FINAP
01 Home02 Pricing03 Features04 Documentation05 Contacts
Sign inGet API key
Sign inGet API key
Legal / DPA23 sections / 02 annexes

DATA PROCESSING AGREEMENT

Last updated: 21.05.2026

Read document
Document index25
01DEFINITIONS02ROLES OF THE PARTIES03SCOPE OF PROCESSING04CUSTOMER INSTRUCTIONS05CUSTOMER RESPONSIBILITIES06FINAP RESPONSIBILITIES07CONFIDENTIALITY08SECURITY MEASURES09SUB-PROCESSORS10INTERNATIONAL DATA TRANSFERS11DATA SUBJECT REQUESTS12PERSONAL DATA BREACHES13ASSISTANCE WITH COMPLIANCE14AUDITS AND INFORMATION RIGHTS15RETURN OR DELETION OF DATA16ANONYMISED AND AGGREGATED DATA17WEB INTELLIGENCE AND DEVICE SIGNALS18SPECIAL CATEGORY DATA19CUSTOMER CONFIGURATION AND INTEGRATION20LIABILITY21TERM AND TERMINATION22GOVERNING LAW AND JURISDICTION23CONTACTA1DETAILS OF PROCESSINGA2TECHNICAL AND ORGANISATIONAL MEASURES

This Data Processing Agreement (“DPA”) forms part of the Terms of Use or any other written agreement entered into between FINAP LTD, a company registered in England and Wales under company number 17235755, with its registered office at Suite 7039, 128 Aldersgate Street, Barbican, London, EC1A 4AE, United Kingdom (“FINAP”, “Processor”, “we”, “us”, or “our”), and the customer using FINAP services (“Customer”, “Controller”, “you”, or “your”).

This DPA applies where FINAP processes Personal Data on behalf of the Customer in connection with the provision of FINAP services, including APIs, SDKs, WEB Intelligence, dashboard tools, playground services, validation services, data intelligence services, and related technology services.

If there is any conflict between this DPA and the Terms of Use in relation to the processing of Personal Data, this DPA shall prevail to the extent of such conflict.

1. DEFINITIONS

For the purposes of this DPA:

“Applicable Data Protection Laws” means all applicable laws and regulations relating to privacy and data protection, including where applicable the UK GDPR, EU GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations, and any other applicable data protection or privacy laws.

“Controller” means the party that determines the purposes and means of processing Personal Data.

“Processor” means the party that processes Personal Data on behalf of the Controller.

“Personal Data” means any information relating to an identified or identifiable natural person.

“Processing” means any operation performed on Personal Data, including collection, recording, storage, use, disclosure, transmission, analysis, deletion, or destruction.

“Customer Personal Data” means Personal Data processed by FINAP on behalf of the Customer under this DPA.

“Data Subject” means the individual to whom Personal Data relates.

“Sub-processor” means any third party appointed by FINAP to process Customer Personal Data on behalf of the Customer.

“Services” means the services provided by FINAP, including API services, SDKs, WEB Intelligence, BIN API, IBAN Validation API, FX Rates API, platform tools, dashboard, playground, technical support, and related technology services.

“Supervisory Authority” means the relevant data protection authority, including the UK Information Commissioner’s Office or any competent EU data protection authority.

2. ROLES OF THE PARTIES

The Customer is the Controller of Customer Personal Data processed through the Services.

FINAP acts as Processor where it processes Customer Personal Data on behalf of the Customer and in accordance with the Customer’s instructions.

In some circumstances, FINAP may act as an independent Controller for certain data, including account registration data, billing data, compliance records, sanctions screening records, security logs, service analytics, customer communications, and business administration records. Such processing is governed by FINAP’s Privacy Policy and not by this DPA.

3. SCOPE OF PROCESSING

FINAP shall process Customer Personal Data only to the extent necessary to provide the Services, maintain platform security, operate APIs, generate API responses, provide technical support, comply with applicable law, and perform its obligations under the Terms of Use and this DPA.

The subject matter, duration, nature, purpose, categories of data subjects, and categories of Personal Data are described in Annex 1 of this DPA.

