Data processing addendum
TradeFlow.studio · updated 26 September 2026
1. Roles and scope
For customer, lead, job, quote and invoice personal data entered by a business into its workspace, that business is the controller and TradeFlow is the processor. Processing lasts while the workspace is active and until its data is deleted under the Terms. It covers storing, displaying, updating, backing up and deleting records to provide TradeFlow. Data may include names, contact details, addresses, appointment details, job notes and financial records about the business’s customers, staff and contacts. The business determines its lawful basis and the content it enters.
2. Instructions and confidentiality
TradeFlow processes workspace data only to provide the service, on the controller’s documented instructions in the Terms and in-app actions, or as required by UK law. We will inform the controller before processing required by law unless the law prevents this. People authorised to process workspace data must be bound by confidentiality.
3. Security
We apply access controls, encrypted connections, database encryption at rest, tenant isolation and security logging appropriate to the risk. We review these measures and restrict operational access. The business is responsible for its users’ permissions and for keeping account credentials secure.
4. Subprocessors
The controller generally authorises Render (application hosting) and Neon (database hosting) to process workspace data, as workspace-data subprocessors. Clerk handles account authentication; Appwrite receives a connection check but no workspace records. We will give notice of a proposed new workspace-data subprocessor and a reasonable opportunity to object. We require subprocessors to protect data under written terms and remain responsible for their performance.
5. Assistance and incidents
Taking account of the processing and information available to us, we will reasonably assist the controller with data subject requests, security obligations, breach notifications, impact assessments and regulator consultations. We will tell the controller without undue delay after becoming aware of a personal data breach affecting its workspace data and share information reasonably needed for its response. Contact help@tradeflow.studio for these requests.
6. Return, deletion and audit
At the end of service, the controller may request a copy or deletion of its workspace data, subject to legal retention duties. We will delete or return it and delete remaining copies when those duties and backup retention allow. We will provide information reasonably needed to show compliance with this addendum and allow or contribute to a reasonable audit arranged with appropriate confidentiality and security safeguards.
7. International transfers
Primary application and database hosting are in Frankfurt, Germany. Any restricted transfer of workspace personal data outside the UK will require an applicable lawful transfer mechanism and safeguards. We will provide relevant transfer information on request.