{"success":true,"data":{"id":"01a11f24-e047-7607-8d24-2f2250dfc45a","group":"dpa","locale":"en","slug":"dpa","version":"1.5","title":"Data Processing Agreement (DPA)","description":"DPA pursuant to Art. 28 GDPR and Art. 9 FADP","body_markdown":"# Data Processing Agreement (DPA)\n\n\u003e Elchi Studios is a brand of Krauss Software, the sole proprietorship of **Samuel Krauss**, Oberägeri ZG, Switzerland. The counterparty is Krauss Software, owned by Samuel Krauss.\n\n\npursuant to Art. 28 GDPR and Art. 9 FADP (Switzerland)\n\n---\n\n**between**\n\nKrauss Software, owned by Samuel Krauss (brand Elchi Studios)\nIm Ländli 18, 6315 Oberägeri, Switzerland\n(hereinafter **\"Processor\"**)\n\n**and**\n\nthe respective client as per the service agreement\n(hereinafter **\"Controller\"**)\n\n---\n\n## Preamble\n\nThis Data Processing Agreement (DPA) governs the processing of personal data by the Processor on behalf of the Controller pursuant to Art. 28 GDPR and Art. 9 of the Swiss Federal Act on Data Protection (FADP). It forms an integral part of the service agreement concluded between the parties.\n\n---\n\n## Section 1: Subject Matter and Duration\n\n**1.1 Subject Matter:** The Processor provides technical services under the main contract (in particular web development and hosting), in the course of which it may gain access to personal data of the Controller or the Controller's customers.\n\n**1.2 Duration:** Data processing continues for the duration of the main contract. Upon termination, data is handled in accordance with Section 8.\n\n---\n\n## Section 2: Nature and Purpose of Processing\n\nThe processing of personal data includes in particular:\n\n- Access to server data and databases for technical maintenance and development\n- Storage and management of user data in hosted projects\n- Logging of access and errors for diagnostic purposes\n\nProcessing is carried out exclusively for the purpose of fulfilling the main contract.\n\n---\n\n## Section 3: Categories of Personal Data and Data Subjects\n\nProcessing may involve the following categories of personal data:\n\n- Contact and identification data (name, email, address)\n- Technical usage data (IP addresses, log data)\n- Transaction data (depending on project type)\n- Other data categories as defined by the Controller\n\nData subjects may include customers, users and visitors of the Controller's systems and websites.\n\n---\n\n## Section 4: Processor Obligations\n\nThe Processor undertakes to:\n\n**4.1** Process personal data only on documented instructions from the Controller.\n\n**4.2** Ensure that all persons authorised to process personal data are bound to confidentiality or are subject to a statutory obligation of confidentiality.\n\n**4.3** Implement all technical and organisational measures required under Art. 32 GDPR / Art. 8 FADP to ensure appropriate data security, in particular:\n- Encryption of stored and transmitted data\n- Access controls and authentication measures\n- Regular security updates and backups\n\n**4.4** Comply with the conditions of this DPA when engaging sub-processors (see Section 5).\n\n**4.5** Assist the Controller, taking into account the nature of the processing, in fulfilling its obligations (data subject rights, notification obligations, data protection impact assessments).\n\n**4.6** Notify the Controller of any personal data breach without undue delay (within 24 hours of becoming aware of it at the latest).\n\n---\n\n## Section 5: Sub-processors\n\n**5.1** Since 3 October 2026 the Processor operates the hosted projects on its own servers and engages the following sub-processors for this:\n\n| Sub-processor | Service | Country (location) |\n|---|---|---|\n| Infomaniak Network SA | Servers, object storage for pictures | Switzerland (Geneva) |\n| Hetzner Online GmbH | Servers, copy of the database | Germany (Falkenstein, Nuremberg) |\n| Tavuru | Server of the primary database | Germany (Frankfurt) |\n| UpCloud Oy | Servers | Netherlands (Amsterdam) |\n| Scaleway SAS | Servers, copy of the database, nightly copy of the pictures | Netherlands (Amsterdam), France (Paris) |\n| ClouDNS Ltd. | Answers the DNS queries for the servers' names; sees DNS queries only, no project content and no account data | Bulgaria (Sofia) |\n| Resend, Inc. | Sending email, where a project sends email through the Processor (e.g. notifications from contact forms); sent from Resend's EU region, stored in the USA | USA |\n\nCloudflare, Inc. (USA) holds the DNS zones, receives no personal data from the projects and so is not a sub-processor.