This Data Processing Agreement (“DPA”) forms part of the Terms of Service and governs CardFlow’s processing of personal data on your behalf under UK GDPR Article 28.
1. Roles
You are the controller of the personal data you process through the service. CardFlow is the processor, acting only on your documented instructions (these Terms and your use of the service being such instructions).
2. Subject-matter & duration
We process personal data for the duration of your subscription and through the deletion window that follows its end, after which the data is erased.
3. Nature & purpose
The processing is for the purpose of hosting and operating your inventory management system and storefront — storing and serving the records you create through the service.
4. Categories of data subjects & data
Data subjects include your staff and your end customers. Personal data includes contact details (such as name, email, and address) and order and transaction records that you enter or that the storefront collects.
5. Our obligations (Article 28(3))
- process the personal data only on your documented instructions;
- ensure persons authorised to process it are bound by confidentiality;
- implement appropriate technical and organisational security measures (Article 32);
- assist you, where feasible, in responding to data-subject requests;
- assist you with security, breach-notification, and impact-assessment obligations;
- delete or return the personal data at the end of the service, per section 10;
- make available the information needed to demonstrate compliance and allow audits.
6. Sub-processors
You authorise us to engage the sub-processors below. We will give notice before adding or replacing a sub-processor so you have the opportunity to object.
- Hetzner — Tenant hosting / infrastructure
- Cloudflare — DNS and edge proxy
- Stripe — Payment processing
- Grafana Cloud — Log storage (Loki)
- Backblaze B2 / S3 — Encrypted backups
- Tailscale — Management network (metadata only)
- Google — Operator identity assertion (SSO)
7. Security measures
Measures include per-tenant isolation, encryption of data in transit and at rest, encrypted off-site backups, and least-privilege access controls. We review these measures as the service evolves.
8. International transfers
Hosting and backups are within the UK/EU. Where a sub-processor processes data outside the UK/EU, that transfer is covered by an appropriate safeguard such as Standard Contractual Clauses.
9. Breach notification
We will notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information you reasonably need to meet your own notification duties.
10. Deletion
When a tenant ends, we follow a pause-first process: your data is retained during a deletion window so you can reactivate, and is permanently erased (including backups) once that window expires or on your request.