1.Purpose and Scope

This DPA applies when Finday processes Personal Data within Customer Data on behalf of the Customer to provide the Services.

This DPA does not replace the Finday Privacy Policy for the processing of account, billing, support, security, marketing, product analytics, or Finday operational data carried out by Finday as a Personal Data Controller.

2.Definitions

Terms that are not defined in this DPA have the same meaning as in the Finday Terms and Conditions or the Finday Privacy Policy.

"Customer Personal Data" means Personal Data that is entered, uploaded, imported, created, stored, processed, or synchronized by or on behalf of the Customer through the Services.

"Personal Data Controller" means a party that determines the purposes of, and exercises control over, the processing of Personal Data.

"Personal Data Processor" means a party that processes Personal Data on behalf of a Personal Data Controller.

"Subprocessor" means a third party engaged by Finday to process Customer Personal Data in order to provide the Services.

3.Roles of the Parties

For Customer Personal Data, the Customer generally acts as the Personal Data Controller and Finday acts as the Personal Data Processor.

Finday may act as a Personal Data Controller for data whose purposes and means of processing Finday determines itself, including User account, security, billing, support, communications, product usage, compliance, and Finday operational data.

If the law or a written agreement establishes a different role for a particular processing activity, that provision will apply to that processing activity.

4.Processing Instructions

Finday will process Customer Personal Data only on the Customer's documented instructions, including:

  1. the Finday Terms and Conditions;
  2. this DPA;
  3. the related order form, invoice, proposal, or written agreement;
  4. configurations, roles, permissions, workflows, integrations, and User actions within the Services;
  5. support, migration, export, import, or troubleshooting instructions given by the Customer.

If Finday considers that an instruction violates the law or creates a security risk, Finday may refuse, postpone, restrict, or request clarification of that instruction.

5.Details of Processing

The purpose of processing is to provide, secure, maintain, support, improve, and operate the Services in accordance with the Customer's instructions.

Categories of data subjects may include:

  1. Users, Company Admins, approvers, internal auditors, consultants, accountants, and invited users;
  2. employees, candidates, contractors, payroll recipients, reimbursement recipients, and other HR parties;
  3. customers, vendors, suppliers, contact persons, payment recipients, shareholders, and transaction counterparties;
  4. parties named in documents, invoices, bills, contracts, proofs of payment, bank statements, attachments, or AI prompts uploaded by the Customer.

Categories of Customer Personal Data may include:

  1. identity, contact details, job title, role, permissions, and membership;
  2. bank account data, payments, invoices, bills, transactions, allocations, and reconciliations;
  3. tax data, NPWP (taxpayer identification number), NIK (national identity number), tax documents, and tax identity information;
  4. payroll data, salaries, allowances, deductions, THR (religious holiday allowance), benefits, payslips, attendance, leave, reimbursements, and HR data;
  5. accounting data, journals, chart of accounts, reports, approvals, audit trails, and supporting documents;
  6. documents, images, PDFs, OCR text, file metadata, and attachments;
  7. prompts, instructions, extraction results, transcripts, feedback, and context processed through the AI Features.

The duration of processing follows the period of use of the Services, retention periods, the offboarding period, legal obligations, and the deletion provisions in the Terms and Conditions, the Privacy Policy, and this DPA.

6.Customer Responsibilities

The Customer is responsible for:

  1. having the legal basis, notice, consent, authority, or other processing basis required for Customer Personal Data;
  2. ensuring that Customer Personal Data is accurate, relevant, and not excessive for the purposes of processing;
  3. giving processing instructions that are valid, clear, and in accordance with the law;
  4. managing roles, permissions, admin access, integrations, approvals, and User actions;
  5. responding to requests from Personal Data Subjects where the Customer acts as the Personal Data Controller;
  6. not entering passwords, secret keys, private keys, CVVs, credentials, OTPs, or other security data into free-text fields, attachments, support tickets, or AI prompts that are not designed for that purpose;
  7. evaluating whether a particular processing activity requires a personal data protection impact assessment, additional notice, or additional consent.

7.Finday's Obligations as Processor

Finday will:

  1. process Customer Personal Data in accordance with the Customer's instructions and this DPA;
  2. maintain the confidentiality of Customer Personal Data;
  3. limit personnel access based on job requirements;
  4. implement reasonable technical and organizational measures to protect Customer Personal Data;
  5. reasonably assist the Customer in fulfilling the Customer's obligations as a Personal Data Controller;
  6. notify the Customer of relevant Personal Data incidents in accordance with this DPA;
  7. ensure that Subprocessors are bound by relevant data protection obligations;
  8. delete, anonymize, archive, or return Customer Personal Data in accordance with this DPA and the applicable offboarding provisions.

8.Security Measures

Finday implements security measures designed to protect Customer Personal Data, which may include:

  1. user authentication;
  2. role-based and tenant-based access control;
  3. data separation by company or tenant;
  4. internal access restrictions;
  5. encryption of data in transit using secure protocols;
  6. logging and audit trails;
  7. backup and disaster recovery;
  8. access control over secrets and credentials;
  9. security monitoring;
  10. review of admin and support access;
  11. incident response procedures;
  12. row-level security and/or tenant filters at the application and database levels where relevant.

