Data Processing Agreement
Last updated 13 September 2026
Who this is for: Business customers (for example financial advisers, accountants or firms) using Freeholt under a Master Service Agreement to hold information about their own clients. It does not apply to individual account holders, for whom the Privacy Policy applies.
This Data Processing Agreement ("DPA") forms part of the Master Service Agreement or other agreement (the "Agreement") between [Freeholt Pte. Ltd.] ("Freeholt", the "Processor") and the customer named in the Agreement (the "Customer", the "Controller"). It applies to the extent Freeholt processes Personal Data on behalf of the Customer in providing the Service.
Terms such as Personal Data, Data Subject, Processing, Controller, Processor, Sub-processor, Supervisory Authority and Personal Data Breach have the meanings given in the GDPR; equivalent terms in the UK GDPR, the Singapore PDPA and the Australian Privacy Act are read accordingly.
1. Roles and scope
- The Customer is the Controller of Customer Personal Data and Freeholt is its Processor. Where the Customer is itself a processor for a third-party controller, the Customer warrants that it has the authority to appoint Freeholt as a sub-processor on these terms.
- Freeholt is an independent Controller of the account data of the Customer's own users (names, email addresses, sign-in records), of billing data, and of aggregated, anonymised statistics (section 9); the Privacy Policy governs that processing.
- Annex I describes the subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects.
2. Instructions
Freeholt will process Customer Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by law that applies to Freeholt, in which case Freeholt will inform the Customer of that requirement before processing unless the law prohibits it.
The Customer's instructions are: the Agreement, this DPA, and the Customer's and its authorised users' use of the Service's features and settings. Additional instructions must be agreed in writing and may be subject to a reasonable fee if they require work outside the Service.
Freeholt will inform the Customer without delay if, in its opinion, an instruction infringes data protection law, and may suspend the affected processing until the instruction is confirmed or withdrawn.
The Customer is responsible for the lawfulness of the Customer Personal Data and its instructions, including having a lawful basis, giving Data Subjects the required notices, and obtaining any consents needed, in particular before entering a client's financial, tax residency or citizenship information.
3. Confidentiality
Freeholt ensures that every person it authorises to process Customer Personal Data is bound by a contractual or statutory duty of confidentiality, and that access is limited to those who need it to perform the Agreement.
4. Security
Freeholt implements and maintains the technical and organisational measures in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the Processing and the risk to Data Subjects. Freeholt may update Annex II from time to time provided the overall level of protection is not reduced.
The Customer is responsible for the security of its own systems, credentials and users, for configuring the Service appropriately (including which users have access and whether optional features such as the assistant, sharing or Legacy Access are used), and for deciding whether the measures in Annex II are appropriate for the Personal Data it chooses to enter.
5. Sub-processors
- The Customer gives Freeholt general written authorisation to engage the Sub-processors listed in Annex III, and to engage others, subject to this section.
- Freeholt will give the Customer at least 30 days' notice by email before a new Sub-processor processes Customer Personal Data, identifying the Sub-processor, its role and location. The Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection in good faith within 30 days, the Customer may terminate the affected part of the Service on notice and receive a pro-rata refund of prepaid fees for the terminated part.
- Freeholt will impose on each Sub-processor, by written contract, data protection obligations that are no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each Sub-processor's obligations.
6. Assistance with Data Subject requests and compliance
- Taking into account the nature of the Processing, Freeholt will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects to exercise their rights. The Service provides self-service access, correction, export (including a complete machine-readable backup) and deletion of the data a user has entered; where a request cannot be fulfilled through the Service, Freeholt will act on the Customer's written instruction within 10 business days.
- If Freeholt receives a request directly from a Data Subject relating to Customer Personal Data, it will refer the Data Subject to the Customer and notify the Customer without undue delay, and will not respond substantively except on the Customer's instruction or as required by law.
- Freeholt will assist the Customer, taking into account the nature of the Processing and the information available to it, in meeting the Customer's obligations regarding security, breach notification, data protection impact assessments and prior consultation with Supervisory Authorities.
