Cash Flow Frog logo
← Back to Trust Center

Data Processing Agreement

FinBoard Ltd. (d/b/a Cash Flow Frog) · Effective: July 2026

How this DPA applies. This Data Processing Agreement is automatically incorporated into our Terms of Service and applies to all customers whose use of the Services involves the processing of personal data on their behalf. No signature is required for it to take effect. If your organization requires a countersigned copy, contact us at contact@cashflowfrog.com and we will execute the signature version.

This Data Processing Agreement (“DPA”) forms an integral part of and is subject to the agreement that governs the provision of the Services (the “Agreement”), by and between [] (“Controller”) and FinBoard Ltd. (d/b/a Cash Flow Frog) and its Affiliates (“Processor”). The Agreement may take the form of a Customer Agreement, Terms of Service, or other written agreement between the parties. Capitalized terms not otherwise defined herein shall have the meaning given to them in the Agreement.

Whereas, in connection with the performance of its obligations under the Agreement, Processor may Process Controller Personal Data (both as defined below) on behalf of the Controller; and

Whereas, the parties wish to set forth the mutual obligations with respect to the Processing of Controller Personal Data by the Processor;

Now therefore, intending to be legally bound, the parties hereby agree as follows:

1. Definitions

In addition to capitalized terms defined elsewhere in this DPA, the following terms shall have the meanings set forth below:

  1. 1.1.
    Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. “Control” for purposes of this definition means direct or indirect ownership or control of more than 50% of the voting interest in the subject entity.
  2. 1.2.
    Applicable Data Protection Law” means any applicable laws relating to privacy or data protection, applicable to the Processing of Personal Data under this DPA, including:
    1. 1.2.1.
      Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (“GDPR”) and laws implementing or supplementing the GDPR;
    2. 1.2.2.
      The GDPR as amended and adopted into UK law in accordance with the European Union (Withdrawal) Act 2018, the UK’s Data Protection Act, 2018 and the UK Data (Use and Access) Act, 2025 (collectively, “UK GDPR”);
    3. 1.2.3.
      The California Consumer Privacy Act of 2018, Cal. Civil Code Title 1.81.5 and the regulations thereunder, as amended by the California Consumer Privacy Rights Act of 2020 (collectively, “CCPA”); and/or
    4. 1.2.4.
      The Israel Protection of Privacy Law, 1981, all related regulations enacted thereunder including without limitation the Israeli Protection of Privacy Regulations (Information Security) – 2017, and the Israel Privacy Protection Authority’s Guidelines, (collectively, “Israeli Privacy Law”).
  3. 1.3.
    Controller Personal Data” means any Personal Data Processed by Processor on behalf of Controller pursuant to or in connection with the Agreement.
  4. 1.4.
    Standard Contractual Clauses” means the standard contractual clauses for the transfer of Personal Data to data importers established in third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as set out in Commission Implementing Decision (EU) 2021/914 and available at: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32021D0914&qid=1640528660139&from=EN;
  5. 1.5.
    UK Addendum” shall mean the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses as issued by the UK Information Commissioner under S119A(1) Data Protection Act 2018.
  6. 1.6.
    Sub Processor” means any person (excluding an employee of Processor or any Processor Affiliate) appointed by or on behalf of Processor or any Processor Affiliate to Process Controller Personal Data on behalf of the Controller in connection with the Agreement.
  7. 1.7.
    Data Subject” shall mean the person whose Personal Data is Processed and both Data Subject as defined under the GDPR and Consumer as defined under the CCPA.
  8. 1.8.
    Personal Data” shall mean Personal Data as defined under the GDPR, ‘Personal Information’ as defined under the CCPA and ‘Information’ or ‘Personal Information’ (‘meida ishi’) as defined under Israeli Privacy Law, in each case, as applicable.
  9. 1.9.
    Processing” shall be as defined in the GDPR, the CCPA, and Israeli Privacy Law, in each case as applicable.
  10. 1.10.
    The terms “Controller”, “Data Protection Officer”, “Personal Data Breach”, “Processor”, and “Supervisory Authority” shall have the meanings ascribed to them in the GDPR.
  11. 1.11.
    The terms “Business”, “Sell”, “Share”, and “Service Provider”, shall have the meanings ascribed to them in the CCPA.

