Data Processing Agreement
Article 1. Scope of processing
1.1. Provider (“Processor”) may process personal data on behalf of Subscriber (“Controller”) as necessary for the performance of the services under the Agreement and in accordance with this DPA. The processing will cover the elements set out in the annex to this DPA. The Agreement constitutes the Controller’s complete instructions regarding the processing of personal data. Any additional or alternative instructions shall require the prior written agreement of both Parties and shall be reasonable. The Processor shall be entitled to suspend execution of any instruction that it believes infringes applicable law.
Article 2. Obligations of the Parties
2.1. The Controller shall (a) comply with applicable law in processing personal data under this DPA, (b) be solely responsible for determining the purposes and means of the processing of personal data and, where required, obtaining any necessary consents or authorizations from data subjects or third parties, (c) ensure that personal data provided to the Processor is accurate, complete, up to date and adequate for the intended processing, and promptly notify the Processor of any relevant changes or inaccuracies, and (d) implement and maintain appropriate technical and organizational measures for the protection of personal data in respect of all components, systems and credentials under its control.
2.2. The Processor shall (a) process personal data only on documented instructions from the Controller, unless required to do otherwise by applicable law, (b) ensure that persons authorized to process personal data are subject to confidentiality obligations under contract, policy, or law, (c) implement and maintain technical and organizational measures as set out in 6.4, (d) provide reasonable assistance to the Controller as set out in Article 3 in fulfilling the Controller’s obligations under applicable law, and (e) make available information as set out in Article 8.
Article 3. Assistance to the Controller
3.1. The Controller shall be solely responsible for enabling data subjects to exercise their rights under applicable law. If a data subject contacts the Processor directly, the Processor shall inform the Controller of the request and redirect the data subject to the Controller. The Processor shall not be required to take further action unless agreed in writing, but shall provide reasonable cooperation insofar as this is possible and taking into account the nature of the processing and the information available to the Processor.
3.2. The Processor shall provide reasonable assistance to the Controller, insofar as reasonably possible and taking into account the nature of the processing and the information available to the Processor, with data protection impact assessments and consultations with competent authorities that are required under applicable law, subject always to reimbursement of the Processor’s reasonable costs.
3.3. Unless prohibited under applicable law, the Processor shall inform the Controller without undue delay if it or any sub-processor: (a) receives an inquiry, subpoena, or audit demand from a competent authority relating to the services; or (b) receives an instruction that the Processor believes infringes applicable law. The Processor shall provide such cooperation as is reasonably required, taking into account the nature of the processing and the information available to the Processor, to enable the Controller to comply with its statutory obligations, subject always to reimbursement of the Processor’s reasonable costs, except where the relevant request results directly from a fault of the Processor.
Article 4. Disclosure
4.1. The Processor shall not disclose personal data to any third party or public authority except: (a) on the documented instructions of the Controller; (b) to authorized sub-processors in accordance with Article 5; or (c) where required by applicable law.
4.2. The Processor shall ensure that any person acting under its authority who has access to personal data: (a) is bound by appropriate confidentiality obligations under contract, policy, or law; and (b) accesses personal data only where necessary for the performance of their duties.
Article 5. Use of sub-processors
5.1. The Controller acknowledges and agrees to the sub-processors listed at [Support Hub | Finticx]. The Processor may engage additional or replacement sub-processors to support the provision of the services, provided that the Processor informs the Controller. The Controller may object to a new sub-processor on reasonable grounds based on compliance with applicable law by providing notice within 30 days of receiving the Processor’s information. If the Controller does not object within that period, the sub-processor shall be deemed approved. If the Controller does object, the Processor will use reasonable efforts to make available a reasonable alternative. If no alternative is available, either Party may terminate the affected services by notice.
5.2. The Processor shall ensure that each sub-processor is bound by written obligations providing a level of protection for personal data not less than that required under applicable law. The Processor shall use reasonable efforts to ensure compliance by its sub-processors.
