with the Information Commissioner (UK GDPR Articles 32 to 36).

10. Personal data breaches

If we become aware of a personal data breach affecting Customer Personal Data, we will notify the workspace owner without undue delay and in any case within 48 hours of becoming aware of it. We will tell you, as far as we know at the time, what happened, the types and rough numbers of people and records involved, the likely consequences, and what we have done or propose to do. We will add further details as they become available, take reasonable steps to contain the breach, and help you meet your own duty to report to the Information Commissioner within 72 hours where required. Telling you about a breach is not an admission of fault.

11. Deleting or returning data

We will keep data longer only where the law requires us to, and only for that purpose.

12. Information and audits

We will make available the information reasonably needed to show that we meet this DPA and UK GDPR Article 28, and answer reasonable security questionnaires. You (or an independent auditor you appoint who is bound by confidentiality) may audit our compliance once in any 12-month period, on at least 30 days’ written notice, during business hours and at your own cost. We may ask you to rely on existing reports or certifications (including those of our sub-processors, such as Cloudflare’s) where they answer your questions. These limits do not apply where the Information Commissioner requires an audit or after a personal data breach affecting your data.

13. International transfers

CompanyFlowHQ runs on Cloudflare’s global network, and some sub-processors are based in the USA, so Customer Personal Data may be processed outside the UK. We transfer it only where the UK has recognised the destination as adequate (including the UK Extension to the EU–US Data Privacy Framework for certified US companies), or under the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment and supplementary measures where needed. You authorise these transfers.

14. Liability

Each party’s liability under this DPA is subject to the limits and exclusions in the Terms of service. Nothing in this DPA limits either party’s liability that cannot be limited by law, or the rights of data subjects under Data Protection Law.

15. Duration, precedence and law

This DPA lasts for as long as we process Customer Personal Data for you. Sections that by their nature should continue (such as confidentiality, deletion and liability) continue after it ends. If this DPA conflicts with the Terms on data protection, this DPA wins. It is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

We may update this DPA to reflect changes in law, in our sub-processors (following section 7) or in the service. We will give you at least 30 days’ notice of any change that materially reduces the protection of your data.

16. Sub-processor list

Always used

Only if you switch the feature on or connect the account

Some things happen without any personal data leaving CompanyFlowHQ: weather forecasts use rounded coordinates only (MET Norway), and public holiday dates use only a country code (Nager.Date). Push notifications to phones and browsers pass through the push service built into the device (Apple, Google, Mozilla or Microsoft) and are end-to-end encrypted, so that service cannot read them.

17. Contact

Questions about this DPA or about how we handle your data: email privacy@companyflowhq.com or write to CompanyFlowHQ, 117 St Paul’s Avenue, Harrow, HA3 9PT, United Kingdom. To report a security problem, email security@companyflowhq.com.