Data processing agreement
Our role and responsibilities as a data processor.
Last updated: 9 July 2026
Purpose and roles
This Data Processing Agreement ("DPA") governs the processing of personal data that Freelance Budget carries out on your behalf when you use the Service. It forms part of, and is subject to, our Terms of service.
For the business data you enter that contains personal data about third parties — for example the names and contact details of your own clients on invoices and quotes — you act as the data controller and Freelance Budget, published by I Make IT, acts as your processor, processing that data only to provide the Service to you. For your own account data, Freelance Budget is the controller (see our Privacy policy).
Scope, nature and purpose
Subject matter: the provision of the Freelance Budget budgeting and treasury service. Duration: for as long as your account is active, subject to the legal retention periods below. Nature and purpose: hosting, storing and processing the data you enter so the Service can display it, compute projections and statistics, and generate your documents.
Types of data and data subjects
The personal data processed may include the identification and contact details of your clients and contacts, and the business, financial and accounting information you record. Data subjects may include your clients, contacts and, where applicable, your team members. We do not require special categories of data, and we ask that you do not enter them.
Our obligations as processor
We process personal data only on your documented instructions — your use of the Service being the primary instruction — unless required by law. Our personnel are bound by confidentiality. We implement appropriate technical and organisational security measures.
Taking into account the nature of the processing, we assist you in responding to data-subject requests and in meeting your security, breach-notification and impact-assessment obligations. We notify you without undue delay after becoming aware of a personal-data breach affecting your data.
Sub-processors
You authorise us to engage sub-processors to run the Service. We currently rely on: OVHcloud (hosting, EU and Canada), our transactional email provider, Stripe (payment processing) and Powens (bank aggregation). Each is bound by data-protection obligations consistent with this DPA. We will inform you of any intended change to our sub-processors so that you can object on reasonable grounds.
International transfers
Personal data is primarily processed in the European Union. Where a sub-processor processes data outside the EU, the transfer is covered by appropriate safeguards such as the European Commission's Standard Contractual Clauses.
Security
We apply access controls, encryption in transit, encryption at rest for connected-service credentials (AES-256-GCM), least-privilege access and a segregated infrastructure. Only read-only scopes are requested from third-party providers.
Return and deletion
On termination of the Service, we delete or return the personal data we process on your behalf, except where we are legally required to retain it — notably invoices and accounting records, which French law requires to be kept for 10 years.
Audits
We make available the information necessary to demonstrate compliance with this DPA and, on reasonable prior request and subject to confidentiality, allow for audits proportionate to the processing.
Acceptance and contact
This DPA applies automatically when you use the Service to process personal data of third parties. For a countersigned copy or specific questions, contact damien@i-make-it.net.