This Data Processing Agreement (the DPA) forms part of the Agreement between the business or organisation identified in an Order or at sign-up (the Customer) and CertFlow LTD (company number 17056886), a company registered in England and Wales whose registered office is 20 Wenlock Road, London, N1 7GU (CertFlow). It applies whenever CertFlow Processes Customer Personal Data on the Customer's behalf in providing the Service.
This DPA records the parties' controller and processor arrangements for Article 28 of the UK GDPR. It should be read with the applicable Order and CertFlow's Terms & Conditions. Capitalised terms not defined here have the meanings given in the Agreement.
1. Scope, parties and roles
For Customer Personal Data, the Customer is the Controller and CertFlow is the Processor. If the Customer Processes personal data for another controller, the Customer is a Processor, CertFlow is its Subprocessor, and references in this DPA to the Customer's obligations as Controller include the corresponding obligations that the Customer must pass on for its own controller.
The Customer appoints CertFlow to Process Customer Personal Data only for the purposes and duration described in Schedule 1, on the documented instructions described in this DPA, and subject to the safeguards in Schedules 2 to 4. CertFlow accepts that appointment.
This DPA does not govern personal data for which CertFlow determines the purposes and means as an independent Controller. That limited Controller processing includes subscription and billing administration, CertFlow's own business contacts and direct communications, fraud and platform-security administration, legal compliance, and public-website activity, as explained in the Privacy Policy. A data item may fall within different roles for different processing operations; the role follows the actual purpose and control, not merely where the data is stored.
| Party | Identity and role |
|---|---|
| Customer | The business or organisation named in the Order, checkout or organisation workspace. Controller, or Processor for its own controller, of Customer Personal Data. |
| CertFlow | CertFlow LTD, company number 17056886, 20 Wenlock Road, London, N1 7GU. Processor, or Subprocessor where the Customer is itself a Processor. |
| Privacy contact | info@certflow.co.uk; 0114 392 2407. This contact point does not represent that CertFlow has appointed a statutory data protection officer. |
2. Definitions and interpretation
| Term | Meaning |
|---|---|
| Agreement | The applicable Order, the Terms & Conditions, this DPA and any service-specific terms or statement of work incorporated into the Order. |
| Customer Data | Data, files, records, images, signatures, messages and other content submitted to, generated in or made available through the Service by or for the Customer. |
| Customer Personal Data | Personal Data contained in Customer Data that CertFlow Processes on the Customer's behalf. It excludes data for which CertFlow acts as an independent Controller. |
| Data Protection Laws | The UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations 2003, Data (Use and Access) Act 2025, and other privacy or data-protection law applicable to the Processing, in each case as amended, replaced or supplemented. |
| Data Subject Request | A request or exercise of a right by an individual under Data Protection Laws in relation to Customer Personal Data. |
| Restricted Transfer | A transfer of personal data that requires an adequacy regulation or appropriate safeguard under Data Protection Laws, including remote access from a third country where the law treats that access as a transfer. |
| Security Incident | An event affecting the confidentiality, integrity or availability of systems or data. A Personal Data Breach has the meaning in the UK GDPR and is a Security Incident involving Customer Personal Data. |
| Subprocessor | A third party engaged by or for CertFlow to Process Customer Personal Data on the Customer's behalf. |
| UK GDPR | The retained and amended version of the General Data Protection Regulation that forms part of United Kingdom law. |
The terms Controller, Processor, Data Subject, Personal Data, Process, Processing, special categories of personal data, criminal offence data, Supervisory Authority and appropriate technical and organisational measures have the meanings given by Data Protection Laws.
References to an Article are to the UK GDPR unless stated otherwise. References to written instructions include the Agreement, an Order, configuration choices and actions made by authorised users through the Service, and instructions sent from an authorised Customer contact by email or an agreed support channel. "Including" does not limit the words that precede it.
3. Incorporation, duration and precedence
This DPA applies from the later of 24 August 2026 and the date on which CertFlow first Processes Customer Personal Data under the Agreement. It continues for as long as CertFlow or a Subprocessor retains Customer Personal Data, including any protected backup retention period. Clauses that are intended to protect data after termination continue until the relevant data has been returned or deleted.
If this DPA conflicts with another part of the Agreement about Processing Customer Personal Data, the order of precedence is: (1) mandatory international-transfer terms; (2) this DPA; (3) the applicable Order; and (4) the Terms & Conditions. The conflict is resolved only to the extent needed. Nothing in this DPA reduces a protection that Data Protection Laws make mandatory.
If a Customer organisation contains several workspaces, brands or business units under one Agreement, the contracting Customer remains responsible for their instructions. Notices sent to the Customer contact or workspace owner recorded in the Service are notices to the Customer.
