Last updated: July 30, 2026 (version 1.0)
This Data Processing Agreement ("DPA") is part of the Terms of Service ("Terms") between the customer ("Controller") and Walletguide GmbH ("SaaSFlow", "Processor") and governs the processing of personal data on behalf of the customer when using the SaaSFlow services. It takes effect when the contract for the use of the services is concluded, without requiring a separate signature (Art. 28(9) GDPR, electronic form). This English version is a convenience translation; the German version (Auftragsverarbeitungsvertrag) is the legally binding one. If you need a countersigned copy, contact [email protected].
§ 1 Subject matter and duration
(1) SaaSFlow provides services to the customer for analyzing and planning financial and subscription data (the "Services") in accordance with the Terms. In doing so, SaaSFlow processes personal data on behalf of the customer within the meaning of Art. 28 GDPR.
(2) The subject matter, nature and purpose of the processing, the types of personal data and the categories of data subjects are described in Annex 1.
(3) The duration of this DPA corresponds to the term of the service contract. Termination rights follow the Terms. In the event of a serious breach of this DPA by SaaSFlow, the customer may terminate the service contract for cause.
§ 2 Responsibility and right to issue instructions
(1) The customer is the controller within the meaning of the GDPR. The customer is responsible for the lawfulness of the processing and for safeguarding the rights of data subjects.
(2) SaaSFlow processes personal data only on documented instructions from the customer, including with regard to transfers to a third country, unless SaaSFlow is required to process by Union or Member State law. In that case, SaaSFlow informs the customer before processing, unless that law prohibits such notification.
(3) The customer's instructions initially follow from the Terms, this DPA and the use of the features of the Services (for example, connecting a data source or approving an AI provider in the product settings). The customer issues supplementary individual instructions in text form to [email protected].
(4) If SaaSFlow considers an instruction to infringe data protection law, SaaSFlow informs the customer without undue delay and may suspend execution until the instruction is confirmed or changed.
§ 3 Obligations of SaaSFlow
(1) SaaSFlow organizes its internal operations to meet the requirements of data protection and implements the technical and organizational measures pursuant to Art. 32 GDPR described in Annex 2. SaaSFlow may replace individual measures with equivalent or better ones; the level of protection of Annex 2 must not be undercut.
(2) SaaSFlow commits all persons who process the customer's personal data to confidentiality, unless they are already subject to an appropriate statutory obligation of secrecy. This confidentiality obligation survives the end of the respective engagement and of this DPA.
(3) SaaSFlow notifies the customer without undue delay after becoming aware of a personal data breach affecting the customer's personal data. To the extent already known, the notification contains at least the information pursuant to Art. 33(3) GDPR (nature of the breach, categories and approximate number of data subjects and records concerned, likely consequences, measures taken and proposed). SaaSFlow supports the customer with the customer's notification obligations under Art. 33 and 34 GDPR.
(4) Upon request, SaaSFlow names a contact person for data protection questions in connection with this DPA, reachable via [email protected].
(5) SaaSFlow regularly reviews the effectiveness of the technical and organizational measures (Art. 32(1)(d) GDPR).
(6) Where the customer corrects, restricts or deletes data within the Services directly, this counts as an instruction. Where the customer cannot perform a correction or deletion directly, SaaSFlow carries it out on the customer's instruction.
§ 4 Confidentiality of customer data
(1) SaaSFlow treats all data and information that the customer brings into the Services, or that SaaSFlow obtains about the customer's business while providing the Services, as confidential. This applies regardless of whether the data contains personal data and covers in particular the customer's financial, revenue, subscription, account and planning data as trade secrets within the meaning of Sec. 2 of the German Trade Secrets Act (GeschGehG).
(2) The scope, exceptions and survival of this confidentiality obligation follow section 9 (Confidentiality) of the Terms. The obligations under this § 4 survive the termination of this DPA.
§ 5 Sub-processors
(1) The customer grants SaaSFlow general authorization to engage sub-processors for the processing. The sub-processors approved at the time of contract conclusion are listed in Annex 3.
