Data Processing Agreement
The Article 28 contract that governs your staff and client data. It is incorporated into the Terms you accept when you create an account, and it is published here so you can read it first.
In plain English: when you put your staff and clients into CleanFlo, that data is still yours and they are still your responsibility. This document is the legal promise about what we will and will not do with it on your behalf: required by law for both of us, and written so you can actually read it.
1. What This Agreement Is
UK GDPR Article 28 requires a written contract whenever one organisation processes personal data on another's behalf. You are that other organisation. We are the one doing the processing.
This Data Processing Agreement ("DPA") is that contract. It forms part of, and is incorporated into, the Terms & Conditions you accepted when you created your CleanFlo account. You do not need to sign anything separately, accepting the Terms accepts this, although we will countersign a copy on request if your own compliance process needs one. Write to privacy@cleanflo.io.
Where this DPA and the Terms disagree about personal data, this DPA wins.
2. Definitions
"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" have the meanings given to them in UK GDPR.
"Data Protection Law" means the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003, each as amended.
"Customer Personal Data" means the Personal Data within the Customer Data you or your Users put into, or generate through, the Platform: your staff records, your client records, your job records, and everything described in Annex 1.
"Sub-processor" means a third party engaged by us to process Customer Personal Data.
"we", "us", "our" means WhealBit (trading as CleanFlo). "you", "your" means the Customer. Other capitalised terms carry the meaning given in the Terms.
3. Roles and Scope
3.1 You are the Controller
For Customer Personal Data, you are the Controller and we are the Processor. You decide why the data is held and what happens to it. We hold it and act on your instructions.
This matters more than it sounds. It means the staff member who asks what you hold about them is asking you, not us. It means the lawful basis for recording a cleaner's location is yours to establish. It means that if the ICO asks who decided something, the answer is you.
3.2 Where we are a Controller instead
We are an independent Controller, and this DPA does not apply, for: your account holder's own identity and contact details; billing and subscription records; support conversations you have with us; and the diagnostic and security telemetry we keep to run the Platform. Those are governed by our Privacy Policy, which sets out the split in full at Section 2.1.
3.3 We never become a Controller of your data
We do not use Customer Personal Data for our own purposes. Specifically, and without qualification: we do not sell it, we do not share it for advertising, we do not use it to train machine-learning or AI models, and we do not use it to build products or profiles beyond providing the Platform to you. The only aggregate figures we derive are counts that cannot identify any person or any customer.
3.4 How this document maps to Article 28(3)
| (a) documented instructions | Section 4 |
|---|---|
| (b) confidentiality of personnel | Section 5 |
| (c) Article 32 security measures | Section 6 and Annex 1 |
| (d) conditions for engaging sub-processors | Section 7 and Annex 2 |
| (e) assistance with data subject rights | Section 8 |
| (f) assistance with Articles 32–36 | Sections 6 and 9 |
| (g) deletion or return at end of contract | Section 10 |
| (h) information and audits | Section 11 |
4. Our Instructions From You
We process Customer Personal Data only on your documented instructions, including on transfers out of the UK. Your instructions are:
- the Terms and this DPA;
- your and your Users' ordinary use of the Platform's features: creating a client, assigning a job, sending an invoice, recording an incident and so on. Configuring a feature is an instruction to process the data that feature needs;
- any further written instruction you give us, which we will follow where it is technically feasible and lawful. We may charge for work that goes materially beyond providing the Platform, and we will tell you before we do.
If we believe an instruction breaches Data Protection Law, we will tell you and may pause that processing until it is resolved. We will not simply carry it out and leave the exposure with you.
Where UK or EU law requires us to process data other than on your instructions, we will tell you before doing so unless that law forbids it on important public-interest grounds.
5. Confidentiality
Everyone we authorise to process Customer Personal Data: employees, contractors and anyone else, is bound by a written duty of confidentiality that survives the end of their engagement.
Access is granted on a need-to-know basis only, is limited to what the individual's role actually requires, and is withdrawn when that need ends. We keep the number of people with production data access as small as running the service allows.
