Mast Finance Sàrl — Last updated: 28 August 2026
Mast Finance engages the following third-party subprocessors to provide components of the Service. This page is maintained in accordance with our Data Processing Agreement.
Customers may object to a new or replacement subprocessor on reasonable and documented data protection grounds within 14 days of the relevant update being published on this page, as described in our DPA.
Current Subprocessors
| Subprocessor | Purpose | Data categories | Location | Transfer basis |
|---|---|---|---|---|
| Amazon Web Services (AWS EMEA Sàrl, Luxembourg) | Cloud infrastructure: hosting, storage, compute, transactional email delivery (SES), static asset delivery (CloudFront), and AI inference via AWS Bedrock (Anthropic Claude and Cohere models accessed as part of the managed Bedrock service, powering Mast AI: in-app help, financial analysis, report generation, and RAG reranking). | Customer Data (financial and accounting records), Service Data, AI prompts and completions, transactional email content. | Customer Data is stored in Switzerland (eu-central-2, Zurich). AI inference runs primarily in Switzerland (Zurich); chat and embeddings use EU cross-region inference profiles that can burst across EU regions, and Cohere reranking runs in EU (Frankfurt, eu-central-1). Transactional email (SES) runs in EU (Ireland, eu-west-1); account emails from the authentication service (verification codes, password resets) are sent via SES in EU (Frankfurt, eu-central-1). Monthly disaster-recovery snapshots of the production database are copied to EU (Ireland, eu-west-1), encrypted with a dedicated key and retained 10 years under CO Art. 958f. Where a customer enables bill reception by email, inbound messages and attachments are held transiently (at most 7 days) by SES/S3 in EU (Ireland, eu-west-1), because SES email receiving is not offered in Zurich. Static assets served via CloudFront global edge locations (no Customer Data). | Single AWS Data Processing Addendum. Transfers within Switzerland and the EU; EU-region processing covered by the Switzerland–EU adequacy decision. AWS does not use Bedrock inputs or outputs to train models. |
| Stripe, Inc. | Payment processing, billing, and subscription management for Mast's own subscription (Mast is the merchant of record). | Billing contact data, payment status, subscription details. No Customer Data (financial or accounting records) is transmitted. | EU / United States (billing contact data only). | Certified under both the EU-US Data Privacy Framework and the Swiss-US Data Privacy Framework. As a Swiss controller, Mast relies on the Swiss-US Data Privacy Framework for transfers to the United States. |
| Microsoft Corporation (Microsoft 365 / Graph) | Email send and receive on the customer's behalf via Microsoft Graph OAuth, where the customer connects a Microsoft mailbox to the email integration. | OAuth tokens and email message content and metadata for connected mailboxes. | European Union / United States, depending on the customer's Microsoft tenant region. | Microsoft's Data Protection Addendum and Standard Contractual Clauses; EU-US Data Privacy Framework and Swiss-US Data Privacy Framework for US transfers. |
| PostHog, Inc. | Product analytics — usage events, feature adoption, and (where enabled) anonymised session recordings with masked input fields. Consent-gated. Processes Service Data only; no Customer Data is transmitted. | Service Data (telemetry, usage events, masked session recordings). IP addresses are not collected. | EU (Frankfurt, eu-central-1) via PostHog Cloud EU. | Standard Contractual Clauses in place. Data resident in the EU. |
| Functional Software, Inc. dba Sentry | Error monitoring and performance monitoring — stack traces and technical metadata. No personal data is collected by default; email addresses in error messages are redacted before transmission. | Technical stack traces and metadata (Service Data). | EU (Frankfurt) via Sentry Cloud EU region. | Standard Contractual Clauses in place. Data resident in the EU. |
| External developers — Switzerland or the European Union (independent contractors engaged by Mast Finance; natural persons, identity provided on request) | Development, maintenance, diagnosis, and support of the Service. Access to an environment containing customer or tester data is opened case by case by written notice naming the environment, the scope, and an expiry date of at most 12 months, and is revocable at any time. The processing is purely technical: contractors are not engaged to analyse, enrich, extract, or otherwise exploit personal data, and encounter it only incidentally to that work. | Customer Data and Service Data, limited to what a given task requires: identification and contact details, authentication metadata (never passwords in clear text), activity and audit records, support correspondence, and customers' accounting records. No special-category data is sought. | Switzerland or the European Union. Contractors may reach customer or tester data only from Switzerland or the EU, including while travelling. | Written services contract with a processor annex under art. 28 GDPR and art. 9 revFADP, confidentiality backed by a contractual penalty, professional liability insurance required before any access to real data, and no onward subprocessing without Mast's prior specific written authorisation. |
We list this category before any such access is opened, so that the 14-day objection period described above runs ahead of the event rather than after it. Individual contractors are not named here because they are natural persons; we identify the contractor engaged at any given time to any customer who asks.
