Bufin

Data Processing Addendum. Bufin

Last updated 2026-08-18

This Data Processing Addendum ("DPA") supplements the Terms of Service and applies where Bufin processes personal data on your behalf and data-protection law (such as the GDPR, UK GDPR, or Quebec's Law 25) requires such terms. Most individuals won't need it; it mainly matters if you use Bufin's household or shared features in a way that makes you a "controller", or if you're a business that needs a processing agreement on file. It is written in plain language and errs toward transparency rather than legalese.

1. Who is what

For your private financial data under Google sign-in: YOU are the controller and your own Google cloud is your storage. Bufin is not even a processor of that data, because it never reaches our servers and we can't read it. For email-account data and shared community/household data that does reach our systems, you are the controller and Bufin is the processor, processing that data only to provide the service.

2. Details of processing

Subject matter & purpose: providing the Bufin budgeting service and its shared features. Duration: for as long as your account exists, then deleted per our retention schedule (see the Privacy Policy). Nature: storage, retrieval, display, and transmission as needed to run the app. Categories of data: account identifiers (email, name, avatar, provider ID), tier/billing metadata, and, for email accounts, your encrypted budget data; plus any content you submit to shared features. Categories of data subjects: you, and any household members or people whose details you choose to enter.

3. Our obligations as processor

We will: (a) process personal data only on your documented instructions, which include your use of the app's features and these terms; (b) ensure people authorized to process the data are bound by confidentiality; (c) apply appropriate technical and organizational security measures (see our Security page); (d) engage subprocessors only as listed on our Subprocessors page, under equivalent data-protection obligations, and give notice of material changes; (e) assist you, taking into account the nature of processing, in responding to data-subject requests and in meeting your security, breach-notification, and impact-assessment obligations; (f) notify you without undue delay after becoming aware of a personal-data breach affecting your data; and (g) at the end of the service, delete or return the personal data, except where law requires us to keep it.

4. International transfers

Where personal data is transferred across borders, we rely on appropriate safeguards, such as the EU Standard Contractual Clauses: through our providers, as described on our Subprocessors page.

5. Audits

On reasonable written request, and no more than once a year unless required by a regulator, we will make available the information reasonably necessary to demonstrate compliance with this DPA. Given Bufin's size, this normally takes the form of written answers and documentation rather than on-site audits.

6. How to put this in place

For most users, accepting the Terms of Service incorporates this DPA automatically. If your organization needs a countersigned copy or has specific clauses to add, email [email protected] and we'll work with you in good faith.

7. Precedence & contact

If this DPA conflicts with the Terms of Service on the processing of personal data, this DPA governs for that subject. Everything here works alongside our Privacy Policy and Subprocessors list. Contact: [email protected].