4. Documented instructions and limits on Processing
CertFlow will:
- Process Customer Personal Data only on the Customer's documented instructions, including for Restricted Transfers, unless United Kingdom law requires other Processing;
- where law requires Processing contrary to an instruction, tell the Customer about that legal requirement before Processing unless the law prohibits notice on important grounds of public interest;
- Process only the data reasonably needed to provide, operate, secure, support and maintain the subscribed Service, perform the Agreement, or comply with another valid documented instruction;
- not sell Customer Personal Data, use it for third-party behavioural advertising, or use it for CertFlow's independent direct-marketing purposes; and
- notify the Customer promptly if, in CertFlow's reasonable opinion, an instruction infringes Data Protection Laws, and may suspend only the affected instruction while the parties clarify or correct it.
The Agreement, the Customer's selected features and settings, authorised use of the Service, support and migration requests, and any written instruction accepted by CertFlow together form the Customer's complete documented instructions. The Customer may give a reasonable additional instruction that is consistent with the Agreement and Data Protection Laws. If it requires a material change to the Service, unusual manual work or extra cost, the parties will agree scope, timing and any reasonable charge before work begins.
CertFlow may block, remove, preserve or disclose particular data where reasonably necessary to comply with law, a binding authority request, or an urgent instruction to protect individuals or the Service. Where legally permitted, CertFlow will notify the Customer and limit the action to what is necessary.
5. Customer obligations
The Customer is responsible for the lawfulness, fairness and accuracy of its collection and instructions. The Customer warrants on a continuing basis that it:
- has authority to give the instructions and to disclose Customer Personal Data to CertFlow and the authorised Subprocessors;
- has provided all required privacy information and has a valid lawful basis for each purpose, together with an Article 9 condition and any Data Protection Act 2018 Schedule 1 condition where special-category data is involved;
- has identified and complied with the additional rules for criminal-offence data, employee monitoring, location data, signatures, health and safety records, and records about competence or employment;
- will use data minimisation, set appropriate retention periods, keep data accurate where necessary, and avoid placing Personal Data in public, unrestricted or free-text fields unless appropriate;
- will assess whether the Service and the measures in Schedule 2 are appropriate for the Customer's Processing risks, and complete any required data protection impact assessment before high-risk Processing begins;
- will manage authorised users, roles, permissions, devices, exports, recipients and integrations, promptly remove leavers, protect credentials and report suspected compromise; and
- if acting as a Processor, has its controller's authorisation to appoint CertFlow and will not give an instruction that breaches the Customer's own processing agreement.
The Service is not intended for storing full payment-card numbers or for routine Processing of children's data. The Customer must contact CertFlow before introducing high-volume special-category data, systematic monitoring, large-scale criminal-offence data or another use materially outside Schedule 1 so that the parties can assess instructions, safeguards and Service suitability.
CertFlow is not responsible for determining the Customer's lawful basis, retention schedule, professional record-keeping duty or response to an individual, except for the Processor obligations expressly allocated to CertFlow by this DPA and Data Protection Laws.
6. Confidentiality and personnel
CertFlow will ensure that persons authorised to Process Customer Personal Data are subject to a contractual, statutory or professional duty of confidentiality, receive access only where reasonably needed for their role, and are informed of relevant security and data-handling responsibilities. Those duties continue after their access or engagement ends.
CertFlow will limit administrative access to authorised personnel and service providers who require it for support, security, reliability, legal compliance or another documented purpose. CertFlow will not disclose Customer Personal Data to another Customer, except where the originating Customer has deliberately shared or published it through a Service feature or where law requires disclosure.
The confidentiality provisions in the Agreement apply in addition to this section. If there is a conflict, the provision that gives Customer Personal Data greater protection applies.
7. Security of Processing
Taking account of the state of the art, implementation cost, and the nature, scope, context, purposes and risks of the Processing, CertFlow will maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. The current baseline measures are described in Schedule 2.
CertFlow may update the measures as technology, threats and the Service change, provided that the overall level of protection for Customer Personal Data is not materially reduced during the Subscription Term. A measure applies only where relevant to the Processing and architecture. No internet service can eliminate all risk, and Schedule 2 does not create an absolute security warranty.
The Customer acknowledges the shared-responsibility measures in Schedule 2. CertFlow is not required to undermine another customer's security, disclose credentials or exploitable technical detail, or provide unrestricted access to production systems in order to demonstrate compliance.
8. Subprocessors and changes
8.1 General authorisation
The Customer gives CertFlow general written authorisation to engage the Subprocessors listed in Schedule 3. CertFlow will use a Subprocessor only for the part of the Service and categories of data reasonably required for that provider's function.