No system is entirely free of risk. The Customer remains responsible for the security of accounts, devices, networks, credentials, User access, and the Customer's internal configurations.

9.Subprocessors

The Customer grants Finday general written authorization to use the Subprocessors necessary to provide the Services, including the categories of Subprocessors listed in the Finday Privacy Policy.

Finday will ensure that Subprocessors process Customer Personal Data under relevant contractual obligations and only to the extent necessary to support the Services.

Finday may update the list of Subprocessors from time to time. If a change of Subprocessor has a material impact on the processing of Customer Personal Data, Finday will provide reasonable notice. The Customer may submit a reasoned written objection within 15 calendar days after the notice. The parties will endeavor to find a reasonable solution. If no solution is available, the Customer may stop using the affected feature or terminate the Services in accordance with the applicable agreement.

10.Cross-Border Data Transfers

Finday and Subprocessors may process or store Customer Personal Data outside Indonesia where necessary to provide the Services.

If Personal Data is transferred outside the jurisdiction of Indonesia, Finday will apply protection mechanisms in accordance with applicable law, which may include an assessment of the level of protection in the destination country, binding contractual protections, limitation of processing purposes, access controls, Subprocessor due diligence, and notice or consent where required by law.

11.AI Features

If the Customer uses the AI Features, Customer Personal Data, documents, prompts, instructions, metadata, company context, extraction results, transcripts, or feedback may be processed by Finday and AI Subprocessors to the extent necessary to provide the AI Features.

Finday will endeavor to limit the data sent to AI providers to what the feature requires and use configurations that restrict the use of Customer Data for general model training without appropriate permission.

The Customer remains responsible for conducting human review of AI output before journal posting, approvals, payments, payroll, tax filing, exports, filings, or important business decisions.

12.Personal Data Subject Requests

If Finday receives a request from a Personal Data Subject relating to Customer Personal Data processed on behalf of the Customer, Finday may direct the request to the Customer or ask for the Customer's instructions.

Finday will reasonably assist the Customer in fulfilling Personal Data Subject requests to the extent required by law and to the extent the information is available through the Services or Finday's operational support.

13.Personal Data Incidents

If Finday becomes aware of an incident that could reasonably affect the confidentiality, integrity, or availability of Customer Personal Data, Finday will take reasonable steps to identify, contain, assess, mitigate, and document the incident.

Where Finday acts as a Personal Data Processor, Finday will notify the Customer without undue delay after Finday confirms that the incident is relevant to Customer Personal Data. Where reasonably possible, initial notice will be provided within 2 x 24 hours after confirmation of the relevant incident so that the Customer can evaluate its notification obligations under applicable law.

Initial notice may be given in stages and may be updated as additional information becomes available. The notice may include, to the extent known at the time, the types of data affected, when and how the incident occurred, the known impact, and the handling or recovery steps.

14.Compliance Assistance

At the Customer's reasonable request, Finday will provide reasonably available information to help the Customer meet its personal data protection obligations, including in relation to security, Personal Data Subject requests, personal data protection impact assessments, cross-border transfers, and Personal Data incidents.

Assistance that requires additional work, special access, development, custom exports, or support beyond the standard services may be subject to reasonable additional fees if agreed by the parties.

15.Return, Export, and Deletion

While the subscription is active, the Customer is responsible for exporting the Customer Data required for compliance, backup, audit, tax, accounting, payroll, and internal needs.

After the subscription ends, the provisions on export, reactivation, retention, deletion, backups, audit trails, and data that cannot be deleted immediately are governed by the Finday Terms and Conditions, the Finday Privacy Policy, and the applicable written agreement.

After receiving a valid deletion request from a party authorized to represent the Customer, Finday will use reasonable efforts to delete or anonymize Customer Personal Data within 90 calendar days, unless retention is still required or permitted for legal, tax, accounting, payroll, security, dispute, backup, or audit trail purposes or for legitimate business interests.

Data in backups may remain stored until the backup and disaster recovery cycle ends. Such data will not be used for active operations unless required for recovery, security, compliance, or legal obligations.

16.Audit and Information

Finday will provide the information reasonably necessary to demonstrate compliance with this DPA, such as a summary of security controls, a list of Subprocessor categories, related policies, or written responses to reasonable compliance questions.

Direct audits of Finday's systems, facilities, code, or infrastructure may only be carried out with prior written consent, within a reasonable scope, subject to confidentiality protections and security restrictions, and on a schedule that does not disrupt the operations of Finday or other Customers.

17.Confidentiality

Finday will ensure that personnel with access to Customer Personal Data are subject to appropriate confidentiality obligations.

The Customer must keep confidential any security information, technical documentation, reports, or non-public information of Finday received under this DPA.

18.Conflicts and Liability

If there is a conflict between this DPA and the Finday Terms and Conditions regarding the processing of Customer Personal Data by Finday as a Personal Data Processor, this DPA prevails to the extent of that conflict.

The limitations of liability, indemnification, governing law, dispute resolution, and other general provisions in the Finday Terms and Conditions continue to apply to this DPA, unless otherwise stated in writing.