---
title: "Data processing note · Foundiry"
description: "When you enter data about other people, you are the controller and Foundiry is your processor. What that means, and how to get a signed DPA."
url: "https://foundiry.com/legal/dpa"
---

Legal

# Data processing note

A plain-language summary of the controller/processor relationship for the personal data you put into your workspace about other people. A signed DPA is available on request.

- **Version**: 1.0
- **In effect from**: 4 Sept

## 1. Who is what

Two different relationships run in parallel, and confusing them is the usual source of trouble.

- **Your own account data**: your name, email, country, billing details. We are the **controller**. Covered by the [privacy policy](https://foundiry.com/legal/privacy).
- **Data you enter about other people**: colleagues you invite, sales contacts, investor contacts, candidates. You are the **controller**; we are your **processor** and act on your instructions. This note covers that.

## 2. What we do with it

We process it only to provide the service to you: storing it, showing it back to the people in your workspace who are permitted to see it, running the product’s calculations over it, and, only for a specific action you approve, sending the necessary part to the provider performing that action.

We do not use it for our own purposes, we do not sell it, and we do not train models on it. Using it any other way would make us a controller of it, which we are not.

## 3. Your responsibilities

- Having a lawful basis for the personal data you enter about other people.
- Telling those people how their data is used, where the law requires it.
- Handling requests they make to you about their data. You can use the product’s own export and deletion tools, and we will help where we can.
- Not entering special-category data. The product is not designed for it and we do not want it.
- Managing who in your workspace can see what, using the roles available to you.

## 4. Our commitments as processor

- Process only on your documented instructions, which the product’s own interface constitutes.
- Keep it confidential and require the same of anyone with access.
- Apply the technical measures described on the security page: per-workspace isolation enforced in the database, private file storage, hashed share tokens, step-up verification for sensitive actions.
- Use only the sub-processors listed in the privacy policy, each under equivalent terms, and tell you before adding one.
- Help you respond to data-subject requests and to regulators.
- Notify you without undue delay if we become aware of a breach affecting your data.
- Delete or return the data at the end of the agreement, subject to records we must retain by law.

## 5. Sub-processors and transfers

The full list is in the [privacy policy](https://foundiry.com/legal/privacy), which also covers where processing happens and the transfer mechanism relied on when data crosses a border.

## 6. Getting a signed agreement

This note is a summary, not the agreement itself. If you need a signed DPA, including Standard Contractual Clauses, a sub-processor list as an annex, or a security schedule for your own compliance review, request one through [the contact form](https://foundiry.com/contact), or write to info@foundiry.com.

During the invite-only beta these are issued on request rather than published, so that what you sign is the reviewed version rather than a draft.

---

Questions about this document go to [our contact form](https://foundiry.com/contact). To exercise a data-protection right, use the [data request form](https://foundiry.com/legal/data-request).
