Data Protection

Version 2.0
Last Updated: 2 June 2026

Becoming a customer of our service implies acceptance of our Data Processing Agreement, unless otherwise explicitly agreed with us in writing.

Data Processing Agreement

This document lays out the responsibilities of Fin Codes API (owned and operated by Granular Code Pte. Ltd., UEN 202244865C), hereafter referred to as Fin Codes API, to its customers with regards to data protection in general and the European Union’s General Data Protection Regulation (GDPR) specifically.

This Data Processing Agreement forms part of and is incorporated into the Fin Codes API Terms of Service. In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to data protection and privacy matters.

1. Fin Codes API as Data Processor, Definitions

Fin Codes API is a Data Processor operating on behalf of its customers.

Customers are individuals or organizations paying money to use the Fin Codes API service. Free trial users of the Fin Codes API Service are not Customers and should not send Fin Codes API personal data.

Fin Codes API's Customers are Data Controllers.

"Personal data" means any information relating to an identified or identifiable person.

"Data Protection Laws" means all applicable data protection and privacy laws and regulations, including, where applicable, the EU General Data Protection Regulation (EU) 2016/679 ("EU GDPR"), the UK GDPR, the UK Data Protection Act 2018, the Singapore Personal Data Protection Act 2012 ("PDPA"), and any legislation implementing, supplementing, replacing, or amending the foregoing.

"Services" means the Fin Codes API (application program interface) and the professional services provided by Fin Codes API.

"Sub-processor" means any Data Processor engaged by Fin Codes API.

"Data Subject" means the individual to whom Personal Data relates.

2. Processing of Personal Data

Use of the service implies that Fin Codes API may process personal data on behalf of the Data Controller in accordance with the requirements of Data Protection Laws. The Data Controller will ensure that instructions to Fin Codes API for the processing of personal data comply with Data Protection Laws. The Data Controller is solely responsible for the accuracy, quality, and legality of Personal Data and the means by which it acquires personal data.

Data Processor shall process the Customer Personal Data as a processor, as necessary to perform its obligations under the Terms of Service or in this DPA (the "Permitted Purpose"). Data Processor shall not retain, use, disclose or otherwise process the Customer Personal Data for any purpose other than the Permitted Purpose except where otherwise required by law(s) that are not incompatible with the applicable Data Protection Laws, and shall not "sell" the Customer Personal Data. Data Processor shall promptly inform Customer if it becomes aware that the Data Processor cannot perform its obligations.

The Customer may submit Personal Data through the Services, including account holder names, IBANs, bank account numbers, BIC codes, and other financial identifiers, solely for the purpose of providing validation, verification, and related banking reference services.

The Customer remains solely responsible for ensuring that it has an appropriate legal basis for processing such Personal Data and for transmitting such Personal Data to Fin Codes API.

Fin Codes API lays out a full and accurate description of its data protection practices on its website at Privacy Policy. This description is updated from time to time as and when practices change.

3. Nature of Processing

Fin Codes API processes Personal Data solely for the purpose of providing the Services requested by the Customer.

Personal Data submitted through the Services is processed transiently and in real time. Fin Codes API does not store or persist API request or response data beyond what is technically necessary for service delivery, logging, security monitoring, abuse prevention, troubleshooting, and compliance purposes.

Where operational analytics or security logging is required, Fin Codes API may retain pseudonymised or masked identifiers derived from submitted data. Such identifiers are not used to identify individuals and are retained only for the period reasonably necessary for the stated purposes.

4. Rights of Data Subjects

The Data Controller is solely responsible for the collecting of all necessary consent from Data Subjects to allow Fin Codes API to process personal data on its behalf.

Fin Codes API will, to the extent legally permitted, promptly notify the Data Controller if it receives a request from a Data Subject for access to, or deletion of, that person’s personal data. Fin Codes API will not respond to a Data Subject request without the Data Controllers prior written consent except to confirm that the request relates to the Data Controller. The Data Controller is solely responsible for completing such request as required by law.

5. Personnel

Fin Codes API ensures that its personnel engaged in the processing of personal data are informed of the confidential nature of the personal data, have received appropriate training on their responsibilities and have agreed to confidentiality obligations that survive the termination of that persons’ employment or engagement by Fin Codes API.

Fin Codes API shall take commercially reasonable steps to ensure the reliability of any Fin Codes API personnel engaged in the processing of personal data and that access to personal data by Fin Codes API is limited to those Fin Codes API personnel who require such access to perform the Services.

Privacy and data protection inquiries may be directed to [email protected].

6. Sub-Processors

The Data Controller agrees Fin Codes API may engage third-party Sub-processors to provide the Services and such Sub-processors may access personal data, and appoint additional levels of Sub-processors, only for purposes of providing the services Fin Codes API retained them to provide and not for any other purpose.

Fin Codes API takes all reasonable steps to evaluate the security, privacy and confidentiality practices of proposed Sub-Processors that have access to or process Service Data both before they are engaged and on an ongoing basis.

Fin Codes API uses two categories of Sub-processors:

  1. Customer Account Data Sub-processors, which process information required for billing, account administration, support, and service analytics.
  2. API Data Sub-processors, which process data submitted through the Services solely for the purpose of providing the requested validation, verification, or banking reference services.

Unless explicitly stated otherwise, Customer Account Data Sub-processors do not receive API request or response data.

