This page lists the third parties that process personal data in connection with Finexer's services. Section 1 is the complete list of our sub-processors, meaning the third parties that process personal data which we handle on behalf of a client. That section forms Annex 1 to our Data Processing Agreement and is the list referred to in Section 4 of that agreement. The sections that follow cover providers that process personal data for which Finexer is itself the controller, and parties that are not our processors at all. We publish those sections for transparency, and the notification and objection process described below applies to section 1.
We keep this page current. Before we add or replace a sub-processor that processes personal data on behalf of a client, we notify affected clients and give them at least 30 days to object in writing on reasonable data protection grounds. We work in good faith to resolve an objection during that period. If it cannot reasonably be accommodated, the options may include not making the change, offering a reasonable alternative, or allowing the client to terminate the affected services without penalty before the proposed sub-processor is used for its personal data. The full process is set out in Section 4 of the Data Processing Agreement.
We send that notice automatically to the data protection contact recorded in your Finexer Account. You must keep that contact current, including after any change of personnel, so that notice reaches you.
1. Sub-processors engaged in providing the Services
These are the sub-processors that may process personal data we handle on behalf of a client, including account information, payment initiation details and client-facing copies or extracts of consent and audit data. Finexer's canonical consent, authorisation and regulated-service audit record is separate Controller processing described in our Privacy Policy.
| Entity | Purpose | Corporate location | Data location |
|---|---|---|---|
| Microsoft Ireland Operations Limited (Microsoft Azure) | Cloud infrastructure, application hosting and data storage | Ireland, part of a group headquartered in the USA | North Europe (Ireland) |
| Microsoft Ireland Operations Limited (Microsoft Azure AI Document Intelligence) | Automated reading of the required data fields from an identity document submitted by a client as part of a Verification check. The service reads the document and returns those fields to us so that we can perform the comparison and produce the result | Ireland, part of a group headquartered in the USA | United Kingdom |
| Amazon Web Services EMEA SARL | Cloud infrastructure, data storage, delivery of one-time passcodes by SMS through Amazon Simple Notification Service, and delivery of our system emails, including one-time passcodes, password resets, billing notices and dashboard notifications | Luxembourg, part of a group headquartered in the USA | Europe (Ireland), eu-west-1 |
A data location in this table identifies the primary region in which the relevant service stores or processes data. It does not, by itself, exclude remote support or administration by authorised supplier personnel or onward access within a supplier's corporate group. We assess those arrangements separately and apply the transfer mechanism required by UK data protection law where access from another country constitutes a restricted transfer.
The document-reading service is used only where a client submits an identity document for a Verification check. For a document-check flow enabled in production, the image is removed from active systems no later than 30 days after the check and the deletion control must be verified before production use. An inaccessible residual copy may remain in a protected backup for no more than 90 further days, after which it expires under the verified backup lifecycle, as described in our Privacy Policy.
The data location shown for Amazon Web Services is where it stores and processes data for us. Where a message is sent to a mobile number, final delivery necessarily involves onward transmission by mobile network operators and their interconnect partners, which may be outside the United Kingdom depending on the number and the network. Those operators carry the message as part of providing a public telecommunications service and act as controllers in their own right rather than as our sub-processors, so we cannot specify or control the route a message takes.
2. Processors engaged for our own purposes
These providers process personal data for which Finexer is the controller. That includes personal data relating to our clients' staff and to prospective clients, and, where the table says so, technical data such as an IP address that we process in order to keep accounts and the Services secure. None of them has access to account information retrieved from a bank, or to payment data.
Where we use more than one provider to perform the same technical function, and none of those providers processes personal data on behalf of a client, we describe them in the table below by that function and by where they are established, rather than listing each entity separately. We will tell you which providers we currently use for such a function if you ask. This convention applies only to this section. A provider that processes personal data we handle on behalf of a client is named individually in section 1, whatever its size.
| Entity | Purpose | Corporate location | Data location |
|---|---|---|---|
| HubSpot, Inc. | Customer relationship management, sales and client communications | USA | EU / UK |
| Global Data Consortium, Inc., part of the London Stock Exchange Group (LSEG Risk Intelligence) | Identity verification of the directors and other persons responsible for the management of a prospective or existing client, carried out during onboarding and on a due diligence refresh. We submit the individual's name, date of birth, address and telephone number as given to us in the Onboarding Application, and receive back only a verification result. A check is run individually, at the discretion of our compliance team, and not automatically for every individual | USA | USA and, where the provider routes a check to a local reference source, the country of that source |
| IP geolocation providers established in the European Union | Resolution of an IP address into an approximate location. We use this to identify access to a Finexer Account from a location not previously seen for that account, so that we can ask for additional verification, and to establish the approximate location of the connection used to complete a consent journey. We send the IP address and receive back location and network information | European Union | European Union |
The transfer mechanism we rely on for each provider in this section is:
- HubSpot, Inc.: the UK Extension to the EU–US Data Privacy Framework, under which HubSpot maintains an active self-certification;
- Global Data Consortium, Inc.: the UK International Data Transfer Addendum to the EU standard contractual clauses, supported by our own transfer risk assessment; and
- IP geolocation providers established in the European Union: the United Kingdom's adequacy regulations for the European Economic Area, since no transfer outside it is involved.
If a provider's certification lapses, or we replace it with one that is not certified, we will make the transfer under the UK International Data Transfer Addendum instead, supported by our own transfer risk assessment, and will update this page accordingly.
