TechVentures hit 96% accuracy on Q1 forecast
GlobalRetail generated 12 scenarios in 8 min
ScaleUp reduced forecast cycle from 2wk to 3hr
NexGen found $4.2M in budget optimization
Legal

Data Processing Agreement

This DPA governs how ForezynPlan processes personal data on behalf of business customers and satisfies the requirements of applicable data protection laws worldwide, including the EU GDPR, UK GDPR, US state privacy laws (CCPA/CPRA, VCDPA, CPA and others), and other regional privacy regulations.

Effective date:April 1, 2026Last updated:April 12, 2026Version:2.0

Globally applicable: This DPA is designed to satisfy processor agreement requirements under all major data protection frameworks worldwide — including the EU GDPR, UK GDPR, US state privacy laws (CCPA/CPRA, VCDPA, CPA, CTDPA, TDPSA and others), LGPD, PIPEDA, and more. Enterprise customers may request a countersigned version — contact legal@forezynplan.com.

01

Introduction & Scope

This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the ForezynPlan Terms of Service (or, where applicable, a separately executed Master Services Agreement) between ForezynPlan Ltd ("ForezynPlan", "we", "us", or "Processor") and the business entity or individual ("Customer" or "Controller") that has accepted those terms.

This DPA applies wherever ForezynPlan processes Personal Data on behalf of the Customer in connection with the provision of the ForezynPlan financial planning platform and related services ("Services"). It sets out the rights and obligations of both parties with respect to the processing of Personal Data and is designed to satisfy the requirements of applicable data protection and privacy laws across all jurisdictions in which ForezynPlan or its Customers operate, including — without limitation — the EU GDPR, the UK GDPR, US state privacy laws (CCPA/CPRA, VCDPA, CPA, CTDPA, TDPSA and others), Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act 1988, and Singapore's PDPA.

In the event of a conflict between this DPA and the Terms of Service, this DPA shall take precedence with respect to matters relating to Personal Data processing.

01
02

Definitions

"Applicable Data Protection Law" means all applicable data protection, privacy, and security laws and regulations in any jurisdiction in which ForezynPlan or the Customer operates, including without limitation: the EU General Data Protection Regulation (EU GDPR 2016/679); the UK General Data Protection Regulation and the Data Protection Act 2018; Brazil's Lei Geral de Proteção de Dados (LGPD); Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws; Australia's Privacy Act 1988 (Cth); Singapore's Personal Data Protection Act (PDPA); and any successor or replacement legislation, in each case as amended from time to time.

United States. The United States does not currently have a single federal privacy law of general applicability. Instead, a growing number of US states have enacted comprehensive privacy statutes, all of which are included in "Applicable Data Protection Law" where they apply to the Customer's or a Data Subject's state of residence.

"Controller" means the Customer, being the natural or legal person who determines the purposes and means of the processing of Personal Data.

"Processor" means ForezynPlan Ltd, which processes Personal Data on behalf of the Controller.

"Personal Data", "Data Subject", "Processing", "Personal Data Breach", "Supervisory Authority", and "Special Categories of Personal Data" each have the meanings given to them in Applicable Data Protection Law.

"Services" means the ForezynPlan software platform and any ancillary services provided by ForezynPlan under the Terms of Service or Master Services Agreement.

"Sub-processor" means any third party engaged by ForezynPlan to process Personal Data on behalf of the Controller in connection with the Services.

"Standard Contractual Clauses" or "SCCs" means the standard data protection clauses for the transfer of Personal Data to third countries adopted by the European Commission pursuant to Article 46(2) of the EU GDPR, or the International Data Transfer Agreement (IDTA) or Addendum adopted for UK transfers, as applicable.

02
03

Details of Processing

Article 28(3) GDPR — Processing Schedule

Subject Matter. ForezynPlan processes Personal Data in order to provide and maintain the Services, including hosting, data storage, analytics, customer support, and security monitoring.

Duration. ForezynPlan will process Personal Data for the duration of the Customer's subscription and, thereafter, for such period as is necessary to comply with legal obligations or as otherwise agreed in writing, subject to Section 12 (Data Retention & Deletion).

Nature of Processing. Collection, storage, retrieval, analysis, transmission, and deletion of Personal Data as required to deliver the Services.

Purpose of Processing. To fulfil ForezynPlan's contractual obligations to the Customer, including providing the financial planning platform, generating reports, sending notifications, providing customer support, and maintaining the security and integrity of the Services.