Any changes to the Sub-Processors engaged by Fin Codes API will be notified by an update to this page, located at https://fincodesapi.com/gdpr#sub-processors You may also email [email protected] and request to be notified directly when this list changes.

The following is an up-to-date list (as of 2 June 2026) of the names and locations of Fin Codes API Sub-Processors:

Customer Account Data Sub-processors
Sub-processor Purpose Location of Sub-processor
ChartMogul Subscription and revenue analytics Germany
Cloudflare CDN, security, DDoS protection, proxy services United States
Crisp Live chat and support service France
Google Application analytics and diagnostics, User authentication United States
MailerSend Emailing service United States
Ploi Deployment and infrastructure management The Netherlands
Sentry Error tracking United States
Stripe Billing and payment processing United States
UpCloud Cloud hosting Finland
API Data Sub-processors
Sub-processor Purpose Data Types Location of Sub-processor
Apicunia Verification of Payee services Account holder names, IBANs, account numbers United Kingdom

Fin Codes API may replace existing Sub-processors or appoint additional Sub-processors from time to time.

Any material change to the Sub-processor list will be reflected on this page. Customers may object to a new Sub-processor on reasonable data protection grounds by contacting [email protected] within 30 days of the change. If no mutually acceptable solution can be reached, Customer may terminate the affected Services without penalty.

Fin Codes API will not disclose API request data to additional API Data Sub-processors without updating this DPA and Sub-processor list.

7. International Data Transfers

Personal Data may be processed in countries outside the European Economic Area, including Singapore, the United States, the United Kingdom, and other jurisdictions in which Fin Codes API or its Sub-processors operate.

Where required by applicable Data Protection Laws, Fin Codes API shall ensure that appropriate safeguards are in place for such transfers, including adequacy decisions, Standard Contractual Clauses, or other lawful transfer mechanisms recognised under applicable law.

8. Security

Fin Codes API agrees to implement and maintain appropriate administrative, technical, and physical safeguards for Personal Data processed through the Services.

As Fin Codes API can process your Customer's Personal Data, security is a core concern in all parts of our infrastructure.

Fin Codes API does not store payment card details. Payment information is processed directly by our payment providers.

Except where necessary to provide the requested Services, Fin Codes API does not disclose API request data submitted by Customer to third parties.

Any Sub-processors that receive API request data are identified in the API Data Sub-processors section above.

Fin Codes API takes all reasonable steps to protect data we receive from loss, misuse or unauthorized access, disclosure, alteration and/or destruction. Fin Codes API puts in place appropriate physical and electronic procedures to safeguard and secure such data.

Fin Codes API uses a third party enterprise-class web application firewall to restrict access to our Services. We use a „block first, ask questions later“ approach and all subsequent requests by a potential threat will also be blocked - only a manual review by our support team will lift a block.

All communication with our Service is performed through a secure connection. We do not provide any non-SSL endpoints. Data encryption is applied wherever possible which means that even in transit between our servers, your data is kept encrypted.

All our servers are firewalled and kept updated with the latest security patches. All security keys and passwords stored by our application on your behalf are kept encrypted at rest.

9. Security Breach Management and Notification

If Fin Codes API becomes aware of unlawful access to the Data Controller's personal data stored through the Services, or unauthorized access to the Services resulting in loss, disclosure, or alteration of the Data Controller's personal data ("Security Breach"), Fin Codes API will promptly: (a) notify the Data Controller of the Security Breach; (b) investigate the Security Breach and provide the Data Controller with information known to Fin Codes API about the Security Breach; and (c) follow its policies and procedures to mitigate the effects and to minimize any damage resulting from the Security Breach.

The Data Controller agrees that an unsuccessful Security Breach attempt will not be subject to Section 7.1 above. An unsuccessful Security Breach attempt is one that results in no unauthorized access to the Data Controller's personal data or to the Services storing your Personal Data, and may include, without limitation, pings and other broadcast attacks on firewalls or edge servers, port scans, unsuccessful log-on attempts, denial of service attacks, packet sniffing (or other unauthorized access to traffic data that does not result in access beyond IP addresses or headers) or similar incidents.

Notification(s) of Security Breaches, if any, will be delivered to one or more of the Customer’s business, technical or administrative contacts by any means Fin Codes API selects, including via email. It is Customer’s sole responsibility to ensure it maintains accurate contact information on Fin Codes API’s support systems at all times.

Fin Codes API’s report of and/or response to a Security Breach under this Section will not be construed as an admission by Fin Codes API to fault or liability with respect to the Security Breach.

10. Deletion of Customer Data

Fin Codes API agrees to delete Customer personal data in accordance with Fin Codes API’s procedures and Data Protection Laws.

With termination of the Terms of Service and this DPA, Fin Codes API shall delete or anonymize any remaining Customer Personal Data retained by Fin Codes API in accordance with its retention policies and applicable Data Protection Laws. Where Personal Data has been processed transiently and is not retained, no return of data will be possible.

Where applicable, Fin Codes API will provide reasonable confirmation of deletion upon request.

11. Governing Laws

This Agreement is governed by the laws of Singapore.

In addition to this DPA, the attached Standard Contractual Clauses (SCC) shall apply to ensure an adequate level of data protection. In the event of inconsistencies between regulations from this DPA and those from the SCC, regulations from the SCC shall prevail.

12. Legal Effect

This agreement comes into effect from the time of purchase of a Fin Codes API subscription. It expires with cessation of the Customer's Fin Codes API subscription.