This Data Processing Addendum ("DPA") forms part of the agreement between Finansist AI, Inc. ("Finansist AI", "Company", "Processor") and the customer entity identified in the applicable order form or terms of use ("Customer", "Controller"). It governs the processing of Personal Data by Finansist AI on behalf of the Customer in connection with the Finansist AI platform and services (the "Service").
This DPA is incorporated by reference into the Terms of Use and the Privacy Policy. In the event of a conflict between this DPA and those documents, this DPA shall prevail with respect to data protection matters.
Definitions
Subject Matter, Duration, Nature, and Purpose of Processing
Subject matter: Finansist AI processes Personal Data submitted by the Customer through the Service, including financial records, invoice data, ERP exports, email content, supplier and employee contact details, and other business data that may contain Personal Data.
Duration: Finansist AI processes Personal Data for the duration of the Customer's active subscription to the Service and for any additional period required to comply with legal obligations or exercise legitimate interests, as described in the Privacy Policy and Section 8 of this DPA.
Nature and purpose of processing: Personal Data is processed by Finansist AI for the purpose of providing the Service, which includes AI-based reconciliation, invoice detection, financial analysis, supplier communication assistance, and related automation functions. Processing is carried out solely on the Customer's instructions as set out in this DPA and the applicable Terms of Use, and not for Finansist AI's own independent purposes.
Categories of Personal Data Processed
Depending on how the Customer uses the Service, Finansist AI may process the following categories of Personal Data:
- Contact and identity data: names, email addresses, job titles, and telephone numbers of the Customer's employees, authorized users, suppliers, counterparties, and other individuals whose information is submitted to the Service.
- Financial and transactional data: invoice amounts, payment references, bank account identifiers, transaction descriptions, and related financial records that may identify natural persons.
- Business correspondence: email content and attachments submitted to or processed through the Service that contain references to natural persons.
- Account and access data: usernames, login credentials (in hashed form), and access logs relating to authorized users of the Customer's account.
- ERP and system data: records exported from the Customer's ERP, accounting, or cloud systems that may contain personal identifiers.
Categories of Data Subjects
Personal Data processed under this DPA may relate to the following categories of data subjects:
- The Customer's employees and authorized users accessing the Service;
- The Customer's suppliers, vendors, and service providers whose contact details and invoices are submitted to the Service;
- The Customer's customers and counterparties whose information appears in financial records or correspondence processed through the Service;
- Other individuals whose Personal Data is incidentally included in documents or data submitted by the Customer.
Obligations and Rights of the Controller
The Customer, as Controller, is responsible for:
- ensuring it has a valid lawful basis under Applicable Data Protection Law for providing Personal Data to Finansist AI and for authorising the processing described in this DPA;
- providing all required notices to data subjects and obtaining all necessary consents, authorisations, and permissions prior to submitting Personal Data to the Service;
- ensuring that all Personal Data submitted to the Service is accurate, lawfully obtained, and processed in compliance with Applicable Data Protection Law;
- configuring user access permissions and ensuring that only authorised personnel access the Service;
- exercising its rights under this DPA, including issuing documented instructions to Finansist AI regarding the processing of Personal Data.
Obligations of the Processor
Finansist AI, as Processor, shall:
- process Personal Data only on the documented instructions of the Customer as set out in this DPA and the Terms of Use, and not for any other purpose, unless required to do so by applicable law;
- ensure that persons authorised to process Personal Data are subject to appropriate confidentiality obligations;
- implement the technical and organisational security measures described in Section 7 of this DPA;
- assist the Customer, taking into account the nature of processing, in responding to requests from data subjects exercising their rights under Applicable Data Protection Law;
- assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR, including security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the information available to Finansist AI;
- at the Customer's choice, delete or return all Personal Data to the Customer upon termination of the Service, and delete existing copies unless applicable law requires otherwise;
- make available to the Customer all information necessary to demonstrate compliance with the obligations in this DPA, and allow for and contribute to audits conducted by the Customer or a mandated auditor, subject to reasonable notice and confidentiality obligations.
Finansist AI shall promptly inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.
Security Measures
Finansist AI implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk presented by the processing, taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing. These measures include:
- Encryption: Personal Data is encrypted in transit using TLS and encrypted at rest using industry-standard encryption algorithms.
- Access controls: access to Personal Data is restricted to authorised personnel on a need-to-know basis, enforced through role-based access controls and authentication requirements.
- Infrastructure security: the Service is hosted on cloud infrastructure with physical and logical security controls, including network segmentation, firewalls, and intrusion detection.
- Monitoring and logging: security events, access logs, and system activity are monitored and logged to detect and respond to anomalies and incidents.
- Backups and recovery: encrypted backups are maintained to support data recovery in the event of a system failure or incident, with retention as described in the Privacy Policy.
- Vendor security assessments: Subprocessors are evaluated for their security practices prior to engagement.
- Employee training: personnel with access to Personal Data receive training on data protection and security requirements.
Data Retention and Deletion
Finansist AI retains Personal Data for the duration of the Customer's subscription and for any additional period required by applicable law or as described in the Privacy Policy. Upon termination or expiry of the Service:
- Finansist AI will provide the Customer with access to Personal Data stored within the Service for a period of up to two (2) months from the date of termination, for the purpose of export and retrieval.
