Legal

Data Processing Addendum

This Data Processing Addendum (DPA) sets out how TradersFlow processes personal data on behalf of business customers who use the Service to manage their own customers' information.

Last updated: 1 September 2026
Status: draft contractual document. This DPA is provided in good faith as a working draft for business customers who need one. It has not been reviewed or approved by a solicitor, and it is not legal advice. If your organisation requires a signed or negotiated DPA, please have it reviewed by your own legal adviser and contact us at privacy@tradersflow.co.uk.
01

Parties & scope

This DPA is entered into between:

  • Customer — the individual or business that holds a TradersFlow account ("you"); and
  • ProcessorAE TECHNOLOGIES GROUP LTD, a company registered in England and Wales under company number 17419062, registered office 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom, which operates the TradersFlow service ("TradersFlow", "we").

It applies to the processing of personal data carried out by TradersFlow on your behalf in the course of providing the Service, and forms part of our Terms of Service. Terms not defined here have the meaning given in the UK GDPR and the Data Protection Act 2018 ("Data Protection Law").

02

Roles of the parties

You are the controller of the personal data you enter into TradersFlow about other people — in particular your own customers and contacts (names, addresses, phone numbers, email addresses, job details, quotes, invoices, photographs of work, review and lead submissions). You decide what to collect, why, and how long to keep it in the Service.

TradersFlow is the processor of that data: we process it on your documented instructions to host, store, display, transmit, back up and secure it, and to deliver the features you use (such as sending an invoice email to your customer).

TradersFlow is a separate controller for the personal data we need for our own purposes — your account and identity data, subscription and billing records, security logs, support correspondence and the minimal anti-abuse trial record. That processing is described in our Privacy Policy and is not governed by this DPA.

You confirm that you have a lawful basis for the personal data you upload, that you have provided any notices your own customers are entitled to, and that your instructions to us will not put us in breach of Data Protection Law.

03

Details of processing (Annex)

  • Subject matter: provision of the TradersFlow trade-business management service.
  • Duration: for as long as your account is active, plus the retention periods set out in the Privacy Policy.
  • Nature and purpose: hosting, storage, organisation, retrieval, display, transmission by email, backup, deletion, technical support, and — only where you use an AI feature — transmission of the relevant extract to our AI sub-processor to generate an answer, insight explanation or draft for you.
  • Types of personal data: names, postal addresses, email addresses, telephone numbers, job and site details, quote and invoice contents and amounts, payment status, photographs and documents you upload, review and enquiry submissions.
  • Categories of data subjects: your customers and prospective customers, your site contacts, people who submit enquiries or reviews through your public portfolio page, and your own staff where you record them.
  • Special category data: not requested and not required. You should not upload special category or criminal offence data into the Service.
04

Processor obligations

We will:

  • process personal data only on your documented instructions (your use of the Service, this DPA and the Terms constitute those instructions), unless required otherwise by law — in which case we will tell you first unless the law prohibits it;
  • not sell your data, share it for advertising, or use it — or allow any sub-processor to use it — to train machine-learning models. Where you use an AI feature, the relevant content is sent to OpenAI as our sub-processor purely to generate output back to you, and OpenAI does not use API content to train its models;
  • only access it where reasonably necessary to operate the platform, provide support you have requested, investigate abuse or comply with law, under role-based permissions and with administrative actions logged;
  • tell you if, in our opinion, an instruction infringes Data Protection Law.
05

Confidentiality

Personal data processed under this DPA is treated as confidential. Any person authorised to access it is bound by a duty of confidentiality and is granted only the minimum access needed for their role.

06

Security measures

We implement appropriate technical and organisational measures under Article 32 UK GDPR, taking account of the state of the art, cost, and the risks to individuals. Current measures include: encryption in transit and at rest, database row-level security isolating each account's records, per-account isolated file storage, hashed passwords, role-based administrative access with audit logging, secrets held in a managed vault, dependency scanning, and encrypted daily backups.

Measures may change as the platform evolves; we will not materially reduce the overall level of security during the term. Full details are on our Security page.

07

Sub-processors

You give general authorisation for us to engage sub-processors. The current list — with purpose, data categories and location — is published at tradersflow.co.uk/subprocessors.

Each sub-processor is engaged under written terms imposing data-protection obligations no less protective than those in this DPA, and we remain liable to you for their performance. We will give reasonable advance notice (by email or in-app notice) before adding or replacing a sub-processor, and you may object on reasonable data-protection grounds; if we cannot resolve the objection you may terminate the affected part of the Service.

08

Data subject requests & assistance

The Service gives you direct access to the personal data you hold, so in most cases you can respond to access, rectification, erasure, restriction and portability requests yourself by viewing, editing, exporting or deleting the relevant records.

Where you cannot do so with the tools provided, we will provide reasonable assistance. If a data subject contacts us directly about data you control, we will not respond substantively — we will refer them to you where we can identify you as the controller.

We will also provide reasonable assistance with data protection impact assessments and prior consultation with the ICO, so far as it relates to our processing and the information available to us.

09

Personal data breaches

We will notify you without undue delay, and in any event within 72 hours of becoming aware, of a personal data breach affecting personal data we process on your behalf. Our notice will describe, so far as known: the nature of the breach, categories and approximate numbers of records and data subjects affected, likely consequences, and the measures taken or proposed.

We will assist you in meeting your own notification obligations to the ICO and to affected individuals. Reporting a breach is not an admission of fault.

10

International transfers

Primary storage is in EU/UK-adequate regions. Where a sub-processor processes personal data outside the UK or EEA (for example our subscription management provider in the United States), the transfer is made under an adequacy decision or under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with any supplementary measures we assess as necessary.

11

Return & deletion of data

You can export your data at any time from within the Service, and delete business data or your entire account at any time — see Delete your account & data.

On termination, we will delete personal data processed on your behalf in line with the retention periods in our Privacy Policy, save where storage is required by law. Backups are purged on their normal rolling cycle, within 30 days.

12

Audits & information

On reasonable written request, and no more than once in any 12-month period (unless required by a supervisory authority or following a breach), we will make available the information reasonably necessary to demonstrate compliance with this DPA. Where an on-site audit is required by Data Protection Law, it will be conducted on reasonable notice, during business hours, subject to confidentiality, and in a way that does not disrupt the Service or other customers' data.

13

Liability, term & precedence

This DPA takes effect when you begin using the Service and continues for as long as we process personal data on your behalf. Liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except to the extent liability cannot lawfully be limited.

If there is a conflict between this DPA and the Terms of Service in relation to data protection, this DPA prevails. This DPA is governed by the law of England and Wales.

14

How to put this in place

For most customers, this published DPA is sufficient and applies automatically alongside the Terms of Service — no signature is required.

If you need a countersigned copy or your own template reviewed, email privacy@tradersflow.co.uk with your business details. Please allow time for review; we may need to take legal advice before signing bespoke terms.