Mast Finance Sàrl — Effective date: 28 August 2026 — Version 1.0
1. Legal Framework
1.1 Swiss Code of Obligations (CO Art. 958f)
Swiss law requires entities subject to bookkeeping obligations (i.e., the company using Mast) to retain their accounting records for 10 years from the end of the fiscal year in which the last entry was made. This includes:
- Accounting books (journal, ledger, inventory)
- Supporting documents and vouchers
- Invoices (issued and received)
- Bank statements
- VAT documents
- Annual and audit reports
Important: This obligation belongs to the company (the data controller), not to Mast Finance as the SaaS provider (data processor). When a company closes its Mast account, it is their responsibility to retain their records for the legally required period.
1.2 Swiss Federal Act on Data Protection (revFADP / nDSG)
Under the revFADP (effective September 1, 2023):
- Personal data must be deleted or anonymized when it is no longer needed for the purpose it was collected.
- Once the business relationship with a customer ends, Mast has no legal basis to retain that customer's data long-term.
- The data minimization principle requires that data retention be limited to what is strictly necessary.
1.3 Data Portability
The revFADP grants individuals the right to receive their personal data in a commonly used electronic format. Mast extends this to all tenant data (not just personal data) to ensure companies can export their complete financial records before account closure.
2. Account Deletion and Post-Termination Lifecycle
The same Day 0 / Day 30 / Day 90 clock applies whether the account is deleted at the customer's request or the subscription simply ends (cancellation, expiry of a free trial, or cancellation for non-payment). Only the Day 0 step differs, as set out below.
2.1 Day 0: Deletion Requested, or the Subscription Ends
Deletion at your request. To have the account deleted, write to contact@mastfinance.io from the account owner's address. Before we confirm the deletion:
- we offer you a complete export of all your tenant data (a JSON file containing all financial records), which you may decline in writing;
- we record in the audit log who requested the deletion, whether the export was provided or declined, and the timestamp.
Once the deletion is confirmed, the tenant status is set to PENDING_DELETION, user sessions for the account are revoked and login is disabled. You are informed that the data is retained for 30 days and that you can ask us to cancel the deletion during that period.
End of subscription. Where the account simply reaches the end of a cancelled or unpaid subscription, or a free trial expires, no lockout applies at Day 0: you and your users keep read and export access for the 30-day grace period below. Cancellation for non-payment is described in §9.7 of the Terms of Service.
2.2 Day 0-30: Grace Period
- All data remains fully intact.
- Where access has not been disabled (end of subscription), you can sign in and export your data throughout this period via Settings > Data Export.
- To cancel a deletion and have the account reactivated, email
contact@mastfinance.io. Reactivation checks seat availability — if an organisation has filled the vacated seat, reactivation into that organisation is blocked until its owner frees a seat, and we tell you which organisation(s) are at capacity. - Export reminder emails are sent to the billing or contact address on the account around Day 20 ("10 days remaining") and again around Day 25 ("5 days remaining — final warning").
- No automated data processing occurs during this period.
2.3 Day 30: PII Anonymization
- Individual personal data anonymized: User first names, last names, email addresses, phone numbers, and address/bank fields are replaced with SHA-256 hashes or cleared.
- Cognito user permanently deleted from AWS Cognito.
- Tenant status changed to
ARCHIVED. Tenant settings JSON cleared. - Company name retained: The tenant's company name and creation date are kept as business data (not individual PII) for Mast's own billing cross-reference.
- Reactivation is no longer possible after this point.
2.4 Day 90: Financial Data Purge
All tenant-scoped financial data permanently deleted:
- Invoices, credit notes, offers, orders, delivery notes
- Bills, expenses, purchase orders
- Journal entries and journal lines
- Bank accounts and bank transactions
- Customers, suppliers, products, cost centers
- Fixed assets and depreciation schedules
- Fiscal years, accounting periods
- Tax rates, VAT settings
- Chart of accounts
- Company profile and settings
- Roles and permissions
- Teams and team memberships
User records deleted (already anonymized at Day 30).
Retained by Mast (for Mast's own 10-year bookkeeping obligation under CO Art. 958f):
- Tenant record (id, company name, slug, subscription plan, creation date, deletion date, purge date) — serves as the billing cross-reference to identify which company Mast issued invoices to.
- Audit logs (operational events with anonymized user references — no individual PII, no customer financial data).
- Stripe billing records (subscription invoices, payment history) — retained externally in Stripe, linkable via tenant ID.
This structure ensures Mast can always identify which company it billed and for what period, satisfying the 10-year retention requirement, without retaining any of the customer's own financial or personal data.
3. Data Export
3.1 Export Availability
The account owner can export all tenant data at any time via:
- the Settings > Data Export page in the application, including while the account is read only or within the 30-day grace period;
- the export Mast Finance offers before confirming a deletion request.
3.2 Export Contents
The export includes all tenant-scoped data organized by entity type:
| Category | Entities Included |
|---|---|
| Accounting | Chart of accounts, journal entries, journal lines, fiscal years, accounting periods |
| Sales | Invoices, credit notes, offers, orders, delivery notes |
| Purchases | Bills, expenses |
| Treasury | Bank accounts, bank transactions |
| Database | Customers, suppliers, products, cost centers |
| Assets | Fixed assets, depreciation schedules |
| Settings | Company profile, tax rates, currency settings, roles, users |
3.3 Export Format
- JSON: Structured by entity type (direct download, streamed response).
- CSV: ZIP archive with one CSV per entity type.
- Future: S3 pre-signed URL for large tenants.
3.4 Legal Notice
The export includes a notice reminding the company that they are responsible for retaining their accounting records for 10 years under Swiss law (CO Art. 958f).
4. What Mast Retains After Full Purge
After the 90-day purge completes, the only data Mast retains is:
| Data Type | Contains PII? | Retention Period | Legal Basis |
|---|---|---|---|
| Tenant record (company name, plan, dates) | No (business data) | 10 years | CO Art. 958f (billing cross-reference) |
| Mast's own invoices to the customer (Stripe) | No (business data) | 10 years | CO Art. 958f (Mast's own bookkeeping) |
| Audit logs (operational events) | No (user refs anonymized at Day 30) | 10 years | CO Art. 958f + legitimate interest |
| Anonymized usage statistics | No | Indefinite | Legitimate interest (product improvement) |
No individual personal data (names, personal emails, phone numbers) or customer financial data (invoices, journals, bank transactions) is retained after the 90-day purge. The tenant record retains only the company name and subscription metadata needed for Mast to identify who it billed, as required by Swiss bookkeeping law.
5. Contact
For questions about data retention or to request account reactivation during the grace period:
- Email:
contact@mastfinance.io - Subject: "Account Reactivation Request" (include company name and owner email)
Mast Finance Sàrl — Rue Centrale 15, 1003 Lausanne, Switzerland — contact@mastfinance.io