secureflowgroup
Protection platformContinuous website defence Website scannerFind vulnerabilities and malware AI threat analysis NewPrioritise real security risk Live security eventsSee every block and alert Automated responseContain threats in seconds Security integrationsConnect your existing stack Protection playbooks NewLaunch proven security controls Security updatesSee the latest improvements
FeaturedContinuous website protection

Monitor, block and recover from web threats from one clear platform.

Explore protection →
Security resource hubPractical website protection advice DocumentationSetup and protection guides API referenceEvents, alerts and integrations Threat insightsUnderstand emerging web risk Security guidesStep-by-step hardening playbooks Customer storiesSee how teams reduce exposure Security communityLearn with other site owners Support centreGet help from real people
Popular guideHarden your website in 30 minutes

A practical checklist for safer forms, logins, payments and admin access.

Read guide →
Company overviewWho we protect and why AboutWhy we built SecureFlowGroup TeamMeet the security specialists Careers HiringJoin our security team PressNews and media resources PartnersProtect customers together Trust centreHow we protect your data ContactTalk to the right team
PricingCareers Hiring
Client loginProtect my site
ProtectionResourcesCompanyPricingCareers HiringClient loginProtect my site
Legal & compliance
UK GDPREU GDPRSCCs / IDTA

Data Processing Addendum

The processor terms governing how SecureFlowGroup handles customer personal data when delivering website-protection services.

Last updated: 28 July 2026Applies where SecureFlowGroup processes data for a customer
Privacy Terms Cookies Acceptable use Data processing
On this pageScope and order of priorityRoles and instructionsProcessing detailsCompliance with lawConfidentiality and accessSecurity measuresPersonal data breachesSubprocessorsInternational transfersData-subject requestsCompliance assistanceInformation and auditsReturn and deletionLiability and contact
Need help?

Questions about these terms can be sent through our contact page.

Contact SecureFlowGroup →
Complete these details before publishing

This is a comprehensive UK and EU-oriented website template, not a substitute for advice from a solicitor or data-protection professional. Replace every highlighted field with the company’s real legal name, company number, registered office, privacy email and service-specific information before launch.

Legal name: [SECUREFLOWGROUP LEGAL ENTITY] Company number: [COMPANY NUMBER] Registered office: [REGISTERED OFFICE] Legal email: [LEGAL EMAIL]

Scope and order of priority

This Data Processing Addendum applies where SecureFlowGroup processes customer personal data on behalf of a customer in connection with the services. It supplements the Terms, order form or other written agreement between the parties.

If there is a conflict about processing customer personal data, this Addendum takes priority, followed by the order form and then the general Terms, unless the parties expressly agree otherwise in writing.

Roles and documented instructions

The customer is the controller and SecureFlowGroup is the processor for customer personal data, except where either party independently determines purposes and means and therefore acts as a separate controller.

SecureFlowGroup will process customer personal data only on documented instructions, including the agreement, customer configuration, support requests and lawful use of features. If SecureFlowGroup believes an instruction infringes applicable data-protection law, it will inform the customer unless prohibited by law and may pause the affected processing.

Processing details

Subject matterProvision, security, support and improvement of the contracted website-protection services.
DurationFor the agreement term plus the limited return, deletion, backup and legal-retention periods described below.
Nature and purposeHosting, collection, transmission, classification, detection, logging, analysis, alerting, support, backup, deletion and authorised incident response.
Types of personal dataBusiness contact details, user identifiers, authentication records, IP addresses, device data, request and event logs, support content, security findings and personal data incidentally present in authorised website traffic.
Categories of peopleCustomer personnel, account users, website visitors, end users, customers of the customer, contractors, support contacts and other people whose data appears in authorised systems.
Special categoriesNot intentionally required. The customer must avoid submitting special-category or criminal-offence data unless specifically agreed and lawfully protected.

Compliance with law

Each party will comply with the data-protection law that applies to it, including the UK GDPR, Data Protection Act 2018 as amended, EU GDPR where applicable, and relevant national implementing laws. The customer is responsible for lawful instructions, transparency, lawful bases, data accuracy, data minimisation and responding to people whose information it controls.

SecureFlowGroup will not combine customer personal data with information obtained from another source for unrelated advertising, sell it, or use it to train a general-purpose public AI model unless the customer gives specific written permission and the use is lawful.

Confidentiality and access

SecureFlowGroup will ensure people authorised to process customer personal data are subject to confidentiality duties and receive appropriate privacy and security training. Access will be limited according to role, need and least privilege, reviewed periodically and removed when no longer required.