\n\n**5.2** For disclosure abroad: Germany, the Netherlands, France and Bulgaria belong to the EEA and, under Annex 1 of the Swiss Data Protection Ordinance (DPO), ensure an adequate level of data protection (Art. 16 para. 1 FADP). For disclosure to Resend in the USA, data from Switzerland is covered by the European Commission's Standard Contractual Clauses with the adaptations required by Swiss law, which form part of Resend's data processing agreement (Art. 16 para. 2 let. d FADP); for data subject to the GDPR, Resend is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR), and the same Standard Contractual Clauses apply in addition (Art. 46(2)(c) GDPR).\n\n**5.3** Where a project is hosted with another provider at the Controller's request, the main contract names that provider. Where that provider is outside Switzerland and the EEA, the Processor ensures an adequate level of protection (e.g. through EU Standard Contractual Clauses).\n\n**5.4** The Controller approves the sub-processors named in clause 5.1 and grants general authorisation for the engagement of further sub-processors in the area of hosting and server infrastructure, provided these are bound to equivalent data protection obligations.\n\n**5.5** The Processor ensures that sub-processors are subject to the same data protection obligations as the Processor itself.\n\n**5.6** Changes or additions to sub-processors will be communicated to the Controller in advance (at least 14 days' notice). The Controller may object in writing within this period.\n\n---\n\n## Section 6: Data Subject Rights\n\nThe Processor shall assist the Controller in responding to data subject requests (access, rectification, erasure, restriction, portability, objection). Where possible, the Processor shall provide technical means or take appropriate measures to support this.\n\n---\n\n## Section 7: Controller Audit Rights\n\n**7.1** The Controller has the right to verify compliance with this DPA and data protection requirements at the Processor's premises.\n\n**7.2** The Processor shall make all necessary information available to the Controller and permit audits or inspections (with reasonable advance notice of at least 14 days).\n\n---\n\n## Section 8: Return and Deletion of Data\n\n**8.1** Upon termination of the main contract, personal data shall be returned or deleted at the Controller's request, unless statutory retention obligations apply.\n\n**8.2** The Processor shall confirm deletion in writing upon request.\n\n---\n\n## Section 9: Liability\n\nThe liability of the parties is governed by the provisions of the main contract and applicable statutory provisions.\n\n---\n\n## Section 10: Governing Law\n\nSwiss law applies. The place of jurisdiction is Zug, Switzerland.\n\n---\n\n*This DPA is agreed as an integral part upon conclusion of the main service agreement.*\nVersion 1.5, in effect from 9 October 2026: the table in section 5.1 names the copies of the database at Hetzner (Nuremberg) and Scaleway (Paris), which already existed. In effect without notice, since on that day no controller outside Elchi Studios was affected.\n\n*Version 1.5 | 9 October 2026*\n\n","body_html":"\u003ch1 id=\"data-processing-agreement-dpa\"\u003eData Processing Agreement (DPA)\u003c/h1\u003e\n\u003cblockquote\u003e\n\u003cp\u003eElchi Studios is a brand of Krauss Software, the sole proprietorship of \u003cstrong\u003eSamuel Krauss\u003c/strong\u003e, Oberägeri ZG, Switzerland. The counterparty is Krauss Software, owned by Samuel Krauss.