(2) SaaSFlow informs the customer's account owners by email at least 14 days before a new sub-processor processes the customer's personal data or an existing one is replaced, and updates the public sub-processor list.
(3) The customer may object to a change within 14 days of receiving the information, on important data protection grounds. If the customer does not object, the change is deemed approved. In the event of an objection, the parties seek an amicable solution (for example, not using the affected feature). If no solution is found, either party may terminate the service contract with 30 days' notice.
(4) SaaSFlow imposes on every sub-processor, by contract, the same data protection obligations as set out in this DPA, in particular sufficient guarantees of technical and organizational measures pursuant to Art. 32 GDPR. Where a sub-processor fails to fulfill its obligations, SaaSFlow remains liable to the customer for the performance of that sub-processor's obligations.
(5) Ancillary services without substantive access to customer data, such as telecommunications, postal, cleaning or security services, are not sub-processing within the meaning of this § 5.
§ 6 Transfers to third countries
(1) Processing in third countries outside the EU and the EEA only takes place if the requirements of Art. 44 et seq. GDPR are met.
(2) For sub-processors in the United States, SaaSFlow bases the transfer on a certification under the EU-US Data Privacy Framework, where available, and additionally concludes the EU Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914, Module 3 for sub-processing relationships), so that a valid transfer mechanism remains in place should the Data Privacy Framework cease to apply. The safeguard applicable to each provider is stated in the sub-processor list.
§ 7 Assistance to the customer
(1) SaaSFlow assists the customer with appropriate technical and organizational measures in responding to requests from data subjects under Chapter III of the GDPR (including access, rectification, erasure, data portability). If a data subject contacts SaaSFlow directly, SaaSFlow forwards the request to the customer without undue delay.
(2) Taking into account the nature of the processing and the information available to SaaSFlow, SaaSFlow assists the customer in complying with the obligations under Art. 32 to 36 GDPR (security of processing, breach notifications, data protection impact assessments, prior consultation).
(3) Assistance under this § 7 is free of charge to the extent it can be provided within the Services with reasonable effort. For effort beyond that, initiated by the customer, SaaSFlow may charge a reasonable fee; this does not apply where the effort results from a breach of obligations by SaaSFlow.
§ 8 Evidence and audit rights
(1) SaaSFlow demonstrates compliance with the obligations under this DPA by appropriate means, in particular current attestations or certificates of the infrastructure providers used (for example, ISO 27001, SOC 2 of the data centers), self-assessments and the documentation of the technical and organizational measures.
(2) Where the evidence under paragraph 1 is insufficient in an individual case, the customer may, with reasonable prior notice (as a rule 30 days) and at most once per calendar year, conduct an audit during regular business hours, or have it conducted by an expert third party bound to confidentiality who is not a competitor of SaaSFlow. Audits prompted by a concrete data protection incident remain unaffected. Each party bears its own costs.
§ 9 Deletion and return
(1) After the end of the service contract, SaaSFlow deletes all personal data of the customer or, at the customer's choice, returns it (export in a common machine-readable format), unless Union or Member State law requires further storage.
(2) Deletion from the production systems takes place no later than 90 days after the end of the contract. Copies in backup systems are overwritten as part of the regular backup rotation; until then they remain subject to the protections of this DPA and are not restored, except where necessary to restore the overall system.
(3) Upon request, SaaSFlow confirms the deletion in text form.
§ 10 Liability
Liability in connection with the processing of personal data is governed by Art. 82 GDPR. In all other respects, the liability provisions of the Terms also apply to claims in connection with this DPA.
§ 11 Final provisions
(1) In the event of contradictions between this DPA and the Terms, this DPA prevails in data protection matters.
(2) Amendments and additions to this DPA require text form. SaaSFlow informs the customer of changes to this DPA in text form; otherwise, the change mechanism of the Terms applies.
(3) The law of the Federal Republic of Germany applies.
(4) This DPA is available in German and English. The German version is legally binding; the English version is a non-binding convenience translation.