5.3. The Processor shall make available to the Controller an up-to-date list of contracted sub-processors, either upon written request or by publication on a designated website.
Article 6. Location of processing
6.1. The Processor may process and store personal data within the EEA and, where required for the provision of the services, in other jurisdictions, provided that such processing complies with applicable law.
6.2. Where the processing of personal data involves a transfer outside the EEA, the Processor shall rely on an appropriate transfer mechanism recognized under applicable law and shall inform the Controller thereof. The Controller shall be deemed to have approved such transfers provided a valid mechanism is in place. The Controller remains solely responsible for determining whether any transfer impact assessment or supplementary measures are required in connection with such transfer. The Processor shall provide reasonable cooperation and assistance in this regard. The Processor shall not be responsible for the sufficiency of any transfer mechanism mandated under applicable law.
6.3. If the Processor becomes aware that a transfer mechanism relied upon is no longer valid or effective, it shall inform the Controller. The Processor may continue the relevant transfer as long as permitted under applicable law and shall not be obliged to suspend processing unless and until the Controller provides alternative lawful instructions.
Article 7. Technical and organizational measures
7.1. The Processor shall implement and maintain appropriate technical and organizational measures (TOMs) designed to protect personal data against accidental, unauthorized or unlawful access, disclosure, loss, or destruction, taking into account the state of the art, the costs of implementation, and the nature, scope, and purposes of processing. Such TOMs may include, where appropriate, encryption, access controls, and recovery procedures, and regular testing.
7.2. Upon receiving notice from the Controller, the Processor shall, within a reasonable period, provide a general description of its TOMs sufficient to demonstrate compliance with applicable law. The Processor may fulfill this obligation by providing relevant third-party certifications, audit reports, or equivalent documentation. Adherence to an approved code of conduct under article 40 GDPR or an approved certification mechanism under article 42 GDPR may also serve as evidence of sufficient guarantees. Any cooperation beyond the scope of this Article 6 shall remain subject to confidentiality and security restrictions and to reimbursement of the Processor’s reasonable costs.
Article 8. Personal data breaches
8.1. In the event of a personal data breach, the Processor shall inform the Controller without undue delay and in any event within 48 hours of becoming aware. At such time, the Processor shall communicate the information then available to it. The Processor shall inform the Controller as further information is obtained, and shall cooperate with the Controller to investigate the personal data breach, take appropriate steps to mitigate its adverse effects, and assist with any notifications to competent authorities or data subjects as required by applicable law.
Article 9. Audit rights
9.1. The Processor shall make available to the Controller, upon written request, information reasonably necessary to demonstrate compliance with this DPA. Where available, the Processor may satisfy this obligation by providing up-to-date third-party audit or certification reports, which the Controller agrees shall be sufficient to discharge this obligation.
9.2. The Controller may carry out an audit where the information provided under 8.1 is not reasonably sufficient to demonstrate compliance. Any such audit shall: (a) be conducted no more than once in any 12-month period; (b) be subject to at least 30 days’ prior notice; (c) take place during normal business hours; and (d) be strictly limited to documents relevant to the processing of personal data under this DPA.
9.3. Each Party shall bear its own costs in connection with any audit. Any additional cooperation or resources required from the Processor beyond providing existing information or reports shall be subject to reimbursement of the Processor’s reasonable costs.
Article 10. Deletion and return of personal data
10.1. The Processor shall retain personal data only for as long as necessary to perform the services or as required by applicable law. Upon expiry or termination of the Agreement, the Processor shall, at the Controller’s choice and within a reasonable period and subject to its technical capabilities: (a) make available for download to the Controller a copy of the personal data in a commonly used format; or (b) securely delete the personal data, except to the extent retention is required by applicable law. Where applicable law requires continued storage, the Processor shall notify the Controller (unless legally prohibited) and shall ensure such personal data is kept securely and not processed for other purposes.
10.2. Any additional data export, migration, or assistance requested by the Controller shall be subject to the Processor’s standard professional services terms and the reimbursement of its reasonable costs.