Coreflow Data Processing Agreement | Version 1.1, July 2026
Streamline Digital Limited

Data Processing Agreement

The Coreflow platform | Streamline Digital Ltd

Version 1.1, July 2026. Supersedes the version scoped to Coreflow AI and Coreflow Operations only.

Between: Streamline Digital Ltd ("Processor") and the Customer named in the Order Confirmation ("Controller").

Background

This Data Processing Agreement ("DPA") is entered into between Streamline Digital Ltd, a company registered in England and Wales under number 06785278 with registered office at Jubilee House, East Beach, Lytham St Annes, FY8 5FT ("Processor"), and the Client identified above ("Controller").

The Processor provides the Controller with access to the Coreflow platform, comprising the Modules set out in the Controller’s Order Confirmation (which may include Coreflow Integration, Coreflow Operations, Coreflow AI and Coreflow Signable), together with associated professional services (the "Services"), under the Coreflow Subscription Terms issued by Streamline Digital Ltd together with the Order Confirmation and the applicable Module Schedules or, for customers on earlier terms, the Master Services Agreement or equivalent commercial agreement between the parties (in each case the "Principal Agreement"). In the course of providing the Services, the Processor processes Personal Data on behalf of the Controller.

This DPA reflects the requirements of Article 28 of the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018, and sets out the terms on which such processing takes place. It is supplemental to and forms part of the Principal Agreement. In the event of conflict between this DPA and the Principal Agreement, this DPA prevails in respect of the processing of Personal Data.

1. Definitions

"Controller"the Client, who determines the purposes and means of processing of Personal Data under this DPA.
"Processor"Streamline Digital Ltd, who processes Personal Data on behalf of the Controller.
"Data Subject"an identified or identifiable natural person to whom Personal Data relates.
"Personal Data"any information relating to an identified or identifiable natural person, as defined in the UK GDPR.
"Processing"any operation or set of operations performed on Personal Data, as defined in the UK GDPR.
"Personal Data Breach"a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.
"Sub-Processor"any third-party processor engaged by the Processor to carry out processing activities on behalf of the Controller in connection with this DPA.
"Supervisory Authority"the Information Commissioner’s Office (ICO).
"Restricted Transfer"a transfer of Personal Data to a country or territory outside the United Kingdom which is not subject to an adequacy decision.
"IDTA"the International Data Transfer Agreement issued by the ICO under section 119A of the Data Protection Act 2018, or any successor instrument.
"Module Schedule"a schedule to the Principal Agreement setting out terms specific to a Module of the Coreflow platform.
"Principal Agreement"the agreement identified in the Background to this DPA.

2. Details of processing

Subject matterProvision of the Coreflow platform and the Modules applicable to the Order Confirmation, together with associated professional services.
DurationFor the term of the Principal Agreement and until all Personal Data is returned or deleted following termination, in accordance with clause 3.8.
Nature of processingCollection, storage, organisation, structuring, retrieval, use, disclosure, transmission, erasure and destruction of Personal Data as required to deliver the platform and professional services.
Purpose of processingTo enable the Controller to run its business on the Coreflow platform, including marketing, lead generation and communications via Coreflow AI; business operations, invoicing, service delivery and workflows via Coreflow Operations; the connection of the Controller’s systems via Coreflow Integration; and electronic signature via Coreflow Signable, in each case as applicable to the Order Confirmation.
Types of Personal DataNames, email addresses, telephone numbers, postal addresses, company information, communication history, behavioural and engagement data, signatures and signature audit data, documents submitted for signature (which may contain any category of personal data the Controller includes in them), and any other personal data submitted by the Controller or its authorised users to the platform.
Categories of Data SubjectsThe Controller’s customers, prospective customers, leads, members, employees, contractors, suppliers, signatories and recipients of documents, and any other individuals whose personal data is submitted to or generated within the platform by the Controller.

3. Processor obligations

3.1Instructions. The Processor shall only process Personal Data on the documented instructions of the Controller, unless required to do so by applicable law. Where required by law to process without instructions, the Processor shall inform the Controller of that legal requirement before processing, unless prohibited by law. The Processor shall promptly notify the Controller if, in its reasonable opinion, any instruction infringes the UK GDPR or other applicable data protection legislation, without being obliged to act on that instruction pending the Controller’s response.

