Data Processing Agreement (DPA)
Last updated: 29 September 2026
This is a translation provided for convenience. The German version is legally binding; in case of any discrepancy, the German version prevails.
This Data Processing Agreement ("DPA") forms part of the agreement between the customer organisation ("Controller") and Innopulse Consulting GmbH ("FLIORE", "Processor") for use of the FLIORE service. It governs FLIORE's processing of personal data on the Controller's behalf under the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR). Where a signed DPA exists between the parties, that signed version prevails.
1. Roles
The Controller determines the purposes and means of processing the personal data it uploads to FLIORE (its mandates, beneficial owners, documents, transactions and related records). FLIORE processes that personal data solely as Processor, on the Controller's documented instructions, including those set out in this DPA and in the configuration of the service.
2. Scope and instructions
FLIORE processes personal data only to provide and support the service and as further instructed by the Controller in writing. FLIORE informs the Controller if, in its opinion, an instruction infringes applicable data-protection law. FLIORE does not process the data for its own purposes and never sells it.
3. Categories of data and data subjects
Data subjects may include the Controller's clients, their beneficial owners, officers and related persons. Personal data may include identity data (name, date of birth, nationality), status data (PEP flags, risk classifications), documents and their contents, transaction data and correspondence. Sensitive personal data is processed only if the Controller stores it within its documents.
4. Confidentiality
FLIORE ensures that persons authorised to process the personal data are bound by confidentiality and appropriately trained. Access by FLIORE personnel is limited to what is necessary to operate and support the service, and is logged.
5. Security measures
FLIORE implements appropriate technical and organisational measures, in particular: two-factor authentication (available for every account and enforceable for the whole organisation); row-level security enforcing strict separation of organisations at the database layer; encryption of documents at rest and in transit; short-lived signed URLs for document access; encryption of message content; access logging and an audit trail of security-relevant actions; and least-privilege operational access. The measures are reviewed and improved on an ongoing basis.
6. Subprocessors
The Controller authorises FLIORE to engage the subprocessors listed on the Subprocessors page, each bound by data-protection obligations no less protective than this DPA. This includes the AI provider used by FLIORE AI (by default Anthropic; optionally OpenAI or Azure OpenAI), to which the relevant mandate context is transmitted solely to generate a requested answer and which does not use that data for training. The Controller may disable AI or use its own AI key (BYOK). FLIORE gives reasonable notice of intended changes to its subprocessors so that the Controller may object on reasonable data-protection grounds. FLIORE remains responsible for the performance of its subprocessors.
7. International transfers
Personal data is stored in Switzerland (Zurich region). The application hosting infrastructure is operated within the EU. Where a subprocessor processes data outside Switzerland or the EEA, FLIORE relies on a recognised transfer mechanism (adequacy decision, or EU Standard Contractual Clauses with the Swiss addendum) and applies supplementary measures such as encryption in transit.
8. Assistance to the Controller
Taking into account the nature of the processing, FLIORE assists the Controller with responding to data-subject requests (access, correction, deletion, portability, objection), data-protection impact assessments and consultations with supervisory authorities, to the extent the Controller cannot reasonably do so itself using the features of the service.
9. Notification of data-security breaches
FLIORE notifies the Controller without undue delay after becoming aware of a data-security breach affecting the Controller's data and provides the information reasonably available to help the Controller meet its own notification obligations. FLIORE does not notify supervisory authorities or data subjects on the Controller's behalf unless instructed to do so.
10. Return and deletion
On termination of the service, FLIORE deletes or returns the Controller's personal data in accordance with the agreement, subject to any retention the Controller instructs or that FLIORE is legally required to observe. Back-ups are overwritten on their regular cycle.
11. Audits
FLIORE makes available the information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and subject to confidentiality, allows for and contributes to audits – where appropriate also through third-party reports and questionnaires – without disproportionately disrupting the service or compromising other customers' data.
12. Liability and precedence
Liability under this DPA is subject to the limitations in the main agreement. In case of conflict between this DPA and the main agreement regarding data protection, this DPA prevails. This DPA is governed by Swiss law; the place of jurisdiction is Zug.
13. Language
This DPA is concluded in German. Translations into other languages are provided for information only; in case of discrepancies, the German version prevails.
This page presents FLIORE's standard data-processing terms for transparency and is not legal advice. A signed DPA, which may be requested at hello@fliore.com, governs the parties' binding obligations. Organisations should have it reviewed by their own counsel before relying on it.
