Mast Finance Sàrl — Effective date: 13 July 2026 — Version 1.1
1. Contractual Framework
This Data Processing Agreement ("DPA") forms an integral part of, and is incorporated into, the Terms of Service between Mast Finance Sàrl ("Mast Finance" or "Processor") and the customer ("Controller"). In the event of conflict, this DPA prevails with respect to data protection matters.
This DPA reflects the requirements of the EU General Data Protection Regulation (GDPR), in particular Article 28, and the Swiss Federal Act on Data Protection (revFADP / nDSG).
2. Definitions
Terms not defined in this DPA have the meanings given in the Terms of Service or applicable data protection law. In this DPA:
- Controller: the customer, who determines the purposes and means of processing Customer Data.
- Processor: Mast Finance Sàrl, who processes personal data on behalf of the Controller.
- Customer Data: personal data provided by or generated on behalf of the Controller through use of the Service.
- Subprocessor: any third party engaged by Mast Finance to process Customer Data.
3. Subject Matter, Nature, and Duration
Mast Finance processes Customer Data on behalf of the Controller for the purpose of providing the Service, including hosting, storage, transmission, retrieval, computation, analysis, generation of outputs, customer support, security operations, and deletion.
Processing takes place for the duration of the subscription and any agreed data export or wind-down period following termination.
4. Categories of Personal Data and Data Subjects
Personal data processed may include:
- business contact and account data (names, roles, contact and company details);
- authentication and access data (user IDs, login events, session data, device identifiers);
- technical and usage data (logs, metadata, IP addresses, timestamps);
- billing and subscription data;
- Customer Data, which may include financial, accounting, expense, and treasury data relating to employees, contractors, customers, suppliers, or other individuals.
Data subjects may include: the Controller's employees and contractors, customers, suppliers, and any other individuals whose personal data is included in Customer Data.
5. Controller Obligations
The Controller:
- confirms it has a lawful basis for providing personal data to Mast Finance;
- is responsible for ensuring transparency toward data subjects;
- is responsible for the accuracy, legality, and completeness of instructions;
- will ensure Customer Data does not contain special categories of personal data (Art. 9 GDPR) unless expressly agreed in writing.
5.1 Fiduciary and Practice Relationships (Tri-Partite Arrangements)
Where the customer is a fiduciary, accounting, or advisory firm ("Practice") that uses the Service inside a client's tenant while acting as that client's agent, the parties acknowledge a tri-partite arrangement: the client is the controller of its own Customer Data, the Practice acts on the client's behalf under a separate mandate, and Mast Finance remains the processor. In these arrangements the Practice warrants that it is authorised by the client to instruct Mast Finance in respect of that client's Customer Data, and the client's instructions and this DPA continue to govern Mast Finance's processing. The allocation of responsibilities between the client and the Practice, including the scope of the Practice's authority to act as agent, is set out in the engagement letter between them; see the engagement letter template at engagement-letter-template.md. Nothing in such an arrangement enlarges Mast Finance's obligations beyond those in this DPA.
6. Processor Obligations
Mast Finance shall:
- process Customer Data only on documented instructions from the Controller;
- ensure authorised personnel are bound by appropriate confidentiality obligations;
- implement and maintain appropriate technical and organisational security measures;
- not process Customer Data for its own purposes or disclose it to third parties except as required to provide the Service or comply with law;
- inform the Controller promptly if an instruction infringes applicable data protection law.
Service Data: Mast Finance acts as an independent data controller with respect to Service Data (account metadata, usage logs, feature adoption data, and other technical/behavioural data generated through interaction with the Service, excluding Customer Data). Mast Finance may collect, use, and analyse Service Data for legitimate internal business purposes as described in its Privacy Policy.
7. Security Measures
Mast Finance implements appropriate technical and organisational security measures, including encryption of data in transit and at rest, access controls, logging and monitoring, incident response procedures, and regular security assessments.
8. Subprocessors
The Controller grants Mast Finance general authorisation to engage subprocessors. Mast Finance maintains a publicly available list at mastfinance.io/subprocessors.
The Controller may object to a new subprocessor on reasonable data protection grounds within 14 days. If the objection cannot be resolved, the Controller may terminate the relevant service upon written notice.
Mast Finance imposes equivalent data protection obligations on subprocessors and remains liable for their acts and omissions.
