Data Processing Agreement
Effective: 1 January 2025 · Governed by: GDPR Article 28 · Entity: Neufin OÜ (Estonia)
1. Parties and Scope
This Data Processing Agreement (“DPA”) is entered into between Neufin OÜ, registered in Estonia (EU) (“Processor”), and the enterprise customer identified in the Order Form or API agreement (“Controller”).
This DPA forms part of, and is governed by, the NeuFin Terms of Service and applies to all Personal Data processed by Neufin OÜ on behalf of the Controller through the NeuFin platform, APIs, and related services.
2. Nature of Processing
The Processor processes Personal Data solely to provide the NeuFin portfolio intelligence services contracted by the Controller. This includes:
- Portfolio analysis and behavioral DNA scoring
- Swarm IC multi-agent analysis
- PDF report generation
- API authentication and rate-limiting
- Session management and audit logging
The Processor does not use Controller's Personal Data to train AI models or for any purpose beyond service delivery.
3. Types of Personal Data
- Email addresses and name (authentication)
- Portfolio holdings (positions, weights, values)
- IP addresses and session identifiers
- Usage logs and API call records
No special category data (Article 9 GDPR) is collected or processed.
4. Processor Obligations
- Process Personal Data only on documented instructions from the Controller
- Ensure persons authorised to process are bound by confidentiality
- Implement appropriate technical and organisational security measures (see Section 6)
- Assist the Controller with data subject rights requests within 30 days
- Delete or return all Personal Data upon termination, at Controller's election
- Make available all information necessary to demonstrate compliance and allow for audits
5. Sub-processors
The Processor engages the following sub-processors. The Controller authorises these engagements:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database & auth | EU (Germany) |
| Railway Corp. | Backend compute | US / EU |
| Vercel Inc. | Frontend hosting | US / EU (edge) |
| Anthropic PBC | AI inference | United States |
| OpenAI LLC | AI inference (fallback) | United States |
| Stripe Inc. | Payment processing | United States |
The Processor will notify the Controller at least 14 days before adding or replacing sub-processors.
6. Technical and Organisational Measures
- TLS 1.3 encryption in transit on all connections
- AES-256 encryption at rest for all stored data
- Row-level security isolating each customer's data
- Role-based access controls with principle of least privilege
- Automated backups with 30-day retention
- Annual penetration testing
- SOC 2 Type II audit in progress (target: Q3 2026)
7. International Transfers
Where Personal Data is transferred to sub-processors outside the EU/EEA (Anthropic, OpenAI, Stripe, Vercel US edge), such transfers are governed by Standard Contractual Clauses (SCCs) as adopted by the European Commission.
8. Data Breach
The Processor will notify the Controller without undue delay, and no later than 72 hours after becoming aware, of any Personal Data breach. Notification will include the nature of the breach, categories and number of data subjects affected, likely consequences, and measures taken to address the breach.
9. Contact
Data Protection Officer: legal@neufin.ai
Neufin OÜ · Harju maakond, Tallinn, Kesklinna linnaosa, Vesivärva tn 50-201, 10152 · Estonia
To request a countersigned copy of this DPA for your enterprise contract, email legal@neufin.ai.