Flitz.ai Flitz.ai

Data Processing Addendum & Subprocessors

Last updated: May 2026

1. Purpose

This page describes how Flitz.ai (operated by The Mejlerö Company GmbH, Switzerland — "the Processor") processes personal data on behalf of its customers ("the Controller") and lists every subprocessor we use to deliver the Service. It complements the Privacy Policy and the Terms of Service. Where it conflicts with a separately signed Data Processing Addendum, the signed DPA prevails.

2. Roles

Customer = Controller. Customer determines the purposes and means of personal data processing inside the Service. Flitz.ai = Processor. Flitz processes personal data only on documented instructions from the Customer (i.e. by operating the Service as configured by the Customer).

3. Categories of data subjects & data

Data subjects: the Customer's employees, contractors, end-users, and any natural persons identifiable in the Customer's invoices, bank transactions, CRM records, time entries, chat messages, password vault entries, intranet content, GDPR records and other documents stored in the Service. Categories of data: name, email address, postal address, phone number, IBAN / payment data, transaction amounts, employment data (for payroll), free-text content, IP address, browser / device metadata, authentication credentials (hashed), and any data the Customer voluntarily uploads.

4. Security measures

Encryption at rest (AES-256) and in transit (TLS 1.3). Tenant-level data isolation enforced by a global query scope at the model layer. Zero-knowledge encryption for the password vault (browser-side WebCrypto; the server stores ciphertext only). Role-based access control with TenantRole permissions and a documented access-review workflow. Daily encrypted backups with a 30-day retention. Detailed Technical & Organisational Measures (TOMs) are listed inside the GDPR module of the application and available on request.

5. Subprocessor engagement

We engage the subprocessors listed below. We sign EU SCCs (Standard Contractual Clauses) and / or Swiss-DSG-equivalent contracts with each one. We will give Customers 14 days' advance notice before adding or replacing a subprocessor; subscribe to [email protected] for change notifications, or check this page (it is the canonical register).

6. Data subject rights & breach notification

We assist the Controller in fulfilling Art. 15–22 GDPR / revFADP requests. The GDPR module of the application includes a built-in DSR workflow with a 30-day clock and a one-click +60-day extension under Art. 12(3). In the event of a personal data breach affecting Customer data, we notify the Controller within 24 hours of becoming aware, and we assist with the Art. 33 / revFADP notifications to the supervisory authority (72 hours / "as soon as possible").

7. Data location & transfers

Primary processing and storage takes place inside the EU (DigitalOcean Frankfurt). Some subprocessors transfer data to the United States — those transfers are covered by the EU-U.S. Data Privacy Framework where the subprocessor is certified, or by Standard Contractual Clauses (SCCs / Swiss-DSG addendum) where it is not.

8. Audit rights & contact

The Controller may audit our compliance with this addendum once per calendar year, with reasonable advance notice and at the Controller's cost, subject to a confidentiality undertaking. We are happy to provide our most recent SOC 2 / ISO 27001 / penetration-test summaries on request. For any DPA-related question, breach report, or to request a counter-signed DPA: [email protected].

Subprocessor register

These are the third parties we use to deliver the Service. The list is canonical — we do not engage subprocessors that are not listed here.

Subprocessor Purpose Processing location Data processed
DigitalOcean, LLC
https://www.digitalocean.com
Application hosting and database storage EU (Frankfurt) All Customer data at rest
Anthropic PBC
https://www.anthropic.com
AI invoice parsing, booking, audit, advisory and document Q&A United States (SCCs in place) Document content, invoice metadata, free-text prompts
Stripe Payments Europe, Ltd.
https://stripe.com
Subscription billing and payment processing Ireland (EU) Customer name, email, billing address, payment instrument
Mailtrap (Railsware Products Studio LLC)
https://mailtrap.io
Transactional email delivery (account, billing, alerts) EU (Czech Republic) Recipient email, message content

Customer-side integrations (the Customer's own bank account, the Customer's own Gmail / IMAP server connected via OAuth, etc.) are operated by the Customer's chosen providers and are not Flitz subprocessors.

Need a counter-signed DPA?

For Customers in regulated industries or larger organisations that need a separately signed Data Processing Addendum, email [email protected] with your legal entity name and we will counter-sign and return within five business days.

Email [email protected]