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003epursuant to Art. 28 GDPR and Art. 9 FADP (Switzerland)\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003cstrong\u003ebetween\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eKrauss Software, owned by Samuel Krauss (brand Elchi Studios)\u003cbr /\u003e\nIm Ländli 18, 6315 Oberägeri, Switzerland\u003cbr /\u003e\n(hereinafter \u003cstrong\u003e\u0026quot;Processor\u0026quot;\u003c/strong\u003e)\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eand\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003ethe respective client as per the service agreement\u003cbr /\u003e\n(hereinafter \u003cstrong\u003e\u0026quot;Controller\u0026quot;\u003c/strong\u003e)\u003c/p\u003e\n\u003chr /\u003e\n\u003ch2 id=\"preamble\"\u003ePreamble\u003c/h2\u003e\n\u003cp\u003eThis Data Processing Agreement (DPA) governs the processing of personal data by the Processor on behalf of the Controller pursuant to Art. 28 GDPR and Art. 9 of the Swiss Federal Act on Data Protection (FADP). It forms an integral part of the service agreement concluded between the parties.\u003c/p\u003e\n\u003chr /\u003e\n\u003ch2 id=\"section-1-subject-matter-and-duration\"\u003eSection 1: Subject Matter and Duration\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e1.1 Subject Matter:\u003c/strong\u003e The Processor provides technical services under the main contract (in particular web development and hosting), in the course of which it may gain access to personal data of the Controller or the Controller's customers.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e1.2 Duration:\u003c/strong\u003e Data processing continues for the duration of the main contract. Upon termination, data is handled in accordance with Section 8.\u003c/p\u003e\n\u003chr /\u003e\n\u003ch2 id=\"section-2-nature-and-purpose-of-processing\"\u003eSection 2: Nature and Purpose of Processing\u003c/h2\u003e\n\u003cp\u003eThe processing of personal data includes in particular:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAccess to server data and databases for technical maintenance and development\u003c/li\u003e\n\u003cli\u003eStorage and management of user data in hosted projects\u003c/li\u003e\n\u003cli\u003eLogging of access and errors for diagnostic purposes\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eProcessing is carried out exclusively for the purpose of fulfilling the main contract.\u003c/p\u003e\n\u003chr /\u003e\n\u003ch2 id=\"section-3-categories-of-personal-data-and-data-subjects\"\u003eSection 3: Categories of Personal Data and Data Subjects\u003c/h2\u003e\n\u003cp\u003eProcessing may involve the following categories of personal data:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eContact and identification data (name, email, address)\u003c/li\u003e\n\u003cli\u003eTechnical usage data (IP addresses, log data)\u003c/li\u003e\n\u003cli\u003eTransaction data (depending on project type)\u003c/li\u003e\n\u003cli\u003eOther data categories as defined by the Controller\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eData subjects may include customers, users and visitors of the Controller's systems and websites.\u003c/p\u003e\n\u003chr /\u003e\n\u003ch2 id=\"section-4-processor-obligations\"\u003eSection 4: Processor Obligations\u003c/h2\u003e\n\u003cp\u003eThe Processor undertakes to:\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e4.1\u003c/strong\u003e Process personal data only on documented instructions from the Controller.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e4.2\u003c/strong\u003e Ensure that all persons authorised to process personal data are bound to confidentiality or are subject to a statutory obligation of confidentiality.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e4.3\u003c/strong\u003e Implement all technical and organisational measures required under Art. 32 GDPR / Art. 8 FADP to ensure appropriate data security, in particular:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEncryption of stored and transmitted data\u003c/li\u003e\n\u003cli\u003eAccess controls and authentication measures\u003c/li\u003e\n\u003cli\u003eRegular security updates and backups\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e4.4\u003c/strong\u003e Comply with the conditions of this DPA when engaging sub-processors (see Section 5).