Memberflow logo

Data Processing Agreement

The Article 28 terms for member data we process on your behalf.

Version 1.0 — July 13, 2026
Who needs this: if you run a community with UK/EU members, you are the controller of their personal data and Memberflow is your processor. This agreement is what lets you answer your members lawfully when they ask who processes their data. It applies automatically to your use of Memberflow — you don't need to sign anything. If your organisation needs a counter-signed copy, email us.

This DPA forms part of the agreement between Skool Nerds / Bad Day Excellence ("Processor", "we") and the Memberflow customer ("Controller", "you"), and applies whenever we process personal data on your behalf.

1. Roles

You are the Controller of personal data relating to your community members. We are your Processor for that data. For your own account data (your email, password, entitlement) we act as an independent Controller under our Privacy Policy.

2. Subject matter, duration, nature and purpose

We process your community members' personal data solely to provide Memberflow: building the insights you view, and — only where you enable them — publishing scheduled posts, sending welcome/broadcast DMs, and processing membership approvals. Processing lasts for as long as you have an account, or until you delete the data.

3. Categories of data and data subjects

We do not require or want special-category data. Please don't put it in a DM template.

4. Your instructions

We process this data only on your documented instructions — which, in practice, are the actions you take in the product. We will tell you if we believe an instruction breaches data protection law.

5. Confidentiality

Access to your data is limited to those who need it to operate or support the service, under confidentiality obligations.

6. Security

Our measures include: HTTPS for all transport; encryption at rest of the stored Skool session token (decrypted only inside our server process at point of use); row-level security and owner-scoping on customer data; and least-privilege key handling, with server-only keys never shipped to clients. See our Trust & Security page.

7. Subprocessors

You authorise us to use the subprocessors listed on our Trust & Security page (currently: Supabase/AWS for backend and hosting, Vercel for web hosting, Resend for transactional email, Giphy for GIF search, and Google/YouTube Data API for analytics). We remain responsible for their performance. We will keep the list current and give you a reasonable opportunity to object to a new subprocessor that processes your data.

8. International transfers

Our backend is hosted in the United States (AWS us-west-2). Where you are in the UK/EEA, transfers are made under appropriate safeguards (Standard Contractual Clauses and, where applicable, the UK Addendum / EU-US Data Privacy Framework), including in our agreement with Supabase.

9. Assisting you

Taking into account the nature of the processing, we will assist you with:

10. Breach notification

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need to meet your own notification duties.

11. Deletion and return

You can delete your data at any time. Deleting your account performs a full erasure: all of your server-side Memberflow data — automation content, the encrypted session token, DM/approval records, and your analytics warehouse — is deleted, along with your account. Backups age out on our providers' normal cycles.

12. Audit

We will make available the information reasonably necessary to demonstrate compliance with this DPA, including our data inventory and subprocessor list.

13. Contact

Data protection contact: brian@baddayexcellence.com

UK users may also complain to the Information Commissioner's Office (ICO), and can raise a privacy complaint directly on our Privacy Policy page — we acknowledge within 30 days.