Security & privacy

Your customer data. Clearly governed.

FinSuites processes data on your behalf. This page explains what that means in practice, which documents cover it and how to use them. No marketing phrases, just the GDPR articles behind each point.

DPA under Art. 28 GDPR EU representative under Art. 27 GDPR Subprocessors disclosed

At a glance

Six things that are settled from day one

DPA under Art. 28 GDPR

The data processing agreement is ready as a PDF and countersigned on request. It covers instructions, subprocessors, deletion and support with data subject requests.

View DPA →
EU representative under Art. 27 GDPR

BestLife Group GmbH in Nuremberg is the contact for supervisory authorities and data subjects. Your contacts never have to reach out to a company outside the EU.

Privacy policy →
All subprocessors disclosed

Platform, payments, email, messaging, telephony, analytics: every provider is listed with purpose and processing location. Services you do not activate do not process anything.

View list →
Third-country transfers covered

The core platform runs in the US. Transfers rely on the EU Commission's Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.

Encryption & access control

Encrypted transmission, role-based permissions per user, two-factor login for your account. Payment card data lives with the payment provider only.

Consent is built in

Double opt-in for email lists, documented consent per contact, automatic unsubscribe links, and access, export and deletion straight from the system.

Roles

Who is responsible for what

The GDPR distinguishes between the party deciding about data and the party processing it on their behalf. At FinSuites this is clearly split.

YouController

You decide which data you collect from your contacts, what you use it for and on which legal basis. You obtain consent and answer your contacts' requests. FinSuites gives you the tools inside the system.

WeProcessor

FinSuites processes data only on your instructions, uses only the documented subprocessors, secures processing technically and organisationally, and supports you with access, deletion and export.

Documents

Everything your data protection officer wants to see

Data Processing Agreement (DPA)Current version as PDF. Countersigned version on request via privacy@finsuites.com.
Open PDF
Subprocessor listTransparency under Art. 28 GDPR: provider, purpose, processing location.
View
Privacy policyController, EU representative, legal bases, retention, data subject rights.
View
Cookie policyWhich cookies the website sets and how you control them.
View
Terms & ConditionsContract basis for business customers.
View

Technical & organisational

Technical and organisational measures

AreaMeasure
TransmissionAll connections between browser, app and platform are encrypted (TLS)
AccountsRoles and permissions per user, two-factor login, session control
PaymentsCard data is stored by the payment provider (Stripe) only, never by FinSuites
SubprocessorsContractually bound to instructions and to data protection duties at least at DPA level
Data subject rightsAccess, rectification, deletion, export and objection via privacy@finsuites.com or directly in the system
RetentionCustomer data is retained as set out in the DPA and deleted or returned after the contract ends
WebsiteSelf-hosted fonts, no external font CDNs, YouTube videos load only after a click (youtube-nocookie)

FAQ

What data protection officers ask us

Where is the data processed?

FinSuites is a white-label implementation of the GoHighLevel / LeadConnector platform. The core infrastructure runs in the US. Transfers rely on the EU Commission's Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework. We say this openly so you can put it in your records of processing.

Do I get a signed DPA?

Yes. The DPA is available as a PDF. For a countersigned version, write to privacy@finsuites.com and we send it back to you.

Who is my contact inside the EU?

BestLife Group GmbH in Nuremberg is the EU representative under Art. 27 GDPR and the contact for supervisory authorities and data subjects. Contact details are in the privacy policy.

Can I export my data and end the contract?

Yes. Contacts, pipelines and conversations can be exported at any time. The contract is cancellable monthly; after it ends, data is deleted as set out in the DPA.

What about WhatsApp, SMS and telephony?

These channels run via Meta and Twilio respectively and only become active once you set them up in your system. As long as you do not use a channel, no data is processed there. Both providers are listed with purpose and location in the subprocessor list.

Questions?

Talk to us about privacy directly.

For questions on the DPA, countersigning or your specific case: privacy@finsuites.com. Or sort it out in a short call.