2. Applicability and Roles of the Parties

  1. 2.1.
    For Processing subject to the GDPR and/or UK GDPR: When Controller Personal Data is subject to the GDPR and/or the UK GDPR, Controller serves as a Controller of such Personal Data and Processor serves as a Processor on its behalf. In such case, the Applicable Data Protection Law shall be as described in Sections 1.2.1 and 1.2.2, respectively, and this DPA shall be interpreted accordingly.
  2. 2.2.
    For Processing subject to the CCPA: When Controller Personal Data is subject to the CCPA, Controller serves as a Business with respect to such Personal Data and Processor serves as a Service Provider on its behalf. In such case, the Applicable Data Protection Law shall be as described in Section 1.2.3 and this DPA shall be interpreted accordingly.
  3. 2.3.
    For Processing subject to Israeli Privacy Law: When Controller Personal Data is subject to Israeli Law, Controller shall be considered the party controlling the database of Controller Personal Data and Processor serves as an outsourced service provider on its behalf. In such case, the Applicable Data Protection Law shall be as described in Section 1.2.4 and this DPA shall be interpreted accordingly.

3. Processing of Controller Personal Data

  1. 3.1.
    Processor shall Process Controller Personal Data on Controller’s behalf and at Controller’s instructions as specified in the Agreement and in this DPA, including without limitation with regard to transfers of Controller Personal Data to a third country or international organization. Any other Processing shall be permitted only in the event that such Processing is required by any applicable law to which the Processor is subject. In such event, Processor shall, unless prohibited by such applicable law, inform Controller of that requirement before engaging in such Processing.
  2. 3.2.
    Controller instructs Processor (and authorizes Processor to instruct each Sub Processor) (i) to Process Controller Personal Data for the provision of the services, as detailed in the Agreement (“Services”) and as otherwise set forth in the Agreement and in this DPA, and/or as otherwise directed by Controller; and (ii) to transfer Controller Personal Data to any country or territory as reasonably necessary for the provision of the Services and in accordance with Applicable Data Protection Law.
  3. 3.3.
    Controller sets forth the details of the Processing of Controller Personal Data in Schedule 1 (Details of Processing of Controller Personal Data), attached hereto.
  4. 3.4.
    For Processing subject to the CCPA: Processor undertakes that it shall not Sell or Share Personal Data when Processing Personal Data as a Service Provider and shall not retain, use, or disclose Personal Data for any commercial purpose other than providing the Services to Controller and as otherwise permitted under the Agreement.

4. Controller

Controller represents and warrants that it has and shall maintain throughout the term of the Agreement and this DPA, all necessary rights to provide the Controller Personal Data to Processor for the Processing to be performed in relation to the Services and in accordance with the Agreement and this DPA. To the extent required by Applicable Data Protection Laws, Controller is responsible for obtaining any necessary Data Subject consents to the Processing, and for ensuring that a record of such consents is maintained throughout the term of the Agreement and this DPA and/or as otherwise required under Applicable Data Protection Laws. Without limiting the foregoing, to the extent that the Services involve connecting to third-party software platforms (such as accounting software, banking services, or other integrations) or to third-party services via MCP (Model Context Protocol) or similar protocols, Controller acknowledges and agrees that: (i) any such connection is made at Controller’s request and on Controller’s instructions; (ii) such third-party platforms and services are not Sub Processors of the Processor and are not appointed by or on behalf of the Processor; (iii) Controller is solely responsible for its relationship with such third parties, including ensuring that Controller has all necessary rights, authorizations, and consents to connect to such platforms, to provide Controller Personal Data to the Processor through such platforms, and to permit the Processor to access and process such data on Controller’s behalf; and (iv) Processor shall have no liability for the data processing practices of such third-party platforms.

