Legal
Data processing agreement
Data processing agreement under Art. 28 GDPR for the processing of your accounting data in Saldek.
Last updated: 10 October 2026
This translation is provided for information only. Only the German version is legally binding. Read the German original
1. Subject and scope
This agreement governs the rights and obligations of the parties in connection with the processing of personal data by FluxonLab (processor) on behalf of the customer (controller) in providing the accounting and document extraction platform Saldek.
Type of data: Financial and accounting data, invoice and document data, master data of business partners (suppliers/customers) including their e-mail addresses, VAT IDs (USt-IdNr./UID), bank details (IBAN/BIC), booking notes.
Categories of data subjects: Employees, officers, customers and suppliers of the controller.
2. Obligations of the processor (Art. 28(3) GDPR)
a) Instructions (Art. 28(3)(a)): The processor processes personal data only on documented instructions from the controller. Customer data is stored in Germany: the databases on servers of Hetzner Online GmbH, the document files with Amazon Web Services in the Frankfurt am Main region. In the "Standard" mode, sub-processors in the USA (see letter d) process documents, booking details and imported bank transactions in order to read documents, propose bookings, match bank transactions to documents and detect duplicates; they keep the transmitted data only for a limited time, as described in the privacy policy. The transfer is based on the EU standard contractual clauses, for Google on the EU-US Data Privacy Framework, otherwise also on the EU standard contractual clauses. In the "Without AI" mode, it does not take place. Regardless of the mode, Resend in the USA sends the service's e-mails, including invitations to addresses specified by the customer, confirmation codes to the sender addresses of the e-mail document intake stored by the customer, each with the name of the organisation, and the invoices the customer sends from Saldek to the recipients they specify, with the invoice as a PDF attachment and the organisation's e-mail address as the reply-to address (see list); this transfer is also based on the EU standard contractual clauses. Where the e-mail document intake is set up, Mailgun Technologies, Inc. (USA) receives the e-mails to the organisation's intake address in its EU region; this transfer is based on the EU-US Data Privacy Framework, otherwise on the EU standard contractual clauses. The purposes also include "Ask Saldek" (the question, the earlier questions of the conversation and matching extracts from documents and entries go to the AI services to produce an answer with sources) and voice notes and voice input (converting the recording to text); details in Annex II.
b) Confidentiality (Art. 28(3)(b)): All persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
c) Technical and organisational measures (Art. 32 / Art. 28(3)(c)): Tenant separation at database level (row-level security), cryptographic checksums (SHA-256), WORM archiving of posted documents (locked for 7 years, 8 years for organisations in Germany), transport encryption (TLS) and password hashing with Argon2id.
d) Sub-processors (Art. 28(3)(d) and (4)): The controller gives its general authorisation for the sub-processors in the publicly available list (Annex IV). The processor informs the controller of the addition or replacement of a sub-processor at least 14 days in advance; it imposes the same data protection obligations on it and is liable for it (Clause 7.7).
e) Data subject rights and erasure (Art. 28(3)(e) and (g)): Support in fulfilling data subject rights (access, rectification, erasure). After the end of the contractual relationship, all data is handed over in full (export) or deleted on request. For this, the controller chooses in the organisation's settings: when closing, the data remains stored read-only and exportable and is deleted automatically after the end of the retention period under § 132 BAO (for Austrian organisations; otherwise when the controller deletes the organisation). With immediate deletion, the data is deleted immediately on the controller's express instruction; the statutory retention obligations (in particular § 132 BAO and § 212 of the Austrian Business Code, UGB, or § 147 AO and § 257 HGB in Germany) are then fulfilled by the controller, for example with the export created beforehand. Files in the archive under a retention lock (Object Lock) cannot be deleted by anyone before the lock ends; until then they remain stored inaccessibly and are deleted automatically afterwards. Deleted data remains in the encrypted backups until they expire after 30 days.
f) Notification of breaches (Art. 28(3)(f), Art. 33 GDPR): The processor notifies the controller of a personal data breach without undue delay and at the latest within 48 hours of becoming aware of it, and assists it under Clause 9.
g) Unlawful instructions and audits (Art. 28(3)(h) GDPR): If the processor considers an instruction unlawful, it informs the controller without delay. It makes available the information needed to demonstrate compliance and allows for audits under Clause 7.6.
3. Standard contractual clauses, sub-processors and conclusion
In addition to this page, the European Commission's standard contractual clauses under Implementing Decision (EU) 2021/915 with Annexes I–IV (section 4 and the annexes below) apply and form part of this agreement; in case of conflict the clauses prevail. The processor informs the controller of the addition or replacement of a sub-processor at least 14 days in advance; if the controller objects for good cause and no solution is found, it may terminate the contract as of the date of the change; fees already paid for the period after that are refunded pro rata.
The AVV is part of the terms (clause 9) and is concluded on registration. You can get a signed copy on request at contact@fluxonlab.com (subject: Auftragsverarbeitung (AVV)).
4. Standard contractual clauses (Implementing Decision (EU) 2021/915)
Official English version, unchanged (OJ L 199, 7.6.2021, p. 18; EUR-Lex); the German version is binding. Chosen are Option 1 (Regulation (EU) 2016/679) in Clause 1(a) and in Clauses 8 and 9, and Option 2 (general written authorisation) in Clause 7.7 with a period of 14 days. Annexes I–IV follow below.
