Data protection
Part A explains how we handle data. Part B summarises the data processing arrangement, that is, what applies when we process document data on your behalf. Where your data actually goes is shown step by step on our transparency page.
Part A: Privacy policy
This policy follows the Swiss Federal Act on Data Protection (FADP) and the associated ordinance (DPO).
1. Controller
HuusFlow Kotsakidis
Steinackerstrasse 2a
8302 Kloten, Switzerland
Contact for data protection matters: contact@huusflow.ch
2. Which data we process on this website
Server access data: When you visit this website, our server automatically records technical details (IP address, date and time, page requested, browser type). This data serves the security and stability of operations and is not merged with other data sources.
Contact and demo enquiries: If you contact us via the demo form or by e-mail, we process the data you provide (name, e-mail, telephone, company, message) solely in order to answer your enquiry and to prepare a possible contract.
No advertising trackers: This website uses no advertising cookies, no behavioural tracking, no social media pixels and no third-party audience measurement.
No requests to third parties: We deliver fonts and all other resources from our own server. When you visit this website, your IP address is not transmitted to any third-party provider.
3. Hosting
This website and the HuusFlow application run on servers in Switzerland (Infomaniak Network SA, Geneva). The database and the stored documents are held there as well. Outside Switzerland, personal data is processed only for the text recognition step described under section 4.
4. Data processing in the HuusFlow application
For customers who use HuusFlow, we process document data (invoices, receipts, delivery notes) on the customer’s behalf. Transmission is encrypted. The details are governed by the data processing agreement, summarised in Part B.
Where the AI processing takes place: Automatic recognition and categorisation runs via Google Vertex AI. We have fixed the processing to the Netherlands data centre region (europe-west4) and have not left it on the default setting, under which the provider chooses the location itself. For this step your documents leave Switzerland. No processing takes place in the United States. The Netherlands is an EU member state and appears on the Federal Council’s list of states with adequate data protection (Annex 1 DPO), which is why the disclosure is based on Art. 16 para. 1 FADP and no additional safeguards are required. We point out that providers with a parent company in the United States may be subject to the US CLOUD Act regardless of the place of processing.
Processing on Swiss servers on request: On request we will set up your client account on a model that runs entirely on Swiss servers. Text recognition then takes place in Switzerland as well. We do not recommend this as the standard, because our own comparative test with around 3000 documents showed a markedly higher correction rate and a longer processing time. What that means in detail is disclosed with figures on our transparency page.
No further processing: For Vertex AI, Google contractually undertakes that transmitted content is not used to train or improve AI models and is not made accessible to other customers. Your documents serve solely to process your own request.
No automated individual decisions: The system’s suggestions are presented to you for review and are transferred only after your approval. There is no automated individual decision within the meaning of Art. 21 FADP.
5. Disclosure of data
We do not sell data and do not pass it on for advertising purposes. Data is disclosed only to the sub-processors named in Part B, in so far as this is necessary for operations, and where we are legally obliged to do so, in particular towards Swiss authorities in the context of lawful proceedings.
6. Retention and deletion
We retain personal data only for as long as is necessary for the respective purpose or as required by legal obligations. In detail:
Server access data: 90 days, then automatic deletion.
Contact and demo enquiries: 24 months after the last contact, provided no contract is concluded.
Customer document data and bookings: for the duration of the contract. After the contract ends we delete it within 30 days, unless you have requested an export beforehand.
Backup copies: within the ordinary backup cycle, at the latest 90 days after the time of deletion.
Access tokens for connected systems: up to 12 months after the last use.
Logs of support access: for the duration of the contract.
On request we confirm the deletion in text form.
7. Retention obligations and archiving
Business records and accounting documents must be retained for ten years under Art. 958f CO and under the Swiss Ordinance on the Keeping and Preservation of Business Records. This obligation applies to you as a company, not to us.
HuusFlow is not your archive. The processed documents are transferred to your accounting system and retained there. We keep the data available during the term of the contract for ongoing operations, not as an audit-proof long-term archive. Please make sure that your retention is arranged there.