3.2Confidentiality of processing. The Processor shall ensure that all persons authorised to process Personal Data are subject to binding obligations of confidentiality, whether by contract or operation of law, and shall ensure such obligations remain in force after any change of personnel.

3.3Technical and organisational security measures. The Processor shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk of the processing, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing. Such measures shall include as appropriate:

pseudonymisation and encryption of Personal Data at rest and in transit

ongoing confidentiality, integrity, availability and resilience of processing systems and services

the ability to restore the availability and access to Personal Data in a timely manner following a physical or technical incident

a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational security measures

access controls and authentication mechanisms to restrict access to Personal Data to authorised personnel only

staff training on data protection and information security obligations

3.4Sub-processing. The Processor shall not engage any new Sub-Processor or replace any existing Sub-Processor without providing the Controller with prior written notice of at least thirty (30) days, giving the Controller the opportunity to object on reasonable data protection grounds. The Controller’s general written authorisation is given for the Sub-Processors listed in clause 6. The Processor shall: (a) impose data protection obligations on each Sub-Processor that are no less protective than those set out in this DPA; (b) remain fully liable to the Controller for the performance of each Sub-Processor’s obligations; and (c) enter into a written agreement with each Sub-Processor incorporating terms equivalent to those in this DPA.

3.5Changes made by a Sub-Processor to its own sub-processors. Some Sub-Processors allow the Processor a period shorter than thirty (30) days in which to object to changes to their own sub-processors, after which the Processor is deemed to have consented: at the date of this DPA, HighLevel Inc. allows fourteen (14) days and Signable Ltd allows ten (10) business days. For such changes, the Processor shall inform the Controller as soon as reasonably practicable after being informed itself, and the Controller must raise any objection within seven (7) days of that notice so that the Processor is able to object in time. The Processor cannot give the Controller a longer objection period than it holds itself. The periods that apply are set out in the applicable Module Schedule.

3.6Data Subject rights. The Processor shall assist the Controller, by appropriate technical and organisational measures and taking into account the nature of the processing, to fulfil the Controller’s obligations to respond to requests from Data Subjects exercising their rights under UK GDPR, including rights of: access (Article 15); rectification (Article 16); erasure (Article 17); restriction (Article 18); data portability (Article 20); and objection (Article 21). The Processor shall forward any Data Subject request received directly by the Processor to the Controller without delay and shall not act on any such request without the Controller’s written instruction.

3.7Assistance with Controller compliance. The Processor shall assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 of the UK GDPR, having regard to the nature of processing and the information available to the Processor, including security of processing (Article 32); notification of Personal Data Breaches to the Supervisory Authority (Article 33); communication of Personal Data Breaches to Data Subjects (Article 34); data protection impact assessments (Article 35); and prior consultation with the Supervisory Authority (Article 36).

3.8Personal Data Breach notification. The Processor shall notify the Controller without undue delay, and in any event within forty-eight (48) hours of becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of the Controller. Such notification shall include, to the extent then known: (a) a description of the nature of the breach, including the categories and approximate number of Data Subjects and Personal Data records affected; (b) the name and contact details of the Processor’s data protection contact; (c) the likely consequences of the breach; and (d) the measures taken or proposed to address the breach and mitigate its possible adverse effects. Where the information cannot be provided at the same time, it may be provided in phases without undue further delay.

3.9Return and deletion of Personal Data. Upon termination or expiry of the Principal Agreement, or upon the Controller’s written request, the Processor shall, at the Controller’s election: (a) securely return all Personal Data to the Controller in a commonly used machine-readable format; or (b) securely and permanently delete all Personal Data and all copies thereof. The Processor shall complete such return or deletion within thirty (30) days of the request or termination date, and shall provide written confirmation once complete. The Processor may retain Personal Data to the extent required by applicable law, and shall notify the Controller of any such retention obligation.

3.10Sub-Processor retention the Processor cannot override. Where a Sub-Processor retains Personal Data for a period the Processor cannot override, that retention is set out in the applicable Module Schedule, and the Controller instructs the Processor and that Sub-Processor to retain the data for that period. Clause 3.9 applies subject to this clause. At the date of this DPA this applies to Signable Ltd, which retains envelopes and associated data for approximately seven (7) years from the end of the provision of its service. The Controller may at any time during that period require the data to be returned and deleted, and the Processor shall pass the request to the Sub-Processor and use reasonable endeavours to give it effect.

