Data Processing Agreement
Last updated: 18 July 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the customer company ("Controller") and [Flusso legal entity name] ("Processor", "Flusso") for use of the Flusso service. It governs Flusso's processing of personal data on the Controller's behalf and reflects Article 28 GDPR. Where it conflicts with the Terms & Conditions on data protection, this DPA prevails.
1.Roles
For the financial and operational data the Controller uploads or connects to Flusso, the Controller is the controller and Flusso is the processor. Flusso processes such data only on the Controller's documented instructions, including as set out in this DPA and the service's configuration.
2.Subject matter, duration, nature, and purpose
- Subject matter:processing of personal data contained in the Controller's invoices, bank data, counterparties, and related records.
- Duration: for the term of the agreement and until deletion is completed under Section 8.
- Nature and purpose: parsing SDI e-invoices, reconciling bank transactions, forecasting liquidity, collections, and preparing payments for human approval — to provide the Flusso service.
3.Categories of data and data subjects
Data subjectsinclude the Controller's personnel and account users, and individuals identifiable within business documents (for example contacts at suppliers, customers, and debtors).
Categories of data include: identity and contact details; company and VAT identifiers; invoice content (supplier and customer names, VAT numbers, addresses, line items, amounts, VAT, payment terms, creditor IBAN/BIC, notes, attachments); derived analytics, classification, and accounting-journal data; bank transactions, balances, and payment initiations; collections/dunning state and debtor contact emails; and supplier bank-detail (IBAN) fingerprints. No special-category data is intentionally processed, and no card numbers are stored.
4.Processor obligations
- process personal data only on the Controller's documented instructions, including for international transfers, unless required by law (in which case Flusso will inform the Controller where permitted);
- ensure persons authorised to process the data are bound by confidentiality;
- implement appropriate technical and organisational security measures (Section 6);
- engage sub-processors only under Section 5 and flow down equivalent data-protection obligations;
- taking into account the nature of processing, assist the Controller with data-subject requests and with its obligations on security, breach notification, and data-protection impact assessments;
- notify the Controller without undue delay after becoming aware of a personal data breach; and
- at the Controller's choice, delete or return personal data at the end of the service (Section 8).
5.Sub-processors
The Controller provides general authorisation for Flusso to engage the sub-processors listed on our Subprocessors page, which reflects the current list. Optional sub-processors are engaged only when the Controller enables the relevant integration. We will give notice of intended changes to sub-processors so the Controller has the opportunity to object on reasonable data-protection grounds.
6.Security measures
- TLS encryption for data in transit;
- encryption at rest via MongoDB Atlas;
- tenant isolation — all access is scoped by tenant id so that one company's data is not accessible to another;
- role-based access control and maker-checker approval on payments;
- audit logging of sensitive actions; and
- least-privilege staff access granted through an allow-list.
7.Assistance, audits, and breach notification
Flusso will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable notice, confidentiality, and security constraints. Flusso will assist the Controller in responding to data-subject requests and in meeting breach-notification obligations.
8.Deletion and return
On termination or on the Controller's instruction, deletion follows a soft-delete with a 30-day grace period: access is disabled immediately and the request can be cancelled within the window, after which all tenant data is permanently purged across datastores. Backups expire on their normal cycle (approximately 30 days) after the purge. Bank and accounting connections are revoked on deletion so no further data is pulled. Because Italian law requires businesses to keep invoices for around ten years, the Controller is responsible for its own statutory retention; Flusso deletes on the Controller's instruction.
9.International transfers
Flusso hosts and stores data in the EU/EEA where feasible through its providers' regions [confirm regions]. Where a sub-processor processes data outside the EEA, Flusso relies on an appropriate transfer mechanism such as the EU Standard Contractual Clauses.
10.Contact
For any matter under this DPA, contact [DPO / privacy contact] at admin@flusso.finance.

