Last updated: July 2026
This Data Processing Agreement (“DPA”) pursuant to Art. 28 GDPR is concluded between FjordPoint Capital GmbH, Im Prüfling 2, 60389 Frankfurt am Main, Germany (“Processor”) and the customer identified in the Fynton account (“Controller”) for the use of Fynton (“Service”), accessible at fynton.ai. It applies where the Controller processes personal data through the Service and the Processor processes that data on the Controller's behalf.
This DPA is accepted by the Controller by checking the acceptance box in the first-login Terms modal. It is effective for the duration of the subscription and terminates upon account deletion. A PDF copy is available for download here; enterprise customers may request a countersigned copy at fynton@fjordpoint-capital.com.
The Processor provides a B2B SaaS platform for AI-assisted investor matching and relationship management. The Processor processes personal data on behalf of the Controller for the duration of the subscription and until all data is deleted in accordance with the Terms of Service and Privacy Policy.
Processing is limited to providing, operating, and improving the Service, including:
Types of data: names, business contact details (email, phone), company affiliations, job titles, interaction and usage data, notes, email metadata and (where connected) email body text for business-relevant messages, calendar metadata, billing contact details.
Categories of data subjects: the Controller's employees and authorised users; investors, allocators, and business contacts researched or managed through the Service; third-party contacts from publicly available or relationship-sourced sources.
The Processor shall:
The Controller authorises the Processor to engage the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database and authentication | EU (Frankfurt) |
| Render Services, Inc. | Application hosting | EU (Frankfurt) |
| Stripe Payments Europe, Ltd. | Payment processing | Ireland (EU) |
| OpenAI (OpenAI Ireland Ltd.) | AI processing | EU / USA (SCCs) |
| PostHog, Inc. | Analytics | EU (EU-hosted) |
| Google Ireland Limited | OAuth login, email integration | Ireland (EU) |
DPAs are concluded with all sub-processors; Standard Contractual Clauses are in place where applicable. The Processor ensures each sub-processor is bound by data protection obligations equivalent to this DPA. The Processor will inform the Controller of intended changes to sub-processors; the Controller may object on reasonable grounds relating to data protection within 14 days of notification.
Primary data storage and application hosting are in the EU (Frankfurt region). Transfers outside the EU/EEA are based on EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and/or adequacy decisions (e.g. EU-US Data Privacy Framework), as described in the Privacy Policy (Section 7). PostHog is EU-hosted; no transfer applies.
The Controller shall:
The Processor notifies the Controller within 72 hours of becoming aware of a personal data breach, providing the information required under Art. 33(3) GDPR.
Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. Nothing in this DPA limits either party's liability for breaches of data protection law where such limitation is not permitted by applicable law.
This DPA is governed by German law. Place of jurisdiction: Frankfurt am Main, Germany.
FjordPoint Capital GmbH
Im Prüfling 2, 60389 Frankfurt am Main, Germany
Email: fynton@fjordpoint-capital.com