Flurzi Commit Legal

Business Data Processing Agreement

Back to Home

Publication revision: 1.1.1-uk-20260922. Effective date: 22 September 2026. Current rollout is UK web and iOS; Android is deferred. Features described in these documents are not all enabled. Original-account and newer decision-record exports currently use separate controls. Closure and erasure requests require review across the original account, Firebase and providers; submission does not confirm completion. Your statutory rights are unchanged.

BUSINESS DATA PROCESSING AGREEMENT

Document key: BUSINESS_DPA

Version: 1.1.1-uk-20260922

Effective date: 22 September 2026

This Business Data Processing Agreement (DPA) forms part of the Flurzi Commit Business Terms between the Business Customer (Controller) and Flurzi Limited (Processor) to the extent Flurzi processes personal data in Business Customer Content on the Customer's behalf.

1. Definitions

1.1 Applicable Data Protection Law means the UK GDPR, Data Protection Act 2018 and other data-protection law that applies to the relevant processing, including the Data (Use and Access) Act 2025 amendments where in force, and EU GDPR where it applies to the processing.

1.2 Customer Personal Data means personal data contained in Business Customer Content that Flurzi processes on the Customer's behalf.

1.3 Subprocessor means another processor engaged by Flurzi to process Customer Personal Data in providing the service.

1.4 Terms such as controller, processor, personal data, processing and personal data breach have the meanings given by Applicable Data Protection Law.

2. Scope and duration

2.1 This DPA applies for the duration of the Business service and for as long afterwards as Flurzi processes Customer Personal Data on behalf of the Customer.

2.2 The subject matter, nature, purpose, categories of data and categories of data subjects are described in Schedule 1.

3. Processing instructions

3.1 Flurzi will process Customer Personal Data only on the Customer's documented instructions, including the instructions in the Business Terms, configured workspace settings and documented requests made through the service, unless UK law or another law binding on Flurzi requires different processing.

3.2 If law requires Flurzi to process Customer Personal Data beyond the Customer's instructions, Flurzi will inform the Customer before processing unless the law prohibits that notice.

3.3 Flurzi will promptly inform the Customer if, in Flurzi's reasonable opinion, an instruction infringes Applicable Data Protection Law, and may suspend the affected processing while the parties resolve the issue.

3.4 The Customer acknowledges that configuration and actions performed by its authorised users through the service constitute documented instructions within their permitted scope.

4. Confidentiality

Flurzi will ensure that personnel authorised to process Customer Personal Data are subject to appropriate confidentiality obligations and receive access only where required for their role.

5. Security

5.1 Flurzi will maintain appropriate technical and organisational measures having regard to the nature of the processing, the sensitivity of financial and accounting data, the state of the art, implementation costs and relevant risks.

5.2 The principal measures are summarised in Schedule 2 and may evolve as technology and risks change, provided that the overall level of protection is not materially reduced.

6. Subprocessors

6.1 The Customer gives Flurzi general authorisation to use Subprocessors to provide the Business service, subject to this section.

6.2 Flurzi will maintain an up-to-date subprocessor register at https://flurzicommit.com/legal/subprocessors identifying the relevant service, legal entity, processing purpose and location information available to Flurzi.

6.3 Flurzi will impose data-protection obligations on each Subprocessor that provide substantially equivalent protection for Customer Personal Data as required of Flurzi under this DPA for the processing delegated to that Subprocessor.

6.4 Where Applicable Data Protection Law requires prior notice of a new Subprocessor, Flurzi will provide reasonable notice before the new Subprocessor begins processing Customer Personal Data. The Customer may object on reasonable data-protection grounds during the stated objection period. The parties will work in good faith to resolve a valid objection. If no reasonable alternative is available, either party may terminate the materially affected feature or service in accordance with the Business Terms.

6.5 Flurzi remains responsible for its Subprocessors to the extent required by Applicable Data Protection Law and the contract.

7. International transfers

7.1 Flurzi will not make a restricted transfer of Customer Personal Data except on the Customer's documented instructions or as necessary to provide the service under an appropriate lawful transfer mechanism.

7.2 Where required, Flurzi will use an applicable safeguard such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses or another approved mechanism, and will carry out any required transfer-risk/data-protection assessment and supplementary measures.

7.3 Where the parties need to execute or incorporate an approved transfer instrument for a particular transfer, they will do so and the approved mandatory clauses prevail over conflicting commercial wording to the extent required by law.

8. Data-subject rights

8.1 Taking into account the nature of the processing, Flurzi will provide reasonable technical and organisational assistance to help the Customer respond to requests by data subjects exercising rights under Applicable Data Protection Law.

8.2 If Flurzi receives a request directly concerning Customer Personal Data for which the Customer is controller, Flurzi will not independently fulfil the request except on the Customer's instruction or where legally required. Flurzi will forward or otherwise notify the Customer where legally permitted and reasonably identifiable.

9. Personal data breaches

9.1 Flurzi will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.

9.2 The notice will include information reasonably available to Flurzi about the nature of the breach, affected data/data subjects, likely consequences and measures taken or proposed, to the extent required to help the Customer meet its legal obligations.

