Data Processing Agreement (DPA)
1Roles and scope
The Controller is the company whose workspace the personal data belongs to. BankConnector processes personal data in Customer Data as Processor, on the Controller's behalf.
For Usage Data (technical logs, metrics, and de-identified aggregated data), BankConnector is an independent controller for the purposes of service operation, security, fraud and abuse prevention, and service improvement, as described in the Agreement.
Where the Controller's access is provided through a Platform, the Platform's access to and processing of the Controller's data takes place under the Controller's authorisation in its own agreement with the Platform; the Platform is not a subprocessor of BankConnector.
2Processing details (Article 28(3))
- Subject matter and nature: hosting, validation, conversion, delivery, retrieval, normalisation, journaling, and display of payment files, bank statements, and related records; operation of user accounts and approval workflows.
- Purpose: providing the services described in the Service Description, as configured and instructed by the Controller through the services.
- Duration: the term of the Agreement plus the wind-down and retention periods stated in the Agreement and the Service Description.
- Categories of data subjects: the Controller's users (administrators, approvers, viewers); payment parties appearing in payment instructions and bank statements (e.g. employees, suppliers, customers of the Controller); approvers subject to bank-mandated identity requirements.
- Categories of personal data: name and contact details of users; authentication data (password hashes, TOTP enrolment); names, addresses, and account identifiers (IBAN/BBAN) of payment parties; remittance information; payment amounts, dates, and references; approver identity data, including national identity numbers where a bank requires them for payment-file authorisation (stored encrypted, masked in display, never written to logs).
- Special categories: none. The Controller must not submit Article 9 GDPR data, payment-card primary account numbers, or health data.
3Processor obligations
Instructions. BankConnector processes personal data only on the Controller's documented instructions (the Agreement, this DPA, and the Controller's configuration and use of the services), unless required by EU or Member State law, in which case BankConnector informs the Controller before processing unless that law prohibits it. BankConnector will inform the Controller if, in its opinion, an instruction infringes the GDPR.
Confidentiality. Persons authorised to process personal data are bound by confidentiality obligations and receive access only as needed for their role.
Security. BankConnector implements the technical and organisational measures in Annex II and the Security Policy, including field-level encryption at rest, TLS in transit, tenant isolation enforced at the database layer, role-based access control, multi-factor authentication, and a tamper-evident audit trail. Measures may be updated provided the overall level of protection is not materially reduced.
Assistance. Taking into account the nature of processing, BankConnector assists the Controller with appropriate technical and organisational measures in responding to data-subject requests (access, rectification, erasure, restriction, portability, objection), including through the built-in export and erasure functions, and, insofar as information is available to BankConnector, with the Controller's obligations under Articles 32–36 GDPR (security, breach notification, DPIAs, prior consultation).
Personal-data breach. BankConnector notifies the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal-data breach affecting Customer Data, providing (as information becomes available) the nature of the breach, categories and approximate numbers of data subjects and records concerned, likely consequences, measures taken or proposed, and a contact point. BankConnector documents breaches and remediation.
Deletion and return. During the term, the Controller can export its data at any time using the export functions. On termination and expiry of the wind-down period, BankConnector deletes or anonymises personal data in Customer Data in accordance with the retention schedule in the Service Description (journal documents 90 days; audit records 5 years; usage events 365 days; idempotency records 24 hours), except where EU or Member State law requires longer storage or a documented legal hold applies. The Controller's per-user and company-level erasure functions are described in the Documentation.
Audits. BankConnector makes available the information reasonably necessary to demonstrate compliance with Article 28, including summaries of security assessments and, once achieved, certification reports (available on request under NDA), and allows and contributes to audits. Audits beyond documentation review (including on-site inspections) are limited to once per 12 months, on at least 30 days' notice, during business hours, at the Controller's cost, under confidentiality, and must not compromise the security or data of other customers; an additional audit is permitted where required by a supervisory authority or following a material breach.
4Subprocessors
The Controller grants a general authorisation for the subprocessors listed in Annex III (also published at bankconnector.com/legal). BankConnector will give at least 30 days' notice before adding or replacing a subprocessor; the Controller may object on reasonable data-protection grounds, in which case the parties will seek a solution and, failing one, the Controller may terminate the affected services with a pro-rata refund of prepaid unused fees.
BankConnector imposes data-protection obligations on subprocessors equivalent to this DPA and remains fully liable for their performance.
5Transfers
Customer Data is stored and processed within the EU/EEA. Personal data is not transferred outside the EEA unless the transfer is protected by a Chapter V GDPR mechanism (adequacy decision or Standard Contractual Clauses, with supplementary measures where needed), and any such subprocessor is identified in Annex III.
6General
This DPA lasts as long as BankConnector processes personal data in Customer Data. Liability under this DPA is subject to the Agreement's liability provisions. This DPA is governed by the law and venue of the Agreement.
Annex IProcessing details
As set out in Section 2.
Annex IITechnical and organisational measures (summary; detail in the Security Policy)
- Encryption: field-level AES-256-GCM encryption at rest for payment payloads, credentials, and approver identity data, with key-identifier tagging for rotation; TLS 1.2+ in transit.
- Tenant isolation: every record is bound to a platform/company scope; isolation enforced at three layers, including PostgreSQL Row-Level Security on all tenant tables.
- Access control: role-based access (admin, approver, viewer); multi-factor authentication (TOTP) for login and approval step-up; session management with secure cookies and CSRF protection; login throttling and lockout.
- Integrity and auditability: tamper-evident, hash-chained audit log per company, verifiable on demand; maker-checker approval workflows; versioned, immutable approval policies changed only by dual co-signature.
- Key custody: bank-connection key material generated and stored server-side, encrypted at rest; destroyed on wind-down completion.
- Operations: production/sandbox separation with fail-closed production boot gates; SSRF and input-validation controls; monitoring and alerting; documented and periodically exercised disaster-recovery procedures; least-privilege database access.
- Personnel: access on a need-to-use basis; confidentiality undertakings.
- Data minimisation: approver national identity numbers encrypted and masked, never logged; usage telemetry contains no payment content or PII.
Annex IIISubprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services EMEA SARL | Cloud infrastructure and database hosting | EU regions |
The current list is maintained at bankconnector.com/legal; changes are notified per Section 4.1.