Privacy Policy
How we handle data in BrokerFlux, and the difference between the data we decide about and the data we only hold for you.
Last updated 20 August 2026 · BrokerFlux is operated by WASTEFLUX LTD, registered in England and Wales, company number 17273695.
Who this is for
This policy covers BrokerFlux, the software platform waste-brokerage businesses use to run their operations. It is written for those businesses and the people who work for them.
If you booked a skip or a collection from a company that happens to use BrokerFlux, this is not the policy that applies to you. That company decides what happens to your information and publishes its own policy — ask them for it.
Two different roles
The law distinguishes between deciding what happens to data and merely holding it on someone else's instructions. We do both, for different things, and it changes your rights.
- We are the controller of your account: the names and email addresses of your team, your company details, your subscription and billing records, support correspondence, and logs of how the service is used.
- We are a processor of everything you put into the platform — your customers, your suppliers, your jobs, prices, documents and messages. You decide what to collect and why. We act on your instructions and do not use it for our own purposes.
For anything in the second category, the business you deal with is the controller. Send them your request and they will direct us. We are responsible for the security of everything we hold, in both roles.
What we collect, and why
| Data | Why | Basis |
|---|---|---|
| Name, work email, and the organisation you belong to | To create and secure your account | Performance of our contract with you |
| Company details, billing address, subscription and payment records | To take payment and meet our tax obligations | Contract, and legal obligation |
| Pages visited, actions taken, errors and timings | To keep the service working, diagnose faults and prevent abuse | Our legitimate interest in a reliable, secure service |
| Support messages you send us | To answer you and improve the product | Contract, and legitimate interest |
| Operational data you enter or upload | To provide the service to you — we hold it, you decide it | Processed on your instructions |
We do not sell data, we do not share it for advertising, and we do not use the operational data you put into the platform to train AI models.
Signing in
Accounts and sign-in are handled for us by Clerk. Your password is never sent to or stored by BrokerFlux — Clerk holds it, and we receive only a signed token confirming who you are. Two-factor authentication is available and we recommend turning it on.
We never ask for, and never store, your sign-in details for anyone else's service — not HMRC, not your bank, not your accounting software. Where the platform connects to one of those, it does so through that provider's own OAuth authorisation screen, and we hold only the resulting access token, encrypted.
Our checks against HMRC run under our own registered software credentials, not yours.
Payments and card details
Payments are processed by Stripe. Card numbers never reach our servers. They are typed directly into a form served by Stripe and embedded in our pages, so the details go from the browser to Stripe without passing through BrokerFlux code.
What we store is the card brand, the last four digits, and Stripe's own reference — enough to show you which card is on file and to charge it again, and not enough to be a card number. We hold no full card numbers, expiry dates or security codes anywhere.
Bank details you record for paying suppliers are different: those we do hold, and they are encrypted at rest as described below.
When we look at your data
Being your processor means we do not browse your data out of interest. Our staff access it only for these purposes, and only as much of it as the purpose needs:
- To operate, maintain and secure the service — including investigating an error or a performance problem.
- To answer a support request, or to fix a fault you have reported.
- To investigate suspected fraud, abuse, non-payment or a breach of our terms.
- To meet a legal obligation, or respond to a lawful request from a regulator, court or law-enforcement body.
- Where you have asked us to do something specific.
Access is restricted by role, so people can reach only what their job requires. Where an administrator needs to see the platform as your account shows it, that is done with a time-limited session that expires after 15 minutes, and every action taken during it is recorded against the individual who took it. Those records are kept and can be produced to you on request.
Your subscription agreement is our documented instruction to do the above. If a law compels us to go further, we will tell you unless we are prohibited from doing so.
Where it is kept
The service, its database and its files run on dedicated servers operated by Hetzner Online GmbH, Falkenstein, Germany. That is where your operational data is processed and stored.
Some of the providers below are outside the UK and EEA; where that is the case, transfers are covered by the UK International Data Transfer Addendum, EU Standard Contractual Clauses, or an adequacy decision.
