Data Processing Agreement
Last updated: 22 August 2026
This agreement forms part of our Terms of Service and applies where CFO Pal processes personal data on your behalf. It is written to be read by a compliance officer, not skimmed.
This DPA forms part of and supplements the CFO Pal Terms of Service between CFO PAL LTD ("Processor") and the Customer ("Controller"). By accepting the Terms of Service, both parties are deemed to have entered into this DPA.
Where there is any inconsistency, the order of precedence is: (1) the UK Addendum or Standard Contractual Clauses where applicable, (2) this DPA, (3) the Terms of Service.
1. Definitions
"UK GDPR", "EU GDPR", "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in applicable data protection law.
"Applicable Data Protection Law" means the UK GDPR, the Data Protection Act 2018, and, where relevant, the EU GDPR.
"Customer Personal Data" means personal data contained within data the Controller imports into or generates within the Service.
2. Roles
2.1 The Controller is the controller of Customer Personal Data. The Processor is the processor.
2.2 Where the Controller is an accounting practice processing data on behalf of its own clients, the Controller warrants that it has authority from those clients to appoint the Processor as a sub-processor and to enter into this DPA.
3. Scope of processing
Subject matter: provision of the CFO Pal financial management, reporting and forecasting platform.
Duration: for the term of the Terms of Service, plus the retention period set out in clause 9.
Nature and purpose: importing, storing, structuring, analysing, computing, reporting on and displaying financial data; generating forecasts, budgets, board packs, alerts and AI-assisted commentary.
Aggregation: the Processor may operate an automated process that derives aggregated statistics from Customer Data for the purposes of operating, analysing and improving the Service. That process writes only aggregated values to a separate data store; no Customer Personal Data is written to, or retained in, that store. Aggregation applies minimum cohort thresholds and suppression of small samples such that the resulting output is anonymous and no longer personal data. In respect of that anonymous output the Processor acts as a controller in its own right, as permitted by clause 5.6 of the Terms of Service. The Controller may opt out at any time, and on opting out no further contribution is made.
Types of personal data: names, business contact details and financial transaction details of the Controller's customers, suppliers, employees and directors, as contained in invoices, ledgers and accounting records.
Categories of data subject: the Controller's customers, suppliers, employees, directors and, where the Controller is an accounting practice, the equivalent individuals of its client businesses.
Special category data: none is required or intended. The Controller must not upload special category data.
4. Processor obligations
The Processor shall:
4.1 Process Customer Personal Data only on the Controller's documented instructions, which include the Terms of Service and use of the Service by authorised users, unless required otherwise by law, in which case it will notify the Controller unless legally prohibited.
4.2 Ensure personnel authorised to process Customer Personal Data are bound by confidentiality obligations and receive appropriate data protection training.
4.3 Implement and maintain the technical and organisational measures set out in Annex 1.
4.4 Not engage a sub-processor without complying with clause 5.
4.5 Taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures in responding to data subject rights requests.
4.6 Assist the Controller in complying with its obligations regarding security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of processing and the information available to the Processor.
4.7 At the Controller's choice, delete or return Customer Personal Data at the end of the provision of services, in accordance with clause 9.
4.8 Make available all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits in accordance with clause 8.
4.9 Immediately inform the Controller if, in its opinion, an instruction infringes Applicable Data Protection Law.
5. Sub-processors
5.1 The Controller grants general authorisation for the Processor to engage the sub-processors listed at cfopal.co.uk/subprocessors.
5.2 The Processor will give at least 30 days' notice of any intended addition or replacement of a sub-processor, by updating that page and, where the Controller has subscribed to notifications, by email.
5.3 The Controller may object on reasonable data protection grounds within 30 days. The parties will work in good faith to resolve the objection. If it cannot be resolved, the Controller may terminate the affected part of the Service without penalty for the remainder of the paid term.
5.4 The Processor will impose on each sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable for their performance.
6. Security
6.1 The Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as set out in Annex 1.
7. Personal data breach
7.1 The Processor shall notify the Controller without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting Customer Personal Data.
7.2 The notification will describe, so far as known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed.
7.3 The Processor will cooperate with the Controller and take reasonable steps to mitigate the effects of the breach.
8. Audit
8.1 The Processor will make available such information as is reasonably necessary to demonstrate compliance, including any current third party security certification or audit report.
