Legal
Data Processing Agreement
This agreement sets out how Floxa Ltd processes personal data on behalf of its customers, and forms part of the agreement governing your use of Floxa.
Last updated: 2 September 2026
This Data Processing Agreement ("DPA") is entered into between Floxa Ltd ("Floxa"), a company registered in England and Wales under company number 16971343 with its registered office at Office 439, Unit 5, 399-405 Oxford Street, Mayfair, London, England, W1C 2BU, and the customer that has an account for the Floxa service (the "Customer"). It supplements, and forms part of, the agreement between the Customer and Floxa governing the Customer's use of the Floxa service — including the Floxa Terms of Service, unless a separately signed agreement applies (the "Agreement").
This DPA applies where and to the extent that Floxa processes Customer Data (defined below) that is personal data on behalf of the Customer in the course of providing the Floxa service (the "Services").
1. Definitions
- "Data Protection Laws" means all laws applicable to the processing of personal data under this DPA, including the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and, where applicable, the EU GDPR (Regulation (EU) 2016/679).
- "Customer Data" means personal data that the Customer (or its users) submits to, stores in, or generates within the Services — for example records about the Customer's staff, clients, suppliers and contacts, invoices, expenses, timesheets, schedules and uploaded files.
- "Sub-processor" means a third party engaged by Floxa to process Customer Data on Floxa's behalf.
- "UK GDPR" means Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of the European Union (Withdrawal) Act 2018.
- "controller", "processor", "data subject", "personal data", "personal data breach" and "processing" have the meanings given in the UK GDPR.
2. Roles of the parties
For Customer Data, the Customer is the controller (or, where the Customer acts on behalf of a third-party controller, a processor) and Floxa is a processor acting on the Customer's documented instructions.
Floxa acts as an independent controller for personal data it processes for its own purposes — for example account registration and authentication data, subscription billing records, service communications, and security logs. That processing is described in Floxa's privacy policy and is outside the scope of this DPA.
3. Subject matter, duration, nature and purpose
The subject matter of the processing is the provision of the Services under the Agreement. The duration of the processing is the term of the Agreement plus the deletion period in section 11. The nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.
4. Processing on instructions
Floxa will process Customer Data only on the Customer's documented instructions, including with regard to transfers of personal data to a third country, unless required to do otherwise by law that applies to Floxa (in which case Floxa will inform the Customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest). The Agreement, this DPA, and the Customer's use and configuration of the Services constitute the Customer's complete instructions. Floxa will inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.
5. Confidentiality
Floxa ensures that all persons authorised to process Customer Data are bound by contractual or statutory obligations of confidentiality, and that access to Customer Data is limited to those who need it to deliver the Services.
6. Security
Floxa implements and maintains appropriate technical and organisational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, as required by Article 32 UK GDPR. The current measures are described in Annex 2. Floxa may update these measures from time to time, provided the updates do not materially reduce the overall level of protection.
7. Sub-processors
The Customer grants Floxa general written authorisation to engage Sub-processors to process Customer Data. The current list is published at floxa.co.uk/legal/subprocessors and forms Annex 3 of this DPA.
- Floxa will impose data protection obligations on each Sub-processor by written contract that are no less protective than those in this DPA, and remains liable to the Customer for the performance of each Sub-processor's obligations.
- Floxa will give the Customer at least 30 days' notice (by email to the account owner and by updating the sub-processor page) before adding or replacing a Sub-processor that processes Customer Data.
- The Customer may object to a new Sub-processor on reasonable data protection grounds within that notice period. If the parties cannot resolve the objection in good faith, the Customer may terminate the affected Services and receive a pro-rata refund of any prepaid fees for the unused remainder of the subscription term. This is the sole remedy for such an objection.
8. Data subject rights
Taking into account the nature of the processing, Floxa will assist the Customer, by appropriate technical and organisational measures and insofar as this is possible, in fulfilling the Customer's obligation to respond to data subjects' requests to exercise their rights under Data Protection Laws (access, rectification, erasure, restriction, portability and objection). In the first instance this assistance is provided through the Services themselves, which allow the Customer to access, correct, export and delete Customer Data. If Floxa receives a request from a data subject relating to Customer Data, it will (to the extent legally permitted) promptly redirect the data subject to the Customer.
9. Personal data breach
Floxa will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Data. The notification will describe, to the extent then known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Floxa will provide timely updates as further information becomes available and will reasonably cooperate with the Customer's own notification obligations. Floxa's notification of a breach is not an acknowledgement of fault or liability.
10. DPIAs and prior consultation
Taking into account the nature of the processing and the information available to Floxa, Floxa will provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with the Information Commissioner's Office (or other competent supervisory authority) that relate to the processing of Customer Data under this DPA.
