FinHub Data Processing Appendix
Overview
The DPA serves as an integral part of the FinHub Customer Agreement, concluded between FinHub's respective contracting party (the "Processor") and the Client (the "Controller").
1. Scope
1.1 Controller
Any legal or natural person, alone or joined with others, that determines the purposes of any personal data and the means of processing it. The Client holds this role.
1.2 Processor
Any legal or natural person who processes personal data on behalf of a data controller. FinHub functions as Processor for the Client.
1.3 Applicable laws
References any effective national or international legal act, including the GDPR, regulating data processing activities.
1.4 FinHub as Controller — exception
FinHub acts independently as Controller regarding KYC, CDD checks, regulatory compliance, and fraud prevention — the DPA provisions don't apply to this usage.
1.5 Processor — permitted processing
The Processor may process the Client's personal data for:
- Service provision under the concluded agreements
- Processing required under applicable national and international laws
- Transfers to payment processors and banking partners per the Client's instructions
- Compliance with Client-provided instructions
2. Data Processing Purpose and Duration
2.1 Processing purpose
"The Processor undertakes to process the personal data with the purpose of fulfilling its obligations under this DPA and the other agreements."
2.2 Compatible purpose requirement
Processing operations cannot serve purposes incompatible with the purpose for which the personal data was initially collected.
2.3 Mandatory processing
The Parties acknowledge that processing operations are mandatory for the Controller in order to ensure the proper performance of the DPA.
2.4 Duration limitation
The Processor has the right to process the personal data for no longer than the agreements for the respective services are valid, including any transitional period. Upon termination, the Processor will cease the personal data processing.
2.5 Employee compliance
The Processor must ensure that all employees, or other individuals involved by the Processor in processing the personal data, are familiar with and comply with the provisions of this DPA.
3. Processor's Obligations and Warranties
3.1 Written instruction requirement
The Processor will process personal data only based on written instructions (including in electronic format) transferred by the Controller. Initial instructions appear in Schedule 1 and Schedule 2. The Processor must immediately inform the Controller if, in its opinion, an instruction of the Controller infringes data protection regulations.
3.2 Legal compliance
The Processor will ensure compliance with the obligations applicable to it under the laws governing personal data protection, and will implement mandatory legislative changes.
3.3 Rights implementation
The Processor will help the Controller implement the obligations arising from laws governing personal data protection, including the Controller's obligation to give effect to the rights of data subjects to access, alter, erase, or suspend the processing of personal data.
3.4 Non-circumvention obligation
The Processor shall refrain from actions which would force the Controller to act against the requirements laid down in the laws governing personal data protection.
3.5 Non-disclosure commitment
The Processor will not transfer or otherwise disclose personal data, or any other information related to its processing, to any third party except its authorised employees, consultants, and sub-processors. The Processor must provide notice when legally required to disclose data.
3.6 Information access
Upon the Controller's request, the Processor will provide all information on the personal data processed on the Controller's behalf, including the exact location of personal data storage.
3.7 Storage location notice
The Processor will notify the Controller, with a reasonable notice period, each time the location of personal data storage is expected to change.
3.8 Data protection impact assessment
The Controller has the right to carry out a data protection impact assessment to evaluate the measures envisaged by the Processor. The Processor must cooperate and provide existing assessment information.
3.9 Warranties and undertakings
3.9.1 Technical and organizational measures
The Processor will have in place appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorised disclosure, or access.
3.9.2 Contact person and cooperation
The Processor will appoint and make available to the Controller a contact person within its organisation, authorised to respond to enquiries concerning the processing of personal data.
3.9.3 Audit and review rights
Upon the Controller's reasonable request, the Processor will make available its data processing facilities, data files, and documentation needed for processing, for reviewing, auditing, and/or certifying by the Controller.
4. Controller's Obligations, Representations and Warranties
4.1 Data lawfulness
The Controller warrants and will ensure that, during the entire validity term of the agreements for the provision of services, all personal data transferred to the Processor is processed on a lawful basis, is accurate and complete, and does not infringe upon the rights of data subjects.
5. Sub-processor
5.1 Material subcontractor status
Any sub-processor for the processing of personal data transferred by the Controller will be considered a material subcontractor. Prior to engaging a new sub-processor or replacing an existing one, the relevant procedure for material subcontractors must be followed.
5.2 Audit rights
The Controller will have the right to request the Processor to perform an audit of the respective sub-processor, or to obtain confirmation that such an audit was performed.
5.3 Sub-processor obligations
The Processor will ensure that all sub-processors approved by the Controller undertake, in writing, to follow the laws governing personal data protection and the rules established in this DPA.
6. Transfers of Personal Data to Third Countries
6.1 Prior consent required
The Processor will not, without the prior written consent of the Controller, transfer personal data outside the European Economic Area (the EEA).
6.2 Standard contractual clauses
Upon consent, the Processor will prioritise sending data only with the application of the standard contractual clauses approved by the European Commission. Alternative arrangements may apply for jurisdictions with adequate protection or binding corporate rules.
The Controller has the right to withdraw consent regarding the transfer of personal data to third countries for a reasonable reason. In this case, the Processor will immediately stop the transfer.
7. Information Security and Confidentiality
7.1 Appropriate security measures
The Processor will take appropriate technical and organisational measures to ensure the security of processed personal data, considering the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.
