Abacum

Last Reviewed: 17 Jun 2026

Data Use Review

At a Glance

Abacum's DPA explicitly designates Abacum as an independent controller for account and usage data, permitting it to use that data to optimise the platform for its own purposes beyond the customer's instructions. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.

Company & Product Details

HQ

United States, Spain

Products

FP&A Platform

Product description

AI-native financial planning and analysis platform for budgeting, forecasting, reporting, and scenario planning.

What data is being processed?

Employee data (name, salary, location, performance/bonus data), personal financial information (account balances, loans, bank account numbers), customer data of the Licensee, authorized user account data (email, name)

Document Details

Date of DPA

N/A

Additional date information

Neither the US DPA nor the EEA DPA carries an explicit revision or effective date on its face. The US DPA states it "shall be effective as of the Effective Date of the Agreement" (i.e. the date the customer signs). The copyright footer reads "© 2026 Abacum Inc." No stated standalone document date.

What jurisdictions are covered?

GDPR (EU/EEA) is explicitly addressed in both DPAs. UK GDPR and the UK Data Protection Act 2018 are covered in the US DPA. The Swiss Federal Act on Data Protection (FADP, including the Revised FADP) is addressed in the US DPA. US state laws covered include CCPA/CPRA (California), VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), UCPA (Utah), MCDPA (Montana), OCPA (Oregon), and TDPSA (Texas). (US DPA section 1 Definitions)

Is the DPA incorporated into service or customer agreements?

Yes
US DPA preamble: "This Data Processing Addendum ('DPA') supplements and is incorporated into the Abacum's Master Subscription Agreement." EEA DPA section 1.3: the DPA governs processing "in the context of the provision of the SUBSCRIPTION AGREEMENT." Section 1.4: "This DPA will take priority over any similar provisions contained in other agreements between the parties." (US DPA preamble; EEA DPA sections 1.3–1.4)

Location & Transfers

Where is data held or processed?

Ireland, Germany, United States The EEA DPA (Appendix C.5) specifies processing locations as AWS EU-West-1 Region (Ireland) and AWS EU-Central-1 Region (Frankfurt, Germany). The US DPA acknowledges that transfer of Licensee's Personal Data to the United States is necessary for provision of the Services. (EEA DPA Appendix C.5; US DPA section 6.1)

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
The US DPA incorporates EU Commission SCCs (Decision 2021/914, dated 4 June 2021) for ex-EEA transfers: Module 1 (Controller-to-Controller), Module 2 (Controller-to-Processor), and Module 3 (Processor-to-Subprocessor), governed by Dutch law (Clause 17). The UK Addendum (ICO template) is incorporated in Exhibit D for ex-UK transfers. Swiss adaptations are included for Swiss data transfers. The EU-US Data Privacy Framework, UK Extension, and Swiss-US Data Privacy Framework are used as primary transfer mechanisms where available, with EU SCCs as fallback. (US DPA sections 6.2–6.4, Exhibit D)

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

SOC 2 Type II certified and ISO 27001 certified. The EEA DPA requires maintaining "information security, data governance and other controls" and explicitly commits to compliance with the AICPA's SOC 2 framework. Security documentation is available on written request. Security measures include pseudonymisation, encryption, ongoing confidentiality/integrity/availability, resilience, and regular testing of measures. (EEA DPA sections 5.2, C.2; product security page)

Non Processor Data Use

Does the company process data solely as a processor?

No
US DPA section 9 explicitly establishes Abacum as "an independent controller, not a joint controller with Licensee" for Abacum Account Data and Abacum Usage Data. Abacum processes these as an independent controller for purposes including: managing the customer relationship, core business operations (accounting, audits, tax, compliance), fraud and security incident monitoring, identity verification, regulatory compliance, and — notably — "to provide, optimize, and maintain the Services, to the extent permitted by Data Protection Laws." The last purpose constitutes independent controller use of personal data (including personal data of the Licensee's authorized users) to optimize the platform beyond the customer's processing instructions. Note: The EEA DPA Appendix B includes a "No Training Use" commitment explicitly prohibiting use of customer personal data for AI model training. (US DPA section 9; EEA DPA Appendix B)

Subprocessing

General authorization

General
Both DPAs grant general authorisation for sub-processors. EEA DPA section 6.2: general authorisation with 30-day advance written notice before adding or replacing sub-processors. US DPA section 4.1: general written authorisation with at least 10 days' notice before adding new sub-processors, with customer objection rights within 10 days of notice. Sub-processor lists are maintained (Appendix B / Exhibit B) but not publicly visible in the template versions. (EEA DPA section 6.2; US DPA sections 4.1–4.2)

Do all the DPA terms flow down to sub-processors?