Types of Personal Data. The types of Personal Data processed depend on the Customer's use of the Services and typically include: names, email addresses, job titles, and employment information; financial data including budgets, forecasts, actuals, and transaction records; user activity logs and audit trail data; device identifiers and IP addresses (for security purposes).

Categories of Data Subjects. The Data Subjects are typically employees, contractors, and authorised users of the Customer who have been granted access to the Services, and any individuals whose Personal Data the Customer uploads to or creates within the Services.

03
04

Controller Obligations

The Customer warrants and represents that: (a) it has a valid legal basis under Applicable Data Protection Law for providing Personal Data to ForezynPlan and instructing ForezynPlan to process it; (b) it has provided all necessary notices to, and obtained all necessary consents from, Data Subjects; and (c) it will comply with its obligations as a Controller under Applicable Data Protection Law.

The Customer agrees to ensure that its instructions to ForezynPlan comply with Applicable Data Protection Law and will not instruct ForezynPlan to process Personal Data in a manner that would cause ForezynPlan to violate any applicable law, regulation, or supervisory authority guidance.

The Customer is responsible for the accuracy, quality, and legality of the Personal Data it submits to the Services. ForezynPlan does not verify the lawfulness of the Personal Data provided by the Customer.

The Customer acknowledges that ForezynPlan is not responsible for determining whether the Services are appropriate for the Customer's specific legal obligations and that it is the Customer's responsibility to ensure the Services meet its data protection requirements before use.

04
05

Processor Obligations

ForezynPlan will only process Personal Data: (a) on documented instructions from the Customer, including as set out in this DPA and the Terms of Service; (b) as strictly necessary to provide, maintain, and support the Services; or (c) as required by applicable law, in which case ForezynPlan will (where legally permitted) notify the Customer before undertaking such processing.

ForezynPlan will ensure that all personnel authorised to process Personal Data are subject to appropriate obligations of confidentiality and have received training on data protection requirements.

ForezynPlan will provide the Customer with such information as is reasonably necessary to demonstrate compliance with the obligations of a Processor under Applicable Data Protection Law and will co-operate with audits and inspections as set out in Section 13 of this DPA.

ForezynPlan will not sell, rent, or otherwise disclose Personal Data to third parties for their own independent purposes. ForezynPlan will not process Personal Data for its own commercial benefit beyond what is necessary to provide the Services.

ForezynPlan will promptly notify the Customer if, in its reasonable opinion, an instruction from the Customer infringes Applicable Data Protection Law.

05
06

Sub-processors

The Customer provides ForezynPlan with general written authorisation to engage Sub-processors as necessary to provide the Services. ForezynPlan's current list of approved Sub-processors is set out in the table below. ForezynPlan will provide the Customer with at least 30 days' prior written notice (by email to the account administrator) of any intended changes to this list, including the addition or replacement of Sub-processors. The Customer may object to any new Sub-processor in writing within 14 days of such notice on reasonable grounds. If the Customer objects and ForezynPlan cannot accommodate the objection without materially impacting the Services, ForezynPlan will notify the Customer and the Customer may terminate the relevant Services on 30 days' written notice without penalty.

ForezynPlan will enter into a written data processing agreement with each Sub-processor that imposes obligations at least equivalent to those imposed on ForezynPlan under this DPA. ForezynPlan remains liable to the Customer for the acts and omissions of its Sub-processors to the same extent as if ForezynPlan were performing the processing directly.

Sub-processor
Country / Region
Purpose
Microsoft Azure
EU (West & North Europe)
Cloud infrastructure, compute, storage, managed databases, and networking
Microsoft Sentinel
EU
Security information and event management (SIEM) and threat detection
Azure Key Vault
EU
Encryption key management and secret storage
Stripe
USA / EU
Payment processing (PCI DSS Level 1 certified; card data does not pass through ForezynPlan systems)
SendGrid (Twilio)
USA / EU
Transactional email delivery (account notifications, reports)
Intercom
USA / EU
Customer support and in-product messaging
Mixpanel
USA
Product analytics (anonymised usage data only; no financial data)
Hotjar
EU (Malta)
Session recording and heatmaps on the marketing website only
06
07

Data Subject Rights Assistance

ForezynPlan will, taking into account the nature of the processing, provide the Customer with reasonable technical and organisational assistance to enable the Customer to fulfil its obligations to respond to Data Subject requests to exercise their rights under Applicable Data Protection Law, including rights of access, rectification, erasure, restriction, portability, and objection.

