Data Processing Agreement
Terms for processing personal data on behalf of DisplayFlow customers.
Version: 8 October 2026. For agreement with a completed customer service schedule.
Parties and application
Babbage-AI Consultancy Limited, company number 16299266. Registered address: 29 Warren Road, Scunthorpe, North Lincolnshire, DN15 6XH, United Kingdom.
This Data Processing Agreement (DPA) is between Babbage-AI Consultancy Limited (DisplayFlow) and the customer identified in the applicable service agreement. It applies to personal data that DisplayFlow processes on the customer’s behalf to provide the agreed service. The customer acts as controller, or as a processor authorised by its controller; DisplayFlow acts as processor or sub-processor respectively. Our own account, billing and website processing is described in the Privacy Policy.
These terms take effect only when incorporated into or expressly agreed as part of the customer’s service agreement. Before agreement, the parties must complete the service details below. Publishing this page does not establish customer acceptance or confirm those details. For customer personal data, agreed DPA terms take precedence over conflicting service terms.
Processing details
The subject matter is delivery of the contracted digital-signage and, where enabled, quiz services. Processing includes receiving, storing, organising, retrieving, displaying, transmitting and deleting customer content, and supporting those operations. It lasts for the service term and any agreed return/deletion period.
Data may include names, business contact details, images, video, customer-supplied text, participant identifiers, answers and scores, and screen/device identifiers and operational logs where they relate to individuals. Data subjects may include customer staff, customers, visitors, quiz participants and people featured in content. The exact categories and enabled features must be recorded in the service details. Special-category and criminal-offence data are outside the agreed scope unless expressly agreed in writing with suitable safeguards.
Customer instructions and responsibilities
The customer determines the purposes of processing, provides lawful documented instructions and ensures appropriate notices, permissions and a lawful basis for its content and disclosures. Its service agreement, enabled settings and authorised requests form the instructions. The customer controls who can administer its account and what is shown publicly on screens.
DisplayFlow will process customer personal data only on those instructions, including for transfers, unless applicable law requires otherwise. Where permitted, it will inform the customer of that legal requirement before processing. It will immediately inform the customer if an instruction appears to infringe applicable data protection law.
Confidentiality and security
DisplayFlow will ensure that authorised people handling customer personal data are subject to confidentiality obligations. It will maintain technical and organisational measures appropriate to the risk, including access restrictions, account separation, protected authentication, secure transmission, and procedures for managing incidents and restoring service.
The platform includes password hashing for admin accounts, authenticated administration, customer-scoped records and screen-authenticated player access. The parties must record the deployment’s backup, recovery, access-review and security arrangements in the service details. No certification, encryption-at-rest arrangement or fixed recovery target is asserted by this page.
Sub-processors
DisplayFlow will obtain the customer’s prior specific or general written authorisation before engaging sub-processors. Where general authorisation is agreed, it will notify the customer of intended additions or replacements in advance and provide an opportunity to object before the change. The notice period and objection process must be recorded in the service agreement.
Sub-processors will be bound by written obligations providing equivalent protection for the processing entrusted to them. DisplayFlow remains responsible to the customer for their performance of those obligations. Hosting, storage, support email and optional AI processing must be included where they process customer data. OpenAI is used for requested AI image generation; Stripe’s payment processing and website analytics may involve separate controller roles and should not automatically be treated as customer-content sub-processing.
Service providers and locations
Hosting is supplied by EURHOSTing.net in the Netherlands. Babbage-AI Consultancy Limited provides email and support services. OpenAI provides requested AI image generation. Stripe and Google Analytics support payments and optional website measurement respectively. The service schedule must identify each provider’s contracting entity, role, actual processing locations and applicable data-processing terms before agreement.
International transfers
DisplayFlow will make restricted international transfers only in accordance with documented instructions and applicable law. The service details must identify processing countries and any applicable adequacy decision, UK International Data Transfer Agreement, UK Addendum or other lawful safeguard, together with any required assessment and supplementary measures.
Assistance and incidents
Taking account of the nature of processing and available information, DisplayFlow will assist the customer with data-subject requests, security obligations, breach notifications, impact assessments and prior consultation. Requests concerning customer-controlled data will be passed to the customer unless law requires a direct response.
DisplayFlow will notify the customer without undue delay after becoming aware of a personal data breach affecting customer data. It will provide available details about the incident, affected data and individuals, likely consequences, containment and remediation, with further information as it becomes available. The customer decides its regulatory and individual notifications; the parties will cooperate in investigating and mitigating the breach.
Return and deletion
At the end of the service, DisplayFlow will, at the customer’s choice, return or delete customer personal data and delete existing copies unless applicable law requires retention. The default service schedule provides a 90-day recovery window after an account is archived following expiry or closure, followed by reviewed deletion unless service resumes or a documented legal hold applies. An earlier customer return/deletion instruction takes precedence where lawful. Routine backups have a 30-day retention target. Implementation and coverage of existing backups must be confirmed before agreement. The parties must agree an export method and a deadline for handling specific return/deletion requests. Any retained backup copies must remain protected, be excluded from ordinary use and be deleted on the agreed cycle; if restored, the relevant deletion instructions must be reapplied. Separate lawful retention of controller records, such as billing records, is covered by the Privacy Policy.
Information and audits
DisplayFlow will make available information needed to demonstrate compliance with the agreed processing obligations and allow and contribute to audits, including inspections, by the customer or its mandated auditor. Practical arrangements must protect other customers’ data and service security without preventing legally required oversight. Both parties will cooperate with competent supervisory authorities.
Service details to complete before agreement
The parties must record: customer legal name and controller authority; service scope and enabled features; data and data-subject categories; processing duration; approved sub-processors and their roles and locations; transfer safeguards; security and backup arrangements; return/deletion deadlines; sub-processor change notice and objection procedure; and customer privacy/incident contacts.
Needs verification: provider contracting entities and downstream email infrastructure, processing locations beyond the confirmed Netherlands hosting, transfer safeguards and provider contracts, and deployment of the retention schedule across live data and all backup copies. Request a completed service schedule and business/legal review before relying on this page as an agreed DPA.
Urgent data incidents
Contact Richard Smith at richard@babbage-ai.co.uk for urgent data incidents. Send only the information needed to report the incident; do not include passwords or access tokens.
Contact and changes
For a customer-specific DPA, service schedule, data request or incident contact, email hello@displayflow.co.uk. Changes to this web page do not amend an already agreed DPA; amendments must follow the customer’s agreement.