This Data Processing Agreement (“DPA”) forms part of the agreement
between a ServiceFlowOS business customer (“the Controller”) and
Michael Wood Web & Automation
(“the Processor”) where the Processor processes personal data on
the Controller's behalf through ServiceFlowOS or related hosted
services.
This DPA is intended to set out the parties' responsibilities
under applicable UK data-protection law, including the UK GDPR
and the Data Protection Act 2018.
This public DPA applies alongside the client's signed ServiceFlowOS
agreement. A separately signed DPA may be provided where a client
requires organisation-specific details.
1. Roles of the parties
The Controller decides why and how personal data relating to its
customers, staff, suppliers, contacts and other individuals is
collected and used.
The Processor processes that personal data only to provide,
host, secure, maintain, support and improve the contracted
ServiceFlowOS services.
2. Subject matter and duration
The subject matter is the processing of personal data necessary
to provide the Controller's ServiceFlowOS installation and any
associated hosting, support, maintenance, backup, email-delivery,
website or integration services.
3. Nature and purpose of processing
- Hosting and operating ServiceFlowOS.
- Authenticating users and maintaining security.
- Generating quotes, invoices, receipts and other documents.
- Sending authorised transactional emails.
- Providing support and troubleshooting.
- Maintaining backups and disaster-recovery capability.
- Applying software maintenance and security updates.
- Providing agreed integrations and data exports.
4. Categories of data subjects
- Customers and prospective customers.
- Client staff, contractors and authorised users.
- Customer contacts, site contacts and drivers.
- Suppliers and business partners.
- People named in quotes, jobs, invoices or documents.
- Website visitors and people making enquiries.
5. Types of personal data
- Names, job titles and business names.
- Email addresses, telephone numbers and postal addresses.
- Customer, site and contact records.
- Account usernames, roles and authentication records.
- Quotes, jobs, invoices, notes and correspondence.
- Vehicle, collection, delivery or operational information.
- Uploaded documents, signatures and photographs.
- Payment status and transaction references.
- IP addresses, timestamps, audit records and security logs.
- Other information the Controller chooses to enter.
6. Special-category and high-risk data
ServiceFlowOS is not designed as a general-purpose repository for
special-category data, criminal-offence data, children's data or
highly sensitive personal information unless specifically agreed.
7. Controller instructions
The Processor will process personal data only on documented
instructions from the Controller, including instructions contained
in the service agreement, this DPA, authorised platform use and
support requests.
8. Controller obligations
- Process personal data lawfully, fairly and transparently.
- Provide appropriate privacy information to data subjects.
- Identify valid lawful bases and required conditions.
- Keep data accurate and remove it when no longer required.
- Control user access and maintain internal security.
- Handle rights requests and regulatory communications.
- Notify the Processor promptly of suspected compromise or misuse.
9. Confidentiality
The Processor will ensure that people authorised to process
Controller personal data are subject to appropriate confidentiality
obligations.
10. Security measures
- HTTPS encryption in transit.
- Password hashing and secure session handling.
- Role-based and restricted administrative access.
- CSRF and input-validation protections.
- Prepared database queries and access controls.
- Software maintenance and security patching.
- Logging, monitoring and incident investigation.
- Routine backups and recovery procedures.
- Secure hosting and infrastructure controls.
11. Sub-processors
The Controller gives general written authorisation for the
Processor to use sub-processors reasonably necessary to provide
the services.
- Cloud and website hosting providers.
- Database, backup and infrastructure providers.
- Email hosting and transactional email providers.
- Domain registration and DNS providers.
- Payment processors.
- Monitoring, security or support providers.
- Approved third-party integrations.
12. International transfers
The Processor will not knowingly transfer Controller personal
data outside the UK except where an appropriate lawful transfer
mechanism applies.
13. Data-subject rights
The Processor will provide reasonable assistance to help the
Controller respond to valid requests for access, correction,
deletion, restriction, objection or portability.
14. Personal-data breaches
The Processor will notify the Controller without undue delay
after becoming aware of a confirmed personal-data breach affecting
Controller personal data.
15. Data-protection impact assessments
The Processor will provide reasonable information and assistance
needed for the Controller's data-protection impact assessment or
prior consultation obligations.
16. Audits and compliance information
The Processor will make available information reasonably necessary
to demonstrate compliance with this DPA.
17. Return and deletion
On termination, the Controller may request a reasonable export of
available personal data before account closure.
After the agreed closure or export period, the Processor will
delete or anonymise live Controller personal data unless retention
is legally required. Data may remain temporarily in backups until
those backups are rotated.
18. Business continuity and backups
The Processor will use reasonable backup and recovery arrangements
where included in the service.
19. Liability
Liability under this DPA is subject to the exclusions and
limitations contained in the applicable ServiceFlowOS agreement
or Terms of Service, except where prohibited by law.
20. Priority
If this DPA conflicts with general service terms about the
processing of Controller personal data, this DPA takes priority
for that processing.
21. Governing law
This DPA is governed by the laws of England and Wales.
Contact
Questions about this DPA can be sent to
hello@serviceflowos.co.uk .