Before a Subprocessor Processes Customer Personal Data, CertFlow will put in place a written contract that imposes data-protection obligations providing materially the same protection as the obligations relevant to that Processing under this DPA, including appropriate security, confidentiality, deletion, assistance and transfer terms. CertFlow remains responsible to the Customer for the Subprocessor's performance of those obligations as required by Article 28(4).
8.2 Thirty-day notice and right to object
CertFlow will give at least 30 days' prior written notice before appointing a new or replacement Subprocessor that will materially Process Customer Personal Data. Notice may be sent by email or in-product message to the Customer contact and may also be published by updating Schedule 3. The notice will identify the provider, function and usual Processing location. If an urgent replacement is reasonably necessary for security, availability or law and 30 days is impracticable, CertFlow will give as much advance notice as possible and explain the reason.
The Customer may object before the appointment date on reasonable, documented data-protection grounds relating to its Customer Personal Data. The parties will work in good faith for up to 30 days to address the concern, including by additional safeguards, a commercially reasonable configuration or an alternative provider where available. An objection is not reasonable if based only on general preference, cost or competition.
If the parties cannot resolve a valid objection and CertFlow cannot provide the affected Service without that Subprocessor, the Customer may terminate only the affected Service or Order by written notice before the appointment takes effect, without an early-termination charge, and CertFlow will refund any prepaid Fees for the unused terminated period. Continued use after the appointment date, without a timely objection, confirms the Customer's authorisation.
8.3 Scope of the list
A provider is a Subprocessor only to the extent it Processes Customer Personal Data on CertFlow's behalf. Schedule 3 separately identifies services ordinarily used for CertFlow's own Controller activities or supplied directly to website visitors; listing those services for transparency does not authorise them to receive Customer Personal Data under this DPA.
9. Data Subject Requests
Taking account of the nature of the Processing, CertFlow will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to Data Subject Requests under Chapter III of the UK GDPR. This may include search, access, correction, restriction, export or deletion functions in the Service and reasonable additional assistance where the Customer cannot complete the response itself.
If CertFlow receives a Data Subject Request that clearly concerns Customer Personal Data, CertFlow will notify the Customer without undue delay and will not respond substantively except on the Customer's documented instruction or where law requires it. CertFlow may acknowledge receipt, verify enough information to route the request, tell the individual to contact the Customer, and preserve the request record.
The Customer remains responsible for deciding whether a right applies, verifying identity and authority, communicating with the individual, and meeting the statutory deadline. The Customer must give CertFlow the information and instruction reasonably needed in time for assistance. CertFlow may charge reasonable, agreed costs for unusually extensive manual assistance not caused by CertFlow's breach, but will not charge for normal self-service functions or assistance that Data Protection Laws require CertFlow to provide at its own cost.
10. Personal Data Breaches
CertFlow will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notice will be sent to the Customer's recorded security, privacy or workspace contact. The Customer is responsible for keeping those details current and monitoring them.
To the extent known at the time, the notice will describe: the nature of the breach; affected systems and data; categories and approximate numbers of Data Subjects and records where reasonably ascertainable; likely consequences; measures taken or proposed to contain, investigate and mitigate it; and an appropriate CertFlow contact. CertFlow may provide information in phases as the investigation develops and will not delay an initial notice solely because every fact is not yet known.
CertFlow will take reasonable steps to contain and remediate a breach within its control, preserve appropriate evidence, investigate the cause, and provide further information reasonably required for the Customer's assessment and notices. A notice is not an admission of fault or liability.
The Customer is responsible for deciding whether to notify the Information Commissioner's Office, another authority or affected individuals and for the content and timing of those notices. CertFlow will not notify affected individuals about Customer Personal Data unless instructed by the Customer or legally required. Where legally permitted, CertFlow will tell the Customer before making a required notice.
11. Security, impact-assessment and regulatory assistance
Taking account of the nature of the Processing and information available to it, CertFlow will provide reasonable assistance with the Customer's obligations under Articles 32 to 36, including security assessments, Personal Data Breach risk and notification, data protection impact assessments, and prior consultation with a Supervisory Authority.
Assistance may include relevant information from this DPA, completed security questionnaires, architecture or control descriptions at an appropriate level, information about a specific incident, and reasonable discussions with the Customer or authority. CertFlow may redact information that would expose another customer, privileged advice, confidential pricing, credentials or exploitable security detail, while providing a meaningful alternative where possible.
The Customer must identify the Processing and risk being assessed, provide reasonable notice, and first use information and self-service materials already made available. Any substantial bespoke assistance may be charged at reasonable rates agreed in advance unless it is required because CertFlow breached this DPA.
