Data Processing Addendum

Last updated on May 1, 2026

This Data Processing Addendum (the DPA) forms part of the agreement governing the Customer's use of any service provided by Ingram Technologies SRL that refers to this DPA (the Agreement). The parties are:

  • Ingram Technologies SRL, a Belgian private limited liability company with company number 0766280697, VAT number BE0766280697, and registered office at Rue du Poinçon 51A, 1000 Brussels, Belgium (Ingram, we, us); and
  • the person or entity that has entered into the Agreement with Ingram (Customer, you).

This DPA takes effect when the Customer accepts it electronically, enters into an Agreement that incorporates it, or begins using a Service whose terms incorporate it. A person accepting for an entity represents that they have authority to bind it.

This DPA applies to every Ingram Service. Each Service publishes its own Product Annex, linked from that Service's terms or legal pages, setting out the service-specific processing detail Article 28(3) GDPR requires. The applicable Product Annex forms part of this DPA.

The Privacy Policy describes the personal data Ingram processes as an independent Controller for its own account, and the rights of the individuals concerned. The Security & Compliance page describes Ingram's technical and organizational measures, and is incorporated as set out in section 6.2.

1. Definitions

  • Applicable Data Protection Law — the GDPR, the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data, and any other privacy or data-protection law applicable to processing under the Agreement.
  • Customer Personal Data — Personal Data that Ingram processes on the Customer's behalf in providing a Service.
  • Data Incident — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data on systems controlled by Ingram or its Subprocessors. Unsuccessful attempts that do not compromise Customer Personal Data are not Data Incidents.
  • GDPR — Regulation (EU) 2016/679.
  • Product Annex — the service-specific processing annex published for a Service, or that the Agreement otherwise identifies.
  • SCCs — the European Commission's standard contractual clauses adopted by Implementing Decision (EU) 2021/914.
  • Service — a product or service supplied by Ingram under the Agreement.
  • Subprocessor — a third party appointed by or on behalf of Ingram to process Customer Personal Data in connection with a Service.

Controller, Data Subject, Personal Data, Personal Data Breach, Process, Processor, and Supervisory Authority have the meanings given in the GDPR.

2. Scope and roles

2.1. This DPA applies only where Ingram processes Customer Personal Data as a Processor on the Customer's behalf. The Customer is the Controller of that data, or a Processor acting for another Controller. Where the Customer is a Processor, Ingram is its Subprocessor. Each party complies with the obligations that apply to it under Applicable Data Protection Law.

2.2. A Customer acting as a Processor warrants that the relevant Controller has authorized its instructions, Ingram's appointment, and the Subprocessors authorized under this DPA, and will act as Ingram's sole point of contact for that Controller unless the law requires otherwise.

2.3. Ingram also processes information as an independent Controller, for account administration, billing, fraud prevention, security, legal compliance, and business communications. That processing is outside this DPA and is described in the Privacy Policy.

3. Documented instructions

3.1. Ingram processes Customer Personal Data only on the Customer's documented instructions, unless Union or Member State law requires otherwise. Those instructions are the Agreement, this DPA, the applicable Product Annex, the Customer's configuration and use of the Service, and any further written instruction Ingram accepts. They authorize Ingram to process Customer Personal Data as necessary to provide, maintain, secure, troubleshoot, and support the Service and to perform the Agreement.

3.2. If law requires processing outside those instructions, Ingram will inform the Customer beforehand unless the law prohibits it on important grounds of public interest.

3.3. Ingram will promptly tell the Customer if an instruction appears to infringe Applicable Data Protection Law, and may suspend the affected processing until the Customer confirms or modifies it.

3.4. The Customer is responsible for the lawfulness, accuracy, and content of Customer Personal Data and its instructions, including giving required notices, establishing a lawful basis, and obtaining any authorization Ingram and its Subprocessors need.

3.5. Unless a Product Annex says otherwise, the Customer will not intentionally submit special categories of Personal Data under Article 9 GDPR, or data relating to criminal convictions and offences under Article 10 GDPR.

3.6. Where a Service uses AI-assisted processing, Ingram warrants that its agreement with each AI provider prohibits the provider from using Customer Personal Data to train, fine-tune, or otherwise develop or improve its models. Ingram will not use Customer Personal Data for those purposes itself.

4. Processing details

The applicable Product Annex sets out the subject matter, nature, purpose, duration and frequency of processing; the categories of Data Subjects and of Customer Personal Data; any special-category restrictions; the retention and deletion arrangements; the relevant international transfers; and where to find the current Subprocessor list.

5. Confidentiality and personnel

Everyone Ingram authorizes to process Customer Personal Data is bound by a duty of confidentiality, gets access only where their duties require it, and is trained on Ingram's security and privacy practices. Ingram remains responsible for its personnel's compliance with this DPA.

