Legal

Data Processing Agreement

Template DPA outlining controller-processor responsibilities.

1. Roles

Customer acts as controller; Finar Tech acts as processor for the limited purpose of delivering contracted services.

2. Subprocessors

Current subprocessors include Vercel (EU) and Resend (EU data region). We provide 30 days notice prior to new subprocessors.

3. Security controls

Encryption in transit and at rest, logical access controls, vulnerability management, and annual penetration testing.

4. Data subject requests

We support access, export, and deletion requests within 15 days.

5. Incident response

Notifies customer without undue delay, includes nature of incident, affected records, and remediation steps.