Data Processing Addendum

Last updated: 30 July 2026

This Data Processing Addendum forms part of the LinesFlow Terms. It applies when Linesflow Ltd processes personal data on a customer’s behalf, including where the customer acts for a client. In that processing, the customer is the controller or processor, and Linesflow Ltd is its processor or sub-processor.

1. Processing details

  • Subject: document capture, extraction, review, reconciliation, publishing, support, security, and deletion.
  • Duration: the service term plus the documented deletion and backup periods.
  • People: customer users and individuals identified in invoices, credit notes, statements, supplier files, and accounting records.
  • Data: identity and contact details, transaction and employment-related details, account codes, bank references, document content, and audit metadata.
  • Purpose: providing the features selected and instructed by the customer.

The customer must avoid special-category or criminal-offence data unless the parties first record appropriate instructions and safeguards.

2. Customer instructions and responsibilities

The Terms, product configuration, authorised user actions, and documented support requests are the customer’s instructions. The customer is responsible for the lawfulness, accuracy, minimisation, and retention of data supplied. We will notify the customer if an instruction appears to breach data-protection law, unless prohibited from doing so, and may pause the affected processing.

3. Our processor commitments

We will:

  • process personal data only on documented instructions, including for international transfers, unless UK law requires otherwise;
  • ensure people authorised to process it are bound by confidentiality;
  • maintain risk-appropriate technical and organisational security controls, including access control, encryption where appropriate, secure development, logging, backups, vulnerability management, and incident response;
  • help the customer respond to individual-rights requests and meet security, breach-notification, DPIA, and regulator-consultation duties, taking account of the processing and information available to us;
  • notify the customer without undue delay after confirming a personal-data breach affecting customer data and provide available facts and updates;
  • provide information reasonably needed to demonstrate compliance and permit a proportionate audit no more than annually, unless an incident or regulator requires more frequent review.

4. Sub-processors

The customer generally authorises sub-processors used to deliver LinesFlow. Current categories include hosting and deployment (Render and Vercel), database infrastructure (Supabase), authentication (Google), email (Resend), payments (Stripe), and AI extraction (OpenAI and, only if configured, DeepSeek). The current register identifies their functions and transfer controls. Customer-selected accounting platforms are third-party services instructed by the customer rather than our general infrastructure sub-processors.

We will give at least 15 days’ notice before adding or replacing a material sub-processor where practicable. A customer may object on reasonable data-protection grounds during that period. The parties will work in good faith on an alternative; if none is reasonably available, the customer may terminate the affected feature.

5. International transfers

We will not transfer protected data outside the UK without a lawful mechanism. Depending on destination and provider, this may be UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to approved standard contractual clauses, together with supplementary measures identified by a transfer-risk assessment.

6. Return and deletion

The customer can export account data during the term. On valid deletion or termination instructions, we delete or return customer personal data within 30 days, unless law requires retention. Copies in protected backups remain isolated from routine use and are removed through the normal backup cycle. Required legal records remain protected and are used only for that purpose.

7. Priority and contact

If this addendum conflicts with the Terms on processing personal data, this addendum prevails. Email privacy@linesflow.com for data protection matters.