The Article 28 agreement.

Last updated: 11 September 2026

When someone fills in your form, you are the controller of what they sent and Flora is your processor. Article 28 of the UK and EU GDPR says that arrangement needs a written agreement. This is it.

It applies to every account on every plan, including free ones, from the moment you create one. You do not need to ask for it and there is nothing to sign for it to bind us. It forms part of the terms.

Need it signed? On the Business plan we will sign this, countersign your copy and return it, along with a written record of where data sits that your auditors can read. On Custom we will negotiate the terms themselves. Write to [email protected]. The protections below are the same either way, a signature changes the paperwork rather than the promise.

01 Who this is between

You, the account holder, as controller. Us, Serendipiware Ltd, a company registered in England & Wales, company number 17232380, registered office Unit A, 82 James Carter Road, Mildenhall, Suffolk, IP28 7DE, United Kingdom, as processor.

This covers submission data only. For your own account data, your email address and your settings, we are the controller and the privacy notice governs instead. The two never mix.

Terms defined in the GDPR carry their GDPR meaning here. GDPR means Regulation (EU) 2016/679 and the UK GDPR as it has effect in domestic law, whichever applies to you, and both where both do.

02 What is being processed

Subject matterReceiving, storing and displaying the submissions sent to your forms.
DurationFor as long as your account exists. Each submission, until you delete it.
Nature and purposeCollection, storage, retrieval and deletion, so you can read what people sent you. No analysis of any kind.
Types of personal dataWhatever your forms ask for. Typically a name, an email address and a message. You choose the fields, so you decide this.
Categories of data subjectThe people who fill in your forms. Usually your customers, enquirers, applicants or patients.
Special category dataOnly if your forms collect it. Flora does not require it and does not treat it differently, so the safeguards are yours to put in place.

03 We act only on your instructions

We process submission data only on your documented instructions, including where we transfer it. Your instructions are: the service itself, as the docs describe it, plus the settings you choose on each form, plus anything you ask us in writing.

We will not use submission data for anything of our own. Not product analytics, not benchmarking, not spam filtering across accounts, not training a model, ours or anyone else’s. There is no version of Flora where that becomes a feature.

If the law requires us to process it some other way, we will tell you before we do unless that law forbids us from telling you. If we think an instruction of yours breaks data protection law, we will say so rather than quietly carry it out.

04 Confidentiality

Everyone we let near submission data is bound to keep it confidential, by their contract, and that duty outlasts their involvement. We keep the number of such people as small as running the service allows.

In practice we read a submission only when you ask us to look at one, for support. Not for any other reason, and not out of curiosity.

05 Security

We keep appropriate technical and organisational measures under Article 32. These are the ones we have, written so you can check them rather than take them:

  • Encryption in transit with TLS 1.3, and encryption at rest on disk.
  • Row level security in Postgres, so separation between accounts is enforced by the database rather than by application code. One account cannot read another’s rows even if the application had a bug.
  • The service key that can write submissions lives only on the ingest server and is never sent to a browser. The browser holds a publishable key whose reach is defined by those same policies.
  • No passwords anywhere, so there is no password database to leak. Sign in is a one time code sent to the account address.
  • Submitter IP addresses, user agents and device fingerprints are not recorded, so they cannot be disclosed, subpoenaed or lost.
  • Notification emails carry no submission contents, so a compromised mailbox does not expose what people sent you.
  • Least privilege between the parts: the site, the endpoint and the database each hold only the credentials they need, and the dashboard holds none that can write a submission.
  • Access to production by us is limited to the people who run the service, over authenticated sessions, and only where support requires it.
  • We keep no backups of submission data and never restore from our provider’s. A deletion is not reversible by us, by design. The provider’s own encrypted copies stay in the same region and age out within 7 days.

We may change these as the service changes, but not in a way that weakens the protection overall.

06 Subprocessors

You give us general authorisation to use the subprocessors below. Each one is under a written contract with data protection obligations no weaker than these, and we remain answerable to you for what they do.

WhoWhat they doWhereWhat they touch
SupabaseDatabase and authenticationParis, France (eu-west-3)Submission contents, account data
RailwayThe endpoint your forms post toAmsterdam, NetherlandsSubmission contents, in transit
CloudflareThis site, the dashboard and DNSServed from the location nearest the visitorNo submission contents. Requests and pages only.
Brevo (Sendinblue)Notification and login emailsFranceYour email address. No submission contents.
StripePaymentsIreland and the EUBilling data. No submission contents.

