Data Processing Addendum
Last updated 24 September 2026
Scope
This Data Processing Addendum (DPA) applies when a Finalizo customer (the Customer) places personal data about clients, contacts, employees, contractors, or other individuals into Finalizo to create or deliver a handover pack. It forms part of the Terms of Service.
The Customer is the controller (or equivalent decision-maker) for Customer Data. Nebula Craft Design Ltd, operator of Finalizo, is the processor. Each party will comply with the data protection laws that apply to its role.
Processing instructions
Finalizo will process Customer Data only to provide, secure, support, and improve the Finalizo service as described in the Customer's instructions and the Terms. Processing includes hosting project records, delivering client pages and transactional emails, recording handover acknowledgement evidence, providing controlled credential reveal, generating exports, and maintaining security and reliability.
The Customer is responsible for having a lawful basis, giving required notices, responding to data subject requests, and ensuring that the Customer Data and instructions are appropriate. The Customer must not place special-category data, payment card data, or secrets that it is not authorised to handle into Finalizo.
Confidentiality and security
Finalizo will require personnel who can access Customer Data to keep it confidential and will maintain technical and organisational measures appropriate to the risk. Measures include access controls, encryption of credential secrets, HTTPS/TLS, audit logging for sensitive actions, rate limiting, secure development practices, backups, and incident response procedures. The Security page describes the current control position; it is not a certification.
Subprocessors
The Customer authorises Finalizo to use the providers in the Subprocessor Register. Finalizo remains responsible for its subprocessors' processing obligations under this DPA. Finalizo will update the register when a material subprocessor is added and will provide a reasonable way to raise a written objection on data protection grounds.
International transfers
Where Customer Data is transferred outside the United Kingdom or European Economic Area, Finalizo will use an applicable adequacy decision, approved transfer mechanism, or other lawful safeguard. Provider locations and transfer information are maintained in the Subprocessor Register and may depend on production configuration.
Rights and assistance
Taking account of the nature of processing, Finalizo will provide reasonable assistance with data subject requests, security assessments, incident information, and regulatory enquiries. Requests should be sent to privacy@finalizo.com, with the Customer copied where appropriate.
Personal data breaches
Finalizo will notify the Customer without undue delay after confirming a personal data breach affecting Customer Data and will provide information reasonably available to help the Customer meet its obligations. Notifications will not include unnecessary credentials or personal data.
Deletion and return
The Customer can export available records and request deletion. Following account deletion or the end of the service, Finalizo will delete or return Customer Data within the periods described in the Privacy Policy, subject to legal retention, fraud prevention, security, backup rotation, and dispute-related holds.
Audit information
Finalizo will make reasonable information available to demonstrate compliance with this DPA. Any audit must be proportionate, protect other customers' confidentiality, avoid disruption, and be requested with reasonable notice. The Customer is responsible for its own controller-side compliance assessment.
Contact
For DPA questions or a signed customer-specific addendum, contact privacy@finalizo.com.