4. CUSTOMER INSTRUCTIONS

FINAP shall process Customer Personal Data only on documented instructions from the Customer, including instructions contained in:

1. the Terms of Use;

2. this DPA;

3. the Customer’s use and configuration of the Services;

4. API requests submitted by or on behalf of the Customer;

5. written instructions agreed between the parties.

FINAP shall notify the Customer if, in FINAP’s reasonable opinion, an instruction infringes Applicable Data Protection Laws, unless prohibited from doing so by law.

The Customer acknowledges that its use of the Services constitutes instructions for FINAP to process Customer Personal Data for the purposes of providing the Services.

5. CUSTOMER RESPONSIBILITIES

The Customer is responsible for ensuring that:

1. it has a valid lawful basis for processing Customer Personal Data;

2. it has provided appropriate privacy notices to Data Subjects;

3. it has obtained valid consent where required by law;

4. its use of FINAP SDKs, APIs, scripts, WEB Intelligence tools, and similar technologies complies with Applicable Data Protection Laws;

5. it does not submit unnecessary, excessive, unlawful, or prohibited Personal Data to FINAP;

6. it has authority to instruct FINAP to process Customer Personal Data;

7. its use of FINAP outputs, scores, signals, and API responses complies with applicable laws;

8. it responds to Data Subject requests where it acts as Controller;

9. it maintains appropriate legal documentation, including privacy notices and cookie notices where required;

10. it does not use the Services for unlawful surveillance, discrimination, profiling, fraud, abuse, or prohibited purposes.

The Customer is solely responsible for the accuracy, legality, quality, and compliance of Customer Personal Data submitted to FINAP.

6. FINAP RESPONSIBILITIES

FINAP shall:

1. process Customer Personal Data only in accordance with this DPA and the Customer’s documented instructions;

2. implement appropriate technical and organisational measures to protect Customer Personal Data;

3. ensure that persons authorised to process Customer Personal Data are subject to confidentiality obligations;

4. assist the Customer with Data Subject requests where reasonably possible;

5. assist the Customer with security, breach notification, and compliance obligations where required by Applicable Data Protection Laws;

6. maintain appropriate records of processing where required;

7. engage Sub-processors only in accordance with this DPA;

8. delete or return Customer Personal Data after termination where required and technically feasible, subject to lawful retention rights.

7. CONFIDENTIALITY

FINAP shall ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations, whether contractual, statutory, or professional.

FINAP shall take reasonable steps to ensure that access to Customer Personal Data is limited to personnel, contractors, and Sub-processors who require access for the purposes of providing the Services.

8. SECURITY MEASURES

FINAP shall implement appropriate technical and organisational measures designed to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure.

Such measures may include, where appropriate:

1. encryption in transit;

2. access controls;

3. authentication controls;

4. secure API key management;

5. infrastructure security controls;

6. logging and monitoring;

7. vulnerability management;

8. backup and recovery processes;

9. segregation of access rights;

10. incident response procedures;

11. secure development practices;

12. restricted internal access to production systems;

13. supplier and Sub-processor security review;

14. measures to ensure ongoing confidentiality, integrity, availability, and resilience of systems.

The Customer acknowledges that no internet-based service can be guaranteed to be completely secure and that the Customer is responsible for securing its own systems, integrations, API keys, user devices, and implementation environment.

9. SUB-PROCESSORS

The Customer authorises FINAP to engage Sub-processors for the purpose of providing the Services.

Sub-processors may include providers of:

1. cloud hosting and infrastructure;

2. content delivery networks;

3. database hosting;

4. analytics and monitoring;

5. email delivery;

6. payment processing;

7. security services;

8. fraud prevention services;

9. data intelligence providers;

10. customer support tools;

11. logging and error monitoring;

12. compliance and sanctions screening.

FINAP shall ensure that Sub-processors are subject to data protection obligations that are substantially similar to those set out in this DPA.

FINAP remains responsible for the performance of its Sub-processors to the extent required by Applicable Data Protection Laws.

FINAP may update its list of Sub-processors from time to time. Where required by law, FINAP shall provide notice of material changes to Sub-processors and allow the Customer to object on reasonable data protection grounds.

10. INTERNATIONAL DATA TRANSFERS

FINAP may process or transfer Customer Personal Data outside the United Kingdom or European Economic Area where necessary to provide the Services or engage Sub-processors.

