Legal

Data Processing Addendum

Last updated: 3 August 2026 · Finvora

This DPA describes how Finvora processes Customer Data on behalf of customer organisations using the Finvora cloud service. Have your counsel review before relying on it for enterprise procurement.

1. Roles

This Data Processing Addendum (“DPA”) forms part of the agreement between the customer (“Controller”) and Finvora (“Processor”) for the Finvora service.

Controller determines the purposes of processing Customer Data. Processor processes Customer Data only on documented instructions from Controller, except where required by law.

2. Scope of processing

Subject matter: hosting and processing business and personal data entered into Finvora (users, customers, invoices, accounting records, etc.).

Duration: for the term of the subscription and any post-termination retention required for backups or law.

Nature: storage, transmission, display, backup, and support access as needed to provide the service.

3. Processor obligations

Processor shall:

  • Process Customer Data only as instructed in the main agreement and this DPA.
  • Ensure persons authorised to process data are bound by confidentiality.
  • Implement appropriate technical and organisational security measures.
  • Assist Controller with data subject requests and reasonable DPIA / audit cooperation, subject to confidentiality and fees where appropriate.
  • Delete or return Customer Data after end of services, subject to legal retention.
  • Notify Controller without undue delay after becoming aware of a personal data breach affecting Customer Data.

4. Subprocessors

Controller authorises Processor to engage subprocessors necessary to deliver the service. Typical categories include cloud hosting, transactional email, payment processing, and error monitoring. Processor remains responsible for subprocessors and will impose equivalent data-protection obligations.

A current illustrative list (subject to change): cloud infrastructure provider(s), Amazon SES (or successor) for email, Stripe for payments, optional analytics/error tools when enabled.

5. International transfers

Where Customer Data is transferred internationally, Processor will ensure an adequate transfer mechanism under applicable law.

6. Controller responsibilities

Controller is responsible for the lawfulness of Customer Data it submits, for configuring access within the tenant, and for providing required notices to its own end users and customers.

7. Contact

Privacy / DPA inquiries: privacy@finvora.ai. Support: support@finvora.ai.

Related: Privacy · Terms · Cookies · DPA