5. International Data Transfers

  1. 5.1.
    To the extent that the Processor Processes Controller Personal Data relating to Data Subjects in the EU or Israel and such Processing is subject to GDPR or Israeli Privacy Law and the Processing takes place in countries outside of the European Economic Area that do not provide an adequate level of data protection, as determined by the relevant authority in the applicable jurisdiction, the Standard Contractual Clauses shall apply and shall be incorporated herein upon execution of this Agreement by the parties. Annexes 1 and 2 attached hereto shall apply as Annexes 1 and 2 of the Standard Contractual Clauses. The Standard Contractual Clauses are modular, containing numerous sections that each pertain to a specific type of entity or transfer. For the purposes of this DPA and any transfers of data to third countries pursuant hereto, only the modular sections pertaining to module two (Controller to Processor) of the Standard Contractual Clauses shall apply, in addition to all general sections therein. Processor agrees to cooperate with Controller for the implementation of any technical measures as may be deemed necessary to permit the transfer of Controller Personal Data to countries outside of the applicable jurisdiction on the basis of the Standard Contractual Clauses and agrees to provide information as needed in order to allow Controller to conduct a transfer impact assessment.
  2. 5.2.
    To the extent that the Processor Processes Controller Personal Data that is protected by and subject to the UK GDPR, and the Processor Processes such data in a country other than the United Kingdom whose data protection laws were deemed inadequate by the United Kingdom, the UK Addendum shall apply and shall be incorporated herein upon execution of this Agreement by the parties. Annexes 1 and 2 attached hereto shall apply as Appendices 1 and 2 of the UK Addendum. Processor agrees to cooperate with Controller for the implementation of any technical measures as may be deemed necessary to permit the transfer of Controller Personal Data to countries outside of the United Kingdom on the basis of the UK Addendum and agrees to provide information as needed in order to allow Controller to conduct a transfer impact assessment.
  3. 5.3.
    Processor shall ensure that any recipient of Controller Personal Data and involved in International Transfer is bound by the same data protection obligations as set out in this section, including the implementation of appropriate safeguards for international data transfers.

6. Processor Employees

Processor shall take reasonable steps to ensure that access to the Controller Personal Data is limited on a need to know and/or access basis and that all Processor employees receiving such access are subject to confidentiality undertakings or professional or statutory obligations of confidentiality in connection with their access to and use of Controller Personal Data.

7. Security

  1. 7.1.
    Processor shall implement appropriate technical and organizational measures to ensure an appropriate level of security of the Controller Personal Data as set forth in the Binding Security Document attached hereto as Schedule 2. In assessing the appropriate level of security, Processor shall take into account the risks that are presented by the nature of the Processing and the information available to the Processor.
  2. 7.2.
    For Processing subject to Israeli Privacy Law: Processor shall implement information security measures and take all necessary measures as per the Israeli Privacy Law, in order to maintain the integrity, availability, confidentiality, survival and reliability of Personal Information of the Data Subjects, and comply with all provisions of the Israeli Privacy Law, including, and without limitation, the obligations of an “external party” under section 15 of the Protection of Privacy Regulations (Data Security), 5777-2017, which a “database owner” must oblige an external party within the framework of an outsourcing agreement (as such terms are defined in the Israeli Privacy Law), and all which are hereby explicitly incorporated in this DPA;
  3. 7.3.
    Processor will report, at least once a year, to Controller on the manner in which it is complying with its obligations under the Israeli Privacy Law and this DPA.

8. Personal Data Breach

  1. 8.1.
    Processor shall notify Controller without undue delay and, where feasible, immediately upon Processor becoming aware of a Personal Data Breach affecting Controller Personal Data. In such event, Processor shall provide Controller with reasonable and available information to assist Controller in meeting any obligations to inform Data Subjects or Supervisory Authorities of the Personal Data Breach as required under Applicable Data Protection Law.
  2. 8.2.
    At the written request of the Controller, Processor shall reasonably cooperate with Controller and take such commercially reasonable steps as are agreed by the parties or required under Applicable Data Protection Law to assist in the investigation, mitigation and remediation of any Personal Data Breach.

