Data Processing Addendum

Effective date: September 01, 2026

This Data Processing Addendum (DPA) forms part of the Terms of Service and any applicable Order Form between you and Francis (together, the Agreement). It applies whenever Francis processes Personal Data on your behalf as your processor in providing the Services. It is incorporated into the Agreement automatically; we will also sign a copy on request.

Capitalised terms not defined here have the meaning given in the Agreement.

How this DPA applies

This DPA applies to Francis's processing of Personal Data that Francis processes as your processor in providing the Services, to the extent that processing is subject to Applicable Data Protection Laws. It takes effect when you accept the Agreement (or, if signed separately, on the date both parties sign) and continues for as long as Francis processes that Personal Data.

Definitions

  • Personal Data: the part of Customer Data that relates to an identified or identifiable natural person, as defined by applicable data-protection law, and that Francis processes on your behalf as a processor. This is the data this DPA governs. (Customer Data, the broader set of data you bring into the Platform, is defined in the Agreement.)
  • Affiliate: an entity that controls, is controlled by, or is under common control with a party.
  • Applicable Data Protection Laws: all data-protection and privacy laws that apply to the processing of Personal Data under the Agreement, including EU Data Protection Law where relevant.
  • EU Data Protection Law: the General Data Protection Regulation (EU) 2016/679 (GDPR), the e-Privacy Directive 2002/58/EC, and their national implementations, each as amended or replaced.
  • EEA: the European Economic Area, and for the purposes of this DPA also the United Kingdom and Switzerland.
  • Data Controller, Data Processor, Data Subject, Processing and Supervisory Authority: have the meanings given in the GDPR. "Process", "processes" and "processed" are read accordingly.
  • Security Incident (or Data Breach): a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of, or access to, Personal Data.
  • Sub-processor: a processor engaged by Francis or its Affiliates to process Personal Data in providing the Services.
  • Standard Contractual Clauses (or SCCs): the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced. For transfers governed by UK or Swiss law, SCCs also include the UK International Data Transfer Addendum and the equivalent Swiss adaptations.

Relationship with the Agreement

This DPA forms part of the Agreement. If there is a conflict between this DPA and the rest of the Agreement on a data-protection matter, this DPA prevails to the extent of the conflict.

Claims under this DPA are subject to the limitations of liability in the Agreement, except: (a) nothing in the Agreement or this DPA limits either party's liability that cannot be limited by law, including an individual's own direct claims under data-protection law; and (b) where an Order Form sets a specific limit for data-protection liability, that limit applies to claims under this DPA in place of the Agreement's general limitation.

This DPA is governed by the law and jurisdiction set out in the Agreement, unless Applicable Data Protection Laws require otherwise. It terminates automatically when the Agreement ends, though obligations that by their nature are intended to survive will continue, including those relating to confidentiality, security of any retained Personal Data, return or deletion of Personal Data, cooperation with audits and data subject requests in respect of retained data, international-transfer safeguards for retained data, and liability for breaches occurring before termination.

Francis may update this DPA from time to time. The version in effect when you accept the Agreement governs our processing of your Personal Data for the term, and any update applies prospectively, on reasonable prior written notice to you. No update will materially reduce the protections for Personal Data, your rights, or Francis's obligations under this DPA below the version then in effect, except as required by law or agreed with you.

Roles of the parties

You are the controller of the Personal Data (or, where you act on behalf of a third party, its processor), and Francis is your processor. Francis processes Personal Data only to provide the Services and only on your documented instructions, as set out in this DPA.

Where Francis acts as a controller of other data, such as your account information and website data, it handles that data under its Privacy Policy. For clarity, the Privacy Policy does not apply to the Personal Data Francis processes as your processor under this DPA.

Your instructions and our processing

You are responsible for meeting your obligations as a controller, for the lawfulness of the Personal Data and of the instructions you give us, and for having the notices, consents and legal bases needed for us to process Personal Data and provide the Services.

By entering into the Agreement, you instruct Francis to process Personal Data to provide and support the Services, and as further described in this DPA. We process Personal Data only on your documented instructions, including the Agreement and any additional written instructions you give and we acknowledge in writing. If we believe an instruction infringes Applicable Data Protection Laws, we will tell you promptly and will not carry out the relevant instruction until the matter is resolved with you, unless we are required to act by applicable law.

No use for our own purposes. We do not use Personal Data for our own purposes. In particular, we do not use Personal Data for product development, analytics, benchmarking, or to train, fine-tune or improve any machine-learning or AI model, unless you instruct us to in writing. The only exception is data that has been aggregated and irreversibly anonymised so that it no longer identifies you, your business or any individual.