12. Records, information and audits
CertFlow will keep the records about Processor activities required by Article 30(2), cooperate with the Information Commissioner's Office as required by law, and make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 and this DPA.
The parties will normally use this DPA, Schedule 2, current Subprocessor information, security responses and any suitable independent assurance that CertFlow lawfully holds before requesting an inspection. No certification or audit report is promised unless expressly identified in a signed Order or supplied during due diligence.
If that information is insufficient, the Customer may audit CertFlow's relevant compliance itself or through an independent auditor that is not a competitor and is bound by confidentiality. Except following a material Personal Data Breach, a reasonable suspicion of material non-compliance, or a binding authority request, an audit is limited to once in any 12-month period, on at least 20 business days' written notice, during normal business hours and without unreasonable disruption.
The audit scope, duration, personnel, evidence handling and security rules must be agreed in advance. An audit must not access another customer's data, source code, credentials, penetration-test details or systems beyond what is reasonably necessary. CertFlow may provide redacted evidence or supervised access where that adequately demonstrates the control. The Customer will give CertFlow a copy of the findings and keep them confidential.
The Customer bears its and CertFlow's reasonable audit costs, except that CertFlow will bear its reasonable internal costs where the audit identifies a material breach of this DPA by CertFlow. Audit arrangements do not restrict a Supervisory Authority's powers or remove a mandatory right under Data Protection Laws. CertFlow will promptly inform the Customer if it believes an audit instruction infringes Data Protection Laws.
13. Government and authority requests
Unless prohibited by law, CertFlow will notify the Customer promptly of a legally binding request by a public authority for Customer Personal Data. CertFlow will review the request for apparent validity, seek clarification or narrowing where reasonably appropriate, and disclose only the data it is legally required to provide.
Where notice is prohibited, CertFlow will use reasonable efforts to obtain permission to notify and will document the request and response to the extent lawful. Nothing in this section requires CertFlow to bring proceedings, incur disproportionate cost, breach law or disclose privileged advice. Additional measures for requests connected with Restricted Transfers are in Schedule 4.
14. Return, deletion and backup expiry
14.1 Customer election
The Customer may use available export functions during the Subscription Term. During the 30-day export period after termination described in the Terms, the Customer may instruct CertFlow in writing either: (a) to return Customer Personal Data in the available standard export format and then delete CertFlow's remaining copies; or (b) to delete it without return. CertFlow will comply unless law requires retention.
If the Customer gives no election, CertFlow will treat that silence as an instruction to delete and will schedule Customer Personal Data in active systems for deletion within 90 days after termination. If the Customer elects return, CertFlow will provide the standard export within a reasonable period and schedule active deletion by the end of that same 90-day period, or promptly after a later return date agreed in writing. Additional transformation or migration services require prior agreement.
14.2 Protected backups and legally required retention
Deletion from active systems may not immediately remove Customer Personal Data from protected backups. Backup copies are isolated from ordinary business use, retained only for resilience, recovery, security and integrity, and expire when automatically deleted or overwritten at the end of the applicable configured backup lifecycle. CertFlow will not extend that lifecycle merely to retain data that the Customer instructed it to delete. If a backup is restored, the restored data remains subject to this DPA and previously deleted data will be isolated and deleted again before being returned to ordinary use where technically feasible.
If United Kingdom law requires CertFlow to retain particular Customer Personal Data, CertFlow will inform the Customer unless prohibited, identify the legal basis where appropriate, isolate the retained data from other Processing, protect it under this DPA, and delete it when the requirement ends. CertFlow may retain evidence that an instruction was completed, provided that evidence does not contain Customer Personal Data beyond what is legally necessary.
On written request after completion, CertFlow will confirm return or deletion at an appropriate organisational level. Data for which CertFlow is an independent Controller is retained under the Privacy Policy and is not governed by the Customer's election under this section.
15. Restricted Transfers
The Customer instructs CertFlow to make the transfers reasonably necessary to provide the Service using the locations and providers in Schedule 3, subject to the safeguards in Schedule 4. CertFlow will not make a Restricted Transfer of Customer Personal Data without an applicable adequacy regulation, appropriate safeguard or other lawful exception.
The fact that a service uses a global network does not by itself mean every Customer record is stored outside the United Kingdom. A Restricted Transfer may nevertheless occur through routing, support access, email delivery, mobile synchronization or a provider's downstream operations. CertFlow will assess the actual transfer rather than relying only on the provider's headquarters.
