Legal
Data Processing Agreement
The terms on which we process personal data on your behalf. This applies whenever you use FluxDM to handle conversations with your own customers, which is essentially always.
Last updated 1 September 2026
Before you read on
If you need this signed as a counter-signed document for your own compliance file, including the standard contractual clauses as an executed annex, email [email protected] and we will do that. The page below sets out the terms; a page on a website is not a signature and we are not going to pretend otherwise.
1. Who is who
This agreement supplements our terms of service. You are the controller of the personal data in your workspace. FluxDM LLC is the processor. We process that data only to provide the service and only on your instructions.
Where terms like controller, processor, personal data, processing and data subject appear, they carry the meaning given in the UK GDPR and the EU GDPR.
2. What we process, and why
Subject matter: providing a shared omnichannel inbox — receiving messages from the channels you connect, storing them, letting your team read and reply, linking a person’s identities across channels into one profile, and dispatching replies back to the right platform.
Duration: for as long as you have an account with us, plus the period described in section 8.
Categories of data subject: your customers and anyone who messages a channel you have connected; and your own team members who use the workspace.
Categories of personal data — this depends on what your customers send you, which we do not control:
- Identifiers: names, handles and usernames, platform account IDs, phone numbers, email addresses.
- Message content and attachments, including anything a customer chooses to put in a message.
- Profile data your team adds: tags, notes, custom fields.
- Technical data: IP addresses and device information for web chat visitors, push tokens for your team's devices.
Special category data: FluxDM is not designed for it and you should not use it for that purpose. We recognise a customer may volunteer sensitive information in a message without being asked — a clinic’s patient describing a symptom, for instance. If that is a routine part of your use case rather than an occasional accident, tell us before you sign so we can agree the appropriate additional safeguards instead of discovering it later.
3. Your instructions, and our limits
We process personal data only as needed to provide the service, as set out in this agreement, or as you otherwise instruct in writing. We will tell you if we believe an instruction breaks data protection law.
We do not sell personal data, and we do not use the content of your customers’ conversations for our own purposes, including training machine-learning models.
4. Confidentiality
Access is limited to people who need it to run or support the service, and they are bound by confidentiality obligations.
5. Security
We maintain technical and organisational measures appropriate to the risk. Currently that means:
- Encryption of data in transit over public networks.
- Signature verification on every inbound platform webhook, so forged or replayed payloads are rejected before they reach your inbox.
- Access to a workspace restricted to members you have invited, with administrative functions restricted to administrators.
- Credentials and tokens excluded from application logs.
- Infrastructure firewalled so the application host is not directly reachable from the public internet.
We will not list controls we have not built. If your assessment needs a specific measure that is not above, ask rather than assume, and we will tell you honestly whether we have it.
6. Sub-processors
You give general authorisation for us to engage sub-processors. The current list, what each one does and where it sits, is on our sub-processors page.
We will give you at least 30 days’ notice before adding a sub-processor that processes conversation content, and you may object on reasonable data protection grounds within that period. If we cannot resolve the objection, you may terminate the affected part of the service and we will refund any prepaid, unused fees for it.
Each sub-processor is engaged under a written contract with obligations no less protective than these. Note that the channel providers — Meta, Telegram, TikTok, X, SMS carriers — act on their own terms in respect of messages on their platforms, and connecting a channel necessarily involves them.
Where you enable an AI feature — the answering bot, reply drafts, conversation summaries, automated follow-ups or voice-note transcription — the conversation content that feature operates on is sent to Google LLC (the Gemini API) to generate the result. It is a sub-processor listed on the sub-processors page. As stated in section 3, this is done to provide the feature and never to train machine-learning models. If you would rather no conversation content reach an AI provider, leave the AI features off and none is sent.
The same applies to task-synchronisation integrations you choose to connect. A task integration receives the task title and status only. HubSpot can also receive a customer’s name, email address, phone number and company when you enable contact sync. These providers are listed on the sub-processors page before their release flags are enabled. No message content, internal notes or attachments are sent to them.
7. International transfers
The application, database and cache run on infrastructure in Germany, so conversation data is stored in the EU. FluxDM LLC is a US company, so administrative access originates in the United States, and some sub-processors operate globally.
For transfers of UK or EU personal data to a third country we rely on the European Commission’s standard contractual clauses, with the UK International Data Transfer Addendum where UK data is involved. These are executed as a separate annex on request — see the note at the top of this page.
8. Deletion and return
On termination, or on your written request at any time, we will delete the personal data in your workspace. Ask us at [email protected] and we will confirm in writing when it is done.
Being straight with you about the current state: an admin can erase one end-customer’s personal data in their workspace through the API, and we keep a count-only audit of what was removed. There is still no self-service delete button in the product UI. Backups and logs may retain copies for a short period afterwards. We may keep data where law requires it, and we will tell you what and why if that happens.
You can export customer data from the product at any time, and we will help with a fuller export if you need one.
9. Helping you with data subject requests
If one of your customers contacts us directly with a request about their data, we will not answer it ourselves — we will pass it to you, because you are the controller and it is your call.
Where you need help responding to a request for access, correction, deletion, restriction, objection or portability, we will assist within a reasonable time. Much of it you can do yourself in the product; where you cannot, ask us.
10. Personal data breaches
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any event within 72 hours of becoming aware, with what we know: what happened, which data and roughly how many people are affected, the likely consequences, and what we are doing about it. If the picture is incomplete we will send what we have and follow up rather than waiting until the story is tidy.
Notifying regulators and affected individuals is your decision as controller. We will give you what you need to make it.
11. Audits and information
On reasonable request, and no more than once a year unless a regulator or a breach requires otherwise, we will provide the information you reasonably need to demonstrate our compliance with this agreement. We do not hold third-party certifications such as SOC 2 or ISO 27001 today, and we will say so rather than deflect the question.
12. Annexes
- Annex I — details of processing: as set out in section 2 above.
- Annex II — technical and organisational measures: as set out in section 5 above.
- Annex III — standard contractual clauses and the UK addendum, executed separately on request.
- Annex IV — sub-processors: the sub-processors page, as updated from time to time under section 6.
13. Precedence
Where this agreement conflicts with the terms of service on the processing of personal data, this agreement wins. Where it conflicts with the standard contractual clauses, the clauses win.
Questions about anything on this page? [email protected].