If ForezynPlan receives a Data Subject request directly, ForezynPlan will promptly (and in any event within 5 business days) redirect the Data Subject to the Customer and will not respond to the Data Subject directly unless instructed to do so by the Customer or required by applicable law.

ForezynPlan offers the following self-service tools within the platform to assist Controllers in fulfilling Data Subject requests: (a) export of all Personal Data associated with a user account; (b) deletion of individual user accounts and associated data; (c) account audit log export for subject access requests. For data subject requests that cannot be fulfilled via self-service tools, the Customer should contact privacy@forezynplan.com with a detailed description of the request.

07
08

Security Measures

Article 32 GDPR — Technical & Organisational Measures

ForezynPlan implements and maintains appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing, as required by Applicable Data Protection Law (including Article 32 of the EU GDPR and equivalent provisions in other applicable laws). These measures include, but are not limited to:

Encryption. All Personal Data is encrypted at rest using AES-256-GCM. All data in transit is protected using TLS 1.3 (minimum TLS 1.2 for internal service-to-service communication). Encryption keys are managed in Azure Key Vault with HSM-backed storage.

Access Controls. Production system access is restricted to authorised ForezynPlan engineers on a least-privilege basis, with multi-factor authentication enforced and just-in-time (JIT) access for privileged operations. No standing admin accounts exist in production.

Infrastructure. All infrastructure is hosted on Microsoft Azure within ISO 27001 and SOC 2 Type II certified data centres in the EU. Network security includes VNets with strict ACLs, Azure DDoS Protection Standard, and a Web Application Firewall with OWASP Core Rule Set.

Monitoring. ForezynPlan operates a 24/7 security monitoring programme using Microsoft Sentinel SIEM with automated alerting, UEBA, and an on-call security engineering rotation. All administrative actions are logged to a tamper-evident, immutable audit log with 12-month retention.

Testing. ForezynPlan conducts annual penetration tests by a CREST-accredited third party, continuous SAST/SCA scanning on all code changes, and quarterly access reviews. A formal Secure Development Lifecycle (SDL) is followed for all product development.

ForezynPlan holds the following certifications: SOC 2 Type II (Security, Availability, Confidentiality); ISO 27001; and a published CSA STAR Level 1 self-assessment. Copies of audit reports are available to Customers under a Non-Disclosure Agreement — contact security@forezynplan.com.

08
09

Personal Data Breach Notification

72-Hour Notification Obligation

ForezynPlan will notify the Customer without undue delay — and in any event no later than 72 hours — after becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of the Customer. Where notification within 72 hours is not possible, ForezynPlan will provide an initial notification within 72 hours and a more detailed report as soon as reasonably practicable thereafter.

ForezynPlan's notification will include, to the extent known at the time: (a) a description of the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and Personal Data records concerned; (b) the name and contact details of ForezynPlan's Data Protection contact; (c) the likely consequences of the Personal Data Breach; and (d) the measures taken or proposed to address the breach.

Important: The Customer is solely responsible for determining whether a Personal Data Breach must be notified to the relevant Supervisory Authority and/or affected Data Subjects under Applicable Data Protection Law, and for making any such notifications within the timeframes required by law (typically 72 hours for Supervisory Authorities under GDPR). ForezynPlan's notification to the Customer does not substitute for the Customer's own notification obligations.

ForezynPlan will co-operate with the Customer and take reasonable commercial steps to assist in the investigation, mitigation, and remediation of each Personal Data Breach.

09
10

Data Protection Impact Assessments

Where the Customer is required to carry out a Data Protection Impact Assessment (DPIA) or prior consultation with a Supervisory Authority under Articles 35 and 36 of the EU GDPR (or equivalent UK GDPR provisions) in connection with the Services, ForezynPlan will provide the Customer with reasonable assistance, including access to relevant information about ForezynPlan's processing activities and technical and organisational security measures.

ForezynPlan will notify the Customer as soon as practicable if it becomes aware that any instruction from the Customer would, in ForezynPlan's reasonable opinion, require the Customer to conduct a DPIA or is likely to result in a high risk to Data Subjects.

10
11

International Data Transfers

ForezynPlan stores and primarily processes Personal Data within the European Economic Area (EEA), using Microsoft Azure data centres in the EU West Europe and North Europe regions. ForezynPlan does not proactively transfer Personal Data outside the EEA or the UK without appropriate safeguards.

