Flitz.ai Flitz.ai

Privacy Policy

Last updated: March 2026

1. Data Controller

The data controller responsible for data processing on this website is Flitz.ai, Switzerland. We process your personal data in compliance with the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR).

2. Data We Collect

We collect data you provide directly (name, email, company name during registration), data generated through your use of our services (invoices, journal entries, financial data), and technical data (IP address, browser type, access times) for service operation.

3. How We Use Your Data

We use your data to provide and improve our accounting services, process your invoices and financial data using AI, generate reports and financial statements, and communicate with you about your account and our services.

4. AI Processing

Your invoices, documents, and photos (for features such as invoice scanning, identity verification, and household inventory features) are processed by Anthropic PBC ("Claude AI"), our primary AI subprocessor, to extract data and create bookkeeping entries or other feature-specific results. This processing is essential to those features and always requires your explicit in-app consent before the first use of each feature, naming what data is sent and to whom. Document content is sent to the AI API for processing but is not used to train AI models. The current list of AI subprocessors is published in our subprocessor register and updated when providers change.

5. Data Storage & Security

All data is stored on servers in the EU. We use industry-standard encryption (AES-256) for data at rest and TLS 1.3 for data in transit. Each customer's data is completely isolated at the database level through our multi-tenant architecture.

6. Data Sharing

We do not sell your data. We share data only with: third-party AI providers for invoice processing, payment processors (Stripe) for billing, and as required by Swiss law. The current list of subprocessors is published in our subprocessor register.

7. Your Rights

You have the right to access, correct, or delete your personal data. You may export your data at any time. To exercise these rights, contact us at [email protected].

8. Cookies & Analytics

We do not use tracking or analytics cookies, and we run no third-party analytics service (no Google Analytics or similar) on this website. The only cookies we set are essential ones — required for session management, authentication, CSRF protection and to remember your tenant context. They identify your login session, not you across the web, and are never used for tracking, profiling or advertising. Because they are strictly necessary, no consent banner is required for them. Our visitor statistics are collected entirely server-side, without cookies and without any client-side tracking script. Visitors are counted as salted one-way hashes; raw IP addresses are never stored. These statistics cannot be linked back to an identifiable person, and nothing is shared with third parties. Exception: landing pages that our customers publish through the Marketing module (under /lp/) may load that customer's own Google Ads conversion tag. Those pages — and only those — show a consent banner where you can decline; the customer running the campaign is the data controller for that tag.