6. Security Measures
We implement and maintain appropriate technical and organisational measures under Article 32. The measures in place at the date of this DPA are:
| Encryption in transit | TLS 1.2 or higher for all traffic between your devices and our infrastructure, and between our infrastructure and every sub-processor. |
|---|---|
| Encryption at rest | AES-256 on the production database and on stored files, applied by our hosting provider. |
| Tenant isolation | Row-level security is enforced in the database itself, on every table holding Customer Personal Data, so that one customer’s records cannot be read by another even if application code is wrong. |
| Access control | Role-based permissions within your account (owner, supervisor, cleaner), so that a cleaner cannot reach financial or company-wide data. |
| Authentication | Passwords are hashed by our authentication provider and are never stored or transmitted in plaintext. |
| Segregation of duties | Administrative platform tooling is separated from the customer application and restricted to named personnel. |
| Logging | Administrative and destructive actions are recorded in an audit log with actor and timestamp. |
| Diagnostic minimisation | Error and diagnostic records pass through two independent redaction stages that strip credentials, email addresses, postcodes, phone numbers and bank details before storage. |
| Resilience | Managed daily backups with point-in-time recovery, held by our hosting provider within the region stated in Annex 1. |
| Testing | An automated test suite gates every release, including tests that assert tenant isolation and permission boundaries. |
Security is not static. We may change these measures, but any change must maintain or improve the overall level of protection. The current list is always the one published on this page.
7. Sub-processors
7.1 Your general authorisation
You give us general authorisation to engage Sub-processors. Those engaged at the date of this DPA are listed in Annex 2 and maintained at cleanflo.io/subprocessors.
7.2 Notice and your right to object
Before we add or replace a Sub-processor, we will give you at least 30 days' notice by email to your account address and by updating the sub-processor page.
If you have a reasonable objection on data protection grounds, tell us within those 30 days. We will work with you to find a resolution. If we cannot, you may terminate your subscription without penalty and receive a pro-rata refund of any fees paid for the unused remainder of your term: an unusual right to grant, and the only honest one, because an objection you cannot act on is not a right at all.
7.3 Our responsibility for them
Every Sub-processor is engaged under a written contract imposing data protection obligations no less protective than those in this DPA. We remain fully liable to you for their performance. A failure by a Sub-processor is our failure.
8. Helping You Answer Individuals
Data Subjects will sometimes contact us directly: a cleaner asking what is held about them, a client asking to be deleted. When that happens and the request concerns Customer Personal Data, we will not answer it ourselves. We will tell them promptly that you are the Controller, direct them to you, and let you know it happened. Deciding is your job; getting them to the right door is ours.
Taking account of the nature of the processing, we will assist you by appropriate technical and organisational measures in meeting your obligations to Data Subjects under Articles 12–23. In practice:
- Access and portability. The Platform's export tools let you retrieve Customer Personal Data yourself, in CSV and JSON, at any time and without asking us.
- Rectification. You can correct any record directly in the Platform.
- Erasure and restriction. You can delete records directly. Where a request needs data removed that the Platform's own screens do not reach, ask us and we will do it.
- Anything else. Where you cannot satisfy a request with the tools available, we will provide reasonable assistance. We do not charge for assistance with a straightforward request.
We aim to respond to an assistance request within 5 working days, which leaves you the rest of your own one-month Article 12(3) deadline to actually answer the individual.
9. Breaches, Assessments and Consultation
9.1 Personal Data Breaches
We will notify you without undue delay, and in any event within 24 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
The 24 hours is deliberate and tighter than the law requires of us. Your own Article 33 duty is to notify the ICO within 72 hours of your becoming aware, and your clock starts when ours stops, so a slow processor spends your deadline, not its own.
Our notification will describe, as far as we know it at the time: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where we cannot provide everything at once, we will provide it in phases without further undue delay rather than waiting for a complete picture.
We will not notify the ICO or affected individuals on your behalf unless you instruct us to in writing. That decision is the Controller's, and making it for you would take it out of your hands.
9.2 Data Protection Impact Assessments
We will provide reasonable assistance with any Data Protection Impact Assessment you carry out under Article 35, and with any prior consultation with the ICO under Article 36, in each case relating to your use of the Platform.
