FinHub

FinHub Data Processing Appendix

Overview

The DPA serves as an integral part of the FinHub Customer Agreement, concluded between FinHub's respective contracting party (the "Processor") and the Client (the "Controller").

1. Scope

1.1 Controller

Any legal or natural person, alone or joined with others, that determines the purposes of any personal data and the means of processing it. The Client holds this role.

1.2 Processor

Any legal or natural person who processes personal data on behalf of a data controller. FinHub functions as Processor for the Client.

1.3 Applicable laws

References any effective national or international legal act, including the GDPR, regulating data processing activities.

1.4 FinHub as Controller — exception

FinHub acts independently as Controller regarding KYC, CDD checks, regulatory compliance, and fraud prevention — the DPA provisions don't apply to this usage.

1.5 Processor — permitted processing

The Processor may process the Client's personal data for:

  • Service provision under the concluded agreements
  • Processing required under applicable national and international laws
  • Transfers to payment processors and banking partners per the Client's instructions
  • Compliance with Client-provided instructions

2. Data Processing Purpose and Duration

2.1 Processing purpose

"The Processor undertakes to process the personal data with the purpose of fulfilling its obligations under this DPA and the other agreements."

2.2 Compatible purpose requirement

Processing operations cannot serve purposes incompatible with the purpose for which the personal data was initially collected.

2.3 Mandatory processing

The Parties acknowledge that processing operations are mandatory for the Controller in order to ensure the proper performance of the DPA.

2.4 Duration limitation

The Processor has the right to process the personal data for no longer than the agreements for the respective services are valid, including any transitional period. Upon termination, the Processor will cease the personal data processing.

2.5 Employee compliance

The Processor must ensure that all employees, or other individuals involved by the Processor in processing the personal data, are familiar with and comply with the provisions of this DPA.

3. Processor's Obligations and Warranties

3.1 Written instruction requirement

The Processor will process personal data only based on written instructions (including in electronic format) transferred by the Controller. Initial instructions appear in Schedule 1 and Schedule 2. The Processor must immediately inform the Controller if, in its opinion, an instruction of the Controller infringes data protection regulations.

3.2 Legal compliance

The Processor will ensure compliance with the obligations applicable to it under the laws governing personal data protection, and will implement mandatory legislative changes.

3.3 Rights implementation

The Processor will help the Controller implement the obligations arising from laws governing personal data protection, including the Controller's obligation to give effect to the rights of data subjects to access, alter, erase, or suspend the processing of personal data.

3.4 Non-circumvention obligation

The Processor shall refrain from actions which would force the Controller to act against the requirements laid down in the laws governing personal data protection.

3.5 Non-disclosure commitment

The Processor will not transfer or otherwise disclose personal data, or any other information related to its processing, to any third party except its authorised employees, consultants, and sub-processors. The Processor must provide notice when legally required to disclose data.

3.6 Information access

Upon the Controller's request, the Processor will provide all information on the personal data processed on the Controller's behalf, including the exact location of personal data storage.

3.7 Storage location notice

The Processor will notify the Controller, with a reasonable notice period, each time the location of personal data storage is expected to change.

3.8 Data protection impact assessment

The Controller has the right to carry out a data protection impact assessment to evaluate the measures envisaged by the Processor. The Processor must cooperate and provide existing assessment information.

3.9 Warranties and undertakings

3.9.1 Technical and organizational measures

The Processor will have in place appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorised disclosure, or access.

3.9.2 Contact person and cooperation

The Processor will appoint and make available to the Controller a contact person within its organisation, authorised to respond to enquiries concerning the processing of personal data.

3.9.3 Audit and review rights

Upon the Controller's reasonable request, the Processor will make available its data processing facilities, data files, and documentation needed for processing, for reviewing, auditing, and/or certifying by the Controller.

4. Controller's Obligations, Representations and Warranties

4.1 Data lawfulness

The Controller warrants and will ensure that, during the entire validity term of the agreements for the provision of services, all personal data transferred to the Processor is processed on a lawful basis, is accurate and complete, and does not infringe upon the rights of data subjects.

5. Sub-processor

5.1 Material subcontractor status

Any sub-processor for the processing of personal data transferred by the Controller will be considered a material subcontractor. Prior to engaging a new sub-processor or replacing an existing one, the relevant procedure for material subcontractors must be followed.

5.2 Audit rights

The Controller will have the right to request the Processor to perform an audit of the respective sub-processor, or to obtain confirmation that such an audit was performed.

5.3 Sub-processor obligations

The Processor will ensure that all sub-processors approved by the Controller undertake, in writing, to follow the laws governing personal data protection and the rules established in this DPA.

6. Transfers of Personal Data to Third Countries

6.1 Prior consent required

The Processor will not, without the prior written consent of the Controller, transfer personal data outside the European Economic Area (the EEA).

6.2 Standard contractual clauses

Upon consent, the Processor will prioritise sending data only with the application of the standard contractual clauses approved by the European Commission. Alternative arrangements may apply for jurisdictions with adequate protection or binding corporate rules.

The Controller has the right to withdraw consent regarding the transfer of personal data to third countries for a reasonable reason. In this case, the Processor will immediately stop the transfer.

7. Information Security and Confidentiality

7.1 Appropriate security measures

The Processor will take appropriate technical and organisational measures to ensure the security of processed personal data, considering the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.

