Mast Finance Sàrl — Effective date: 31 August 2026 — Version 1.0
1. Contractual Framework
This Data Processing Agreement ("DPA") forms an integral part of, and is incorporated into, the Terms of Service between Mast Finance Sàrl ("Mast Finance" or "Processor") and the customer ("Controller"). In the event of conflict, this DPA prevails with respect to data protection matters.
This DPA reflects the requirements of the EU General Data Protection Regulation (GDPR), in particular Article 28, and the Swiss Federal Act on Data Protection (revFADP / nDSG).
2. Definitions
Terms not defined in this DPA have the meanings given in the Terms of Service or applicable data protection law. In this DPA:
- Controller: the customer, who determines the purposes and means of processing Customer Data.
- Processor: Mast Finance Sàrl, who processes personal data on behalf of the Controller.
- Customer Data: personal data provided by or generated on behalf of the Controller through use of the Service.
- Subprocessor: any third party engaged by Mast Finance to process Customer Data.
3. Subject Matter, Nature, and Duration
Mast Finance processes Customer Data on behalf of the Controller for the purpose of providing the Service, including hosting, storage, transmission, retrieval, computation, analysis, generation of outputs, customer support, security operations, and deletion.
Processing takes place for the duration of the subscription and any agreed data export or wind-down period following termination.
4. Categories of Personal Data and Data Subjects
Personal data processed may include:
- business contact and account data (names, roles, contact and company details);
- authentication and access data (user IDs, login events, session data, device identifiers);
- technical and usage data (logs, metadata, IP addresses, timestamps);
- billing and subscription data;
- Customer Data, which may include financial, accounting, expense, and treasury data relating to employees, contractors, customers, suppliers, or other individuals.
Data subjects may include: the Controller's employees and contractors, customers, suppliers, and any other individuals whose personal data is included in Customer Data.
5. Controller Obligations
The Controller:
- confirms it has a lawful basis for providing personal data to Mast Finance;
- is responsible for ensuring transparency toward data subjects;
- is responsible for the accuracy, legality, and completeness of instructions;
- will ensure Customer Data does not contain special categories of personal data (Art. 9 GDPR) unless expressly agreed in writing.
5.1 Fiduciary and Practice Relationships (Tri-Partite Arrangements)
Where the customer is a fiduciary, accounting, or advisory firm ("Practice") that uses the Service inside a client's tenant while acting as that client's agent, the parties acknowledge a tri-partite arrangement: the client is the controller of its own Customer Data, the Practice acts on the client's behalf under a separate mandate, and Mast Finance remains the processor. In these arrangements the Practice warrants that it is authorised by the client to instruct Mast Finance in respect of that client's Customer Data, and the client's instructions and this DPA continue to govern Mast Finance's processing. The allocation of responsibilities between the client and the Practice, including the scope of the Practice's authority to act as agent, is set out in the engagement letter between them; Mast Finance provides an engagement letter template for this purpose on request. Nothing in such an arrangement enlarges Mast Finance's obligations beyond those in this DPA.
6. Processor Obligations
Mast Finance shall:
- process Customer Data only on documented instructions from the Controller;
- ensure authorised personnel are bound by appropriate confidentiality obligations;
- implement and maintain appropriate technical and organisational security measures;
- not process Customer Data for its own purposes or disclose it to third parties except (i) as required to provide the Service or comply with law, or (ii) where the Customer has expressly enabled the model improvement programme described in the Terms of Service, in which case processing is limited to producing irreversibly anonymised training examples, and the resulting anonymised data falls outside the scope of this DPA;
- inform the Controller promptly if an instruction infringes applicable data protection law.
Service Data: Mast Finance acts as an independent data controller with respect to Service Data (account metadata, usage logs, feature adoption data, and other technical/behavioural data generated through interaction with the Service, excluding Customer Data). Mast Finance may collect, use, and analyse Service Data for legitimate internal business purposes as described in its Privacy Policy.
7. Security Measures
Mast Finance implements appropriate technical and organisational security measures, including encryption of data in transit and at rest, access controls, logging and monitoring, incident response procedures, and regular security assessments.
8. Subprocessors
The Controller grants Mast Finance general authorisation to engage subprocessors. Mast Finance maintains a publicly available list at mastfinance.io/subprocessors.
The Controller may object to a new subprocessor on reasonable data protection grounds within 14 days. If the objection cannot be resolved, the Controller may terminate the relevant service upon written notice.
Mast Finance imposes equivalent data protection obligations on subprocessors and remains liable for their acts and omissions.
