This Data Processing Agreement ("DPA") forms part of the Master Service Agreement (or other written agreement for the Service) between Pregress (trading as Finimbus), registered at [registered address] under company number [company registration number] ("Finimbus", "we", "us") ("Processor") and the customer ("Controller"). It applies to the extent Finimbus processes personal data on behalf of the Controller under the GDPR, and reflects the requirements of Article 28.
Subject matter and duration
Finimbus processes personal data to provide the Service: reading Azure metadata and cost data from the Controller's subscriptions and producing findings. Processing lasts as long as the Controller uses the Service, plus the deletion period below.
Nature, purpose, data and subjects
| Item | Description |
|---|---|
| Nature and purpose | Collection, storage, analysis and display of Azure environment data to identify cost savings; user administration; support. |
| Categories of data subjects | The Controller's employees, contractors and administrators who use the Service; people whose names or identifiers appear in Azure resource names, tags or activity metadata. |
| Types of personal data | Name, work email, role, sign-in and audit events; user principal names and identifiers in Azure resource metadata or tags; IP addresses. The Service is not designed to process special categories of data, and the Controller shall not send any. |
Instructions
Finimbus processes personal data only on the Controller's documented instructions, which are this DPA, the MSA, the Controller's configuration of the Service, and its further reasonable written instructions. If Finimbus believes an instruction infringes the GDPR it will tell the Controller. It does not process the data for its own purposes, except for de-identified, aggregated statistics where the Controller has opted in to research and development use, and as the law requires.
Confidentiality
Finimbus ensures that people authorised to process the personal data are bound by confidentiality and are given access only as needed.
Security
Finimbus implements the technical and organisational measures described below and keeps them appropriate to the risk:
- encryption of data in transit (TLS) and at rest;
- Azure client secrets encrypted at rest with a separately held key; secrets kept in a managed key vault;
- read-only, least-privilege access to the Controller's Azure environment;
- role-based access control, individual accounts and strong authentication for staff, with access reviewed regularly;
- separation of staging and production environments and no use of Customer Data in non-production;
- audit logging and monitoring, and backup with tested restoration;
- a process to detect, assess and handle security incidents.
Subprocessors
The Controller gives general authorisation for the following subprocessors:
| Subprocessor | Service | Location |
|---|---|---|
| Microsoft Ireland Operations Ltd (Microsoft Azure) | Hosting, database, storage, logging, key management | West Europe |
| Microsoft Azure Communication Services | Transactional email | EU |
Finimbus will tell the Controller at least 30 days before adding or replacing a subprocessor, by email or in the application. The Controller may object on reasonable data protection grounds within that period; if the parties cannot resolve it, the Controller may terminate the affected Service without penalty. Finimbus imposes on each subprocessor obligations equivalent to this DPA and remains responsible for them.
International transfers
Finimbus processes the personal data in the EU. Any transfer outside the EEA takes place only under an adequacy decision or the EU Standard Contractual Clauses, with supplementary measures where needed.
Assistance with data subject rights
Finimbus will promptly forward to the Controller any request it receives from a data subject about the Controller's data, will not respond itself except to redirect, and will help the Controller with appropriate technical and organisational measures to answer such requests.
Personal data breaches
Finimbus will notify the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Controller's data, with the information it then has about the nature of the breach, the data and people concerned, the likely consequences and the measures taken, and will update it as it learns more.
Assistance with compliance
Taking into account the nature of processing and the information available to it, Finimbus will reasonably help the Controller to meet its obligations on security, breach notification, data protection impact assessments and prior consultation.
Deletion and return
On termination, or when the Controller disconnects a subscription, Finimbus makes the data available for export for 30 days, then deletes the personal data from production systems within a further 30 days and from backups within 35 days after that, unless EU or Member State law requires storage. Client secrets are deleted immediately when the Controller removes the connection. On request Finimbus confirms deletion in writing.
Audits
Finimbus will provide the Controller with the information needed to show compliance with Article 28 and allow audits by the Controller or an auditor it appoints, no more than once a year (or after a breach) with 30 days' notice, during business hours, subject to confidentiality and without access to other customers' data. The Controller bears the cost of audits, except where one reveals a material breach by Finimbus.
Liability and order of precedence
The liability provisions of the MSA apply to this DPA. If this DPA conflicts with the MSA about personal data, this DPA prevails. If the Standard Contractual Clauses apply, they prevail over both.
Contact
Data protection questions: privacy@finimbus.dev. Need a countersigned copy for your records? Write to legal@finimbus.dev.