Data Processing Agreement
Version 1.0 · Last updated 27 September 2026
This Data Processing Agreement (“DPA”) forms part of the Finero Terms of Use and of any order form or separately agreed contract for the Service (together, the “Agreement”) between Finero and the Customer. “Finero”, “Customer” and “Service” have the meanings given in the Terms of Use. The Customer enters into this DPA by accepting the Terms of Use; no separate signature is required.
1. Definitions
1.1 “Data Protection Laws” means all laws relating to the processing of personal data that apply to the processing under this DPA, including, as applicable, the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection (“FADP”), the Israeli Protection of Privacy Law, 5741-1981, and US state privacy laws. “UK GDPR” means the GDPR as it forms part of the law of the United Kingdom, and “US state privacy laws” means the comprehensive privacy laws of US states, such as the California Consumer Privacy Act.
1.2 “GDPR” means Regulation (EU) 2016/679.
1.3 “Customer Personal Data” means personal data that Finero processes on behalf of Customer in providing the Service.
1.4 “SCCs” means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.
1.5 “Sub-processor” means any third party engaged by Finero to process Customer Personal Data.
1.6 “Controller”, “processor”, “personal data”, “personal data breach”, “processing”, “data subject” and “supervisory authority” have the meanings given in the GDPR.
2. Roles and instructions
2.1 Customer is the controller and Finero is the processor of Customer Personal Data.
2.2 Finero processes Customer Personal Data only on Customer’s documented instructions, including with regard to transfers to third countries, unless required to do so by law to which Finero is subject. In that case, Finero will inform Customer of that legal requirement before processing, unless that law prohibits it. The Agreement, this DPA and Customer’s use and configuration of the Service are Customer’s complete instructions.
2.3 Finero will promptly inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
2.4 Customer is responsible for the lawfulness of the processing it instructs, including having a lawful basis for it and providing any notices required by Data Protection Laws.
2.5 The details of the processing are set out in Annex 1.
3. Confidentiality
Finero ensures that every person it authorises to process Customer Personal Data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality.
4. Security
Finero implements and maintains the technical and organisational measures set out in Annex 2 to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. Finero may update these measures, provided the overall level of security is not reduced.
5. Sub-processors
5.1 Customer grants Finero a general written authorisation to engage Sub-processors, including those on the current list, which Finero provides to Customer as set out in Annex 3.
5.2 Finero will notify Customer at least 30 days before engaging a new or replacement Sub-processor. Customer may object in writing on reasonable data protection grounds within that period. The parties will discuss the objection in good faith. If it is not resolved, Customer may terminate the affected part of the Service, and Finero will refund any prepaid fees for the terminated period.
5.3 Finero imposes on each Sub-processor, by written contract, data protection obligations that provide at least the same level of protection as this DPA, and remains fully liable to Customer for each Sub-processor’s performance of those obligations, subject to Section 12.1.
5.4 Third-party services that Customer chooses to connect to the Service, such as its ERP system, payment provider or email account, are engaged by Customer under its own terms and are not Sub-processors.
6. International transfers
6.1 Customer Personal Data is hosted in the European Union. Finero and its Sub-processors process it outside the European Economic Area only in compliance with Chapter V GDPR and other applicable Data Protection Laws.
6.2 Where Customer Personal Data is transferred to Finero in a country that is not recognised as providing an adequate level of protection, Module Two (controller to processor) of the SCCs is incorporated into this DPA by reference, as follows: Clause 7 (docking clause) applies; under Clause 9, Option 2 applies, with the notice period in Section 5.2; the optional wording in Clause 11 does not apply; the competent supervisory authority is determined under Clause 13; under Clause 17, Option 1 applies, and the governing law is that of Ireland; and under Clause 18, the courts of Ireland have jurisdiction. Annex I of the SCCs is completed by Annex 1, Annex II by Annex 2, and Annex III by the list of Sub-processors provided under Annex 3.
6.3 For transfers subject to the UK GDPR, the SCCs apply as amended by the International Data Transfer Addendum issued by the UK Information Commissioner (version B1.0). For transfers subject to the FADP, references to the GDPR are read as references to the FADP, and the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner.
6.4 Where Finero transfers Customer Personal Data to a Sub-processor, it ensures an appropriate safeguard under Data Protection Laws, such as an adequacy decision (including the EU-US Data Privacy Framework) or Module Three (processor to processor) of the SCCs.
6.5 If the SCCs conflict with this DPA, the SCCs prevail.
7. Assistance
7.1 Taking into account the nature of the processing, Finero assists Customer by appropriate technical and organisational measures, insofar as possible, in responding to requests from data subjects exercising their rights. Finero promptly forwards to Customer any such request it receives and does not respond to it except on Customer’s instructions.
7.2 Taking into account the nature of the processing and the information available to Finero, Finero assists Customer in ensuring compliance with its obligations under Articles 32 to 36 GDPR.
8. Personal data breaches
8.1 Finero notifies Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
8.2 The notice includes, to the extent then known, the information listed in Article 33(3) GDPR. Where not all of it is available at once, Finero provides it in phases without undue further delay.
