Data Processing Agreement
How A8 Core™ processes personal data on your behalf, the security measures that apply, and how the subprocessor register works for a deployment-specific platform.
Last updated 23 July 2026 · Version v.260723
This Data Processing Agreement is offered as an exhibit to a platform agreement. It is not a substitute for a negotiated agreement and it has not been reviewed by your counsel or by ours for your specific deployment. Where a signed platform agreement and this document conflict, the signed agreement controls.
1. Scope and role of the parties
This agreement applies where Financial Infrastructure, Inc. (“A8 Core”, “we”) processes personal data on behalf of a customer (“you”) in the course of providing the A8 Core™ platform.
For that processing you are the controller and we are a processor. Where you are yourself acting as a processor for a third party, we act as a subprocessor and your instructions must be consistent with the instructions you have received. We do not determine the purposes for which personal data in your tenant is processed.
Separately, we act as a controller for a narrow set of data we process for our own purposes: account administration and billing, security and abuse prevention, and aggregated operational telemetry that does not identify your end users. That processing is described in our privacy policy and is not governed by this agreement.
2. Subject matter and duration
The subject matter is the provision of the platform. The duration is the term of your platform agreement plus any period in which we are required to retain data under clause 11 or by law. The categories of data subject and personal data, and the nature and purpose of processing, are set out in Exhibit A.
3. Processing on documented instructions
We process personal data only on your documented instructions, which comprise your platform agreement, this agreement, your configuration of the platform, and any instruction you give through the platform or its APIs. We will tell you if we consider an instruction to infringe applicable data-protection law, and we may suspend that instruction until it is resolved.
We do not sell personal data, and we do not use personal data in your tenant to train models that serve other customers.
4. Confidentiality of personnel
Access to personal data is limited to personnel who need it to deliver or support the platform. Those personnel are bound by written confidentiality obligations that survive the end of their engagement, and access is granted on a least-privilege basis and reviewed periodically.
5. Security of processing
We implement technical and organisational measures appropriate to the risk, described in Exhibit B and summarised in our security policy. Two measures are central enough to state here rather than in an exhibit:
- Authorization is enforced per data element. Every read and every write is evaluated against the caller, the record, the purpose and the delegation in force at that moment, and the decision is recorded. Authentication alone does not grant access to data.
- Decisions are evidenced. Access and change decisions produce a tamper-evident record intended to be sufficient for your own examination and audit obligations.
We may update these measures, provided the update does not materially reduce the overall level of security.
6. Subprocessors
You give general authorisation for us to engage subprocessors. Each subprocessor is bound by data-protection obligations no less protective than those in this agreement, and we remain responsible for their performance.
The subprocessor list is deployment-specific and is therefore maintained as a referenced exhibit rather than a fixed list in this document. Which subprocessors apply to you depends on the environment, region and integrations your deployment uses. The current register, including the constants that apply to every deployment, is published at /subprocessors/.
We will give you notice of an intended new or replacement subprocessor that processes your personal data, with a reasonable period to object on reasonable data-protection grounds. If we cannot accommodate a well-founded objection you may terminate the affected service.
7. Assisting with data-subject rights
The platform provides functions to access, correct, export and delete records so that you can respond to data-subject requests yourself. Where you cannot, we will assist you at your reasonable request. If a request reaches us directly we will not respond to its substance; we will refer the individual to you and tell you promptly.
8. Personal-data breach notification
We will notify you without undue delay, and in any event within seventy-two hours of becoming aware of a personal-data breach affecting personal data we process for you. The notification will describe the nature of the breach, the categories and approximate number of records affected so far as known, the likely consequences, the measures taken or proposed, and a contact point. We will provide further information as the investigation progresses rather than delaying the first notification until everything is known.
9. Assessments and audits
We will provide the information reasonably necessary for you to demonstrate compliance and to carry out a data-protection impact assessment. On reasonable notice, and no more than once in any twelve months unless required by a regulator or following a breach, you may audit our compliance with this agreement. Where available, current third-party audit reports and completed security questionnaires will be offered first, and are usually sufficient.
10. International transfers
Where personal data is transferred across a border in a way that requires a transfer mechanism, we will implement an appropriate one, including standard contractual clauses where applicable, together with any supplementary measures the circumstances require. Hosting regions are a configurable property of a deployment; tell us your constraint before provisioning rather than after.
11. Return and deletion
On termination, and at your choice, we will return or delete personal data processed for you, and delete existing copies, except to the extent we are required to retain it by law. Deletion covers backups on their ordinary expiry cycle rather than immediately, and we will tell you what that cycle is for your deployment.
An honest limitation, stated rather than buried. Records held in a system whose retention we do not control — for example a document-execution provider you have chosen, or an early evaluation record captured before provisioning — are deleted according to that system’s capabilities. Where a retention promise cannot be performed in full, we will tell you which system limits it instead of making the promise anyway.
12. Liability and precedence
The limitations and exclusions of liability in your platform agreement apply to this agreement. In the event of conflict, the order of precedence is: your signed platform agreement, then this agreement, then the exhibits, then any other document.
13. Exhibits
Exhibit A — nature of processing. Categories of data subject, categories of personal data, sensitive categories where applicable, nature and purpose of processing, and duration. Issued per deployment, because a retirement custodian, a private-fund administrator and a digital-asset trustee do not process the same categories.
Exhibit B — technical and organisational measures. The control set for your deployment, cross-referenced to our security policy and Trust Center.
Exhibit C — subprocessors. Maintained at /subprocessors/ and versioned.
To receive an executed DPA with the exhibits completed for your deployment, contact legal@a8core.com.
Financial Infrastructure, Inc. is a technology provider. It is not a bank, trust company, broker-dealer or investment adviser, and nothing in this document is legal advice. This agreement is governed by the laws of the State of California, and the exclusive venue for disputes is the state and federal courts located in San Mateo County, California.
Questions about this document? Contact legal@a8core.com or write to Financial Infrastructure, Inc., PO Box 1410, Menlo Park, California 94026-1410.