Finora← Back to home
Finora · Legal centre

Data Processing Addendum

The processing terms for business customer information entrusted to Finora.

Review draft · 26 September 2026 · Not yet effective

1. Roles and instructions

The proposed parties are the business customer identified in its account or order and Jorge Rodrigues, trading as Finora at Rua Miguel Lemos 7, Rio de Janeiro, RJ, 22071-000, Brazil. Requests and instructions may be sent through the contact form. The final processing arrangement must identify the customer and the applicable services.

For permitted personal data submitted to a workspace, the customer acts as controller, or as a processor authorised to appoint Finora. Finora acts as processor for the instructed service activity. Finora’s own account, security and business administration, and Paddle’s independent purchase processing, are addressed separately. Applicable data-protection law includes Brazil’s LGPD where it governs the processing.

Finora processes customer personal data only on documented lawful instructions to provide the agreed service, unless law requires otherwise. Finora will notify the customer if an instruction appears to infringe applicable data-protection law, unless prohibited. The customer is responsible for collection notices, lawful basis and authority to give instructions.

2. Processing description

  • Purpose and subject matter: receive authorised ecommerce records, calculate sales/profit/inventory results, store and display those records and results for authorised users, and provide related support.
  • Nature: collection, organisation, storage, retrieval, calculation, transmission to approved service providers, export and deletion as required for the service.
  • Data subjects: authorised account users, customer staff and individuals identified in permitted merchant records.
  • Data categories: account/workspace identifiers, business contact information and any personal information included in permitted sales, stock or cost records. Uploads should omit unnecessary customer identifiers.
  • AI processing: customer-entered prompts and relevant conversation content when an AI feature is requested. Sending personal data to AI requires appropriate customer authority and inclusion in the processing arrangement.
  • Duration: the service period and the agreed return/deletion process. Special-category data, criminal-offence data, passwords and full payment-card details are excluded unless expressly agreed with suitable safeguards.

3. Confidentiality and security

Personnel with access must be bound by confidentiality and limited to access necessary for their role. Measures must be appropriate to the processing risks and documented in the security schedule.

The current application includes HTTPS, authenticated account access, server-side workspace permissions, database row-level access policies and restricted administrative payment-claim functions. No independent security certification, comprehensive security audit or fixed uptime guarantee is claimed by this document.

Finora will notify the customer without undue delay after becoming aware of a personal-data breach affecting instructed processing, provide available information relevant to the customer’s duties, and supply updates as further facts become available.

4. Providers and international transfers

For application records, authentication and requested AI features, Finora uses Lovable Cloud and the downstream providers applicable to those services. The provider page links to their published identities, purposes and locations. Framer and Gmail handle website enquiries; Paddle handles its Merchant of Record activities under its own responsibilities.

The customer’s final processing agreement must authorise the relevant subprocessors and establish notice and a reasonable opportunity to object to changes on data-protection grounds. A provider’s broader list is not an instruction to share data with every service on it.

For restricted international transfers, the correct parties and a valid mechanism must be documented. European or UK safeguards in a provider agreement do not automatically satisfy Brazil’s LGPD. Where ANPD standard clauses are the chosen mechanism, their required text and completed particulars must form part of the relevant contract. This webpage does not claim that such a contract has already been signed.

5. Customer assistance and review

Taking account of the nature of processing and available information, Finora will provide appropriate assistance with data-subject requests, security obligations, incident assessment and required impact assessments. Merchant-controlled requests should normally be directed to the merchant, with Finora’s cooperation.

Finora will make information reasonably necessary to demonstrate its processor compliance available and allow the audit arrangements required by applicable law, with safeguards for security, confidential information and other customers’ data.

6. Return and deletion

At the end of instructed processing, the final agreement must provide for return or deletion of merchant personal data at the customer’s choice, except for legally required retention. Finora’s contact form is the route for requesting export, account closure or deletion. The proposed operating deadline is subject to confirmation before this addendum is adopted.

Cancellation stops renewal and does not itself erase the workspace. A deletion request must identify the account and be verified before an export or destructive action. Data retained for a legal obligation, security investigation or dispute must be limited to that purpose.

The active-system deletion process and provider backup process are separate. Lovable’s public processing terms allow residual backup data for a limited period; Framer also describes backups that are not individually accessible. Their public clauses do not establish one universal backup-expiry deadline for Finora. Any customer promise requiring a specific maximum must be agreed with the relevant provider first.