Data Processing Agreement
Standard Data Processing Agreement (DPA) between Flowen Technologies Ltd (Processor) and NHS trusts, ICBs, private clinics, and institutional customers (Controller). Effective 1 August 2026.
This Data Processing Agreement ("Agreement") supplements the commercial agreement between Flowen Technologies Ltd and the Controller organisation. Where any inconsistency exists between this Agreement and the commercial agreement in respect of data protection obligations, this Agreement shall prevail.
For NHS organisations, this Agreement is designed to be consistent with NHS standard data sharing terms and the NHS Data Security and Protection Toolkit requirements. For bespoke terms or to request a signed DPA, contact hello@flowen.digital.
CLAUSE 1Definitions
Definitions
In this Agreement: "Controller" means the organisation (NHS trust, ICB, private clinic, educational institution, or other body) contracting with Flowen Technologies Ltd for access to the Flowen Platform. "Processor" means Flowen Technologies Ltd, a company registered in England and Wales, operating the Flowen speech fluency platform at flowen.digital. "Data Subject" means the individual (typically a patient or platform user) whose personal data is processed. "Personal Data", "Special Category Data", "Processing", "Data Breach", "Supervisory Authority", and other terms have the meanings given in the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018). "Sub-processor" means any third party engaged by Flowen Technologies Ltd to process Personal Data on behalf of the Controller. "Services" means the Flowen speech fluency platform and associated clinical management tools provided under the commercial agreement between the parties.
CLAUSE 2Subject Matter, Duration, Nature & Purpose
Subject Matter, Duration, Nature & Purpose
2.1 SUBJECT MATTER This Agreement governs the processing of Personal Data by the Processor on behalf of the Controller in connection with the provision of the Services. 2.2 DURATION This Agreement is effective from the date the Controller first accesses the Services and remains in force for the duration of the commercial agreement between the parties, including any run-off period required to complete residual processing obligations. 2.3 NATURE OF PROCESSING The Processor will process Personal Data to: (a) deliver platform access and speech practice sessions; (b) facilitate clinical oversight between assigned SLPs and patients; (c) generate therapy progress reports; (d) maintain session records and audit trails; (e) provide technical support. 2.4 PURPOSE OF PROCESSING Processing is carried out for the purpose of delivering speech fluency support and clinical workflow management as described in the commercial agreement. 2.5 TYPES OF PERSONAL DATA — Identity data: name, email address, role — Special category health data: speech fluency metrics, acoustic biomarkers, therapy progression data — Clinical data: treatment plans, session notes, clinician observations 2.6 CATEGORIES OF DATA SUBJECTS Patient users (persons who stammer) and clinician users (SLPs and other healthcare professionals) within the Controller's organisation or patient population.
CLAUSE 3Controller Obligations
Controller Obligations
3.1 The Controller warrants that it has a valid lawful basis under UK GDPR Article 6 and, where applicable, Article 9(2) for each purpose for which it instructs the Processor to process Personal Data. 3.2 The Controller is responsible for obtaining all necessary consents from Data Subjects and providing appropriate transparency information (privacy notices) to Data Subjects about the use of the Flowen Platform before data is entered into the system. 3.3 The Controller shall provide complete and accurate instructions to the Processor and shall not instruct the Processor to process Personal Data in a manner that would cause the Processor to violate applicable data protection law. 3.4 The Controller is responsible for assessing and documenting the legal basis for processing under their own data protection obligations, including maintaining their own Article 30 Records of Processing Activities.
CLAUSE 4Processor Obligations
Processor Obligations
4.1 INSTRUCTIONS The Processor shall process Personal Data only on the documented instructions of the Controller and for no other purpose, except where required to do so by UK law. If required to process for another purpose by law, the Processor will notify the Controller before processing (unless prohibited by law). 4.2 CONFIDENTIALITY The Processor shall ensure that all personnel authorised to process Personal Data are under appropriate confidentiality obligations, whether contractual or statutory. 4.3 SECURITY The Processor shall implement and maintain appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure. Current measures include: AES-256-GCM encryption at rest; TLS 1.3 in transit; PostgreSQL row-level security; JWT authentication; no raw audio storage; PHI-masked error monitoring; UK data residency. 4.4 SUB-PROCESSORS The Processor is authorised to engage sub-processors to assist in delivering the Services, subject to the provisions of Clause 5 below. 4.5 DATA SUBJECT RIGHTS The Processor shall promptly notify the Controller (within 3 business days) upon receiving a Data Subject request relating to data processed on behalf of the Controller, and shall provide reasonable assistance to enable the Controller to fulfil its obligations to respond. 4.6 DATA PROTECTION IMPACT ASSESSMENTS The Processor shall provide reasonable assistance to the Controller in conducting Data Protection Impact Assessments (DPIAs) where required under UK GDPR Article 35, including providing information about processing activities and security measures. 4.7 DELETION OR RETURN Upon termination of the commercial agreement, the Processor shall, at the Controller's election, either securely delete or return all Personal Data (and copies thereof), unless retention is required by UK law. The Processor will confirm completion within 30 days of termination. 4.8 AUDIT & INFORMATION The Processor shall provide the Controller with all information necessary to demonstrate compliance with this Agreement. The Processor shall allow for and contribute to audits conducted by the Controller or its authorised auditor, on reasonable notice (not less than 14 days), during normal business hours, subject to appropriate confidentiality undertakings. The Processor may charge a reasonable fee for audit assistance beyond routine documentation provision.
