Privacy Policy
Last updated: 18 July 2026
This Privacy Policy explains how Flusso, operated by [Flusso legal entity name] ("Flusso", "we", "us"), handles personal data in connection with our cash-flow reconciliation service at flusso.finance. Flusso is a multi-tenant service: each company is a separate tenant, and all data is scoped to the company that owns it.
1.Our two roles: controller and processor
Our data-protection role depends on the data in question:
- Processor. For the financial and operational data a company uploads or connects to Flusso — invoices, bank transactions, counterparties, and related records — the customer company is the controller and Flusso acts as a processor, handling that data only on the company's documented instructions. These terms are set out in our Data Processing Agreement.
- Controller. For the personal data of our own account holders — names, email addresses, login credentials, role, and billing details — Flusso is the controller. This policy governs that relationship.
2.Data we process
Depending on how a company uses Flusso, we process the following categories of data:
- Company & identity. Legal entities and VAT numbers, company names and addresses; user accounts (name, email, hashed credentials, role); team invitations (email address); and hashed API keys.
- Financial documents. Italian SDI e-invoices (FatturaPA) — supplier and customer names, VAT numbers, addresses, line items, amounts, VAT, payment terms, creditor IBAN/BIC, notes, and embedded attachments — together with derived classification, analytics and accounting-journal entries, VAT liquidation figures, and collections/dunning state including debtor contact emails.
- Banking. Transactions and balances from a connected bank aggregator, bank connection credentials and tokens, SEPA payment initiations, and maker-checker approvals.
- Anti-fraud. Fingerprints of supplier bank details (IBAN) used to detect changes and possible fraud.
- Product & billing. AI copilot usage and credits, billing events, an audit log, web-push subscriptions, and OAuth tokens for accounting connectors.
We do not intentionally collect special-category data. Payment card numbers are never stored on our servers — checkout is hosted by Stripe.
3.How we use data and our legal bases
- To provide the service— parsing invoices, reconciling bank data, forecasting liquidity, and preparing payments. Basis: performance of a contract, or our processing on the controller's instructions.
- Security and fraud prevention — audit logging, maker-checker approvals, and supplier bank-detail fingerprints. Basis: legitimate interests.
- Billing and administration — subscriptions and AI credits via Stripe. Basis: performance of a contract and legal obligation.
- AI copilot — when a user asks the assistant a question, we send a per-request financial summary plus the question to our AI subprocessor to generate an answer. This content is not used to train models. Basis: performance of a contract / legitimate interests.
4.Sharing and subprocessors
We share data with vetted subprocessors that help us run the service — hosting, authentication, bank aggregation, e-invoicing, accounting connectors, email, and AI. Optional subprocessors are engaged only when a company enables the relevant integration. The current list, with the purpose and data involved for each, is on our Subprocessors page. We do not sell personal data and do not use third-party advertising or tracking.
5.International transfers
We host and store data in the EU/EEA where feasible through our providers' regions [confirm regions]. Where a subprocessor processes data outside the EEA, we rely on an appropriate transfer mechanism such as the EU Standard Contractual Clauses.
6.Retention and deletion
Data is retained for the life of the account. On an erasure request or account closure, deletion is a soft-delete with a 30-day grace period: access is disabled immediately and the request can be cancelled within the window, after which all tenant data is permanently purged across our datastores. Backups expire on their normal cycle (approximately 30 days) after the purge.
- Deletion can be initiated by the company owner (self-service) or by Flusso staff on request; individual users can delete their own account.
- Because Italian law requires businesses to keep invoices for around ten years, the customer company (as controller) is responsible for its own statutory retention. Flusso deletes on the controller's instruction.
- Bank and accounting connections are revoked on deletion so no further data is pulled.
7.Your rights
Subject to applicable law, you have the right to access, rectification, erasure, restriction, portability, and objection in respect of your personal data. Where Flusso acts as a processor, requests relating to company data are directed to the customer company as controller, and we will assist them in responding.
To exercise a right, contact us at admin@flusso.finance or use the relevant in-app controls. You also have the right to lodge a complaint with a supervisory authority (in Italy, the Garante per la protezione dei dati personali).
8.Security
We use TLS for data in transit, encryption at rest via MongoDB Atlas, strict tenant isolation (all access is scoped by tenant id), role-based access with maker-checker on payments, audit logging, and least-privilege staff access via an allow-list. Further detail is in our Data Processing Agreement.
9.Cookies and local storage
Flusso uses only essential cookies and local storage. See our Cookie & Storage Notice for details.
10.Changes and contact
We may update this policy from time to time; the "Last updated" date above reflects the latest version. For any privacy question, or to reach our data protection contact, email admin@flusso.finance or write to [DPO / privacy contact], [Flusso legal entity name], [Registered address] ([Company registration no. / VAT]).