11. Deletion and return of Customer Data
During the term of the Agreement, the Customer can access and export Customer Data through the Services. Upon termination or expiry of the Agreement, Floxa will delete Customer Data from its production systems within 90 days, unless retention is required by applicable law (for example financial records Floxa must retain as a controller). Customer Data in encrypted backups is deleted as those backups expire in the ordinary backup rotation, no more than 35 days after deletion from production, and is not restored to production except where required for disaster recovery.
12. Audit and information
Floxa will make available to the Customer information reasonably necessary to demonstrate compliance with its obligations under Article 28 UK GDPR, including summaries of relevant third-party audit reports and certifications held by its infrastructure Sub-processors. Where that information is insufficient, Floxa will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, provided that: the Customer gives at least 30 days' written notice; audits occur no more than once in any 12-month period (except following a personal data breach or where required by a supervisory authority); the auditor is bound by confidentiality; and the audit is conducted during normal business hours with minimal disruption and at the Customer's expense.
13. International transfers
Floxa stores Customer Data in the United Kingdom and the European Union, as described in the sub-processor list. Floxa will not transfer Customer Data outside the UK or EEA unless the transfer is protected by a lawful transfer mechanism under Data Protection Laws — an adequacy regulation (including the UK Extension to the EU–US Data Privacy Framework), Standard Contractual Clauses together with the UK International Data Transfer Addendum, or the UK International Data Transfer Agreement, together with any supplementary measures reasonably required.
14. Liability
Each party's liability arising out of or related to this DPA is subject to the exclusions and limitations of liability set out in the Agreement. This DPA does not limit any liability that cannot be limited under Data Protection Laws, including liability to data subjects.
15. General
- If there is a conflict between this DPA and the Agreement regarding the processing of Customer Data, this DPA prevails.
- Floxa may update this DPA from time to time to reflect changes in Data Protection Laws or the Services; material changes will be notified to the Customer, and the version published at floxa.co.uk/legal/dpa is the current version.
- This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute arising from it, except where Data Protection Laws provide otherwise.
Annex 1 — Details of processing
Categories of data subjects
- The Customer's users, employees, workers and subcontractors;
- The Customer's clients and prospective clients, and their personnel and contacts;
- The Customer's suppliers and other business contacts.
Categories of personal data
- Identity and contact data — names, email addresses, phone numbers, postal addresses;
- Work and employment-related data — schedules, timesheets, task assignments, job records;
- Financial and transaction data — invoices, quotes, expenses, payment references and bank account details recorded for invoicing;
- Files and content uploaded to the Services — logos, receipts, photos, documents and attachments;
- Communications sent through the Services (e.g. emailed invoices).
Special category data
The Services are not designed for, and Floxa does not intend to process, special category data or criminal offence data. The Customer agrees not to submit such data to the Services.
Nature, purpose and frequency of processing
Hosting, storage, computation, transmission, display, export, backup and deletion of Customer Data as necessary to provide the Services — business management for trade companies, including scheduling, invoicing, expenses, timesheets and payments. Processing is continuous for the duration of the Agreement.
Annex 2 — Technical and organisational measures
- Encryption in transit. All connections to the Services use TLS. Connections between the application and the database are encrypted with certificate-authority verification.
- Encryption at rest. Customer Data is encrypted at rest at the storage layer. Designated sensitive fields (such as saved bank details) are additionally encrypted at the application layer with AES-256-GCM, with the encryption key held separately from the database, so database access alone does not expose them.
- Tenant isolation. Every tenant table is protected by forced PostgreSQL row-level security scoped to the customer's organisation, in addition to application-layer scoping of every query — two independent layers, so a defect in one does not expose data across tenants.
- Access control. Role-based access control within each organisation; authentication with hashed credentials or OAuth; session management with secure cookies. Uploaded files are stored in private object storage and served only through an authenticated, organisation-scoped proxy — never from public URLs.
- Data locality. The production database runs in the AWS London region (eu-west-2); uploaded files are stored under EU jurisdiction; transactional email is sent from an EU region.
- Least privilege. Third-party API credentials are scoped to the minimum required permissions (e.g. restricted Stripe API keys). Production access is limited to authorised personnel.
- Backups and resilience. Automated, encrypted database backups with point-in-time recovery, retained on a fixed rotation.
- Verification. An automated security test suite verifies tenant isolation (row-level security enforcement on every tenant table) and field-level encryption against the real database schema, alongside documented manual security testing playbooks.
- Email hygiene. Transactional email is sent without tracking pixels or rewritten tracking links.
Annex 3 — Authorised Sub-processors
The authorised Sub-processors, the purpose for which each is engaged, and the processing location are listed at floxa.co.uk/legal/subprocessors, which is incorporated into this DPA by reference and updated as described in section 7.
Contact
Questions about this DPA: support@floxa.co.uk, or write to Floxa Ltd, Office 439, Unit 5, 399-405 Oxford Street, Mayfair, London, England, W1C 2BU.