Abacum
Last Reviewed: 17 Jun 2026
At a Glance
Abacum's DPA explicitly designates Abacum as an independent controller for account and usage data, permitting it to use that data to optimise the platform for its own purposes beyond the customer's instructions. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.
Company & Product Details
HQ
United States, Spain
Products
FP&A Platform
Product description
AI-native financial planning and analysis platform for budgeting, forecasting, reporting, and scenario planning.
What data is being processed?
Employee data (name, salary, location, performance/bonus data), personal financial information (account balances, loans, bank account numbers), customer data of the Licensee, authorized user account data (email, name)
Document Details
Date of DPA
N/A
Additional date information
Neither the US DPA nor the EEA DPA carries an explicit revision or effective date on its face. The US DPA states it "shall be effective as of the Effective Date of the Agreement" (i.e. the date the customer signs). The copyright footer reads "© 2026 Abacum Inc." No stated standalone document date.
What jurisdictions are covered?
GDPR (EU/EEA) is explicitly addressed in both DPAs. UK GDPR and the UK Data Protection Act 2018 are covered in the US DPA. The Swiss Federal Act on Data Protection (FADP, including the Revised FADP) is addressed in the US DPA. US state laws covered include CCPA/CPRA (California), VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), UCPA (Utah), MCDPA (Montana), OCPA (Oregon), and TDPSA (Texas). (US DPA section 1 Definitions)
Is the DPA incorporated into service or customer agreements?
Link
Location & Transfers
Where is data held or processed?
Ireland, Germany, United States The EEA DPA (Appendix C.5) specifies processing locations as AWS EU-West-1 Region (Ireland) and AWS EU-Central-1 Region (Frankfurt, Germany). The US DPA acknowledges that transfer of Licensee's Personal Data to the United States is necessary for provision of the Services. (EEA DPA Appendix C.5; US DPA section 6.1)
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
SOC 2 Type II certified and ISO 27001 certified. The EEA DPA requires maintaining "information security, data governance and other controls" and explicitly commits to compliance with the AICPA's SOC 2 framework. Security documentation is available on written request. Security measures include pseudonymisation, encryption, ongoing confidentiality/integrity/availability, resilience, and regular testing of measures. (EEA DPA sections 5.2, C.2; product security page)
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
EEA DPA section 9.2 requires notification "within 24 hours after the Data Processor has become aware of the personal data breach." The US DPA section 8.5 requires notification "without undue delay" and provides assistance to help the customer comply with breach notification obligations to supervisory authorities and data subjects. (EEA DPA sections 9.1–9.2; US DPA sections 8.5–8.6)
What happens to the data on termination?
On termination, Abacum shall return all personal data to the customer and delete existing copies, unless law requires storage. EEA DPA section 10.1 and Appendix C.4 require deletion or return with written certification at the customer's choice. US DPA section 2.3: "at Licensee's choice, Abacum shall return or delete Licensee's Personal Data" with certification on request per EU SCC Clause 8.1(d). (EEA DPA section 10.1, Appendix C.4; US DPA section 2.3)