Data Processing Addendum
Billflow's standard processor terms for personal data a business instructs Billflow to process on its behalf.
Last updated 16 August 2026
This DPA applies where it is incorporated into the agreement between a Billflow customer (the “Customer”) and Billflow. For procurement, a countersigned copy or agreed amendments, contact hello@billflowinvoicing.com.
1. Roles and scope
For Customer Personal Data processed through Billflow on the Customer's documented instructions, the Customer acts as controller (or as a processor acting for another controller, where applicable) and Billflow acts as processor. Each party remains responsible for the obligations that apply to it under applicable data-protection law.
“Customer Personal Data” means personal data submitted to, generated in or made available to Billflow by or for the Customer in connection with the service, excluding personal data Billflow processes independently for its own account administration, billing, security, fraud prevention or legal obligations.
2. Processing instructions
Billflow will process Customer Personal Data only on the Customer's documented instructions, including instructions expressed through the Customer's configuration and authorised use of the service, unless UK law requires otherwise. Where legally permitted, Billflow will inform the Customer before carrying out processing required by law.
Billflow will inform the Customer if, in Billflow's reasonable view, an instruction infringes applicable data-protection law and may pause the affected processing while the parties resolve the issue.
3. Confidentiality and access
Billflow will ensure that people authorised to process Customer Personal Data are subject to appropriate confidentiality obligations and that access is limited to what is reasonably required to provide, secure and support the service.
4. Security
Taking account of the nature, scope, context and purposes of processing and the relevant risks, Billflow will maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Current product safeguards are described in the Billflow Trust Centre. Security measures may evolve as the service changes, provided the overall level of protection is not materially reduced during the agreement.
5. Subprocessors
The Customer gives Billflow general written authorisation to use subprocessors necessary to provide the service. Billflow will impose data-protection obligations on subprocessors that provide an equivalent level of protection for the Customer Personal Data relevant to their processing.
Billflow publishes its current subprocessor list. Where the parties have agreed a subprocessor-change notice process, Billflow will provide the agreed notice and a reasonable opportunity to object on legitimate data-protection grounds.
6. Individual rights
Taking into account the nature of the processing, Billflow will provide reasonable assistance through appropriate technical and organisational measures to help the Customer respond to requests from individuals exercising applicable data-protection rights. Billflow will not independently decide whether the Customer must grant a request concerning data the Customer controls.
7. Security incidents, DPIAs and regulatory assistance
Billflow will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and will provide available information reasonably required for the Customer's assessment and notifications.
Taking into account the nature of processing and information available to Billflow, Billflow will reasonably assist the Customer with security obligations, breach notifications, data-protection impact assessments and prior consultation with a supervisory authority where those obligations relate to Billflow's processing for the Customer.
8. Return and deletion
At the end of the services involving Customer Personal Data, Billflow will, at the Customer's choice and subject to applicable law, delete or return Customer Personal Data and delete remaining copies under Billflow's control. Limited data may be retained where required by law, for security/fraud prevention, legal claims or within protected backup cycles until overwritten in the ordinary course.
9. Demonstrating compliance and audits
Billflow will make information reasonably necessary to demonstrate compliance with these processor obligations available to the Customer. Subject to appropriate confidentiality, security and operational safeguards, Billflow will allow and contribute to reasonable audits or inspections required by applicable data-protection law, with the parties first using available documentation and remote evidence where that can reasonably satisfy the request.
10. International transfers
Billflow will not make a restricted transfer of Customer Personal Data unless an applicable lawful transfer mechanism or exception is in place. Where required, this may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses, or another legally recognised safeguard.
11. Customer responsibilities
The Customer is responsible for ensuring it is entitled to provide Customer Personal Data to Billflow, that its instructions are lawful, and that it gives individuals the information required about its use of Billflow. The Customer should configure user access, automation and integrations appropriately for its business and the sensitivity of the data involved.
Schedule 1 — Details of processing
Subject matter and purpose
Providing Billflow's invoicing, payment tracking, collections, customer administration, communications and configured AI/automation functionality, together with service security, support and maintenance.
Duration
For the duration of the applicable customer agreement and any limited period required for secure deletion, backup expiry or lawful retention.
Nature of processing
Collection, storage, organisation, retrieval, consultation, transmission to authorised service providers, generation of invoices and communications, classification and other configured operations necessary to provide Billflow.
Categories of data subjects
The Customer's customers, prospective customers, suppliers or other contacts whose information the Customer is authorised to manage, plus authorised Customer users where relevant to workspace activity.
Typical personal data
Names, business/contact details, invoice and transaction-related information, payment status, jobs/bookings or service descriptions, communications and customer-service/collections records supplied or generated through the service.
Billflow is not intended to be used as a general repository for special-category personal data. Customers should not import sensitive data merely because a connected system contains it.
Schedule 2 — Security and subprocessors
The current security overview is maintained in the Trust Centre. The current production provider register is maintained at Subprocessors. These schedules form part of the operational description of this DPA and may be updated as Billflow develops, subject to the protections in this DPA and any agreed notice rights.