9. Sub Processing

  1. 9.1.
    Controller authorizes Processor to appoint (and permits each Sub Processor appointed in accordance with this Section 9 to appoint) Sub Processors in accordance with this Section 9.
  2. 9.2.
    Processor may continue to use those Sub Processors already engaged by Processor as identified to Controller as of the date of this DPA. A list of Processor’s current processors is attached hereto as Schedule 3.
  3. 9.3.
    Processor may appoint new Sub Processors and shall give notice of any such appointment to Controller. If, within seven (7) days of such notice, Controller notifies Processor in writing of any reasonable objections to the proposed appointment, Processor shall not appoint the proposed Sub Processor for the Processing of Controller Personal Data until reasonable steps have been taken to address the objections raised by Controller and Controller has been provided with a reasonable written explanation of the steps taken. Where such steps are not sufficient to relieve Controller’s reasonable objections, each of Controller or Processor may, by written notice to the other party and with immediate effect, terminate the Agreement to the extent that it relates to the Services requiring the use of the proposed Sub Processor. In such event, the terminating party shall not bear any liability for such termination.
  4. 9.4.
    With respect to each new Sub Processor, Processor shall:
    1. 9.4.1.
      Prior to the Processing of Controller Personal Data by Sub Processor, take reasonable steps (for instance by way of reviewing privacy policies as appropriate) to ensure that Sub Processor is committed and able to provide the level of protection for Controller Personal Data required by this DPA; and
    2. 9.4.2.
      ensure that the arrangement between the Processor and the Sub Processor is governed by a written contract, including terms that offer a materially similar level of protection for Controller Personal Data as those set out in this DPA and meet the requirements of Applicable Data Protection Law.
  5. 9.5.
    Processor shall remain fully liable to the Controller for the acts or omissions of any Sub Processor as if done by Processor.

10. Data Subject Rights

  1. 10.1.
    Controller shall be solely responsible for compliance with any statutory obligations concerning requests to exercise Data Subject rights under Applicable Data Protection Laws (e.g., for access, rectification, deletion of Controller Personal Data, etc.). Processor shall, at Controller’s sole expense, use commercially reasonable efforts to assist Controller in fulfilling Controller’s obligations with respect to such Data Subject requests, as required under Applicable Data Protection Laws.
  2. 10.2.
    Upon receipt of a request from a Data Subject under any Applicable Data Protection Laws in respect to Controller Personal Data, Processor shall promptly notify Controller of such request and shall not respond to such request except on the documented instructions of Controller or as required by Applicable Data Protection Laws to which the Processor is subject, in which case Processor shall, to the extent permitted by Applicable Data Protection Laws, inform Controller of such legal requirement prior to responding to the request.

11. Data Protection Impact Assessment and Prior Consultation

At Controller’s written request and expense, the Processor and each Sub Processor shall provide reasonable assistance to Controller with respect to any Controller Personal Data Processed by Processor and/or a Sub Processor, with any data protection impact assessments or prior consultations with Supervisory Authorities or other competent data privacy authorities, as required under any applicable laws.

12. Deletion or Return of Controller Personal Data

Processor shall promptly and in any event within 60 (sixty) days of the date of cessation of provision of the Services to Controller involving the Processing of Controller Personal Data, delete, return, or anonymize all copies of such Controller Personal Data, provided however that Processor may retain Controller Personal Data, as permitted by applicable law.