3.11Records of processing. The Processor shall maintain accurate written records of all categories of processing activities carried out on behalf of the Controller, as required by Article 30(2) of the UK GDPR, and shall make such records available to the Controller or the Supervisory Authority upon request.

3.12Audit and inspection rights. The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations set out in this DPA, and shall permit and contribute to audits and inspections conducted by the Controller or a third-party auditor mandated by the Controller, subject to: (a) at least thirty (30) days’ prior written notice; (b) a maximum of one audit per calendar year, except where there are reasonable grounds to believe a breach has occurred; (c) the Controller bearing the reasonable costs of any such audit; and (d) any auditor being subject to confidentiality obligations acceptable to the Processor.

3.13Data protection contact. The Processor shall appoint a data protection contact and provide their details to the Controller on request, and shall notify the Controller of any change within ten (10) business days.

4. Controller obligations

4.1The Controller warrants and represents that it has a lawful basis for each instance of processing of Personal Data under UK GDPR, and has provided all necessary privacy notices to and obtained all necessary consents from Data Subjects as required by applicable law.

4.2The Controller shall ensure that its instructions to the Processor comply with all applicable data protection laws and shall not instruct the Processor to process Personal Data in a manner that would cause the Processor to breach applicable law.

4.3The Controller is responsible for the accuracy, quality and lawfulness of the Personal Data submitted to the platform, and for ensuring it is adequate, relevant and limited to what is necessary for the purposes of processing.

4.4The Controller shall maintain its own record of processing activities as required by Article 30(1) of the UK GDPR and shall not rely on the Processor’s records in place of its own obligations.

4.5Where the Controller is itself a processor acting on behalf of its own clients, the Controller warrants that it is authorised to engage the Processor as a sub-processor and that its own controller contract contains data protection obligations no less protective than those in this DPA, and references in this DPA to the Controller’s instructions mean instructions the Controller is itself authorised to give.

5. International data transfers

5.1The Processor shall not transfer Personal Data to a country or territory outside the United Kingdom without the prior written consent of the Controller, unless such transfer is covered by: (a) an adequacy decision made by the Secretary of State under the UK GDPR; (b) appropriate safeguards under Article 46 UK GDPR, including an IDTA or the UK Addendum to the EU Standard Contractual Clauses; or (c) an applicable derogation under Article 49 UK GDPR.

5.2The parties acknowledge that the Coreflow AI platform is delivered through HighLevel Inc., whose infrastructure is hosted on Amazon Web Services and Google Cloud Platform, operated in the United States of America. UK transfers of Personal Data to HighLevel Inc. are governed by HighLevel Inc.’s Customer Data Processing Addendum, which incorporates the EU 2021 Standard Contractual Clauses together with the UK Transfer Addendum (being the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued pursuant to Section 119A(1) of the Data Protection Act 2018). HighLevel Inc. is also certified to the UK Extension to the EU-US Data Privacy Framework as an additional safeguard. The Processor shall: (a) maintain its agreement with HighLevel Inc. incorporating these transfer mechanisms for the duration of this DPA; (b) monitor HighLevel Inc.’s published DPA for material changes; and (c) notify the Controller without undue delay of any change that may affect the lawfulness of the transfer.

5.3Where Microsoft Azure processes Personal Data within the United Kingdom or European Economic Area in connection with the Coreflow Operations platform or the Coreflow Integration engine, no Restricted Transfer occurs. Where Azure processes Personal Data outside these territories, the Processor shall ensure that appropriate safeguards are in place and shall notify the Controller.

5.4Personal Data processed by Signable Ltd in connection with Coreflow Signable is hosted in the United Kingdom. No Restricted Transfer occurs.

5.5The Processor shall conduct a Transfer Risk Assessment in respect of any Restricted Transfer where required under applicable ICO guidance and shall make the outcome available to the Controller on request.

6. Approved Sub-Processors

The Controller grants its general written authorisation for the Processor to use the following Sub-Processors in connection with the delivery of the platform and professional services. Clauses 3.4 and 3.5 govern changes. Where the Controller objects and the objection is unresolved within fourteen (14) days, either party may terminate the affected Module or, where the Module cannot be severed, the Principal Agreement, on thirty (30) days’ written notice without penalty.

