Skip to content
ProductSourcesCapabilitiesDevelopersPricingTrust
Sign InSee how it works

Legal / dpa-2026-08-12

FINA1 Data Processing Addendum

Processor and service-provider terms governing Customer Personal Data.

Terms of Service↗Privacy Policy
Terms of ServicePrivacy PolicyAcceptable Use PolicyCustomer-Directed Source Access TermsSource Access AttestationData Processing AddendumCopyright and Source Rights PolicySubprocessor List

Effective Date: August 12, 2026 Version: dpa-2026-08-12

This Data Processing Addendum (“DPA”) forms part of the agreement governing Customer’s use of the FINA1 Service (“Agreement”) and applies when FINA1 processes Customer Personal Data on Customer’s behalf.

“FINA1” means the FINA1 legal entity identified as the service provider in the Agreement. “Customer” means the customer identified in the Agreement. Capitalized terms not defined here have the meanings given in the Agreement.

1. Definitions

For this DPA:

  • “Applicable Data Protection Law” means privacy and data-protection law applicable to the processing, including where applicable the EU General Data Protection Regulation 2016/679 (“EU GDPR”), the UK GDPR and Data Protection Act 2018 as amended, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), and other applicable U.S. state privacy laws.
  • “Customer Personal Data” means personal data, personal information, or equivalent regulated information contained in Customer Data that FINA1 processes on Customer’s behalf in connection with the Service.
  • “Controller”, “Processor”, “Business”, “Service Provider”, “Sell”, “Share”, “Personal Data”, “Personal Information”, “Processing”, and “Data Subject” have the meanings given by Applicable Data Protection Law.
  • “Security Incident” means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by FINA1. Security Incident does not include unsuccessful attempts that do not compromise Customer Personal Data.
  • “Subprocessor” means a third party engaged by FINA1 to process Customer Personal Data on Customer’s behalf.

2. Roles and scope

As between the parties, Customer is the Controller or Business and FINA1 is the Processor or Service Provider with respect to Customer Personal Data processed under Customer’s documented instructions.

Each party will comply with Applicable Data Protection Law applicable to its role. Customer is responsible for determining the lawfulness of its instructions, providing required notices, obtaining required consents or other legal bases, and ensuring that Customer has authority to disclose Customer Personal Data to FINA1 and direct its processing.

FINA1 may act as an independent Controller for account administration, security, billing administration, legal compliance, and other processing described in the FINA1 Privacy Policy. Such independent-controller processing is outside the processor obligations in this DPA.

3. Processing instructions

FINA1 will process Customer Personal Data only:

  1. to provide, secure, support, and maintain the Service under the Agreement;
  2. in accordance with Customer’s documented instructions, including authenticated configuration and requests submitted through the Service;
  3. as necessary to comply with applicable law; or
  4. as otherwise expressly agreed in writing.

If FINA1 is required by law to process Customer Personal Data contrary to Customer’s instructions, FINA1 will notify Customer before the processing unless legally prohibited.

FINA1 will promptly inform Customer if, in FINA1’s reasonable judgment, an instruction infringes Applicable Data Protection Law, and may suspend the affected processing while the parties address the issue.

Customer will not instruct FINA1 to process data in a manner prohibited by the Agreement or Acceptable Use Policy.

4. Confidentiality

FINA1 will ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations and receive access only to the extent reasonably necessary for their duties.

5. Security measures

FINA1 will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, implementation costs, nature and scope of processing, and risks to individuals.

The security measures include the controls described in Annex II. FINA1 may update those measures provided the overall level of security is not materially reduced.

Customer is responsible for secure configuration and use of the Service, including management of its users, roles, devices, API keys, MCP credentials, customer-bound Source credentials, and integrations.

6. Subprocessors

Customer grants FINA1 general authorization to engage Subprocessors to process Customer Personal Data in accordance with this DPA.

FINA1 will:

  • maintain a current list of material Subprocessors;
  • impose data-protection obligations on each Subprocessor that are no less protective in material respects than those applicable to the relevant processing under this DPA;
  • remain responsible for the Subprocessor’s performance of its data-protection obligations to the extent required by Applicable Data Protection Law; and
  • provide notice of a new material Subprocessor before that Subprocessor begins processing Customer Personal Data when required by Applicable Data Protection Law or the Agreement.