Yes
EEA DPA section 6.3 requires "the same data protection obligations as set out in this DPA shall be imposed on that sub-processor by way of a contract." Section 6.5: "the Data Processor shall remain fully liable to the Data Controller as regards the fulfilment of the obligations of the sub-processor." US DPA section 4.3 requires sub-processors to observe "data protection obligations comparable to those imposed on Abacum under this DPA." (EEA DPA sections 6.3, 6.5; US DPA section 4.3)

Is data only processed on the instruction of the controller?

Yes
EEA DPA section 3.1: "The Data Processor shall process personal data only on documented instructions from the data controller." US DPA section 2.1: "Abacum shall not process Personal Data for purposes other than those set forth in the Agreement and/or Exhibit A, in a manner inconsistent with the terms and conditions set forth in this DPA." (EEA DPA section 3.1; US DPA section 2.1)

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
EEA DPA section 8.1 commits Abacum to assist "by appropriate technical and organisational measures... in the fulfilment of the Data Controllers obligations to respond to requests for exercising the data subjects rights laid down in Chapter 3 GDPR." US DPA section 8.1 similarly commits Abacum to apply appropriate measures to assist with Data Subject Requests. (EEA DPA section 8.1; US DPA section 8.1)

Does the contract include staff confidentiality clauses?

Yes
EEA DPA section 4.1: access to personal data is restricted to persons "who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality" on a need-to-know basis, with the access list kept under periodic review. US DPA section 3: "any person it authorizes to process Personal Data has agreed to protect Personal Data in accordance with Abacum's confidentiality obligations." (EEA DPA section 4.1; US DPA section 3)

Are there audit rights for the data?

Structured
Both DPAs provide audit rights with limitations. EEA DPA sections 11.1 and C.7 allow the Data Controller to mandate audits including on-site inspections with reasonable notice. US DPA section 8.4 structures the programme: primary mechanism is copies of certifications/reports (SOC 2, ISO 27001) upon written request; on-site audits via independent third party are available where reports are insufficient, limited to once per year, during business hours, with reasonable prior notice, at the Licensee's cost, and restricted to Licensee-relevant data. (EEA DPA sections 11.1, C.7; US DPA section 8.4)

Is there assistance with DPIA requests?

Yes
US DPA section 8.3 explicitly commits Abacum to provide "reasonable cooperation and assistance where necessary for Licensee to comply with its obligations under the Data Protection Laws to conduct a data protection impact assessment." EEA DPA section 5.4 commits assistance with compliance with Article 32 GDPR security obligations. US DPA section 8.3 also covers assistance with supervisory authority consultations. (US DPA section 8.3; EEA DPA section 5.4)

How much notice is provided for data breaches?

EEA DPA section 9.2 requires notification "within 24 hours after the Data Processor has become aware of the personal data breach." The US DPA section 8.5 requires notification "without undue delay" and provides assistance to help the customer comply with breach notification obligations to supervisory authorities and data subjects. (EEA DPA sections 9.1–9.2; US DPA sections 8.5–8.6)

What happens to the data on termination?

On termination, Abacum shall return all personal data to the customer and delete existing copies, unless law requires storage. EEA DPA section 10.1 and Appendix C.4 require deletion or return with written certification at the customer's choice. US DPA section 2.3: "at Licensee's choice, Abacum shall return or delete Licensee's Personal Data" with certification on request per EU SCC Clause 8.1(d). (EEA DPA section 10.1, Appendix C.4; US DPA section 2.3)