Legal

Data Processing Agreement

Last updated: 23 July 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between a ServiceFlowOS business customer (“the Controller”) and Michael Wood Web & Automation (“the Processor”) where the Processor processes personal data on the Controller's behalf through ServiceFlowOS or related hosted services.

This DPA is intended to set out the parties' responsibilities under applicable UK data-protection law, including the UK GDPR and the Data Protection Act 2018.

This public DPA applies alongside the client's signed ServiceFlowOS agreement. A separately signed DPA may be provided where a client requires organisation-specific details.

1. Roles of the parties

The Controller decides why and how personal data relating to its customers, staff, suppliers, contacts and other individuals is collected and used.

The Processor processes that personal data only to provide, host, secure, maintain, support and improve the contracted ServiceFlowOS services.

2. Subject matter and duration

The subject matter is the processing of personal data necessary to provide the Controller's ServiceFlowOS installation and any associated hosting, support, maintenance, backup, email-delivery, website or integration services.

3. Nature and purpose of processing

  • Hosting and operating ServiceFlowOS.
  • Authenticating users and maintaining security.
  • Generating quotes, invoices, receipts and other documents.
  • Sending authorised transactional emails.
  • Providing support and troubleshooting.
  • Maintaining backups and disaster-recovery capability.
  • Applying software maintenance and security updates.
  • Providing agreed integrations and data exports.

4. Categories of data subjects

  • Customers and prospective customers.
  • Client staff, contractors and authorised users.
  • Customer contacts, site contacts and drivers.
  • Suppliers and business partners.
  • People named in quotes, jobs, invoices or documents.
  • Website visitors and people making enquiries.

5. Types of personal data

  • Names, job titles and business names.
  • Email addresses, telephone numbers and postal addresses.
  • Customer, site and contact records.
  • Account usernames, roles and authentication records.
  • Quotes, jobs, invoices, notes and correspondence.
  • Vehicle, collection, delivery or operational information.
  • Uploaded documents, signatures and photographs.
  • Payment status and transaction references.
  • IP addresses, timestamps, audit records and security logs.
  • Other information the Controller chooses to enter.

6. Special-category and high-risk data

ServiceFlowOS is not designed as a general-purpose repository for special-category data, criminal-offence data, children's data or highly sensitive personal information unless specifically agreed.

7. Controller instructions

The Processor will process personal data only on documented instructions from the Controller, including instructions contained in the service agreement, this DPA, authorised platform use and support requests.

8. Controller obligations

  • Process personal data lawfully, fairly and transparently.
  • Provide appropriate privacy information to data subjects.
  • Identify valid lawful bases and required conditions.
  • Keep data accurate and remove it when no longer required.
  • Control user access and maintain internal security.
  • Handle rights requests and regulatory communications.
  • Notify the Processor promptly of suspected compromise or misuse.

9. Confidentiality

The Processor will ensure that people authorised to process Controller personal data are subject to appropriate confidentiality obligations.

10. Security measures

  • HTTPS encryption in transit.
  • Password hashing and secure session handling.
  • Role-based and restricted administrative access.
  • CSRF and input-validation protections.
  • Prepared database queries and access controls.
  • Software maintenance and security patching.
  • Logging, monitoring and incident investigation.
  • Routine backups and recovery procedures.
  • Secure hosting and infrastructure controls.

11. Sub-processors

The Controller gives general written authorisation for the Processor to use sub-processors reasonably necessary to provide the services.

  • Cloud and website hosting providers.
  • Database, backup and infrastructure providers.
  • Email hosting and transactional email providers.
  • Domain registration and DNS providers.
  • Payment processors.
  • Monitoring, security or support providers.
  • Approved third-party integrations.

12. International transfers

The Processor will not knowingly transfer Controller personal data outside the UK except where an appropriate lawful transfer mechanism applies.

13. Data-subject rights

The Processor will provide reasonable assistance to help the Controller respond to valid requests for access, correction, deletion, restriction, objection or portability.

14. Personal-data breaches

The Processor will notify the Controller without undue delay after becoming aware of a confirmed personal-data breach affecting Controller personal data.

15. Data-protection impact assessments

The Processor will provide reasonable information and assistance needed for the Controller's data-protection impact assessment or prior consultation obligations.

16. Audits and compliance information

The Processor will make available information reasonably necessary to demonstrate compliance with this DPA.

17. Return and deletion

On termination, the Controller may request a reasonable export of available personal data before account closure.

After the agreed closure or export period, the Processor will delete or anonymise live Controller personal data unless retention is legally required. Data may remain temporarily in backups until those backups are rotated.

18. Business continuity and backups

The Processor will use reasonable backup and recovery arrangements where included in the service.

19. Liability

Liability under this DPA is subject to the exclusions and limitations contained in the applicable ServiceFlowOS agreement or Terms of Service, except where prohibited by law.

20. Priority

If this DPA conflicts with general service terms about the processing of Controller personal data, this DPA takes priority for that processing.

21. Governing law

This DPA is governed by the laws of England and Wales.

Contact

Questions about this DPA can be sent to hello@serviceflowos.co.uk .

Direct, UK-based support

Work directly with the developer behind the platform.

No anonymous software company, outsourced support team or complicated chain of account managers. ServiceFlowOS is developed and supported directly by Michael Wood | Web & Automation.

Reviews displayed above were left for Michael Wood | Web & Automation, the independent UK business responsible for designing, developing and supporting ServiceFlowOS.

Hi, I'm Michael

Questions about ServiceFlowOS?

I'm usually available on WhatsApp if you'd like to ask anything before booking a demo.

Message me
WhatsApp Michael