Data processing addendum
Effective October 5, 2026 · Version 1.0
This Data Processing Addendum (the "DPA") forms part of the Master Services Agreement (the "Agreement") between Finic Technologies Inc. ("Finic") and Customer. It sets out how Finic handles Customer Data, including Finic's zero data retention commitment in Section 3. Capitalized terms not defined here have the meanings in the Agreement. If this DPA conflicts with the Agreement on the processing of Customer Data, this DPA controls.
1. Definitions
"Customer Personal Data" means personal information contained in Customer Data that Finic processes on Customer's behalf.
"Data Protection Laws" means the privacy and data protection Laws that apply to the processing of Customer Personal Data, which may include the Gramm-Leach-Bliley Act and its implementing regulations ("GLBA"), the California Consumer Privacy Act as amended ("CCPA"), other US state privacy laws, and, where applicable, the EU General Data Protection Regulation ("GDPR") and the UK GDPR.
"Nonpublic Personal Information" has the meaning given in GLBA.
"Saved Requests" means requests that an Authorized User chooses to save in the playground.
"Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data processed by Finic.
"Subprocessor" means a third party that Finic engages to process Customer Personal Data.
Terms such as "controller," "processor," "business," "service provider," "data subject" and "processing" have the meanings given in the applicable Data Protection Laws.
2. Roles and scope
2.1 Roles. Customer is the controller of Customer Personal Data (and, under the CCPA, the business). Finic is Customer's processor (and, under the CCPA, its service provider). Where Customer acts as a processor for another controller, Finic is Customer's subprocessor.
2.2 Scope. Annex 1 describes the processing. Personal information Finic collects about Customer's Authorized Users to run their accounts, such as names, email addresses and sign-in records, is governed by Finic's Privacy Policy, not this DPA.
2.3 Compliance. Each party will comply with the Data Protection Laws that apply to it. Customer is responsible for the lawfulness of the Customer Personal Data it submits, including providing notices and obtaining consents or opt-outs required by GLBA and other Data Protection Laws.
3. Zero data retention
3.1 What is never stored. Finic processes Input and Output in memory for the duration of each request and does not write them to databases, files, logs or backups, so Finic personnel cannot review them afterward. This covers:
- the context;
- the questions, including their instructions, choices and levels; and
- the answers and probabilities the Services return.
It applies equally to requests sent to the API and to requests run in the playground. Finic requires each Subprocessor that handles Input or Output to process it only to answer the request and not to retain it.
3.2 What is recorded. For each request, Finic records only Usage Data:
- the time of the request;
- the organization, and the API Key or, for playground runs, the Authorized User who sent it;
- whether the request came from the API or the playground;
- the model;
- the HTTP status and, for errors, the error type (such as
invalid_request), but not the error message; - the number of questions;
- the number of input tokens, and the credit the request used;
- the latency; and
- the request ID returned in the
X-Request-Idheader, and the response's decision ID.
Finic also records when each API Key was last used. Finic uses Usage Data to show usage in the Portal, charge requests against Customer's credit, enforce rate limits, keep the Services secure and reliable, and answer support requests. Usage Data is part of Finic's billing records: Finic keeps it while Customer's account is open and for seven (7) years after it closes, then deletes it.
3.3 Saved Requests. If an Authorized User saves a request in the playground, Finic stores its context and questions within Customer's organization, visible only to that user, so the user can run it again. Answers are not stored; the Portal keeps them only in the user's browser tab. Finic deletes a Saved Request when the user deletes it, when the user is removed from Customer's organization, or as described in Section 9. Deleted Saved Requests remain in Finic's encrypted database backups for up to seven (7) days.
3.4 Content sent to Finic. If Customer includes Input or Output in a support email or attachment, Finic keeps that message as described in the Privacy Policy.
3.5 Legal orders. If a court or regulator lawfully orders Finic to preserve Input or Output, the order can apply only to requests received after it, since earlier content no longer exists. Finic will notify Customer unless Laws prohibit it.
3.6 No training. Finic will not use Customer Data to train, fine-tune or evaluate any model. Because Input and Output are not stored, they cannot be used later.
4. Processing
4.1 Instructions. Finic will process Customer Personal Data only to provide the Services and in accordance with Customer's documented instructions. The Agreement, this DPA and Customer's configuration and use of the Services are Customer's complete instructions. Finic will tell Customer if it believes an instruction violates Data Protection Laws, and if Laws require processing that is not instructed, unless Laws prohibit telling Customer.
