The binding terms under which Fininvo processes personal data on your behalf as your processor, with GDPR, UK GDPR and DPDP safeguards and full Annexes.
July 2, 2026
August 1, 2026
4.0
This document is published by Fininvo, a trade name of Prashbi Global Services Pvt. Ltd., a company incorporated under the laws of India (CIN: U52100KA2020PTC133490), with its registered office at Tholons Tower, 346 HIG, 17th Cross Rd, Dollars Colony, R.M.V. 2nd Stage, Bengaluru, Karnataka 560094, India. References to "Fininvo", "we", "us", or "our" in this document refer to Prashbi Global Services Pvt. Ltd..
Terms not defined here have the meaning given in the Terms of Service or in Applicable Data Protection Law.
| Applicable Data Protection Law | All laws applying to the processing of personal data under this DPA, including the EU GDPR (Regulation 2016/679), the UK GDPR and Data Protection Act 2018, the Swiss FADP, India's Digital Personal Data Protection Act 2023 and DPDP Rules 2025, and the CCPA/CPRA where applicable. |
| Customer Data | All data, including personal data, that you or your users submit to the services. |
| Controller / Processor | As defined in the GDPR. Under the DPDP Act, controller corresponds to Data Fiduciary and processor to Data Processor; those readings apply throughout. |
| SCCs | The Standard Contractual Clauses approved by European Commission Decision 2021/914, as amended or replaced. |
| UK Addendum | The UK International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner. |
| Sub-processor | A third party engaged by Fininvo that processes personal data contained in Customer Data. |
This DPA forms part of the Terms of Service (or your Master Services Agreement, if you have one) and applies whenever Fininvo processes personal data on your behalf in providing the services. You act as the controller (or, where you process on behalf of another controller, as a processor) and Fininvo acts as your processor (or sub-processor). For our own limited processing, such as billing, account administration and security telemetry, we act as an independent controller as described in the Privacy Policy.
Precedence. If this DPA conflicts with the Terms of Service, this DPA prevails for data protection matters. If the SCCs conflict with this DPA, the SCCs prevail. A signed MSA may modify this DPA only where it is at least as protective of personal data.
This DPA applies automatically to all customers, without signature, whenever you use the services to process personal data. A countersigned copy is available (Section 17).
This DPA applies for as long as Fininvo processes personal data on your behalf: for the subscription term plus the post-termination export and deletion window in Section 14. Obligations that by their nature survive (confidentiality, deletion, audit records) survive termination.
The subject matter, duration, nature and purpose of processing, the categories of data subjects and the categories of personal data are set out in Annex I, which forms part of this DPA and completes the corresponding annexes of the SCCs.
We process personal data only on your documented instructions, including with regard to international transfers, unless required otherwise by law to which we are subject; in that case we inform you of the legal requirement before processing, unless the law prohibits it on important grounds of public interest. The parties agree that the Terms of Service, this DPA, your configuration of the services and your use of their features constitute your complete documented instructions. Additional instructions require written agreement. We will inform you if, in our opinion, an instruction infringes Applicable Data Protection Law.
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, we implement and maintain the technical and organisational measures set out in Annex II. We may update those measures from time to time, provided the update does not materially reduce the overall protection of personal data.
You provide general written authorisation for Fininvo to engage sub-processors. The current list, including entity, purpose, location and safeguards, is published at fininvo.com/subprocessors (Annex III).
30 day notice and objection. We update the sub-processor page at least 30 days before a new sub-processor processes personal data, and offer an email subscription for proactive notice. You may object on reasonable, documented data protection grounds within the notice period; if we cannot offer a reasonable alternative, you may terminate the affected subscription with a prorated refund of prepaid unused fees as your exclusive remedy.
The services include controls that let you retrieve, correct, delete, export and restrict personal data, and you are primarily responsible for responding to data subject requests using those controls. If a data subject contacts us directly about data we process on your behalf, we do not respond substantively; we redirect the request to you and notify you promptly. Taking into account the nature of processing, we assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise data subject rights.
Taking into account the nature of processing and the information available to us, we assist you in ensuring compliance with your obligations regarding security of processing, breach notification, data protection impact assessments and prior consultations with supervisory authorities. Assistance beyond the information and tools we already make available (this DPA, the Security page, audit reports and questionnaire responses) may be charged at reasonable rates where the effort is material and specific to your organisation.
We notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting personal data we process on your behalf. To the extent known at the time and as information becomes available, the notice includes:
We cooperate with you and take reasonable steps as directed by you to assist in the investigation, mitigation and remediation. Our notice is not an admission of fault or liability. You are responsible for notifying your supervisory authority and data subjects where required; we assist as described in Section 10.
Where personal data protected by the GDPR, UK GDPR or Swiss FADP is transferred to a country without an adequacy decision, the parties enter into the SCCs, which are incorporated into this DPA by reference and completed as follows:
Transfers of personal data of data principals located in India are made only to countries or territories not restricted by the Central Government under section 16 of the DPDP Act.
We make available to you all information reasonably necessary to demonstrate compliance with this DPA, including summaries of penetration tests, security questionnaire responses and, when available, third-party certification reports (under NDA). Where those materials are not sufficient to meet a legal requirement, you (or an independent auditor bound by confidentiality who is not our competitor) may audit our compliance, subject to: at least 30 days written notice; at most once in any 12 month period, unless a supervisory authority requires more or a material breach has occurred; business hours; no access to other customers' data; and reimbursement of our reasonable costs where the audit exceeds two business days.
During the subscription and for 30 days after termination, you may export Customer Data using the services' export tools. After that window, we delete the personal data we process on your behalf from active systems within 60 days, and from backups as those backups expire in the ordinary rotation cycle (at most 90 further days), except where law requires continued retention, in which case we isolate and protect the data and process it only for that purpose. On written request we confirm deletion.
Each party's liability arising out of or related to this DPA (including the SCCs) is subject to the exclusions and limitations of liability in the Terms of Service or your MSA, except where Applicable Data Protection Law does not permit such limitation for the liability in question.
This DPA is effective without signature. If your procurement or compliance process requires a countersigned copy, use the Download PDF button at the top of this page to save the current version, or email dpo@fininvo.com with your legal entity details and we will return a countersigned PDF, normally within 5 business days.
Data exporter: the customer identified in the account or Order Form (controller, or processor under Module Three). Data importer: Prashbi Global Services Pvt. Ltd. (CIN: U52100KA2020PTC133490), Tholons Tower, 346 HIG, 17th Cross Rd, Dollars Colony, R.M.V. 2nd Stage, Bengaluru, Karnataka 560094, India (processor). Contact: dpo@fininvo.com.
The services are not designed to require special category data. Depending on your configuration and local law you may submit data such as health information (leave records), biometric attendance events, or statutory identifiers. Such data receives the full protections of Annex II; you are responsible for the lawfulness of collecting it.
Hosting, storage, computation, transmission, display, backup and deletion of Customer Data as needed to provide the ERP, HRMS, Payroll, Jobs and Recruit services and related support. Processing is continuous for the subscription term plus the export and deletion window in Section 14. Retention follows Section 14.
TLS 1.2+ (1.3 preferred) for data in transit; AES-256 for data at rest; managed key services with rotation.
Role-based access with least privilege, MFA for administrative access, unique accounts, prompt deprovisioning, quarterly access review.
Logical isolation of every tenant enforced in the application and data layer on every query.
Segmented networks, security groups and firewalls, hardened bastion access, no direct public database exposure.
Secure development lifecycle, code review, dependency and secret scanning in CI, periodic penetration testing.
Centralised audit and security logging, alerting on anomalous access, clock synchronisation.
Automated daily backups with encryption, periodic restore testing, multi-availability-zone deployment, disaster recovery plan.
Inherited from ISO 27001 and SOC 2 certified cloud providers (AWS, Microsoft Azure) data centres.
Confidentiality undertakings, security and privacy training, background verification where lawful.
Documented incident response process with severity classification, 72 hour customer notification, post-incident review.
Purpose-bound retention, deletion workflows for termination and data subject requests, backup expiry within the rotation cycle.
Sub-processor due diligence, contractual flow-down of these measures, transfer safeguards.
Further detail is published on the Security page; enterprise customers may request our security packet under NDA.
The authorised sub-processors, including legal entity, purpose, location of processing and safeguards, are listed at fininvo.com/subprocessors. That page is incorporated into this DPA as Annex III and is kept current under the notice process in Section 8.
Data Protection Officer
dpo@fininvo.comPrivacy Team
privacy@fininvo.comSecurity Team
security@fininvo.comGrievance Officer
grievance@fininvo.comRegistered Office
Prashbi Global Services Pvt. Ltd.
Tholons Tower, 346 HIG, 17th Cross Rd, Dollars Colony,
R.M.V. 2nd Stage, Bengaluru, Karnataka 560094, India
CIN: U52100KA2020PTC133490