9.3 Flurzi may provide information in phases where all details are not available at the time of the initial notice.

9.4 Notification under this section is not an admission of fault or liability.

10. Assistance and compliance

Taking into account the nature of processing and information available to Flurzi, Flurzi will provide reasonable assistance with:

the Customer's security obligations;

breach assessment and notification;

data-protection impact assessments where the service processing requires one;

prior consultation with a supervisory authority where required; and

demonstrating compliance with the processor obligations that apply to Flurzi.

11. Return, export and deletion

11.1 During the service, authorised OWNER and DIRECTOR roles can request the Business raw-data export provided by the product.

11.2 On termination or closure, and subject to the Business Terms, Flurzi will delete or return Customer Personal Data at the Customer's choice where technically and legally applicable, and delete remaining copies when no longer required.

11.3 Section 11.2 does not require deletion of data that Flurzi must retain by law, data subject to an active legal hold, or information for which Flurzi has a separate lawful controller purpose. Retained data will be minimised, access-restricted and processed only for the applicable retention purpose.

11.4 The Customer understands that posted business accounting records may need to remain intact as records of the Business Customer even where a particular authorised user requests personal erasure. Flurzi will minimise former-user identifiers where appropriate without corrupting the Business Customer's record.

12. Audit and information rights

12.1 Flurzi will make available information reasonably necessary to demonstrate compliance with the processor obligations in this DPA, which may include security documentation, relevant policies, audit summaries or independent assurance reports when available.

12.2 If that information is insufficient for a reasonable, specific compliance need, the Customer may request an audit. Audits must be reasonable in scope, frequency and timing, protect other customers and Flurzi confidential information, avoid unnecessary disruption and be subject to appropriate confidentiality and security requirements.

12.3 Unless a serious incident, regulator or demonstrated material non-compliance requires otherwise, the Customer will not require more than one customer-initiated audit in any 12-month period. The Customer bears its own audit costs and Flurzi's reasonable incremental costs where permitted by law and agreed in advance.

13. Customer obligations

13.1 The Customer is responsible for determining that its instructions are lawful, providing required privacy information, identifying an appropriate lawful basis and responding to data subjects as controller.

13.2 The Customer will not instruct Flurzi to process personal data that is excessive, irrelevant or unlawfully obtained, and will use access controls appropriate to the sensitivity of the workspace.

13.3 The Customer is responsible for its own endpoint/device security, user management, role assignment and internal confidentiality obligations.

14. Liability and precedence

14.1 Liability under this DPA is subject to the liability provisions of the Business Terms except to the extent Applicable Data Protection Law requires otherwise.

14.2 If this DPA conflicts with the Business Terms about the protection or processing of Customer Personal Data, this DPA prevails for that subject matter. Any applicable approved international transfer instrument prevails to the extent its mandatory clauses require.

15. Governing law

This DPA is governed by the governing-law clause in the Business Terms, except where an applicable mandatory data-transfer instrument specifies otherwise.

Schedule 1 - Processing details

A. Subject matter

Provision of Flurzi Commit Business, including hosting, organising and processing Customer financial/accounting data; connected-account ingestion; manual/imported data processing; classification and reconciliation; invoicing and bill management; reporting; commitments and decision-support features; authorised exports; support; backup; security and related service operations.

B. Duration

For the Business service term and any limited post-termination period required to support export, deletion, backups, legal holds and lawful retention.

C. Nature and purpose of processing

Collection on instruction, receipt, recording, organisation, structuring, storage, retrieval, consultation, classification, matching, reconciliation, calculation, reporting, display, transmission to authorised users/providers, backup, security monitoring, export, deletion and anonymisation as necessary to provide the Business service.

D. Categories of data subjects

Business Customer authorised users; owners; directors; employees; contractors; accountants and advisers; customers; suppliers; payers/payees; business contacts; counterparties; and other individuals whose data the Business Customer lawfully places in the workspace.

E. Types of personal data

Names and contact details; business role and organisation information; bank and transaction data; invoice/bill and payment information; accounting references; customer/supplier records; receipts and attachments; commitment and approval data; user notes; audit/activity information; device/security information where contained in Customer Content; and other data the Customer chooses to upload within supported features.

F. Special-category/criminal-offence data

Ordinary Flurzi Commit Business features do not require special-category or criminal-offence data as a standard input. The Customer must not upload such data unless it is necessary, lawful, supported by the relevant feature and subject to any additional safeguards required by law.

Schedule 2 - Security measures

Flurzi's security programme for the service is designed to include:

1. authenticated, role- and workspace-based access control, default-deny permissions, tenant isolation and restricted administrative/support access;

2. multi-factor and step-up authentication for sensitive actions;

3. encryption in transit and at rest for sensitive data, together with managed key and secret controls for production credentials;

4. logging, tamper-evident audit trails, monitoring, alerting and incident investigation;

5. secure software-development practices, dependency/security scanning and pre-release security testing;

6. backup, restore testing, resilience and disaster-recovery controls;

7. file size/type validation, quarantine and malware scanning for enabled upload features;
Personal terms · Personal privacy · Business terms · Business privacy · Business DPA · Cookies