13. Audit Rights

  1. 13.1.
    Subject to Sections 13.2 and 13.3, Processor shall make available to an auditor mandated by Controller in coordination with Processor, upon prior written request, such information reasonably necessary to demonstrate compliance with this DPA and shall allow for audits, including inspections, by such reputable auditor mandated by the Controller in relation to the Processing of the Controller Personal Data by the Processor, provided that such third-party auditor shall be subject to confidentiality obligations.
  2. 13.2.
    Any audit or inspection shall be at Controller’s sole expense, and subject to Processor’s reasonable security policies and obligations to third parties, including with respect to confidentiality. The results of any audit or inspection shall be considered the confidential information of the Processor and subject to the confidentiality provisions under the Agreement.
  3. 13.3.
    Controller and any auditor on its behalf shall use best efforts to minimize or avoid causing any damage, injury or disruption to the Processor’s premises, equipment, employees and business and shall not interfere with the Processor’s day-to-day business. Controller and Processor shall mutually agree upon the scope, timing and duration of the audit or inspection and the reimbursement rate, for which Controller shall be responsible. Processor need not give access to its premises for the purposes of such an audit or inspection:
    1. 13.3.1.
      to any individual, unless he or she produces reasonable evidence of identity and authority;
    2. 13.3.2.
      if Processor was not given a prior written notice of such audit or inspection;
    3. 13.3.3.
      outside of normal business hours at those premises, unless the audit or inspection needs to be conducted on an emergency basis; or
    4. 13.3.4.
      for the purposes of more than one (1) audit or inspection in any calendar year, except for any additional audits or inspections which:
      1. 13.3.4.1.
        Controller reasonably considers necessary because of genuine concern as to Processor’s compliance with this DPA; or
      2. 13.3.4.2.
        Controller is required to carry out by Applicable Data Protection Law, a Supervisory Authority or any similar regulatory authority responsible for the enforcement of Applicable Data Protection Law in any country or territory where Controller has identified its concerns or the relevant requirement or request in its prior written notice to Processor of the audit or inspection.
  4. 13.4.
    Processor shall immediately inform Controller if, in its opinion, an instruction received under this DPA infringes the GDPR or other Applicable Data Protection Laws.

14. Limitation of Liability

Controller shall indemnify and hold Processor harmless against all claims, actions, third party claims, losses, damages and expenses incurred by the Processor and arising directly or indirectly out of or in connection with a breach of this DPA and/or applicable laws by Controller. Each party’s liability toward the other party shall be subject to the limitations on liability under the Agreement.

15. General Terms

  1. 15.1.
    Governing Law and Jurisdiction.
    1. 15.1.1.
      Subject to sections 15.1.2 and 15.1.3, the parties hereby expressly agree that the competent courts detailed in the Agreement shall be the exclusive jurisdiction regarding any disputes hereunder and this DPA shall be governed by the laws stipulated in the Agreement.
    2. 15.1.2.
      To the extent that the Standard Contractual Clauses apply and/or EU Member State law is required in connection with this DPA, the laws of Ireland shall be deemed the relevant jurisdiction and the competent courts in Ireland shall have exclusive jurisdiction regarding all disputes hereunder.
    3. 15.1.3.
      Notwithstanding the foregoing in this Section 15.1 the parties to this DPA hereby agree that the competent courts in California shall have exclusive jurisdiction regarding all disputes hereunder relating solely to the CCPA, and that the competent courts in Tel Aviv, Israel shall have exclusive jurisdiction regarding all disputes hereunder relating solely to the Israeli Privacy Law and the parties expressly consent to such jurisdiction.
  2. 15.2.
    Order of Precedence.
    1. 15.2.1.
      Nothing in this DPA reduces Processor’s obligations under the Agreement in relation to the protection of Controller Personal Data or permits Processor to Process (or permit the Processing of) Controller Personal Data in a manner that is prohibited by the Agreement.
    2. 15.2.2.
      This DPA is not intended to, and does not in any way limit or derogate from Controller’s obligations and liabilities towards the Processor under the Agreement and/or pursuant to Applicable Data Protection Laws or any law applicable to Controller in connection with the collection, handling and use of Controller Personal Data by Controller or other processors or their sub processors, including with respect to the transfer or provision of Controller Personal Data to Processor and/or providing Processor with access thereto.
    3. 15.2.3.
      Subject to this Section 15.2, with regard to the subject matter of this DPA, in the event of inconsistencies between the provisions of this DPA and any other agreements between the parties, including the Agreement and including (except where explicitly agreed otherwise in writing, signed on behalf of the parties) agreements entered into or purported to be entered into after the date of this DPA, the provisions of this DPA shall prevail. In the event of inconsistencies between the provisions of this DPA and the Standard Contractual Clauses or UK Addendum (to the extent either applies), the Standard Contractual Clauses or UK Addendum, as applicable, shall prevail.
  3. 15.3.
    Changes in Data Protection Laws.
    1. 15.3.1.
      Controller may, by at least 45 (forty-five) calendar days’ prior written notice to Processor, request in writing any variations to this DPA if they are required as a result of any change in, or decision of, a competent authority under any Applicable Data Protection Laws in order to allow Controller Personal Data to be Processed (or continue to be Processed) without breach of such Applicable Data Protection Laws.
    2. 15.3.2.
      If Controller gives notice with respect to its request to modify this DPA under Section 15.3.1, (i) Processor shall make commercially reasonable efforts to accommodate such modification request and (ii) Controller shall not unreasonably withhold or delay agreement to any consequential variations to this DPA proposed by Processor to protect the Processor against additional risks, or to indemnify and compensate Processor for any further steps and costs associated with the variations made herein.
  4. 15.4.
    Severance.Should any provision of this DPA be held invalid or unenforceable, then the remainder of this DPA shall remain valid and in force. The invalid or unenforceable provision shall either be (i) amended as necessary to ensure its validity and enforceability, while preserving the parties’ intentions as closely as possible or, if this is not possible, (ii) construed in a manner as if the invalid or unenforceable part had never been contained therein.