CLAUSE 5Sub-processors
Sub-processors
5.1 CURRENT SUB-PROCESSORS The Controller consents to the engagement of the following sub-processors: — Supabase Inc.: database infrastructure and authentication (UK-GBR data centres) — Vercel Inc.: cloud hosting and edge functions (UK/EU regions) — Agora Inc.: real-time voice processing for AI speech coach sessions (live audio streamed in-session only; no persistent audio storage by Agora) — Functional Software Inc. (Sentry): anonymised error monitoring (PHI masking enabled) — Stripe Inc.: payment processing (operates as independent data controller for payment data) A current, complete list of sub-processors is maintained at flowen.digital/dpa and updated upon any change. 5.2 NEW SUB-PROCESSORS The Processor shall give the Controller at least 30 days' written notice before adding or replacing a sub-processor. The Controller may object to a new sub-processor within this period on reasonable data protection grounds. If the parties cannot resolve the objection, either party may terminate the commercial agreement on written notice without penalty. 5.3 FLOW-DOWN OBLIGATIONS The Processor shall impose equivalent data protection obligations on each sub-processor by way of a written contract, including all obligations set out in this Agreement. The Processor remains fully liable to the Controller for any failure by a sub-processor to fulfil its data protection obligations.
CLAUSE 6International Transfers
International Transfers
6.1 Personal Data shall be stored in UK data centres. 6.2 Where processing by a sub-processor involves transfer to a country outside the UK, the Processor shall ensure an appropriate safeguard is in place as required by UK GDPR Chapter V, including: UK adequacy regulations, Standard Contractual Clauses (SCCs) with UK Addendum, or the UK International Data Transfer Agreement (IDTA). 6.3 The Processor will notify the Controller of any planned international transfers prior to their implementation and provide evidence of the applicable safeguard on request.
CLAUSE 7Personal Data Breaches
Personal Data Breaches
7.1 The Processor shall notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a Personal Data Breach involving data processed on behalf of the Controller. 7.2 The notification shall include, to the extent then known: (a) a description of the nature of the breach; (b) the categories and approximate number of Data Subjects affected; (c) the categories and approximate number of Personal Data records affected; (d) the likely consequences of the breach; (e) the measures taken or proposed to address the breach and mitigate its effects. 7.3 The Processor shall cooperate with and provide reasonable assistance to the Controller in any notification to the ICO or Data Subjects required under UK GDPR Articles 33 and 34.
CLAUSE 8Clinical Safety
Clinical Safety
8.1 The Processor operates under the NHS DCB0129 Clinical Safety Standard. The Processor's Clinical Safety Case Report and Hazard Log are available to the Controller upon request. 8.2 The Controller's clinical staff must receive appropriate training before using the Platform in a clinical context. The Processor will provide training materials and, where agreed, remote training sessions. 8.3 The Controller is responsible for DCB0160 (Deployment Clinical Safety) compliance within its own organisation, including appointing a Deployment Clinical Safety Officer. 8.4 Clinical safety incidents or near-misses must be reported to the Processor at hello@flowen.digital with the subject [CLINICAL SAFETY INCIDENT].
CLAUSE 9Liability
Liability
9.1 Each party's liability to the other under or in connection with this Agreement is subject to the limitations and exclusions in the commercial agreement between the parties. 9.2 The Processor's liability under this Agreement shall not exceed the greater of: (a) the total fees paid by the Controller to the Processor in the 12 months preceding the claim; or (b) £50,000. 9.3 Neither party shall be liable for indirect, consequential, or punitive damages. 9.4 Nothing in this Agreement excludes liability for death or personal injury caused by negligence, fraud, or any other liability that cannot be excluded under English law.
CLAUSE 10Governing Law
Governing Law
This Agreement is governed by the laws of England and Wales. Any disputes arising out of or in connection with this Agreement shall be subject to the exclusive jurisdiction of the courts of England and Wales.
Current Sub-processor Register
| Sub-processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Supabase Inc. | Database, auth, storage | UK-GBR | SCCs + UK Addendum |
| Vercel Inc. | Hosting, edge functions | UK/EU | SCCs + UK Addendum |
| Agora Inc. | Real-time voice (AI speech coach sessions — live audio only, not stored) | US/EU | SCCs + UK Addendum |
| Functional Software Inc. (Sentry) | Error monitoring (PHI masked) | EU/US | SCCs + UK Addendum |
| Stripe Inc. | Payment processing | US/EU | Independent controller; UK–US Data Bridge |
Last updated: 1 August 2026. Changes to sub-processors are notified with 30 days' notice.
Request a Signed DPA
NHS trusts, ICBs, and institutional customers can request a fully executed, signed DPA — including organisation-specific schedules and any required NHS standard terms — by contacting our team.
Request DPA →