Legal

Data Processing Agreement

Effective Date: March 1, 2026 — Last Updated: March 2, 2026

GDPR Article 28 Compliant

Who This Applies To

This Data Processing Agreement (“DPA”) applies to B2B customers, enterprise clients, and any organization acting as a Data Controller who uses Fortress Finance services. Individual consumers are covered under the Privacy Policy. To execute this DPA formally — Contact: elijahhenry11@gmail.com (Fortress Finance support).

1. Definitions

ControllerThe natural or legal person, public authority, agency, or other body which determines the purposes and means of the processing of Personal Data. In the context of this DPA, the Controller is the Fortress Finance customer (the organization or individual business entity).
ProcessorA natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of the Controller. Fortress Finance Ltd. acts as the Processor under this DPA.
Data SubjectAn identified or identifiable natural person whose Personal Data is processed. This includes end users of the Controller's organization who access Fortress Finance services.
Personal DataAny information relating to an identified or identifiable natural person, as defined under GDPR Article 4(1). This includes but is not limited to names, email addresses, and financial account identifiers.
ProcessingAny operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, storage, adaptation, retrieval, use, disclosure, or erasure.
Sub-processorAny third party engaged by Fortress Finance to process Personal Data on behalf of the Controller in connection with the provision of Fortress Finance services.
GDPRThe General Data Protection Regulation (EU) 2016/679, together with any national implementing legislation and successor legislation.
SCCsStandard Contractual Clauses adopted by the European Commission for the transfer of personal data to third countries, pursuant to GDPR Article 46(2)(c).

2. Scope and Purpose of Processing

This DPA governs the processing of Personal Data by Fortress Finance (as Processor) on behalf of the Controller in connection with the provision of portfolio analytics, market intelligence, risk assessment, and related financial services (“the Services”).

The Controller determines the purposes and means of processing Personal Data. Fortress Finance processes Personal Data solely to provide the Services as described in the applicable order form, subscription agreement, or Terms of Service. Fortress Finance does not process Personal Data for its own independent commercial purposes, including advertising or data brokerage.

3. Categories of Personal Data Processed

CategoryData TypesPurpose
Account DataEmail address, name, password hash, 2FA configurationAuthentication, account management, communications
Portfolio DataExchange connections, API key metadata (encrypted), holdings, transaction history, asset allocationsPortfolio analytics, performance reporting, risk assessment
Usage DataFeature usage patterns, API call logs, session durations, page viewsService improvement, billing, abuse prevention
Payment DataBilling name, invoice history (via Stripe — card details never stored by Fortress)Subscription management, revenue operations
CommunicationsSupport tickets, email correspondenceCustomer support, legal compliance
Special Categories: Fortress Finance does not knowingly process special categories of personal data as defined in GDPR Article 9 (e.g., racial or ethnic origin, health data, biometric data, political opinions, or religious beliefs). The Services are not designed for such processing and Controllers must not submit such data.

4. Processing Instructions

Fortress Finance shall process Personal Data only on the documented instructions of the Controller, including with regard to transfers of Personal Data to a third country or international organization, unless required to do so by applicable law. In such a case, Fortress Finance shall inform the Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

The Controller's instructions are recorded in: (i) this DPA, (ii) the applicable Terms of Service, and (iii) any written instructions provided by the Controller to Fortress Finance support channels. Fortress Finance shall immediately inform the Controller if, in its opinion, an instruction infringes GDPR or other applicable data protection provisions.

5. Security Measures

Fortress Finance implements appropriate technical and organizational security measures as required by GDPR Article 32, including:

Encryption at RestAES-256-GCM encryption for all stored API credentials, sensitive financial data, and personally identifiable information.
Encryption in TransitTLS 1.3 enforced for all data transmissions. HTTP connections are automatically upgraded to HTTPS.
Access ControlMandatory two-factor authentication (TOTP) for all accounts. Role-based access control with principle of least privilege. Every data query is scoped to the authenticated account at the application layer.
Exchange AccessRead-only API key access for all exchange connections. Fortress Finance never requests withdrawal, trade, or transfer permissions.
Security PostureNo current third-party security certifications. Vulnerability disclosure program in place. Formal SOC 2 audit will be pursued before onboarding any customer for whom it is a contractual requirement.
Data IsolationLogical data isolation between customers. Multi-tenant architecture in which every query is scoped to the authenticated account.
Incident ResponseDocumented incident response plan. 24/7 automated monitoring. Security team on-call for P1 incidents.

6. Authorized Sub-processors

The Controller provides general authorization for Fortress Finance to engage the following sub-processors. Fortress Finance will provide the Controller with at least 30 days' notice before adding or replacing sub-processors.

