Skip to content
Legal

Data Processing Addendum

Effective September 19, 2026. Issued by Finance Operating System. Governed by the laws of the State of Florida, United States.

1. Agreement

This Data Processing Addendum ("DPA") is between the customer identified in the account ("Customer") and Finance Operating System, and forms part of the Terms of Service. It applies when Finance Operating System processes Customer Personal Data on Customer's behalf in providing the Service. Finance Operating System contracts from the State of Florida, United States.

For a countersigned copy, email legal@financeoperatingsystem.com. Use of the Service constitutes agreement to this DPA.

2. Roles

For Customer Personal Data, Customer is the controller (or "business" under U.S. state privacy laws) and Finance Operating System is the processor (or "service provider"). Where Customer is itself a processor (for example an accounting firm acting for an end client), Finance Operating System acts as a sub-processor.

Finance Operating System will process Customer Personal Data only on documented instructions from Customer, including as configured in the Service, unless required by U.S. or Florida law, in which case we will notify Customer unless legally prohibited.

3. Scope and subject matter

Finance Operating System processes Personal Data to provide the Service described in the Terms: ledger storage, reporting, invoicing, bills, banking connections, payroll add-ons where enabled, AI Copilot responses you request, payment processing, audit logging, security, and customer support. Duration matches the term of the subscription plus the deletion period in Section 11.

4. Categories of data and data subjects

  • Identifiers (name, email, organization role)
  • Financial and commercial records Customer creates or imports
  • Bank transaction metadata (via Plaid, read-only, if enabled)
  • Usage telemetry, security logs, and audit logs

Data subjects may include Customer's users, employees, customers, vendors, and other contacts Customer stores in the Service. Customer is responsible for providing notices and obtaining any consents required for that data.

5. Confidentiality and personnel

Finance Operating System ensures that persons authorized to process Customer Personal Data are bound by confidentiality and receive appropriate training. Access is limited on a least-privilege basis.

6. Sub-processors

Customer authorizes Finance Operating System to engage the sub-processors listed at /sub-processors. We impose data protection terms no less protective than this DPA. We will give at least 30 days' notice of a new sub-processor that will process Customer Personal Data. Customer may object on reasonable data-protection grounds; if we cannot accommodate the objection, Customer may terminate the affected Service as its sole remedy.

7. Security measures

We maintain technical and organizational measures described on our security page, including encryption in transit, encryption at rest for stored data, tenant isolation, access control, logging, and backup practices appropriate to a financial SaaS product.

8. U.S. state privacy (including service-provider terms)

Finance Operating System will not sell Customer Personal Data, will not retain, use, or disclose it except as needed to provide the Service or as permitted as a service provider / processor under applicable U.S. state privacy laws (including, where applicable, the California Consumer Privacy Act as amended), and will not combine it with personal information from other sources except as allowed by those laws to provide the Service.

9. International transfers

Where Personal Data of EEA, UK, or Swiss data subjects is transferred to the United States or another third country, the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914), including the UK Addendum where applicable, are incorporated by reference. Module Two (controller to processor) or Module Three (processor to processor) applies according to Customer's role.

10. Assistance, rights requests, and DPIAs

The Service includes tools for access, correction, export, and deletion. Finance Operating System will reasonably assist Customer with data subject requests, data protection impact assessments, and consultations with authorities, taking into account the nature of processing. Customer remains responsible for responding to requests directed at Customer.

11. Breach notification

We will notify Customer without undue delay, and in any event within 72 hours after becoming aware of a Personal Data Breach affecting Customer Personal Data, with information reasonably available to us to help Customer meet its own notification duties.

12. Audits

On reasonable written request, no more than once per year (unless a competent authority or a confirmed breach requires more), and subject to confidentiality, we will provide our then-current security documentation (including a SOC 2 report when available) and respond to a reasonable security questionnaire.

13. Deletion and return

On termination or Customer's written request, we will delete or return Customer Personal Data within 30 days, except where U.S. or Florida law requires retention, or copies remaining in encrypted backups until those backups expire in the ordinary cycle.

14. Liability and governing law

Liability under this DPA is subject to the limitations in the Terms. This DPA is governed by the laws of the State of Florida, United States and the venue provisions of the Terms, except that the SCCs are governed as stated in those clauses.

15. Contact

Privacy / DSR: privacy@financeoperatingsystem.com
DPA execution: legal@financeoperatingsystem.com
Finance Operating System, State of Florida, United States

Data Processing Addendum | Finance Operating System