IN WITNESS WHEREOF, this DPA is entered into and becomes a binding part of the Agreement with effect from the later date set out below.

Controller: [Insert Company Name]

Signature
Name
Title
Date

Processor: FinBoard Ltd. (d/b/a Cash Flow Frog)

Signature
Name
Title
Date

Schedule 1: Details of Processing of Controller Personal Data

This Schedule 1 includes certain details of the Processing of Controller Personal Data as required by Article 28(3) GDPR.

Subject matter and duration of the Processing of Controller Personal Data

The subject matter and duration of the Processing of the Controller Personal Data are set out in the Agreement and this DPA.

The nature and purpose of the Processing of Controller Personal Data

Rendering Services in the nature of a cloud-based cash flow forecasting and monitoring platform on a software-as-a-service basis, including the extraction and processing of financial and business data from the Controller’s accounting software platforms and banking institutions, generating cash flow forecasts, and related analytics, as detailed in the Agreement.

The types of Controller Personal Data to be Processed are as follows

Names, email addresses, phone numbers, business details and contact information, financial and business data (including invoices, transaction records, client and vendor details, employee information), banking transaction data and account balances.

The categories of Data Subjects to whom the Controller Personal Data relates are as follows

Controller’s employees, clients, vendors, business contacts, and other individuals whose personal data is contained within datasets.

The obligations and rights of Controller

The obligations and rights of Controller are set out in the Agreement and this DPA.

Schedule 2: Binding Security Document

  1. 1.
    Encryption. Controller Personal Data shall be encrypted in transit using TLS 1.2 (or equivalent) encryption. Controller Personal Data shall be stored in encrypted form at rest within Amazon Web Services (AWS) (or equivalent) infrastructure using AES-256 encryption (or equivalent).
  2. 2.
    Certifications and Compliance. Processor maintains ISO 27001 (Information Security Management) certification.
  3. 3.
    Access Controls. Processor shall implement role-based access controls to restrict access to Controller Personal Data on a need-to-know basis. Processor shall require multi-factor authentication for personnel accessing systems that process Controller Personal Data.
  4. 4.
    Network Security. Processor shall maintain firewalls, intrusion detection/prevention systems, and other appropriate network security measures to protect Controller Personal Data from unauthorized access.
  5. 5.
    Vulnerability Management. Processor shall conduct periodic vulnerability assessments and penetration testing of its systems and shall remediate identified vulnerabilities in a timely manner based on risk severity.
  6. 6.
    Malware Protection. Processor shall deploy and maintain anti-malware software on all systems used to process Controller Personal Data.
  7. 7.
    Patch Management. Processor shall maintain a patch management program to ensure that operating systems, software, and firmware are updated in a timely manner to address known security vulnerabilities.
  8. 8.
    Business Continuity and Disaster Recovery. Processor shall maintain business continuity and disaster recovery plans that include regular backups of Controller Personal Data, testing of backup restoration procedures, and defined recovery time objectives.
  9. 9.
    Logging and Monitoring. Processor shall maintain audit logs of access to and activities within systems processing Controller Personal Data. Processor shall implement monitoring mechanisms to detect and alert on potential security incidents.
  10. 10.
    Physical Security. Processor shall maintain appropriate physical security controls for any facilities housing systems that process Controller Personal Data, including access controls, visitor management, and environmental protections.