Planned / Not Yet Active
| Subprocessor | Purpose | Status |
|---|---|---|
| SIX bLink (SIX Group AG) | Open banking / bank feed connectivity (AIS) for automatic import of bank transactions. | Built but dormant. The feature is currently flagged off and no personal data is sent to SIX bLink yet. This page will be updated before the integration is activated. |
Customer-Directed Merchant Data Sources
The following are integrations the customer authorises and connects, so that Mast can pull the customer's own sales and transaction data into the Service on the customer's instruction. Mast does not control the data held in these platforms and does not engage them as its own subprocessors; the customer's relationship with each provider is governed by that provider's own terms. They are listed here for transparency.
| Provider | Purpose | Characterisation |
|---|---|---|
| PayPal | Import the customer's own PayPal sales and transaction data. | Customer-directed data source connected via the customer's own credentials/OAuth. Not a Mast sub-processor of Mast-controlled data. |
| Shopify | Import the customer's own Shopify order and sales data. | Customer-directed data source connected via the customer's own credentials/OAuth. Not a Mast sub-processor of Mast-controlled data. |
| WooCommerce | Import the customer's own WooCommerce order and sales data. | Customer-directed data source connected via the customer's own credentials/OAuth. Not a Mast sub-processor of Mast-controlled data. |
Changes
This page will be updated before any new subprocessor is engaged. A changelog of changes is maintained below.
| Date | Change |
|---|---|
| 24 February 2026 | Initial publication. |
| 18 April 2026 | Migrated product analytics from self-hosted to PostHog Cloud EU (Frankfurt); added PostHog, Inc. as subprocessor. Clarified Sentry status: error monitoring has been provided by Sentry Cloud EU since inception; added Functional Software, Inc. dba Sentry as a named subprocessor for transparency. |
| 29 May 2026 | Updated AWS subprocessor scope to include AI inference (AWS Bedrock) for Mast AI. |
| 13 July 2026 | Rewrote the table into purpose / data categories / location / transfer basis columns. Corrected the AWS row: AI inference runs primarily in Switzerland (Zurich) but chat/embeddings can burst across EU regions and Cohere reranking runs in EU (Frankfurt), all under the Switzerland–EU adequacy decision (removed the self-contradictory "exclusively Zurich" wording). Added Microsoft (email via Graph OAuth) as a subprocessor. Added the Swiss-US Data Privacy Framework alongside the EU-US Data Privacy Framework for Stripe. Added SIX bLink as planned / not yet active. Documented PayPal, Shopify, and WooCommerce as customer-directed merchant data sources rather than Mast sub-processors. |
| 9 August 2026 | Added External developers — Switzerland or the European Union as a subprocessor category, covering independent contractors engaged by Mast Finance for development, maintenance, diagnosis, and support. Listed in advance of any such access being opened. Contractors are natural persons and are therefore not named on this page; the contractor engaged at any given time is identified to any customer on request. |
| 10 August 2026 | Corrected the transactional-email (SES) region: Ireland (eu-west-1), not Frankfurt (eu-central-1). The account's verified sending identities and the inbound pipeline both run in eu-west-1; the Frankfurt statement was stale. No new subprocessor and no change to where Customer Data is stored. |
| 28 August 2026 | Republished with the rest of the legal set. Extended the AWS row to state two EU-region Customer Data flows that were previously undisclosed: monthly disaster-recovery database snapshots copied to Ireland (eu-west-1) and retained 10 years, and inbound invoice email held transiently (at most 7 days) by SES/S3 in Ireland where a customer enables bill reception by email. No new subprocessor. |
Contact
For questions about our subprocessors, please contact us at contact@mastfinance.io.
Mast Finance Sàrl — Rue Centrale 15, 1003 Lausanne, Switzerland — contact@mastfinance.io