8. Data security
We take the technical and organisational measures required by Art. 8 FADP and Art. 1 et seq. DPO. These include in particular:
Encryption: Transmission exclusively via TLS. Files and database are encrypted at rest with AES-256. Passwords are not stored in plain text, but as non-reversible check values.
Separation of client accounts: The data of each customer is kept separately. The separation is enforced at the level of the data query, not at the level of the user interface.
Access by us: We do not access your content. If handling a support request makes it necessary to view your screen, we obtain your express consent beforehand, as a rule directly during the support conversation. Access remains limited to what is necessary, is logged and ends when the matter is closed.
Data centre: Operation at Infomaniak Network SA in Geneva. According to its own information, the operator is certified to ISO/IEC 27001.
Backup copies: We keep several copies on separate systems and regularly restore the backup as a test.
Development and operations are aligned with the requirements of ISO 27001. Certification is in preparation.
9. Data security breaches
If a breach of data security occurs that is likely to result in a high risk to the data subjects, we report it to the Federal Data Protection and Information Commissioner (FDPIC) as quickly as possible (Art. 24 FADP).
If customer data that we process on a customer’s behalf is affected, we inform the customer without delay, at the latest within 48 hours of becoming aware, with the information available. In that case, notifying the supervisory authority and, where applicable, the data subjects is the customer’s responsibility.
10. Your rights
Under Art. 25 to 29 FADP you have the right to information about the data processed about you, to rectification of incorrect data, to deletion or restriction of processing, to the release or transfer of your data in a common electronic format, as well as the right to object to processing.
To exercise these rights, please contact contact@huusflow.ch. We answer enquiries as a rule within 30 days. We may request additional details in order to verify your identity.
You also have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern.
11. Changes
We may adapt this policy if our processing or the legal situation changes. The version published on this page at the relevant time applies. We additionally inform customers of material changes in text form.
Part B: Data processing at a glance
This part summarises what applies when we process document data on your behalf. The full data processing agreement is authoritative; we send it to you before the contract is concluded and provide it at any time on request.
12. Roles
You are the controller within the meaning of the FADP, HuusFlow is the processor. We process your data exclusively on your documented instructions and never for our own purposes.
If you are a fiduciary, you remain responsible towards your own clients. Article 9 FADP requires you to satisfy yourself that we can guarantee data security, and requires your prior authorisation for engaging sub-processors. That is why we disclose them here by name.
13. Places of processing
Storage, database, files and operations: Switzerland, Geneva.
Text recognition and data extraction: Netherlands, region europe-west4.
United States: no processing.
We show the complete path of a document step by step on our transparency page.
14. Sub-processors
Infomaniak Network SA, Geneva, Switzerland: Operation of the servers, the database and the file storage. Processing in Switzerland. Swiss company without a foreign parent company.
Google (Vertex AI): AI-supported text recognition and data extraction from documents. Processing in the Netherlands. The disclosure is based on Art. 16 para. 1 FADP. Please note: the parent company is domiciled in the United States, and access under the US CLOUD Act cannot be ruled out. Under the contract, customer data is not used for model training.
Your accounting system is not a sub-processor of ours. The transfer to it takes place on your instruction into a system that you operate and are responsible for yourself.
We inform you in text form at least 30 days in advance before a further sub-processor is added or an existing one is changed. You may object for important reasons relating to data protection.
15. Protective measures
The measures described under section 8 apply. On request we provide you with the information you need in order to satisfy yourself, in accordance with Art. 9 para. 2 FADP, that we can guarantee data security.
16. Your rights as a customer
You may request a complete export of your data in a common format at any time.
You may verify compliance with the data processing agreement, as a rule by inspecting documentation, reports and certificates, and in justified cases also on site after prior notice.
We support you with requests for information, rectification, deletion and release from your own customers. If such a request is addressed directly to us, we forward it to you and do not answer it ourselves.
After the contract ends we release your data and subsequently delete it in accordance with section 6.
17. Questions
Do you have questions about where and how your data is processed? Write to us at contact@huusflow.ch. You will get concrete information, not marketing phrases.
Version of 1 August 2026. We update this policy as soon as anything changes in our setup.