4.2 Personnel. Finic will limit access to Customer Personal Data to personnel who need it to provide the Services and who are bound by confidentiality obligations.
5. US privacy laws
5.1 CCPA. Finic will not (a) sell or share Customer Personal Data, as those terms are defined in the CCPA; (b) retain, use or disclose it for any purpose other than the business purposes specified in the Agreement, including for any commercial purpose other than providing the Services; (c) retain, use or disclose it outside the direct business relationship between Customer and Finic; or (d) combine it with personal information Finic receives from or on behalf of anyone else, except as the CCPA permits. Finic will notify Customer if it can no longer meet its obligations under the CCPA. Customer may take reasonable steps to stop and remediate unauthorized use of Customer Personal Data. Finic certifies that it understands and will comply with these restrictions.
5.2 GLBA. To the extent Customer Personal Data includes Nonpublic Personal Information, Finic will (a) use and disclose it only to perform the Services, consistent with the limits on reuse and redisclosure in 12 C.F.R. § 1016.11; and (b) maintain an information security program with administrative, technical and physical safeguards designed to ensure its security and confidentiality, protect against anticipated threats or hazards to its security or integrity, and protect against unauthorized access to or use of it that could result in substantial harm or inconvenience to any customer, as described in Annex 2.
6. Subprocessors
6.1 Authorization. Customer authorizes Finic to engage the Subprocessors listed in Annex 3. Finic will impose on each Subprocessor data protection obligations at least as protective as those in this DPA, to the extent applicable to the services it provides, and remains responsible for each Subprocessor's performance.
6.2 Changes. Finic will give Customer at least thirty (30) days' notice before a new Subprocessor processes Customer Personal Data. Customer may object on reasonable data protection grounds within that period. The parties will work in good faith to resolve the objection; if they cannot, Customer may terminate the affected Services and receive a refund of unused purchased credit and any Fees prepaid for the remainder of their term.
7. Security
7.1 Measures. Finic will implement and maintain the technical and organizational measures in Annex 2. Finic may update them, provided updates do not materially reduce the overall protection of Customer Personal Data.
7.2 Security Incidents. Finic will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident. The notice will describe, to the extent known, the nature of the incident, the categories and approximate volume of data affected, the likely consequences and the measures taken or proposed. Finic will take reasonable steps to contain, investigate and remediate the incident, and will provide information Customer reasonably needs to meet its own notification obligations.
7.3 Service incidents affecting banking organizations. If Customer is a banking organization subject to the federal computer-security incident notification rules, Finic will notify Customer's designated contact as soon as possible after determining that it has experienced a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, the Services provided to Customer for four or more hours.
8. Assistance and audits
8.1 Data subject requests. If Finic receives a request from an individual to exercise rights over Customer Personal Data, Finic will promptly forward it to Customer and will not respond except to direct the individual to Customer. Because Finic does not retain Input or Output, it will generally hold no Customer Personal Data to act on, other than Saved Requests. Finic will provide reasonable assistance for Customer to respond.
8.2 Assessments. Finic will provide reasonable information and assistance for Customer's data protection impact assessments, vendor risk assessments and consultations with regulators, taking into account the nature of the processing and the information available to Finic.
8.3 Information. On written request, Finic will provide Customer with information reasonably necessary to demonstrate compliance with this DPA, such as responses to security questionnaires and, when available, third-party audit reports under confidentiality.
8.4 Audits. If that information is not sufficient to demonstrate compliance, or if a regulator or a Security Incident requires it, Customer may audit Finic's compliance with this DPA no more than once in any twelve-month period (except after a Security Incident or at a regulator's direction), on at least thirty (30) days' notice, during business hours, at Customer's expense, and under a mutually agreed scope and confidentiality terms. Customer may use a third-party auditor that is not a Finic competitor and is bound by confidentiality obligations.
8.5 Regulators. Finic acknowledges that the Services it performs for Customer may be subject to examination by Customer's regulators, including under the Bank Service Company Act, and will cooperate with such examinations to the extent Laws require.
9. Deletion
When the Agreement ends, or earlier when Customer asks Finic at support@finic.ai to close its account, Finic will within thirty (30) days delete Customer's Saved Requests, API Keys, invitations and organization records, and the accounts of Authorized Users who belong to no other organization, except where Laws require Finic to keep them. Because Finic does not retain other Input or Output, there is no other Customer Personal Data to return or delete. Finic keeps Usage Data and billing records as described in Section 3.2.