Customer may object to a new Subprocessor on reasonable documented data-protection grounds by notifying FINA1 within 15 days after notice. The parties will work in good faith to address the objection. If no commercially reasonable alternative is available, either party may terminate the affected Service without penalty for the unused prepaid portion attributable to that affected Service.

Current material Subprocessors are listed in the FINA1 Subprocessor List.

7. Data-subject requests

Taking into account the nature of processing, FINA1 will provide reasonable assistance through appropriate technical and organizational measures to help Customer respond to requests from Data Subjects to exercise rights under Applicable Data Protection Law.

If FINA1 receives a request directly concerning Customer Personal Data for which Customer is Controller or Business, FINA1 will, where legally permitted, direct the requester to Customer or notify Customer and will not independently respond except as authorized by Customer or required by law.

Customer is responsible for responding to requests and determining whether a request is valid.

8. Assistance with compliance

Taking into account the nature of processing and information available to FINA1, FINA1 will provide reasonable assistance to Customer with obligations relating to:

  • security of processing;
  • Security Incident notification;
  • data-protection impact assessments;
  • prior consultation with supervisory authorities; and
  • reasonable information required to demonstrate compliance with processor obligations.

Assistance requiring material work beyond ordinary Service functionality may be subject to reasonable fees agreed in advance, unless the need for assistance results from FINA1’s breach of this DPA.

9. Security Incidents

FINA1 will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data and, where practicable, within 48 hours after confirmation.

The notice will include information reasonably available to FINA1 concerning:

  • the nature of the Security Incident;
  • categories of affected data and Data Subjects where known;
  • likely consequences where reasonably ascertainable;
  • measures taken or proposed to contain, investigate, and remediate the incident; and
  • a contact point for follow-up.

FINA1 may provide information in phases as the investigation develops. Notification is not an admission of fault or liability.

Customer is responsible for determining whether notification to individuals, regulators, or other parties is required.

10. Deletion and return

During the Agreement, Customer may use available Service functionality to access or export Customer Data where supported.

After termination or expiration of the applicable Service, FINA1 will delete or return Customer Personal Data in accordance with Customer’s documented instruction, unless applicable law requires retention. Unless otherwise stated in an Order Form:

  • active-system deletion is scheduled within 30 days after the data is no longer required;
  • routine backups age out within 35 days after deletion from active systems; and
  • legal holds, security investigations, tax/accounting obligations, and immutable records required for legal defense may be retained for the applicable lawful period with access restricted to the relevant purpose.

Provider response payloads are not persistently stored by default, and persistent provider caching is disabled by default.

11. Audits and compliance information

FINA1 will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant policies, security summaries, independent reports or certifications if available, and responses to reasonable security questionnaires.

No more than once in any 12-month period, unless required by a regulator or following a material Security Incident, Customer may request an audit reasonably necessary to verify FINA1’s compliance. Audits will:

  • be subject to reasonable advance notice;
  • occur during normal business hours;
  • avoid access to other customers’ data, FINA1 trade secrets, or information that would create security risk;
  • use existing independent reports and remote review before on-site inspection where those materials reasonably address the request; and
  • be conducted at Customer’s expense unless the audit identifies a material breach by FINA1.

Any auditor must be independent, appropriately qualified, and bound by confidentiality obligations.

12. U.S. state privacy-law terms

To the extent CCPA or another U.S. state privacy law applies to FINA1’s processing of Customer Personal Data as a Service Provider, Contractor, or Processor:

  1. FINA1 will process Customer Personal Data only for the limited and specified purposes described in the Agreement and Customer’s documented instructions.
  2. FINA1 will not Sell or Share Customer Personal Data.
  3. FINA1 will not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for a commercial purpose other than the business purposes and services specified in the Agreement, except as permitted by Applicable Data Protection Law.
  4. FINA1 will not combine Customer Personal Data with personal information received from another person or collected from FINA1’s own consumer interaction except as permitted by law for a Service Provider or Contractor.
  5. FINA1 will provide the same level of privacy protection required of the applicable role under law.
  6. FINA1 will notify Customer if FINA1 determines it can no longer meet an applicable statutory obligation.
  7. Customer may take reasonable and appropriate steps to help ensure FINA1’s use is consistent with Customer’s obligations and, upon notice of unauthorized use, to stop and remediate that use.

