Data Processing Agreement
Last updated Oct 1, 2026
This Data Processing Agreement ("DPA") forms part of the contract between Finchbyte ("Processor", "we") and each client ("Controller", "you") whenever we process personal data on the client's behalf. It is designed to meet Article 28 of the EU and UK GDPR, section 8(2) of the India DPDP Act 2023, the CCPA/CPRA service provider requirements, the LGPD and similar laws. By accepting a proposal, you agree to this DPA.
1. Details of the processing
| Subject matter and purpose | Providing the marketing, SEO, CRM, funnel, automation, social media and reporting services in your proposal. |
| Duration | For as long as we provide the services, plus the return and deletion period below. |
| Types of personal data | Contact details (name, email, phone), business details, form submissions and leads, website analytics and advertising data, messages, and any other data you ask us to handle. |
| Data subjects | Your website visitors, leads, customers, subscribers and staff. |
2. Our obligations
- We process the personal data only on your documented instructions (the proposal, this DPA and your written instructions), unless the law requires otherwise, in which case we tell you first where allowed.
- Everyone who processes the data for us is bound by confidentiality.
- We apply appropriate technical and organisational security measures (section 5).
- We help you respond to data subject requests, carry out data protection impact assessments and consult regulators, where relevant to our services.
- We tell you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting your data, with the information you need to notify authorities and people.
- At the end of the services, we return or delete your personal data within 90 days, as you choose, unless the law requires us to keep it.
- We make available the information needed to show compliance and allow reasonable audits, with 30 days' notice, once a year, at your cost.
3. CCPA/CPRA service provider terms
We will not sell or share your personal information, retain, use or disclose it outside our direct business relationship with you or for any purpose other than the services, or combine it with personal information from other sources except as the CCPA allows. We will tell you if we can no longer meet these obligations.
4. Sub-processors
You authorise us to use sub-processors to provide the services. We sign data protection terms with each of them that are at least as protective as this DPA, and we remain responsible for them. We will announce new sub-processors on this page at least 14 days before they start; you may object on reasonable data protection grounds.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hostinger International Ltd. | Website, portal and database hosting | Per our hosting plan's data centre |
| Our email delivery provider | Sending transactional and notification emails | As configured |
| Google LLC (Analytics, Search Console, Ads, Workspace) | Analytics, reporting and advertising for you | Global |
| Meta Platforms (Meta Ads, WhatsApp Business) | Advertising and messaging for you | Global |
| Microsoft Corporation (Clarity) | Website behaviour analytics | Global |
| LinkedIn Ireland | Advertising for you | Global |
5. Security measures
- HTTPS encryption in transit and encrypted passwords; private, access-controlled storage for documents.
- Role-based access, two-factor authentication for staff, and strict separation so each client only sees its own data.
- Hashing of IP addresses, data minimisation, and automatic deletion of website activity after 13 months.
- Regular backups, software updates, access logging and staff confidentiality commitments.
6. International transfers
Where personal data from the EEA, UK or Switzerland is transferred to a country without an adequacy decision, the EU Standard Contractual Clauses (Module 2 or 3, as applicable) and the UK Addendum are incorporated into this DPA by reference. We do not transfer data to countries restricted under the DPDP Act.
7. Your responsibilities
You are responsible for having a lawful basis and giving the required notices for the personal data you ask us to process, including consent for cookies and marketing messages on your own websites and campaigns.
8. Liability and conflicts
The liability terms in our Terms of Service apply. If this DPA conflicts with other terms about personal data, this DPA applies. For a signed copy, contact our contact page.