Schedule 3: Sub Processors List

Sub-ProcessorData Transferred and PurposeHosting Location
Amazon Web Services, Inc. (AWS)Cloud computing and database hosting; storage of all Controller Personal Data on the Platform.United States (Virginia)
MongoDB, Inc.Database hosting services; storage of Controller Personal Data.United States
Google LLCAI ToolGlobal
Anthropic, PBCAI ToolGlobal
OpenAI OpCo, LLCAI ToolGlobal

Annex 1

Annex 1 to the Standard Contractual Clauses – MODULE 2 (CONTROLLER TO PROCESSOR)

The following Annexes form part of the Standard Contractual Clauses and must be completed and signed by the Parties.

A. List of Parties

DATA EXPORTER (Controller) – Customer, as detailed in the Agreement

DATA IMPORTER (Processor) – FinBoard Ltd. (d/b/a Cash Flow Frog), as detailed in the Agreement

B. Description of Transfer

Categories of Data Subjects whose personal data is transferred

Controller’s employees, clients, vendors, business contacts, and other individuals whose personal data is contained within the Controller’s accounting software, banking accounts, and financial records.

Categories of personal data transferred

Names, email addresses, phone numbers, business details, financial and business data (invoices, transaction records, client and vendor details, employee information), banking transaction data and account balances.

Special categories of data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures

None.

The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis)

Continuous basis throughout the term of the Agreement.

Nature of the Processing

Collection, storage, organization, structuring, retrieval, use, and disclosure by transmission to Controller in connection with the provision of the Services.

Purpose(s) of the data transfer and further Processing

To provide cloud-based cash flow forecasting and monitoring services on a software-as-a-service basis, including the extraction and processing of financial and business data from accounting software platforms and banking institutions, generating cash flow forecasts, and related analytics.

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period

For the duration of the Agreement, and thereafter in accordance with Section 12 of the DPA (Deletion or Return of Controller Personal Data).

For transfers to (sub-) processors, also specify subject matter, nature and duration of the Processing

As set forth in Schedule 3.

C. Competent Supervisory Authority

The competent supervisory authority regarding this transfer is the Irish Data Protection Commission, in accordance with Clause 13.

Annex 2

Annex 2 to the Standard Contractual Clauses

Description of the technical and organizational security measures implemented by the data importer in accordance with Clause 8.6 (or document/legislation attached):

As described in Schedule 2.

Schedule C: International Data Transfer Addendum to the EU Commission Standard Contractual Clauses ("Addendum")

PART 1: DETAILS

A. Parties– FinBoard Ltd. (d/b/a Cash Flow Frog) and Customer, as detailed in the Agreement and DPA

B. Selected SCCs, Modules and Selected Clauses

Addendum EU SCCs: The version of the Approved EU SCCs which this Addendum is appended to, detailed below, including the Appendix Information: Date; Reference (if any); Other identifier (if any); or the Approved EU SCCs, including the Appendix Information and with only the following modules, clauses or optional provisions of the Approved EU SCCs brought into effect for the purposes of this Addendum:

ModuleModule in operationClause 7 (Docking Clause)Clause 11 (Option)Clause 9a (Prior Authorization or General Authorization)Clause 9a (Time period)Is personal data received from the Importer combined with personal data collected by the Exporter?
1
2XNoNoGeneral Authorization7 daysNo
3
4

C. Appendix Information

Appendix Information” means the information which must be provided for the selected modules as set out in the Appendix of the Approved EU SCCs (other than the Parties), and which for this Addendum is set out in:

Annex 1A: List of Parties: As detailed in the Agreement

Annex 1B: Description of Transfer: As detailed in Schedule 1 of the DPA

Annex II: Technical and organisational measures including technical and organisational measures to ensure the security of the data: As detailed in Schedule 2 of the DPA

Annex III: List of Sub processors (Modules 2 and 3 only): As detailed in Schedule 3 of the DPA

D. Ending this Addendum when the Approved Addendum Changes

This Addendum shall terminate according to the terms of the DPA.

PART 2: MANDATORY CLAUSES

Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.


Related: Privacy Notice | Terms of Service | Trust Center