Mast Finance Sàrl — Effective date: 13 July 2026 — Version 1.1
Mast Finance engages the following third-party subprocessors to provide components of the Service. This page is maintained in accordance with our Data Processing Agreement.
Customers may object to a new or replacement subprocessor on reasonable and documented data protection grounds within 14 days of the relevant update being published on this page, as described in our DPA.
Current Subprocessors
| Subprocessor | Purpose | Data categories | Location | Transfer basis |
|---|---|---|---|---|
| Amazon Web Services (AWS EMEA Sàrl, Luxembourg) | Cloud infrastructure: hosting, storage, compute, transactional email delivery (SES), static asset delivery (CloudFront), and AI inference via AWS Bedrock (Anthropic Claude and Cohere models accessed as part of the managed Bedrock service, powering Mast AI: in-app help, financial analysis, report generation, and RAG reranking). | Customer Data (financial and accounting records), Service Data, AI prompts and completions, transactional email content. | Customer Data is stored in Switzerland (eu-central-2, Zurich). AI inference runs primarily in Switzerland (Zurich); chat and embeddings use EU cross-region inference profiles that can burst across EU regions, and Cohere reranking runs in EU (Frankfurt, eu-central-1). Transactional email (SES) runs in EU (Frankfurt, eu-central-1). Static assets served via CloudFront global edge locations (no Customer Data). | Single AWS Data Processing Addendum. Transfers within Switzerland and the EU; EU-region processing covered by the Switzerland–EU adequacy decision. AWS does not use Bedrock inputs or outputs to train models. |
| Stripe, Inc. | Payment processing, billing, and subscription management for Mast's own subscription (Mast is the merchant of record). | Billing contact data, payment status, subscription details. No Customer Data (financial or accounting records) is transmitted. | EU / United States (billing contact data only). | Certified under both the EU-US Data Privacy Framework and the Swiss-US Data Privacy Framework. As a Swiss controller, Mast relies on the Swiss-US Data Privacy Framework for transfers to the United States. |
| Microsoft Corporation (Microsoft 365 / Graph) | Email send and receive on the customer's behalf via Microsoft Graph OAuth, where the customer connects a Microsoft mailbox to the email integration. | OAuth tokens and email message content and metadata for connected mailboxes. | European Union / United States, depending on the customer's Microsoft tenant region. | Microsoft's Data Protection Addendum and Standard Contractual Clauses; EU-US Data Privacy Framework and Swiss-US Data Privacy Framework for US transfers. |
| PostHog, Inc. | Product analytics — usage events, feature adoption, and (where enabled) anonymised session recordings with masked input fields. Consent-gated. Processes Service Data only; no Customer Data is transmitted. | Service Data (telemetry, usage events, masked session recordings). IP addresses are not collected. | EU (Frankfurt, eu-central-1) via PostHog Cloud EU. | Standard Contractual Clauses in place. Data resident in the EU. |
| Functional Software, Inc. dba Sentry | Error monitoring and performance monitoring — stack traces and technical metadata. No personal data is collected by default; email addresses in error messages are redacted before transmission. | Technical stack traces and metadata (Service Data). | EU (Frankfurt) via Sentry Cloud EU region. | Standard Contractual Clauses in place. Data resident in the EU. |
Planned / Not Yet Active
| Subprocessor | Purpose | Status |
|---|---|---|
| SIX bLink (SIX Group AG) | Open banking / bank feed connectivity (AIS) for automatic import of bank transactions. | Built but dormant. The feature is currently flagged off and no personal data is sent to SIX bLink yet. This page will be updated before the integration is activated. |
Customer-Directed Merchant Data Sources
The following are integrations the customer authorises and connects, so that Mast can pull the customer's own sales and transaction data into the Service on the customer's instruction. Mast does not control the data held in these platforms and does not engage them as its own subprocessors; the customer's relationship with each provider is governed by that provider's own terms. They are listed here for transparency.
| Provider | Purpose | Characterisation |
|---|---|---|
| PayPal | Import the customer's own PayPal sales and transaction data. | Customer-directed data source connected via the customer's own credentials/OAuth. Not a Mast sub-processor of Mast-controlled data. |
| Shopify | Import the customer's own Shopify order and sales data. | Customer-directed data source connected via the customer's own credentials/OAuth. Not a Mast sub-processor of Mast-controlled data. |
| WooCommerce | Import the customer's own WooCommerce order and sales data. | Customer-directed data source connected via the customer's own credentials/OAuth. Not a Mast sub-processor of Mast-controlled data. |
Changes
This page will be updated before any new subprocessor is engaged. A changelog of changes is maintained below.
| Date | Change |
|---|---|
| 24 February 2026 | Initial publication. |
| 18 April 2026 | Migrated product analytics from self-hosted to PostHog Cloud EU (Frankfurt); added PostHog, Inc. as subprocessor. Clarified Sentry status: error monitoring has been provided by Sentry Cloud EU since inception; added Functional Software, Inc. dba Sentry as a named subprocessor for transparency. |
| 29 May 2026 | Updated AWS subprocessor scope to include AI inference (AWS Bedrock) for Mast AI. |
| 13 July 2026 | Rewrote the table into purpose / data categories / location / transfer basis columns. Corrected the AWS row: AI inference runs primarily in Switzerland (Zurich) but chat/embeddings can burst across EU regions and Cohere reranking runs in EU (Frankfurt), all under the Switzerland–EU adequacy decision (removed the self-contradictory "exclusively Zurich" wording). Added Microsoft (email via Graph OAuth) as a subprocessor. Added the Swiss-US Data Privacy Framework alongside the EU-US Data Privacy Framework for Stripe. Added SIX bLink as planned / not yet active. Documented PayPal, Shopify, and WooCommerce as customer-directed merchant data sources rather than Mast sub-processors. |
Revision history
- v1.1 (2026-07-13): Rewrote subprocessor table into a complete, non-contradictory form (purpose, data categories, location, transfer basis). Fixed the self-contradictory AWS residency wording, added Microsoft, characterised PayPal/Shopify/WooCommerce as customer-directed sources, and listed SIX bLink as planned. Added draft banner.
- v1.0 (2026-02-24): initial.
Contact
For questions about our subprocessors, please contact us at contact@mastfinance.io.
Mast Finance Sàrl — Rue Centrale 15, 1003 Lausanne, Switzerland — contact@mastfinance.io