Data Processing Agreement
Last updated: July 2026
1. Subject matter
This Data Processing Agreement ("DPA") is a processing agreement under Article 28 GDPR between:
Controller (Customer) — the entity that uses the Finowo Service and determines the purposes and means of processing personal data with respect to Customer Data,
and
Processor (Finowo):
FINOWO sp. z o.o., Żurawia 6/12 lok. 745, 00-503 Warszawa, Poland,
KRS: 0001183467, NIP: 7011269175, REGON: 542227920
("Finowo", "Processor").
This DPA forms an integral part of the Terms of Service and applies where Finowo processes personal data on behalf of the Customer in connection with the Service.
2. Definitions
"Personal data", "processing", "controller", "processor", and "personal data breach" have the meanings given in the GDPR. "Customer Data" means personal data submitted to or processed in the Service on behalf of the Customer.
3. Subject, nature, and purpose of processing
| Element | Description |
|---|---|
| Subject | Processing of Customer Data in the Finowo Service |
| Nature | Hosting, storage, transmission, display, backup, technical support, compliance automation (to the extent enabled by the Customer) |
| Purpose | Providing the Service under the Terms and the Customer's instructions |
| Duration | Term of the Service agreement + retention periods under the Privacy Policy / law |
4. Types of data and data subjects
| Data subjects | Types of data (examples) |
|---|---|
| Customer's employees / users | Name, email, role, access logs |
| Customer's counterparties / end customers | Identity and contact data, VAT/NIP, transactional data — as entered by the Customer |
| Other individuals whose data the Customer places in the Service | As contained in Customer Data |
Finowo does not determine the purposes of processing Customer Data; it acts only on documented Customer instructions, unless EU or Polish law requires otherwise.
5. Finowo's obligations (Art. 28 GDPR)
Finowo shall:
- Process Customer Data only on documented Customer instructions (including those implied by use of the Service)
- Ensure that persons authorised to process data are bound by confidentiality
- Implement appropriate technical and organisational measures (Art. 32 GDPR), including encryption at rest and in transit, access control, and audit logs
- Not engage sub-processors except under Section 6
- Assist the Customer — to a reasonable extent — in fulfilling data subject rights requests
- Assist the Customer in ensuring compliance with Arts. 32–36 GDPR, taking into account the nature of processing
- At the end of the provision of services, at the Customer's choice, delete or return Customer Data (subject to legal retention duties) and delete existing copies unless law requires retention
- Make available information necessary to demonstrate compliance with Art. 28 and allow audits agreed in advance (no more than once per year, except on reasonable suspicion of a breach)
6. Sub-processors
The Customer gives general authorisation for Finowo to use sub-processors in the categories described in the Privacy Policy (including EU hosting, transactional email, billing).
Finowo will:
- Enter into a contract with each sub-processor imposing data-protection obligations at least equivalent to this DPA
- Inform the Customer of intended sub-processor changes, with a right to object on legitimate data-protection grounds
- Remain liable to the Customer for the sub-processors' acts as for its own
7. Transfers outside the EEA
Finowo will not transfer Customer Data outside the EEA without: (a) an adequacy decision, or (b) Standard Contractual Clauses (SCCs) and — where required — supplementary measures. Primary infrastructure is in Germany (Hetzner).
8. Personal data breaches
Finowo will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, providing the information required by Art. 33(3) GDPR to the extent available, so the Customer can meet its own obligations toward the authority and individuals.
9. Customer instructions
Use of the Service constitutes documented processing instructions. Additional written instructions should be sent to privacy@finowo.finance. Finowo will inform the Customer if, in its opinion, an instruction infringes the GDPR or other data-protection law — to the extent permitted by law.
10. Liability
The parties' liability under this DPA is subject to the liability limitations in the Terms of Service, without prejudice to mandatory provisions of the GDPR and Polish law.
11. Governing law
This DPA is governed by Polish law. Matters not covered are governed by the GDPR and the Polish Personal Data Protection Act.
12. Contact
FINOWO sp. z o.o.
privacy@finowo.finance · legal@finowo.finance
Żurawia 6/12 lok. 745, 00-503 Warszawa, Poland
KRS: 0001183467 · NIP: 7011269175