Data Processing Addendum

This Finrep Data Processing Addendum ("DPA") governs how Finrep Inc., a Delaware corporation ("Finrep"), processes Customer Data to provide the Services. It applies under the Finrep Terms of Service, an Order Form, or any other agreement between you ("Customer") and Finrep for the Services (the "Agreement").

This DPA forms part of the Agreement and applies automatically; no separate signature is needed. If this DPA conflicts with the Agreement, the Terms of Service, the Privacy Policy or an Order Form, this DPA controls.

Effective date: 1 January 2026. Last updated: 20 August 2026.

1. Definitions

  • Customer Data: all data Customer or its users submit to the Services, or that the Services generate for them. This includes prompts, uploaded documents, files, chat history and Outputs, and any personal data in them.
  • Outputs: any content the Services generate in response to Customer Data.
  • Sub-processor: any third party Finrep engages that processes Customer Data.
  • Security Incident: a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Data.

2. Roles

2.1 Customer is the controller of Customer Data. Finrep is a processor and acts only on Customer's instructions. The Agreement, this DPA and Customer's use of the Services are those instructions.

2.2 Finrep acts as an independent controller only for account information (such as user names and business emails) and for Service Operation Data (clause 4.5), as described in the Finrep Privacy Policy.

3. Ownership

3.1 Customer Data and Outputs remain the property of Customer and its clients. Finrep gains no rights in them beyond the limited licence needed to provide the Services.

3.2 Finrep keeps ownership of the Services, its software, models, system prompts and know-how. This does not include any Customer Data or Outputs.

4. Restrictions on use, including AI

4.1 Finrep will process Customer Data only to provide, secure and support the Services for Customer.

4.2 Finrep will not use Customer Data or Outputs, and will not allow any Sub-processor to use them, to train or fine-tune any AI or machine-learning model.

4.3 Finrep will not use Customer Data or Outputs for product improvement or benchmarking.

4.4 Finrep uses each AI provider listed in Annex 2 under a zero-data-retention arrangement. Under it, the provider does not store prompts or outputs after the request completes and does not use them for training.

4.5 Clauses 4.1 to 4.4 do not prevent Finrep from using Service Operation Data. That means system logs, performance metrics, error counts, usage volumes and billing records that contain no Customer Data content. Finrep uses Service Operation Data only to operate, secure, monitor and bill for the Services.

4.6 Finrep will not sell Customer Data.

5. Confidentiality and security

5.1 Finrep will treat Customer Data as Customer's confidential information. Access is limited to personnel who need it to provide or support the Services, and each is bound by confidentiality obligations.

5.2 Finrep will maintain the security measures in Annex 1. Finrep holds a SOC 2 Type II report and ISO/IEC 27001:2022 certification, and will share current copies with Customer under NDA on request.

6. Sub-processors

6.1 Customer authorises the Sub-processors listed in Annex 2.

6.2 Finrep will give Customer at least 30 days' notice by email before adding or replacing a Sub-processor. Customer may object on reasonable data-protection grounds within that period, and the parties will work in good faith to resolve the objection.

6.3 Finrep will bind each Sub-processor to written data-protection terms, including the restriction in clause 4.2, and remains responsible for its Sub-processors.

7. Data location and transfers

7.1 Finrep hosts and backs up Customer Data in the United States (Google Cloud, us-east1). Hosting in another region may be agreed in an Order Form.

7.2 Finrep will notify Customer in advance before moving the primary hosting location of Customer Data.

7.3 Finrep personnel and the Sub-processors listed in Annex 2 may access or process Customer Data from outside the hosting region where needed to provide the Services.

7.4 Where Customer Data includes personal data from the EU, EEA or UK, the EU Standard Contractual Clauses (Module 2, and Module 3 where Customer acts as a processor) and the UK Addendum apply and are incorporated by reference.

8. Security Incidents

8.1 Finrep will notify Customer without undue delay, and in any event within 48 hours of becoming aware of a Security Incident affecting Customer Data. The first notice may be preliminary, and Finrep will add details as they become known.

8.2 Notice will go to Customer's designated security contact, or to its account administrators if none is designated. It will describe what happened, the data involved, and the steps taken and planned.

8.3 Finrep will not notify Customer's clients about an incident affecting Customer Data without Customer's prior consent, unless the law requires it.

9. Return and deletion

9.1 For 30 days after termination or expiry, Customer may export its Customer Data.

9.2 Finrep will delete all Customer Data from production systems within 30 days after termination or expiry, and from backups within 90 days after termination or expiry.

9.3 Finrep will confirm deletion in writing on request.

9.4 Finrep may keep only what the law requires it to keep. Anything kept stays protected under this DPA and is used for no other purpose.

10. Security reviews

On request, Finrep will provide its current SOC 2 Type II report and ISO 27001 certificate under NDA, and will reasonably answer Customer's security questionnaires.

11. Liability and term

11.1 Liability under this DPA follows the limitations in the Agreement.

11.2 This DPA lasts as long as Finrep processes Customer Data. Clauses 3, 4 and 9 survive termination.

Annex 1: Security measures

  • Encryption: AES-256 at rest. TLS 1.2 or higher in transit; TLS 1.0 and 1.1 are disabled.
  • Hosting: Google Cloud, us-east1, across multiple availability zones.
  • Access control: least-privilege access for personnel, with multi-factor authentication.
  • Tenant isolation: each customer's documents and chats are scoped to its organisation and are not shared across customers.
  • Backups: automated database backups with point-in-time recovery, and versioned object storage, all within the United States.
  • Monitoring: centralised audit logging and alerting on security events.
  • Testing: independent penetration testing.
  • AI gateway: model calls go through a gateway Finrep hosts itself.

Annex 2: Authorised Sub-processors

Sub-processorPurposeLocationData retention
Google Cloud PlatformHosting, storage, backups; Vertex AI modelsUnited StatesZero data retention for AI calls; hosting under the Agreement
CloudflareNetwork edge: TLS termination and DDoS protectionGlobal edge networkTraffic passes through and is not stored
AnthropicAI model (Claude)United StatesZero data retention
OpenAIAI modelUnited StatesZero data retention
Microsoft Azure OpenAIAI modelUnited StatesZero data retention
Amazon Web Services BedrockAI modelUnited StatesZero data retention
VercelAI gatewayUnited StatesZero data retention
CohereSearch result rankingUnited StatesZero data retention