Skip to content

Data Processing Agreement

Effective 14 July 2026

Effective date: 14 July 2026

This Data Processing Agreement ("DPA") forms part of and is incorporated into the Fluck for Business Terms of Service (the "Agreement") between:

  • Fluck AI LTD, Company No. 15723506, of Innovation Centre, Knowledge Gateway, Boundary Road, Colchester, Essex, CO4 3ZQ, United Kingdom ("Fluck", "Processor"); and
  • the business customer that accepts the Agreement (the "Business", "Controller").

Together the "parties".


1. Definitions

1.1 Terms not defined here have the meaning given in the Agreement.

1.2 In this DPA:

  • "UK GDPR" means the UK General Data Protection Regulation as it forms part of UK law by virtue of the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018.
  • "Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 ("PECR"), and, where applicable to the Business's activities, the EU General Data Protection Regulation (Regulation (EU) 2016/679, "EU GDPR").
  • "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach" and "Supervisory Authority" have the meanings in the UK GDPR.
  • "Customer Personal Data" means Personal Data contained in Customer Data that Fluck Processes on behalf of the Business under the Agreement.
  • "Sub-processor" means any third party engaged by Fluck to Process Customer Personal Data.
  • "UK IDTA" means the Information Commissioner's International Data Transfer Agreement; "UK Addendum" means the ICO's International Data Transfer Addendum to the EU SCCs; "EU SCCs" means the European Commission Standard Contractual Clauses (Decision 2021/914).

2. Roles and scope

2.1 As between the parties, the Business is the Controller and Fluck is the Processor of Customer Personal Data. Where the Business is itself a processor for another controller, the Business appoints Fluck as its sub-processor and warrants it has authority to do so.

2.2 Fluck acts as an independent Controller for a limited set of data it processes for its own purposes: account administration, billing, security, fraud prevention, and legal compliance. That processing is governed by Fluck's own privacy notice, not this DPA.

2.3 This DPA applies to all Processing of Customer Personal Data by Fluck under the Agreement.

3. Processing instructions

3.1 Fluck will Process Customer Personal Data only on the Business's documented instructions, including as set out in the Agreement, this DPA (with Schedule 1), and any configuration the Business makes in the Service, unless required to do otherwise by law. If required by law to Process otherwise, Fluck will inform the Business first unless the law prohibits it.

3.2 Fluck will inform the Business if, in its opinion, an instruction infringes Data Protection Law. Fluck is not obliged to give legal advice and this does not diminish the Business's responsibility for its instructions.

3.3 The Business warrants that its instructions and the Processing described in Schedule 1 comply with Data Protection Law, and that it has a valid lawful basis (and, where required, consent) for the Processing.

4. Confidentiality

4.1 Fluck will ensure that persons authorised to Process Customer Personal Data are bound by confidentiality obligations and have received appropriate data-protection training, and that access is limited to those who need it to provide the Service.

5. Security (Article 32)

5.1 Fluck will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking account of the state of the art, cost of implementation, and the nature, scope, context and purposes of Processing. The measures are set out in Schedule 2 and include, at minimum:

  • encryption of Customer Personal Data in transit (TLS 1.2+) and at rest;
  • access controls with role-based permissions, least-privilege, and multi-factor authentication for administrative access;
  • network security including firewalls, segmentation and isolation of production environments;
  • pseudonymisation and minimisation where practicable;
  • logging, monitoring and alerting of access and security events;
  • regular backups with tested restoration;
  • vulnerability management, patching and periodic penetration testing;
  • secure software-development practices and code review; and
  • business continuity and disaster-recovery arrangements.

5.2 Fluck may update the measures provided the level of security is not materially reduced.

6. Sub-processors

6.1 The Business gives general authorisation for Fluck to engage Sub-processors to Process Customer Personal Data. Current Sub-processors are listed in Schedule 1, Part D. The categories are: cloud hosting and infrastructure; messaging and integration platforms (Meta — WhatsApp/Instagram/Messenger); Google (Business Profile); Trustpilot; email and SMS delivery providers; and AI model/inference providers.

6.2 Fluck will impose on each Sub-processor, by written contract, data-protection obligations no less protective than those in this DPA.

6.3 Fluck will give the Business at least 14 days' prior notice (by email or in-product notice, or by updating a public Sub-processor list) of any intended addition or replacement of a Sub-processor. The Business may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, the Business may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the terminated part.

6.4 Fluck remains liable to the Business for the acts and omissions of its Sub-processors in respect of Customer Personal Data as if they were its own.

7. Assistance to the Business

7.1 Data-subject requests. Taking account of the nature of the Processing, Fluck will assist the Business by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights under Data Protection Law (access, rectification, erasure, restriction, portability, objection). Where Fluck receives such a request directly, it will not respond except to acknowledge and direct the request to the Business, and will notify the Business without undue delay.

7.2 DPIAs and consultation. Fluck will provide reasonable assistance to the Business with data-protection impact assessments and prior consultations with the ICO, taking into account the information available to Fluck.

7.3 Fluck may charge a reasonable fee for assistance that is excessive or unrelated to a security incident or its own default, having first notified the Business.

8. Personal Data Breach

8.1 Fluck will notify the Business without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

8.2 The notification will include, to the extent known and as it becomes available: the nature of the breach, categories and approximate number of Data Subjects and records affected, likely consequences, and the measures taken or proposed to address it and mitigate its effects.

8.3 Fluck will take reasonable steps to mitigate and remediate the breach and will cooperate with the Business. The Business is responsible for any notifications to the ICO or Data Subjects, unless the law requires Fluck to notify in its own capacity.

