Accord de traitement des données avec Stripe
Un relevé de l'accord de traitement des données régissant le prestataire de paiement d'alpflo. Stripe traite les données de paiement de la clientèle pour le compte d'alpflo, ce qui en fait un sous-traitant. alpflo ne rédige pas cet accord lui-même ; il est publié par Stripe.
Dernière mise à jour 2026-08-02
Ce document est l'accord de traitement des données de Stripe et n'est disponible qu'en anglais ; alpflo ne le traduit pas.
1 · Why it applies
Because alpflo is the merchant of record and Stripe processes customers' payment data on alpflo's behalf, Stripe is a processor under the revFADP and the GDPR. A Data Processing Agreement governs that relationship. It is the arrangement the published privacy notice refers to when it states that each processor acts on alpflo's instructions under such an agreement.
2 · Status — in force
On file and in force. Stripe's Data Processing Agreement is not a separate signature: it states that it “is subject to and forms part of the Agreement”, so it is incorporated automatically into the Stripe Services Agreement alpflo accepted when the account was opened. There is no separate acceptance step in the Stripe Dashboard, and none is required.
- Processor: Stripe Payments Europe, Limited — the contracting entity for accounts outside the Americas, Switzerland included. This matches the name published in the privacy notice.
- Controller: alpflo.
- Version: the agreement published at stripe.com/legal/dpa, last updated 18 November 2025.
- Cross-border transfers: covered by the agreement's Data Transfers Addendum, which incorporates the standard contractual clauses and names Switzerland alongside the EEA and the UK.
3 · Stripe's own sub-processors
Stripe publishes the third parties it uses at stripe.com/legal/service-providers. Several are established in the United States, which is part of why the privacy notice names Stripe as a cross-border flow. The agreement gives alpflo email notification of changes to that list and 30 days to object in writing to a newly added sub-processor.
4 · Out of scope here
The bank-side trust pack — the processor's own DPA, SLA, professional-indemnity cover, and CH-hosting evidence a bank procurement team asks for — is a separate, later piece of work. This note records only Stripe's customer-facing DPA.