13. International transfers

13.1 EEA transfers

Where Customer transfers Customer Personal Data subject to the EU GDPR to FINA1 in a country not recognized as providing an adequate level of protection and no other lawful transfer mechanism applies, the parties incorporate the European Commission Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (“EU SCCs”) as follows:

  • Module Two (Controller to Processor) applies where Customer is a Controller and FINA1 is a Processor;
  • Module Three (Processor to Processor) applies where Customer is a Processor and FINA1 is a Subprocessor;
  • Clause 7 (Docking Clause) applies;
  • in Clause 9, Option 2 (general written authorization) applies and the notification period is 15 days;
  • in Clause 11, the optional independent dispute-resolution language does not apply;
  • for Module Two or Three, the time period in Clause 17 is governed by the law of Ireland to the extent the SCCs require law of an EU Member State permitting third-party beneficiary rights;
  • under Clause 18, the courts of Ireland are selected; and
  • Annexes I through III of the EU SCCs are completed by the corresponding information in this DPA and the FINA1 Subprocessor List.

Nothing in the Agreement modifies the EU SCCs in a manner that reduces protections or conflicts with the SCCs.

13.2 UK transfers

For a restricted transfer subject to UK data-protection law where no other lawful transfer mechanism applies, the EU SCCs as completed above are supplemented by the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, template Addendum B.1.0 issued by the UK Information Commissioner and laid before Parliament on February 2, 2022, as revised under its mandatory-clause update mechanism (“UK Addendum”).

The parties incorporate the UK Addendum’s mandatory clauses by reference. The parties and selected modules are those identified in this DPA; the processing and security information is contained in Annexes I and II; and either party may end the UK Addendum to the extent the approved Addendum permits termination following an official revision.

Where UK law requires a transfer-risk assessment or equivalent data-protection test, the initiating party remains responsible for completing it, and FINA1 will provide reasonable information available to it for that assessment.

13.3 Other jurisdictions

If Applicable Data Protection Law requires another transfer mechanism, the parties will reasonably cooperate to implement a valid mechanism without reducing the protections in this DPA.

14. Government requests

Unless prohibited by law, FINA1 will notify Customer before disclosing Customer Personal Data in response to binding legal process. FINA1 will review requests for facial validity and scope and, where appropriate and legally permitted, seek clarification, narrowing, or protective treatment.

FINA1 will not voluntarily provide Customer Personal Data to a governmental authority except where necessary to protect rights or safety, address an emergency, comply with sanctions or export controls, or as otherwise permitted by law and the Agreement.

15. Special categories, regulated data, and children

The Service is not designed to require special-category data, protected health information subject to HIPAA, payment-card data requiring FINA1 to act as the card-data merchant processor, government-issued identity documents, biometric identifiers, children’s data, or other highly regulated personal data unless FINA1 expressly agrees in a written Order Form or product specification.

Customer will not intentionally submit such data unless the Agreement expressly authorizes the relevant category and required safeguards are in place.

16. Liability and precedence

The liability provisions of the Agreement apply to this DPA except to the extent prohibited by Applicable Data Protection Law or the EU SCCs/UK Addendum.

If there is a conflict between this DPA and the Agreement regarding processing of Customer Personal Data, this DPA controls. If there is a conflict between this DPA and mandatory provisions of the EU SCCs or UK Addendum for a covered transfer, those mandatory provisions control.

17. Duration

This DPA takes effect when the Agreement becomes effective and remains in force for as long as FINA1 processes Customer Personal Data on Customer’s behalf.


Annex I — Processing Details

A. Parties

Data exporter / Customer: The Customer identified in the Agreement. Contact details are those maintained in the applicable Order Form or Customer account. Customer is Controller or Processor as applicable.

Data importer / FINA1: The FINA1 legal entity identified as service provider in the Agreement. Contact details are those identified in the Agreement or FINA1 legal/contact section. FINA1 is Processor or Subprocessor as applicable.