9. Deletion and return

9.1 On termination or expiry of the Agreement, and at the Business's choice, Fluck will delete or return all Customer Personal Data, and delete existing copies, unless retention is required by law.

9.2 Fluck provides self-service export tools and will retain Customer Personal Data for 30 days after termination to allow export/return, after which it will delete or anonymise it in accordance with clause 9.1 and its retention schedule. Backup copies are deleted on the ordinary backup-rotation cycle.

10. Audits

10.1 Fluck will make available to the Business information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR, including relevant certifications, third-party audit reports and security summaries.

10.2 Where that information is insufficient, the Business (or a mandated independent auditor bound by confidentiality) may audit Fluck's relevant Processing, on at least 30 days' written notice, no more than once in any 12-month period (unless required by a Supervisory Authority or following a Personal Data Breach), during business hours, without unreasonably disrupting Fluck's operations. Each party bears its own audit costs.

11. International transfers

11.1 Fluck will not transfer Customer Personal Data outside the UK (or, where the EU GDPR applies, the EEA) unless an appropriate safeguard is in place under Data Protection Law.

11.2 Where a transfer requires safeguards, the parties agree that the UK IDTA (or the EU SCCs as supplemented by the UK Addendum) applies and is incorporated by reference, with Fluck as data exporter/importer as applicable, together with any required transfer risk assessment. The relevant modules and options are those appropriate to a controller-to-processor (or processor-to-sub-processor) transfer.

11.3 Sub-processors receiving Customer Personal Data outside the UK/EEA are bound by equivalent transfer safeguards.

12. Liability

12.1 Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Agreement.

13. Duration and precedence

13.1 This DPA takes effect on the Effective date and continues while Fluck Processes Customer Personal Data. In the event of conflict between this DPA and the rest of the Agreement on the subject of data protection, this DPA prevails.


Schedule 1 — Processing details

Part A — Subject matter, nature and purpose Provision of the Fluck Business Portal SaaS, including review/reputation management, digital loyalty, omnichannel inbox (WhatsApp Business, Instagram, Facebook/Messenger, email, web chat), knowledge base and AI assistant, ticketing/SLAs, customer profiles/CRM, surplus offers, and discovery/listing to the Fluck consumer app. The nature of Processing includes collection, storage, organisation, retrieval, transmission, analysis, and deletion of Customer Personal Data to deliver these features.

Part B — Duration For the term of the Agreement plus the post-termination retention period in clause 9.2.

Part C — Categories of Data Subjects and Personal Data

Data Subjects: the Business's customers, prospective customers, contacts, loyalty-programme members, reviewers, message senders, and the Business's own staff/team members who use the Service.

Categories of Personal Data: identification and contact details (name, email, phone, social-platform handles/IDs); message and conversation content across connected channels; loyalty records (stamps, tiers, vouchers, transaction history); review and reputation interactions; support tickets and notes; CRM profile data and tags; device/technical data (IP address, identifiers, log data); and any other Personal Data the Business chooses to submit.

Special category data: not intended. The Business must not submit special category data (Article 9) or criminal-offence data (Article 10) except where strictly necessary, lawful, and configured appropriately; the Business is responsible for any such data it submits.

Part D — Sub-processors (current list)

Sub-processor categoryPurposeLocation
Cloud hosting / infrastructure (incl. DigitalOcean)Hosting, storage, computeUK / EEA (with safeguards where outside)
Meta Platforms (WhatsApp Business, Instagram, Messenger)Omnichannel messaging integrationEEA / US (with safeguards)
Google (Business Profile)Review/listing integrationEEA / US (with safeguards)
TrustpilotReview integrationEEA
Email / SMS delivery providersTransactional and notification deliveryUK / EEA / US (with safeguards)
AI model / inference providersPowering the AI assistantUK / EEA / US (with safeguards)

The current, maintained Sub-processor list is available on request at hello@fluckai.com (or via the contact form at https://www.fluckai.com/contact) and via in-product notice.


Schedule 2 — Technical and organisational security measures

Access control and identity

  • Role-based access control with least-privilege; unique accounts (no shared credentials).
  • Multi-factor authentication required for administrative and production access.
  • Prompt revocation of access on role change or departure; periodic access reviews.

Encryption and data protection

  • Encryption in transit using TLS 1.2 or higher for all external connections.
  • Encryption at rest for databases and object storage (AES-256 or equivalent).
  • Secrets and keys managed in a dedicated secrets store; no secrets in source code.

Network and infrastructure security

  • Production isolated from development/test; segmented networks and firewalls.
  • Managed database instances not exposed beyond required networks; hardened hosts.
  • DDoS protection and rate limiting at the gateway.

Application security

  • Secure SDLC with peer code review and pre-commit checks.
  • Authentication via a central OAuth2 authorisation server issuing RSA-signed JWTs; auth enforced on protected endpoints.
  • Input validation and protection against common vulnerabilities (injection, XSS, CSRF).
  • Dependency and vulnerability scanning; timely patching.

Monitoring, logging and response

  • Centralised logging of access and security-relevant events; alerting on anomalies.
  • Documented incident-response process with defined roles and escalation.
  • Personal Data Breach notification without undue delay (clause 8).

Resilience and continuity

  • Automated, encrypted backups with periodic restoration testing.
  • Business-continuity and disaster-recovery procedures.

Organisational measures

  • Confidentiality obligations and data-protection training for personnel.
  • Vendor/sub-processor due diligence and contractual data-protection terms.
  • Data-minimisation and retention controls; secure deletion on termination.