10. International transfers
Finic stores and processes Customer Personal Data in the United States. Encrypted connections to the Services are received at the nearest Amazon CloudFront location and carried to the United States. To the extent the GDPR or UK GDPR applies to a transfer of Customer Personal Data to Finic, the parties agree to the Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor) or Module Three (processor to processor) as applicable, and the UK International Data Transfer Addendum, each incorporated by reference and completed with the details in Annexes 1 to 3, with the governing law and forum of Ireland for the Clauses and of England and Wales for the UK Addendum. Customer will tell Finic before submitting personal data subject to these laws.
11. Changes
Finic will update this DPA only as provided in the Agreement, and will give at least thirty (30) days' notice before any change that reduces the protection of Customer Data, including the commitments in Section 3. A change never applies to requests sent before it takes effect.
12. Liability
Each party's liability under this DPA is subject to the limitations in the Agreement.
Annex 1: Description of processing
Subject matter and purpose. Automated evaluation of the context and questions Customer submits, to return probability estimates that support Customer's fraud, risk and compliance decisions.
Nature of processing. Receiving, analyzing and returning data through the API and the Portal. Processing is in memory for the duration of each request.
Categories of data subjects. Determined by Customer. Typically Customer's customers and applicants, their counterparties and payees, principals of merchants and business customers, and other individuals named in Customer's records.
Categories of personal data. Determined by Customer. Typically identifiers and contact details, account and transaction records, device, network and session data, identity verification results, and case notes. The Acceptable Use Policy prohibits card numbers, authentication secrets, health information and biometric identifiers.
Sensitive data. Customer should not submit sensitive data unless necessary for its questions. Government identification numbers may be submitted only as the Acceptable Use Policy permits.
Frequency. Continuous, as Customer sends requests.
Retention. Input and Output: not retained after each request is answered (Section 3.1). Saved Requests: as described in Sections 3.3 and 9.
Subprocessors. As listed in Annex 3, for hosting and model inference.
Annex 2: Technical and organizational measures
Data retention by design. Request content is processed in memory and is not written to databases, logs or backups (Section 3). Service logs record request metadata only.
Encryption. Connections to the Services over the internet use TLS 1.2 or higher. Between Amazon CloudFront and Finic's servers, traffic stays within Amazon Web Services' private network. Connections from Finic's servers to its database and to Subprocessors use TLS. Databases, server disks and backups are encrypted at rest with AES-256.
Credentials. API Keys are shown once and stored only as SHA-256 hashes, with a short prefix kept so they can be identified. Portal passwords are stored as salted PBKDF2-SHA256 hashes. Sign-in with a password requires a one-time code sent by email. Sessions are stored as hashes, bound to anti-forgery tokens, and expire.
Access control. Finic's servers and database have no public network addresses. Administrative access is limited to authorized Finic personnel, goes through Amazon Web Services' identity and systems management services rather than SSH or other open ports, and is recorded in AWS CloudTrail. Customer organizations are logically isolated, and administrative actions in the Portal are recorded in an audit log.
Network and infrastructure. The Services are hosted in Amazon Web Services' US West (Oregon) region. Only Amazon CloudFront can reach Finic's servers, and only Finic's servers can reach its database. Authentication and API traffic are rate limited, and the Portal uses a strict content security policy.
Secure development. Changes are tested automatically, and dependencies are checked for known vulnerabilities before each release. Releases are versioned, and a release that fails its health checks is rolled back automatically.
Monitoring and incident management. Finic is alerted automatically when the Services become unreachable or return server errors. Finic keeps service logs, which contain no request content, for thirty (30) days, remediates vulnerabilities according to severity, and maintains an incident response process that includes the notifications in Section 7.
Business continuity. The database is backed up automatically, with point-in-time recovery for seven (7) days. Finic's servers restart automatically after a failure.
Personnel. Finic personnel are bound by confidentiality obligations and have access removed promptly when their role ends.
Annex 3: Subprocessors
- Amazon Web Services, Inc.: content delivery (Amazon CloudFront), compute, database and backups for the API and the Portal. Location: United States.
- Runpod, Inc.: GPU compute for model inference. Location: United States.