Where such transfer is subject to transfer restrictions under Applicable Data Protection Laws, FINAP shall ensure that appropriate safeguards are in place, which may include:

1. adequacy regulations or adequacy decisions;

2. Standard Contractual Clauses;

3. the UK International Data Transfer Agreement;

4. the UK Addendum to the EU Standard Contractual Clauses;

5. contractual, organisational, and technical safeguards.

The Customer authorises FINAP to make such transfers where necessary for the provision of the Services.

11. DATA SUBJECT REQUESTS

If FINAP receives a request from a Data Subject relating to Customer Personal Data, FINAP shall, where reasonably possible and legally permitted:

1. notify the Customer;

2. not respond directly unless required by law or authorised by the Customer;

3. provide reasonable assistance to the Customer in responding to the request.

The Customer is responsible for responding to Data Subject requests where it acts as Controller.

FINAP may charge reasonable fees for assistance where requests are excessive, complex, repetitive, or outside normal service scope.

12. PERSONAL DATA BREACHES

FINAP shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

Such notice shall include, where reasonably available:

1. a description of the nature of the breach;

2. categories and approximate number of affected Data Subjects, where known;

3. categories and approximate number of affected records, where known;

4. likely consequences of the breach, where known;

5. measures taken or proposed to address the breach;

6. contact details for further information.

The Customer is responsible for determining whether notification to a Supervisory Authority or Data Subjects is required.

FINAP’s notification of a Personal Data Breach shall not be construed as an admission of fault or liability.

13. ASSISTANCE WITH COMPLIANCE

Taking into account the nature of processing and information available to FINAP, FINAP shall provide reasonable assistance to the Customer with:

1. security obligations;

2. breach notification obligations;

3. data protection impact assessments;

4. consultations with Supervisory Authorities;

5. Data Subject rights requests;

6. audits or compliance reviews required by Applicable Data Protection Laws.

FINAP may charge reasonable fees for assistance that is extensive, repetitive, complex, or outside the standard scope of the Services.

14. AUDITS AND INFORMATION RIGHTS

FINAP shall make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, and commercial sensitivity restrictions.

Where required by Applicable Data Protection Laws, the Customer may request an audit or inspection of FINAP’s processing activities.

Any audit must:

1. be conducted on reasonable written notice;

2. occur during normal business hours;

3. not disrupt FINAP’s business operations;

4. be limited to systems and records relevant to Customer Personal Data;

5. be conducted by an independent auditor subject to confidentiality obligations;

6. not compromise the security or confidentiality of FINAP systems, other customers, suppliers, or confidential information.

FINAP may satisfy audit obligations by providing security summaries, policies, certificates, reports, questionnaires, or other reasonable documentation.

15. RETURN OR DELETION OF DATA

Upon termination of the Services or at the Customer’s written request, FINAP shall delete or return Customer Personal Data where technically feasible and legally required.

FINAP may retain Customer Personal Data where necessary to:

1. comply with legal obligations;

2. maintain billing, accounting, tax, or business records;

3. resolve disputes;

4. enforce agreements;

5. prevent fraud or abuse;

6. maintain security logs;

7. comply with sanctions, AML, or compliance requirements;

8. protect legal rights.

Data retained under this section shall remain protected in accordance with this DPA and FINAP’s internal retention practices.

16. ANONYMISED AND AGGREGATED DATA

FINAP may process Customer Personal Data to create anonymised, aggregated, or de-identified data that no longer identifies the Customer, Data Subjects, or any individual.

FINAP may use such anonymised or aggregated data for:

1. analytics;

2. benchmarking;

3. service improvement;

4. product development;

5. machine learning and artificial intelligence model improvement;

6. security research;

7. fraud prevention;

8. operational reporting;

9. commercial analysis.

Such data shall not be considered Personal Data where it cannot reasonably identify an individual.

17. WEB INTELLIGENCE AND DEVICE SIGNALS

Where the Customer uses FINAP’s WEB Intelligence services, SDKs, scripts, APIs, or similar technologies on its own website, application, checkout, or platform, the Customer acknowledges that such use may involve processing of technical signals relating to end users.

