Data Processing Agreement
Last updated: 6 August 2026
1. Introduction and Incorporation
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between BureauFlow Limited, a company registered in England and Wales (company number 17378706) (“BureauFlow”, “we”, “us”), and the customer (“Customer”, “you”).
It applies where you act as a data controller of personal data that you enter into the Service and BureauFlow processes that data on your behalf as a data processor under the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.
2. Definitions
“Personal data”, “controller”, “processor”, “processing”, “data subject”, and “personal data breach” have the meanings given in the UK GDPR. “Customer Data” means personal data that you (or users acting on your behalf) enter into the Service and for which you act as controller — in particular, data relating to your payroll clients and their employees. “Service” has the meaning given in the Terms of Service.
3. Details of Processing
Subject matter: the provision of the Service to the Customer.
Duration: for the duration of the Customer’s agreement with BureauFlow, followed by the applicable post-termination retention period described in the Terms of Service.
Nature and purpose: storage, organisation, retrieval, and display of Customer Data; deadline and compliance tracking; and optional AI-assisted features where used by the Customer — in each case solely to provide the Service.
Data subjects: the Customer’s payroll clients’ contacts and those clients’ employees.
Categories of personal data: may include names, contact information, employer and employee identifiers, payroll configuration data, PAYE references, and other information entered into the Service by the Customer.
4. Processor Obligations
BureauFlow will:
- process Customer Data only on the Customer’s documented instructions, which comprise the Terms of Service, this DPA, and the Customer’s use of the features of the Service, unless required to process otherwise by law (in which case we will inform you unless the law prevents it);
- ensure that persons authorised to process Customer Data are bound by obligations of confidentiality;
- implement appropriate technical and organisational measures as described in the Annex to this DPA, in accordance with Article 32 UK GDPR;
- taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures in responding to data subject requests, and assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 UK GDPR;
- notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data.
5. Sub-Processors
The Customer provides general written authorisation for BureauFlow to engage sub-processors to support the provision of the Service. The authoritative current sub-processor list is maintained in Section 5 of our Privacy Policy.
We will update that list at least 14 days before a new sub-processor begins processing Customer Data. The Customer may object to a new sub-processor in writing to support@bureauflow.co.uk on reasonable data-protection grounds; if the objection cannot be resolved, the Customer may terminate its agreement in accordance with the Terms of Service.
Where we engage a sub-processor, we impose data protection obligations on it that are materially equivalent to those in this DPA, and we remain responsible for its performance.
6. International Transfers
Where Customer Data is transferred outside the United Kingdom, we ensure the transfer is protected by appropriate safeguards recognised under UK GDPR, including the ICO’s International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, or an applicable adequacy decision.
7. Return and Deletion of Customer Data
On termination of the Customer’s agreement, Customer Data remains available for export and is then deleted in accordance with the retention periods set out in the Terms of Service and Privacy Policy, except where law requires longer retention.
8. Audit and Information
BureauFlow will make available information reasonably necessary to demonstrate compliance with Article 28 UK GDPR. Where reasonably required, and subject to appropriate confidentiality obligations and reasonable notice, the parties may agree an audit process.
9. Liability and Governing Law
Liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service, except where applicable data protection law provides otherwise. This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Annex: Technical and Organisational Measures
- Encryption in transit (TLS 1.2+, HTTPS with strict transport security) and at rest (AES-256)
- Logical tenant isolation, with database row-level security policies as a second layer of defence
- Access controls: strong password requirements, email verification, role-based permissions, session tokens with automatic rotation, and immediate deactivation/revocation of user access
- Audit logging of changes to client records, payroll configurations, and settings
- Encrypted, redundant daily backups with documented restore procedures tested via live recovery drill
- Automated dependency vulnerability scanning and a scheduled weekly security audit
- Security headers (Content Security Policy, HSTS, clickjacking protection) on every response
- Rate limiting on authentication and sensitive endpoints, and CSRF protection on data-changing requests
Questions about this DPA can be sent to support@bureauflow.co.uk.