Data Processing Agreement (Art. 28 GDPR)
Version 1.0 · effective 6 October 2026 · English is the authoritative version. Accepted as part of the Terms of Service when the customer creates an account.
Controller: the Customer (the business that subscribes). Processor: CySo Solutions Ltd, Republic of Cyprus, registration no. HE487195, registered office 7 Igerias Street, Limassol, Cyprus (legal@cysosolutions.com).
1. Subject matter and duration
The Processor reads, records, stores and makes available the Customer's bank and payment data in order to provide the CySo Bank Connector. This agreement lasts for the subscription, plus the deletion period in §8.
2. Nature and purpose
Purposes:
- collect data from the sources the Customer connects (banks through the Customer's own Enable Banking application; Viva.com notifications);
- store the data encrypted;
- make it available to the Customer and to the people, agents and AI assistants the Customer authorises.
The processing is read-only: the Service never initiates payments.
3. Data and data subjects
- Data: account identifiers (name, IBAN), balances, transactions (date, amount, description, counterparty name and IBAN), salary payments where present.
- Data subjects: the Customer's staff and owners, and the Customer's customers, suppliers, employees and other counterparties who appear in transactions.
- No special-category data is intended. Transaction texts are as the bank supplies them.
4. Processor obligations
The Processor:
- processes the data only on the Customer's documented instructions, including with regard to transfers to a third country, unless EU or Member State law requires otherwise; in that case it informs the Customer first, unless that law forbids it. The instructions are the Terms, the Customer's settings and the Customer's actions in the Service;
- ensures that anyone authorised to process the data is bound by confidentiality;
- applies the security measures in §5;
- uses sub-processors only as in §6;
- helps the Customer answer data-subject requests (Art. 28(3)(e)) and meet its duties on security, breach notification, impact assessments and prior consultation (Arts. 32–36), taking into account the nature of the processing;
- at the Customer's choice, deletes or returns the data at the end of the service, as in §8, unless EU or Member State law requires storage;
- makes available the information needed to show compliance, and allows audits as in §9;
- tells the Customer at once if an instruction appears to break data-protection law.
5. Security measures (summary)
- Every bank value (amounts, names, IBANs, descriptions, balances, session IDs) is encrypted with AES-256-GCM. Dates, internal IDs, the company name and flags are not. Keys are derived per customer from a master key held as an encrypted platform secret, never in source code.
- Links, keys and tokens are stored only as SHA-256 hashes, except the Viva notification address, which is stored encrypted so it can be shown to the Customer. Separate keys exist for web sign-in, set-up and reading.
- Every database query is scoped to the authenticated customer.
- Allow-listed outgoing calls: bank access is limited to account information (balances, transactions). The code refuses payment endpoints.
- Viva credentials are never stored. The Customer's Enable Banking key is stored only encrypted.
- Security log of key actions (no IP addresses, no bank values; deleted automatically after 12 months); automated tests for customer isolation; a security review before each major release.
6. Sub-processors
The Customer authorises Cloudflare, Inc. (hosting, database). (Stripe and Google handle only the Customer's account and billing data, never bank data; see the Privacy Notice.)
The Processor will notify the Customer by email at least 30 days before adding or replacing a sub-processor that handles bank data. The Customer may object; if the parties can't resolve the objection, the Customer may terminate and get back the unused part of the month it paid for. The Processor imposes the same data-protection obligations on each sub-processor and remains responsible for them.
Enable Banking, Viva.com and the Customer's AI provider are engaged by the Customer directly and are not sub-processors.
7. International transfers
Cloudflare is a US company, and requests are processed on its global network. Transfers rely on the EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework. The database is located in Cloudflare's Western-Europe region.
8. Deletion at the end
When the subscription ends, collection stops at once. All Customer bank data is deleted 30 days later, including the stored Enable Banking key, unless EU or Member State law requires storage. Before then, the Customer may export it (CSV). Copies in the database's recovery history expire within a further 30 days. The security log (no bank values) is kept 12 months.
9. Audits
The Processor gives the Customer, on request, a written description of its measures and the latest security-review summary, and allows audits by the Customer or an auditor it mandates. On-site audits require 30 days' notice, are limited to once a year unless there is a breach, and are at the Customer's cost.
10. Breach notification
The Processor notifies the Customer of a personal-data breach without undue delay, and within 48 hours of becoming aware of it. The notice includes what is known, and the rest follows as it becomes known.
11. Liability and precedence
Liability is as in the Terms of Service. If this agreement conflicts with the Terms on data protection, this agreement prevails.