Data Processing Agreement

Version 1.0 · Last updated 27 September 2026

This Data Processing Agreement (“DPA”) forms part of the Finero Terms of Use and of any order form or separately agreed contract for the Service (together, the “Agreement”) between Finero and the Customer. “Finero”, “Customer” and “Service” have the meanings given in the Terms of Use. The Customer enters into this DPA by accepting the Terms of Use; no separate signature is required.

1. Definitions

1.1 “Data Protection Laws” means all laws relating to the processing of personal data that apply to the processing under this DPA, including, as applicable, the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection (“FADP”), the Israeli Protection of Privacy Law, 5741-1981, and US state privacy laws. “UK GDPR” means the GDPR as it forms part of the law of the United Kingdom, and “US state privacy laws” means the comprehensive privacy laws of US states, such as the California Consumer Privacy Act.

1.2 “GDPR” means Regulation (EU) 2016/679.

1.3 “Customer Personal Data” means personal data that Finero processes on behalf of Customer in providing the Service.

1.4 “SCCs” means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.

1.5 “Sub-processor” means any third party engaged by Finero to process Customer Personal Data.

1.6 “Controller”, “processor”, “personal data”, “personal data breach”, “processing”, “data subject” and “supervisory authority” have the meanings given in the GDPR.

2. Roles and instructions

2.1 Customer is the controller and Finero is the processor of Customer Personal Data.

2.2 Finero processes Customer Personal Data only on Customer’s documented instructions, including with regard to transfers to third countries, unless required to do so by law to which Finero is subject. In that case, Finero will inform Customer of that legal requirement before processing, unless that law prohibits it. The Agreement, this DPA and Customer’s use and configuration of the Service are Customer’s complete instructions.

2.3 Finero will promptly inform Customer if, in its opinion, an instruction infringes Data Protection Laws.

2.4 Customer is responsible for the lawfulness of the processing it instructs, including having a lawful basis for it and providing any notices required by Data Protection Laws.

2.5 The details of the processing are set out in Annex 1.

3. Confidentiality

Finero ensures that every person it authorises to process Customer Personal Data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality.

4. Security

Finero implements and maintains the technical and organisational measures set out in Annex 2 to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. Finero may update these measures, provided the overall level of security is not reduced.

5. Sub-processors

5.1 Customer grants Finero a general written authorisation to engage Sub-processors, including those on the current list, which Finero provides to Customer as set out in Annex 3.

5.2 Finero will notify Customer at least 30 days before engaging a new or replacement Sub-processor. Customer may object in writing on reasonable data protection grounds within that period. The parties will discuss the objection in good faith. If it is not resolved, Customer may terminate the affected part of the Service, and Finero will refund any prepaid fees for the terminated period.

5.3 Finero imposes on each Sub-processor, by written contract, data protection obligations that provide at least the same level of protection as this DPA, and remains fully liable to Customer for each Sub-processor’s performance of those obligations, subject to Section 12.1.

5.4 Third-party services that Customer chooses to connect to the Service, such as its ERP system, payment provider or email account, are engaged by Customer under its own terms and are not Sub-processors.

6. International transfers

6.1 Customer Personal Data is hosted in the European Union. Finero and its Sub-processors process it outside the European Economic Area only in compliance with Chapter V GDPR and other applicable Data Protection Laws.

6.2 Where Customer Personal Data is transferred to Finero in a country that is not recognised as providing an adequate level of protection, Module Two (controller to processor) of the SCCs is incorporated into this DPA by reference, as follows: Clause 7 (docking clause) applies; under Clause 9, Option 2 applies, with the notice period in Section 5.2; the optional wording in Clause 11 does not apply; the competent supervisory authority is determined under Clause 13; under Clause 17, Option 1 applies, and the governing law is that of Ireland; and under Clause 18, the courts of Ireland have jurisdiction. Annex I of the SCCs is completed by Annex 1, Annex II by Annex 2, and Annex III by the list of Sub-processors provided under Annex 3.

