VERSION: 1.0
Last Updated: 1. April 2025
1.1 Agreement.
This Data Processing Addendum (the "DPA”) forms an integral part of the Terms of Service available at Terms of Service and the Order executed separately by the Parties (collectively, the "Agreement").
1.2 Data Processing Agreement.
By entering into the Agreement with the Provider, the Client acknowledges that it has read and understood this DPA and agrees to be bound by it.
Other than the terms defined in the body of this DPA or in the Agreement, these terms have the following meaning:
"Data Breach" means a breach of security of the Services leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed by the Provider under this DPA.
"Data Protection Legislation" means, as applicable to a party and its Processing of Personal Data, the EU Data Protection Law and any other law applicable for the provision of the Services.
"EU Data Protection Laws" mean Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such data (General Data Protection Regulation) (the "GDPR") and the EU e-Privacy Directive (Directive 2002/58/EC). The terms "Controller", "Processor", "Process", "Processing", and "Data Subject" shall have the same meanings given to them under the GDPR.
"Personal Data" means any information that (i) is protected as "personal data", "personal information" or "personally identifiable information" under Data Protection Legislation; and (ii) is Processed by the Provider on behalf of the Client in the course of providing the Services, as more particularly described in Annex A of this DPA.
"Sub-processor" means any third party engaged by the Provider to assist in fulfilling its obligations with respect to providing the Services and that Processes Personal Data as a Processor.
"Standard Contractual Clauses" means the standard contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 (the "EU SCCs").
3.1 Roles.
For the purposes of this DPA, the Client (or a third party on whose behalf the Client is authorized to instruct the Provider) is the Controller of the Personal Data, and the Provider shall Process Personal Data as a Processor (or Sub-processor, as applicable to the Client's use of the Services).
3.2 Permitted Purposes.
The Provider shall Process Personal Data for the purposes described in Annex A and in accordance with Client's documented lawful instructions ("Permitted Purposes"), except where otherwise required by the Data Protection Legislation. To the extent required by Data Protection Legislation, this Section 3.2 constitutes the certification from the Provider to the Processing instructions herein. The Provider is obliged at all times to Process Personal Data in compliance with Data Protection Legislation and fulfil all its obligations arising out of Data Protection Legislation.
3.3 Processing Instructions.
The Provider shall immediately inform the Client if it becomes aware that the Client's Processing instructions infringe Data Protection Legislation. If the Provider is unable to Process Personal Data in accordance with the Client's documented lawful instructions, the Provider is obliged to promptly notify the Client of its inability to comply.
3.4 Security Measures.
The Provider shall implement and maintain reasonable and appropriate technical and organizational measures designed to protect Personal Data from Data Breaches and preserve their security, integrity, and confidentiality. Such measures shall have regard to the state of the art, the costs of implementation and the nature, scope, context, and purposes of Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons.
3.5 Access and Confidentiality.
The Provider shall ensure that any person it authorizes to Process the Personal Data (including Provider's staff, agents and Sub-processors) ("Personnel") are under appropriate obligations of confidentiality (whether a contractual or statutory duty), have received proper training, and are informed about the confidential nature of the Personal Data, their obligations related to it, and have access to Personal Data only on a need-to-know basis. The Provider shall ensure that Personnel Process the Personal Data only as necessary for the Permitted Purposes.
3.6 Data Returns and Deletion.
Upon termination or expiration of the Agreement, the Provider must delete or return to the Client all Personal Data in its possession or control except for one copy for archival and compliance purposes.
4.1 Right to conduct audits.
The Client shall have the right to conduct an audit to verify Provider's compliance with its obligations laid down in Art. 28 GDPR (if applicable) and in this DPA. The Provider shall allow the Client to carry out the audit if (i) the Client requests to carry out the audit via a written notice at least 30 (thirty) days in advance; (ii) the Client will specify the agenda for such audit in such notice; (iii) the audit shall not take place more than once a year; (iv) all associated costs and expenses shall be borne by the Client or reimbursed to the Provider on demand; and (v) the audit shall last no longer than the equivalent of 1 working day (8 hours) of Provider's representative. On the request of the Client, the Provider will provide the Client with the estimated cost that it expects to incur during such audit according to the extent specified in the agenda provided by the Client.
