Skip to main content
Data Protection

Data processing

Last updated: 23 August 2026

What this is

Version 1.0 · 23 August 2026

Where CONFLUXUS LTD holds personal data on your behalf — in your workspace, or on a website or application we host for you — you are the controller and we are the processor.

Article 28(3) of the UK GDPR requires that relationship to be governed by a written contract containing specific terms. This document is that contract. It forms Schedule 2 to our Master Services Agreement.

We act only on your instructions

We process your data only as needed to provide the services you have asked for, and on your documented instructions. If we ever think an instruction would breach data protection law, we will tell you.

We will never sell your data, use it for our own marketing, or use it to train any artificial intelligence system.

Confidentiality and security

Everyone with access is under a written duty of confidence, committed to before they are given access, and access is limited to those who need it.

Our security measures include:

  • Access rules enforced in the database itself, not only in the interface — a client’s users can reach only their own organisation’s data.
  • Individual named accounts, with two-factor authentication available on all and used on administrator accounts.
  • Encryption in transit and at rest; credentials held in a secrets vault, never in source code.
  • Uploaded files kept in private storage, scoped per client, shared only by explicit permission.
  • Automated backups with point-in-time recovery.
  • Audit records for security-relevant actions, written by the database rather than the application so they cannot be bypassed.

Sub-processors

The authoritative list of everyone involved in your engagement — including our hosting provider and the contracted personnel who work on client projects — is published in your workspace at app.confluxus.co.uk/subprocessors, and we will provide it on request before you engage us. You give general authorisation for us to use them, as Article 28(2) permits.

A shorter public list covers only enquiries sent through our website. We keep the engagement list in the workspace rather than on the open web because Article 28 requires us to tell you, not to publish how we deliver — but nothing about it is withheld from you.

We give 14 days’ notice before adding or replacing one. You may object on reasonable data-protection grounds, and if we cannot resolve your objection you may end the affected services without penalty and get back anything you prepaid.

Every sub-processor is bound by terms at least as protective as these, and we remain fully liable to you for what they do.

If something goes wrong

We will tell you about any personal data breach affecting your data within 24 hours of becoming aware of it — deliberately tighter than the 72 hours you have to notify the ICO, because your clock starts when we tell you.

We will tell you what happened, who and how many people are affected, the likely consequences, and what we have done. We will help you notify the ICO and affected individuals, but the decision to notify is yours — we will not do it on your behalf without your agreement unless the law requires us to.

Helping you meet your obligations

We will help you respond to requests from individuals exercising their rights — access, correction, deletion, restriction, portability and objection. If someone contacts us directly about your data we will not answer them on the substance; we will pass it to you within two working days.

We will also assist with data protection impact assessments where they relate to work we do for you.

Getting your data back, and deletion

At the end of the services, or earlier if you ask, we will delete or return your data — your choice — and delete our copies. We keep backups for 30 days afterwards so a failed migration can be recovered, then delete those too.

This sits alongside clause 8.5 of the Master Services Agreement, which gives you a free export of your data when you leave. Nothing here lets us withhold your data.

Checking we are doing this properly

We will give you the information you need to satisfy yourself we are complying, and will allow an audit on 30 days’ notice, once in any 12 months — or more often after a breach or if a regulator requires it. In most cases a completed security questionnaire answers the question without anyone needing to visit.

Where your data is held

Your data is held in the European Union (Ireland), which UK adequacy regulations treat as offering equivalent protection.

Two things go further:

  • Notification emails are delivered by a provider in the United States — recipient name, email address and the content of that message.
  • Some design, development and support work is delivered by contracted personnel in South Africa, who may access the project content they are working on.

Both rest on a UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment which we maintain and will share on request. We will not move your data to another country without putting an appropriate safeguard in place first and telling you.

Changes to this document

Unlike our Acceptable Use Policy, we cannot change this document unilaterally in any way that reduces the protection given to your data. Changes take effect only by agreement, or where the law requires them. Previous versions are available on request.

That distinction is deliberate: the Acceptable Use Policy governs what you may do, and has to keep pace with new kinds of abuse. This document is our obligation to you, and a processor able to rewrite its own duties would defeat the purpose of having it.

Company details

CONFLUXUS LTD

Registered in England and Wales, company number 17400384

Registered office: 66 Paul Street, London, England, EC2A 4NA

Contact: hello@confluxus.co.uk