Data Processing Addendum

Last updated: Sept 24, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service, Master Subscription Agreement, or other written agreement governing Customer's access to and use of the Services, as applicable (the "Agreement"), between Authlayer, Inc., operating the Finlens platform ("Processor" or "Finlens"), and the customer that is party to the Agreement ("Controller" or "Customer"). This DPA governs Finlens's Processing of Customer Personal Data on Customer's behalf in connection with the Services. If there is a conflict between this DPA and the Agreement concerning the Processing of Customer Personal Data or other data-protection matters, this DPA controls.

For online and self-serve subscriptions, this DPA is incorporated into and accepted together with the applicable Terms of Service and does not require a separate signature. For subscriptions governed by a signed Order Form, Master Subscription Agreement, or other written agreement, this DPA is incorporated into that Agreement. Except as otherwise provided in Section 6, the terms of this DPA are fixed as of the applicable Effective Date. Annex III (Subprocessors) is maintained at https://www.finlens.app/dpa and may be updated in accordance with Section 6.

‍

1. Definitions

Capitalized terms not defined here have the meaning given in the Agreement.

"Applicable Data Protection Law" means all U.S. laws and regulations applicable to the Processing of Customer Personal Data under this DPA, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (the "CCPA"), the Gramm-Leach-Bliley Act and its Safeguards Rule ("GLBA"), and other applicable U.S. state privacy laws.

"Business," "Service Provider," "Consumer," "Personal Data," "Processing," "Sell," "Share," and "Personal Data Breach" have the meanings given under Applicable Data Protection Law. "Controller" and "Processor" refer, respectively, to the Business and the Service Provider.

"Customer Personal Data" means the subset of Customer Data that is Personal Data and that Finlens Processes solely as a Service Provider on Customer's behalf. Customer Personal Data does not include Account Data, which the parties Process as independent controllers under the Agreement.

"Services" means the Subscription Services under the Agreement.

"Subprocessor" means a third party engaged by Finlens to Process Customer Personal Data. Customer-authorized Connected Services are not Subprocessors.

2. Roles and Scope

2.1 Roles. As between the parties, Customer is the Controller (Business) and Finlens is the Processor (Service Provider) with respect to Customer Personal Data. Where Customer connects or submits data belonging to its own clients, Customer acts as the controlling party for that data as between the parties. For data Finlens Processes for its own business purposes, such as account administration and billing (Account Data), Finlens acts as an independent controller, and that Processing is outside the scope of this DPA and addressed in the Agreement, including Section 5.9.

2.2 Scope. This DPA applies to the Processing of Customer Personal Data by Finlens on Customer's behalf as described in Annex I.

2.3 Compliance. Each party will comply with its obligations under Applicable Data Protection Law.

2.4 Data Residency. Customer Personal Data is hosted and stored on infrastructure located in the United States.

3. Processing of Personal Data

3.1 Documented Instructions. Finlens will Process Customer Personal Data only on Customer's documented instructions, unless required otherwise by law, in which case Finlens will inform Customer before Processing unless the law prohibits it. The Agreement, this DPA, and Customer's configuration and use of the Services are Customer's complete and documented instructions.

3.2 Lawfulness. Customer is responsible for the lawfulness of Customer Personal Data and for having an appropriate legal basis to provide it to Finlens for Processing.

3.3 Service Provider Commitments (CCPA). Finlens will not Sell or Share Customer Personal Data, and will not retain, use, or disclose it except as necessary to perform the Services, for the specific business purposes set out in the Agreement and Annex I, or as otherwise permitted by Applicable Data Protection Law. Finlens will not retain, use, or disclose Customer Personal Data outside the direct business relationship between the parties, and will not combine it with Personal Data from other sources except as permitted under Applicable Data Protection Law. Finlens certifies that it understands and will comply with these restrictions. Finlens will notify Customer if it determines it can no longer meet its obligations under Applicable Data Protection Law, and Customer may take reasonable steps to stop and remediate unauthorized Processing.

3.4 Details of Processing. The subject matter, duration, nature, and purpose of the Processing, the types of Personal Data, and the categories of data subjects are set out in Annex I.

4. Confidentiality

Finlens will ensure that personnel authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations and Process such data only as necessary to provide the Services.

5. Security

5.1 Security Measures. Finlens will implement and maintain the technical and organizational measures set out in Annex II, designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure or access.

5.2 Evolution of Measures. The measures in Annex II are subject to technical progress. Finlens may update them provided the updates do not materially reduce the overall level of security of the Services.

6. Subprocessors

6.1 General Authorization. Customer authorizes Finlens to engage Subprocessors to Process Customer Personal Data. The current Subprocessors are listed in Annex III, maintained at https://finlens.app/dpa 

6.2 Subprocessor Obligations. Finlens will impose data-protection obligations on each Subprocessor that are substantially similar to those in this DPA by written contract, and remains responsible for each Subprocessor's performance of its obligations. This Section 6.2 does not apply to customer-authorized Connected Services — the financial-data integrations that Customer elects to connect and may disconnect, identified under "Financial-Data Integrations (Customer-Authorized)" in Annex III — which are Third Party Products addressed in Sections 1.4 and 7.1 of the Agreement and used at Customer's direction.

