Data Processing Agreement (Template)
Data Processing Agreement (Template)
> **Template — not yet legal advice.** This is a starting point for operators who deploy > FinanceSight on behalf of others (e.g. for clients or an organisation) and need a processor > agreement. **Have it reviewed and completed by a qualified solicitor** before use. Bracketed > `[…]` fields must be filled in.
_Last updated: 2026-06-09 · Version 1.0.0_
This Data Processing Agreement ("DPA") forms part of the agreement between **[Controller]** ("the Controller") and **[Operator]** ("the Processor") for the provision of the FinanceSight service.
1. Subject matter and roles
The Processor processes personal data on behalf of the Controller solely to provide the FinanceSight service. The Controller is the controller of that personal data.
2. Nature and purpose of processing
Hosting and operating a personal-finance application: storage of account and financial records, authentication, notifications, and any optional integrations the Controller enables.
3. Categories of data and data subjects
• **Data subjects:** the Controller's end users. - **Categories:** account identifiers (username, optional email), financial records entered by users, security/audit events, and any data sent to enabled third-party sub-processors.
4. Duration
For the term of the service agreement, after which data is returned or deleted per clause 8.
5. Processor obligations
The Processor shall: (a) process only on documented instructions; (b) ensure persons authorised to process are bound by confidentiality; (c) implement appropriate technical and organisational security measures (see the [Security page](/legal/security)); (d) assist the Controller with data- subject requests and breach notification; and (e) make available information necessary to demonstrate compliance.
6. Sub-processors
The Processor uses the sub-processors listed in [Sub-processors](/legal/sub-processors). The Controller authorises these and will be informed of material changes, with an opportunity to object.
7. International transfers
Where personal data is transferred outside the Controller's jurisdiction, an appropriate transfer mechanism shall be used. _(Specify mechanism and regions: [….])_
8. Return or deletion
On termination, the Processor shall, at the Controller's choice, return or delete the personal data, subject to the retention of backups for the period stated in the [Privacy Policy](/legal/privacy) and any retention required by law.
9. Audit
The Processor shall make available information reasonably necessary to demonstrate compliance and allow for audits, subject to reasonable notice and confidentiality.
10. Liability and governing law
As set out in the underlying service agreement and the [Terms of Service](/legal/terms).
**Controller:** [name, signature, date] **Processor:** [name, signature, date]
FinanceSight needs JavaScript to run. See /llms.txt for more.