4.2 Independent Auditor.
In case the Client requests the audit by an independent party – external licensed auditor, the Provider may object to an external licensed auditor appointed by the Client to conduct the audit if the auditor is, in Provider's reasonable opinion, not suitably qualified or independent, a competitor of the Provider, or otherwise manifestly unsuitable. Any such objection will require the Client to appoint another auditor.
5.1 Client's Processing of Personal Data.
The Client shall, in its use of the Services, Process Personal Data in accordance with Data Protection Legislation. The Client shall have the sole responsibility for the accuracy, quality, and legality of Personal Data and how the Client acquired Personal Data.
5.2 Client's Compliance.
The Client agrees that (i) it shall comply with its obligations as a Controller under Data Protection Legislation in respect of its Processing of Personal Data and any Processing instructions it issues to the Provider; (ii) it has provided notice and obtained (or shall obtain) all consents or any other necessary authorizations (as applicable) under Data Protection Legislation for the Provider to Process Personal Data for the Permitted Purposes; (iii) it shall be responsible for providing any notices required by Data Protection Legislation to the relevant data subjects with respect to sharing their Personal Data with the Provider; (iv) it has fulfilled (or shall fulfil) all registration or notification obligations to which the Client is subject under the Data Protection Legislation; and (v) it is responsible for its own Processing of Personal Data, including integrity, security, maintenance, and appropriate protection of Personal Data under the Client's control.
5.3 Technical and Organizational Measures.
The Client is responsible for its secure use of the Services, protecting the security of Personal Data when in transit to and from the Services, and taking any appropriate technical, organizational, and security measures to securely encrypt or backup any Personal Data uploaded to the Services. The Client is also responsible for the use of the Services by any person authorized by the Client to access or use the Services, and any person who gains access to its Personal Data or the Services as a result of its failure to use reasonable security precautions, even if the Client did not authorize such use. The Client agrees to notify the Provider immediately upon becoming aware of any unauthorized use of the Services or any other breach of security involving the Services.
6.1 Data Subject Rights.
To the extent that the Client is unable to access the relevant Personal Data within the Services independently, the Provider shall, taking into account the nature of the Processing, provide assistance (including by appropriate technical and organizational measures) to provide reasonable cooperation to the Client in order to (i) respond to any requests from a data subject seeking to exercise any of its rights under Data Protection Legislation (including its right of access, correction, objection, erasure and data portability, as applicable); and (ii) any other correspondence, enquiry or complaint received from a data subject, regulator or other third party in connection with the Processing of the Personal Data (collectively "Correspondence").
In the event that any such Correspondence is made directly to the Provider, it shall promptly notify the Client and shall not respond directly unless legally compelled to do so. If the Provider is required to respond to such Correspondence, the Provider shall promptly notify the Client and provide it with a copy of the request, unless legally prohibited from doing so.
6.2 Data Protection Impact Assessment.
To the extent required by Data Protection Legislation, the Provider shall provide reasonable cooperation regarding the Services to enable the Client to carry out data protection impact assessments or prior consultations with data protection authorities as required by Data Protection Legislation.
6.3 Request for Disclosure.
The Provider is obliged to promptly notify the Client about any legally binding request for disclosure of the personal data by a judicial or regulatory authority unless otherwise prohibited, such as the obligation under criminal law to preserve the confidentiality of a judicial enquiry and to assist the Client accordingly (at the Client's expense).
7.1 Data Breach.
Upon becoming aware of a Data Breach, the Provider shall notify the Client without undue delay and shall provide such timely information and cooperation as the Client may reasonably require in order to fulfil its data breach reporting obligations under Data Protection Legislation, including the type of data affected and the identity of the affected person(s) as soon as such information becomes known or available to the Provider.
7.2 No acknowledgement.
The Client agrees that any notification that the Provider provides to the Client in relation to a Data Breach shall not be construed or understood as an acknowledgement of any fault or liability.
7.3 Further Conduct.
The Provider shall further take all such measures and actions as are reasonable to remedy or mitigate the effects of the Data Breach and shall keep the Client informed of all developments in connection with the Data Breach.
