Data processing agreement
Scope and status
This annex covers personal data that CEL TECHNOLOGIES LTD (Finbar) processes as the Customer's processor or subprocessor (Customer Personal Data). Roles depend on actual activities; the privacy notice covers Finbar's separate controller activities, including accounts and billing.
Adapted from Common Paper DPA 1.1 under CC BY 4.0; its standard terms are not incorporated by reference and Common Paper does not endorse Finbar.
This annex forms part of the accepted business terms, consumer terms or incorporating order, not merely by viewing it. Separately signed agreements take precedence for their services, subject to mandatory law and transfer clauses.
Cover schedule
| Item | Processing scope |
|---|---|
| Provider | CEL TECHNOLOGIES LTD; company details |
| Customer | Contracting party identified in the applicable service agreement, acting as controller or processor for the relevant processing |
| Roles | Customer as controller or processor; Finbar as processor or subprocessor as appropriate |
| Service and processing | Receive, host, retrieve, analyse and transform customer-supplied documents, workbooks, prompts and related workspace content to provide the agreed Finbar financial-research service, with necessary support and return/deletion |
| Data subjects | Customer users and people identified in customer-supplied content |
| Personal information | Account/workspace identifiers; names, contact and professional information and other personal information in documents, workbooks, prompts, conversations and related outputs supplied or generated within the agreed processing scope |
| Sensitive information | Special-category processing is outside the agreed scope unless expressly agreed following an appropriate assessment |
| Frequency and duration | As the Customer uses the service, with storage for the service and until return/deletion under this annex |
| Subprocessors | The provider register identifies provider services, tasks and locations; general authorisation and the 14-calendar-day notice/objection process below apply |
| Security measures | The security schedule below |
| International processing | The locations described in the provider register, subject to the international-transfer requirements below |
| Contacts | Customer Notice Address under the service agreement, or a replacement data-protection contact designated by the Customer; provider contact inquiries@finbar.com |
Customer determines its supplied content and remains responsible for its lawfulness and authority to give instructions as controller or processor. Processing outside this scope requires documented agreement.
Instructions and confidentiality
Finbar will process Customer Personal Data only on documented Customer instructions, including for transfers, unless law requires otherwise, with prior notice unless legally prohibited. The agreed service, this annex and authorised use document the initial instructions; further instructions must be documented and lawful.
Finbar will immediately inform Customer if it considers an instruction infringes data protection law, and notify Customer if it cannot comply with instructions. It will not substitute different processing purposes.
Authorised personnel must be bound by confidentiality commitments or an appropriate statutory duty. The applicable service agreement's staff-access restrictions apply.
Security schedule
Finbar will implement lawful, appropriate technical and organisational measures, considering processing risks, nature, scope, context and purposes, the state of the art and implementation costs:
| Area | Measures and obligations |
|---|---|
| Access control | Account authentication and permissions control access to account and workspace services. Authorised Finbar personnel may access customer content only as needed for support, troubleshooting, security or legal obligations. |
| Staff authentication | MFA is enforced for staff access to AWS, Microsoft Azure and Microsoft 365. |
| Confidentiality | Staff and contractors who can access customer data are bound by written confidentiality obligations. |
| Requests and incidents | Finbar maintains an accountable contact and backup for privacy requests and security reports. The assistance and breach-notification obligations below apply. |
| Retention and deletion | The return/deletion provisions below govern customer-instructed processing, including residual backup handling and protection of retained data. |
| Resilience and effectiveness | Finbar will maintain security, availability, recovery and assessment arrangements appropriate to the processing risks, as required by applicable data protection law. |
No independent certification, fixed recovery time or uptime guarantee is promised. Required transfer annexes must describe transfer-specific measures.
Subprocessors
Customer gives general written authorisation for the subprocessors identified in the subprocessor register for the relevant processing. Finbar will email affected Customers at their designated contact address at least 14 calendar days before a new or replacement subprocessor begins processing their Customer Personal Data, and update the register. The notice will identify the subprocessor, its processing locations and tasks, and the intended start date. Finbar will provide any longer notice period required by applicable law or binding transfer clauses.
Customer may object during the notice period on reasonable data-protection grounds by emailing inquiries@finbar.com with the subprocessor and grounds. Finbar will assess the objection before the start date and work with Customer towards a lawful practical resolution.
Processing requiring unresolved authorisation will not proceed until the objection is addressed; binding instructions and law remain controlling. This annex adds no automatic cancellation/refund right; existing contractual and statutory rights remain.
Finbar will bind each subprocessor by a written agreement imposing the applicable data protection obligations for the subcontracted processing, and remains responsible to the Customer for the subprocessor's performance of those obligations as required by law.
International transfers
Processing may occur in the provider register's locations, subject to documented instructions; no UK-only or EU-only residency is promised.
Before a restricted transfer, the responsible party must establish its lawful mechanism and complete any required assessments and safeguards, including entering any required EU standard contractual clauses, UK Addendum or IDTA with the correct parties, modules and annexes. Acceptance of this annex does not itself execute a separate transfer instrument.
Assistance and personal data breaches
Considering the processing's nature, Finbar will assist Customer through appropriate technical and organisational measures, insofar as possible, with individuals' rights. Requests will be referred to Customer; substantive responses on its behalf require its instructions or a legal requirement.
Considering the processing and available information, Finbar will assist with security, breach notification, data protection impact assessments and prior consultation.
Finbar will notify Customer without undue delay on becoming aware of a breach affecting Customer Personal Data, provide available information and updates, and take appropriate containment and remedial steps. Shorter applicable obligations prevail; notification is not an admission of liability.
Return and deletion
At the end of the processing services, Finbar will, at the Customer's choice, return or delete Customer Personal Data and delete existing copies unless applicable law requires retention. During the service, Finbar will assist with and carry out lawful deletion instructions within applicable requirements. Any retained data remains protected and must not be used for unrelated purposes.
These obligations do not await a separate request. Neither the service agreement's 60-day deletion period, privacy notice targets, controller-side evidence retention nor inactive-account review overrides them or earlier statutory or binding-instruction deadlines.
Backups must follow the agreed schedule and law, remain beyond ordinary use pending timely expiry, and have deletion reapplied on restoration.
Compliance information and audits
Finbar will make available information necessary to demonstrate compliance with its applicable processor obligations and allow for and contribute to audits, including inspections, by the Customer or an auditor it appoints.
Where sufficient, existing documentation and evidence will be used first. Reasonable confidentiality, scope, security, scheduling and non-disruption arrangements must not prevent necessary audits, limit mandatory rights or delay lawful regulatory access. No recurring independent audit programme, absolute annual limit or automatic audit fee is imposed.
Relationship to the service agreement
This annex governs processing while Finbar retains Customer Personal Data on the Customer's behalf and prevails over conflicting general service terms. Mandatory transfer clauses and law prevail over both.
The service agreement's lawful liability limits and exclusions apply; this annex adds no higher or unlimited contractual category. Individuals' statutory rights, regulatory powers and non-limitable liability, including under mandatory transfer clauses, remain unaffected.