← Back to home

Data Processing Agreement (DPA)

Last updated: July 2026

This Data Processing Agreement (“DPA”) pursuant to Art. 28 GDPR is concluded between FjordPoint Capital GmbH, Im Prüfling 2, 60389 Frankfurt am Main, Germany (“Processor”) and the customer identified in the Fynton account (“Controller”) for the use of Fynton (“Service”), accessible at fynton.ai. It applies where the Controller processes personal data through the Service and the Processor processes that data on the Controller's behalf.

This DPA is accepted by the Controller by checking the acceptance box in the first-login Terms modal. It is effective for the duration of the subscription and terminates upon account deletion. A PDF copy is available for download here; enterprise customers may request a countersigned copy at fynton@fjordpoint-capital.com.

1. Subject matter and duration

The Processor provides a B2B SaaS platform for AI-assisted investor matching and relationship management. The Processor processes personal data on behalf of the Controller for the duration of the subscription and until all data is deleted in accordance with the Terms of Service and Privacy Policy.

2. Nature and purpose of processing

Processing is limited to providing, operating, and improving the Service, including:

  • Storing and displaying investor profiles, contacts, and pipeline data entered or generated for the Controller
  • Running AI-assisted matching, enrichment, and outreach suggestions
  • Processing interaction data (accepts, declines, relationship status, notes) to personalise the Controller's agents
  • Optional email and calendar integration data connected by the Controller
  • Billing, support, and security operations

3. Types of personal data and categories of data subjects

Types of data: names, business contact details (email, phone), company affiliations, job titles, interaction and usage data, notes, email metadata and (where connected) email body text for business-relevant messages, calendar metadata, billing contact details.

Categories of data subjects: the Controller's employees and authorised users; investors, allocators, and business contacts researched or managed through the Service; third-party contacts from publicly available or relationship-sourced sources.

4. Obligations of the Processor

The Processor shall:

  • Process personal data only on the Controller's instructions (deemed given by use of the Service, including these Terms, this DPA, and in-product actions), unless required by EU or Member State law
  • Ensure that all persons authorised to process personal data are bound by confidentiality
  • Implement appropriate technical and organisational measures pursuant to Art. 32 GDPR, including encryption of email body content at rest (see Privacy Policy, Section 13)
  • Not engage sub-processors beyond those listed in Section 5 without notifying the Controller (14-day objection window)
  • Forward data subject requests (Art. 15–22 GDPR) to the Controller without undue delay and assist where feasible
  • Assist the Controller with its obligations under Art. 32–36 GDPR (security, breach notification, data protection impact assessments)
  • Delete all personal data within 30 days of account termination, subject to statutory retention obligations
  • Provide information necessary to demonstrate compliance with Art. 28 GDPR and support audits upon reasonable notice (reasonable costs may apply beyond standard documentation)

5. Sub-processors

The Controller authorises the Processor to engage the following sub-processors:

Sub-processor Purpose Location
Supabase Inc. Database and authentication EU (Frankfurt)
Render Services, Inc. Application hosting EU (Frankfurt)
Stripe Payments Europe, Ltd. Payment processing Ireland (EU)
OpenAI (OpenAI Ireland Ltd.) AI processing EU / USA (SCCs)
PostHog, Inc. Analytics EU (EU-hosted)
Google Ireland Limited OAuth login, email integration Ireland (EU)

DPAs are concluded with all sub-processors; Standard Contractual Clauses are in place where applicable. The Processor ensures each sub-processor is bound by data protection obligations equivalent to this DPA. The Processor will inform the Controller of intended changes to sub-processors; the Controller may object on reasonable grounds relating to data protection within 14 days of notification.

6. International transfers

Primary data storage and application hosting are in the EU (Frankfurt region). Transfers outside the EU/EEA are based on EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and/or adequacy decisions (e.g. EU-US Data Privacy Framework), as described in the Privacy Policy (Section 7). PostHog is EU-hosted; no transfer applies.

7. Controller obligations

The Controller shall:

  • Ensure it has a valid legal basis for all personal data it uploads, connects, or causes to be processed through the Service
  • Comply with applicable data protection laws, including providing required notices to data subjects
  • Not use the Service to process special categories of data (Art. 9 GDPR) unless explicitly agreed in writing
  • Ensure authorised users comply with the Terms of Service and this DPA

8. Data breaches

The Processor notifies the Controller within 72 hours of becoming aware of a personal data breach, providing the information required under Art. 33(3) GDPR.

9. Liability

Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. Nothing in this DPA limits either party's liability for breaches of data protection law where such limitation is not permitted by applicable law.

10. Governing law

This DPA is governed by German law. Place of jurisdiction: Frankfurt am Main, Germany.

11. Contact

FjordPoint Capital GmbH
Im Prüfling 2, 60389 Frankfurt am Main, Germany
Email: fynton@fjordpoint-capital.com

Legal notice / Imprint · Privacy · Terms · Disclaimer · DPA ·