Where Personal Data is transferred to Sub-processors located outside the EEA or the UK (see Section 6), ForezynPlan ensures that such transfers are made on the basis of: (a) an adequacy decision by the European Commission or the UK Secretary of State; (b) Standard Contractual Clauses (EU SCCs — Commission Implementing Decision 2021/914 or the UK IDTA/Addendum, as applicable); or (c) another appropriate safeguard under Article 46 of the EU GDPR or UK GDPR.

By entering into this DPA, the Customer authorises ForezynPlan to make these transfers subject to the safeguards described above. Where SCCs are used, the Customer (as Controller) and ForezynPlan (as Processor) agree that the Module Two SCCs (Controller to Processor) are incorporated into this DPA by reference, with ForezynPlan acting as the data exporter and the relevant Sub-processor as the data importer, to the extent applicable.

ForezynPlan will promptly notify the Customer if it is required to suspend or terminate an international transfer mechanism and will co-operate in good faith to identify an alternative mechanism.

11
12

Data Retention & Deletion

ForezynPlan will retain Personal Data for the duration of the Customer's subscription and for a further period of 30 days following termination or expiry of the subscription ("Retention Period"), during which the Customer may request an export of its data. After the Retention Period, ForezynPlan will securely delete or anonymise all Personal Data in its systems, including backups, subject to any overriding legal retention obligation.

Customers may configure custom data retention policies within the platform (e.g., extending or reducing the Retention Period) subject to ForezynPlan's minimum and maximum retention limits and any applicable regulatory requirements. Enterprise customers may negotiate bespoke retention terms.

ForezynPlan uses cryptographic erasure (key destruction) to delete data from encrypted storage, supplemented by logical deletion from application databases. Physical media containing Personal Data is decommissioned in accordance with NIST SP 800-88 guidelines.

On receipt of a written request from the Customer, ForezynPlan will issue a written confirmation of deletion within 30 days of completing the deletion process.

12
13

Audit & Inspection Rights

ForezynPlan will make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations of a Processor under Applicable Data Protection Law, and will allow for and contribute to audits and inspections conducted by the Customer or an auditor mandated by the Customer.

Before exercising any audit right, the Customer must: (a) provide at least 30 days' prior written notice; (b) ensure the audit is conducted during normal business hours; (c) use a qualified and independent auditor (not a competitor of ForezynPlan); and (d) ensure the auditor is bound by confidentiality obligations. Audits shall be limited in scope to matters directly relevant to ForezynPlan's compliance with this DPA and shall not unreasonably disrupt ForezynPlan's operations.

As an alternative to a direct audit, ForezynPlan may satisfy the Customer's audit requirements by providing: (a) its current SOC 2 Type II report; (b) its ISO 27001 certificate; and/or (c) responses to a Customer-provided security questionnaire. ForezynPlan will make its SOC 2 Type II report available to the Customer under a Non-Disclosure Agreement within 10 business days of a written request.

The Customer may conduct no more than one audit per calendar year, unless an audit is required by a Supervisory Authority or follows a confirmed Personal Data Breach attributable to ForezynPlan.

13
14

Liability & Indemnity

ForezynPlan's liability to the Customer for any breach of this DPA shall be subject to the limitations and exclusions set out in the Terms of Service (or Master Services Agreement), except that nothing in this DPA shall limit ForezynPlan's liability for: (a) death or personal injury caused by its negligence; (b) fraud or fraudulent misrepresentation; or (c) any other liability that cannot be excluded by law.

Each party shall indemnify and hold harmless the other party from any losses, claims, damages, and regulatory fines arising from the indemnifying party's breach of its obligations under this DPA, subject always to the limitations set out in the Terms of Service.

Where a Supervisory Authority or court of competent jurisdiction holds both parties jointly and severally liable for a Personal Data Breach, the parties agree to allocate liability between themselves in proportion to their respective responsibility for the damage caused.

14
15

Governing Law & Contact

This DPA shall be governed by and construed in accordance with the laws of England and Wales. Any disputes arising under or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales, except where the Customer is domiciled in the EU, in which case the courts of the Customer's domicile shall have non-exclusive jurisdiction.

This DPA may be updated by ForezynPlan from time to time to reflect changes in Applicable Data Protection Law, supervisory authority guidance, or ForezynPlan's processing activities. ForezynPlan will provide at least 30 days' notice of material changes. The Customer's continued use of the Services after the notice period constitutes acceptance of the updated DPA.

To execute a countersigned version of this DPA, to request a copy of our SOC 2 report, or to raise any queries about our data processing practices, please contact the ForezynPlan Data Protection team using the details below.

ForezynPlan Data Protection Team

15
Data Processing Agreement — ForezynPlan — ForezynPlan