Data Processing Agreement
Last updated: 8 July 2026
Purpose
These processing terms apply whenever an agency (the “Controller”) uses the LatchFlow platform to process personal data through LatchFlow (the “Processor”). They are incorporated into our Terms of Service and satisfy Article 28 of the UK GDPR. A countersigned copy is available for your records on request before you connect live data.
Roles
The agency is the Controller and determines the purposes and means of processing its tenant, landlord, contractor, and operational data. LatchFlow is the Processor and processes that personal data only on the agency’s documented instructions — including the instructions expressed through the product’s configuration, approval rules, and connected channels — except where the law requires otherwise.
Subject matter and details of processing
- Subject matter — provision of the LatchFlow AI operations platform.
- Duration — the term of the agency’s account, plus the deletion window below.
- Nature and purpose — storing and organising records; drafting, sending, and logging communications; triaging maintenance; chasing compliance; answering calls; and running supervised operational workflows.
- Types of personal data — names, contact details, correspondence, tenancy and property details, payment-status and arrears information, call transcripts, and any operational or safeguarding notes the agency chooses to record.
- Categories of data subject — tenants, landlords, applicants, guarantors, contractors, and the agency’s own staff.
Our obligations as Processor
- Process personal data only on the Controller’s documented instructions.
- Ensure personnel with access are bound by confidentiality.
- Implement appropriate technical and organisational security measures (below).
- Assist the Controller, taking account of the nature of processing, with data-subject requests, security, breach notification, and data-protection impact assessments.
- Not sell personal data and not use Customer Data to train third-party AI models.
- Make available the information needed to demonstrate compliance, and allow for reasonable audits (see below).
Security measures
- Encryption of personal data in transit (TLS) and at rest.
- Strict per-agency isolation — every data query is scoped to the agency, so one workspace cannot read another’s data.
- Least-privilege, authenticated access, with sensitive and customer-facing actions gated behind human approval.
- A full audit trail of AI drafts, decisions, approvals, overrides, and write-backs.
- Server-side re-verification of voice caller identity; privileged secrets held server-side only.
- Managed, backed-up infrastructure with monitoring and change control.
Further detail is on our Security page.
Subprocessors
The Controller authorises LatchFlow to engage the subprocessors listed below to deliver the service. We impose data-protection obligations on each that are no less protective than these terms, and we remain liable for their performance. We will give advance notice of any intended addition or replacement of a subprocessor that handles workspace data, and the Controller may object on reasonable data-protection grounds.
- Vercel Inc. — Application hosting and content delivery (EU/US (region-configured)).
- Supabase — Managed PostgreSQL database and encrypted file storage (Project-configured region).
- OpenAI — Large language model that drafts replies, summaries and triage (no training on your data via the API) (US).
- ElevenLabs — Voice synthesis and telephony transcription for the AI phone line (US/EU).
- Twilio — Telephony, SMS and WhatsApp message transport (EU/US).
- Microsoft 365 — Your own connected mailbox, accessed under your OAuth grant (your tenant, your data) (Your Microsoft tenant).
International transfers
Where a subprocessor processes personal data outside the UK, the transfer is made under the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum, plus supplementary measures. The primary hosting region for the workspace is confirmed with the Controller.
Personal data breaches
We will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, with the information reasonably available to help the Controller meet its own notification obligations to the ICO and, where required, to data subjects.
Return and deletion
On termination, and at the Controller’s choice, we will return or delete the Controller’s personal data within 30 days, and delete existing copies except where the law requires retention. The Controller can also export its data from the product at any time during the term.
Audit
We will make available the information reasonably necessary to demonstrate compliance with these terms and, on reasonable notice and subject to confidentiality, allow the Controller (or an appointed auditor) to verify it, in a way that does not compromise the security of other customers.
Contact
To request a countersigned copy or ask a processing question: support@latchflow.co.uk.