SECTION I
Clause 1
Purpose and scope
Clause 2
Invariability of the Clauses
Clause 3
Interpretation
Clause 4
Hierarchy
Clause 5 - Optional
Docking clause
SECTION II
OBLIGATIONS OF THE PARTIES
Clause 6
Description of processing(s)
Clause7
Obligations of the Parties
7.1. Instructions
7.2. Purpose limitation
7.3. Duration of the processing of personal data
7.4. Security of processing
7.5. Sensitive data
7.6. Documentation and compliance
7.7. Use of sub-processors
7.8. International transfers
Clause 8
Assistance to the controller
Clause 9
Notification of personal data breach
9.1 Data breach concerning data processed by the controller
9.2 Data breach concerning data processed by the processor
SECTION III
FINAL PROVISIONS
Clause 10
Non-compliance with the Clauses and termination
Annex I – List of parties
Controller: the customer, with the name, address and contact details given at registration and in the organisation's profile. Signature and date: acceptance at registration (electronic); a signed copy on request.
Processor: FluxonLab (sole proprietorship, owner Çağrı Bozgeyik), Arndtstraße 68, Tür 3, 1120 Wien, Austria; data protection contact: contact@fluxonlab.com. No data protection officer has been appointed.
Annex II – Description of the processing
Categories of data subjects: employees, officers, customers, suppliers and other business partners of the controller and the users of its organisation.
Categories of personal data: invoice and document data (names, addresses, VAT IDs, bank details/IBAN, amounts, line items), booking details, imported bank transactions, master data of business partners including their e-mail addresses, questions and answers in "Ask Saldek", text created from voice recordings, user data of the organisation (name, e-mail address, role).
Sensitive data: processing of special categories is not intended. Where a document exceptionally contains such data (for example a pharmacy invoice), the same measures under Annex III apply.
Nature of the processing: storing, reading, structuring, matching, transmitting to the sub-processors in Annex IV, archiving, exporting, deleting.
Purposes: reading documents, booking proposals, bank reconciliation, duplicate checks, answers in "Ask Saldek" (questions and matching extracts sent to AI services), converting voice notes and voice input to text, creating and sending invoices, importing from connected mailboxes and storage, document intake by e-mail via the organisation's intake address, exports (DATEV, BMD), tamper-proof archiving of posted documents – in each case to provide Saldek under the terms.
Duration: the term of the contract; then until deletion under clause 2 e, including the lock periods of posted documents (7 years, 8 years for organisations in Germany).
Sub-processors: subject matter, nature and duration as above, limited to the purpose stated for each in Annex IV.
Annex III – Technical and organisational measures
- Tenant separation at database level (row-level security with forced policies; the application uses a role without bypass rights).
- Encryption in transit (TLS) and of backups; document files in the archive in the Frankfurt am Main region.
- Immutability of posted documents: WORM storage (Object Lock in compliance mode) with SHA-256 checksums; journals append-only.
- Access control: passwords hashed with Argon2id, roles and permissions per organisation, scoped keys, a second factor (TOTP) for platform administrators.
- Logging: a change log per organisation; sign-in and security logs are deleted after 90 days.
- Data minimisation towards AI services: IBANs, e-mail addresses and phone numbers in booking details, bank transactions and the extracts for "Ask Saldek" are masked before transmission; the "Without AI" mode transmits nothing; customer data is not used to train models.
- Availability: encrypted backups, kept for 30 days.
- Personal data breaches: notification to the controller without undue delay and at the latest within 48 hours of becoming aware, with the information under Clause 9.2; further information as it becomes available.
- Assistance with data subject rights: export, rectification and erasure in the application; requests to contact@fluxonlab.com.
Annex IV – List of sub-processors
The controller authorises the following sub-processors. Purpose, location, transfer basis and contract are listed in the sub-processor list as amended from time to time; changes are announced at least 14 days in advance under Clause 7.7.
- Hetzner Online GmbH — Germany
- Amazon Web Services EMEA SARL, Luxembourg — Germany (AWS region Frankfurt am Main) for the document files; the backups in an AWS region in the EU
- TypeSafe AI, Inc., San Francisco (model “Jev”) — USA
- OpenAI Ireland Ltd, Dublin (model “gpt-6-luna”) — USA (processing by affiliates of OpenAI)
- Google Cloud EMEA Limited, Dublin (model “gemini-3.5-flash-lite”) — USA and other countries in which Google operates data centres
- Microsoft Ireland Operations Limited, Dublin (Azure Speech, model “MAI-Transcribe-2”) — Ireland (Azure region North Europe)
- OpenAI Ireland Ltd, Dublin (model “gpt-transcribe”) — USA (processing by affiliates of OpenAI)
- Stripe Payments Europe, Ltd. — Ireland (EU); disclosure to Stripe, Inc. (USA) possible
- Functional Software, Inc. (Sentry), San Francisco — Germany (Sentry’s EU data region, Frankfurt am Main); administrative data and access by Sentry also in the USA
- Plus Five Five, Inc., San Francisco (Resend) — USA (according to Resend, all data is stored in the USA, including message contents and attachments, metadata, logs and account data; the Ireland region only determines the sending route)
- Mailgun Technologies, Inc. (Mailgun EU) — Mailgun’s EU region (data centres in Germany and Belgium); access for support and operations also from the USA
- Google LLC, Mountain View (Google account: Google Drive and Gmail mailbox) — USA and other countries in which Google operates data centres