- Freeholt may charge a reasonable fee for assistance that goes beyond what the Service provides or that is caused by the Customer's own breach.
7. Personal Data Breach
Freeholt will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point; information may be provided in phases as it becomes available. Freeholt will cooperate with the Customer's investigation and remediation. Notification is not an admission of fault.
8. Deletion and return
On termination or expiry of the Agreement, or earlier on the Customer's written request, the Customer may export Customer Personal Data using the Service's export and backup features for 30 days, after which Freeholt will delete all Customer Personal Data (and existing copies) within a further 30 days, unless and to the extent that law requires Freeholt to retain it. Provider backups that contain the data expire within 30 days of deletion and are not used to restore a terminated account. Freeholt will confirm deletion in writing on request.
9. Aggregated and anonymised data
Freeholt may create aggregated, anonymised statistics from Customer Personal Data in the manner and subject to the safeguards described in section 5 of the Privacy Policy (identifiers removed, minimum group size, coarsening, no re-identification). Such statistics do not identify the Customer, its users, or any Data Subject, are not Personal Data, and may be used by Freeholt for any lawful purpose during and after the Agreement. The Customer may opt its account out of contributing to statistics by written notice; the opt-out applies prospectively.
10. Audits
- Freeholt will make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA, including summaries of security measures, sub-processor contracts (redacted for commercial terms), and any third-party audit reports or certifications Freeholt holds.
- Where that information is not sufficient to demonstrate compliance, the Customer (or an independent auditor it appoints who is bound by confidentiality and is not a competitor of Freeholt) may audit Freeholt's compliance no more than once in any 12-month period, or additionally following a Personal Data Breach or where required by a Supervisory Authority, on at least 30 days' written notice, during business hours, without unreasonably disrupting Freeholt's operations, and at the Customer's cost. Audits of Sub-processors are conducted through the audit rights Freeholt holds against them.
11. International transfers
Customer Personal Data is stored in Seoul, South Korea (AWS ap-northeast-2) and processed by Sub-processors in the United States, as set out in Annex III.
- Where Customer Personal Data is subject to the GDPR and is transferred to a country without an adequacy decision, the parties enter into the EU Standard Contractual Clauses (Commission Decision (EU) 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, which are incorporated by reference with the Customer as data exporter and Freeholt as data importer; Clause 7 (docking) is included, Clause 9 option 2 with the notice period in section 5 applies, Clause 11 optional language is not included, Clause 13 is completed according to the Customer's establishment, Clause 17 selects the law of Ireland and Clause 18 the courts of Ireland, and Annexes I, II and III of this DPA serve as the Annexes to the Clauses. South Korea benefits from an EU adequacy decision, so storage there does not itself require the Clauses.
- Where Customer Personal Data is subject to the UK GDPR, the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the Information Commissioner's Office is incorporated, with Table 2 selecting the modules above, and applies to transfers from the United Kingdom.
- Where Customer Personal Data is subject to the Singapore PDPA, Freeholt ensures each overseas recipient is bound by legally enforceable obligations to provide a standard of protection comparable to the PDPA, in accordance with the Personal Data Protection Regulations 2021.
- Where Customer Personal Data is subject to the Australian Privacy Act, the Customer acknowledges that it is disclosed to overseas recipients in South Korea and the United States, and Freeholt takes reasonable steps, by contract with each recipient, to ensure the recipient does not breach the Australian Privacy Principles.
- Onward transfers by Freeholt to Sub-processors are made under the Sub-processor's own standard contractual clauses or an applicable adequacy or certification mechanism.
12. Liability and precedence
Each party's liability under or in connection with this DPA is subject to the exclusions and limitations of liability in the Agreement, and this DPA does not increase either party's total liability. Nothing in this section limits a party's liability to a Data Subject or Supervisory Authority under data protection law where that liability cannot be limited by contract.
