Data Processing Agreement

Last updated: 17 July 2026

WorkflowMind

148 The Rose Bowl, Portland Crescent, Leeds, LS1 3HB, United Kingdom

(" Processor", " WorkflowMind", " we", " us")

This Data Processing Agreement (" DPA") forms part of the agreement between WorkflowMind and the business creating a WorkflowMind workspace (" Controller", " you") for use of the WorkflowMind process-mapping application and related diagnostic and membership services (the " Service"). It applies whenever WorkflowMind processes Personal Data on your behalf as a processor, whether you are a business using the Service directly or a consultant using the Service on a client's behalf.

By ticking the confirmation box when creating a workspace, you agree to this DPA on behalf of yourself and, where applicable, on behalf of the client whose data will be processed in that workspace.


1. Definitions

Terms not otherwise defined below have the meaning given in the UK GDPR and/or EU GDPR (together, " Data Protection Legislation"):

  • "Personal Data", "Processing", "Data Subject", "Controller", "Processor", "Personal Data Breach" — as defined in Data Protection Legislation.
  • "Sub-processor" means any third party engaged by WorkflowMind to process Personal Data on WorkflowMind's behalf in connection with the Service.
  • "Client Data" means Personal Data submitted to, or generated within, a client workspace in the course of using the Service (e.g. names, job titles, or other details of individuals referenced in process maps).

2. Roles of the Parties

2.1 As between WorkflowMind and the Controller, the Controller is the Controller of Client Data and WorkflowMind is the Processor.

2.2 Where a business signs up and uses the Service directly, that business is the Controller of its own Client Data and WorkflowMind is the Processor. This is the default arrangement for the Service.

2.3 Where a consultant creates and administers a workspace on behalf of an end client, the consultant confirms, by accepting this DPA, that they are authorised to do so on the client's behalf, and that either:

(a) the consultant is acting as the client's own processor or authorised representative, in which case the client remains the Controller and the consultant is responsible for having its own lawful basis and arrangements with the client for that role; or

(b) the consultant and client are joint controllers of the Client Data,

and in either case WorkflowMind processes Client Data as a Processor (or sub-processor, as applicable) acting on documented instructions as set out in this DPA.

3. Subject Matter, Duration, and Details of Processing

3.1 Subject matter: provision of the WorkflowMind process-mapping Service, including diagnostic engagements and ongoing membership services delivered using the Service.

3.2 Duration: for as long as the relevant workspace remains active, plus any retention period described in Clause 8.

3.3 Nature and purpose of processing: hosting, storage, display, and enabling of collaborative editing of process maps and related workspace content; providing supporting features such as notifications, in-app support, and payment processing.

3.4 Categories of Data Subjects: employees, contractors, and other individuals of the Controller whose names, roles, or other details are referenced within process maps or workspace content; workspace users (the Controller's team members, and, where applicable, a consultant's team members) themselves.

3.5 Categories of Personal Data: names, job titles/roles, email addresses, and any other Personal Data the Controller chooses to include within process maps or workspace content. WorkflowMind does not require or request special category data (Art. 9 GDPR) and the Controller should avoid including it in workspace content unless strictly necessary and lawful to do so.

4. Processor Obligations

WorkflowMind shall:

4.1 Process Client Data only on the documented instructions of the Controller (including as set out in this DPA and the Terms of Service), unless required to do otherwise by law, in which case WorkflowMind will inform the Controller before processing, unless prohibited from doing so.

4.2 Ensure that persons authorised to process Client Data are subject to confidentiality obligations.

4.3 Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as further described in Annex B.

4.4 Not engage a Sub-processor without the Controller's general authorisation, as set out in Clause 6.

4.5 Taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as reasonably possible, with the fulfilment of the Controller's obligations to respond to requests from Data Subjects exercising their rights under Data Protection Legislation.

4.6 Assist the Controller in ensuring compliance with its obligations relating to security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the information available to WorkflowMind.

4.7 At the Controller's election, and subject to Clause 8, delete or return all Client Data after the end of the provision of the Service, save to the extent retained in backups per Clause 8.

4.8 Make available to the Controller information reasonably necessary to demonstrate compliance with this Clause 4, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable advance notice, confidentiality, and no more than once per year (unless required following a Personal Data Breach or by a supervisory authority).

