Data processing agreement

Version: 2026-08-18

Agreement pursuant to Art. 28 GDPR between you as the controller and the operator of Moneyflowr as the processor.

1. Parties

Controller is the account holder who activates Company mode. Processor is the operator of Moneyflowr named in the legal notice. This agreement takes effect when you accept it while activating Company mode and applies for as long as the company data exists in your account.

It is needed because Company mode lets you store data about your own clients. You decide what is stored about those people, which makes you the controller for that data; we merely hold it for you. Art. 28(3) GDPR requires a contract before such processing begins. Art. 28(9) allows it in electronic form, which is what your acceptance produces.

2. Subject matter and duration

Subject matter is the storage and display of the client and invoice records you create in Company mode. The processing lasts as long as those records exist in your account. Deleting a client, deleting the company data or deleting your account ends it for the data concerned.

3. Nature, purpose, data and data subjects

Purpose and nature: storing, displaying, exporting and deleting the records solely so that the Company mode features you use can work. We do not analyse this data, do not use it for our own purposes and do not pass it to anyone beyond the sub-processor named below.

Types of data: client name, email address, telephone number, postal address and free-text notes; invoice numbers, dates, currencies, amounts and line item descriptions.

Categories of data subjects: your clients and their contact persons.

4. Processing on instructions only

We process this data only on your documented instructions. Your use of the application is the instruction: what you enter, edit, export and delete determines what happens. There is no processing of client data beyond what your actions in the app trigger.

If an instruction appears to us to infringe data protection law, we will tell you and may suspend it until you confirm it, as provided in Art. 28(3) sentence 3 GDPR.

5. Confidentiality

Moneyflowr is operated by a single person, who is bound to confidentiality and is the only one with administrative access. Should anyone else ever be given such access, they will be placed under a confidentiality undertaking beforehand.

6. Security of processing (Art. 32 GDPR)

The following measures are in place. They are described as they actually are, not as a wish list.

  • Transport encryption: the site is served over HTTPS only, with certificates renewed automatically.
  • Access control: passwords are stored as bcrypt hashes. The login session is an AES-encrypted, HttpOnly cookie holding nothing but a session identifier, so a session can be revoked server-side at any time.
  • Separation: every database query is scoped to the owning account. Company records are reachable only through the account that created them, and only while that account holds an active Pro plan.
  • Abuse protection: sign-in and administrative access attempts are rate-limited per IP address.
  • Server hardening: the server accepts SSH key authentication only, with password logins disabled and repeated attempts banned automatically. The application port is not exposed to the internet; it is reachable only through the reverse proxy.
  • Availability: the database is dumped nightly and the last seven dumps are kept, so data can be restored after a technical incident.
  • Location: the server is operated in Nuremberg, Germany. Client data is not transferred outside the EU.

7. Sub-processors

You authorise the following sub-processor. There is no other party that receives your client data.

Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany — operates the server and the database. Processing takes place in Nuremberg, Germany.

The AI assistant is not a sub-processor for your client data. Where it reports on receivables it receives invoice numbers, amounts, due dates and status only; client names and contact details are deliberately excluded from what is sent, so no data identifying your clients leaves the system.

We will inform you before adding or replacing a sub-processor. You may object; if you do and we cannot accommodate it, you may stop using Company mode and have the data deleted.

8. Assistance

Company mode lets you view, correct, export and delete every client and invoice record yourself, which is normally all you need to answer a data subject's request. Where that is not enough, we will assist you as far as we reasonably can.

If we become aware of a personal data breach affecting your client data, we will inform you without undue delay and provide what we know, so that you can meet your own deadline under Art. 33 GDPR.

9. Return and deletion

You can export your data as CSV from the app at any time, and delete individual records, the company data or the entire account yourself. Deletion removes the data from the live database immediately; nightly dumps still containing it are overwritten within seven days. We keep no separate copies beyond that.

10. Verification

On request we will provide the information you need to demonstrate compliance with Art. 28 GDPR, in text form. Where that does not suffice, an inspection can be arranged after reasonable notice, at a time that does not disrupt operations.

11. Your obligations as controller

You decide what client data you enter and are responsible for having a legal basis for it, for informing your clients, and for answering their requests. Please enter only what you actually need; the notes field in particular is free text and is not intended for sensitive information within the meaning of Art. 9 GDPR.

12. Acceptance

Accepting this agreement is a precondition for activating Company mode. The date of your acceptance is recorded with your company data. If this agreement changes materially, we will ask you to accept the new version.

Privacy policy · Impressum