Security measures

SecureFlowGroup will maintain technical and organisational measures appropriate to the risk, service and available technology. Measures should include, as applicable:

  • Encryption in transit and at rest where appropriate.
  • Strong authentication, multi-factor authentication and role-based access.
  • Network segregation, environment separation and controlled administrative access.
  • Secure development, code review, dependency management and vulnerability remediation.
  • Logging, monitoring, anomaly detection and incident-response procedures.
  • Business continuity, protected backups and tested restoration processes.
  • Supplier due diligence, contractual controls and periodic risk review.
  • Data minimisation, configurable retention and secure deletion.
  • Personnel screening where lawful and proportionate, confidentiality and training.

Detailed measures may be set out in a security schedule or trust centre. SecureFlowGroup may update measures provided the overall protection is not materially reduced.

Personal data breaches

SecureFlowGroup will notify the customer without undue delay after becoming aware of a confirmed personal data breach affecting customer personal data. Notice will include available information about the nature of the breach, likely consequences, affected data and people, containment and recommended actions.

SecureFlowGroup will take reasonable steps to contain, investigate and remediate the breach and will provide information reasonably needed for the customer’s regulatory and individual notifications. Notification is not an admission of fault or liability.

Subprocessors

The customer gives general authorisation for SecureFlowGroup to use subprocessors needed to provide the service. SecureFlowGroup will maintain an up-to-date list, perform proportionate due diligence and impose written data-protection duties offering a level of protection materially equivalent to this Addendum.

SecureFlowGroup will provide advance notice of a new subprocessor where required. A customer may object on reasonable data-protection grounds within the stated notice period. The parties will work in good faith on a solution; if none is reasonably available, the customer may terminate the affected service.

Add the live subprocessor list URL and notice period before publication: [SUBPROCESSOR PAGE / NOTICE PERIOD].

International transfers

SecureFlowGroup will not make a restricted transfer of customer personal data without an approved legal mechanism. Depending on the transfer, this may include UK adequacy regulations, an EU adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses.

The parties will complete transfer-risk assessments and apply supplementary safeguards where required. If a transfer mechanism is replaced or invalidated, the parties will cooperate to implement a valid alternative. Applicable standard clauses are incorporated by reference to the extent needed and take priority over conflicting terms.

Data-subject requests

Taking account of the nature of the processing, SecureFlowGroup will provide reasonable assistance through technical and organisational measures so the customer can respond to requests for access, correction, deletion, restriction, objection, portability or rights relating to automated decisions.

If SecureFlowGroup receives a request relating to customer personal data, it will redirect the requester to the customer and will not respond substantively unless authorised or legally required.

Compliance assistance

SecureFlowGroup will provide reasonable information and assistance for data-protection impact assessments, prior consultation with regulators, security obligations, breach assessment and customer complaints, taking account of the processing and information available to SecureFlowGroup.

Assistance beyond standard service capabilities may be chargeable at agreed professional-services rates unless it is needed because SecureFlowGroup breached this Addendum.

Information and audits

SecureFlowGroup will make available information reasonably necessary to demonstrate compliance, which may include independent reports, certifications, security documentation and questionnaire responses.

Where that information is insufficient, the customer may request an audit no more than once per year, or more often following a material breach or regulator request. Audits must be proportionate, confidential, avoid disruption, respect other customers’ information and normally use an independent qualified auditor. The customer bears reasonable audit costs unless the audit identifies a material SecureFlowGroup breach.

Return and deletion

At the customer’s choice and subject to product functionality, SecureFlowGroup will return or delete customer personal data after termination. SecureFlowGroup may retain information where required by law, for legal claims, or in protected backups that cannot reasonably be isolated, provided retained data remains protected and is not used for another purpose.

The production deletion period and backup expiry period must be stated in the order or trust centre: [PRODUCTION DELETION PERIOD] and [BACKUP EXPIRY PERIOD].

Liability and contact

Liability under this Addendum is subject to the liability terms in the main agreement except where applicable law or incorporated standard contractual clauses require otherwise.

Data-protection notices should be sent to [PRIVACY EMAIL]. The parties should insert the names, addresses, registration details and signatures required for the actual contract before relying on this Addendum.

secureflowgroup

Continuous website protection for teams that cannot afford breaches, malware or downtime.

Protection

Website scannerAI threat analysis NewLive security eventsAutomated responseIntegrationsProtection playbooksPricingSecurity updates

Resources

DocumentationAPI referenceThreat insightsSecurity guidesCustomer storiesCommunityService statusSupport centre

Company

AboutTeamCareers HiringPressPartnersTrust centreContact

Security briefing

Practical protection advice. No spam. Unsubscribe anytime.

Find us on

Xin◉
Protection network operational
24/7 Monitoring15 min Critical responseEU & UK Data optionsHuman Support
© 2026 SecureFlowGroup Ltd.
PrivacyTermsCookiesAcceptable useData processing