Sub-processorServiceLocationData Processed
SupabaseDatabase hosting & authenticationUnited StatesAll user and portfolio data
VercelApplication hosting & CDNUnited StatesRequest logs, session data
StripePayment processingUnited StatesBilling name, payment method metadata
Amazon Web ServicesFile storage, infrastructureUnited StatesExported reports, document storage
ResendTransactional email deliveryUnited StatesEmail address, email content
Anthropic / OpenAIAI inference (Fortress AI feature)United StatesAnonymized portfolio context queries

7. Data Subject Rights Assistance

Fortress Finance shall assist the Controller in fulfilling its obligations to respond to requests from Data Subjects exercising their rights under GDPR Chapter III, including:

  • Right of Access (Art. 15) — Fortress provides data export functionality. API available for programmatic export.
  • Right to Rectification (Art. 16) — Corrections can be made through account settings. Support-assisted corrections available within 5 business days.
  • Right to Erasure (Art. 17) — Account deletion triggers full data removal within 30 days, subject to legal retention obligations.
  • Right to Data Portability (Art. 20) — Portfolio data exportable in CSV and JSON formats from the dashboard.
  • Right to Object (Art. 21) — Users may opt out of non-essential processing through account settings.

Fortress Finance will respond to Controller requests for Data Subject assistance within 30 days of receipt. Complex requests may be extended by an additional 60 days with written notice.

8. Personal Data Breach Notification

In the event of a Personal Data Breach as defined in GDPR Article 4(12), Fortress Finance shall:

  • Notify the Controller without undue delay and, where feasible, within 72 hours of becoming aware of the breach
  • Provide the Controller with sufficient information to fulfill its own notification obligations to supervisory authorities and Data Subjects
  • Include in the notification: nature of the breach, categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken or proposed to address the breach
  • Cooperate with the Controller in any investigation and remediation of the breach
  • Maintain a breach register documenting all Personal Data Breaches regardless of notification obligation

9. Data Retention and Deletion

Fortress Finance retains Personal Data for as long as the Controller's account is active and as necessary to provide the Services. Upon account termination or written request:

  • Default: All Personal Data deleted or anonymized within 24 months after account deletion
  • Accelerated deletion: Available upon written request; completed within 30 days
  • Enterprise/Institutional: Custom data retention schedules available, defined in the order form
  • Legal holds: Fortress may retain data as required by applicable law, regulatory requirements, or legitimate legal proceedings. Controller will be notified of any such retention.
  • Backups: Deleted data is removed from backups within 90 days of the deletion request

10. International Data Transfers

Fortress Finance infrastructure is primarily located in the United States. For transfers of Personal Data from the European Economic Area (EEA) or United Kingdom to the United States, Fortress Finance relies on the following transfer mechanisms:

  • Standard Contractual Clauses (SCCs) — Module 2 (Controller to Processor) pursuant to European Commission Decision 2021/914, incorporated by reference into this DPA
  • UK Addendum — The International Data Transfer Addendum (IDTA) as required by the UK Information Commissioner's Office

Copies of the applicable SCCs and transfer impact assessments are available upon written request — Contact: elijahhenry11@gmail.com (Fortress Finance support).

11. Audit Rights

Fortress Finance shall make available to the Controller all information necessary to demonstrate compliance with GDPR Article 28 obligations and shall allow for and contribute to audits and inspections conducted by the Controller or a mandated auditor, subject to the following conditions:

  • Maximum one audit per calendar year unless a suspected breach warrants an additional audit
  • Minimum 30 days advance written notice of the audit
  • Audits conducted during normal business hours with minimal disruption to operations
  • Controller bears all costs of the audit unless material non-compliance is discovered
  • Auditors must execute a confidentiality agreement before accessing Fortress systems
  • Fortress may satisfy audit requests by providing then-current third-party security certifications and penetration test reports, when such reports are available

12. Term and Termination

This DPA is effective upon the earlier of: (i) the Controller's acceptance of the Terms of Service, or (ii) execution of a signed DPA document. This DPA is co-terminous with the main service agreement between the parties and terminates automatically upon expiration or termination of that agreement. Upon termination, Section 9 (Data Retention and Deletion) survives and governs post-termination data handling.

13. Governing Law and Jurisdiction

This DPA shall be governed by and construed in accordance with the laws applicable to the main service agreement. Where the Controller is established in the European Union, this DPA shall be governed by the laws of the Controller's EU member state of establishment. Nothing in this DPA limits any supervisory authority's rights under applicable data protection law.

Execute This DPA

Ready to execute this Data Processing Agreement?

To formally execute this DPA as a binding agreement between your organization and Fortress Finance Ltd., send an email to our legal team with the following information:

  • Company legal name and registration number
  • Registered address and country of incorporation
  • Data Protection Officer contact (if applicable)
  • Name and title of authorized signatory
  • Fortress Finance account email
  • Any custom retention or transfer requirements
Email elijahhenry11@gmail.com →