Skip to content
Finchbyte

Data Processing Agreement

Last updated Oct 1, 2026

This Data Processing Agreement ("DPA") forms part of the contract between Finchbyte ("Processor", "we") and each client ("Controller", "you") whenever we process personal data on the client's behalf. It is designed to meet Article 28 of the EU and UK GDPR, section 8(2) of the India DPDP Act 2023, the CCPA/CPRA service provider requirements, the LGPD and similar laws. By accepting a proposal, you agree to this DPA.

1. Details of the processing

Subject matter and purposeProviding the marketing, SEO, CRM, funnel, automation, social media and reporting services in your proposal.
DurationFor as long as we provide the services, plus the return and deletion period below.
Types of personal dataContact details (name, email, phone), business details, form submissions and leads, website analytics and advertising data, messages, and any other data you ask us to handle.
Data subjectsYour website visitors, leads, customers, subscribers and staff.

2. Our obligations

  • We process the personal data only on your documented instructions (the proposal, this DPA and your written instructions), unless the law requires otherwise, in which case we tell you first where allowed.
  • Everyone who processes the data for us is bound by confidentiality.
  • We apply appropriate technical and organisational security measures (section 5).
  • We help you respond to data subject requests, carry out data protection impact assessments and consult regulators, where relevant to our services.
  • We tell you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting your data, with the information you need to notify authorities and people.
  • At the end of the services, we return or delete your personal data within 90 days, as you choose, unless the law requires us to keep it.
  • We make available the information needed to show compliance and allow reasonable audits, with 30 days' notice, once a year, at your cost.

3. CCPA/CPRA service provider terms

We will not sell or share your personal information, retain, use or disclose it outside our direct business relationship with you or for any purpose other than the services, or combine it with personal information from other sources except as the CCPA allows. We will tell you if we can no longer meet these obligations.

4. Sub-processors

You authorise us to use sub-processors to provide the services. We sign data protection terms with each of them that are at least as protective as this DPA, and we remain responsible for them. We will announce new sub-processors on this page at least 14 days before they start; you may object on reasonable data protection grounds.

Sub-processorPurposeLocation
Hostinger International Ltd.Website, portal and database hostingPer our hosting plan's data centre
Our email delivery providerSending transactional and notification emailsAs configured
Google LLC (Analytics, Search Console, Ads, Workspace)Analytics, reporting and advertising for youGlobal
Meta Platforms (Meta Ads, WhatsApp Business)Advertising and messaging for youGlobal
Microsoft Corporation (Clarity)Website behaviour analyticsGlobal
LinkedIn IrelandAdvertising for youGlobal

5. Security measures

  • HTTPS encryption in transit and encrypted passwords; private, access-controlled storage for documents.
  • Role-based access, two-factor authentication for staff, and strict separation so each client only sees its own data.
  • Hashing of IP addresses, data minimisation, and automatic deletion of website activity after 13 months.
  • Regular backups, software updates, access logging and staff confidentiality commitments.

6. International transfers

Where personal data from the EEA, UK or Switzerland is transferred to a country without an adequacy decision, the EU Standard Contractual Clauses (Module 2 or 3, as applicable) and the UK Addendum are incorporated into this DPA by reference. We do not transfer data to countries restricted under the DPDP Act.

7. Your responsibilities

You are responsible for having a lawful basis and giving the required notices for the personal data you ask us to process, including consent for cookies and marketing messages on your own websites and campaigns.

8. Liability and conflicts

The liability terms in our Terms of Service apply. If this DPA conflicts with other terms about personal data, this DPA applies. For a signed copy, contact our contact page.