Legal
Consultant Data Addendum
Last updated 17 August 2026
This addendum applies when a consultant, adviser, agency or other business user submits workflow information relating to a client or third party. It supplements the Terms & Conditions and the Privacy Notice, and applies over them where they differ on the handling of client information.
Status. This is a practical commercial document written from verified product behaviour. It is not a regulator-reviewed Data Processing Agreement and is not a claim of certification or regulatory compliance. It requires professional legal review before it is signed or relied upon contractually.
1. Client authority
Before submitting client information you confirm that you have the necessary authority, permission or lawful basis to do so, and that submitting it does not breach a confidentiality agreement, engagement letter or other obligation you owe the client.
You decide what to submit. WorkflowMD does not need personal data to produce an assessment — describing roles rather than named individuals, and leaving out customer records the analysis does not need, is usually enough.
2. Ownership
- You or your underlying client retain ownership of all submitted workflow information: process descriptions, interview answers, supporting documents and the business knowledge they contain.
- WorkflowMD does not acquire ownership of your client’s business processes, documents or underlying intellectual property.
- You grant WorkflowMD only the rights necessary to host, process, analyse and return the service — including transmitting content to the AI processing services described below, and storing it where you choose to save an assessment.
- WorkflowMD retains ownership of the platform itself: its software, scoring engine, methodology, report structure and branding. That does not extend to your content.
3. Confidentiality
WorkflowMD treats the following as confidential: commercially sensitive workflow information, internal processes, submitted supporting documents, generated assessment outputs, and client identities where you provide them.
We will not intentionally publish client-specific information, and will not use it as a public case study, testimonial, sample assessment or marketing example without permission. Published sample assessments are constructed illustrative scenarios, not customer material.
Access to stored content is limited to the account that created it, enforced at the database layer, plus the restricted administrative access needed to operate and support the service.
4. Processing instructions
Submitted content is processed to:
- operate the application and your workspace;
- generate workflow assessments, findings and target-state design;
- generate AI-assisted analysis of the material you provide;
- save reports and derived improvement actions where you choose to save them;
- respond to your support requests;
- maintain security, enforce plan limits and prevent abuse.
Related: How WorkflowMD reaches a conclusion
5. Subprocessors
WorkflowMD relies on third-party infrastructure and AI subprocessors. Application hosting and the AI gateway are provided by Lovable; AI analysis is produced by Google Gemini models reached through that gateway; the database and authentication run on Lovable Cloud; payments are handled by Paddle as Merchant of Record; transactional email is sent through Lovable’s managed email service. The current summary is on the Data & Security page.
We make no representation that AI providers do not retain, review or train on content routed to them. That question is not yet independently confirmed, and this addendum will be updated when it is.
6. Security controls
We assert only the following controls, each verified against the shipped product:
- encryption in transit (HTTPS/TLS) for all traffic;
- row-level database access controls, enforced at the database rather than in the interface, so one account cannot read another account’s reports;
- authenticated workspace access for saved reports, progress and settings;
- restricted administrative access — privileged credentials are server-side only and never reach the browser;
- an append-only record of automated decisions.
We do not claim SOC 2, ISO 27001, HIPAA compliance, GDPR certification, penetration testing, zero data retention or end-to-end encryption.
7. Supporting documents
A document or pasted text is read from the request and sent to the AI processing service for extraction. The structured summary is returned to your browser for review; nothing starts automatically.
The source file is not persisted in WorkflowMD application storage after extraction — we operate no file storage for uploaded documents. We do not state that uploaded documents are never stored anywhere: the content is transmitted to the AI processing service, and provider-side handling has not been independently confirmed.
8. Retention and deletion
- Saved reports — kept until you delete them. Deleting a report also removes its improvement actions, value metrics and snapshots.
- Analysis records — each automated analysis is recorded in an append-only audit table so a report remains explainable later. It is not linked to the report record and is not removed when you delete a report.
- Bulk deletion — “Delete my data” in Settings removes every saved report in the workspace; the account and subscription remain.
- Account deletion — currently handled as a manual request through the contact page; there is no self-serve button yet.
- Uploaded source files — not persisted in WorkflowMD storage.
- Application logs — error message, stack and operation tag only, no workflow content. Retention is set by the hosting runtime.
- Payment records — held by Paddle under its own statutory obligations.
We do not state a deletion timeframe, because none has been verified, and we do not claim immediate permanent deletion across all systems, providers and backups. Backup retention is an open item we are still documenting.
9. Security incidents
WorkflowMD will take reasonable steps to investigate a suspected security incident affecting submitted content, to limit its effect, and to notify affected users where notification is legally required or materially relevant to them. No response-time service level is offered, and nothing here creates an SLA.
10. Consultant feedback
Where you give feedback on WorkflowMD:
- participation is voluntary, and you may stop at any time;
- feedback does not create an obligation to purchase, subscribe or renew;
- feedback does not create a partnership, agency, joint venture, reseller or employment relationship;
- feedback does not oblige you to take part in future sessions;
- any commercial arrangement requires a separate written agreement.
Please keep product feedback separate from confidential client information: describe the problem in general terms rather than sharing client material you would not otherwise submit.
11. Legal review and jurisdiction
This document is a first-pass commercial addendum written from verified product behaviour. It has not been reviewed by a qualified legal adviser and should not be represented as a formal regulatory Data Processing Agreement or as evidence of compliance with any specific statute. Professional legal review is required before it is executed or offered as a signed DPA. Governing law and jurisdiction follow the Terms & Conditions.
12. Contact
Questions about this addendum: contact Lee Stephens through the contact page.