7.2 Specific security measures

  • Locked premises containing hardware and portable storage devices
  • An established process for testing personal data restoration
  • Access restrictions — user codes and passwords are unique and not accessible to unauthorised staff
  • Encryption of external transfer channels when applicable
  • An established process for the safe destruction of equipment

7.3 Breach mitigation

The Processor will take all actions to help the Controller mitigate the adverse effects of a data security breach, and will immediately notify the Controller of any incidents.

7.4 Breach notification requirements

The Processor will immediately, and in any case within 24 hours of becoming aware, notify the Controller of any incident related to personal data. Notification must include the nature of the breach, affected data categories, time of breach, likely consequences, and remedial steps taken.

7.5 Employee access control

Access to personal data will be granted only to employees of the Processor who need access to perform the Processor's obligations.

7.6 Cooperation on breaches

In the event of a data security breach, the Parties will put in their best effort, cooperate with each other, and provide all necessary information and data.

7.7 Data storage location

Personal data is stored at the Service Provider's data centres located at 63 Shipchenski prohod blvd., 1000 Sofia, Bulgaria, and 79 Madarski konnik str., 9930 Kaspichan, Republic of Bulgaria (European Union).

7.8 Optional persistent storage function

The Processor offers an optional "Persistent Lawyer Personal Data Storage Free Function" enabling platform users to independently store personal data for extended periods in line with their legal obligations. This function is available only for designated platform modules, remains under the platform user's responsibility for management and retention, receives appropriate security measures but no active monitoring, and carries no liability for the Processor regarding the platform user's usage decisions.

8. Expiration of the Data Processing Appendix

8.1 Application scope

The DPA applies whenever the Processor processes personal data on behalf of the Controller.

8.2 Termination right

The Controller will be entitled to immediately terminate the validity of the concluded agreements and the DPA, and to prohibit the Processor from further processing personal data, where the Processor fails to fulfil the obligations established in the DPA.

9. Measures Upon Completion of Personal Data Processing

9.1 Return or destruction

After the expiry of the concluded agreements and/or the DPA, the Processor shall — at the Controller's discretion, notified to the Processor in writing — return or destroy personal data received from the Controller.

9.2 Confirmation of termination

At the Controller's request, the Processor will provide a list of measures taken to ensure appropriate termination.

10. Liability

10.1 Non-compliance remedy period

Following confirmation of the Processor's or sub-processor's failure to comply with the provisions of this DPA, the Controller will grant the Processor the right to fully remedy the infringement within 30 calendar days. Failure to remediate permits termination without notice.

10.2 Controller status consequence

If the Processor infringes the General Data Protection Regulation by determining the purposes and means of processing, the Processor will be a controller in respect of that processing.

10.3 Non-diminishing effect

No clause of this DPA will in any way be considered as reducing the obligations applicable to the Processor under the laws governing personal data protection.

Schedule 1 — Personal Data Processing Details (GDPR Article 28(3))

1. Personal data definition

Personal data has the meaning given to it in the General Data Protection Regulation and includes the categories of personal data set forth in this DPA, Schedule 1, and Schedule 2.

2. Processing purposes

Personal data will be processed for the purpose of providing services under the concluded agreements, and otherwise to fulfil the obligations under those agreements.

3. Data subject categories

  • Past, current, and future/potential customers/end-users of the Client
  • Past and current natural persons related to the Client's customers/end-users, including legal representatives
  • Other natural persons involved in transactions with the Client's customers/end-users
  • Past and current employees and other representatives of the Client

4. Processed personal data

For Client employees and representatives

  • Identification data — full name, surname, position
  • Contact data — email address, telephone number
  • Technology identifiers and access data — login details, usernames, email, password data, IP address, MAC address
  • Action history and activities — technical server logs, Client support correspondence, Client-elected submission data
  • System rights assignment — roles, permissions

For other categories (detailed in Schedule 2): FinHub does not intentionally process any sensitive personal data (including special categories of personal data) unless the Client or its customers/end-users, in their sole discretion, include such data.

5. Nature of data processing

Processing involves collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

6. Processing duration

The duration is during the validity of the concluded agreements, or until deletion of all the Client's data by FinHub under this DPA.

Production environment logs: FinHub, acting as Processor on behalf of the Client and under the Client's instructions and direction, will store the Client's production environment logs for 10 (ten) years after collection, as determined at the Client's sole discretion.

Schedule 2 — Personal Data Categories (excluding Client employees/representatives)

FinHub may process the following categories of personal data:

Identification information

  • Given name, middle name, surname
  • Personal ID (personal code or other personal identification code)
  • Nationality
  • Country that issued the ID document or personal identification code
  • Date of birth, city of birth, country of birth
  • District / province (county) of birth
  • Document number, document type
  • Country of tax residence
  • Taxpayer identification number
  • Company name (when consisting of a natural person's name/surname)
  • Company code, company code issuer
  • ID document issuer
  • Client ID, Client ID (Company)

Address information

  • Address, country, county, city, street, flat, postcode

Contact information

  • Mobile phone number, email

Financial information

  • IBAN / account number, bank BIC

Transaction information

  • Transaction purpose, transaction amount

Administrative information

  • Member codes
  • Enforcement order number (case number for bailiffs)
  • Restriction document date

Activity data

  • Technical server logs
  • Correspondence with Client support
  • Files the Client elects to send to FinHub for processing