A provider of this kind receives only the IP address to be resolved, and returns location and network information drawn from its own database. We require that it holds the address for no longer than is necessary to answer the request and to investigate faults, that it does not disclose the address to any other company or provider, and that it does not use the address for any other purpose. We carry out this lookup for fraud prevention, security monitoring and to complete consent records retained under our documented policy or an applicable requirement, and we decide ourselves that it takes place, which provider performs it and what we retain. It is therefore processing for which Finexer is the controller, and the provider is our processor rather than a sub-processor of a client's personal data. Where the lookup relates to a consent journey, we also make the approximate location available to the client concerned, as described in clause 12.5 of our Client Terms.
3. Website analytics and marketing
These providers process personal data collected through our public website, for which Finexer is the controller. Except for strictly necessary technologies, they operate only where you have given consent through our cookie banner. They have no access to account information, payment data or the Finexer Account. Further detail is in our Privacy Policy.
| Entity | Purpose | Category | Processing location and transfer safeguard |
|---|---|---|---|
| Google Ireland Limited (Google Tag Manager) | Loading of the tags described in this section, subject to Google Consent Mode. The container itself does not set a cookie or read or write device storage; it is not, itself, a stored cookie falling within a consent category, though the tags it loads once permitted are | Tag-management infrastructure (network request to Google; no device storage by the container itself). See the Privacy Policy for the lawful basis and consent controls | Contracting entity in Ireland (EEA). Google's global infrastructure may process data outside the EEA and the UK, under Google's own Standard Contractual Clauses and the UK International Data Transfer Addendum |
| Google Ireland Limited (reCAPTCHA) | Distinguishing human visitors from automated submissions on our contact, registration, newsletter and job application forms | Form security. The PECR treatment is assessed and documented separately for each form; the technology is treated as strictly necessary only where the narrow exception is supported, and otherwise requires consent before loading or execution | Contracting entity in Ireland (EEA). Google's global infrastructure may process data outside the EEA and the UK, under Google's own Standard Contractual Clauses and the UK International Data Transfer Addendum |
| Google Ireland Limited (Google Analytics) | Website usage statistics in pseudonymised form | Analytics | Contracting entity in Ireland (EEA). Google's global infrastructure may process data outside the EEA and the UK, under Google's own Standard Contractual Clauses and the UK International Data Transfer Addendum |
| Ahrefs Pte. Ltd. (Ahrefs Analytics) | Website usage statistics | Analytics | Singapore, with underlying infrastructure hosted in the United States. Singapore is not covered by UK adequacy regulations. We transfer data under the UK International Data Transfer Addendum to Ahrefs' EU Standard Contractual Clauses (Controller-to-Processor module), supported by our own transfer risk assessment, a copy of which is available on request |
| Google Ireland Limited (Google Ads) | Advertising measurement and delivery | Marketing | Contracting entity in Ireland (EEA). Google's global infrastructure may process data outside the EEA and the UK, under Google's own Standard Contractual Clauses and the UK International Data Transfer Addendum |
| Dealfront Group GmbH (Leadfeeder) | Identification of business interest in our services | Marketing | Germany (EEA). Transfers from the UK to the EEA are permitted under the UK's adequacy regulations for the EEA |
| Albacross Nordic AB | Identification of business interest in our services | Marketing | Sweden (EEA). Transfers from the UK to the EEA are permitted under the UK's adequacy regulations for the EEA |
| Snitcher B.V. | Identification of business interest in our services | Marketing | Netherlands (EEA). Transfers from the UK to the EEA are permitted under the UK's adequacy regulations for the EEA |
Where a provider above also has its own sub-processors, its own privacy notice, cookie notice or Data Processing Addendum describes their identity and location in more detail.
4. Parties that are not sub-processors
Some third parties receive personal data in connection with our services but are not our sub-processors, because they do not process it on our instructions. They act as controllers in their own right, and their own privacy notices apply.
- Banks and other account providers. When we access an account or transmit a payment instruction, the bank processes personal data as a controller under its own agreement with the account holder. We do not appoint or instruct banks and they are not our sub-processors.
- Companies House. We use the Companies House register to verify a business, its directors and its beneficial owners during onboarding. Companies House is a public authority and an independent controller.
- Regulators and authorities. The Financial Conduct Authority, the Information Commissioner's Office, HM Revenue and Customs, law enforcement and the courts act as controllers in their own right where we are required to disclose information to them.
- A client's own email provider. Where a client configures its own SMTP server so that notifications to its customers are sent from its own domain, delivery is handled by the provider that client has chosen. That provider is the client's supplier, not ours.
- Our own transactional email service. Our system emails are composed and queued by mail infrastructure that Finexer operates itself on its own servers. That infrastructure is ours, not a third party's, so it is not a sub-processor. Final delivery of those emails is performed by Amazon Web Services, which is listed as a sub-processor in the table in section 1.
5. Use of personal data for artificial intelligence and model training
We do not use client or end-user personal data to train, fine-tune or improve a general-purpose artificial intelligence or machine learning model, and we do not permit our sub-processors to do so. Transaction categorisation, where a client enables it, uses models that operate solely to provide the service to that client.
If we introduce a sub-processor that provides artificial intelligence functionality, we will add it to the table in section 1 and notify affected clients in advance in accordance with Section 4 of the Data Processing Agreement, so that the 30-day objection right applies before any processing begins.