Who else is involved
We engage these providers to deliver parts of the service. Each is bound by a contract that limits them to our instructions.
| Provider | What it does | Where |
|---|---|---|
| Hetzner Online GmbH | Hosting, database and file storage | Germany |
| Clerk | Sign-in and user accounts | United States |
| Stripe | Subscription billing, and card payments your customers make | United States / EU |
| Zoho Mail (EU) | Sending email on your behalf | European Union |
| Aurinko | Connecting your own mailbox, if you choose to | United States |
| ClickSend | Sending SMS | United Kingdom / Australia |
| Meta Platforms | WhatsApp Business messaging, if you enable it | United States / EU |
| OpenRouter | The Flux assistant | United States |
| Google Maps Platform | Turning addresses into map locations | United States |
| HERE Global | Maps and routing in the driver app | Germany |
| getAddress.io | UK postcode and address lookup | United Kingdom |
Some features connect to services under your own credentials — accounting (Xero) and supplier payouts (TrueLayer, Wise, Revolut) among them. Those are your relationships, on your terms with those providers, and only run when you connect them.
We also query UK public registers. We send an identifier and read the public record back; none of your data is disclosed to them.
| Register | What we ask |
|---|---|
| HM Revenue & Customs | Checking a supplier's VAT registration number |
| Companies House | Checking a company's registration details |
AI features
Two features send content to a language model: the Flux assistant, when you ask it something, and document reading, when you upload a waste transfer note or a supplier invoice for the details to be extracted. The request goes to our model provider, listed above, and the answer comes back to you.
That content is used to answer your request and nothing else. It is not used to train models, ours or anyone else's, and it is not shared with other customers. If you would rather no content left the platform this way, these features can be turned off for your account — ask us.
Automated extraction can be wrong. Nothing it produces is a decision about a person, and a human on your side reviews and approves before anything is acted on.
How long we keep it
- Account and operational data: for as long as your subscription runs.
- After it ends: 30 days, so you can change your mind or export, then deletion or irreversible anonymisation.
- Invoices and payment records: six years, because tax law requires it.
- Technical logs: up to 90 days.
- Audit records of administrative access: two years.
You can ask us to delete your data sooner, subject to records we are required to keep.
Keeping it safe
- Encrypted in transit. Every connection is over TLS. There is no unencrypted route into the service.
- Encrypted at rest. Personal details — names, phone numbers, email and postal addresses, driver licence numbers, supplier bank details — are encrypted in the database with AES-256-GCM, under a key derived separately for each customer, so one customer's key cannot open another's records.
- Access tokens and credentials are encrypted the same way, including the tokens for any accounting, payout or mailbox connection you authorise.
- Customers are separated by the database itself. Row-level security means a query carrying the wrong identity returns nothing — the isolation does not depend on application code remembering to filter.
- Least privilege, and a record of who did what. Permissions are role-based; administrative access is short-lived and audited.
- No card data. Card numbers are handled by Stripe and never stored by us, so they cannot be lost by us.
We review these controls as the product changes, and we fix security defects ahead of other work. No system is perfectly secure, and we will not claim otherwise.
Reporting a security problem
If you believe you have found a vulnerability in BrokerFlux, or you think an incident has affected your data, tell us at admin@wasteflux.co.uk. This is open to anyone, not only customers.
Please include enough detail to reproduce the problem, and give us a reasonable chance to fix it before publishing. We will acknowledge you within two working days, keep you updated, and we will not pursue anyone who reports a genuine finding in good faith and does not access or alter other people's data.
If something goes wrong
If a breach affects personal data we hold, we will tell you without undue delay and give you what you need to meet your own obligations. We notify the Information Commissioner's Office within 72 hours where the law requires it.
Where an incident touches data connected to HMRC services, we report it to HMRC immediately and provide full details within 72 hours, as their terms of use require.
Your rights
Where we are the controller, you can ask for a copy of your data, ask us to correct or delete it, ask us to restrict how we use it, object to processing based on legitimate interests, or ask for it in a portable format. We respond within one month.
You can also do most of this yourself while your subscription is active: account and company details are editable in the product, your records can be exported, and you can ask us to delete an account. Where we hold data as your processor, we act on your instruction.
Email admin@wasteflux.co.uk. If you are unhappy with our response you can complain to the Information Commissioner's Office at ico.org.uk.
Cookies
We set only what the product needs: a session cookie so you stay signed in, and a preference cookie remembering your light or dark theme. No advertising or cross-site tracking cookies, so there is no consent banner to click through.
Changes
If we change this policy we will update the date at the top, and tell account owners by email before anything significant takes effect.
Contact us
WASTEFLUX LTD (company 17273695), 51 Eastern Way, Letchworth Garden City, SG6 4PG, United Kingdom.
Privacy: admin@wasteflux.co.uk · Security: admin@wasteflux.co.uk · Support: admin@wasteflux.co.uk
See also our Terms of Service.