6.3 For transfers subject to the UK GDPR, the SCCs apply as amended by the International Data Transfer Addendum issued by the UK Information Commissioner (version B1.0). For transfers subject to the FADP, references to the GDPR are read as references to the FADP, and the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner.

6.4 Where Finero transfers Customer Personal Data to a Sub-processor, it ensures an appropriate safeguard under Data Protection Laws, such as an adequacy decision (including the EU-US Data Privacy Framework) or Module Three (processor to processor) of the SCCs.

6.5 If the SCCs conflict with this DPA, the SCCs prevail.

7. Assistance

7.1 Taking into account the nature of the processing, Finero assists Customer by appropriate technical and organisational measures, insofar as possible, in responding to requests from data subjects exercising their rights. Finero promptly forwards to Customer any such request it receives and does not respond to it except on Customer’s instructions.

7.2 Taking into account the nature of the processing and the information available to Finero, Finero assists Customer in ensuring compliance with its obligations under Articles 32 to 36 GDPR.

8. Personal data breaches

8.1 Finero notifies Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.

8.2 The notice includes, to the extent then known, the information listed in Article 33(3) GDPR. Where not all of it is available at once, Finero provides it in phases without undue further delay.

8.3 Finero takes reasonable steps to contain, investigate and mitigate the effects of the breach, and keeps Customer informed.

8.4 Notification of a breach is not an acknowledgement of fault or liability.

9. Deletion and return

On termination or expiry of the Agreement, Finero, at Customer’s choice, returns Customer Personal Data in a commonly used, machine-readable format or deletes it, within 30 days, and deletes existing copies, unless Union or Member State law requires their storage. Copies in backups are deleted in the ordinary course of the backup cycle and remain protected by this DPA until then. On request, Finero confirms the deletion in writing.

10. Audits

10.1 Finero makes available to Customer all information necessary to demonstrate compliance with Article 28 GDPR, including written responses to reasonable security questionnaires, and allows for and contributes to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer.

10.2 Customer will first seek to meet its audit needs through the information provided under Section 10.1. Any inspection requires at least 30 days’ written notice, takes place during business hours no more than once in any 12-month period (unless following a personal data breach or required by a supervisory authority), is subject to appropriate confidentiality obligations, must not compromise the security of the Service or the data of Finero’s other customers, and is at Customer’s cost.

11. US state privacy laws

To the extent US state privacy laws apply to Customer Personal Data, Finero acts as Customer’s service provider or processor and will not: (a) sell or share Customer Personal Data; (b) retain, use or disclose it for any purpose other than providing the Service, or outside the direct business relationship between the parties; or (c) combine it with personal data received from other sources, except as those laws permit. Finero certifies that it understands and will comply with these restrictions, and will notify Customer if it can no longer meet them.

12. General

12.1 Finero’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability in the Agreement, including the single aggregate cap in section 18 of the Terms of Use, which applies to all claims against Finero under this DPA and the rest of the Agreement taken together. This DPA creates no separate or additional cap. Nothing in the Agreement limits liability to data subjects or supervisory authorities, or liability that Data Protection Laws or the SCCs do not permit to be limited.

12.2 In the event of conflict, the SCCs prevail over this DPA, and this DPA prevails over the rest of the Agreement on matters of personal data protection.

12.3 This DPA remains in force for as long as Finero processes Customer Personal Data.

12.4 This DPA is governed by the law that governs the Agreement, except that the SCCs are governed as set out in Section 6.2.

12.5 Notices under this DPA are given by email: to Finero at privacy@getfinero.com, and to Customer at the email address of an administrator of its workspace. Either party may change its address by notice to the other.

Annex 1: Details of processing

Annex 2: Technical and organisational measures

Annex 3: Sub-processors

Finero provides the current list of Sub-processors, with the purpose and location of each, to Customer on request at privacy@getfinero.com.