Some CleanFlo features are likely to require a DPIA on your side: recording staff location, and holding health & safety incident records that name individuals, are both on the ICO's list. We maintain our own assessment of these features and will share it to support yours. Ask at privacy@cleanflo.io.
10. Deletion and Return of Data
At your choice, we will delete or return all Customer Personal Data at the end of the provision of services, and delete existing copies, unless UK or EU law requires us to keep them.
| While your account is live | Export whatever you need, whenever you need it, from the Platform’s own export tools. No request to us required. |
|---|---|
| For 30 days after termination | Your data is retained in read-only form so you can still export it. Tell us in this window if you want it deleted sooner and we will delete it sooner. |
| After 30 days | Customer Personal Data is deleted from production systems. |
| Backups | Encrypted backups age out on their own rolling cycle, within 35 days of deletion from production. They are never restored except to recover from a failure, and anything restored is re-deleted. |
| What we keep, and why | Records we are legally required to retain, principally invoices and payment records for 7 years under HMRC rules, are retained for that purpose only, remain protected by this DPA, and are deleted when the obligation ends. |
On request we will certify deletion in writing.
11. Audits and Evidence
We will make available all information reasonably necessary to demonstrate compliance with Article 28, and allow for and contribute to audits and inspections conducted by you or an auditor you mandate.
In the first instance we will answer questions, complete a security questionnaire, and share our current security documentation, sub-processor list and DPIA material. Most compliance needs are met here, and we would rather answer properly than be inspected.
Where that genuinely does not satisfy a requirement, you may audit us on at least 30 days' written notice, no more than once in any 12 months (except after a Personal Data Breach, or where a Supervisory Authority requires it, when there is no limit). An audit must happen during business hours, must not unreasonably disrupt our operations, must not access any other customer's data, and is subject to confidentiality. Each party bears its own costs.
12. International Transfers
Customer Personal Data is stored in the European Economic Area. See Annex 1 for the region. The EEA is covered by UK adequacy regulations, so this is not a restricted transfer.
Some Sub-processors in Annex 2 are established outside the UK and EEA, principally in the United States. For any restricted transfer we put in place an appropriate Article 46 safeguard before the transfer begins: normally the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, and we carry out a transfer risk assessment. Copies are available on request.
Where an adequacy regulation covers a destination, we may rely on it instead. If an adequacy regulation is withdrawn or a transfer mechanism is invalidated, we will implement an alternative safeguard or stop the transfer.
13. Your Obligations
This section is short but it carries the parts of the law we cannot do for you.
- Establish your lawful basis. You must have one under Article 6 for every category of Customer Personal Data you put into the Platform, and a condition under Article 9 for any special category data, which includes health & safety records describing an injury to a named person.
- Tell people. Your staff and your clients must be given the information Articles 13 and 14 require, in your own privacy notice. We help. CleanFlo shows staff a plain-English notice before any location is recorded, and links our privacy notice from the cleaner app, the staff invitation and the client portal, but your own notice is yours to write and must reflect what you actually do.
- Location, specifically. If you use location capture, say so in your staff privacy notice and be able to justify it. We have built it to be proportionate: two points per job, never continuous, declining is free of consequence, but proportionality is a judgement you make about your own workforce.
- Special category data. If you record injuries, the Data Protection Act 2018 requires you to hold an Appropriate Policy Document. Ask us and we will share a template.
- Keep it accurate and lawful. You are responsible for the accuracy, quality and legality of Customer Personal Data and for how it was obtained.
- Look after your accounts. Keep credentials confidential, remove people who leave promptly, and grant the lowest role that lets someone do their job.
14. Liability, Term and Changes
14.1 Liability
Each party's liability under this DPA is subject to the exclusions and cap in Section 8 of the Terms. Nothing in this DPA limits any liability that cannot lawfully be limited, and nothing in it affects a Data Subject's rights under Article 82 to compensation directly from either of us.
14.2 Term
This DPA takes effect when you accept the Terms and continues for as long as we process Customer Personal Data. Sections 5, 10, 11, 12 and 14 survive its termination.
