Flam Data Processing Agreement
Last updated: 5 September 2026
This Data Processing Agreement ("DPA") forms part of the Flam Terms of Use between Flam Labs Ltd, a company registered in England and Wales under company number 17480585, whose registered office is at Primrose Cottage, Eversley Centre, Hook, Hampshire, RG27 0NF, United Kingdom ("Flam", "we", "us" or "Processor"), and the business or organisation using the Flam Service ("Customer", "you" or "Controller").
This DPA applies where Flam processes Personal Data on behalf of the Customer in connection with the Flam Service.
By agreeing to the Flam Terms of Use and using the Service, the Customer also agrees to this DPA.
1. Definitions
For the purposes of this DPA:
"Applicable Data Protection Law" means the UK GDPR, the Data Protection Act 2018 and other applicable UK data protection and privacy legislation, as amended or replaced from time to time.
"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach" and "Processing" have the meanings given to them under Applicable Data Protection Law.
"Customer Data" means Personal Data processed by Flam on behalf of the Customer through the Service.
"Service" means the Flam websites, applications and services provided to the Customer.
"Sub-processor" means another processor engaged by Flam to process Customer Data in connection with providing the Service.
2. Roles of the parties
The Customer is the Controller of Customer Data processed through Flam.
Flam acts as a Processor of that Customer Data on the Customer's behalf.
The Customer determines the purposes for which Customer Data is collected and processed.
The Customer is responsible for ensuring that its collection and use of Personal Data complies with Applicable Data Protection Law, including establishing an appropriate lawful basis and providing any necessary privacy information to Data Subjects.
Flam will process Customer Data only as necessary to provide the Service and in accordance with the Customer's documented instructions, except where processing is required by applicable law.
The Customer's use and configuration of the Service, together with the Terms of Use and this DPA, constitute documented instructions to Flam.
If Flam is legally required to process Customer Data contrary to those instructions, Flam will inform the Customer before carrying out that processing unless prohibited from doing so by law.
3. Details of the processing
Subject matter
Flam processes Personal Data to provide software that enables service businesses to manage customer enquiries, communications, quotes, payments, bookings and related business activities.
Duration
Processing will continue for as long as the Customer uses the Service and for any limited retention period following termination or deletion that is reasonably necessary for backups, security, legal obligations or the orderly deletion of data.
Nature and purpose
Processing may include:
- collecting;
- receiving;
- storing;
- organising;
- retrieving;
- displaying;
- transmitting;
- updating;
- securing;
- backing up;
- deleting; and
- otherwise processing Personal Data as necessary to provide the Service.
The purpose of the processing is to enable the Customer to manage its customer relationships, enquiries, communications, quotes, payments and bookings using Flam.
Categories of Data Subjects
Customer Data may relate to:
- prospective customers of the Customer;
- customers of the Customer;
- people making enquiries;
- people included within booking or event information;
- Customer employees;
- Customer contractors; and
- Customer team members.
Types of Personal Data
Depending on how the Customer configures and uses Flam, Customer Data may include:
- names;
- email addresses;
- telephone numbers;
- postal addresses;
- enquiry information;
- event information;
- appointment or booking information;
- dates and locations;
- messages and communications;
- uploaded files;
- quote information;
- payment and transaction information;
- booking history;
- IP addresses and technical information; and
- other information submitted by Data Subjects or entered by the Customer into the Service.
The Customer controls the information it requests from its customers through configurable enquiry forms and other features.
4. Customer responsibilities
The Customer is responsible for ensuring that:
- it has a lawful basis for processing Customer Data;
- Data Subjects receive appropriate privacy information;
- information requested through enquiry forms is appropriate and necessary;
- Personal Data entered into Flam has been collected lawfully;
- instructions given to Flam comply with Applicable Data Protection Law; and
- its use of the Service complies with Applicable Data Protection Law.
The Customer must not instruct Flam to process Personal Data unlawfully.
Unless expressly agreed otherwise, the Customer should not use Flam to intentionally collect or store special category Personal Data where doing so is not reasonably necessary for its business.
