Skip to content
finimbus
How it works Rules Pricing
Join the waitlist ↗
Legal

Data processing agreement.

Last updated 2 October 2026

On this page

  1. Subject matter and duration
  2. Nature, purpose, data and subjects
  3. Instructions
  4. Confidentiality
  5. Security
  6. Subprocessors
  7. International transfers
  8. Assistance with data subject rights
  9. Personal data breaches
  10. Assistance with compliance
  11. Deletion and return
  12. Audits
  13. Liability and order of precedence
  14. Contact
This DPA applies automatically as part of the MSA. If you need a signed copy, write to legal@finimbus.dev.

This Data Processing Agreement ("DPA") forms part of the Master Service Agreement (or other written agreement for the Service) between Pregress (trading as Finimbus), registered at [registered address] under company number [company registration number] ("Finimbus", "we", "us") ("Processor") and the customer ("Controller"). It applies to the extent Finimbus processes personal data on behalf of the Controller under the GDPR, and reflects the requirements of Article 28.

Subject matter and duration

Finimbus processes personal data to provide the Service: reading Azure metadata and cost data from the Controller's subscriptions and producing findings. Processing lasts as long as the Controller uses the Service, plus the deletion period below.

Nature, purpose, data and subjects

ItemDescription
Nature and purposeCollection, storage, analysis and display of Azure environment data to identify cost savings; user administration; support.
Categories of data subjectsThe Controller's employees, contractors and administrators who use the Service; people whose names or identifiers appear in Azure resource names, tags or activity metadata.
Types of personal dataName, work email, role, sign-in and audit events; user principal names and identifiers in Azure resource metadata or tags; IP addresses. The Service is not designed to process special categories of data, and the Controller shall not send any.

Instructions

Finimbus processes personal data only on the Controller's documented instructions, which are this DPA, the MSA, the Controller's configuration of the Service, and its further reasonable written instructions. If Finimbus believes an instruction infringes the GDPR it will tell the Controller. It does not process the data for its own purposes, except for de-identified, aggregated statistics where the Controller has opted in to research and development use, and as the law requires.

Confidentiality

Finimbus ensures that people authorised to process the personal data are bound by confidentiality and are given access only as needed.

Security

Finimbus implements the technical and organisational measures described below and keeps them appropriate to the risk:

  • encryption of data in transit (TLS) and at rest;
  • Azure client secrets encrypted at rest with a separately held key; secrets kept in a managed key vault;
  • read-only, least-privilege access to the Controller's Azure environment;
  • role-based access control, individual accounts and strong authentication for staff, with access reviewed regularly;
  • separation of staging and production environments and no use of Customer Data in non-production;
  • audit logging and monitoring, and backup with tested restoration;
  • a process to detect, assess and handle security incidents.

Subprocessors

The Controller gives general authorisation for the following subprocessors:

SubprocessorServiceLocation
Microsoft Ireland Operations Ltd (Microsoft Azure)Hosting, database, storage, logging, key managementWest Europe
Microsoft Azure Communication ServicesTransactional emailEU

Finimbus will tell the Controller at least 30 days before adding or replacing a subprocessor, by email or in the application. The Controller may object on reasonable data protection grounds within that period; if the parties cannot resolve it, the Controller may terminate the affected Service without penalty. Finimbus imposes on each subprocessor obligations equivalent to this DPA and remains responsible for them.

International transfers

Finimbus processes the personal data in the EU. Any transfer outside the EEA takes place only under an adequacy decision or the EU Standard Contractual Clauses, with supplementary measures where needed.

Assistance with data subject rights

Finimbus will promptly forward to the Controller any request it receives from a data subject about the Controller's data, will not respond itself except to redirect, and will help the Controller with appropriate technical and organisational measures to answer such requests.

Personal data breaches

Finimbus will notify the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Controller's data, with the information it then has about the nature of the breach, the data and people concerned, the likely consequences and the measures taken, and will update it as it learns more.

Assistance with compliance

Taking into account the nature of processing and the information available to it, Finimbus will reasonably help the Controller to meet its obligations on security, breach notification, data protection impact assessments and prior consultation.

Deletion and return

On termination, or when the Controller disconnects a subscription, Finimbus makes the data available for export for 30 days, then deletes the personal data from production systems within a further 30 days and from backups within 35 days after that, unless EU or Member State law requires storage. Client secrets are deleted immediately when the Controller removes the connection. On request Finimbus confirms deletion in writing.

Audits

Finimbus will provide the Controller with the information needed to show compliance with Article 28 and allow audits by the Controller or an auditor it appoints, no more than once a year (or after a breach) with 30 days' notice, during business hours, subject to confidentiality and without access to other customers' data. The Controller bears the cost of audits, except where one reveals a material breach by Finimbus.

Liability and order of precedence

The liability provisions of the MSA apply to this DPA. If this DPA conflicts with the MSA about personal data, this DPA prevails. If the Standard Contractual Clauses apply, they prevail over both.

Contact

Data protection questions: privacy@finimbus.dev. Need a countersigned copy for your records? Write to legal@finimbus.dev.

finimbus

Azure cost control, built in Belgium by Pregress.

Product

How it worksRulesPricing

Legal

PrivacyTermsCookiesMaster service agreementData processing agreement
© 2026 Finimbus. Not affiliated with Microsoft. Azure is a trademark of Microsoft Corporation.