AI features. Our AI features are off by default and stay off until a Workspace Owner turns them on. The AI providers we use are contractually barred from training their models on your Personal Data. We do not use Personal Data to make decisions about a data subject by solely automated means within the meaning of Article 22 GDPR: our AI features support your team's analysis of financial data, and their output is there for a person to review. Our AI Policy describes how this works.

Sub-processors

You give Francis general authorisation to engage Sub-processors to process Personal Data in providing the Services. Each Sub-processor is bound by a written contract with data-protection obligations no less protective than those in this DPA, as required by Article 28(4) GDPR. A Sub-processor may process Personal Data only to deliver the Services and not for any other purpose. Francis remains fully liable to you for its Sub-processors' acts and omissions.

The current list of Sub-processors, with their functions and locations, is in Schedule 3. Some are engaged only if you use a particular feature, and Schedule 3 groups them accordingly; where you do not use that feature, those Sub-processors process none of your Personal Data. We will give you at least 15 calendar days' notice before adding or replacing a Sub-processor, and the notice will identify the Sub-processor's name, location, processing activities and any international transfers. We may engage a Sub-processor on an expedited basis only where strictly necessary to prevent an imminent and material risk to the confidentiality, integrity or availability of Personal Data or to avoid material disruption to the Services. In that case we will notify you without undue delay, explain the reason for acting on an expedited basis, and your objection right below continues to apply.

You may object to a new Sub-processor on reasonable data-protection grounds by writing to support@francis.app within 15 calendar days of our notice. We will not transmit your Personal Data to the new Sub-processor before that 15-calendar-day period ends, except where we have engaged it on an expedited basis as described above. We will work with you in good faith to address the concern. If we cannot, you may terminate the affected Services, and we will refund any prepaid fees for the terminated portion on a pro-rata basis.

Security

Francis maintains appropriate technical and organisational measures to protect Personal Data against Security Incidents, taking into account the state of the art, the costs of implementation, and the nature, scope and risks of the processing. These measures are described in Schedule 2.

We may update our security measures from time to time as the Services evolve, provided the updates do not materially reduce the overall level of security. You are responsible for your own secure use of the Services, including protecting your account credentials and access.

Francis ensures that personnel authorised to process Personal Data are bound by appropriate confidentiality obligations, receive appropriate data-protection training, and are granted access to Personal Data on a need-to-know basis.

Security Incidents

Francis will notify you of a Security Incident affecting your Personal Data without undue delay, and in any event no later than 48 hours after becoming aware of it, unless prohibited by law. The notice will describe, to the extent we can, the nature of the incident, its likely consequences, and the measures taken or proposed to address it, and will be updated as more information becomes available.

You are responsible for meeting any notification obligations that apply to you as controller. Our notice is not an admission of fault or liability.

Audits and information

On your reasonable request, and no more than once a year in the ordinary course (except where more frequent review is reasonably required by a Security Incident, a material change in the processing, the engagement of a new Sub-processor, identified non-compliance, or a requirement of a Supervisory Authority), Francis will make available the information needed to demonstrate compliance with this DPA, including by responding to reasonable security and audit questionnaires. We may answer in general terms where needed to protect the security or confidentiality of our systems or other customers' data. Where we do, we will still provide enough detail for you to verify our compliance with this DPA.

You, or an independent auditor you appoint who is not a competitor of Francis and is bound by confidentiality, may also conduct an audit of the systems and procedures relevant to the protection of your Personal Data. We will agree the scope, timing and duration in advance to minimise disruption.

We provide this cooperation, and reasonable assistance with data protection impact assessments and consultations with Supervisory Authorities, at no charge. We may recover our reasonable costs only where a request is excessive, or where an audit goes beyond what is reasonably necessary to confirm compliance, and we will tell you in advance if we expect to charge.

Data subject requests

Taking into account the nature of the processing, Francis will assist you with appropriate technical and organisational measures, so far as possible, to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, objection, and rights relating to automated decisions). Where you cannot address a request through your own use of the Services, we will provide reasonable assistance. If we receive a request directly, we will, where legally permitted, promptly tell you rather than respond ourselves. We provide this assistance at no charge, unless your requests are excessive, in which case we may recover our reasonable costs and will tell you in advance.

International transfers

Francis processes Personal Data in the EEA. At the date of this DPA, Personal Data is stored within the EEA, in Frankfurt and Dublin.

Where Personal Data is transferred outside the EEA, including to a Sub-processor, we put appropriate safeguards in place as required by Chapter V of the GDPR, including the European Commission's Standard Contractual Clauses (Module 3, processor-to-processor) together with any transfer impact assessment and supplementary measures needed. Transfers are limited to the locations listed in Schedule 3.