5. Flam's obligations
Flam will:
- process Customer Data only on documented instructions from the Customer;
- comply with applicable obligations imposed directly upon processors by Applicable Data Protection Law;
- ensure that people authorised to process Customer Data are subject to appropriate confidentiality obligations;
- implement appropriate technical and organisational security measures;
- reasonably assist the Customer with Data Subject requests;
- reasonably assist the Customer with its applicable data protection obligations;
- notify the Customer of qualifying Personal Data Breaches as described below;
- maintain appropriate records where required by law; and
- make information reasonably necessary to demonstrate compliance with this DPA available to the Customer.
6. Confidentiality
Flam will ensure that employees, contractors and other people authorised to process Customer Data are subject to appropriate confidentiality obligations.
Access to Customer Data will be limited to people who reasonably require access for purposes including operating, maintaining, securing or supporting the Service.
7. Security
Flam will implement appropriate technical and organisational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Depending on the nature of the processing, these measures may include:
- encryption of data in transit;
- secure password hashing;
- authentication and access controls;
- tenant isolation;
- private storage for customer files;
- database security;
- backups;
- logging and monitoring;
- software patching and dependency updates;
- access restrictions;
- secure hosting infrastructure; and
- appropriate procedures for responding to security incidents.
Security measures may evolve as Flam and the technologies used to provide the Service develop.
No method of electronic storage or transmission can guarantee absolute security.
8. Personal Data Breaches
If Flam becomes aware of a Personal Data Breach affecting Customer Data, Flam will notify the affected Customer without undue delay where required by Applicable Data Protection Law.
Where reasonably available, the notification will provide information concerning:
- the nature of the breach;
- the categories of information affected;
- the categories of Data Subjects affected;
- the likely consequences of the breach; and
- measures taken or proposed to address or mitigate the breach.
Where all information is not immediately available, Flam may provide information in stages.
Flam will take reasonable steps to investigate, contain and mitigate Personal Data Breaches affecting Customer Data.
The Customer remains responsible for determining whether it is required to notify the Information Commissioner's Office, affected Data Subjects or another authority.
9. Data Subject requests
Taking into account the nature of the processing, Flam will provide reasonable assistance to enable the Customer to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.
These may include requests for:
- access;
- rectification;
- erasure;
- restriction;
- portability; or
- objection to processing.
Where Flam receives a request directly from a Data Subject relating to Customer Data, Flam may direct that person to the relevant Customer unless Flam is legally required to respond directly.
The Customer remains responsible for responding to Data Subject requests.
10. Sub-processors
The Customer provides Flam with general authorisation to engage Sub-processors where reasonably necessary to provide the Service.
Sub-processors may provide services including:
- cloud hosting;
- database infrastructure;
- file storage;
- email delivery;
- payment processing;
- security;
- monitoring and error reporting; and
- other infrastructure necessary to operate Flam.
Flam will ensure that Sub-processors processing Customer Data are subject to written contractual obligations providing an appropriate level of data protection consistent with the requirements applicable to Flam under this DPA.
Flam remains responsible for its Sub-processors to the extent required by Applicable Data Protection Law.
Where required, Flam will make information about its material Sub-processors available to Customers.
Where Flam intends to add or replace a Sub-processor that materially affects the processing of Customer Data, Flam will provide reasonable notice where required, allowing the Customer an opportunity to raise reasonable data protection objections.
11. International transfers
Flam will not transfer Customer Data outside the United Kingdom unless the transfer complies with Applicable Data Protection Law.
Where a Sub-processor processes Customer Data outside the United Kingdom, Flam will ensure that an appropriate transfer mechanism is used where required.
This may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved Standard Contractual Clauses; or
- another lawful transfer mechanism.
12. Assistance with compliance
Taking into account the nature of the processing and information available to Flam, Flam will provide reasonable assistance to the Customer in meeting applicable obligations concerning:
- security of processing;
- Personal Data Breach assessment and notification;
- Data Protection Impact Assessments; and
- consultation with supervisory authorities where required.
13. Data Protection Impact Assessments
Where the Customer reasonably determines that its use of Flam requires a Data Protection Impact Assessment, Flam will provide information reasonably available to it that is necessary to assist the Customer in completing that assessment.
The Customer remains responsible for determining whether a DPIA is required and for conducting it.
14. Deletion and return of Customer Data
During the term of the Service, the Customer may access and manage Customer Data through the functionality made available by Flam.
Following termination of the Customer's account, Flam will delete or return Customer Data in accordance with the Customer's instructions where reasonably practicable and as required by Applicable Data Protection Law.