In the event of conflict, the Standard Contractual Clauses prevail over this DPA, this DPA prevails over the Agreement, and the Agreement prevails over the Privacy Policy, in each case to the extent of the conflict and only in relation to the Processing of Customer Personal Data.
13. Term and changes
This DPA applies for as long as Freeholt processes Customer Personal Data. Freeholt may update this DPA to reflect changes in law, in Sub-processors (subject to section 5) or in the Service, on 30 days' notice; a change that materially reduces the Customer's protections requires the Customer's agreement.
14. Annex I: Description of the Processing
| Item | Description |
|---|---|
| Subject matter | Hosting and processing of financial planning data entered by the Customer and its users into the Freeholt Service. |
| Duration | The term of the Agreement plus the export and deletion periods in section 8. |
| Nature and purpose | Storage, retrieval, calculation (projections, comparisons, tax estimates), report and export generation, optional AI narration or assistant, optional email digests, backup, and support, as directed by the Customer through the Service. |
| Categories of Data Subjects | The Customer's clients and their household members (partners, beneficiaries), and the Customer's own authorised users. |
| Types of Personal Data | Names (optional), email addresses, year of birth, retirement ages, countries of tax residence and periods, citizenships, property details including addresses, loan and account balances and the institutions they are held with, income, expenses, savings, pension and investment holdings and transactions, goals and assumptions, assistant conversations, and technical data (IP address and browser in security and Legacy Access logs). |
| Special categories | None are requested. The Customer must not enter special category data, criminal offence data, government identifiers, or financial credentials. |
| Frequency | Continuous, for the duration of the Agreement. |
15. Annex II: Technical and organisational measures
- Access control: every database query from the application is restricted by row-level security to the authenticated account; a service-role credential is used only server-side, scoped to a verified account identifier, and is never exposed to browsers. Administrative access requires multi-factor authentication. Tenant isolation is asserted by an automated gate in continuous integration on every change.
- Encryption: TLS for all traffic; HTTP Strict Transport Security; encryption at rest of the database and its backups by the database provider.
- Authentication: minimum 12-character passwords with mixed character classes, breach-list checking at sign-up, hashed storage by the authentication provider, rate limiting of sign-in and reset attempts.
- Data minimisation: no bank credentials, card numbers or uploaded statement files are stored; statement account numbers are reduced to the last four digits and a keyed one-way hash; audit logs record metadata, never financial values; the AI narration feature sends a structured summary without identifiers.
- Integrity and availability: managed database with provider backups; documented restore runbook; scheduled jobs are authenticated and idempotent; schema changes are versioned and verified by a migration-drift gate.
- Application security: content security policy, frame denial, MIME sniffing protection, referrer and permissions policies on every response; input validation on every server action; error messages sanitised so schema and values are never returned to a browser; no dynamic code evaluation in the application.
- Deletion: self-service and administrative erasure delete every account-linked record in one operation, from a single maintained list that is checked against the schema by an automated test; a minimal erasure record is retained as evidence.
- Organisational: access to production limited to named personnel under confidentiality; secrets held in the hosting provider's encrypted environment configuration and never in source control; dependency and security advisories reviewed; a written security review with tracked findings.
16. Annex III: Authorised Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Managed database, authentication, storage | Seoul, South Korea (AWS ap-northeast-2); US control plane |
| Vercel, Inc. | Application hosting, serverless functions, scheduled jobs, edge network | Seoul, South Korea (AWS ap-northeast-2) (functions); global edge; United States |
| Stripe, Inc. | Payment processing and subscription billing (Customer's own billing data only) | United States |
| Resend, Inc. | Transactional email delivery | United States |
| Anthropic, PBC | Language model for optional assistant and narration features (only when the Customer or its users invoke them) | United States |
Amazon Web Services, Inc. provides the underlying infrastructure for Supabase and Vercel in the regions stated.
Freeholt is a calculator based on the information you provide. It is not financial, tax or legal advice. Please consult a licensed professional.