5. International Transfers

5.1 WorkflowMind hosts and processes data across both EU/EEA and US regions via its Sub-processors listed in Annex A.

5.2 Where Client Data is transferred outside the UK/EEA, WorkflowMind relies on the UK International Data Transfer Addendum and/or EU Standard Contractual Clauses (as applicable), or another valid transfer mechanism recognised under Data Protection Legislation, incorporated by reference into WorkflowMind's agreements with the relevant Sub-processor.

6. Sub-processors

6.1 The Controller provides general authorisation for WorkflowMind to engage the Sub-processors listed in Annex A.

6.2 WorkflowMind will impose data protection obligations on each Sub-processor materially no less protective than those in this DPA.

6.3 WorkflowMind will give the Controller at least 14 days' prior notice (via update to Annex A and/or the WorkflowMind website, or by email where practicable) of any intended addition or replacement of a Sub-processor, giving the Controller the opportunity to object on reasonable data protection grounds within that period. If the Controller objects and the parties cannot resolve the objection, either party may terminate the affected Service in accordance with the Terms of Service.

7. Personal Data Breach

7.1 WorkflowMind will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Client Data, via email to the Controller's registered account contact and/or support@workflowmind.com correspondence, and will provide such information as it has available to assist the Controller in meeting its own notification obligations.

7.2 Notification under this clause is not an acknowledgement by WorkflowMind of fault or liability in respect of the incident.

8. Data Retention and Deletion

8.1 While a workspace is active, Client Data is retained for as long as needed to provide the Service.

8.2 On deletion of a workspace or account, Client Data is removed from live systems; however, it may persist in routine backups maintained by WorkflowMind's hosting Sub-processors (currently Vercel and Supabase) for up to 30 days, after which it is permanently deleted as those backups cycle out.

9. Contact and Data Protection Officer

For any questions about this DPA or Client Data processing:

10. Liability

Each party's liability arising under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service between the parties.

11. Precedence

In the event of a conflict between this DPA and the Terms of Service, this DPA prevails in respect of the processing of Personal Data.


Annex A — Sub-processors

Sub-processorPurposeLocation(s)Transfer Mechanism
VercelApplication hosting / infrastructureUS / EU (edge)SCCs / UK Addendum
SupabaseDatabase hosting and storageUS (us-east-2)SCCs / UK Addendum
OpenAIAI-assisted features (e.g. process map generation/suggestions), used only when a user actively initiates an AI feature such as map generation or a report runUSSCCs
Anthropic (Claude)AI-assisted features, used only when a user actively initiates an AI feature such as map generation or a report runUSSCCs
IntercomCustomer support / in-app messagingUS/EUSCCs
PostHogProduct analyticsEUN/A (EU-hosted)
Google AnalyticsWebsite/product analyticsUSSCCs
StripePayment processingUS/EUSCCs
PostmarkTransactional email deliveryUSSCCs

Note: OpenAI and Anthropic are only given access to process map content when a user actively triggers an AI-assisted feature (e.g. requesting map generation or running a report) — they are not given standing or background access to Client Data. The Controller should ensure Data Subjects are made aware, where relevant, that AI providers may process this content on request, and should avoid triggering AI features on content containing special category data.

Annex B — Technical and Organisational Security Measures

WorkflowMind maintains the following technical and organisational measures:

  • Encryption in transit: all data transmitted to and from the Service is encrypted using TLS.
  • Encryption at rest: data stored in the Service's database and storage infrastructure is encrypted at rest.
  • Access controls: access to Client Data by WorkflowMind personnel is restricted on a role-based, least-privilege basis, limited to personnel who need access to perform their duties.
  • Authentication: user accounts use passwordless authentication via Google Sign-In or one-time email login links; there are no user-managed passwords for the Service.
  • Logging and monitoring: access to production systems and key application events are logged and monitored for suspicious activity.
  • Vulnerability management: WorkflowMind applies security patches to its infrastructure and dependencies on an ongoing basis and monitors for known vulnerabilities.
  • Incident response: WorkflowMind maintains an incident response process to identify, contain, and remediate security incidents, and to support the notification obligations in Clause 7.