← Back to home

Data Processing Agreement

Last updated: 6 August 2026

1. Introduction and Incorporation

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between BureauFlow Limited, a company registered in England and Wales (company number 17378706) (“BureauFlow”, “we”, “us”), and the customer (“Customer”, “you”).

It applies where you act as a data controller of personal data that you enter into the Service and BureauFlow processes that data on your behalf as a data processor under the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.

2. Definitions

“Personal data”, “controller”, “processor”, “processing”, “data subject”, and “personal data breach” have the meanings given in the UK GDPR. “Customer Data” means personal data that you (or users acting on your behalf) enter into the Service and for which you act as controller — in particular, data relating to your payroll clients and their employees. “Service” has the meaning given in the Terms of Service.

3. Details of Processing

Subject matter: the provision of the Service to the Customer.

Duration: for the duration of the Customer’s agreement with BureauFlow, followed by the applicable post-termination retention period described in the Terms of Service.

Nature and purpose: storage, organisation, retrieval, and display of Customer Data; deadline and compliance tracking; and optional AI-assisted features where used by the Customer — in each case solely to provide the Service.

Data subjects: the Customer’s payroll clients’ contacts and those clients’ employees.

Categories of personal data: may include names, contact information, employer and employee identifiers, payroll configuration data, PAYE references, and other information entered into the Service by the Customer.

4. Processor Obligations

BureauFlow will:

5. Sub-Processors

The Customer provides general written authorisation for BureauFlow to engage sub-processors to support the provision of the Service. The authoritative current sub-processor list is maintained in Section 5 of our Privacy Policy.

We will update that list at least 14 days before a new sub-processor begins processing Customer Data. The Customer may object to a new sub-processor in writing to support@bureauflow.co.uk on reasonable data-protection grounds; if the objection cannot be resolved, the Customer may terminate its agreement in accordance with the Terms of Service.

Where we engage a sub-processor, we impose data protection obligations on it that are materially equivalent to those in this DPA, and we remain responsible for its performance.

6. International Transfers

Where Customer Data is transferred outside the United Kingdom, we ensure the transfer is protected by appropriate safeguards recognised under UK GDPR, including the ICO’s International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, or an applicable adequacy decision.

7. Return and Deletion of Customer Data

On termination of the Customer’s agreement, Customer Data remains available for export and is then deleted in accordance with the retention periods set out in the Terms of Service and Privacy Policy, except where law requires longer retention.

8. Audit and Information

BureauFlow will make available information reasonably necessary to demonstrate compliance with Article 28 UK GDPR. Where reasonably required, and subject to appropriate confidentiality obligations and reasonable notice, the parties may agree an audit process.

9. Liability and Governing Law

Liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service, except where applicable data protection law provides otherwise. This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

Annex: Technical and Organisational Measures

Questions about this DPA can be sent to support@bureauflow.co.uk.