(5) Should individual provisions of this DPA be invalid, the validity of the remaining provisions remains unaffected.
Annex 1: Subject matter of the processing
Subject matter and purpose: Provision of the SaaSFlow Services for analyzing, evaluating and planning the customer's financial, revenue and subscription data, including connecting data sources (for example, payment and billing providers, bank accounts, CRM and accounting systems), computing metrics and reports, and optional AI-assisted analyses that the customer must expressly approve per provider.
Nature of the processing: Collection via connected interfaces and imports, storage, structuring, analysis, display, transmission to approved sub-processors, deletion.
Types of personal data:
- Master data of the customer's users (name, email address, role)
- The customer's customer data from connected systems (names, company names, contact details, subscription and revenue data, invoice data)
- Bank and transaction data of connected accounts (account transactions, counterparties with names and account identifiers, payment references, balances)
- Planning, comment and note content, to the extent the customer stores personal data there
- Communication and support data in connection with the use of the Services
Categories of data subjects:
- The customer's users (employees and other persons authorized by the customer)
- The customer's customers and prospects
- Business partners, suppliers and their contact persons, to the extent contained in transaction or CRM data
- The customer's employees, to the extent visible in transaction data (for example, salary payments)
Annex 2: Technical and organizational measures (Art. 32 GDPR)
Encryption and pseudonymization: Transmission of all data exclusively over encrypted connections (TLS). Encryption of data at rest on the cloud infrastructure used. Key management by the certified infrastructure providers. Data minimization for optional AI analyses: only the data categories required for the respective feature are transmitted, and they are named to the customer before approval.
Confidentiality (physical access, system access, data access and separation control):
- Physical security of the data centers through the infrastructure providers (Google Cloud, EU region) with relevant certifications (including ISO 27001, SOC 2)
- Individual user accounts, no shared credentials; multi-factor authentication for administrative access to production systems and cloud consoles
- Role-based access rights on a need-to-know basis; administrative access to production data is restricted to a small number of named persons and is logged
- Logical tenant separation: all customer data is consistently assigned to one customer organization and filtered by it at every access layer
- Separate environments for development, staging and production; no production customer data in test and development environments, technically supported by automated checks for personal data in the source code
Integrity (transfer and input control):
- Changes to the systems exclusively via versioned source control with a review process and automated checks; traceable, automated deployments
- Logging of security-relevant events and system access at the infrastructure level
- Data exports only by authenticated and authorized users of the customer
Availability and resilience:
- Operation on redundant cloud infrastructure in the EU; automated, regular database backups with a documented restore procedure
- Monitoring and alerting for availability and error conditions; protection against overload and network attacks through upstream security and CDN services
- Defined process for security incidents, including customer notification under § 3(3)
Procedures for regular review, assessment and evaluation:
- Regular review of the technical and organizational measures and of access permissions
- Privacy by design and by default, in particular express approval per AI provider before any data is transmitted to it, revocable at any time in the product
- Sub-processor control: data processing agreements are in place with all sub-processors; new sub-processors undergo a data protection review before use
Annex 3: Approved sub-processors
The sub-processors approved as of the publication of this DPA version (July 30, 2026) are:
- Google Cloud Platform (infrastructure and hosting, EU)
- PlanetScale (database hosting, US; data held in the EU)
- Cloudflare (CDN and security services, US)
- Vercel (website and admin hosting, US)
- finAPI GmbH (bank connectivity Europe, Germany)
- Plaid (bank connectivity outside Europe, US)
- Stripe (payment processing, US/Ireland)
- Postmark / ActiveCampaign (transactional email delivery, US)
- Intercom (customer support and chat, US)
- Sentry (error monitoring, US; only after user consent in the product)
- Anthropic (AI analyses, US; only after express approval by the customer)
- Cursor / xAI (AI analyses, US; only after express approval by the customer)
- Google Workspace (internal email and collaboration, EU)
- Slack (internal communication, US)
Details on purpose, data categories, location and transfer safeguards per provider are maintained in the continuously updated sub-processor list. Changes follow the procedure in § 5.