B. Subject matter and duration

Processing necessary to provide, secure, administer, support, and maintain the Service for the duration of the Agreement and the limited post-termination retention periods described in this DPA.

C. Nature and purpose

  • authentication and organization administration;
  • API and MCP request processing;
  • customer-directed Source access;
  • normalization and provenance generation;
  • entitlement, rate-limit, and usage enforcement;
  • support and security operations;
  • transactional communications; and
  • other processing documented in the Agreement or authenticated Customer instructions.

D. Categories of Data Subjects

  • Customer users, administrators, developers, and personnel;
  • Customer’s clients, counterparties, contacts, or other individuals whose data Customer instructs FINA1 to process;
  • individuals whose personal data may appear in Customer-directed Source results; and
  • other Data Subjects identified in Customer’s documented instructions.

E. Categories of Customer Personal Data

  • identifiers and business contact information;
  • account, organization, role, and authorization information;
  • device, network, authentication, and security metadata;
  • request, usage, provenance, and audit metadata;
  • customer-provided queries and parameters;
  • customer-bound Source credential data where configured; and
  • third-party Source data processed transiently at Customer’s direction.

F. Sensitive data

No sensitive or special-category data is intentionally required. If such data appears incidentally in an authorized Source response, it is subject to the same security controls and the default no-persistent-payload-storage rule. Deliberate recurring processing requires written authorization where legally required.

G. Frequency

Continuous or intermittent according to Customer’s use of the Service.

H. Retention

As described in the FINA1 Privacy Policy, this DPA, the applicable Order Form, and Customer’s documented instructions.


Annex II — Technical and Organizational Measures

FINA1’s baseline controls include, as appropriate to the relevant processing:

  1. Access control: role-based access, least privilege, tenant-scoped authorization, restricted administrative access, and authenticated customer operations.
  2. Tenant isolation: database row-level security and server-controlled authorization boundaries for customer-scoped data.
  3. Authentication: secure hosted authentication, verified session claims, protected server-side routes, credential rotation and revocation capabilities.
  4. Service-to-service identity: request-scoped workload identity and authenticated control-plane boundaries rather than shared browser-trusted administrative credentials.
  5. Encryption: encryption in transit and infrastructure-supported encryption at rest.
  6. Secrets management: isolated Vault-backed storage for retrievable customer Source credentials; verifier hashing where retrieval is unnecessary; no cross-customer credential sharing.
  7. Logging hygiene: exclusion of secrets, tokens, cookies, authorization headers, and provider payload bodies from ordinary request-history and audit logs.
  8. Data minimization: metadata-only request history by default; provider payload persistence disabled by default; persistent provider cache disabled by default.
  9. Software security: dependency locking, automated testing, type checking, secret scanning, security validation, and controlled CI/CD.
  10. Availability and recovery: managed cloud infrastructure, backup and recovery processes, bounded rollback capability, and operational monitoring appropriate to the Service.
  11. Incident response: documented investigation, containment, remediation, evidence preservation, and notification processes.
  12. Personnel and vendor controls: confidentiality obligations and contractual security/data-protection requirements for material service providers.
  13. Deletion controls: authenticated account/data workflows, purpose-based retention, scheduled active-system deletion, and bounded backup lifecycle.
  14. Change control: versioned policy and schema changes, auditable repository history, and protected deployment workflows.

Annex III — Subprocessors

The current material Subprocessors are listed in the FINA1 Subprocessor List, which is incorporated into this DPA. The Subprocessor List identifies the provider, purpose, relevant data categories, and primary processing location where known.

FINA1 is the public-facing technology company. ZENITH by FINA1 is its flagship secure API and MCP platform.

Production. Production customer identity and control-plane infrastructure are available. Billing and Source execution remain independently policy- and configuration-gated.

Explore

ProductSourcesCapabilitiesPricing

Build

DevelopersMCPIdeas & RequestsRequest an API

Assurance

SecurityTrustStatusResponsible Disclosure

FINA1

AboutContactPrivacyTermsAcceptable UseSource Access Terms
© 2026 FINA1. Controlling legal documents effective August 12, 2026.Every Source. One Zenith.