Laden...
Laden...
This addendum belongs to the privacy policy
Last updated: 2026-10-02
This addendum describes how personal data is processed when an external AI assistant — such as Claude, ChatGPT, Cursor or Visual Studio Code — is connected to a cashwerk organisation. The connection runs over the MCP endpoint or the external REST API.
It supplements the privacy policy and does not replace it. Where both texts cover the same ground, the privacy policy applies; where only this addendum covers something, this addendum applies.
The connection is established by a signed-in person, and ended by that person. cashwerk does not send data to an AI provider on its own initiative: the assistant requests data and cashwerk answers that request. Without a granted authorisation, no access takes place.
Reachable data is the business data of the single organisation the authorisation was granted for — and within that organisation, only what the authorising person can already reach in the application itself. An authorisation never widens a permission. Access to a different organisation is technically excluded.
Depending on permissions and the licensed scope, this covers:
Which individual operations an assistant sees follows from the public OpenAPI specification. That specification is the authoritative, always-current list.
The externally exposed interface contains no operation that moves money. There is no payment initiation, no payout, no bank transfer and no checkout. Payment operations in this interface only record a payment already received outside the application as a bookkeeping entry against an invoice.
Passwords, authentication secrets and other people’s credentials are likewise out of reach.
Authorisation uses OAuth 2.1 with PKCE. Before it is granted, a consent screen names the requesting assistant and the organisation concerned. The resulting credential is bound to exactly one person and exactly one organisation.
A granted authorisation can be revoked at any time in the application, under Settings → API & integrations, in the My connectors section. Revocation is available on every paid licence and is not tied to a higher plan. After revocation the assistant’s access ends immediately; any further access requires a new authorisation.
Everyone sees and revokes their own authorisations there. Anyone permitted to manage the organisation’s connectors additionally sees every authorisation in the organisation, together with the person who granted it, and can end it — so access can be ended even after that person has left the company.
Every call over the external interface is logged. What is recorded is only that a call happened — not what it contained:
Not logged: request bodies, search terms and other query values, path values, response contents, and anything entered into or returned by an AI assistant. The purpose of logging is security and abuse detection, enforcement of usage limits, billing and support. Log entries are deleted automatically after 13 months.
cashwerk receives no prompts, no conversation history and no model output, stores no such data and uses none of it for training. What reaches cashwerk is only the data request that an assistant’s operation triggers.
The application and the database are operated in the European Union (Google Cloud, Netherlands).
The MCP endpoint, which forwards an assistant’s requests to the application, is operated in Switzerland (Google Cloud, Zurich). Switzerland is recognised by the European Commission as providing an adequate level of data protection. The endpoint forwards requests and does not retain their contents.
Once data has been handed to the connected assistant, its further processing is governed by the terms and privacy notice of that AI provider. The provider is chosen by the authorising person and is not engaged by cashwerk. Before authorising an assistant, read that provider’s privacy notice — in particular on whether submitted content is used to train models.
Questions about this addendum: datenschutz@cashwerk.io. Technical questions about a connection: support@cashwerk.io.