Skip to content

Service providers and subprocessors

Finsaku uses infrastructure and specialist services to operate the SaaS platform. A provider is a subprocessor only when Finserio engages it to process personal data for the contracted service. A provider selected and contracted directly by a customer has a different relationship and is not automatically a Finsaku subprocessor.

The applicable data-processing agreement and its current subprocessor schedule are authoritative. Confirm the contracting entity, processing countries, transfer mechanism, and effective date there before using this page for a legal assessment.

Platform service inventory

The standard platform implementation contains the following service dependencies. Actual use depends on the contracted deployment and enabled features.

Provider or service Purpose Information involved When it applies
Amazon Web Services (AWS) Application hosting, databases, uploaded files, backups, networking, and platform secrets. Tenant configuration, user and lending information, uploaded documents, operational metadata, and backups. Core hosted-platform infrastructure. Confirm the AWS contracting entity and region in the current schedule.
Elastic Cloud Central application logging, application performance monitoring, and browser performance telemetry. Operational events, technical identifiers, tenant or user references included in telemetry, and diagnostic context. When the contracted deployment uses the managed Elastic service.
Auth0 User authentication and organisation membership. User identity, email address, authentication metadata, and organisation membership. When Auth0 authentication is enabled for the deployment.
OpenAI Generates responses for the in-app AI assistant. The user's prompt, conversation context, tool results supplied to the model, and an attached image when the user includes one. When the AI assistant is enabled and used. Finsaku requests that response data is not stored by the model API, but the applicable service terms remain authoritative.

This inventory identifies technical use, not the legal identity of every processor in the chain. It also does not list a provider's own subprocessors. Use the current contractual schedule for that information.

Customer-configured providers

Finsaku also supports providers that a tenant administrator can configure. Account ownership matters:

Provider Function Information that the workflow can send
Mailgun Email delivery Recipients, subject, HTML message, and attachments.
Amazon SES Email delivery Recipients, subject, HTML message, and attachments.
Text2Reach SMS delivery Telephone number and message.
DocuGenerate Document generation Template data and the information selected for the generated document.
Slack Instant messaging Configured channel and message.
KIB Credit reports and configured contract-data exports Personal identifiers, application context, and selected lending information.
Neopay Banklink payments Transaction reference, amount, currency, payment purpose, locale, and callback result.
viss.gov.lv PEP service Politically exposed person checks Person code and the returned check result.
Microsoft Power BI Business intelligence Data exposed through the configured reporting connection.

Some of these providers can act as an independent controller, a customer-appointed processor, or another recipient instead of a Finsaku subprocessor. Record the account owner and contractual role before adding one to a processing register.

See Integration data flows for the operational path and evidence available in Finsaku.

Review a provider change

For each addition or change:

  1. identify the exact legal entity and service;
  2. establish whether Finserio or the customer contracts it;
  3. record its purpose, data categories, data subjects, locations, and retention;
  4. assess transfers and the provider's own subprocessor chain;
  5. map the service to the products and workflows that use it;
  6. complete the approval and notification process required by the agreement;
  7. update the processing register, DORA register, and this service inventory where applicable.