Such signals may include:

1. IP address;

2. geolocation information;

3. user agent;

4. browser name and version;

5. operating system;

6. device type and model;

7. SDK version;

8. URL or page context;

9. event identifiers;

10. visitor identifiers;

11. timestamps;

12. VPN and proxy indicators;

13. bot indicators;

14. tampering indicators;

15. velocity metrics;

16. network information, including ASN and ISP data;

17. risk scores;

18. confidence indicators;

19. other technical, security, behavioural, and environmental signals.

The Customer is responsible for ensuring that its use of WEB Intelligence complies with Applicable Data Protection Laws, including requirements relating to privacy notices, cookies, similar technologies, consent, legitimate interests assessments, and user rights.

FINAP does not authorise the Customer to use WEB Intelligence for unlawful surveillance, discrimination, unauthorised profiling, unlawful monitoring, harassment, or any prohibited purpose.

18. SPECIAL CATEGORY DATA

The Customer must not submit Special Category Data, criminal offence data, government identification documents, payment card numbers, passwords, biometric data for identification purposes, health data, political opinions, religious beliefs, trade union information, sexual orientation information, or other sensitive personal data to FINAP unless expressly authorised in writing by FINAP and permitted by law.

FINAP’s Services are not designed to process such categories of data unless specifically agreed in a separate written agreement.

19. CUSTOMER CONFIGURATION AND INTEGRATION

The Customer is responsible for the configuration and implementation of FINAP Services within its own systems.

The Customer must ensure that:

1. API requests do not contain unnecessary Personal Data;

2. data minimisation principles are applied;

3. API keys are protected;

4. access to FINAP outputs is restricted appropriately;

5. SDKs are implemented in accordance with documentation;

6. privacy notices and cookie notices are updated where required;

7. consent mechanisms are implemented where legally required;

8. FINAP outputs are used responsibly and lawfully.

20. LIABILITY

Each party’s liability under this DPA shall be subject to the limitation of liability provisions set out in FINAP’s Terms of Use, unless otherwise required by Applicable Data Protection Laws.

Nothing in this DPA excludes or limits liability where such exclusion or limitation is prohibited by law.

21. TERM AND TERMINATION

This DPA shall remain in effect for as long as FINAP processes Customer Personal Data on behalf of the Customer.

Termination or expiry of the Terms of Use shall not affect any obligations that are intended to survive termination, including confidentiality, deletion or retention of data, audit rights, liability, and legal compliance obligations.

22. GOVERNING LAW AND JURISDICTION

This DPA shall be governed by and construed in accordance with the laws of England and Wales.

The courts of England and Wales shall have exclusive jurisdiction over any dispute arising out of or in connection with this DPA, unless otherwise required by Applicable Data Protection Laws.

23. CONTACT

For questions regarding this DPA, please contact:

FINAP LTD

Company No. 17235755

Suite 7039, 128 Aldersgate Street, Barbican, London, EC1A 4AE, United Kingdom

Email: support@finap.uk

Website: www.finap.uk

ANNEX 1 — DETAILS OF PROCESSING

1. Subject Matter of Processing

The processing of Customer Personal Data in connection with the provision of FINAP Services, including API infrastructure, WEB Intelligence, BIN API, IBAN Validation API, FX Rates API, SDKs, dashboard tools, playground services, technical support, security monitoring, fraud prevention, and related technology services.

2. Duration of Processing

For the duration of the Customer’s use of the Services and for any additional period required for legal, security, billing, compliance, dispute resolution, fraud prevention, backup, or legitimate business purposes.

3. Nature of Processing

The nature of processing may include:

1. collection;

2. transmission;

3. receipt;

4. storage;

5. hosting;

6. analysis;

7. validation;

8. enrichment;

9. classification;

10. scoring;

11. logging;

12. retrieval;

13. structuring;

14. comparison;

15. aggregation;

16. anonymisation;

17. deletion;

18. security monitoring;

19. technical support.

4. Purpose of Processing

The purposes of processing include:

1. providing FINAP Services;

2. generating API responses;

3. validating submitted data;

4. providing WEB Intelligence outputs;

5. detecting technical risk signals;

6. supporting fraud prevention and security analysis;

7. maintaining platform functionality;

8. authenticating users and API requests;

9. monitoring usage and performance;

10. troubleshooting and support;

11. billing and balance management;

12. preventing abuse;

13. improving service quality;

14. complying with legal obligations.

