Data Processing Addendum
Last updated: August 27, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Springrock Ventures LLC ("Finvo", "we") and the customer agreeing to those Terms ("Customer", "you"). It applies where, in your use of Finvo, you provide us with personal data of your own clients or contacts (for example, the names, email addresses, and postal addresses of invoice recipients). For that data you act as the controller and Finvo acts as your processor. For your own account data, Finvo is the controller — see our Privacy Policy.
1. Scope and roles
We process Customer Personal Data only to provide the Service and only on your documented instructions (which the Terms and your use of the Service constitute), unless required by law, in which case we will notify you unless legally prohibited.
2. Nature of processing
- Subject matter & duration: processing of Customer Personal Data for the duration of your account.
- Purpose: generating, storing, and emailing invoices and related documents on your behalf.
- Types of personal data: recipient/client names, email addresses, postal addresses, and invoice line-item details you enter.
- Categories of data subjects: your clients, customers, and contacts.
3. Our obligations (Art. 28 GDPR)
- Process Customer Personal Data only on your instructions.
- Ensure personnel authorized to process are bound by confidentiality.
- Implement appropriate technical and organizational security measures (Section 6).
- Engage sub-processors only under Section 5 and flow down equivalent data-protection obligations.
- Assist you, taking into account the nature of processing, in responding to data-subject requests (access, erasure, rectification, portability, objection).
- Assist you with security, breach notification, and data protection impact assessments (Art. 32–36).
- Notify you without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data.
- Delete or return Customer Personal Data on termination, and delete existing copies unless retention is required by law (see our retention practices in the Privacy Policy).
- Make available information necessary to demonstrate compliance and allow for reasonable audits.
4. Data-subject requests
You can access, export, correct, and delete Customer Personal Data directly in the Service (including full data export and account deletion). Where you need our help to fulfil a data-subject request you cannot complete yourself, contact privacy@finvo.dev.
5. Sub-processors
You authorize us to engage the sub-processors below. We flow down data-protection obligations to each and remain responsible for their performance. We will give notice of any intended change so you can object.
| Sub-processor | Purpose |
|---|---|
| Stripe, Inc. | Payment processing and subscription billing |
| OVHcloud | Dedicated-server hosting for our application, database, and object storage (self-managed by us) |
| Resend (Plus Five Five, Inc.) | Email delivery (recipient email addresses and invoice PDFs are transmitted when you email an invoice) |
6. Security measures
- Encryption in transit (HTTPS/TLS) for all traffic to the Service.
- Access controls and the principle of least privilege for our infrastructure.
- Passwords hashed with bcrypt; API keys stored as HMAC hashes; secrets not exposed to the client.
- Self-hosted database and object storage on isolated private networks.
- Operational monitoring, backups, and health checks.
7. International transfers
Where Customer Personal Data is transferred outside the EEA or UK, such transfers are made under appropriate safeguards, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, as applicable.
8. Contact
For any matter relating to this DPA, contact privacy@finvo.dev (Springrock Ventures LLC, 2108 N Street STE N, Sacramento, CA 95816, USA).