Skip to content
SourceFinch
How it worksSourcesPricingDocsSign inStart free

Legal

Data Processing Addendum

Effective October 4, 2026 · Version 2026-10-04 · SourceFinch is operated by The Schoeller Group LLC.

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between The Schoeller Group LLC (“Processor”) and the customer (“Controller”) and applies when SourceFinch processes personal data on the customer’s behalf. It applies automatically to Business and Enterprise customers and to any customer who asks for it. A countersigned copy is available on request to privacy@sourcefinch.com.

1. Scope and roles

Subject matter: acquisition, extraction, comparison, storage and delivery of content from the Sources the Controller configures, and the related account data needed to provide the Service. Duration: the term of the Terms plus the deletion periods in section 9. Nature and purpose: providing the Service as the Controller instructs. Data subjects and categories: whatever personal data the Controller chooses to include in its Sources and workspace, and the Controller’s users’ account data. The Controller must not configure Sources to collect special-category data, data about children, or data whose collection is prohibited by the Acceptable Use Policy.

2. Instructions

The Processor processes personal data only on the Controller’s documented instructions, which are the Terms, this DPA and the Controller’s configuration of the Service, unless the law requires otherwise, in which case it will tell the Controller before processing where the law allows. The Processor will tell the Controller if it believes an instruction infringes data-protection law.

3. Controller responsibilities

The Controller is responsible for the lawfulness of the processing it instructs, including having a lawful basis and giving any required notice for personal data in its Sources, and for complying with the terms of the websites it monitors.

4. Confidentiality and personnel

Everyone authorized to process the personal data is bound by confidentiality obligations.

5. Security

The Processor maintains the technical and organizational measures described on the security page, including encryption in transit, encryption at rest, workspace isolation by row-level security, hashed credentials, multi-factor authentication for operators, access logging and daily backups. The Processor may update these measures provided it does not materially reduce the overall level of protection.

6. Sub-processors

The Controller authorizes the sub-processors listed on the sub-processors page. The Processor imposes data-protection obligations on each that are no less protective than this DPA and remains responsible for them. The Processor will give at least 30 days’ notice of a new sub-processor to customers who have asked for notice; the Controller may object on reasonable data-protection grounds, and if the parties cannot resolve the objection, the Controller may terminate the affected Service and receive a refund of prepaid fees for the unused period.

7. Assistance and data-subject requests

Taking into account the nature of the processing, the Processor will help the Controller respond to data-subject requests, for example through the export and deletion tools in the Service, and will forward any request it receives directly. It will provide reasonable help with data-protection impact assessments and consultations with authorities.

8. Personal-data breaches

The Processor will notify the Controller without undue delay, and in any case within 72 hours, after becoming aware of a personal-data breach affecting the Controller’s data, with the information the Controller reasonably needs to meet its own obligations, and will take reasonable steps to contain and remedy it.

9. Return and deletion

The Controller can export its data at any time. On termination or deletion, the Processor deletes the personal data after the 14-day grace period; backup copies expire within 8 days, unless the law requires retention.

10. Audits

The Processor will make available information reasonably necessary to demonstrate compliance with this DPA, such as written answers to security questionnaires. On-site audits are available only where the law requires them, with reasonable notice, at the Controller’s cost, no more than once a year and subject to confidentiality.

11. International transfers

Processing takes place in the United States. To the extent the Controller transfers personal data from the EEA, Switzerland or the UK to the Processor, the parties agree to the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, with the optional docking clause; Clause 9 option 2 (general authorization) with the notice period in section 6; Clause 11 optional language omitted; Clauses 17 and 18 governed by the laws and courts of Ireland; and Annexes I to III completed by section 1 of this DPA, the security page and the sub-processors page. For UK transfers the UK International Data Transfer Addendum applies, and for Swiss transfers the Clauses apply with references adapted to the Swiss Federal Act on Data Protection.

12. US state privacy laws

Where the California Consumer Privacy Act or similar US state laws apply, the Processor acts as a service provider or processor: it will not sell or share the personal data, retain, use or disclose it outside the direct business relationship or for any purpose other than providing the Service, or combine it with other data except as those laws permit, and it will notify the Controller if it can no longer meet these obligations.

13. Liability and precedence

Each party’s liability under this DPA is subject to the limitations in the Terms, except where the law does not allow it. If this DPA conflicts with the Terms on the processing of personal data, this DPA controls; the Standard Contractual Clauses control over both.

SourceFinch

Know exactly what changed. Prove it.

ProductHow it worksSource catalogPricingDocsOur crawler
Companyhello@sourcefinch.comTalk to sales
LegalTerms of ServicePrivacy PolicyAcceptable UseSub-processorsDPACookiesSecurity

© 2026 The Schoeller Group LLC. SourceFinch is a product of The Schoeller Group LLC.