Only the first two ever hold submission contents. Cloudflare serves the site and the dashboard and runs our DNS; posts go straight to Railway and the dashboard reads Supabase from your browser, so what Cloudflare handles is the request itself and never what is in a form.

Before we add or replace one, we will update this page and email you at least 30 days before the change takes effect. If you object on reasonable data protection grounds, tell us within those 30 days and we will either find another way or let you cancel and refund the unused part of what you paid.

07 Where it goes, and where it does not

Submission contents are stored in Paris and pass through Amsterdam. They do not leave the EEA in the ordinary running of the service, and no US provider stores them.

We are a UK company, so supporting you means we can reach that data from the United Kingdom. The UK holds an adequacy decision from the European Commission, which is the legal basis for that. If it ever lapses, we will have standard contractual clauses in place before it does rather than after.

Where any transfer outside the EEA or the UK would otherwise need one, the relevant standard contractual clauses apply and are incorporated here, with this agreement supplying the details their annexes ask for.

08 Helping you answer your data subjects

When someone asks you for access, correction, erasure, restriction, portability or objects to processing, answering them is your job and we help you do it:

  • Access, correction and deletion you can do yourself, from the dashboard, immediately and without asking us. A submission, a form, or the whole account.
  • Export gives you a portable copy. If your plan has no export button, ask and we will produce one.
  • For anything the dashboard cannot do, write to us and we will help you answer your data subject within your own one month deadline.
  • If a data subject comes to us directly about a submission, we will not answer for you. We will tell them to contact you, and tell you that they came.

We do not charge for this. A processor that bills its controller for the right to comply is a processor making compliance expensive.

09 If something goes wrong

If we become aware of a personal data breach affecting your submission data, we will tell you without undue delay and in any event within 48 hours of becoming aware. That is deliberately tighter than the 72 hours you then have with your own supervisory authority, because your clock should not be running while you are waiting on us.

We will tell you what we know at the time rather than waiting for a complete picture: what happened, which data and roughly how many people it touches, what it is likely to mean, and what we are doing about it. We will keep telling you as we learn more.

We will not notify your data subjects on your behalf, because the relationship is yours and the notification has to come from you. We will give you everything you need to write it.

We will also help you with data protection impact assessments and with any prior consultation you have to make under Articles 35 and 36, as far as the information is ours to give.

10 Deletion and return

You can delete submission data yourself at any time, three ways: one submission, a whole form with everything in it, or the entire account. Each deletes rows rather than hiding them, and none of them needs our involvement or our permission.

When your account ends, closing it is what deletes the data, and it happens in one operation and immediately. If you would rather have a copy returned first, ask before you close it. If you ask us to delete everything after the fact instead, we will do it within 30 days and confirm in writing.

Deleting is final here, and that is a choice rather than a limitation. We keep no backups of submission data and we never restore from our provider’s. There is no copy of yours that we can reach and no process by which we could put a deleted row back, which is what makes the word deletion mean anything. Our provider still takes its own encrypted copies, in the same region, and those age out within 7 days. Nothing of ours ever reads them.

The one thing we keep is billing records, for the six years tax law requires. Those hold no submission data.

11 Showing our work

We will give you what you need to satisfy yourself that we are doing this properly. In practice that means answering your security questionnaire, once a year and more often if something material changes, and passing on the certifications and reports our subprocessors publish.

You may audit us, yourself or through an auditor you appoint, on 30 days notice, during working hours, no more than once a year unless a breach or a regulator gives you reason. We will cooperate with it.

What we cannot offer is physical access to a data centre we do not own. Nobody can give you that, and a processor our size promising it would be promising something it would have to break. What we can give you is the audit reports of the people who do own them.

12 Liability, and how long this lasts

Liability under this agreement is subject to the limits in section 12 of the terms, except where the GDPR does not permit that.

This agreement starts when you create an account and runs until we stop processing submission data for you. The parts about confidentiality, deletion and liability outlive it.

If anything here conflicts with the terms, this agreement wins on data protection. If we change it, section 10 of the terms says how much notice you get.

13 Getting hold of us

Everything under this agreement, a breach, a data subject request, an audit, a signature, goes to [email protected]. We are small enough that this reaches a person who can act on it, which is the point.

We are not required to appoint a data protection officer and have not appointed one. The address above is the contact point for data protection matters.