If the applicable transfer mechanism requires more information or a signature, the parties will complete the relevant UK International Data Transfer Agreement, UK Addendum or other instrument. Schedule 1 provides the Processing details, Schedule 2 the security measures, Schedule 3 the recipients and locations, and Schedule 4 the transfer rules for that purpose.
16. Liability, changes and general terms
The exclusions and aggregate liability cap in the Agreement apply to this DPA, and claims under this DPA count together with all other claims under the Agreement rather than creating a separate cap. Nothing limits an individual's rights, either party's regulatory responsibility to a Supervisory Authority, or liability that law does not allow to be limited.
CertFlow may update this DPA where reasonably necessary to reflect a change in Data Protection Laws, binding regulatory requirements or the Service, provided it does not materially reduce the protection of Customer Personal Data. CertFlow will give reasonable advance notice of a material change. Subprocessor changes remain subject to the specific 30-day process in section 8.
The governing law, jurisdiction, notices, assignment, third-party-rights, severability and entire-agreement provisions in the Terms apply to this DPA. If an applicable transfer instrument requires different law or forum, that instrument controls for the transfer only.
Questions may be sent to info@certflow.co.uk, telephoned to 0114 392 2407, or posted to CertFlow LTD, 20 Wenlock Road, London, N1 7GU. Instructions and objections under this DPA must be given in writing by an authorised Customer contact; a telephone instruction takes effect only when confirmed in writing. A Customer should use an agreed security contact for an urgent incident and should not send passwords, secret keys or unnecessary Personal Data by ordinary email.
Schedule 1 - Processing details
1. Subject matter, nature, purpose and duration
| Required detail | Description |
|---|---|
| Subject matter | Provision of the CertFlow hosted compliance, inspection, asset-management, workforce, commercial, client-portal, Network, mobile/offline and related support services selected by the Customer. |
| Nature and operations | Collection or receipt; recording; organisation; structuring; storage; hosting; adaptation and updating; retrieval; consultation; display; calculation; report and document generation; synchronization; transmission to authorised users, Customer-selected recipients and approved Subprocessors; backup; export; restriction; return; and deletion. |
| Purposes | To authenticate and authorise access; maintain the Customer workspace; manage organisations, people, sites, assets, jobs, inspections, certificates, qualifications, schedules, timesheets, documents, communications, client access, Network functions and commercial records; provide offline synchronization, maps, notifications and transactional email; support imports and exports; provide support; prevent abuse; maintain security, reliability, backups and recovery; and otherwise perform documented instructions under the Agreement. |
| Frequency | Recurring or continuous while the Service is used, with occasional manual access for authorised support, security, migration, incident response, return or deletion where necessary. |
| Duration | For the Subscription Term and the 30-day exit/export period, followed by return or active-system deletion as instructed and described in section 14. Protected backup copies remain only until expiry through the configured backup lifecycle, unless law requires a longer isolated retention. |
2. Categories of Data Subjects
- Customer owners, administrators, authorised users, employees, workers, agency staff, candidates, contractors, subcontractors, engineers, inspectors and trainees;
- the Customer's clients, prospective clients, suppliers, professional advisers, partners, Network contacts and their personnel;
- site owners, occupiers, duty holders, landlords, tenants, residents, visitors, witnesses, signatories and emergency contacts recorded by the Customer;
- individuals identified in assets, jobs, inspections, certificates, reports, risk assessments, incidents, training, competence, scheduling, HR, billing, support or communication records; and
- any other individual whose Personal Data the Customer lawfully submits within the intended scope of the Service.
3. Types of Personal Data
| Category | Examples, depending on Customer use |
|---|---|
| Identity and contact | Name, title, business and personal contact details, signature, photograph, profile image, emergency contact and internal identifiers. |
| Workspace and access | Organisation membership, role, permissions, user identifier, invitation status, authentication and session events, access history and audit references, to the extent Processed for the Customer rather than CertFlow as Controller. Plaintext passwords are not available to CertFlow. |
| Employment and competence | Employer, job title, trade, discipline, qualifications, training, accreditations, certificates, licences, experience, availability, working hours, timesheets, absence and on-call records. |
| Client, site, asset and job | Company and contact records, addresses, coordinates, access notes, appointment and assignment details, asset identifiers and condition, work orders, inspection observations, defects, remedial actions and service history. |
| Compliance and safety | Inspection and test results, risk assessments, method statements, COSHH and other safety records, compliance status, incident or non-conformance information, competency evidence and professional sign-off. |
| Documents and communications | Uploaded files, photographs, diagrams, plans, certificates, reports, notes, signatures, messages, forum content, support material and export files. |
| Commercial and financial administration | Quotes, invoices, purchase orders, line items, payment status, expenses, mileage, leads and customer-relationship records. Full payment-card numbers are not intended to be stored in Customer Data. |
| Technical and device | IP address, device and app details, timestamps, record identifiers, synchronization metadata, error information, security events and coarse or precise location where the Customer enables a location-dependent function. |
4. Special-category, criminal-offence and children's data
The Service is not designed around large-scale sensitive-data Processing, but Customer-configured HR, competence, occupational, incident, risk and health-and-safety records may contain health, disability, trade-union membership or other special-category data. Free-text fields and uploaded documents could also contain criminal-offence allegations or records. The exact content is determined by the Customer, not CertFlow.