Returning or deleting Personal Data

On termination or expiry of the Agreement, Francis will, at your choice, delete or return your Personal Data and delete existing copies, except where we are required by law to retain it. In that case we will tell you the legal requirement, the categories of data retained and the expected retention period, keep only the minimum needed, and delete it once the legal retention period ends. On your request, Francis will provide written certification that Personal Data has been deleted or returned.

Personal Data is part of your Customer Data and is exported, retained and deleted on the same basis as all Customer Data, including the on-request and default deletion periods and the backup handling described in the Terms of Service under "Exporting and deleting your data". You can ask us to delete your data, or export it from the Platform, at any time before your access ends.

Law enforcement requests

If a law-enforcement or government body asks Francis for Personal Data, we will try to redirect it to you, and may provide your basic contact details for that purpose. If we are compelled to disclose Personal Data, we will disclose only the minimum legally required, challenge overbroad or unlawful demands where reasonably appropriate, document the legal basis for the disclosure, and give you reasonable notice so you can seek a protective order, unless we are legally prohibited from telling you.

General

No one other than the parties, their successors and permitted assigns may enforce this DPA, except to the extent a right cannot be excluded under Applicable Data Protection Laws.


Schedule 1: Subject matter and details of the processing

Subject matter. Francis's provision of the Services under the Agreement, and the processing of Personal Data needed to provide them.

Nature and purpose. Hosting, storing, and processing Personal Data to operate the Platform and provide and support the Services, on your instructions. Francis does not sell Personal Data and does not share it with third parties for their own purposes.

AI features (optional, off by default). If your Workspace Owner enables AI features, we additionally process the prompts and responses generated through those features to deliver them. This includes automated checks and limited human review by authorised Francis personnel, to detect and correct errors and to keep outputs accurate and safe. That review is part of providing the AI features, not model training, and it happens only where AI features are enabled. We do not use your Customer Data to train or fine-tune AI models, and the Sub-processors we engage for AI features (listed in Schedule 3 under "Platform data, only if AI features are enabled") are contractually prohibited from doing so. Those Sub-processors retain Personal Data only for a limited period, and only to deliver the AI features, to detect and prevent misuse of their services, or where required by law.

Duration. For the term of the Agreement, plus the retention and deletion periods in Section 12.

Categories of data subjects. Individuals whose Personal Data appears in the Customer Data, which may include your Users (for example, employees or contractors who access the Services) and third parties with whom you or your Users have a business relationship.

Types of Personal Data. Mainly identification and contact details, such as names, work email addresses and job titles; and Personal Data that appears within the financial and business data you import or create in the Platform, mainly names in transaction descriptions and salary figures used for planning. The same categories of Personal Data may also appear within support communications, screenshots, and screen or call recordings exchanged when we provide or support the Services.

Special-category data. The Services are not intended for special categories of personal data (Article 9 GDPR), and you should not input such data into free-text or other fields.

Schedule 2: Technical and organisational measures

This Schedule serves as Annex II to the Standard Contractual Clauses where they apply. Further detail is available on request at support@francis.app.

Encryption. Personal Data is encrypted at rest using the Advanced Encryption Standard (AES-256) and in transit using TLS.

Confidentiality, integrity, availability and resilience. Francis maintains confidentiality obligations for personnel and requires every Sub-processor to commit to confidentiality. Systems are monitored with automated alerting, and we maintain plans to provision new infrastructure and restore Personal Data from backups after a serious incident.

Backups and restoration. Francis performs regular backups, encrypted in transit and at rest, and runs periodic incident and restoration exercises.

Access control. Personnel use unique credentials. Multi-factor authentication is required for personnel with administrative access and for personnel accessing production systems where Personal Data is processed, and two-factor authentication is enforced at our identity provider. Where a system permits direct login outside single sign-on, we require single sign-on by policy and confirm it in our periodic access review. Access follows least-privilege, role-based and time-based models, is granted by job function, and is promptly updated or removed on role change or departure. Personnel receive appropriate data-protection and security training.

AI features. AI features are disabled by default for every Workspace and can be enabled only by a Workspace Owner. While they are disabled, no Customer Data is transmitted to the Sub-processors listed in Schedule 3 under "Platform data, only if AI features are enabled". Each change to the setting is recorded in an append-only log that captures the Workspace, the acting user, that user's Owner role at the time of the change, the time of the change, and the new state. Access to prompts and responses, for the review described in Schedule 1, is limited to a defined list of members of Francis's technical product team. That list is enforced by role-based access control, is reviewed periodically, and access is removed promptly on role change or departure. Prompts and responses form part of your Customer Data and are retained and deleted on the same basis, as described in Section 12.

