Data Processing Addendum (DPA)
Last Updated: May 10th, 2024
This Data Processing Addendum (DPA) forms an integral part of the Terms of Service between you (“Controller”) and Dafinchi.ai (“Processor”), operated by Dafinchi with its registered office in Atlanta, GA, USA.
This DPA outlines how Dafinchi.ai processes Customer Data on your behalf in accordance with applicable U.S. data protection laws and relevant state-level regulations.
By using Dafinchi.ai, you acknowledge your responsibility as the Controller of Customer Data and agree that Dafinchi.ai processes such data only on your instructions and solely for the purposes defined in this DPA.
AGREED TERMS
1. Definitions and Interpretation
Definitions
-
Controller, Processor, Data Subject, Personal Data, Processing, Personal Data Breach
These terms shall have the meanings assigned under applicable U.S. data protection laws, including the California Consumer Privacy Act (CCPA), HIPAA (where applicable), COPPA, and other relevant state and federal regulations.
-
Data Protection Legislation
All applicable U.S. federal and state data privacy laws governing the collection, processing, storage, security, and protection of personal data.
-
Special Categories of Personal Data
Sensitive information such as racial/ethnic origin, political opinions, religious beliefs, health data, genetic or biometric identifiers, sexual orientation, or similar data defined as sensitive under U.S. privacy laws.
Interpretation
- References to "in writing" include email and electronic communication recognized under the ESIGN Act.
- In case of conflict between this DPA and the Terms of Service or Privacy Policy, the DPA prevails for matters relating to data processing.
2. Personal Data Types and Processing Purposes
Controller–Processor Relationship
- You remain the sole owner and controller of Customer Data.
- Dafinchi processes Customer Data only on documented instructions from you.
- You are responsible for ensuring Customer Data is lawful and compliant with all relevant data protection obligations, including obtaining any required consents.
Purpose and Scope of Processing
Dafinchi processes Customer Data for the following purposes:
- Providing financial insights and analytics through the Dafinchi platform.
- Operating, maintaining, and improving platform functionality.
- Providing technical or administrative support.
- Meeting legal, regulatory, or compliance obligations.
- Conducting security monitoring and fraud prevention.
- Performing anonymization or aggregation of data where permitted.
Duration of Processing
Processing lasts for the duration of your use of the Dafinchi platform unless retention is required by law or explicitly agreed otherwise.
Categories of Data
Dafinchi may process:
- Contact information
- Financial account–related information you provide
- Usage data, device data, and log records
- Any Customer Data submitted via integrations or uploads
Special Categories of Data
You agree not to submit Special Categories of Personal Data unless Dafinchi explicitly approves in writing and additional safeguards are established.
3. Our Obligations as Processor
Processing in Accordance with Your Instructions
- Dafinchi processes Customer Data solely for the purposes described in this DPA.
- Dafinchi will notify you if any instruction appears to violate U.S. data protection laws.
Confidentiality
- Personnel with access to Customer Data are bound by confidentiality obligations (contractual or statutory).
- Customer Data will not be disclosed to third parties except as instructed, legally required, or necessary for service delivery.
Assistance with Compliance
Dafinchi will reasonably assist you with:
- Responding to Data Subject access or deletion requests
- Conducting Data Protection Impact Assessments
- Cooperating with supervisory authorities
- Fulfilling legal reporting obligations
Security Measures
Dafinchi implements technical and organizational measures designed to protect Customer Data from unauthorized access, disclosure, alteration, or destruction.
4. Personal Data Breach
If Dafinchi becomes aware of a data breach involving Customer Data, it will notify you without undue delay, including:
- Details of the breach and affected data
- Number of impacted Data Subjects
- Likely consequences
- Measures taken or proposed
- Recommendations to mitigate potential harm
Breach details will not be disclosed to third parties unless legally required.
5. Cross-Border Transfers of Personal Data
- Customer Data is ordinarily processed within the United States.
- Dafinchi or its subprocessors will not transfer Customer Data outside the United States without your explicit prior approval.
If Customer Data is processed by foreign service providers:
- Those locations may have different privacy laws than the U.S.
- Local authorities in those countries may access data under local laws.
- You may contact us for additional information regarding international data handling.
6. Complaints, Data Subject Requests, and Third-Party Rights
- Dafinchi will notify you promptly of any Data Subject request or complaint.
- Dafinchi will not respond to such requests directly unless instructed by you.
- Dafinchi will assist you in meeting obligations to Data Subjects under U.S. privacy laws.
7. Data Return and Destruction
Upon written request:
- Dafinchi will return or make available a copy of all Customer Data.
- After termination of the Agreement, Customer Data will be securely deleted or returned based on your instructions.
- One archival copy may be retained if required by law.
8. Records and Audits
- Dafinchi maintains detailed records of data processing activities, security controls, and subprocessor usage.
- You may verify compliance once per year through written inquiries or a third-party auditor.
- To protect other users and system security, IT system access will not be granted, but documentation and responses will be provided.
Acceptance
By continuing to use Dafinchi.ai, you acknowledge and agree to the terms of this Data Processing Addendum.