← Back to home

Data Processing Agreement (DPA)

Draft skeleton — last updated: 20 July 2026

Draft skeleton — not yet in force. This is an outline of the terms intended to govern Flowgate's role as a data processor. It is a starting point for legal review and is not a binding contract until finalised by a qualified UK data-protection solicitor and executed by both parties. Do not rely on it. Bracketed items are placeholders or open questions.

1. Parties and roles

This DPA forms part of the agreement between Flowgate Systems ("Processor") and the client ("Controller"). It applies where Flowgate processes personal data on the Controller's behalf — namely the Controller's leads' conversation and contact data, booking data, and (where enabled) call recordings and transcripts.

It reflects the mandatory terms required by Article 28 UK GDPR. Flowgate acts only on the Controller's documented instructions and does not determine the purposes of processing the Controller's lead or participant data.

2. Subject-matter, duration, nature and purpose

  • Subject-matter: provision of the Flowgate lead-qualification, booking, outbound-outreach and (where enabled) meeting-notetaker service.
  • Duration: for the term of the subscription plus the retention periods in the Privacy Policy.
  • Nature and purpose: automated processing of DM conversations, capture of lead contact details, matching bookings to leads, and (where enabled) recording, transcription and AI analysis of booked calls.
  • Types of personal data: names/usernames, message content, email addresses, booking details, call recordings and transcripts, and derived deal information.
  • Categories of data subject: the Controller's leads and the participants on the Controller's recorded calls.

3. Processor obligations (Art. 28(3))

  • Process only on the Controller's documented instructions, including for transfers, unless required by law.
  • Ensure persons authorised to process the data are under confidentiality obligations.
  • Implement appropriate technical and organisational security measures (see section 5).
  • Respect the conditions for engaging sub-processors (section 4).
  • Assist the Controller, by appropriate measures, in responding to data-subject-rights requests.
  • Assist the Controller with security, breach notification, DPIAs, and prior consultation with the ICO.
  • At the Controller's choice, delete or return the personal data at the end of the service, and delete existing copies unless retention is legally required.
  • Make available information necessary to demonstrate compliance and allow for and contribute to audits.

4. Sub-processors

The Controller provides general authorisation for Flowgate to engage the sub-processors listed on the sub-processor page. Flowgate will give notice of intended changes so the Controller may object, and will impose data-protection terms on each sub-processor equivalent to those in this DPA. Flowgate remains liable to the Controller for its sub-processors' performance.

5. Security measures

Measures include: AES-256 encryption of sensitive credentials at rest, Row Level Security and per-tenant isolation, HTTPS-only transport, access controls, and regular security audits. [Full technical and organisational measures schedule to be appended.]

6. International transfers

Where Flowgate or its sub-processors transfer personal data outside the UK, an appropriate transfer mechanism is used — the UK Extension to the EU-US Data Privacy Framework where the importer is certified to it, or otherwise the UK IDTA or the UK Addendum to the EU SCCs, with a transfer risk assessment. Current mechanisms per sub-processor are on the sub-processor page.

7. Controller obligations and responsibilities

  • Establish and document a lawful basis for the processing it instructs.
  • Provide privacy information to its leads and call participants.
  • For recorded calls: inform every participant, and obtain any consent required in the participant's jurisdiction (including jurisdictions requiring all-party consent to recording).
  • Assess whether a DPIA is required for its use of the notetaker, outbound outreach, or automated qualification, and carry one out where needed.
  • Handle direct-marketing compliance (PECR) for outbound messages it enables.

8. Call-recording specific terms (notetaker)

  • Flowgate dispatches a recording bot only where recording consent is explicitly granted on the booking form (fail-closed).
  • Flowgate does not create voiceprints, perform biometric speaker identification, or process voice for the purpose of uniquely identifying individuals.
  • Flowgate does not reuse recordings or transcripts for its own purposes, including model training or any cross-client product.
  • [Retention and deletion schedule for raw recordings and transcripts — to be finalised and technically enforced before the feature is enabled.]

9. Open items for legal review

  • Sufficiency of booking-form consent for the non-form participant on a recorded call.
  • Position on leads/participants located in all-party-consent jurisdictions.
  • Whether a DPIA is mandatory for the notetaker and who owns it (Controller vs Processor).
  • Precise retention/deletion periods and their technical enforcement.
  • Final liability, indemnity and audit-scope wording.

10. Contact

To request the executable DPA, email info@nextdesignwebsite.com.