- After that period, Finansist AI will delete Personal Data from its live systems, subject to applicable legal retention requirements, backup cycles, security obligations, and any outstanding disputes.
- Encrypted backups are retained on a rolling basis of up to 90 days and are purged automatically thereafter.
- Certain categories of data, such as billing records and audit logs, may be retained for longer periods as required by applicable law.
Upon the Customer's written request, Finansist AI will provide confirmation of deletion where technically practicable.
Subprocessors
The Customer grants Finansist AI a general written authorisation to engage Subprocessors to assist in providing the Service. Finansist AI shall ensure that any Subprocessor is bound by data protection obligations no less protective than those set out in this DPA.
Finansist AI's current list of Subprocessors includes the following categories of providers:
- Cloud infrastructure and hosting: providers of computing, storage, and networking infrastructure on which the Service operates.
- AI and machine learning infrastructure: third-party AI service providers used to deliver reconciliation, invoice detection, financial analysis, and communication features. Such providers may process Personal Data in accordance with their own terms and data processing agreements.
- Email delivery: providers used to send transactional and operational email communications on behalf of the Service.
- Analytics and monitoring: providers used for system performance monitoring, error tracking, and usage analytics, operating on anonymized or aggregated data where possible.
- Payment processing: providers used to process subscription fees and billing transactions.
Finansist AI will notify the Customer of any intended addition or replacement of a Subprocessor by email to the address on file at least 30 days before the change takes effect. If the Customer reasonably objects to a new Subprocessor on legitimate data protection grounds, the Customer may notify Finansist AI in writing within 14 days of receiving such notice. The parties will work in good faith to resolve the objection; if the parties are unable to resolve the objection, either party may terminate the relevant portion of the Service on reasonable notice.
International Data Transfers
The Service is operated from Israel, which has been recognized by the European Commission as providing an adequate level of data protection for Personal Data transferred from the European Economic Area.
Where Personal Data is transferred to Subprocessors located in countries or jurisdictions outside Israel or the EEA that do not benefit from an adequacy decision, Finansist AI implements appropriate safeguards, including standard contractual clauses (SCCs) issued by the European Commission or other transfer mechanisms recognized under Applicable Data Protection Law.
The Customer may request information about the transfer mechanisms applicable to specific Subprocessors by contacting Finansist AI at [email protected].
Data Subject Rights
Finansist AI will assist the Customer in fulfilling its obligations to respond to requests from data subjects seeking to exercise their rights under Applicable Data Protection Law, including rights of access, rectification, erasure, restriction, portability, and objection.
Where Finansist AI receives a data subject request directly that relates to Personal Data processed on behalf of the Customer, Finansist AI will promptly notify the Customer and will not respond to the request without the Customer's documented instructions, unless required to do so by applicable law.
The Customer is responsible for maintaining records of data subject requests and for ensuring timely responses within the timeframes required by Applicable Data Protection Law.
Data Breach Notification
Finansist AI will notify the Customer without undue delay, and in any event within 72 hours of becoming aware, of any Personal Data breach affecting Personal Data processed under this DPA, to the extent that notification within that timeframe is reasonably practicable.
Such notification will include, to the extent available at the time:
- a description of the nature of the breach, including the categories and approximate number of data subjects and Personal Data records affected;
- the contact details of Finansist AI's data protection point of contact;
- a description of the likely consequences of the breach;
- a description of the measures taken or proposed to address the breach and mitigate its effects.
Finansist AI will cooperate with the Customer and provide reasonable assistance in making any required notifications to supervisory authorities or affected data subjects.
Data Protection Impact Assessments
Where the Customer is required to conduct a data protection impact assessment (DPIA) in connection with the processing described in this DPA, Finansist AI will provide reasonable assistance by making available information about its processing activities, security measures, and Subprocessors, taking into account the nature of the processing and the information available to Finansist AI.
Records of Processing
Finansist AI maintains records of processing activities carried out on behalf of the Customer, as required by Article 30(2) of the GDPR and equivalent provisions under Applicable Data Protection Law. These records include the categories of processing described in this DPA and are available upon request to the extent required by law.
Audit Rights
Upon the Customer's written request, and no more than once per calendar year unless there are reasonable grounds to believe a breach has occurred, Finansist AI will:
- make available to the Customer or its appointed auditor information reasonably necessary to demonstrate compliance with this DPA;
- allow the Customer or its appointed auditor to conduct an audit or inspection of Finansist AI's data processing practices, subject to at least 30 days' advance written notice, agreement on the scope and format of the audit, execution of a confidentiality agreement, and reimbursement of Finansist AI's reasonable costs.
The parties acknowledge that third-party audit reports or certifications held by Finansist AI may be used to satisfy audit obligations where the Customer determines they are adequate.
Governing Law and Disputes
This DPA shall be governed by and construed in accordance with the laws applicable to the agreement between the parties, as set out in the Terms of Use. Any disputes arising under this DPA shall be resolved in accordance with the dispute resolution provisions of the Terms of Use.
Nothing in this DPA limits the rights of data subjects or supervisory authorities under Applicable Data Protection Law.
Contact
For questions, requests, or notices relating to this DPA, data subject rights, or Finansist AI's data processing practices, please contact:
Finansist AI, Inc. - Data Protection