6. Security

6.1. Taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of processing, as well as the risks to Data Subjects, Ingram implements and maintains technical and organizational measures designed to provide a level of security appropriate to the risk, as Article 32 GDPR requires.

6.2. Those measures are described on the Security & Compliance page. That page, with any additional measures in the applicable Product Annex, is Ingram's description of its technical and organizational measures for the purposes of Article 28(3)(c) GDPR and Annex II of the SCCs, as it reads on the date this DPA takes effect. Ingram may update them to reflect technical development or changes to a Service provided the overall level of protection is not materially reduced, and will supply a point-in-time copy of the measures then in force on request.

6.3. The Customer is responsible for securing its own credentials, accounts, systems, devices, and integrations, controlling its authorized users, and configuring the Service appropriately for its risk.

7. Data Incidents

7.1. Ingram notifies the Customer without undue delay after becoming aware of a Data Incident affecting Customer Personal Data, at the Customer's designated privacy contact or account email. The notice contains the information listed in Article 33(3) GDPR to the extent known, and a contact point; Ingram may provide it in phases without undue further delay.

7.2. Ingram takes reasonable steps to contain, investigate, mitigate, and remediate the Data Incident, and cooperates reasonably with the Customer. Notification is not an admission of fault or liability, and the Customer remains responsible for the notifications it must make as Controller.

8. Data Subject requests

Taking into account the nature of the processing, Ingram assists the Customer through appropriate technical and organizational measures, insofar as possible, in responding to requests to exercise Data Subject rights. If Ingram receives such a request directly, it promptly refers it to the Customer and does not respond substantively unless the Customer instructs it to or the law requires it.

9. Compliance assistance

Taking into account the nature of processing and the information available to it, Ingram provides reasonable assistance with the Customer's obligations under Articles 32 to 36 GDPR, including security assessments, Personal Data Breach notifications, data protection impact assessments, and prior consultations.

If assistance requires material work beyond ordinary support, the parties may agree reasonable fees in advance. No fee applies where the assistance is needed because Ingram breached this DPA.

10. Subprocessors

10.1. The Customer gives Ingram general written authorization to appoint Subprocessors in accordance with this section. The current Subprocessors for each Service are identified on the page the applicable Product Annex references.

10.2. Ingram enters into a written agreement with each Subprocessor imposing data-protection obligations no less protective in substance than those this DPA imposes on Ingram, to the extent relevant to that Subprocessor's services.

10.3. For a planned appointment or replacement, Ingram gives at least 30 days' advance notice, by updating the relevant Subprocessor page and sending notice to the Customer's account email, before the new Subprocessor begins processing Customer Personal Data.

10.4. Where an urgent replacement is reasonably necessary to address a security risk, service failure, legal requirement, or material threat to service continuity, Ingram may appoint it sooner. Ingram will notify the Customer as soon as reasonably practicable, explain the reason, and preserve the objection right in section 10.5.

10.5. The Customer may object to a new or replacement Subprocessor on reasonable, documented data-protection grounds. The parties will work in good faith to resolve the objection; if no commercially reasonable solution is available, the Customer may terminate the affected Service by written notice, and Ingram will refund prepaid fees for the unused period where applicable.

10.6. Ingram remains responsible to the Customer for a Subprocessor's performance of its data-protection obligations to the same extent Ingram would be if it performed the processing itself.

11. International transfers

11.1. Ingram does not transfer Customer Personal Data outside the EEA unless it has a transfer mechanism valid under Chapter V GDPR and any supplementary measures the assessment shows to be required. The mechanisms Ingram relies on are described under "International Data Transfers" in the Privacy Policy; transfers specific to a Service are identified in its Product Annex. The same applies to onward transfers to a Subprocessor.

11.2. Where the SCCs are required for a transfer from the Customer to Ingram, they are incorporated by reference and completed as follows:

  • Module Two applies where the Customer is a Controller and Ingram is a Processor.
  • Module Three applies where the Customer is a Processor and Ingram is a Subprocessor.
  • Module Four applies where Ingram, acting as a Processor in the EEA, transfers or returns Personal Data to a Customer acting as a Controller in a third country and the transfer requires the SCCs.
  • Clause 7, the docking clause, applies.
  • Option 2 in Clause 9(a) applies, with the 30 days' notice period set out in section 10.3.
  • The optional language in Clause 11 does not apply.
  • For the purposes of Clause 13(a), the competent supervisory authority is the Belgian Data Protection Authority.
  • In Clause 17, Option 1 applies and Belgian law governs.
  • The courts of Brussels, Belgium are selected under Clause 18(b).
  • Annex I is completed by this DPA and the applicable Product Annex; Annex II by the measures referenced in section 6.2; and Annex III by the relevant Subprocessor page.

