Scope & Purpose
This Data Processing Agreement (“DPA”) supplements and forms part of the Terms of Service between Finofii Edge LLC (“Processor”) and the Client (“Controller”). It describes the terms under which the Processor processes Personal Data on behalf of the Controller.
This DPA applies to all processing of Personal Data conducted by the Processor in connection with providing accounting, bookkeeping, virtual CFO, and compliance services.
Definitions
- Personal Data: Any information relating to an identified or identifiable natural person.
- Processing: Any operation performed on Personal Data, including collection, storage, use, and deletion.
- Controller: The Client who determines the purposes and means of processing Personal Data.
- Processor: Finofii Edge LLC, which processes Personal Data on behalf of the Controller.
- Sub-Processor: A third party engaged by the Processor to process Personal Data.
- Data Subject: The natural person whose Personal Data is processed.
Processing Details
The Processor shall process Personal Data as follows:
| Attribute | Details |
|---|---|
| Subject Matter | Provision of accounting, bookkeeping, and advisory services |
| Duration | Duration of the service agreement plus retention period |
| Nature & Purpose | Financial record processing, report generation, compliance filing |
| Types of Data | Financial transactions, account details, business entity data, contact information |
| Categories of Data Subjects | Client employees, contractors, vendors, and customers whose data appears in financial records |
Obligations of Processor
The Processor shall:
- Process Personal Data only on documented instructions from the Controller.
- Ensure that personnel authorized to process Personal Data are bound by confidentiality obligations.
- Implement appropriate technical and organizational security measures.
- Engage Sub-Processors only with prior written consent of the Controller.
- Assist the Controller in responding to Data Subject requests.
- Delete or return all Personal Data upon termination of services, at the Controller's choice.
- Make available to the Controller all information necessary to demonstrate compliance.
Obligations of Controller
The Controller shall:
- Ensure a lawful basis for all processing instructions provided to the Processor.
- Provide clear and documented processing instructions.
- Notify the Processor of any changes to processing requirements.
- Ensure compliance with applicable data protection laws.
Sub-Processing
The Processor maintains an up-to-date list of Sub-Processors on our Sub-Processors page. The Controller will be notified at least 30 days before any new Sub-Processor is engaged.
The Controller may object to a new Sub-Processor within 14 days of notification. If no alternative can be agreed upon, either party may terminate the affected services.
International Data Transfers
The Processor shall not transfer Personal Data outside the United States unless:
- The transfer is to a country with an adequate level of data protection.
- Appropriate safeguards are in place (Standard Contractual Clauses or equivalent).
- The Controller has provided prior written authorization.
Security Obligations
The Processor shall implement and maintain security measures including:
- Encryption of Personal Data at rest (AES-256) and in transit (TLS 1.3).
- Access controls with multi-factor authentication and role-based permissions.
- Regular vulnerability assessments and penetration testing.
- Employee security training and background checks.
- SOC 2 Type II certification maintained annually.
Breach Notification
In the event of a Personal Data breach, the Processor shall:
- Notify the Controller without undue delay and within 72 hours of becoming aware of the breach.
- Provide details including nature of breach, categories of data affected, approximate number of data subjects, and remediation steps.
- Cooperate with the Controller in investigating and mitigating the breach.
- Document all breaches including those that do not require notification.
Data Subject Rights
The Processor shall assist the Controller in fulfilling Data Subject requests including access, rectification, erasure, portability, and objection. The Processor shall respond to Controller assistance requests within 5 business days.
Audit Rights
The Controller may audit the Processor's compliance with this DPA once per calendar year with 30 days advance written notice. Audits shall be conducted during normal business hours and shall not unreasonably interfere with the Processor's operations.
The Processor shall make available SOC 2 Type II reports and other relevant compliance documentation as an alternative to on-site audits.
Term & Termination
This DPA remains in effect for the duration of the service agreement. Upon termination:
- The Processor shall, at the Controller's choice, return or delete all Personal Data within 30 days.
- The Processor may retain copies required by applicable law, subject to continued confidentiality.
- Obligations under this DPA survive termination to the extent necessary for ongoing data protection.