Customer Data may remain temporarily within backups or archives after deletion from active systems.
Where immediate deletion from backups is not technically practical, the data will remain protected and will be deleted through Flam's normal backup retention cycle.
Flam may retain information where required by applicable law or where Flam acts as an independent Controller for that information, such as certain financial, security or legal records.
15. Audits and compliance information
Flam will make available information reasonably necessary to demonstrate compliance with its obligations under Article 28 of the UK GDPR and this DPA.
Where that information is insufficient to reasonably demonstrate compliance, the Customer may request an audit relating specifically to Flam's processing of Customer Data.
Audits must:
- be requested on reasonable notice;
- occur no more than once in any 12-month period unless a Personal Data Breach, regulatory requirement or reasonable evidence of material non-compliance justifies an additional audit;
- take place during normal business hours;
- avoid unreasonable disruption to Flam or other customers;
- comply with reasonable security and confidentiality requirements; and
- be limited to information relevant to the Customer's Personal Data and Flam's obligations under this DPA.
Where appropriate, Flam may satisfy an audit request by providing relevant independent certifications, security documentation, questionnaires or audit reports instead of permitting direct access to systems containing other customers' information.
The Customer is responsible for its reasonable audit costs unless the audit identifies a material breach of this DPA by Flam.
16. Customer instructions
The Customer instructs Flam to process Customer Data as reasonably necessary to:
- provide the Service;
- operate features selected or configured by the Customer;
- communicate with Data Subjects on the Customer's behalf;
- facilitate payments and bookings;
- maintain and secure the Service;
- prevent fraud and abuse;
- provide technical support;
- maintain backups; and
- comply with other documented instructions provided through the Customer's use of the Service.
If Flam believes that an instruction infringes Applicable Data Protection Law, Flam will inform the Customer where required and may suspend the relevant processing until the matter is resolved.
17. Liability
The liability of each party arising from or relating to this DPA is subject to the limitations and exclusions of liability contained in the Flam Terms of Use, except to the extent that such liability cannot lawfully be limited or excluded.
Nothing in this DPA limits any responsibility or liability imposed directly upon either party by Applicable Data Protection Law where that responsibility or liability cannot legally be excluded.
18. Relationship with the Terms of Use
This DPA forms part of the Flam Terms of Use.
If there is a conflict between this DPA and the Terms of Use concerning the processing of Customer Data, this DPA will take precedence to the extent of that conflict.
The Privacy Policy explains how Flam processes Personal Data where Flam acts as a Controller in its own right.
19. Changes to this DPA
Flam may update this DPA where reasonably necessary to:
- reflect changes to the Service;
- comply with changes in Applicable Data Protection Law;
- reflect changes to Sub-processors or infrastructure; or
- improve data protection arrangements.
Where a change materially affects the Customer's rights or Flam's data protection obligations, Flam will provide reasonable notice where appropriate.
20. Governing law
This DPA is governed by the laws of England and Wales.
The courts of England and Wales will have jurisdiction over disputes relating to this DPA, subject to any rights or jurisdiction that cannot lawfully be excluded.
21. Contact
Questions relating to this DPA or Flam's processing of Personal Data can be sent to:
Flam Labs LtdPrimrose Cottage, Eversley Centre, Hook, Hampshire, RG27 0NF, United Kingdom
privacy@flamlabs.com
Schedule 1 — Processing details
Controller: The business or organisation holding the Flam account.
Processor: Flam Labs Ltd / Flam.
Subject matter: Provision of the Flam enquiry, communication, quoting, payment and booking management Service.
Duration: For the duration of the Customer's use of Flam, plus applicable deletion, backup and legal retention periods.
Purpose: To process Customer Data on behalf of the Customer in order to provide Flam.
Data Subjects: Customers, prospective customers, enquiry submitters, booking participants where applicable, and members of the Customer's organisation.
Personal Data: Contact information, enquiry responses, communications, booking or event information, quotes, payment records, uploaded files, technical information and other information submitted to the Service by or on behalf of the Customer.
Special category data: Not intentionally required by Flam as part of its standard Service. Customers should not request or store special category data unless they have determined that doing so is necessary and lawful.
Frequency: Continuous or as initiated by the Customer and its customers through use of the Service.