Subprocessors & data hosting
Last updated: 29 September 2026
This is a translation provided for convenience. The German version is legally binding; in case of any discrepancy, the German version prevails.
Full transparency on where your data lives and who processes it. Your mandates, beneficial owners and documents are stored in Switzerland. The list below covers every subprocessor that touches data, so your due diligence has nothing to dig for.
Data at rest is in Switzerland. Your database and documents are stored on Swiss infrastructure (Zurich region), governed by the Swiss Federal Act on Data Protection (FADP). The application layer is served via EU hosting infrastructure.
| Subprocessor | Location | Purpose and data processed |
|---|---|---|
| Supabase (database & storage) | Switzerland | Primary data store for mandates, beneficial owners and documents. All application data and encrypted documents – this is where your data lives at rest. |
| Vercel (application hosting) | European Union (Frankfurt) | Serves the web application and server functions. Transient request processing only; no client data is stored at rest on this layer. |
| Anthropic (AI, default) | USA / EU (depending on provider region) | FLIORE AI: assistant and document extraction, when AI features are used. Only the mandate context relevant to the request, or the document submitted for extraction. Not used for training. |
| OpenAI / Azure OpenAI (AI, optional) | USA / EU (depending on provider region) | Only if configured by the organisation or used with its own key (BYOK). Same scope as above; not used for training. |
| Resend (transactional email) | European Union | Sends account and notification emails. Email address and content of those emails only; messages to clients never contain the message text. |
| Stripe (payments) | EU / USA | Processes platform subscription billing. Billing contact and payment data for your FLIORE subscription; no mandate data. |
AI features are optional: organisations can disable them entirely or run them on their own provider key. A Data Processing Agreement is available on the DPA page and is signed on request. SOC 2 and ISO 27001 are on the roadmap.
