Service providers and subprocessors
Finsaku uses infrastructure and specialist services to operate the SaaS platform. A provider is a subprocessor only when Finserio engages it to process personal data for the contracted service. A provider selected and contracted directly by a customer has a different relationship and is not automatically a Finsaku subprocessor.
The applicable data-processing agreement and its current subprocessor schedule are authoritative. Confirm the contracting entity, processing countries, transfer mechanism, and effective date there before using this page for a legal assessment.
Platform service inventory
The standard platform implementation contains the following service dependencies. Actual use depends on the contracted deployment and enabled features.
| Provider or service | Purpose | Information involved | When it applies |
|---|---|---|---|
| Amazon Web Services (AWS) | Application hosting, databases, uploaded files, backups, networking, and platform secrets. | Tenant configuration, user and lending information, uploaded documents, operational metadata, and backups. | Core hosted-platform infrastructure. Confirm the AWS contracting entity and region in the current schedule. |
| Elastic Cloud | Central application logging, application performance monitoring, and browser performance telemetry. | Operational events, technical identifiers, tenant or user references included in telemetry, and diagnostic context. | When the contracted deployment uses the managed Elastic service. |
| Auth0 | User authentication and organisation membership. | User identity, email address, authentication metadata, and organisation membership. | When Auth0 authentication is enabled for the deployment. |
| OpenAI | Generates responses for the in-app AI assistant. | The user's prompt, conversation context, tool results supplied to the model, and an attached image when the user includes one. | When the AI assistant is enabled and used. Finsaku requests that response data is not stored by the model API, but the applicable service terms remain authoritative. |
This inventory identifies technical use, not the legal identity of every processor in the chain. It also does not list a provider's own subprocessors. Use the current contractual schedule for that information.
Customer-configured providers
Finsaku also supports providers that a tenant administrator can configure. Account ownership matters:
| Provider | Function | Information that the workflow can send |
|---|---|---|
| Mailgun | Email delivery | Recipients, subject, HTML message, and attachments. |
| Amazon SES | Email delivery | Recipients, subject, HTML message, and attachments. |
| Text2Reach | SMS delivery | Telephone number and message. |
| DocuGenerate | Document generation | Template data and the information selected for the generated document. |
| Slack | Instant messaging | Configured channel and message. |
| KIB | Credit reports and configured contract-data exports | Personal identifiers, application context, and selected lending information. |
| Neopay | Banklink payments | Transaction reference, amount, currency, payment purpose, locale, and callback result. |
viss.gov.lv PEP service |
Politically exposed person checks | Person code and the returned check result. |
| Microsoft Power BI | Business intelligence | Data exposed through the configured reporting connection. |
Some of these providers can act as an independent controller, a customer-appointed processor, or another recipient instead of a Finsaku subprocessor. Record the account owner and contractual role before adding one to a processing register.
See Integration data flows for the operational path and evidence available in Finsaku.
Review a provider change
For each addition or change:
- identify the exact legal entity and service;
- establish whether Finserio or the customer contracts it;
- record its purpose, data categories, data subjects, locations, and retention;
- assess transfers and the provider's own subprocessor chain;
- map the service to the products and workflows that use it;
- complete the approval and notification process required by the agreement;
- update the processing register, DORA register, and this service inventory where applicable.