6.3 Changes. Finlens will notify Customer of any intended addition or replacement of a Subprocessor at least 30 days in advance by updating the subprocessor list at https://finlens.app/dpa; Customer may object on reasonable data-protection grounds within the 30-day period.

6.4 Objection. If Customer objects on reasonable data-protection grounds, the parties will work in good faith to resolve the objection. Consent is not required for Finlens to engage a Subprocessor. If the objection cannot be resolved, Customer's sole remedy is to terminate the affected Service for a pro-rata refund of pre-paid, unused Fees for that Service.

7. Assistance to Customer

7.1 Consumer and Data-Subject Requests. Taking into account the nature of the Processing, Finlens will assist Customer by appropriate technical and organizational measures, insofar as reasonably possible, to respond to requests from Consumers or data subjects exercising their rights under Applicable Data Protection Law, and will use reasonable efforts to provide such assistance within a timeframe that allows Customer to meet its legal deadlines. If Finlens receives such a request directly, it will, where permitted, direct the requester to Customer.

7.2 Assessments. Finlens will provide reasonable assistance to Customer with data-protection assessments and consultations with regulators required under Applicable Data Protection Law, taking into account the information available to Finlens.

8. Personal Data Breach

8.1 Notification. Finlens will notify Customer without undue delay, and no later than 72 hours after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.

8.2 Contents. The notification will include, to the extent known and as it becomes available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and the name and contact details of a Finlens point of contact.

8.3 Cooperation. Finlens will take reasonable steps to mitigate the effects of the breach and will cooperate with Customer's reasonable requests. Notification is not an admission of fault.

9. Compliance Information

9.1 Finlens will make available to Customer information reasonably necessary to demonstrate its compliance with this DPA, by providing its then-current security documentation, including Annex II, responses to a reasonable security questionnaire, and, if and when obtained, its then-current third-party audit report or certification.

9.2 The information in Section 9.1 may be requested no more than once in any 12-month period (except where required by a regulator or following a Personal Data Breach affecting Customer Personal Data), on reasonable prior written notice, and is Finlens's Confidential Information. This DPA does not grant Customer or any third party the right to conduct on-site inspections or audits of Finlens's facilities, systems, or personnel.

10. Return and Deletion

10.1 On termination or expiry of the Agreement, and at Customer's choice made within 30 days after the effective date of termination or expiry, Finlens will delete or return Customer Personal Data and delete existing copies, except as required by law and except for derived data as described in Section 3.4 of the Agreement. This Section is implemented in accordance with Section 3.4 of the Agreement.

10.2 Connection-Level Deletion. When Customer disconnects an individual integration without deleting its account, Finlens terminates that connection's access and does not fetch new data to it its active production systems promptly after disconnection.

10.3 Backups. Deletion from backups occurs within 30 days of deletion from active production systems, consistent with Section 3.4.5 of the Agreement.

11. Liability

Each party's liability under or in connection with this DPA is subject to the exclusions and limitations of liability in the Agreement. As provided in Section 5.8 of the Agreement, this DPA forms part of the Agreement, and the Limitation of Liability in Section 9 of the Agreement applies to all claims under or in connection with this DPA.

12. Term

This DPA takes effect on the Effective Date and continues until the Agreement terminates or expires, after which the obligations in Section 10 apply.

Annex I — Details of Processing

Subject matter: Finlens's provision of the financial-management Services to Customer.

Duration: The term of the Agreement, plus the period until deletion or return under Section 10.

Nature and purpose: Hosting, organizing, consolidating, analyzing, and synchronizing Customer's banking, accounting, spend, and payments data to provide financial-management functionality, including journal-entry and ledger generation, transaction categorization, and AI-assisted analysis.

Categories of data subjects:

- Customer's Authorized Users and their personnel and administrators.

- Customer's own customers, vendors, and counterparties whose details appear in financial records (for example, on invoices, bills, and transactions).

Categories of Personal Data:

- Financial data: transactions, bills, invoices, ledgers, chart of accounts, fixed assets, balances, and related counterparty (customer or vendor) details.

- Connected-account metadata from Customer-authorized integrations.

Account and user identity data (such as an Authorized User's name, email address, phone number, and role) that Finlens Processes to administer the Customer account is handled by Finlens as an independent controller and is outside the scope of this DPA. Finlens does not store full payment card numbers or banking login credentials directly; banking connectivity is handled by integration Subprocessors.

Special categories of Personal Data: None. Special-category data constitutes Excluded Data that Customer is prohibited from submitting under Section 1.5 of the Agreement.

Frequency of Processing: Continuous, for the duration of the Agreement.

Annex II — Technical and Organizational Measures

1. Access control and authentication.

- User authentication is delegated to a specialized identity provider; Finlens does not store user passwords. Breached-password and weak-password detection are enforced through the identity provider.

