Data Processing Addendum & Subprocessors
Last updated: May 2026
1. Purpose
This page describes how Flitz.ai (operated by The Mejlerö Company GmbH, Switzerland — "the Processor") processes personal data on behalf of its customers ("the Controller") and lists every subprocessor we use to deliver the Service. It complements the Privacy Policy and the Terms of Service. Where it conflicts with a separately signed Data Processing Addendum, the signed DPA prevails.
2. Roles
Customer = Controller. Customer determines the purposes and means of personal data processing inside the Service. Flitz.ai = Processor. Flitz processes personal data only on documented instructions from the Customer (i.e. by operating the Service as configured by the Customer).
3. Categories of data subjects & data
Data subjects: the Customer's employees, contractors, end-users, and any natural persons identifiable in the Customer's invoices, bank transactions, CRM records, time entries, chat messages, password vault entries, intranet content, GDPR records and other documents stored in the Service. Categories of data: name, email address, postal address, phone number, IBAN / payment data, transaction amounts, employment data (for payroll), free-text content, IP address, browser / device metadata, authentication credentials (hashed), and any data the Customer voluntarily uploads.
4. Security measures
Encryption at rest (AES-256) and in transit (TLS 1.3). Tenant-level data isolation enforced by a global query scope at the model layer. Zero-knowledge encryption for the password vault (browser-side WebCrypto; the server stores ciphertext only). Role-based access control with TenantRole permissions and a documented access-review workflow. Daily encrypted backups with a 30-day retention. Detailed Technical & Organisational Measures (TOMs) are listed inside the GDPR module of the application and available on request.
5. Subprocessor engagement
We engage the subprocessors listed below. We sign EU SCCs (Standard Contractual Clauses) and / or Swiss-DSG-equivalent contracts with each one. We will give Customers 14 days' advance notice before adding or replacing a subprocessor; subscribe to [email protected] for change notifications, or check this page (it is the canonical register).
6. Data subject rights & breach notification
We assist the Controller in fulfilling Art. 15–22 GDPR / revFADP requests. The GDPR module of the application includes a built-in DSR workflow with a 30-day clock and a one-click +60-day extension under Art. 12(3). In the event of a personal data breach affecting Customer data, we notify the Controller within 24 hours of becoming aware, and we assist with the Art. 33 / revFADP notifications to the supervisory authority (72 hours / "as soon as possible").
7. Data location & transfers
Primary processing and storage takes place inside the EU (DigitalOcean Frankfurt). Some subprocessors transfer data to the United States — those transfers are covered by the EU-U.S. Data Privacy Framework where the subprocessor is certified, or by Standard Contractual Clauses (SCCs / Swiss-DSG addendum) where it is not.
8. Audit rights & contact
The Controller may audit our compliance with this addendum once per calendar year, with reasonable advance notice and at the Controller's cost, subject to a confidentiality undertaking. We are happy to provide our most recent SOC 2 / ISO 27001 / penetration-test summaries on request. For any DPA-related question, breach report, or to request a counter-signed DPA: [email protected].
Subprocessor register
These are the third parties we use to deliver the Service. The list is canonical — we do not engage subprocessors that are not listed here.
| Subprocessor | Purpose | Processing location | Data processed |
|---|---|---|---|
|
DigitalOcean, LLC
https://www.digitalocean.com
|
Application hosting and database storage | EU (Frankfurt) | All Customer data at rest |
|
Anthropic PBC
https://www.anthropic.com
|
AI invoice parsing, booking, audit, advisory and document Q&A | United States (SCCs in place) | Document content, invoice metadata, free-text prompts |
|
Stripe Payments Europe, Ltd.
https://stripe.com
|
Subscription billing and payment processing | Ireland (EU) | Customer name, email, billing address, payment instrument |
|
Mailtrap (Railsware Products Studio LLC)
https://mailtrap.io
|
Transactional email delivery (account, billing, alerts) | EU (Czech Republic) | Recipient email, message content |
Customer-side integrations (the Customer's own bank account, the Customer's own Gmail / IMAP server connected via OAuth, etc.) are operated by the Customer's chosen providers and are not Flitz subprocessors.
Need a counter-signed DPA?
For Customers in regulated industries or larger organisations that need a separately signed Data Processing Addendum, email [email protected] with your legal entity name and we will counter-sign and return within five business days.
Email [email protected]