Data processing agreement
Last updated 13 September 2026
In this document “we”, “us” and “FIINO” mean FIINO .
This agreement applies when FIINO processes personal data on behalf of your firm. It forms part of our terms of service and is intended to meet Article 28 of the UK GDPR.
1. Roles
Your firm is the controller of personal data about its clients, their contacts and its employees that it puts into FIINO. FIINO is the processor.
2. Scope of processing
- Subject matter: hosting and processing data to provide practice management software.
- Duration: the term of your subscription, plus the export and deletion period.
- Nature and purpose: storage, retrieval, display, transmission (e.g. emails you send) and deletion.
- Data subjects: your clients and their contacts, your staff and employees, and portal users.
- Types of data: contact details, financial and tax information, payroll and HR records, documents and messages.
- Special category data: only if you choose to store it, for example health information in HR records.
3. Our commitments
- Process personal data only on your documented instructions, which are these terms and your use of the service.
- Ensure people who can access it are bound by confidentiality.
- Keep appropriate technical and organisational measures, including separation between firms, role-based access, encryption in transit, audit logging, and support access only when your firm grants it.
- Help you respond to data subjects exercising their rights.
- Tell you without undue delay after becoming aware of a personal data breach affecting your data.
- Help you with data protection impact assessments and consultation with the ICO where relevant.
- Delete or return your data at the end of the service, unless the law requires us to keep it.
- Make available the information needed to show we meet these obligations.
4. Sub-processors
You authorise us to use sub-processors for hosting, email delivery, payments and error monitoring. We will bind them to equivalent data protection terms, remain responsible for them, and give notice of new sub-processors so you can object.
5. International transfers
Where a sub-processor processes data outside the UK, we will use a lawful transfer mechanism such as UK adequacy regulations or the International Data Transfer Agreement or Addendum.
6. Your responsibilities
You are responsible for having a lawful basis for the personal data you put into FIINO, for the access you give your staff and clients, and for the accuracy of that data.