The Customer must identify the Article 9 condition, any Data Protection Act 2018 Schedule 1 condition and policy-document requirement, and any Article 10 authority for that use. The Customer must not upload children's data or criminal-offence data unless necessary, lawful, within the intended Service and protected by proportionate access and retention settings.
5. Controller rights and obligations
The Customer retains all Controller rights and obligations in relation to Customer Personal Data, including determining purposes, lawful bases, transparency, accuracy, access, recipients and retention; issuing lawful instructions; responding to individuals; and supervising CertFlow. CertFlow receives no ownership of Customer Personal Data and has only the rights needed to perform the Agreement and this DPA.
Schedule 2 - Technical and organisational measures
| Control area | Current baseline measure |
|---|---|
| Access governance | Unique user accounts, organisation membership and role-based permissions are used to limit Service access. Customer administrators control user invitations and assigned roles. Privileged operational access is restricted to personnel and providers with a support, security or service need. |
| Authentication and sessions | Managed authentication handles credential verification and password hashing; CertFlow does not expose plaintext passwords. Authenticated sessions and expiring access tokens are used for Service and mobile synchronization requests. Customers remain responsible for credentials, devices, account sharing and prompt leaver removal. |
| Tenant and database controls | Customer records carry organisation or relationship scope. PostgreSQL row-level security policies and server-side functions enforce organisation, role, ownership, assignment and client-portal boundaries on protected tables. Public or deliberately shared functions expose only the fields intended for that feature. |
| Mobile and offline scope | PowerSync synchronization rules define the selected tables and records available to a signed-in mobile user, separately from database row-level policies; uploads return through authenticated Supabase operations so database policies apply. Offline records may remain on an authorised device, so the Customer must secure devices and remove application data when access ends. |
| Encryption and transmission | Managed hosting services protect network transmission using HTTPS/TLS and provide managed encryption at rest for hosted database, storage and backup services. Protected object access uses permission checks and, where implemented, time-limited signed links. |
| Secrets and service access | Service credentials and privileged keys are kept out of client-visible source where they would grant administrative access and are supplied through managed runtime secrets or environment configuration. Service-role operations are limited to server-side functions and operational purposes. |
| Logging and accountability | The platform records application audit entries for relevant business actions and uses authentication, service, deployment, synchronization and error logs appropriate to operation and investigation. Logging coverage and retention vary by event and do not imply that every user action or data view is recorded. |
| Availability and recovery | Production data uses managed backup and recovery measures designed for resilience. Backups are protected from ordinary user access and are not an on-demand Customer archive. Recovery and deletion are governed by section 14; Customers should export independent copies where professional or statutory retention requires them. |
| Network and delivery protection | Managed hosting, DNS and network providers supply traffic delivery, availability, abuse-prevention and denial-of-service protections. Access to non-public application functions requires authentication except for intentionally public endpoints, which are scoped and may be rate-limited or otherwise protected as appropriate. |
| Secure change management | Application code and database migrations are version controlled. Changes are reviewed and tested in proportion to risk before production deployment, with urgent security fixes handled through an expedited process. Dependencies and managed services are updated or replaced as reasonably required for security and compatibility. |
| Data minimisation and lifecycle | Features collect or expose only the fields configured for their purpose. Customer-controlled roles, scoped views, exports and deletion functions support minimisation. Active-system deletion and protected-backup expiry follow section 14. |
| Incident management | CertFlow maintains an operational process to identify, triage, contain, investigate, remediate and document suspected security incidents, preserve relevant evidence and give contractual Personal Data Breach notices. |
| Personnel and confidentiality | Authorised personnel are subject to confidentiality obligations, receive access on a need-to-know basis and are expected to follow relevant security and data-handling requirements. Access is removed when no longer required. |
| Supplier governance | Providers are selected according to their role and the data involved, placed under appropriate data-protection and confidentiality terms where they are Subprocessors, and reviewed when risk or material service changes warrant it. |
| Physical infrastructure | CertFlow does not rely on Customer Personal Data being stored on an office server. Physical data-centre and hardware controls are provided by the contracted managed infrastructure providers; CertFlow controls logical access to its Service environment. |
Customer shared-responsibility measures
- assign the least privilege reasonably needed and review workspace, client-portal and Network permissions regularly;
- use individual accounts, strong unique credentials and available authentication safeguards, and never share recovery links or administrative secrets;
- keep browsers, operating systems, mobile devices and networks supported, patched, locked and protected against malware;
- remove leavers and lost devices promptly, manage local and offline copies, and notify CertFlow of suspected compromise without delay;
- verify recipients, public-profile settings, generated reports, exports, integrations and email addresses before disclosure;
- minimise sensitive data, use structured restricted fields rather than public or unrestricted notes, and apply the Customer's retention schedule; and
- maintain independent exports or records where legal, professional, insurance or continuity requirements exceed the Service's operational backup purpose.
