Data Processing Addendum
This Data Processing Addendum supplements our Terms of Service and Privacy Policy. It establishes the technical and organizational measures governing data processing on behalf of FinanceAI users.
Data Controller
You (the user) are the Data Controller. You determine the purpose and means of processing personal data within your ledgers.
Data Processor
FinanceAI acts as the Data Processor. We process your financial telemetry strictly on your documented instructions.
Legal Basis
Processing is governed by GDPR Article 28 (Controller-Processor agreements) and applicable SCCs for international transfers.
01 Scope of Processing
FinanceAI processes personal data and financial telemetry solely on behalf of the Data Controller for the following authorized purposes:
- Operating the cryptographic ledgers (income, expense, and capital flow tracking)
- Executing AI heuristic forecasting and predictive burn-rate analysis
- Generating automated financial reports and PDF audit documents
- Providing customer support and resolving technical inquiries
- Ensuring platform security through anomaly detection and access logging
02 Sub-Processor Disclosure
FinanceAI engages vetted sub-processors to deliver specific infrastructure services. All sub-processors are contractually bound to data protection standards equivalent to this DPA.
| Sub-Processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud Infrastructure & Compute | US / EU / AP |
| Google Cloud (Gemini API) | AI Inference Engine | US |
| Stripe Inc. | Payment Processing | US / EU |
| Mailgun (Sinch) | Transactional Email Routing | EU |
03 Technical & Organizational Measures (TOMs)
FinanceAI implements the following security controls to protect data integrity and confidentiality:
Encryption
AES-256 at rest, TLS 1.3 in transit. Zero-knowledge key management.
Access Control
Role-based IAM with principle of least privilege. MFA enforced for operators.
Availability
99.99% uptime SLA. Multi-AZ redundancy. Automated failover.
Audit Logging
Immutable audit trails via Spatie Activity Log. 12-month retention.
04 Data Breach Notification Protocol
In the event of a confirmed data breach affecting personal data, FinanceAI will:
- Within 48 hours — Notify the Data Controller via any registered email addresses.
- Within 72 hours — Deliver a preliminary incident report detailing nature, scope, and containment actions.
- Within 30 days — Provide a full post-mortem with root cause, remediation, and preventive measures.
05 Data Returns & Deletion
Upon termination of services, FinanceAI will, at the Data Controller's election, either (a) return all personal data via a structured export (JSON/CSV), or (b) cryptographically shred all data within 72 hours, with written certification of destruction. No recoverable backups containing personal data will exist beyond 30 calendar days post-deletion-request.