Legal Center

Data Processing Addendum

GDPR Article 28 terms that apply only where a Business/API customer is controller and FinDech UAB is processor.

Last updated · Version 2026-08-31.2

This Data Processing Addendum (“DPA”) applies only where you are a Business/API customer acting as controller and FinDech UAB processes specified personal data on your behalf as processor in connection with GLWS.

This DPA does not mean that every GLWS processing activity is processor processing. FinDech remains controller for its own platform operations, security, fraud prevention, legal compliance, billing (if any), and independent product accounts, as described in the Privacy Policy.

If you are a Consumer using GLWS for your own deals, this DPA does not apply; the Privacy Policy does.

1. Subject matter

FinDech will process personal data that you or your end users submit through the API or a Business integration (for example names, emails, deal terms, evidence metadata, and related identifiers) to provide the GLWS Service on your documented instructions.

2. Instructions

FinDech will process that processor-scope data only on documented instructions, including this DPA, the API Terms, and configuration you apply in the Service, unless Union or Member State law requires otherwise.

3. Confidentiality

Persons authorised to process the data are under confidentiality obligations.

4. Security

FinDech will implement appropriate technical and organisational measures designed to protect processor-scope data, including access control, encryption in transit, private object storage for proof files, and logging with secret redaction. FinDech does not claim ISO, SOC 2, PCI DSS, or similar certifications.

5. Subprocessors

You authorise FinDech to use subprocessors reasonably required to host and operate the Service. Current infrastructure includes website and function hosting, PostgreSQL, authentication, and object storage as described in the Privacy Policy.

A public subprocessor list is not published as a standalone page at this time. FinDech will maintain an internal list and, on written request to legal@findech.com, provide the then-current processor-scope subprocessors. FinDech will impose data-protection terms on subprocessors no less protective than this DPA in material respects. If a verified public list is later published, that list will control for notice purposes.

6. International transfers

Where FinDech transfers processor-scope data outside the EEA, it will use a lawful transfer mechanism required by GDPR, such as Standard Contractual Clauses with the relevant provider where those are in place. FinDech does not promise a mechanism that is not actually in place.

7. Data-subject requests

Taking into account the nature of the processing, FinDech will assist you by appropriate technical and organisational measures, insofar as possible, to fulfil your obligations to respond to data-subject requests for processor-scope data. End users may still contact FinDech; where FinDech is processor, we will redirect or coordinate with you where reasonably identifiable.

8. Breach assistance

FinDech will notify you without undue delay after becoming aware of a personal-data breach affecting processor-scope data, and will provide information reasonably available to assist you in meeting GDPR Articles 33 and 34.

9. DPIA and regulatory assistance

Taking into account the nature of processing and information available, FinDech will assist you with data-protection impact assessments and prior consultations with supervisory authorities where required for processor-scope processing.

10. Deletion and return

At the end of the provision of processor services, FinDech will delete or return processor-scope data at your choice, unless Union or Member State law, fraud-prevention, security, or other lawful retention described in the Privacy Policy requires storage. Deal records that FinDech processes as independent controller are not deleted solely because this DPA ends.

11. Audit information

On reasonable written request, FinDech will make available information necessary to demonstrate compliance with Article 28, such as this DPA, relevant security descriptions, and confirmation of subprocessors. On-site audits are available no more than once per year unless a competent authority or a documented incident reasonably requires more, on reasonable notice, during business hours, and without compromising security or other customers’ data. FinDech does not provide raw production database dumps.

12. Controller responsibilities

You represent that you have a lawful basis to submit personal data, that your instructions are lawful, and that you will not instruct FinDech to process data for prohibited transactions. You are responsible for providing required information to your end users.

13. Contact

legal@findech.com