Data Processing Agreement
Last updated: 1 July 2026 ยท UK GDPR Article 28 compliant ยท EU SCCs available
1. Parties
This Data Processing Agreement (โDPAโ) is entered into between:
- Data Controller: The Client organisation engaging 2-IC DATA SYSTEMS for data migration services, as identified in the project Statement of Work or migration intake form.
- Data Processor: 2-IC DATA SYSTEMS, registered in England and Wales, operating the Flow-X platform at flow-x.madethis.app.
This DPA is incorporated into and forms part of the Terms of Service and applies to all engagements involving the processing of personal data.
2. Nature and Purpose of Processing
2-IC DATA SYSTEMS processes personal data solely for the purpose of performing CRM and ERP data migration services as described in the agreed Statement of Work. Processing activities may include: extraction, transformation, validation, migration, deduplication, field mapping, and deletion of personal data records held within the Client's source and target systems.
2-IC DATA SYSTEMS acts as a data processor only and does not use Client personal data for any other purpose.
3. Types of Personal Data & Data Subjects
- Data subjects: The Client's customers, prospects, partners, and employees whose records are held in the source system.
- Data categories: Names, email addresses, phone numbers, job titles, company affiliations, transaction history, CRM notes, and any other fields present in the source dataset.
- Special categories: The Client must notify 2-IC DATA SYSTEMS before migration if any special category data (Art. 9 GDPR) is present in the dataset.
The Client warrants it has a lawful basis for holding and transferring such data for migration purposes.
4. Processor Obligations (UK GDPR Article 28)
- Process personal data only on documented instructions from the Controller (the agreed SOW), unless required by UK law.
- Ensure all persons authorised to process personal data are subject to a duty of confidentiality.
- Implement appropriate technical and organisational measures to ensure security appropriate to the risk (see Section 8).
- Not engage sub-processors without prior written consent (general authorisation provided by acceptance of these Terms for listed sub-processors in Section 6).
- Assist the Controller in fulfilling data subject rights requests.
- Assist the Controller in compliance with Articles 32โ36 (security, breach notification, DPIA).
- At the Controller's choice, delete or return all personal data after service delivery. Standard deletion within 30 days of project close.
- Make available all information necessary to demonstrate compliance and allow for audits.
5. Controller Instructions
The Controller's processing instructions are documented in the Statement of Work. The Controller shall not instruct processing in violation of UK GDPR or applicable law. 2-IC DATA SYSTEMS will notify the Controller promptly if it believes an instruction would lead to such a violation.
6. Sub-Processors
| Sub-Processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Platform hosting and edge delivery | USA (IDTA/SCCs) |
| Convex Inc. | Database and serverless backend | USA (IDTA/SCCs) |
| Stripe Inc. (via MadeThis) | Payment processing | USA (IDTA/SCCs) |
| PostHog Inc. | Product analytics (non-migration data only) | EU |
14 days' notice will be given of any changes to sub-processors. Each sub-processor is engaged under a contract with equivalent data protection obligations.
7. International Data Transfers
Where personal data is transferred outside the UK to non-adequate countries, 2-IC DATA SYSTEMS relies on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to EU Standard Contractual Clauses (EU SCCs with UK Addendum). EU SCCs (Module 2) are available for EU-to-processor transfers on request.
8. Technical & Organisational Security Measures
- Encryption at rest (AES-256) and in transit (TLS 1.2+)
- Role-based access controls โ only assigned project team members access Client data
- Isolated project workspaces โ no data co-mingling between clients
- Regular access reviews and credential rotation
- Audit logs for all data access events
- Secure deletion within 30 days of project completion
- Staff confidentiality obligations (NDAs in place)
- Incident response plan aligned with 72-hour breach notification requirement
- GDPR compliance scan embedded in migration pipeline (PII field detection)
9. Breach Notification
In the event of a personal data breach affecting Client data, 2-IC DATA SYSTEMS will notify the Controller without undue delay and, where feasible, within 72 hours of becoming aware. Notification will include: nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed.
10. Data Deletion Post-Migration
Upon completion or termination, within 30 calendar days, 2-IC DATA SYSTEMS will:
- Securely delete all copies of Client personal data from project workspaces
- Instruct sub-processors to delete their copies where applicable
- Provide written confirmation of deletion upon request
11. EU Standard Contractual Clauses
For engagements involving EU personal data transferred to a UK-based processor, this DPA incorporates the EU Standard Contractual Clauses (Commission Decision 2021/914, Module 2: Controller to Processor) with the UK Addendum (ICO, March 2022). A countersigned copy incorporating the SCCs and Annexes IโIII is available on request.
12. Audit Rights
The Controller may, on 14 days' written notice, request information to verify compliance or commission an independent audit at the Controller's expense, during business hours, without unreasonably disrupting operations. Third-party certifications or summary reports may satisfy audit requests where they demonstrate compliance.
13. Contact & DPO
For DPA queries, data subject rights assistance, or to request a countersigned copy, contact our Data Protection Officer at team@flow-x.madethis.app.
Need a countersigned copy?
Use โSave / Print PDFโ for your records, or email team@flow-x.madethis.app to request a countersigned PDF with completed Annexes IโIII for enterprise procurement.
Related policies