Current Subprocessors
For the authoritative, version-controlled list with full legal entity names and transfer basis, see the Subprocessors page (also at docs/legal/subprocessors.md). Summary:
| Subprocessor | Purpose | Data Location | Transfer basis |
|---|---|---|---|
| Amazon Web Services (AWS EMEA Sàrl) | Cloud infrastructure, hosting, email delivery (SES), static asset delivery (CloudFront), and AI inference via AWS Bedrock (Anthropic Claude and Cohere models accessed as part of the managed Bedrock service) for Mast AI | Customer Data stored in Switzerland (eu-central-2). AI inference primarily in Switzerland (Zurich); chat/embeddings can burst across EU regions and Cohere reranking runs in EU (Frankfurt, eu-central-1). Email delivery in EU (Frankfurt) | AWS DPA; EU-region processing covered by the Switzerland–EU adequacy decision |
| Stripe, Inc. | Payment processing for Mast's own subscription (billing contact data only; no Customer Data) | EU / US | EU-US and Swiss-US Data Privacy Frameworks |
| Microsoft Corporation (Microsoft 365 / Graph) | Email send and receive on the customer's behalf via Graph OAuth, where the customer connects a Microsoft mailbox | EU / US, depending on the customer's Microsoft tenant | Microsoft DPA and SCCs; EU-US and Swiss-US Data Privacy Frameworks |
| PostHog, Inc. | Product analytics, session replay (anonymised; Customer Data never transmitted) | EU (Frankfurt) via PostHog Cloud EU | SCCs; EU-resident |
| Functional Software, Inc. dba Sentry | Error monitoring and performance monitoring (PII scrubbed; Customer Data never transmitted) | EU (Frankfurt) via Sentry Cloud EU | SCCs; EU-resident |
SIX bLink (open banking / bank feeds) is built but dormant and not yet active; PayPal, Shopify, and WooCommerce are customer-directed merchant data sources the customer connects, not Mast sub-processors of Mast-controlled data. See the Subprocessors page for the full characterisation.
9. International Data Transfers
Customer Data is stored within Switzerland (AWS Zurich). AI inference runs primarily in Switzerland and, for reranking and burst capacity, in EU regions under the Switzerland–EU adequacy decision. Where transfers outside Switzerland or the EEA are necessary, appropriate safeguards are ensured, including:
- adequacy decisions recognised under GDPR or Swiss nDSG, including the Switzerland–EU adequacy decision for EU-region processing;
- the EU-US Data Privacy Framework and the Swiss-US Data Privacy Framework for transfers to certified recipients in the United States (as a Swiss controller, Mast relies on the Swiss-US Data Privacy Framework for its own US transfers);
- Standard Contractual Clauses (SCCs) approved by the European Commission, or Swiss equivalent clauses recognised by the FDPIC;
- other recognised transfer mechanisms as applicable.
10. Assistance to the Controller
Mast Finance shall provide reasonable assistance with:
- responding to data subject requests;
- meeting security and breach notification obligations;
- conducting data protection impact assessments, where required.
Such assistance may be subject to reasonable fees where it requires material effort beyond standard service delivery.
11. Personal Data Breaches
Mast Finance shall notify the Controller without undue delay (within 72 hours where feasible) after becoming aware of a breach affecting Customer Data, providing details of the nature, scope, consequences, and remedial measures.
12. Deletion and Return of Data
Upon termination:
- Customer Data remains available for export for 30 days;
- after this period, Customer Data is deleted or anonymised unless retention is required by law;
- Mast Finance will provide written confirmation of deletion upon request.
13. Audit Rights
Audit rights are satisfied exclusively through the following remote mechanisms:
- completion of Mast Finance's standard security and compliance questionnaire;
- provision of relevant third-party audit reports, certifications, or summaries (such as SOC 2 Type II, ISO 27001, or equivalent).
No physical or on-site audits are granted. Audit requests may be submitted to contact@mastfinance.io and may be made no more than once per calendar year, except following a confirmed breach.
14. Liability
Liability is subject to the limitations in the Terms of Service, to the extent permitted by applicable data protection law.
15. Governing Law and Jurisdiction
This DPA is governed by and construed in accordance with Swiss law, excluding conflict of law rules. The parties submit to the exclusive jurisdiction of the courts of Lausanne, Switzerland. Nothing in this section limits a data subject's right to bring proceedings in any competent jurisdiction as permitted by applicable data protection law.
Revision history
- v1.1 (2026-07-13): Aligned the Section 8 subprocessor summary with
subprocessors.md(added transfer-basis column, named AI inference accurately as AWS Bedrock with Anthropic and Cohere models, added Microsoft, noted SIX bLink as dormant and the customer-directed merchant sources). Added the Swiss-US Data Privacy Framework alongside the EU-US Data Privacy Framework in Sections 8 and 9. Added Section 5.1 acknowledging fiduciary/practice tri-partite arrangements and cross-referencing the engagement letter template. Added draft banner. - v1.0 (2026-02-24): initial.
Mast Finance Sàrl — Rue Centrale 15, 1003 Lausanne, Switzerland — contact@mastfinance.io