Data Processing Addendum
Version 1.0 — September 2026
This Data Processing Addendum ("DPA") forms part of the Fluxeta Terms of Service between you ("Customer") and Decipher Consultancy Services ("Fluxeta"). It applies whenever Fluxeta processes Personal Data on behalf of Customer in providing the Services and is deemed accepted by Customer upon acceptance of the Terms of Service.
1. Definitions
Terms used in this DPA have the meanings set out in the GDPR (Regulation (EU) 2016/679), UK GDPR, or comparable applicable law. In particular:
- "Personal Data" means any information relating to an identified or identifiable natural person that Fluxeta processes on Customer's behalf in providing the Services.
- "Data Subject" means the individual to whom Personal Data relates (typically Customer's end-users, subscribers, or members).
- "Sub-processor" means any third party engaged by Fluxeta to process Personal Data on Customer's behalf. The current list is at fluxeta.com/subprocessors.
- "Applicable Data Protection Law" means the GDPR, UK GDPR, the Digital Personal Data Protection Act 2023 (India), the CCPA / CPRA (California), and any other data-protection law applicable to the processing.
2. Scope and roles
Where Fluxeta processes Personal Data on Customer's behalf in the course of providing the Services, Customer is the Controller (or Data Fiduciary under the DPDP Act) and Fluxeta is the Processor (or Data Processor). Where Fluxeta processes data about Customer's own account (for example, billing details), Fluxeta acts as an independent Controller for that limited purpose.
The subject matter, nature, duration, purpose, and categories of Personal Data are set out in Annex I.
3. Processing instructions
Fluxeta shall process Personal Data only on documented instructions from Customer, as set out in the Terms of Service, this DPA, and any other written instructions Customer provides. If Fluxeta is required by law to process Personal Data outside those instructions, Fluxeta shall inform Customer before processing unless that law prohibits such notice on public-interest grounds.
4. Security measures
Fluxeta shall implement and maintain the technical and organisational measures described in Annex II, designed to ensure a level of security appropriate to the risk. Personnel authorised to process Personal Data are bound by written confidentiality obligations.
5. Sub-processors
Customer provides general written authorisation for Fluxeta to engage the sub-processors listed at fluxeta.com/subprocessors. Fluxeta shall inform Customer of any intended additions or replacements at least 30 days in advance via that page and, on request, by email. Customer may object to a new sub-processor on reasonable grounds within that 30-day period. If Customer's objection cannot be resolved, Customer may terminate the affected Services and receive a refund for the unused portion of any pre-paid fees.
Fluxeta remains liable to Customer for the performance of each sub-processor's obligations to the same extent as if the acts were Fluxeta's own.
6. International transfers
Where Fluxeta transfers Personal Data outside the country of origin, it does so pursuant to an appropriate transfer mechanism. Where GDPR or UK GDPR applies:
- Transfers to countries with an adequacy decision are governed by that decision.
- Transfers to other countries are governed by the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) or the UK International Data Transfer Addendum, as applicable, which are incorporated into this DPA by reference.
7. Data-subject rights
Fluxeta shall, taking into account the nature of the processing, provide reasonable assistance to Customer in responding to requests from Data Subjects to exercise their rights under Applicable Data Protection Law. Customer-facing tools within the Fluxeta admin (data export, subscriber deletion, etc.) are provided as the primary means of fulfilling such requests. Where those tools are insufficient, Customer may contact [email protected] for additional assistance.
8. Breach notification
Fluxeta shall notify Customer without undue delay, and in any event within 72 hours of becoming aware, of any Personal Data breach affecting Customer's Personal Data. Notification shall include (to the extent known) the nature of the breach, the categories and approximate number of Data Subjects affected, the likely consequences, and the measures taken or proposed to address the breach.
9. Audits
Fluxeta shall make available to Customer information reasonably necessary to demonstrate compliance with this DPA. On written request, Fluxeta shall provide summaries of any third-party audit reports (SOC 2, ISO 27001, etc.) it holds. On-site audits by Customer are permitted no more than once per twelve-month period, on 30 days' written notice, conducted at Customer's expense, subject to reasonable confidentiality obligations, and only to the extent necessary to verify Fluxeta's compliance with this DPA.
10. Return and deletion
On termination of the Services, Fluxeta shall, at Customer's choice, delete or return all Personal Data to Customer, and delete existing copies, unless Applicable Data Protection Law requires storage. Customer-facing tools (data export via the admin dashboard) are the primary mechanism for return. Deletion of Personal Data from Fluxeta's active systems shall occur within 30 days of termination; deletion from backup media shall occur within a further 90 days on natural backup rotation.
11. Liability
Each party's liability under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Terms of Service. Nothing in this DPA limits either party's liability where such limitation is prohibited by Applicable Data Protection Law, including in respect of Data Subject rights.
Annex I — Details of processing
Subject matter: Provision of the Fluxeta creator platform (blog, newsletter, membership, courses, products, analytics).
Duration: For the term of the Terms of Service, plus deletion periods in section 10.
Nature and purpose: Storage, transmission, and processing of Personal Data necessary to provide the Services and support Customer's use of them.
Categories of Data Subjects: Customer's end-users, subscribers, members, buyers, students, and other individuals whose data Customer inputs into or generates on the platform.
Categories of Personal Data: Contact details (name, email, phone), account credentials, subscription and membership status, transactional metadata, content submitted by or to the Data Subject, IP addresses, device identifiers, engagement analytics (opens, clicks, page views).
Special-category data: Fluxeta does not intentionally process special-category data. Customer shall not upload special-category data without a lawful basis and appropriate additional safeguards.
Retention: Data is retained for the duration of Customer's account plus the deletion periods in section 10.
Annex II — Technical & organisational measures
Fluxeta implements at minimum the following measures:
- Encryption in transit: TLS 1.2 or higher enforced for all customer-facing endpoints and all sub-processor connections.
- Encryption at rest: AES-256 encryption for object storage (S3) and database volumes.
- Access control: Role-based access control within the platform; principle of least privilege for personnel; multi-factor authentication for all administrative access; SSO available for enterprise customers.
- Network security: Cloudflare edge WAF, rate limiting, DDoS mitigation. Origin firewall restricts inbound traffic to Cloudflare IP ranges.
- Application security: Automated pre-deploy security checks, dependency vulnerability scanning, quarterly manual security review.
- Logging & monitoring: Application and access logs retained for 90 days; anomaly alerting for authentication and payment events.
- Backup & recovery: Daily encrypted backups to a separate storage region; documented restore procedures with periodic test restores.
- Personnel: Confidentiality agreements for all staff; security-awareness training on onboarding and annually.
- Incident response: Documented incident-response plan, breach-notification timelines aligned with section 8.
- Vendor management: Written data-processing agreements with all sub-processors listed at fluxeta.com/subprocessors.
Requesting a countersigned DPA. Enterprise customers who require a counter-signed PDF may email [email protected] with the subject line "DPA counter-signature request" and the account email. We will return an executed PDF within five business days.