Schedule 3 - Current Subprocessors and service recipients
The Customer authorises the following providers as at 24 August 2026, subject to section 8. A provider name identifies the service brand and the applicable contracting entity in CertFlow's supplier agreement. A correction that does not change the entity or risk may be made without notice; a new contracting entity that materially changes the Processing or transfer risk is subject to section 8. A provider is a Subprocessor only for Processing it performs on CertFlow's behalf.
| Provider | Function and Customer Personal Data | Usual location and transfer position |
|---|---|---|
| Supabase | Core managed database, authentication, object storage, server functions, logs, backup and recovery. Depending on Customer use, this may include all categories in Schedule 1. | The primary CertFlow production project is configured in London, United Kingdom. Limited support, security and downstream provider operations may occur elsewhere; Schedule 4 applies to any Restricted Transfer. |
| Vercel | Hosting, deployment and delivery of the web application and website, request processing, operational logs, performance and aggregate analytics. Data may include Customer Personal Data transmitted through the hosted app, public Customer content and request/device metadata. | Global edge and service infrastructure, including the UK, EEA and United States. Customer records are not represented as being persistently stored at every edge location. Schedule 4 applies where Processing is a Restricted Transfer. |
| Journey Mobile / PowerSync | Managed offline synchronization for supported native/mobile use. Selected operational records scoped by synchronization rules, user and organisation identifiers, access tokens and synchronization metadata; binary inspection photographs are handled through Supabase storage rather than PowerSync. | Configured cloud region and provider/downstream operational locations, which may include the UK, EEA and other countries. Schedule 4 applies to any Restricted Transfer. |
| Resend | Transactional and service email delivery, such as invitations, recovery, notices and Customer-triggered messages. Recipient name and email address, subject and message content, secure links and delivery metadata. | United States and Resend downstream provider locations. CertFlow will rely on the UK-US data bridge only when the relevant recipient is actively certified and the transfer is in scope; otherwise an Article 46 safeguard under Schedule 4 is required. |
| Cloudflare | DNS, network delivery, availability, abuse prevention and denial-of-service/security services within the delivery chain. IP address, request headers, routing and security metadata, and transient request content where technically necessary. | Global network. Processing is limited to delivery and security functions; Schedule 4 applies to any Restricted Transfer. |
| OpenStreetMap / Nominatim | Optional mapping and geocoding. Site-address queries may be sent by a CertFlow server function to Nominatim; map-tile requests may be made directly from the user's browser to OpenStreetMap infrastructure. Data may include an address query, coordinates, requested tile, IP address and technical headers. This provider is a Subprocessor only to the extent it Processes that data on CertFlow's behalf; direct browser delivery may instead create a direct recipient relationship. | United Kingdom/EEA and distributed community service infrastructure. The feature is optional and no full Customer record is intentionally sent. Schedule 4 applies if a relevant request is a Restricted Transfer. |
Controller-side and direct third-party services
The following services are used ordinarily for CertFlow's independent Controller activities or a visitor's direct interaction, not as Customer Personal Data Subprocessors under this DPA:
| Service | Ordinary role and boundary |
|---|---|
| Stripe | Subscription checkout, billing, fraud prevention and payment administration for CertFlow. Stripe may act as an independent Controller for parts of payment processing. CertFlow does not receive full payment-card details. Stripe is not authorised by this entry to receive Customer Personal Data from a workspace. |
| Web3Forms | Delivery of forms submitted on CertFlow's public website, such as contact, download or calculator requests. CertFlow determines those public-site purposes as Controller; the service is not ordinarily part of Customer workspace Processing. |
| Calendly | An optional public-site demo-booking experience chosen and loaded by the visitor. Booking data is handled for CertFlow's sales administration and under Calendly's own service terms, not on a Customer's behalf. |
| Google Tag Manager / Google Analytics | Optional public-website tag delivery and analytics after the visitor's consent. CertFlow acts as Controller for that measurement. These tools are not used by virtue of this DPA to analyse Customer Personal Data in a workspace. |
If a future integration causes one of these controller-side services to Process Customer Personal Data on CertFlow's behalf, CertFlow will treat it as a Subprocessor and follow section 8 before that Processing begins. If the Customer independently connects, exports or directs Customer Personal Data to its own third-party account, that recipient is selected by the Customer and is not CertFlow's Subprocessor solely because the Service enabled the transfer.