5. Categories of Data Subjects

Customer Personal Data may relate to:

1. Customer representatives;

2. Customer employees;

3. Customer contractors;

4. Customer developers;

5. Customer administrators;

6. end users of Customer websites, applications, platforms, checkouts, or systems;

7. website visitors;

8. persons whose technical signals are processed through WEB Intelligence;

9. persons whose data is submitted for validation or intelligence purposes.

6. Categories of Personal Data

Customer Personal Data may include:

1. IP addresses;

2. geolocation data;

3. user agent strings;

4. browser information;

5. device information;

6. operating system information;

7. visitor identifiers;

8. event identifiers;

9. timestamps;

10. URL or page context;

11. VPN and proxy indicators;

12. bot detection indicators;

13. tampering indicators;

14. velocity metrics;

15. network and ASN information;

16. risk scores and confidence indicators;

17. API request metadata;

18. account contact details;

19. email addresses;

20. company information;

21. billing information;

22. technical logs;

23. support communications;

24. IBAN or BIN-related information submitted for validation, where applicable.

7. Special Category Data

The Services are not intended to process Special Category Data or criminal offence data.

Customers must not submit such data unless expressly authorised in writing by FINAP and permitted by Applicable Data Protection Laws.

8. Processing Operations

Processing operations may include:

1. receiving API requests;

2. analysing submitted data;

3. generating API responses;

4. creating visitor identifiers;

5. producing risk and confidence scores;

6. detecting VPN, proxy, bot, tampering, and suspicious signals;

7. validating IBAN structures;

8. enriching BIN information;

9. providing FX rate data;

10. logging usage;

11. monitoring security;

12. storing records;

13. providing technical support;

14. creating anonymised or aggregated analytics.

ANNEX 2 — TECHNICAL AND ORGANISATIONAL MEASURES

FINAP applies appropriate technical and organisational measures designed to protect Customer Personal Data, which may include the following:

1. Access Control

• User authentication;

• Role-based access controls where applicable;

• Restricted internal access to production systems;

• Administrative access limited to authorised personnel;

• Access review where appropriate.

2. API Security

• API key-based authentication;

• Secure storage and handling of API keys;

• Ability to revoke or rotate API credentials;

• Rate limiting and abuse prevention controls;

• Monitoring of suspicious API activity.

3. Encryption and Transmission Security

• Encryption in transit using HTTPS/TLS where applicable;

• Secure communication channels;

• Protection of credentials during transmission.

4. Infrastructure Security

• Use of reputable cloud and hosting providers;

• Network security controls;

• Firewalls or equivalent protective controls where applicable;

• Monitoring of infrastructure availability and performance.

5. Logging and Monitoring

• Technical logs;

• Security logs;

• API usage logs;

• Error monitoring;

• Suspicious activity detection;

• Operational monitoring.

6. Data Minimisation

• Processing limited to data required for service delivery;

• Encouragement of customers to avoid submitting unnecessary personal data;

• Retention controls where applicable.

7. Backup and Recovery

• Backup processes where appropriate;

• Recovery procedures for critical systems;

• Measures supporting service continuity.

8. Confidentiality

• Confidentiality obligations for authorised personnel;

• Limited access to customer data;

• Internal handling procedures for sensitive information.

9. Incident Response

• Procedures for identifying and responding to security incidents;

• Internal escalation processes;

• Customer notification where required by law.

10. Supplier Management

• Use of reputable Sub-processors;

• Contractual protections with Sub-processors;

• Review of provider security where appropriate.

FINAP

Financial data and web intelligence APIs for modern applications.

sales@finap.uk
Payment methods
VisaMastercardApple PayGoogle PaySEPABitcoin
ExploreHomeFeaturesPricingDocumentationContacts
Legal01Terms of use02Privacy policy03Cookie policy04Payments policy05Data processing agreement06Refund policy
FINAP LTD / COMPANY NUMBER: 17235755 / UK-REGISTERED SOFTWARE COMPANY
© 2026 FINAP LTD