7.4 Cooperation.
If a Data Breach is caused or materially contributed to by the Client, the Provider will cooperate in the investigation of the Data Breach subject to the Client's obligation to compensate the Provider for its expenses and costs.
8.1 Authorized Sub-processors.
The Client provides a general authorization for the Provider to engage Sub-processors to Process Personal Data on the Client's behalf. The Sub-processors currently engaged by the Provider are included under Annex C.
8.2 New Sub-processors.
The Provider may engage or replace Sub-processors at its discretion, provided that it updates Annex B of the DPA available at Terms of Service to reflect such changes. The Provider shall provide at least ten (10) days' prior written notice to the Client of any new Sub-processor engagement.
8.3 Objections.
If the Client has a reasonable objection to any new Sub-processor, it shall notify the Provider of such objections in writing to info@finlay.ai within ten (10) days from receiving the notification and the Parties will seek to resolve the matter in good faith. If the Client does not provide a timely objection to any new Sub-processor in accordance with this Section 8.3, the Client will be deemed to have consented to the Sub-processor and waived its right to object.
8.4 Liability for Sub-processors.
The Provider remains liable for any breach of this DPA caused by an act, error, or omission of such Sub-processor.
9.1 International Data Transfers.
The Provider shall take all such measures necessary to ensure that the Processing and transfer of Personal Data in or to a territory other than the territory in which the Personal Data was first collected complies with Data Protection Legislation.
9.2 Application of Standard Contractual Clauses.
The Parties agree that when and to the extent the transfer of Personal Data from the Client to the Provider is a restricted transfer and EU Data Protection Laws require that appropriate safeguards are put in place, such transfer shall be governed by the EU SCCs, which shall be incorporated by reference into and form an integral part of this DPA.
9.3 EU Data.
For the purposes of Personal Data that is subject to the EU Data Protection Laws ("EU Data"):
a) where the Client is a Controller of Personal Data, Module Two (Controller to Processor Clauses) will apply and where the Client is a Processor acting on behalf of third-party Controllers, Module 3 (Processor to Processor Clauses) will apply;
b) in Clause 7 (Docking Clause), the optional docking clause will apply;
c) in Clause 9 (Use of Sub-processors), Option 2 will apply, and the time period for prior notice of Sub-processor changes shall be as set out in Section 8.2 of this DPA and the period for notification of objections in Section 8.3 of this DPA;
d) in Clause 11 (Redress), the optional language to permit data subjects to lodge complaints with an independent dispute resolution body will not apply;
e) in Clause 17 (Governing Law), Option 1 will apply, and the EU SCCs will be governed by Czech law;
f) in Clause 18(b) (Choice of forum and jurisdiction), disputes shall be resolved before the courts of Prague, Czech Republic;
The The Client's remedies, including its Affiliates, and the Provider's liability arising out of or in relation to this DPA (including Standard Contractual Clauses), are subject to those limitations of liability and disclaimers set forth in the Agreement. For the avoidance of doubt, nothing in this DPA is intended to limit the rights a Data Subject may have against either Party arising out of such Party's breach of the Standard Contractual Clauses, where applicable.
11.1 Third-Party Beneficiaries.
Data Subjects are the sole third-party beneficiaries to the Standard Contractual Clauses, and there are no other third-party beneficiaries to this DPA, unless specified to the contrary in the Agreement.
11.2 Governing Law and Jurisdiction.
This DPA shall be governed by and construed in accordance with the governing law and jurisdiction provisions in the Agreement, unless and to the extent required otherwise by the Data Protection Legislation or the Standard Contractual Clauses.
11.3 Scope of this DPA.
For the avoidance of doubt, the processing of information other than Personal Data for the Permitted Purposes does not fall under the scope of this DPA.
11.4 Amendments.
The Provider may amend this DPA subject to the conditions set forth in the Agreement. Any such amendments shall be communicated to the Client in accordance with the provisions outlined in the Agreement and shall become effective as specified therein.
11.5 Term.
This DPA shall continue to be in effect for the term of the Agreement plus the period from expiry of the Agreement until the Provider ceases to process Personal Data on behalf of the Client (the "Processing Term").