Skip to main content

Data Processing Annex for Processing on Behalf of Customers

Last updated: September 20, 2026

This annex describes the processing Flatzer carries out on behalf of its customers (the businesses that contract the Service) acting as a data processor. It forms part of the Service’s contractual relationship and does not replace the Terms and Conditions or the Privacy Policy, which remain available in full.

1. Identification of the parties

Processor: Flatzer, a trade name operated by an individual based in Spain, with the contact email published on this page.

Controller: the customer contracting the Service (the business owner). Regarding the personal data that its visitors and end customers provide through the assistant —conversations, documents, voice messages, and scoring—, the customer acts as the controller and Flatzer solely as a processor handling that data under the customer’s documented instructions.

Processor contact: [email protected]

2. Purpose and scope of the engagement

The engagement covers the processing necessary to deliver the contracted sales assistant: managing the conversations held through the widget and enabled channels, transcribing voice messages when the assistant supports audio, handling the documents shared in conversations, computing conversation and contact scorings, and managing bookings when the customer enables that feature.

Processing of the customer’s account data —registration, billing and payments, support, and service communications— is outside this engagement: Flatzer carries it out as a controller under its Privacy Policy.

Terms and Conditions · Privacy Policy

3. Controller instructions

Flatzer processes the data according to the customer’s instructions, which are embodied in the Service configuration:

  • Assistant configuration: catalogue, tone, channels, integrations, and features enabled by the customer.
  • Retention: the conversation retention period configured by the business owner —30 days by default, adjustable between 1 and 90 days.
  • Earlier deletion: the business owner’s request to bring forward the deletion of conversations and associated data.
  • Limits of the engagement: Flatzer does not process that data for its own purposes —for example, it does not use it to train models— except where required by law.

4. Categories of data and purposes

On behalf of the customer, and only when the corresponding features are active, Flatzer processes:

  • Conversation data: messages exchanged between the business’s visitors and the assistant, including the data those visitors provide (name, contact details, preferences), to handle their enquiries under the customer’s configuration.
  • Voice data: audio from voice messages, sent to Groq for transcription; Groq stores the data in the US and may apply limited exceptional retention under the applicable configuration. The resulting transcript is handled as conversation data.
  • Documents: files and their content shared in conversations, to prepare answers and quotes under the customer’s instructions.
  • Scoring and bookings: conversation and contact scoring results, and the data provided to manage appointments, solely to deliver those features to the business.

5. Security measures

Flatzer applies technical and organizational measures appropriate to the risk, including:

  • Encryption in transit: communications with the services use HTTPS/TLS.
  • Per-tenant isolation: agent environments run, where applicable, in containers separated per customer.
  • Access controls: access limited to authorized personnel, with administrative records of the processing.

6. Subprocessors

Depending on the enabled features and the applicable configuration, Flatzer uses the following subprocessors for processing on behalf of the customer. The list is kept consultable and up to date on this page:

  • Groq: voice-message transcription through language models when the assistant supports audio. Privacy policy
  • OpenAI: processing messages and requests through language models when configured for the tenant. Privacy policy
  • Anthropic: processing messages and requests through language models when configured for the tenant. Privacy policy
  • xAI: processing messages and requests through language models when configured for the tenant. Privacy policy
  • DeepSeek: processing messages and requests through language models when configured for the tenant. Privacy policy
  • Z.AI: processing messages and requests through language models when configured for the tenant. Privacy policy
  • Hetzner: hosting infrastructure used to provide the Service. Privacy policy
  • Google Calendar: OAuth, availability, and booking data when the calendar integration is enabled. Privacy policy
  • Tavily: processing web-search queries when the assistant uses that feature. Privacy policy
  • Brave: processing web-search queries when the assistant uses that feature. Privacy policy
  • Stripe: payment handling for the customer’s account; Flatzer’s own processing as a controller described in the Privacy Policy. Privacy policy

Except for Stripe, which is involved in account payment handling, subprocessors participate only when the corresponding feature is active.

7. International transfers

Some subprocessors may process data outside the European Economic Area, including the United States. In particular, audio sent to Groq for transcription is stored in the US and may be subject to limited exceptional retention under the applicable configuration; Flatzer does not promise European residency or zero retention for this processor.

Where applicable law requires a transfer mechanism, the relevant mechanism will be used according to the provider and the applicable configuration. The available information can be requested through the contact in this annex.

8. Retention and deletion

Conversations and persisted messages are retained for the retention period configured by the business owner —30 days by default, adjustable between 1 and 90 days— and are automatically and permanently deleted once they exceed that age, unless a legal obligation requires retaining certain data.

The business owner may request the earlier deletion of those conversations and associated data at any time through the processor’s contact. Documents and scorings persisted alongside conversations follow the same retention period.

9. Assistance to the controller

Flatzer assists the customer, to the extent the technical configuration allows, in handling data subject requests (access, rectification, deletion, or objection) relating to the data processed on the customer’s behalf, through the contact in this annex.

10. Audit and changes to this annex

The customer may request reasonable information about the security measures applied and the current version of this subprocessor list through the processor’s contact.

This annex may be updated to reflect the configuration actually contracted; the current version is published on this page with its update date.

11. Contact

For the queries and requests covered by this annex, you can contact us through:

Processor contact: [email protected]

We will handle queries under the requirements and time limits of applicable law.