DRAFT. Placeholder Data Processing Addendum. For a signed counterpart, email legal@financeoperatingsystem.com.
Legal

Data Processing Addendum

Last updated: 2026-05-23

1. Roles

In respect of Customer Personal Data, Customer is the Controller and Finance Operating System is the Processor. Where Customer is itself a Processor (e.g. an accounting firm acting for an end client), Finance Operating System acts as a Sub-processor.

2. Scope & subject matter

Finance Operating System processes Personal Data only to provide the Service described in the Terms: ledger storage, reporting, AI Copilot responses, payment processing, audit logging, and customer support.

3. Categories of data

  • Identifiers (name, email, organization role)
  • Financial records you create or import
  • Bank transaction metadata (via Plaid, read-only)
  • Usage telemetry and audit logs

4. Sub-processors

Finance Operating System engages the sub-processors listed at /sub-processors. You authorize these sub-processors and will receive at least 30 days' notice of any addition before it processes your data.

5. Security measures

We maintain the technical and organizational measures described at /security — including TLS 1.3 in transit, AES-256 at rest, row-level tenant isolation, encrypted backups, immutable audit logging, and least-privilege access controls.

6. International transfers

Where Personal Data of EEA, UK, or Swiss data subjects is transferred outside the EEA, the EU Standard Contractual Clauses (2021/914) apply and are incorporated by reference, including the UK Addendum where applicable.

7. Data subject requests

We make available, within the Service, the tools necessary for you to fulfill data subject access, rectification, erasure, restriction, portability, and objection requests. We will assist you with such requests on reasonable notice.

8. Breach notification

We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting your Customer Personal Data.

9. Audits

On reasonable request and subject to confidentiality, we will provide our most recent SOC 2 report (when available) and respond to a reasonable security questionnaire once per year.

10. Deletion & return

On termination or your written request, we will delete or return Customer Personal Data within 30 days, except where retention is required by law.

11. Contact

privacy@financeoperatingsystem.com — for DPA execution, legal@financeoperatingsystem.com.