Data Processing & Sub-processors
Last updated: 22 August 2026
When Finsimul processes data on a customer's behalf, the customer is the data controller and Finsimul is the data processor. This page summarises how we process customer data and lists the sub-processors we use. It is offered alongside a full Data Processing Addendum (DPA) available to customers on request.
1. Scope of processing
- Subject matter: provision of the Finsimul cost-intelligence service.
- Nature & purpose: ingesting, normalising, analysing and reporting on cloud and SaaS cost and usage data.
- Types of data: cloud billing and usage records; authorised user account details (name, work email, role).
- Duration: for the term of the subscription and any agreed retention period.
2. Our obligations
We process customer data only on documented instructions, ensure personnel are bound by confidentiality, apply appropriate technical and organisational security measures (see our Security page), assist with data-subject requests and breach notification, and delete or return data at the end of the engagement, all as set out in the full DPA.
3. International transfers
Where data is transferred outside the UK/EEA, we rely on appropriate safeguards such as Standard Contractual Clauses and, where relevant, the UK International Data Transfer Addendum.
4. Sub-processors
We engage the following sub-processors to deliver the service. We remain responsible for their compliance and will give customers notice of material changes.
- Amazon Web Services (AWS) — cloud hosting, infrastructure, and the AI inference used to generate report analysis (via Amazon Bedrock). Region: Asia Pacific (Sydney),
ap-southeast-2. - Anthropic — provider of the Claude models used to generate report analysis and recommendations from cost-data slices and customer-supplied context. Accessed via Amazon Bedrock within our AWS environment, not a direct Anthropic API integration.
- Google — authentication only (OAuth sign-in) for portal and admin console access. We receive the account identity returned by the sign-in flow (name, work email) and nothing else — Finsimul does not read Gmail, Drive, or other Google Workspace data.
- Resend — transactional email delivery (task and report notifications, inbound-inquiry replies) sent to authorised user email addresses.
We do not currently use any error-monitoring or analytics sub-processor. This section is reviewed each time a new data-handling vendor is introduced.
5. Requesting the DPA
To request our full Data Processing Addendum, contact privacy@finsimul.com.