Secure configuration. Francis uses infrastructure-as-code and reusable internal modules to keep systems configured uniformly and repeatably across its infrastructure, and runs automated processes to validate adherence to configuration best practices and to scan for vulnerabilities and other security threats.

Hosting and physical security. The Services run on Amazon Web Services. AWS provides the physical and environmental security of the data centres. Information about AWS security is at https://aws.amazon.com/security/.

Governance. Security and data protection are owned at the executive level, by the CEO and CTO, and our security policies are reviewed at least annually. For privacy or security questions, contact support@francis.app.

Data minimisation and retention. Francis applies data-minimisation and limited-retention principles, as reflected in Section 12.

Certifications. Francis does not yet hold third-party security certifications. We are working towards SOC 2 and ISO/IEC 27001. Our infrastructure runs on AWS, which holds its own ISO certifications (https://aws.amazon.com/compliance/iso-certified/).

Sub-processor measures. When Francis engages a Sub-processor, it requires data-protection terms substantially similar to those in this DPA, including that the Sub-processor: notifies Francis of Security Incidents; deletes data on instruction; does not engage further sub-processors or change processing locations without authorisation; and does not process Personal Data in a way that conflicts with your instructions.

Schedule 3: List of Sub-processors

Last updated: 6 August 2026

On commencement of the Agreement, you authorise the engagement of the following Sub-processors. The groups below show how much of your Customer Data each one sees, and which ones we engage only if you use a particular feature.

Platform data

These Sub-processors receive Customer Data from the Platform as part of their function.

CompanyPurposeLocationMechanism
Amazon Web Services EMEA SARL and Amazon Web Services, Inc.Hosting and infrastructureFrankfurt, Dublin (EEA)EU SCCs (2021) + DPF + UK Addendum

Platform data, via logs and diagnostics

Customer Data can reach these Sub-processors automatically, where it appears in the error reports, logs and monitoring output the Platform generates.

CompanyPurposeLocationMechanism
Functional Software, Inc. (Sentry)Application performance monitoringUSEU SCCs (2021) + DPF + UK Addendum
SolarWinds CorpApplication logging and monitoringUSEU SCCs (2021) + TIA / supplementary measures + UK Addendum

Platform data, via notification emails

We use this Sub-processor to send you notification emails. Where a notification includes something from the Platform, for example the text of a comment someone left on your model, that content passes through it.

CompanyPurposeLocationMechanism
Astrodon Corporation (Loops)Notification and product emailsUSEU SCCs (2021) + DPF

Incidental, via correspondence and support

These Sub-processors are not given Platform data, but Customer Data can appear in what is exchanged when we support you, for example if you share a screen on a support call, send us a document, or paste figures into a message. This reflects the note in Schedule 1 that the same categories of Personal Data may appear within support communications, screenshots, and screen or call recordings.

CompanyPurposeLocationMechanism
Google Ireland Limited and Google LLCEmail and file sharing (including support recordings)USEU SCCs (2021) + DPF
Superhuman Labs, Inc.EmailUSEU SCCs (2021) + DPF + UK Addendum
Intercom, Inc. and Intercom R&D Unlimited CompanyCustomer supportUSEU SCCs (2021) + DPF + UK Addendum
Slack Technologies LimitedInternal communications and customer supportUSEU SCCs (2021) + DPF + UK Addendum
Attio LimitedCRM (including call recordings)UK (EEA/UK)Within EEA / UK adequacy

Platform data, only if you connect Xero, QuickBooks or NetSuite

We engage Codat only if you connect Xero, QuickBooks or NetSuite. Our other integrations do not use Codat. If you connect none of these three, Codat processes none of your Personal Data.

CompanyPurposeLocationMechanism
Codat Limited / Codat Inc.Accounting-system integrationUK, USEU SCCs (2021) + TIA / supplementary measures

Platform data, only if AI features are enabled

We engage the following Sub-processors only if your Workspace Owner enables AI features, which are optional and off by default. If you do not enable AI features, these Sub-processors process none of your Personal Data.

They receive Platform data, but only the data needed for the request a User makes, rather than a continuous copy of your Workspace. They are contractually prohibited from using your data to train or fine-tune AI models, and retain it only for a limited period, and only to deliver the AI features, to detect and prevent misuse of their services, or where required by law.

CompanyPurposeLocationMechanism
Anthropic Ireland LimitedAI model provider for AI featuresUSEU SCCs (2021) + TIA / supplementary measures + UK Addendum
LMNR AI, Inc. (Laminar)Monitoring and quality checks on AI outputsUSEU SCCs (2021) + TIA / supplementary measures + UK Addendum