12. Return and deletion

12.1. During the Agreement, the Customer may request export or deletion to the extent the Service supports it.

12.2. On termination of the affected Service or the Customer's written request, Ingram will, at the Customer's choice, delete or return Customer Personal Data and delete remaining copies, unless the law requires retention. The periods within which deletion takes effect, including for backups, are those published under "Data Retention" and "Data Removal" on the Security & Compliance page as it reads on the date this DPA takes effect, as varied by the applicable Product Annex. Ingram may update those periods to reflect technical development or changes to a Service provided the overall level of protection is not materially reduced.

12.3. Where retention is legally required, Ingram isolates and protects the retained data, processes it only for that purpose, and deletes it when the requirement ends.

13. Information and audits

13.1. Ingram makes available the information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. That includes the published Security & Compliance documentation, a summary of Ingram's most recent independent penetration test findings on request, an overview of Ingram's security policies on request for enterprise customers, and responses to reasonable questionnaires, subject to confidentiality and security restrictions.

13.2. The Customer may request an audit once in any 12-month period, unless a Supervisory Authority requires otherwise or a Data Incident reasonably warrants another. The parties will first seek to satisfy the request through documents and remote review.

13.3. If an on-site or independent audit remains reasonably necessary, it takes place on reasonable prior notice, during business hours, without unreasonable disruption, under confidentiality obligations, and limited in scope to systems and records relevant to Customer Personal Data. The Customer bears its audit costs unless the audit identifies a material breach by Ingram. An audit may not expose another customer's data, trade secrets, or anything that would create a security risk.

14. Liability and precedence

14.1. The liability provisions of the Agreement apply to this DPA, except to the extent Applicable Data Protection Law or the SCCs prohibit limiting or excluding liability. Nothing here limits a Data Subject's rights.

14.2. On the processing or protection of Customer Personal Data, this DPA prevails over the Agreement, and over any page it incorporates, to the extent of a conflict. The applicable Product Annex prevails over this DPA where it expressly varies it. Where the SCCs apply, they prevail over all of them.

14.3. This DPA supersedes any earlier data processing addendum between the parties for the same Service, unless a later bilateral addendum expressly says otherwise.

15. Term and changes

15.1. This DPA continues for as long as Ingram processes Customer Personal Data, and survives termination to the extent necessary to protect that data.

15.2. Ingram may amend this DPA where reasonably necessary to comply with Applicable Data Protection Law, a binding decision, or a material change to a Service, giving advance notice of a material change where practicable. No amendment will materially reduce the protection of Customer Personal Data.

15.3. This DPA is in writing in electronic form for the purposes of Article 28(9) GDPR, and electronic acceptance records are evidence of agreement. The parties may execute a bilateral counterpart on request; the counterpart does not change the terms of this DPA unless it expressly says so.

15.4. This DPA is governed by Belgian law, and disputes go to the courts specified in the Agreement, without prejudice to mandatory rights under Applicable Data Protection Law or the SCCs.

16. Contact

Privacy and data-protection enquiries, including Data Subject requests: privacy@ingram.tech

Contractual notices under this DPA: legal@ingram.tech

Data Incident and vulnerability reports: security@ingram.tech


Financica Product Annex

Last updated: 7 September 2026

This Product Annex forms part of the Ingram Technologies Data Processing Addendum (DPA) when the Customer uses Financica. Capitalized terms not defined here have the meanings given in the DPA. The technical and organizational measures protecting the Personal Data described below are set out on the Security & Compliance page.

1. Subject matter and purpose

Financica is bookkeeping and accounting software. The Customer keeps its books in Financica: it records transactions in a double-entry ledger, connects or imports its bank activity, files documents against it, issues and receives invoices, and produces the reports and filings its accounting obligations require.

Ingram processes Customer Personal Data to sign the Customer's users in, hold the Customer's books and the documents and bank data behind them, run the bookkeeping the Customer asks for, exchange e-invoices on the Customer's instruction, prepare the VAT and annual-account outputs the Customer submits, answer the Customer's questions about its own data through the in-product assistant, and support and secure the Service.

Ingram does not act as the Customer's accountant and does not decide what the Customer's books should say. Financica records and computes; the Customer, and where applicable its accountant, remains responsible for the content of its accounts and its filings.

2. Nature, frequency, and duration

Processing is continuous for as long as the Customer's organization exists in Financica, because the Service holds the Customer's books rather than passing data through. It happens on every use — signing in, connecting a bank or another system, uploading a document, categorizing a transaction, issuing or receiving an invoice, running a report, exporting a filing, asking the assistant, or contacting support — and on the scheduled syncs and imports the Customer has enabled.

It consists of collecting, storing, structuring, computing on, exporting, transmitting, and deleting the data below, until deletion under section 5.

3. Data Subjects and Personal Data

The data can relate to the Customer's own users, staff and directors, to its customers, suppliers and other counterparties and their staff, and to anyone identified in the documents and transactions the Customer records — including sole traders trading under a business, VAT, or bank identifier.

