Data processing terms
Last updated ·
How Confluxive handles data belonging to clients when building and operating automations. These terms sit alongside the service agreement.
Roles
For data inside the client’s own systems, the client is the controller and Confluxive acts as a processor, processing only on documented instructions. For our own business records — such as contact details of client staff — Confluxive acts as controller under the privacy policy.
Scope of processing
Subject matter: delivery, operation and maintenance of automated workflows. Duration: the term of the engagement plus any agreed support period. Nature: reading, transforming, transferring and writing records between the client’s systems. Categories of data: customer contact details, order and invoice records, and employee identifiers where a workflow requires them.
Access controls
Access is granted through the client’s own accounts and approved connection methods, using the minimum permissions the workflow requires. Credentials are stored in Cloudflare Workers secrets, encrypted at rest by Cloudflare and injected into the running Worker rather than held in source code or in a deployment artefact, and access is removed promptly when it is no longer required.
Security measures
Encryption in transit on every connection, with HTTP Strict Transport Security enforced across the site and its API; encryption at rest for stored data, held on Cloudflare-managed storage rather than on a disk we operate; request and error logging on the production application; uptime monitoring that runs outside the hosting provider, so an outage is not reported by the thing that is down; and change control on production: changes reach the live site through one automated pipeline, and only after type checking, unit tests, the port contract suites and the release gate have all passed.
Data location
Automations are hosted in Cloudflare's global edge network. The site and its data run on infrastructure distributed across Cloudflare's worldwide points of presence rather than a single named server or region — this is a deliberate feature of the hosting, not a placeholder.. Where processing occurs outside the client’s jurisdiction, appropriate transfer safeguards such as the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), together with the UK International Data Transfer Addendum where a transfer originates in the United Kingdom are put in place.
Subprocessors
We use Cloudflare, Inc. (global edge network) to deliver services. Each is bound by written terms no less protective than these. Clients are notified before a new subprocessor with access to their data is introduced and may object on reasonable grounds.
Intelligent processing
Where document reading, classification or drafting is used, the client is told which provider processes the data, whether content is retained by that provider, and whether it may be used for model training. Our default is providers and settings that exclude client data from training.
Breach notification
If we become aware of a personal data breach affecting client data, we notify the client without undue delay and within 72 hours, with the information available at that time, and assist with the client’s own notification obligations.
Return and deletion
On termination, we return or delete client data in our possession within 30 days, except where retention is required by law, and confirm deletion in writing on request. Documentation of the automation is handed over as part of the closing process.
Audit and assistance
We make available the information reasonably needed to demonstrate compliance with these terms, and assist the client with data subject requests, impact assessments and regulator queries relating to the processing we carry out.