Start your free 14-day trial Open the demo account Search the whole site
Product DomesticCommercialEnd of tenancyHoliday letsAirbnbWindowsCarpets and upholsteryOne-off and specialistFacilities managementCleaner appRAMSYour websiteInvoicing Everything CleanFlo does →
Compare Cleaning software comparedCleanFlo vs JobberCleanFlo vs ZenMaidCleanFlo vs GetCleanFlowCleanFlo vs ConnecteamCleanFlo vs SweptCleanFlo vs BigChangevs a spreadsheet and WhatsAppCleanFlo vs SqueegeeCleanFlo vs ServiceM8CleanFlo vs Cleenie
Free tools Cleaning Quote CalculatorPrice Per m² CalculatorUK VAT CalculatorProfit Margin CalculatorTrue Cost of a CleanerHoliday Entitlement CalculatorPer-Seat Cost CalculatorContract Tender Calculator All 17 free tools → 16 printable templates →
Pricing Guides Help Contact Sign in

last updated · 23 August 2026

Data Processing Agreement

The Article 28 contract that governs your staff and client data. It is incorporated into the Terms you accept when you create an account, and it is published here so you can read it first.

In plain English: when you put your staff and clients into CleanFlo, that data is still yours and they are still your responsibility. This document is the legal promise about what we will and will not do with it on your behalf: required by law for both of us, and written so you can actually read it.

1. What This Agreement Is

UK GDPR Article 28 requires a written contract whenever one organisation processes personal data on another's behalf. You are that other organisation. We are the one doing the processing.

This Data Processing Agreement ("DPA") is that contract. It forms part of, and is incorporated into, the Terms & Conditions you accepted when you created your CleanFlo account. You do not need to sign anything separately, accepting the Terms accepts this, although we will countersign a copy on request if your own compliance process needs one. Write to privacy@cleanflo.io.

Where this DPA and the Terms disagree about personal data, this DPA wins.

2. Definitions

"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" have the meanings given to them in UK GDPR.

"Data Protection Law" means the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003, each as amended.

"Customer Personal Data" means the Personal Data within the Customer Data you or your Users put into, or generate through, the Platform: your staff records, your client records, your job records, and everything described in Annex 1.

"Sub-processor" means a third party engaged by us to process Customer Personal Data.

"we", "us", "our" means WhealBit (trading as CleanFlo). "you", "your" means the Customer. Other capitalised terms carry the meaning given in the Terms.

3. Roles and Scope

3.1 You are the Controller

For Customer Personal Data, you are the Controller and we are the Processor. You decide why the data is held and what happens to it. We hold it and act on your instructions.

This matters more than it sounds. It means the staff member who asks what you hold about them is asking you, not us. It means the lawful basis for recording a cleaner's location is yours to establish. It means that if the ICO asks who decided something, the answer is you.

3.2 Where we are a Controller instead

We are an independent Controller, and this DPA does not apply, for: your account holder's own identity and contact details; billing and subscription records; support conversations you have with us; and the diagnostic and security telemetry we keep to run the Platform. Those are governed by our Privacy Policy, which sets out the split in full at Section 2.1.

3.3 We never become a Controller of your data

We do not use Customer Personal Data for our own purposes. Specifically, and without qualification: we do not sell it, we do not share it for advertising, we do not use it to train machine-learning or AI models, and we do not use it to build products or profiles beyond providing the Platform to you. The only aggregate figures we derive are counts that cannot identify any person or any customer.

3.4 How this document maps to Article 28(3)

4. Our Instructions From You

We process Customer Personal Data only on your documented instructions, including on transfers out of the UK. Your instructions are:

  • the Terms and this DPA;
  • your and your Users' ordinary use of the Platform's features: creating a client, assigning a job, sending an invoice, recording an incident and so on. Configuring a feature is an instruction to process the data that feature needs;
  • any further written instruction you give us, which we will follow where it is technically feasible and lawful. We may charge for work that goes materially beyond providing the Platform, and we will tell you before we do.

If we believe an instruction breaches Data Protection Law, we will tell you and may pause that processing until it is resolved. We will not simply carry it out and leave the exposure with you.

Where UK or EU law requires us to process data other than on your instructions, we will tell you before doing so unless that law forbids it on important public-interest grounds.

5. Confidentiality

Everyone we authorise to process Customer Personal Data: employees, contractors and anyone else, is bound by a written duty of confidentiality that survives the end of their engagement.

Access is granted on a need-to-know basis only, is limited to what the individual's role actually requires, and is withdrawn when that need ends. We keep the number of people with production data access as small as running the service allows.

6. Security Measures

We implement and maintain appropriate technical and organisational measures under Article 32. The measures in place at the date of this DPA are:

Security is not static. We may change these measures, but any change must maintain or improve the overall level of protection. The current list is always the one published on this page.

7. Sub-processors

7.1 Your general authorisation

You give us general authorisation to engage Sub-processors. Those engaged at the date of this DPA are listed in Annex 2 and maintained at cleanflo.io/subprocessors.

7.2 Notice and your right to object

Before we add or replace a Sub-processor, we will give you at least 30 days' notice by email to your account address and by updating the sub-processor page.

If you have a reasonable objection on data protection grounds, tell us within those 30 days. We will work with you to find a resolution. If we cannot, you may terminate your subscription without penalty and receive a pro-rata refund of any fees paid for the unused remainder of your term: an unusual right to grant, and the only honest one, because an objection you cannot act on is not a right at all.

7.3 Our responsibility for them

Every Sub-processor is engaged under a written contract imposing data protection obligations no less protective than those in this DPA. We remain fully liable to you for their performance. A failure by a Sub-processor is our failure.