Sub-ProcessorProcessing activityLocation / transfer mechanism
HighLevel Inc.Core platform delivery for Coreflow AI: marketing automation, communications, funnel and website delivery, and data storage.United States. Restricted Transfer. EU 2021 SCCs plus UK Transfer Addendum (via the HighLevel DPA). Also certified to the UK Extension to the EU-US Data Privacy Framework.
Amazon Web Services / Google LLC (Google Cloud)Cloud infrastructure and hosting engaged by HighLevel Inc. as its contracted sub-processors. Coreflow AI only.United States. Restricted Transfer governed by HighLevel Inc.’s sub-processor agreements.
Microsoft Corporation (Azure)Cloud infrastructure, storage and compute for Coreflow Operations and the Coreflow Integration engine, operated directly by Streamline Digital Ltd.United Kingdom (UK South / UK West). No Restricted Transfer. Where processing occurs outside the UK, IDTA or equivalent safeguards apply.
Signable LtdElectronic signature for Coreflow Signable: envelope delivery, signing, audit trail and storage of signed documents. Retention per clause 3.10.United Kingdom (AWS London). No Restricted Transfer. ISO 27001 certified.
Stripe, Inc. / GoCardless Ltd (as applicable)Payment processing for subscription and implementation fees. Applies to the whole platform.United States / United Kingdom. Restricted Transfer (Stripe) covered by EU 2021 SCCs plus UK Transfer Addendum. GoCardless: UK-based, no Restricted Transfer.

The Processor shall maintain an up-to-date list of Sub-Processors, published on the Coreflow Trust Centre, and shall make it available to the Controller on request. The Processor shall ensure that each Sub-Processor is subject to written data processing terms that provide at least equivalent protections to those in this DPA.

7. Security incidents and breach management

7.1The Processor shall maintain a documented incident response procedure covering detection, assessment, containment, notification and post-incident review of Personal Data Breaches.

7.2The Processor shall co-operate fully with the Controller in the event of a Personal Data Breach, including by providing all information required by the Controller to notify the Supervisory Authority under Article 33 UK GDPR and, where required, to communicate with affected Data Subjects under Article 34 UK GDPR.

7.3The Processor shall not make any public statement or notification to the Supervisory Authority regarding a Personal Data Breach involving the Controller’s Personal Data without the prior written consent of the Controller, except where required by law.

8. Liability

8.1Each party’s liability under this DPA is subject to the limitations and exclusions set out in the Principal Agreement, save that nothing in the Principal Agreement or this DPA shall limit either party’s liability for: (a) fines or penalties imposed by the Supervisory Authority arising from that party’s own breach of UK GDPR; or (b) claims brought by Data Subjects in respect of that party’s own unlawful processing.

8.2The Controller shall indemnify and hold harmless the Processor against all claims, losses, damages, fines, penalties, costs and expenses incurred by the Processor arising from the Controller’s failure to comply with its obligations under this DPA or applicable data protection law.

8.3The Processor shall indemnify and hold harmless the Controller against all claims, losses, damages, fines, penalties, costs and expenses incurred by the Controller arising directly from the Processor’s failure to comply with its obligations under this DPA or applicable data protection law. This indemnity is subject to the limitations in the Principal Agreement as clause 8.1 provides.

9. General

9.1This DPA shall be governed by the laws of England and Wales and is subject to the exclusive jurisdiction of the courts of England and Wales.

9.2In the event of any conflict between this DPA and the Principal Agreement, this DPA shall prevail in respect of the subject matter of data protection and the processing of Personal Data.

9.3This DPA shall remain in force for the duration of the Principal Agreement and shall survive termination for as long as the Processor retains any Personal Data of the Controller.

9.4The parties shall review this DPA at least annually and shall update it as necessary to reflect changes in applicable data protection law, Sub-Processors or processing activities.

9.5This DPA may be executed in counterparts, each of which shall be deemed an original and which together shall constitute one agreement. Electronic signatures shall be valid and binding.

Execution

This DPA is incorporated into the Agreement by clause 15.1 of the Coreflow Subscription Terms and applies to the processing of Personal Data without the need for separate signature. It takes effect on the date of the Order Confirmation.

Customers who require an executed copy, for example for their own processing records or a client audit, can request one at any time. We will issue a counterpart naming your organisation, signed electronically by Streamline Digital Ltd and counter-signed by you.

Streamline Digital Limited · Registered in England and Wales, company no. 06785278 · Registered office: Jubilee House, East Beach, Lytham St Annes, FY8 5FT · Coreflow Data Processing Agreement, version 1.1, July 2026.