Current Subprocessors
For the authoritative, version-controlled list with full legal entity names and transfer basis, see the Subprocessors page. Summary:
| Subprocessor | Purpose | Data Location | Transfer basis |
|---|---|---|---|
| Amazon Web Services (AWS EMEA Sàrl) | Cloud infrastructure, hosting, email delivery (SES), static asset delivery (CloudFront), and AI inference via AWS Bedrock (Anthropic Claude and Cohere models accessed as part of the managed Bedrock service) for Mast AI | Customer Data stored in Switzerland (eu-central-2). AI inference primarily in Switzerland (Zurich); chat/embeddings can burst across EU regions and Cohere reranking runs in EU (Frankfurt, eu-central-1). Email delivery in EU (Ireland, eu-west-1). Monthly disaster-recovery database snapshots and, where the Controller enables bill reception by email, transiently held inbound messages are stored in EU (Ireland, eu-west-1) | AWS DPA; EU-region processing covered by the Switzerland–EU adequacy decision |
| Stripe, Inc. | Payment processing for Mast's own subscription (billing contact data only; no Customer Data) | EU / US | EU-US and Swiss-US Data Privacy Frameworks |
| Microsoft Corporation (Microsoft 365 / Graph) | Email send and receive on the customer's behalf via Graph OAuth, where the customer connects a Microsoft mailbox | EU / US, depending on the customer's Microsoft tenant | Microsoft DPA and SCCs; EU-US and Swiss-US Data Privacy Frameworks |
| PostHog, Inc. | Product analytics, session replay (anonymised; Customer Data never transmitted) | EU (Frankfurt) via PostHog Cloud EU | SCCs; EU-resident |
| Functional Software, Inc. dba Sentry | Error monitoring and performance monitoring (PII scrubbed; Customer Data never transmitted) | EU (Frankfurt) via Sentry Cloud EU | SCCs; EU-resident |
| External developers — Switzerland or the European Union (independent contractors; natural persons, identity provided on request) | Development, maintenance, diagnosis, and support. Access to an environment holding customer or tester data is opened case by case by written notice, scope-limited, time-limited, and revocable | Switzerland or the EU; contractors may reach customer or tester data only from Switzerland or the EU | Written services contract with an art. 28 GDPR / art. 9 revFADP processor annex; no onward subprocessing without Mast's prior specific written authorisation |
SIX bLink (open banking / bank feeds) is built but dormant and not yet active; PayPal, Shopify, and WooCommerce are customer-directed merchant data sources the customer connects, not Mast sub-processors of Mast-controlled data. See the Subprocessors page for the full characterisation.
9. International Data Transfers
Customer Data is stored within Switzerland (AWS Zurich), with the limited EU-region exceptions listed in §8 and described in the Privacy Policy: AI inference runs primarily in Switzerland and, for reranking and burst capacity, in EU regions; monthly disaster-recovery snapshots of the production database are replicated to AWS Ireland (eu-west-1), encrypted with a dedicated key and retained for 10 years under CO Art. 958f; transactional email is delivered from AWS SES in Ireland (eu-west-1); and, where the Controller enables bill reception by email, inbound messages and attachments are held transiently (at most 7 days) by SES/S3 in Ireland. All of these are covered by the Switzerland–EU adequacy decision. Where transfers outside Switzerland or the EEA are necessary, appropriate safeguards are ensured, including:
- adequacy decisions recognised under the GDPR or the Swiss revFADP, including the Switzerland–EU adequacy decision for EU-region processing;
- the EU-US Data Privacy Framework and the Swiss-US Data Privacy Framework for transfers to certified recipients in the United States (as a Swiss controller, Mast relies on the Swiss-US Data Privacy Framework for its own US transfers);
- Standard Contractual Clauses (SCCs) approved by the European Commission, or Swiss equivalent clauses recognised by the FDPIC;
- other recognised transfer mechanisms as applicable.
10. Assistance to the Controller
Mast Finance shall provide reasonable assistance with:
- responding to data subject requests;
- meeting security and breach notification obligations;
- conducting data protection impact assessments, where required.
Such assistance may be subject to reasonable fees where it requires material effort beyond standard service delivery.
11. Personal Data Breaches
Mast Finance shall notify the Controller without undue delay (within 72 hours where feasible) after becoming aware of a breach affecting Customer Data, providing details of the nature, scope, consequences, and remedial measures.
12. Deletion and Return of Data
Upon termination, Customer Data follows a three-stage lifecycle:
- Day 0 to Day 30: Customer Data remains fully intact and available for export.
- Day 30: personal data within the Customer Data is anonymised and the tenant is archived.
- Day 90: the remaining tenant-scoped financial data is permanently purged. Only a minimal tenant record (company name and subscription metadata), anonymised audit logs, and Mast Finance's own billing records are retained thereafter, as required for Mast Finance's 10-year bookkeeping obligation under CO Art. 958f.
Mast Finance will provide written confirmation of deletion upon request. The full lifecycle, including how deletion is requested, is set out in the Data Retention & Account Deletion Policy.
13. Audit Rights
Audit rights are ordinarily satisfied through the following remote mechanisms:
- completion of Mast Finance's standard security and compliance questionnaire;
- provision of any third-party audit reports or certifications Mast Finance holds at the time of the request.
Physical and on-site audits are not granted as of right. Where the Controller's regulatory obligations require more than the mechanisms above, the parties will agree a proportionate alternative in good faith. Audit requests may be submitted to contact@mastfinance.io and may be made no more than once per calendar year, except following a confirmed breach.
14. Liability
Liability is subject to the limitations in the Terms of Service, to the extent permitted by applicable data protection law.
15. Governing Law and Jurisdiction
This DPA is governed by and construed in accordance with Swiss law, excluding conflict of law rules. The parties submit to the exclusive jurisdiction of the courts of Lausanne, Switzerland. Nothing in this section limits a data subject's right to bring proceedings in any competent jurisdiction as permitted by applicable data protection law.
Mast Finance Sàrl — Rue Centrale 15, 1003 Lausanne, Switzerland — contact@mastfinance.io