8. Helping You Answer Individuals

Data Subjects will sometimes contact us directly: a cleaner asking what is held about them, a client asking to be deleted. When that happens and the request concerns Customer Personal Data, we will not answer it ourselves. We will tell them promptly that you are the Controller, direct them to you, and let you know it happened. Deciding is your job; getting them to the right door is ours.

Taking account of the nature of the processing, we will assist you by appropriate technical and organisational measures in meeting your obligations to Data Subjects under Articles 12–23. In practice:

  • Access and portability. The Platform's export tools let you retrieve Customer Personal Data yourself, in CSV and JSON, at any time and without asking us.
  • Rectification. You can correct any record directly in the Platform.
  • Erasure and restriction. You can delete records directly. Where a request needs data removed that the Platform's own screens do not reach, ask us and we will do it.
  • Anything else. Where you cannot satisfy a request with the tools available, we will provide reasonable assistance. We do not charge for assistance with a straightforward request.

We aim to respond to an assistance request within 5 working days, which leaves you the rest of your own one-month Article 12(3) deadline to actually answer the individual.

9. Breaches, Assessments and Consultation

9.1 Personal Data Breaches

We will notify you without undue delay, and in any event within 24 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

The 24 hours is deliberate and tighter than the law requires of us. Your own Article 33 duty is to notify the ICO within 72 hours of your becoming aware, and your clock starts when ours stops, so a slow processor spends your deadline, not its own.

Our notification will describe, as far as we know it at the time: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where we cannot provide everything at once, we will provide it in phases without further undue delay rather than waiting for a complete picture.

We will not notify the ICO or affected individuals on your behalf unless you instruct us to in writing. That decision is the Controller's, and making it for you would take it out of your hands.

9.2 Data Protection Impact Assessments

We will provide reasonable assistance with any Data Protection Impact Assessment you carry out under Article 35, and with any prior consultation with the ICO under Article 36, in each case relating to your use of the Platform.

Some CleanFlo features are likely to require a DPIA on your side: recording staff location, and holding health & safety incident records that name individuals, are both on the ICO's list. We maintain our own assessment of these features and will share it to support yours. Ask at privacy@cleanflo.io.

10. Deletion and Return of Data

At your choice, we will delete or return all Customer Personal Data at the end of the provision of services, and delete existing copies, unless UK or EU law requires us to keep them.

On request we will certify deletion in writing.

11. Audits and Evidence

We will make available all information reasonably necessary to demonstrate compliance with Article 28, and allow for and contribute to audits and inspections conducted by you or an auditor you mandate.

In the first instance we will answer questions, complete a security questionnaire, and share our current security documentation, sub-processor list and DPIA material. Most compliance needs are met here, and we would rather answer properly than be inspected.

Where that genuinely does not satisfy a requirement, you may audit us on at least 30 days' written notice, no more than once in any 12 months (except after a Personal Data Breach, or where a Supervisory Authority requires it, when there is no limit). An audit must happen during business hours, must not unreasonably disrupt our operations, must not access any other customer's data, and is subject to confidentiality. Each party bears its own costs.

12. International Transfers

Customer Personal Data is stored in the European Economic Area. See Annex 1 for the region. The EEA is covered by UK adequacy regulations, so this is not a restricted transfer.

Some Sub-processors in Annex 2 are established outside the UK and EEA, principally in the United States. For any restricted transfer we put in place an appropriate Article 46 safeguard before the transfer begins: normally the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, and we carry out a transfer risk assessment. Copies are available on request.

Where an adequacy regulation covers a destination, we may rely on it instead. If an adequacy regulation is withdrawn or a transfer mechanism is invalidated, we will implement an alternative safeguard or stop the transfer.

13. Your Obligations

This section is short but it carries the parts of the law we cannot do for you.

  • Establish your lawful basis. You must have one under Article 6 for every category of Customer Personal Data you put into the Platform, and a condition under Article 9 for any special category data, which includes health & safety records describing an injury to a named person.
  • Tell people. Your staff and your clients must be given the information Articles 13 and 14 require, in your own privacy notice. We help. CleanFlo shows staff a plain-English notice before any location is recorded, and links our privacy notice from the cleaner app, the staff invitation and the client portal, but your own notice is yours to write and must reflect what you actually do.
  • Location, specifically. If you use location capture, say so in your staff privacy notice and be able to justify it. We have built it to be proportionate: two points per job, never continuous, declining is free of consequence, but proportionality is a judgement you make about your own workforce.
  • Special category data. If you record injuries, the Data Protection Act 2018 requires you to hold an Appropriate Policy Document. Ask us and we will share a template.
  • Keep it accurate and lawful. You are responsible for the accuracy, quality and legality of Customer Personal Data and for how it was obtained.
  • Look after your accounts. Keep credentials confidential, remove people who leave promptly, and grant the lowest role that lets someone do their job.

14. Liability, Term and Changes

14.1 Liability

Each party's liability under this DPA is subject to the exclusions and cap in Section 8 of the Terms. Nothing in this DPA limits any liability that cannot lawfully be limited, and nothing in it affects a Data Subject's rights under Article 82 to compensation directly from either of us.

14.2 Term

This DPA takes effect when you accept the Terms and continues for as long as we process Customer Personal Data. Sections 5, 10, 11, 12 and 14 survive its termination.

14.3 Changes

We may update this DPA where the law changes, where a Supervisory Authority issues new guidance, or to reflect a change in how the Platform works. Any change that materially reduces your protection or ours will be notified at least 30 days in advance by email and in-app notice. Sub-processor changes follow Section 7.2 instead.

15. Contact

Questions about this DPA, requests for a countersigned copy, security questionnaires and audit requests all go to:

A1. Annex 1, Description of the Processing

A2. Annex 2, Approved Sub-processors

Current as at 23 August 2026. The maintained list, with change history, is at cleanflo.io/subprocessors.