8.3 Finero takes reasonable steps to contain, investigate and mitigate the effects of the breach, and keeps Customer informed.
8.4 Notification of a breach is not an acknowledgement of fault or liability.
9. Deletion and return
On termination or expiry of the Agreement, Finero, at Customer’s choice, returns Customer Personal Data in a commonly used, machine-readable format or deletes it, within 30 days, and deletes existing copies, unless Union or Member State law requires their storage. Copies in backups are deleted in the ordinary course of the backup cycle and remain protected by this DPA until then. On request, Finero confirms the deletion in writing.
10. Audits
10.1 Finero makes available to Customer all information necessary to demonstrate compliance with Article 28 GDPR, including written responses to reasonable security questionnaires, and allows for and contributes to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer.
10.2 Customer will first seek to meet its audit needs through the information provided under Section 10.1. Any inspection requires at least 30 days’ written notice, takes place during business hours no more than once in any 12-month period (unless following a personal data breach or required by a supervisory authority), is subject to appropriate confidentiality obligations, must not compromise the security of the Service or the data of Finero’s other customers, and is at Customer’s cost.
11. US state privacy laws
To the extent US state privacy laws apply to Customer Personal Data, Finero acts as Customer’s service provider or processor and will not: (a) sell or share Customer Personal Data; (b) retain, use or disclose it for any purpose other than providing the Service, or outside the direct business relationship between the parties; or (c) combine it with personal data received from other sources, except as those laws permit. Finero certifies that it understands and will comply with these restrictions, and will notify Customer if it can no longer meet them.
12. General
12.1 Finero’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability in the Agreement, including the single aggregate cap in section 18 of the Terms of Use, which applies to all claims against Finero under this DPA and the rest of the Agreement taken together. This DPA creates no separate or additional cap. Nothing in the Agreement limits liability to data subjects or supervisory authorities, or liability that Data Protection Laws or the SCCs do not permit to be limited.
12.2 In the event of conflict, the SCCs prevail over this DPA, and this DPA prevails over the rest of the Agreement on matters of personal data protection.
12.3 This DPA remains in force for as long as Finero processes Customer Personal Data.
12.4 This DPA is governed by the law that governs the Agreement, except that the SCCs are governed as set out in Section 6.2.
12.5 Notices under this DPA are given by email: to Finero at privacy@getfinero.com, and to Customer at the email address of an administrator of its workspace. Either party may change its address by notice to the other.
Annex 1: Details of processing
- Parties: data exporter: Customer (controller). Data importer: Finero (processor). Contact details are as set out in Section 12.5.
- Subject matter and purpose: provision of the Finero accounts-receivable service: synchronising invoices and customer records from Customer’s ERP system, creating payment links, sending invoice and payment emails, recording payments and reporting them to Customer’s ERP system, and providing collection reporting.
- Nature of processing: collection, recording, storage, organisation, retrieval, use, transmission and deletion.
- Frequency: continuous, for the duration of the Agreement.
- Duration and retention: the term of the Agreement, followed by deletion or return under Section 9.
- Data subjects: Customer’s customers (payers) and their contact persons; Customer’s authorised users of the Service.
- Categories of personal data: names; customer account numbers; contact names; email addresses; invoice details (numbers, dates, amounts, balances and payment terms); payment details (amounts, dates and payment provider references); for users, name, email address, login and activity records, and technical data such as IP addresses. Payment card data is not processed: payers enter it directly with Customer’s payment provider.
- Special categories of data: none.
- Hosting location: European Union (Ireland).
- Processing by Sub-processors: for the duration of the Agreement, as needed to provide the Service.
Annex 2: Technical and organisational measures
- Encryption: all data is encrypted in transit (TLS) and at rest (AES-256). Credentials for connected systems, such as ERP, payment-provider and email account access, are additionally encrypted at the application level with AES-256-GCM.
- Customer separation: every customer’s data is isolated in its own workspace. Isolation is enforced by the database itself on every request, independently of the application.
- Access control: least-privilege, role-based access within each workspace, and every permission is checked on the server. API keys and connected tools are restricted to a single workspace and enabled only by the customer’s administrator. Access to production systems is restricted to a small number of authorised personnel.
- Personnel: everyone with access to Customer Personal Data is bound by confidentiality obligations.
- Data minimisation: only the data needed to provide the Service is processed. No payment card data and no special categories of personal data are processed, and no copies of raw data from connected systems are kept. Customers can switch off the collection of optional data fields.
- Secure development: every change passes automated security and quality checks before release, including tests of customer isolation, permissions and outbound-connection restrictions. The platform also undergoes regular in-depth security reviews, including live attack testing, and findings are remediated promptly.
- Logging: credentials and other secrets are never written to logs, and logs are kept only for limited periods.
- Incident management: personal data breaches are handled and notified as set out in Section 8.
- Hosting: EU-based infrastructure from established providers that hold independent security certifications, such as SOC 2.
Annex 3: Sub-processors
Finero provides the current list of Sub-processors, with the purpose and location of each, to Customer on request at privacy@getfinero.com.