LEGAL · GDPR & DATA PROTECTION

GDPR Compliance & Data Processing

Last updated: 1 May 2026

PsychFlo processes behavioural metadata about employees on behalf of employer organisations. This page explains our obligations and yours under the General Data Protection Regulation (GDPR) and applicable data protection law in your jurisdiction.

GDPR COMPLIANCE STATUS

GDPR Article 28 DPA available
Data minimisation by design
Data residency within agreed jurisdictions
Automated retention and deletion
Employee right of access portal
Lawful basis documented for all processing
Sub-processor agreements in place
ICO registration

1. Controller and Processor Roles

PsychFlo operates in two distinct data roles depending on the context:

DATA CONTROLLER

For website visitors, demo enquiry contacts, and platform account holders. PsychFlo determines the purpose and means of processing this data.

DATA PROCESSOR

For employee behavioural data processed on behalf of client organisations. The client organisation is the Data Controller. PsychFlo processes only under documented instruction set out in a signed DPA.

2. Data Processing Agreement (DPA)

All client organisations that use PsychFlo to process employee data must sign a Data Processing Agreement before any employee data is ingested into the platform. The DPA covers:

Subject matter, duration, nature, and purpose of processing
Type of personal data and categories of data subjects
Obligations and rights of the Controller (client organisation)
PsychFlo's obligations as Processor under GDPR Article 28
Sub-processor authorisation and notification obligations
Assistance with data subject rights requests
Data breach notification procedures (72-hour window to ICO)
Return or deletion of data on contract termination

Request our standard DPA

Available for review before signing any contract

Request DPA →

3. Special Category Data

Employee mental health and wellbeing information may constitute special category data under GDPR Article 9. PsychFlo is specifically designed to avoid processing special category data:

WHAT WE DO PROCESS

Calendar metadata (timing, frequency — not titles or content)
Communication metadata (response latency, participation — not message content)
Task metadata (completion rates, timing — not task names or descriptions)
HRIS data (department, tenure, reporting structure)

WHAT WE DO NOT PROCESS

Message or email content
Audio or video recordings
Individual psychological assessments or diagnoses
Health records or occupational health data
Any data the employee has not consented to share

All outputs are aggregated at team level (minimum five members). No individual-level outputs are generated. This architectural decision means PsychFlo does not produce data about identifiable individuals’ mental health — and therefore does not trigger Article 9 special category requirements in ordinary operation.

4. Lawful Basis for Employee Data Processing

Client organisations (as Data Controllers) are responsible for establishing and documenting a lawful basis for processing their employees’ data using PsychFlo. We recommend and support the following approaches:

Legitimate interests (Art. 6(1)(f))

Monitoring workforce wellbeing to prevent harm and fulfil duty of care obligations is generally accepted as a legitimate interest for employers, provided a Legitimate Interests Assessment (LIA) is completed and documented. PsychFlo can provide a template LIA for client use.

Legal obligation (Art. 6(1)(c))

Employers have statutory duty of care obligations under applicable health and safety legislation. Proactive monitoring to meet these obligations may constitute a legal obligation lawful basis depending on jurisdiction.

Consent (Art. 6(1)(a))

Where clients choose to use consent as their lawful basis, PsychFlo supports opt-in employee consent flows for all employee-facing features. Consent must be freely given, specific, informed, and withdrawable without detriment.

5. Employee Rights Facilitation

PsychFlo is designed to make it straightforward for client organisations to respond to employee rights requests:

Subject access requests

Employees can request their own signal data through the HR admin panel. Export available within 5 business days.

Right to erasure

Individual employee records can be deleted from the platform by the HR admin at any time. Automated deletion at contract end.

Right to restriction

Individual employees can be excluded from signal collection by HR admin. Opt-out does not produce a flag visible to managers.

Right to object

Employees who object to processing can be removed from all data collection without affecting their employment record in the platform.

6. Data Breach Notification

In the event of a personal data breach, PsychFlo will:

1.Notify the affected client organisation without undue delay and within 72 hours of becoming aware of the breach
2.Provide a description of the nature of the breach, categories and approximate number of data subjects and records affected
3.Describe the likely consequences of the breach and measures taken or proposed to address it
4.Cooperate fully with the client organisation’s obligation to notify the ICO where required

7. Contact and Complaints

For GDPR-related enquiries, DPA requests, or data subject rights requests:

PsychFlo Data Protection Contact

Email: info@psychflo.com

You also have the right to complain to the relevant data protection supervisory authority in your jurisdiction.