It can include:

  • names, business contact details, and postal or billing addresses;
  • business, VAT, tax, and Peppol identifiers, and legal-form and registry data looked up from public company registers;
  • bank and payment data: account numbers (IBAN/BIC), account holder names, balances, and transaction lines with their counterparty names, references, communications and amounts;
  • invoice and document content: numbers, dates, descriptions, line items, amounts, payment terms and references, and the source files the Customer uploads or receives, together with the text extracted from them;
  • ledger content: postings, account assignments, analytical labels, attachments, comments, and any note the Customer's users write;
  • payroll, expense and other accounting entries the Customer chooses to record, to the extent they identify a person;
  • prompts and conversations with the in-product assistant, and the Customer data it reads to answer them; and
  • account and technical data generated by use of the Service, such as sign-in events, passkey credentials, IP addresses, audit records, and logs.

Financica is not designed for special categories of Personal Data under Article 9 GDPR or criminal-conviction data under Article 10 GDPR, and the Customer should not put such data in documents, ledger content, assistant prompts, or support requests.

4. Subprocessors, and the systems the Customer connects

Ingram engages the following Subprocessors for Financica. The authorization, notice, urgent-replacement, and objection arrangements in section 10 of the DPA apply to them.

SubprocessorPurposeLocation
Amazon Web Services EMEA SARLDatabase hosting, backups, and document text extractionEuropean Union
Vercel Inc.Application hosting and deliveryEuropean Union (compute), global (edge network)
Cloudflare, Inc.Object storage for uploaded documents, and outbound emailEuropean Union (storage), global (network)
Stripe Payments Europe, Ltd.Subscription billing for the Customer's own Financica planEuropean Union, United States
Exthand SRLPSD2 bank-account connections and transaction retrievalEuropean Union
Scrada BVPeppol access point for sending and receiving e-invoicesEuropean Union
GlitchTipError and performance monitoringEuropean Union
Ingram Technologies SRL (Ingram Cloud), and the AI model providers behind itThe in-product assistantEuropean Union, United States

The current list is also available from Ingram on request. Data sent to the assistant's model providers is not used to train their models.

The systems the Customer connects to Financica — its bank, its Stripe, PayPal or SumUp account, another accounting package, a tax authority portal — are the Customer's own systems, not Ingram Subprocessors. Financica reads from and writes to them on the Customer's instruction, under the Customer's direct relationship with each provider; where such a provider processes data for its own purposes, it does so under its own terms. The one exception is Stripe as billing processor for the Customer's own Financica subscription, which is listed above.

5. Retention and deletion

Financica is a system of record, so the Customer's books, documents and bank data are retained for as long as the Customer's organization exists in the Service. This is deliberate: accounting data is subject to statutory retention periods in the Customer's own jurisdiction, and the Customer, not Ingram, decides when it may be removed.

The Customer can delete individual records, documents and organizations from within the Service at any time. Deleting an organization removes its books, its documents and its bank connections.

When the Customer terminates its subscription and deletes its account, Ingram deletes the Customer Personal Data described in this Annex. Deleted records may persist in encrypted backups until those backups expire.

Bank connections are held only as authorized under PSD2 and expire on their own; revoking a connection stops further retrieval, and already-imported transactions remain part of the Customer's books until the Customer deletes them.

Once an e-invoice has been transmitted, Financica's Peppol access-point provider retains it under its own terms in order to evidence delivery. The applicable period is available from Ingram on request.

Marketing contacts and preferences are handled by Ingram as an independent Controller under the Privacy Policy, not under this DPA. Ingram may keep a suppression record where that is needed to honour a request not to receive further marketing.

6. Location and international transfers

Financica runs on infrastructure in the European Union: the database, the document storage, the application compute, and the Peppol access point.

Some providers behind the Service, including delivery networks and the assistant's model providers, are globally operated or contract through a non-EEA entity. For those, Ingram relies on the mechanisms in section 11 of the DPA: an adequacy decision or the provider's Data Privacy Framework certification where available, otherwise the SCCs with the supplementary measures the assessment requires.

7. Service-specific commitments

The following are commitments under this Annex, in addition to the measures on the Security & Compliance page:

  • Customer data is separated per organization at the database level, and access is enforced by row-level security rather than by application code alone.
  • Financica does not hold the Customer's banking credentials. Bank access is granted by the Customer through its own bank under PSD2 and can be withdrawn there at any time.
  • Customer data sent to the assistant's model providers is not used to train their models, and the assistant reads only the Customer's own organization.
  • Uploaded documents are stored in the European Union and are served only through short-lived, authenticated links; no public URL to a Customer document exists.
  • Ingram does not sell Customer Personal Data and does not use the Customer's books for any purpose other than providing the Service.