- Sessions are validated against the identity provider on each protected request.

- Role-based access control (Owner, Admin, Accountant, Viewer) gates sensitive operations through a layered chain of access checks on API requests.

- Internal administrative endpoints are segregated from customer-facing endpoints and restricted to authorized Finlens personnel.

2. Tenant isolation.

- A hierarchical tenant model (Organization → Workspace → User) is enforced at the application layer. Workspace membership is verified before workspace data is accessed, and database queries and cached responses are scoped per workspace.

3. Encryption.

- In transit: TLS/HTTPS for communication between clients and the Services. Connections between the application and its databases traverse a private, non-public network rather than the public internet.

- At rest: Customer Data is encrypted at rest. The primary database runs on a managed cloud service with encryption-at-rest enabled, and uploaded files are stored in encrypted managed cloud object storage.

- Network isolation: the production database is deployed within a private virtual private cloud and is not accessible from the public internet.

4. Application security.

- Input validation against defined schemas, with rejection of invalid input.

- Distributed rate limiting, with stricter limits on authentication endpoints.

- Cryptographic signature verification of inbound webhooks from QuickBooks and Stripe.

- A global exception handler that returns generic errors without exposing internal details.

- Time-limited signed URLs for access to uploaded documents.

5. Logging, monitoring, and auditability.

- Centralized structured application logging.

- Error and performance monitoring.

- Application-level audit trails recording security events (such as sign-in, log-in and log-out, and role changes) and financial events (such as record creation and deletion and integration connect and disconnect), including actor, action, and timestamp, queryable per workspace.

6. Backups.

- Automated daily backups of the primary database, encrypted at rest, retained for 30 days and then purged in the ordinary course.

7. Environment separation.

- Production, staging, and development run as separate environments.

Annex III — List of Subprocessors

This Annex is maintained at https://finlens.app/dpa  and shall be automatically updated when changes are made to the Annex as shown on such site.  This Annex lists Subprocessors that Process Customer Personal Data. Finlens's application infrastructure and primary data storage are hosted in the United States.

Subprocessor Purpose Processing location
Hosting and infrastructure
Google Cloud Platform Application hosting; primary database; file and document storage United States
Amazon Web Services Vector storage and supplemental object storage; inbound email United States (us-east-1; us-west-1)
Webflow Frontend and static hosting United States
Digital Ocean Application hosting; primary database; file and document storage United States
Cloudflare Cloud Infrastructure and Abuse Detection United States
Authentication
Stytch Authentication and session management United States
AI and document processing
OpenAI Transaction and invoice categorization; AI assistance United States
Anthropic AI query analysis and natural-language financial queries United States
Voyage AI Text embeddings for auto-categorization United States
Qdrant Vector storage for similarity search United States
Extend Document and data extraction in reconciliation United States
Taggun Receipt and document OCR United States
Communications, analytics, and monitoring
Resend Transactional and onboarding email United States
Atlas Customer support and helpdesk United States
Slack Optional customer-authorized notifications United States
Sentry Error and performance monitoring United States
Better Stack Centralized application logging United States
PostHog Product analytics United States

‍

Financial-Data Integrations (Customer-Authorized)

The following are Third Party Products that Customer authorizes and connects (for example, via OAuth) and may disconnect at any time; data flows through them only at Customer's direction, and each is governed by its provider's own terms. They are listed here for transparency. Consistent with Sections 7.1 and 8.2 of the Agreement, Finlens is not responsible for the acts or omissions of these Connected Services, and Section 6.2 of this DPA does not apply to them.

Integration Purpose Processing location
Plaid Bank-account linking and transaction import United States
Intuit (QuickBooks Online) Accounting-data synchronization United States
Stripe Payments and revenue-data synchronization United States

‍

AI subprocessor data use — no model training. Finlens does not use Customer Data to train, improve, or develop any AI or machine-learning models. Finlens's AI Providers, OpenAI and Anthropic, are engaged under their standard commercial API Terms of Service, which provide that Customer Data submitted via the API is not used to train the provider's models; those providers process Customer Data to provide their services and for their own limited operational purposes (such as abuse detection, security, and legal compliance) and may retain it for a limited period for those purposes. Finlens has not opted into any use of Customer Data for model training.

Journal-entry generation. Finlens generates journal entries and ledger postings within its own infrastructure as a deterministic computation, transmitting no Customer Data to any third party for that step. AI Subprocessors are used only in a separate, upstream transaction-categorization step, or when used by the Customer by interacting with "Fin AI" whose output is a category that is then consumed internally by the journal-entry computation.

Signatures

For online and self-serve subscriptions, this DPA is accepted with the Agreement and requires no signature. For subscriptions under a signed Master Subscription Agreement:

CUSTOMER — By: __________ Name: __________ Title: __________ Date: __________

AUTHLAYER, INC. ("Finlens") — By: __________ Name: __________ Title: __________ Date: __________

‍

If you have any questions about this Privacy Policy, please contact us:

By email: support@finlens.app