Schedule 4 - International-transfer safeguards
1. Transfer principles and hierarchy
CertFlow will identify whether a Processing location or remote-access arrangement creates a Restricted Transfer under the law applicable to the exporter. Where more than one mechanism is available, CertFlow may use a lawful mechanism appropriate to the recipient and data, following this order where applicable:
- UK adequacy regulations. A transfer may rely on a current United Kingdom adequacy regulation only while the destination, recipient and data remain within its scope.
- UK-US data bridge. A transfer to the United States may rely on the UK Extension to the EU-US Data Privacy Framework only while the particular recipient is actively certified, the relevant data is covered and all applicable conditions are met. A provider's participation in another framework or an expired certification is not enough.
- Article 46 safeguard. In the absence of applicable adequacy, CertFlow will use the ICO International Data Transfer Agreement, the UK Addendum to the European Commission Standard Contractual Clauses, binding corporate rules or another safeguard recognised by Data Protection Laws.
- Exception. An Article 49 exception will be used only where legally available for the specific transfer and will not be treated as the ordinary basis for repetitive Service transfers.
2. Transfer risk assessment and supplementary measures
Before relying on an Article 46 safeguard, CertFlow or the relevant Subprocessor will complete the required transfer risk assessment or data protection test. The assessment will consider the data and format, purpose, destination laws and practices, recipient, access likelihood, onward transfers and available technical, contractual and organisational protections. It will be reviewed when a material change calls the conclusion into question.
Supplementary measures will be applied where reasonably necessary to ensure that the protection is not materially lower than under United Kingdom Data Protection Laws. Depending on the transfer, these may include data minimisation, encryption in transit and at rest, access controls, pseudonymisation, regional storage, limited support access, logging, confidentiality, challenge and transparency commitments, and deletion limits.
3. Contractual transfer mechanism
Where CertFlow receives a Restricted Transfer directly from the Customer and no adequacy regulation applies, the parties will enter into or incorporate the then-current ICO-approved transfer mechanism identified in the Order or reasonably selected for the transfer. If the UK Addendum is used, the underlying EU Standard Contractual Clauses and correct controller-to-processor or processor-to-processor module will be selected according to the parties' actual roles.
For a Restricted Transfer from CertFlow to a Subprocessor, CertFlow will put the appropriate mechanism in its agreement with that Subprocessor. Customer Personal Data, Data Subjects, purposes, duration, security measures and recipients are described in Schedules 1 to 3, supplemented by the provider-specific details in that mechanism.
If a mandatory term conflicts with this DPA, the mandatory transfer term prevails for the affected transfer. If a mechanism is invalidated, amended or no longer sufficient, the parties will cooperate promptly to implement a valid replacement. CertFlow may suspend the affected transfer or feature until a lawful solution is in place.
4. Onward transfers and public-authority access
A Subprocessor may make an onward transfer only for the authorised Service, under a lawful transfer mechanism and protections no less protective than those required for its Processing. CertFlow will require relevant Subprocessors to limit access to authorised personnel and to flow applicable transfer restrictions to downstream processors.
Where lawful and reasonably possible, CertFlow will require a recipient to review a public-authority request for validity, challenge or narrow disproportionate requests, disclose only what is legally required, document the response and notify CertFlow so that CertFlow can notify the Customer. If notice is prohibited, the recipient should use reasonable efforts to obtain permission and provide lawful aggregate transparency.
The Customer will provide information and cooperation reasonably needed to complete a transfer assessment and will not instruct a transfer that it knows lacks a valid mechanism. On request, CertFlow will provide information about the applicable safeguard, subject to redaction of confidential commercial terms, privileged advice and security-sensitive material.
5. EEA and other export laws
This DPA is drafted principally for United Kingdom law. If the EU GDPR or another export law also applies to Customer Personal Data, the parties will apply its mandatory Processor and transfer requirements to that data. Where an EEA Restricted Transfer requires the European Commission Standard Contractual Clauses, the parties will execute or incorporate the correct module and annexes; this Schedule does not silently select optional clauses or a module inconsistent with the parties' actual roles.