7.2 Specific security measures
- Locked premises containing hardware and portable storage devices
- An established process for testing personal data restoration
- Access restrictions — user codes and passwords are unique and not accessible to unauthorised staff
- Encryption of external transfer channels when applicable
- An established process for the safe destruction of equipment
7.3 Breach mitigation
The Processor will take all actions to help the Controller mitigate the adverse effects of a data security breach, and will immediately notify the Controller of any incidents.
7.4 Breach notification requirements
The Processor will immediately, and in any case within 24 hours of becoming aware, notify the Controller of any incident related to personal data. Notification must include the nature of the breach, affected data categories, time of breach, likely consequences, and remedial steps taken.
7.5 Employee access control
Access to personal data will be granted only to employees of the Processor who need access to perform the Processor's obligations.
7.6 Cooperation on breaches
In the event of a data security breach, the Parties will put in their best effort, cooperate with each other, and provide all necessary information and data.
7.7 Data storage location
Personal data is stored at the Service Provider's data centres located at 63 Shipchenski prohod blvd., 1000 Sofia, Bulgaria, and 79 Madarski konnik str., 9930 Kaspichan, Republic of Bulgaria (European Union).
7.8 Optional persistent storage function
The Processor offers an optional "Persistent Lawyer Personal Data Storage Free Function" enabling platform users to independently store personal data for extended periods in line with their legal obligations. This function is available only for designated platform modules, remains under the platform user's responsibility for management and retention, receives appropriate security measures but no active monitoring, and carries no liability for the Processor regarding the platform user's usage decisions.
8. Expiration of the Data Processing Appendix
8.1 Application scope
The DPA applies whenever the Processor processes personal data on behalf of the Controller.
8.2 Termination right
The Controller will be entitled to immediately terminate the validity of the concluded agreements and the DPA, and to prohibit the Processor from further processing personal data, where the Processor fails to fulfil the obligations established in the DPA.
9. Measures Upon Completion of Personal Data Processing
9.1 Return or destruction
After the expiry of the concluded agreements and/or the DPA, the Processor shall — at the Controller's discretion, notified to the Processor in writing — return or destroy personal data received from the Controller.
9.2 Confirmation of termination
At the Controller's request, the Processor will provide a list of measures taken to ensure appropriate termination.
10. Liability
10.1 Non-compliance remedy period
Following confirmation of the Processor's or sub-processor's failure to comply with the provisions of this DPA, the Controller will grant the Processor the right to fully remedy the infringement within 30 calendar days. Failure to remediate permits termination without notice.
10.2 Controller status consequence
If the Processor infringes the General Data Protection Regulation by determining the purposes and means of processing, the Processor will be a controller in respect of that processing.
10.3 Non-diminishing effect
No clause of this DPA will in any way be considered as reducing the obligations applicable to the Processor under the laws governing personal data protection.
Schedule 1 — Personal Data Processing Details (GDPR Article 28(3))
1. Personal data definition
Personal data has the meaning given to it in the General Data Protection Regulation and includes the categories of personal data set forth in this DPA, Schedule 1, and Schedule 2.
2. Processing purposes
Personal data will be processed for the purpose of providing services under the concluded agreements, and otherwise to fulfil the obligations under those agreements.
3. Data subject categories
- Past, current, and future/potential customers/end-users of the Client
- Past and current natural persons related to the Client's customers/end-users, including legal representatives
- Other natural persons involved in transactions with the Client's customers/end-users
- Past and current employees and other representatives of the Client
4. Processed personal data
For Client employees and representatives
- Identification data — full name, surname, position
- Contact data — email address, telephone number
- Technology identifiers and access data — login details, usernames, email, password data, IP address, MAC address
- Action history and activities — technical server logs, Client support correspondence, Client-elected submission data
- System rights assignment — roles, permissions
For other categories (detailed in Schedule 2): FinHub does not intentionally process any sensitive personal data (including special categories of personal data) unless the Client or its customers/end-users, in their sole discretion, include such data.
5. Nature of data processing
Processing involves collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
6. Processing duration
The duration is during the validity of the concluded agreements, or until deletion of all the Client's data by FinHub under this DPA.
Production environment logs: FinHub, acting as Processor on behalf of the Client and under the Client's instructions and direction, will store the Client's production environment logs for 10 (ten) years after collection, as determined at the Client's sole discretion.
Schedule 2 — Personal Data Categories (excluding Client employees/representatives)
FinHub may process the following categories of personal data:
Identification information
- Given name, middle name, surname
- Personal ID (personal code or other personal identification code)
- Nationality
- Country that issued the ID document or personal identification code
- Date of birth, city of birth, country of birth
- District / province (county) of birth
- Document number, document type
- Country of tax residence
- Taxpayer identification number
- Company name (when consisting of a natural person's name/surname)
- Company code, company code issuer
- ID document issuer
- Client ID, Client ID (Company)
Address information
- Address, country, county, city, street, flat, postcode
Contact information
- Mobile phone number, email
Financial information
- IBAN / account number, bank BIC
Transaction information
- Transaction purpose, transaction amount
Administrative information
- Member codes
- Enforcement order number (case number for bailiffs)
- Restriction document date
Activity data
- Technical server logs
- Correspondence with Client support
- Files the Client elects to send to FinHub for processing