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e4.5\u003c/strong\u003e Assist the Controller, taking into account the nature of the processing, in fulfilling its obligations (data subject rights, notification obligations, data protection impact assessments).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e4.6\u003c/strong\u003e Notify the Controller of any personal data breach without undue delay (within 24 hours of becoming aware of it at the latest).\u003c/p\u003e\n\u003chr /\u003e\n\u003ch2 id=\"section-5-sub-processors\"\u003eSection 5: Sub-processors\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e5.1\u003c/strong\u003e Since 3 October 2026 the Processor operates the hosted projects on its own servers and engages the following sub-processors for this:\u003c/p\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eSub-processor\u003c/th\u003e\n\u003cth\u003eService\u003c/th\u003e\n\u003cth\u003eCountry (location)\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eInfomaniak Network SA\u003c/td\u003e\n\u003ctd\u003eServers, object storage for pictures\u003c/td\u003e\n\u003ctd\u003eSwitzerland (Geneva)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eHetzner Online GmbH\u003c/td\u003e\n\u003ctd\u003eServers, copy of the database\u003c/td\u003e\n\u003ctd\u003eGermany (Falkenstein, Nuremberg)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eTavuru\u003c/td\u003e\n\u003ctd\u003eServer of the primary database\u003c/td\u003e\n\u003ctd\u003eGermany (Frankfurt)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eUpCloud Oy\u003c/td\u003e\n\u003ctd\u003eServers\u003c/td\u003e\n\u003ctd\u003eNetherlands (Amsterdam)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eScaleway SAS\u003c/td\u003e\n\u003ctd\u003eServers, copy of the database, nightly copy of the pictures\u003c/td\u003e\n\u003ctd\u003eNetherlands (Amsterdam), France (Paris)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eClouDNS Ltd.\u003c/td\u003e\n\u003ctd\u003eAnswers the DNS queries for the servers' names; sees DNS queries only, no project content and no account data\u003c/td\u003e\n\u003ctd\u003eBulgaria (Sofia)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eResend, Inc.\u003c/td\u003e\n\u003ctd\u003eSending email, where a project sends email through the Processor (e.g. notifications from contact forms); sent from Resend's EU region, stored in the USA\u003c/td\u003e\n\u003ctd\u003eUSA\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003cp\u003eCloudflare, Inc. (USA) holds the DNS zones, receives no personal data from the projects and so is not a sub-processor.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e5.2\u003c/strong\u003e For disclosure abroad: Germany, the Netherlands, France and Bulgaria belong to the EEA and, under Annex 1 of the Swiss Data Protection Ordinance (DPO), ensure an adequate level of data protection (Art. 16 para. 1 FADP). For disclosure to Resend in the USA, data from Switzerland is covered by the European Commission's Standard Contractual Clauses with the adaptations required by Swiss law, which form part of Resend's data processing agreement (Art. 16 para. 2 let. d FADP); for data subject to the GDPR, Resend is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR), and the same Standard Contractual Clauses apply in addition (Art. 46(2)(c) GDPR).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e5.3\u003c/strong\u003e Where a project is hosted with another provider at the Controller's request, the main contract names that provider. Where that provider is outside Switzerland and the EEA, the Processor ensures an adequate level of protection (e.g. through EU Standard Contractual Clauses).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e5.4\u003c/strong\u003e The Controller approves the sub-processors named in clause 5.1 and grants general authorisation for the engagement of further sub-processors in the area of hosting and server infrastructure, provided these are bound to equivalent data protection obligations.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e5.5\u003c/strong\u003e The Processor ensures that sub-processors are subject to the same data protection obligations as the Processor itself.