8.2 Where that information is insufficient, the Controller may request an audit no more than once in any 12 month period, on 30 days' written notice, at the Controller's cost, during business hours, subject to confidentiality, and conducted so as not to unreasonably disrupt the Processor's operations.
9. Deletion and return
9.1 On termination, the Controller may export Customer Personal Data through the Service.
9.2 The Processor will delete Customer Personal Data within 30 days of termination, except where retention is required by law.
9.3 The Processor may retain anonymised and aggregated data that cannot be attributed to the Controller or any data subject, and system and security logs, in accordance with its Privacy Policy.
10. International transfers
10.1 Where the Processor transfers Customer Personal Data outside the UK, it will do so in reliance on UK adequacy regulations or, where those do not apply, on the International Data Transfer Addendum to the EU Standard Contractual Clauses, which are incorporated into this DPA by reference.
10.2 Details of transfers by sub-processor are published at cfopal.co.uk/subprocessors.
11. Artificial intelligence
11.1 The Processor does not use Customer Personal Data to train, fine-tune or otherwise develop artificial intelligence or machine learning models, and does not permit any sub-processor to do so.
11.2 Where AI-assisted features are used to generate commentary or insights, Customer Personal Data may be transmitted to the AI sub-processor identified at cfopal.co.uk/subprocessors, under contractual terms that prohibit its use for model training. That sub-processor retains submitted data for a limited period for abuse monitoring, currently up to 30 days, after which it is deleted. It is not retained for any other purpose.
12. Liability
Liability under this DPA is subject to the limitations and exclusions in the Terms of Service.
13. Governing law
This DPA is governed by the laws of England and Wales.
ANNEX 1: TECHNICAL AND ORGANISATIONAL MEASURES
Verified against the live environment on 22 August 2026. Every statement below was checked rather than assumed. Review at each renewal and amend if the environment changes.
Encryption
- Data in transit: TLS 1.3 with AES-256-GCM; TLS 1.2 minimum enforced on all connections
- Data at rest: databases, backups and file storage encrypted at rest by our infrastructure providers
Hosting and data location
- Database, authentication and file storage: Supabase, London (eu-west-2)
- Application hosting and compute: Vercel, London (lhr1). Static assets are served through a global content delivery network.
Access control and tenant isolation
- Row-level security enabled on every table containing customer data, enforcing separation between customers and between businesses within a customer account
- Access is resolved through a single set of database functions covering ownership, account membership and team membership, so isolation is enforced in one place rather than repeated per table
- Role-based access control distinguishing read-only from read-write team members, enforced at the database layer rather than in application code
- Anonymous and authenticated database roles hold no blanket access to any customer data
- Two-factor authentication available to all users
- Unique named accounts for all personnel; no shared credentials
- Privileged credentials are restricted to server-side use and are never exposed to the browser
Availability and resilience
- Automated daily database backups, retained for 7 days, restorable to any retained day
Logging and monitoring
- Audit logging of administrative access to customer data
- Application error logging with alerting on failures
- Infrastructure request logs and database logs retained by our providers
Personnel
- Access to production data is limited to personnel who require it
- Access is reviewed on any change of personnel and revoked on the day a person ceases to be engaged
Development and change management
- Segregated production and development environments
- Database schema changes applied as versioned migrations
- Row-level security enabled by default on newly created tables
Vendor management
- Written agreements with all sub-processors including data protection terms
- Sub-processor security posture reviewed before engagement
- Current sub-processor list published at cfopal.co.uk/subprocessors
Disclosed as not yet in place
Stated openly rather than omitted. An accurate annex is worth more than a flattering one, and each item below is something a customer's security questionnaire may ask about.
- No third-party security certification is currently held. Current status is published at cfopal.co.uk/security.
- Formal documented data protection training is not yet in place. Personnel with access to customer data have reviewed the Information Commissioner's Office guidance for small organisations.
- Point-in-time database recovery is not enabled. Recovery granularity is therefore the most recent daily backup.
- File storage objects are not included in database backups. Only regenerable content is held in file storage.
- Independent penetration testing has not yet been carried out.
- Written confidentiality and intellectual property assignment agreements are not yet in place for all personnel and contractors.