Read this boundary first
- Where an institution sends us personal data — an adviser, plan sponsor, third-party administrator or fund sponsor — that institution is the controller and we act as processor for that data. This agreement governs that.
- Where we hold and administer an account, we are a controller in our own right for the records a custodian and trustee must keep. That is not processing on instruction, it is a legal obligation of the custodian, and it is described in our privacy policy rather than here.
- Confusing those two is the single most common wrong answer in a vendor questionnaire about a custodian, so it is stated before anything else.
1. Scope and roles
This agreement applies where Financial Infrastructure, Inc. processes personal data on behalf of a customer institution (“you”) in providing the Investor Services experience. You are the controller; we are the processor. Where you are yourself a processor for a third party, we act as a subprocessor and your instructions must be consistent with the instructions you received.
2. Subject matter and duration
The subject matter is the provision of the service. The duration is the term of your agreement plus any period we must retain data under clause 10 or by law — and for a regulated custodian that statutory period is often longer than the commercial relationship. Categories of data subject and personal data are in Exhibit A, issued per engagement.
3. Processing on documented instructions
We process only on your documented instructions: your agreement, this agreement, your configuration, and instructions given through the service. We will tell you if we consider an instruction to infringe data-protection law and may suspend it until resolved. We do not sell personal data, and we do not use personal data you provide to train models that serve other customers.
4. Security of processing
Measures are described in Exhibit B and summarised in our security policy. Two are central enough to state here:
- Authorisation is enforced per record. Every read and write is evaluated against the caller, the record, the purpose and the delegation in force at that moment, and the decision is recorded. Authentication alone does not grant access to an account.
- Delegated authority is revocable and evidenced. Where an account holder authorises an adviser, the grant, its scope and its revocation are records, and revocation takes effect at the time of the change rather than at the next review cycle.
5. Subprocessors
You give general authorisation for us to engage subprocessors, each bound by obligations no less protective than these, and we remain responsible for their performance. The list is engagement-specific and is therefore maintained as a referenced exhibit at /subprocessors/ — a custodian serving retirement accounts, a trust administrator and a private-fund administrator do not use the same parties. We give notice of an intended new or replacement subprocessor with a reasonable period to object on reasonable data-protection grounds.
6. Data-subject rights
The service provides functions to access, correct, export and delete records so you can respond yourself; where you cannot, we assist on reasonable request. If a request reaches us directly we do not respond to its substance — we refer the individual to you and tell you promptly.
The limit a custodian has to state
- A deletion request cannot override a recordkeeping obligation. Where we hold a record because a custodian or trustee is required to, we will explain the basis and the retention period rather than delete it, and we will delete what is not caught by that obligation.
7. Breach notification
We notify you without undue delay and in any event within seventy-two hours of becoming aware of a personal-data breach affecting data we process for you — nature, categories and approximate number of records so far as known, likely consequences, measures taken, and a contact point. We send the first notification before everything is known rather than waiting until it is.
8. Assessments and audits
We provide the information reasonably necessary for you to demonstrate compliance and to complete a data-protection impact assessment. On reasonable notice, and no more than once in twelve months unless required by a regulator or following a breach, you may audit our compliance. Current third-party reports and completed questionnaires are offered first where they exist, and are usually sufficient.
9. International transfers
Where a transfer requires a mechanism we implement an appropriate one, including standard contractual clauses where applicable. Hosting region is a configurable property of an environment; raise a residency constraint before provisioning, because changing region after data exists is a migration rather than a setting.
10. Return and deletion
On termination, at your choice, we return or delete personal data processed for you and delete existing copies, except where we must retain it by law or to meet a custodial or trust recordkeeping obligation. Deletion covers backups on their ordinary expiry cycle rather than immediately.
An honest limitation. Records held in a system whose retention we do not control — a document-execution provider you have chosen, or an early evaluation record captured before provisioning — are deleted according to that system’s capabilities. Where a promise cannot be performed in full we name the limiting system instead of making the promise.
11. Liability and precedence
The limitations in your signed agreement apply here. Order of precedence: your signed agreement, then this agreement, then the exhibits, then any other document.
12. Exhibits
Exhibit A — nature of processing. Categories of data subject and personal data, purpose, and duration. Issued per engagement.
Exhibit B — technical and organisational measures. Cross-referenced to our security policy.
Exhibit C — subprocessors. Maintained at /subprocessors/ and versioned.
To receive an executed DPA with exhibits completed for your engagement, contact legal@investorservices.com. Governed by the laws of the State of California; exclusive venue is the state and federal courts located in San Mateo County, California. Notices to Financial Infrastructure, Inc., PO Box 1410, Menlo Park, California 94026-1410.
Institutional Trust Company is a proposed trust entity seeking a South Dakota non-depository trust charter. It is not yet chartered, is not accepting accounts, and no regulator has approved any application. Investor Services is a pre-charter demonstration and reference experience operated by Financial Infrastructure, Inc.. Nothing on this site is an offer or solicitation of any security. For self-directed accounts the custodian is a directed, non-discretionary, independent custodian — not a fiduciary, adviser or broker-dealer; the account holder directs, and the custodian does not evaluate, recommend or approve any investment. Trust services are different: a trustee is a fiduciary, and trust-administration duties are described in the applicable trust documents.