14.3 Changes
We may update this DPA where the law changes, where a Supervisory Authority issues new guidance, or to reflect a change in how the Platform works. Any change that materially reduces your protection or ours will be notified at least 30 days in advance by email and in-app notice. Sub-processor changes follow Section 7.2 instead.
15. Contact
Questions about this DPA, requests for a countersigned copy, security questionnaires and audit requests all go to:
WhealBit (trading as CleanFlo). Data Privacy
Email: privacy@cleanflo.io
Website: https://cleanflo.io
A1. Annex 1, Description of the Processing
| Subject matter | Provision of the CleanFlo cleaning-operations platform to the Customer. |
|---|---|
| Duration | The term of the Customer’s subscription, plus the retention periods in Section 10. |
| Nature of the processing | Collection, recording, organisation, structuring, storage, retrieval, use, transmission by email and push notification, restriction, erasure and destruction. All by automated means through the Platform. |
| Purpose | Scheduling and dispatching cleaning work; recording attendance and job completion; invoicing and payment tracking; managing staff records and availability; managing client records and the client portal; health & safety record-keeping; internal messaging; reporting and analytics for the Customer’s own business. |
| Categories of Data Subject | The Customer’s employees, workers and contractors (“staff” / “cleaners”); the Customer’s clients and their nominated contacts; individuals who submit an enquiry or quote request to the Customer; individuals named in a health & safety record. |
| Personal Data: staff | Name, job title, email address, phone number, employment start date, role and status, pay rate, work performance records (job completions, check-in and check-out times, checklist completions), device location captured at job start and job completion only, internal messages, notes recorded by the employer, calendar feed token, hashed password. |
| Personal Data: clients and contacts | Name, company name, email address, phone number, billing and site addresses, property details, service history, invoices and payment status, portal access credentials, ratings, complaints, messages, notes recorded by the Customer, and photographs taken at their premises in the course of the work. |
| Special category data | Data concerning health, where a health & safety record describes an injury to a named individual, together with any photograph attached to that record. Processed only because the Customer records it; never used by us for any purpose of our own. |
| Criminal offence data | None is required or requested by the Platform. The Customer must not enter it into free-text fields. |
| Children’s data | The Platform is not directed at children. Staff records may relate to workers aged 16 or 17 who are lawfully employed; the Customer is responsible for the additional care those records warrant. |
| Frequency | Continuous, for the duration of the subscription. |
| Storage location | European Economic Area. Amazon Web Services, Ireland (eu-west-1), via our hosting provider. |
| Retention | As set out in Section 10 of this DPA and Section 8 of the Privacy Policy. |
A2. Annex 2, Approved Sub-processors
Current as at 23 August 2026. The maintained list, with change history, is at cleanflo.io/subprocessors.
| Supabase, Inc.. USA (data hosted in Ireland, eu-west-1) | Database hosting, authentication, file storage and serverless functions. Processes all categories in Annex 1. Transfer mechanism: EU SCCs with UK Addendum. |
|---|---|
| Netlify, Inc.. USA | Application hosting and content delivery. Processes IP addresses and request metadata. Transfer mechanism: EU SCCs with UK Addendum. |
| Stripe, Inc., USA / Stripe Payments Europe Ltd, Ireland | Subscription billing. Processes account holder billing data only; no staff or client data. Transfer mechanism: EU SCCs with UK Addendum. |
| Resend, Inc.. USA | Transactional and marketing email delivery. Processes recipient names, email addresses and message content. Transfer mechanism: EU SCCs with UK Addendum. |
| Cloudflare, Inc.. USA | Turnstile bot protection on sign-in and sign-up. Processes IP address and browser/device signals. Transfer mechanism: EU SCCs with UK Addendum. |
| OpenStreetMap Foundation. United Kingdom | Map tiles for site locations. Receives the map area viewed and the requesting IP address. No restricted transfer. |
| Ideal Postcodes (postcodes.io): United Kingdom | UK postcode lookup. Receives the postcode being looked up. No restricted transfer. |
| Google LLC, Apple Inc., Mozilla Foundation | Push notification delivery, where the Customer’s staff enable it. Receives the notification payload and a device endpoint identifier. Engaged only because the recipient’s own browser or device requires it; disabling push in Settings removes them entirely. |