This is a comprehensive UK and EU-oriented website template, not a substitute for advice from a solicitor or data-protection professional. Replace every highlighted field with the company’s real legal name, company number, registered office, privacy email and service-specific information before launch.
Scope and order of priority
This Data Processing Addendum applies where SecureFlowGroup processes customer personal data on behalf of a customer in connection with the services. It supplements the Terms, order form or other written agreement between the parties.
If there is a conflict about processing customer personal data, this Addendum takes priority, followed by the order form and then the general Terms, unless the parties expressly agree otherwise in writing.
Roles and documented instructions
The customer is the controller and SecureFlowGroup is the processor for customer personal data, except where either party independently determines purposes and means and therefore acts as a separate controller.
SecureFlowGroup will process customer personal data only on documented instructions, including the agreement, customer configuration, support requests and lawful use of features. If SecureFlowGroup believes an instruction infringes applicable data-protection law, it will inform the customer unless prohibited by law and may pause the affected processing.
Processing details
| Subject matter | Provision, security, support and improvement of the contracted website-protection services. |
|---|---|
| Duration | For the agreement term plus the limited return, deletion, backup and legal-retention periods described below. |
| Nature and purpose | Hosting, collection, transmission, classification, detection, logging, analysis, alerting, support, backup, deletion and authorised incident response. |
| Types of personal data | Business contact details, user identifiers, authentication records, IP addresses, device data, request and event logs, support content, security findings and personal data incidentally present in authorised website traffic. |
| Categories of people | Customer personnel, account users, website visitors, end users, customers of the customer, contractors, support contacts and other people whose data appears in authorised systems. |
| Special categories | Not intentionally required. The customer must avoid submitting special-category or criminal-offence data unless specifically agreed and lawfully protected. |
Compliance with law
Each party will comply with the data-protection law that applies to it, including the UK GDPR, Data Protection Act 2018 as amended, EU GDPR where applicable, and relevant national implementing laws. The customer is responsible for lawful instructions, transparency, lawful bases, data accuracy, data minimisation and responding to people whose information it controls.
SecureFlowGroup will not combine customer personal data with information obtained from another source for unrelated advertising, sell it, or use it to train a general-purpose public AI model unless the customer gives specific written permission and the use is lawful.
Confidentiality and access
SecureFlowGroup will ensure people authorised to process customer personal data are subject to confidentiality duties and receive appropriate privacy and security training. Access will be limited according to role, need and least privilege, reviewed periodically and removed when no longer required.
Security measures
SecureFlowGroup will maintain technical and organisational measures appropriate to the risk, service and available technology. Measures should include, as applicable:
- Encryption in transit and at rest where appropriate.
- Strong authentication, multi-factor authentication and role-based access.
- Network segregation, environment separation and controlled administrative access.
- Secure development, code review, dependency management and vulnerability remediation.
- Logging, monitoring, anomaly detection and incident-response procedures.
- Business continuity, protected backups and tested restoration processes.
- Supplier due diligence, contractual controls and periodic risk review.
- Data minimisation, configurable retention and secure deletion.
- Personnel screening where lawful and proportionate, confidentiality and training.
Detailed measures may be set out in a security schedule or trust centre. SecureFlowGroup may update measures provided the overall protection is not materially reduced.
Personal data breaches
SecureFlowGroup will notify the customer without undue delay after becoming aware of a confirmed personal data breach affecting customer personal data. Notice will include available information about the nature of the breach, likely consequences, affected data and people, containment and recommended actions.
SecureFlowGroup will take reasonable steps to contain, investigate and remediate the breach and will provide information reasonably needed for the customer’s regulatory and individual notifications. Notification is not an admission of fault or liability.
Subprocessors
The customer gives general authorisation for SecureFlowGroup to use subprocessors needed to provide the service. SecureFlowGroup will maintain an up-to-date list, perform proportionate due diligence and impose written data-protection duties offering a level of protection materially equivalent to this Addendum.
SecureFlowGroup will provide advance notice of a new subprocessor where required. A customer may object on reasonable data-protection grounds within the stated notice period. The parties will work in good faith on a solution; if none is reasonably available, the customer may terminate the affected service.
Add the live subprocessor list URL and notice period before publication: [SUBPROCESSOR PAGE / NOTICE PERIOD].
International transfers
SecureFlowGroup will not make a restricted transfer of customer personal data without an approved legal mechanism. Depending on the transfer, this may include UK adequacy regulations, an EU adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses.
The parties will complete transfer-risk assessments and apply supplementary safeguards where required. If a transfer mechanism is replaced or invalidated, the parties will cooperate to implement a valid alternative. Applicable standard clauses are incorporated by reference to the extent needed and take priority over conflicting terms.
Data-subject requests
Taking account of the nature of the processing, SecureFlowGroup will provide reasonable assistance through technical and organisational measures so the customer can respond to requests for access, correction, deletion, restriction, objection, portability or rights relating to automated decisions.
If SecureFlowGroup receives a request relating to customer personal data, it will redirect the requester to the customer and will not respond substantively unless authorised or legally required.
Compliance assistance
SecureFlowGroup will provide reasonable information and assistance for data-protection impact assessments, prior consultation with regulators, security obligations, breach assessment and customer complaints, taking account of the processing and information available to SecureFlowGroup.
Assistance beyond standard service capabilities may be chargeable at agreed professional-services rates unless it is needed because SecureFlowGroup breached this Addendum.
Information and audits
SecureFlowGroup will make available information reasonably necessary to demonstrate compliance, which may include independent reports, certifications, security documentation and questionnaire responses.
Where that information is insufficient, the customer may request an audit no more than once per year, or more often following a material breach or regulator request. Audits must be proportionate, confidential, avoid disruption, respect other customers’ information and normally use an independent qualified auditor. The customer bears reasonable audit costs unless the audit identifies a material SecureFlowGroup breach.
Return and deletion
At the customer’s choice and subject to product functionality, SecureFlowGroup will return or delete customer personal data after termination. SecureFlowGroup may retain information where required by law, for legal claims, or in protected backups that cannot reasonably be isolated, provided retained data remains protected and is not used for another purpose.
The production deletion period and backup expiry period must be stated in the order or trust centre: [PRODUCTION DELETION PERIOD] and [BACKUP EXPIRY PERIOD].
Liability and contact
Liability under this Addendum is subject to the liability terms in the main agreement except where applicable law or incorporated standard contractual clauses require otherwise.
Data-protection notices should be sent to [PRIVACY EMAIL]. The parties should insert the names, addresses, registration details and signatures required for the actual contract before relying on this Addendum.