FinNilai
TrustSecurityPrivacyTermsRefunds

Data Processing Agreement

Data Processing Agreement (DPA)

Version 1.0 · Last updated: 2026-07-18

Pre-signed PDF for your compliance records

Plenitude’s side is countersigned on the effective date. Sign the customer block and keep the executed copy. If you’re signed in, your workspace details pre-fill.

Download PDF

This Data Processing Agreement (“DPA”) forms part of the FinNilai Terms of Service and applies whenever Plenitude Systems Private Limited (“FinNilai”, “we”) processes Personal Data on behalf of a customer (“Customer”, “you”) through the FinNilai service. This DPA is automatically incorporated into your subscription — no separate signature is required, but a counter-signed copy can be requested at privacy@finnilai.com.

1. Parties & roles

Data Fiduciary (Controller): the Customer, with respect to Personal Data uploaded to or generated within the Customer’s workspace.

Data Processor: FinNilai, acting on the Customer’s documented instructions as expressed through the use of the service and its configuration options.

2. Subject matter, duration, and nature of processing

  • Subject matter: provision of the FinNilai accounting, invoicing, and compliance software as described at finnilai.com.
  • Duration: the term of your active subscription plus the 30-day cooling-off period following workspace deletion, subject to statutory retention (see §7).
  • Nature and purpose: storing, indexing, transforming, computing over, and returning Customer data for the sole purpose of operating the service. No secondary use.
  • Categories of data + data subjects: as enumerated in the DPDP disclosure §2.

3. Customer instructions

FinNilai will process Personal Data only on documented instructions from the Customer, which include (a) this DPA, (b) the Terms of Service, and (c) the Customer’s use of the service and its settings. If we believe an instruction violates applicable law, we will notify the Customer and may suspend the affected processing until the matter is resolved.

4. Confidentiality

Every FinNilai staff member with access to Personal Data is under a written confidentiality obligation surviving termination of employment, is trained on data-protection obligations, and only accesses Customer data on a documented, audited basis (see §5).

5. Security measures (Annex II summary)

FinNilai maintains the following technical and organisational measures, appropriate to the risk of processing:

  • Encryption: AES-256 at rest (Supabase managed keys), TLS 1.2+ in transit with HSTS enforced.
  • Access control: Postgres Row-Level Security scoping every query to workspace membership; MFA mandatory for all FinNilai staff; individual access requires typed reason and is fully audited.
  • Segregation: multi-tenant with RLS at the database level — no application code can bypass tenant isolation.
  • Backups: daily point-in-time recovery for the primary database, 7-day recovery window.
  • Logging & monitoring: authentication, administrative, and staff-access events retained for 90 days; error monitoring via Sentry (payloads redacted at source).
  • Change management: all production changes via reviewed pull request and automated tests; migrations version-controlled.
  • Vulnerability management: dependency upgrades reviewed at least weekly; critical CVEs patched within 7 days of disclosure. Full policy at /security.

6. Sub-processors

Customer authorises FinNilai to engage the sub-processors listed on the DPDP disclosure §3. FinNilai remains liable for the acts and omissions of its sub-processors. Material changes to the sub-processor list will be announced by email at least 30 days in advance; Customer may object in writing, in which case FinNilai will work in good faith to provide an alternative or, failing that, Customer may terminate for convenience with pro-rata refund of prepaid fees.

7. Data-subject rights & assistance

The service provides self-service endpoints for Customer to satisfy Data Principals’ rights under the DPDP Act §§11–13 (access, correction, erasure). FinNilai will additionally assist the Customer on reasonable request for any right the self-service surface does not cover. Statutory retention (Income Tax Act §44AA, RBI §16) survives erasure requests as noted in the DPDP disclosure.

8. Personal data breach notification

FinNilai will notify the Customer without undue delay and in any case within 72 hours of becoming aware of a Personal Data Breach affecting the Customer’s Personal Data. Notice will include, to the extent then known: the nature of the breach, categories and approximate number of Data Principals and records concerned, likely consequences, and measures taken or proposed. FinNilai will cooperate with the Customer in any regulatory notification the Customer is required to make to the Data Protection Board of India.

9. Return & deletion at end of processing

At any time during the subscription and for 30 days after termination, Customer may export all Personal Data via Settings → Privacy & data. After the 30-day cooling off, all Personal Data is deleted from production systems within 60 days and from backups within 90 days, save where retention is required by law.

10. Audits & information

FinNilai will make available to the Customer, on written request, all information reasonably necessary to demonstrate compliance with this DPA, including (i) the most recent penetration-test executive summary once available, (ii) our Trust & Security disclosures at /trust, and (iii) responses to reasonable security questionnaires. Customer may audit compliance no more than once per twelve months and only on 30 days’ prior written notice, at Customer’s cost, subject to reasonable confidentiality and scoping restrictions.

11. International transfers

Primary storage and processing occur in India (Mumbai). Certain sub-processors (Resend, Meta WhatsApp Cloud API, Sentry) may process transient data outside India as listed in the DPDP disclosure. FinNilai does not transfer bulk Customer data outside India.

12. Liability & term

This DPA is subject to the liability provisions of the Terms of Service. It takes effect on the earlier of (i) the Customer’s first use of the service and (ii) the effective date of the underlying subscription, and remains in force for the term set out in §2.

13. Contact

Data Protection Officer / Grievance Officer: privacy@finnilai.com. Security team: security@finnilai.com.


For custom clauses or an alternative signing workflow (DocuSign, physical original), email privacy@finnilai.com with your workspace name and what you need.

For questions about any clause on this page, contact our grievance officer at contact@finnilai.com.