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e5.6\u003c/strong\u003e Changes or additions to sub-processors will be communicated to the Controller in advance (at least 14 days' notice). The Controller may object in writing within this period.\u003c/p\u003e\n\u003chr /\u003e\n\u003ch2 id=\"section-6-data-subject-rights\"\u003eSection 6: Data Subject Rights\u003c/h2\u003e\n\u003cp\u003eThe Processor shall assist the Controller in responding to data subject requests (access, rectification, erasure, restriction, portability, objection). Where possible, the Processor shall provide technical means or take appropriate measures to support this.\u003c/p\u003e\n\u003chr /\u003e\n\u003ch2 id=\"section-7-controller-audit-rights\"\u003eSection 7: Controller Audit Rights\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e7.1\u003c/strong\u003e The Controller has the right to verify compliance with this DPA and data protection requirements at the Processor's premises.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e7.2\u003c/strong\u003e The Processor shall make all necessary information available to the Controller and permit audits or inspections (with reasonable advance notice of at least 14 days).\u003c/p\u003e\n\u003chr /\u003e\n\u003ch2 id=\"section-8-return-and-deletion-of-data\"\u003eSection 8: Return and Deletion of Data\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e8.1\u003c/strong\u003e Upon termination of the main contract, personal data shall be returned or deleted at the Controller's request, unless statutory retention obligations apply.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.2\u003c/strong\u003e The Processor shall confirm deletion in writing upon request.\u003c/p\u003e\n\u003chr /\u003e\n\u003ch2 id=\"section-9-liability\"\u003eSection 9: Liability\u003c/h2\u003e\n\u003cp\u003eThe liability of the parties is governed by the provisions of the main contract and applicable statutory provisions.\u003c/p\u003e\n\u003chr /\u003e\n\u003ch2 id=\"section-10-governing-law\"\u003eSection 10: Governing Law\u003c/h2\u003e\n\u003cp\u003eSwiss law applies. The place of jurisdiction is Zug, Switzerland.\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003cem\u003eThis DPA is agreed as an integral part upon conclusion of the main service agreement.\u003c/em\u003e\u003cbr /\u003e\nVersion 1.5, in effect from 9 October 2026: the table in section 5.1 names the copies of the database at Hetzner (Nuremberg) and Scaleway (Paris), which already existed. In effect without notice, since on that day no controller outside Elchi Studios was affected.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eVersion 1.5 | 9 October 2026\u003c/em\u003e\u003c/p\u003e\n","effective_from":"2026-10-09T00:00:00Z","published":true,"source_sha256":"94cf9029ecc674c0abf83ab0d86ad78500f963a2c26401adfeb23cecc985699e","created_at":"2026-10-09T05:31:13.264341Z","updated_at":"2026-10-09T05:31:13.264341Z","alternates":[{"locale":"de","slug":"avv","title":"Auftragsverarbeitungsvertrag (AVV)"}],"toc":[{"level":1,"title":"Data Processing Agreement (DPA)","anchor":"data-processing-agreement-dpa"},{"level":2,"title":"Preamble","anchor":"preamble"},{"level":2,"title":"Section 1: Subject Matter and Duration","anchor":"section-1-subject-matter-and-duration"},{"level":2,"title":"Section 2: Nature and Purpose of Processing","anchor":"section-2-nature-and-purpose-of-processing"},{"level":2,"title":"Section 3: Categories of Personal Data and Data Subjects","anchor":"section-3-categories-of-personal-data-and-data-subjects"},{"level":2,"title":"Section 4: Processor Obligations","anchor":"section-4-processor-obligations"},{"level":2,"title":"Section 5: Sub-processors","anchor":"section-5-sub-processors"},{"level":2,"title":"Section 6: Data Subject Rights","anchor":"section-6-data-subject-rights"},{"level":2,"title":"Section 7: Controller Audit Rights","anchor":"section-7-controller-audit-rights"},{"level":2,"title":"Section 8: Return and Deletion of Data","anchor":"section-8-return-and-deletion-of-data"},{"level":2,"title":"Section 9: Liability","anchor":"section-9-liability"},{"level":2,"title":"Section 10: Governing Law","anchor":"section-10-governing-law"}]}}
