Data Processing Addendum (DPA)
Last updated: July 2026. A negotiated, executable DPA — with standard contractual clauses and a security schedule — is available on request for firms that require one.
1. Roles
For personal data contained in customer content, the customer is the controller and Managing Analyst is the processor, processing such data only on the customer's documented instructions and to provide the Service.
2. Scope & duration
This DPA applies to processing of personal data on behalf of the customer for the term of the agreement. Categories of data subjects and data (deal contacts, user accounts, and information within uploaded documents) and the purpose of processing are set out in the agreement.
3. Confidentiality & personnel
We ensure personnel authorized to process customer data are bound by confidentiality and process data only as instructed.
4. Security measures
We implement technical and organizational measures appropriate to the risk, including access controls, tenant isolation, encryption in transit, and audit logging. A detailed security schedule will be attached. We are transparent that certain launch-hardening measures (encryption-at-rest key management, independent penetration testing, and a formal compliance posture) are being completed prior to general availability for live third-party financial data.
5. Subprocessors
The customer authorizes use of the subprocessors listed in our Privacy Policy / subprocessor list. We impose data-protection obligations on subprocessors no less protective than this DPA and remain responsible for their performance. We will notify customers of material changes to the subprocessor list.
6. Data subject requests & assistance
We assist the customer, taking into account the nature of processing, in responding to data-subject requests and in meeting security, breach-notification, and impact-assessment obligations.
7. Breach notification
We notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data, with information reasonably available to us.
8. Return & deletion
On termination, we delete or return customer personal data as instructed, subject to legal retention requirements.
9. International transfers
Where personal data is transferred across borders, the parties will put in place an appropriate transfer mechanism, such as the applicable standard contractual clauses.
10. Contact
To request an executable copy of this DPA, contact us.