Back to the site

Data Processing Agreement

How the Operator processes personal data on your organisation’s behalf: what, where, with whom, and what you can require.

Last updated

1. Parties, subject and precedence

This Data Processing Agreement (the “DPA”) is between the Customer, as controller, and the Operator named in the imprint, as processor. It applies wherever the Operator processes personal data on the Customer’s behalf in providing the Service under the Terms of Use.

The DPA forms part of the Terms. For the processing it covers, it prevails over the Terms where the two conflict. Terms defined in the Terms of Use have the same meaning here.

2. Nature, purpose and duration

The Operator stores, computes with, renders and exports the data the Customer and its Users enter into the Service, so the Customer can assess its products and produce the reports and evidence the assessment calls for. Nothing is processed for the Operator’s own purposes beyond running, securing and supporting the Service, which the privacy page describes as the Operator’s own processing.

Processing lasts for the term of the agreement and the deletion period in Section 13.

3. Data subjects and types of data

The data subjects are the Customer’s employees and contractors who use the Service, and the Customer’s customers, suppliers and business partners insofar as the Customer names them in what it enters.

The data is: account and membership data of Users (name, email address, role, organisation); the content the Customer enters (Target of Evaluation descriptions, questionnaire answers, evidence attachments, sign-off and approval records with the names of the people who gave them, org-authored catalogue content and frameworks); and usage, audit and security records that name the User who acted.

Special categories of personal data under Art. 9 GDPR and sensitive personal data under the Swiss FADP are excluded. The Service is not designed for them, and the Customer must not enter them. Health, biometric, criminal-record or similar data about any person must be removed or irreversibly anonymised before it is entered.

4. Instructions

The Operator processes personal data only on the Customer’s documented instructions. The Terms, this DPA and the Customer’s and its Users’ use of the Service’s functions are those instructions. Further instructions must be in writing to the contact address in the imprint, and the Operator may charge for work that goes beyond the Service.

If the Operator believes an instruction infringes data protection law, it tells the Customer before acting on it. If Swiss, EU or EEA law requires the Operator to process data otherwise, it informs the Customer of that requirement before processing, unless the law prohibits it.

5. No training

Customer Content, model inputs and model outputs are not used to train, improve or fine-tune any machine-learning model, by the Operator or by any sub-processor. Where a provider’s default terms would allow it, the Operator excludes it by contract or by the provider’s settings before the provider receives any data.

6. Location of processing

The Service, its database, its stored files and its backups run in data centres in the European Union. Transactional mail is sent from the European Union.

For AI-assisted features, the prompt described in the Terms is sent to Mistral AI SAS (France), which processes it in the European Union. It retains inputs and outputs no longer than serving the request requires, except that it may keep request and response data in abuse-monitoring logs for up to 30 days before deletion.

For catalogue binding checks, only catalogue text (countermeasure and attack-step names and descriptions, and a proposed countermeasure’s name and description) is sent to the ranking-model provider. No assessment, product or personal data is.

7. Sub-processors

The Customer gives general authorisation for the Operator to use the sub-processors below to provide and operate the Service. Each is bound by a written contract that imposes the obligations of this DPA, and the Operator remains fully responsible to the Customer for their performance.

The Operator informs the organisation’s administrators at least 30 days before adding or replacing a sub-processor. The Customer may object within that period on legitimate data-protection grounds. If the parties cannot resolve the objection, the Customer may terminate the affected part of the Service, and the Operator refunds prepaid fees for the remaining period.

  • Hetzner Online GmbH, Germany: hosting of the application, its database, file storage and backups, in data centres in Germany and Finland.
  • Scaleway SAS, France: transactional email (Scaleway Transactional Email, region fr-par) for sign-in, invitation and notification mail; receives recipient addresses and message content only.
  • Mistral AI SAS, France: sole model provider for AI-assisted classification, processing in the European Union.
  • TypeSafe: ranking-model services for catalogue binding checks; receives catalogue text only, never personal data.

8. International transfers

Processing is intended to stay within Switzerland and the European Economic Area. Where a sub-processor, or its support staff, accesses personal data from outside Switzerland or the EEA, the Operator relies on a lawful transfer mechanism: an adequacy decision, the EU-U.S. or Swiss-U.S. Data Privacy Framework for recipients listed under it, or the European Commission’s Standard Contractual Clauses with the Swiss adaptations and any supplementary measures the transfer needs.

Transfers between Switzerland and the European Economic Area rest on the respective adequacy decisions.

9. Technical and organisational measures

The Operator implements measures appropriate to the risk, and reviews them as the Service changes:

  • Encryption in transit (TLS) for every connection, and encryption at rest for the database, stored files and backups.
  • Tenant isolation: every read and write is scoped to the acting organisation, re-derived from the session on each request, and a cross-tenant request is answered as not found.
  • Role-based access within an organisation, re-read from the database on every request, so a demotion or removal binds immediately.
  • Authentication with hashed credentials, signed sessions, and API keys that carry the User’s own role and can be revoked at once.
  • Audit records of security-relevant actions, server logs with a short retention window, and rate limits on every route.
  • Backups with tested restore, and a documented purge procedure for an organisation’s data.
  • Static analysis, secret scanning and dependency scanning on every change before it is deployed.
  • Access to production data limited to authorised personnel and sub-processors who need it to provide, secure, support or maintain the Service, each under confidentiality and data-protection obligations.
  • A security incident procedure that covers detection, containment, assessment and the notification in Section 11.

10. Confidentiality

The Operator ensures that every person authorised to process personal data has committed to confidentiality or is under a statutory obligation of confidentiality, and processes the data only as instructed.

11. Assistance and personal data breaches

The Operator forwards any request from a data subject that reaches it to the Customer without undue delay and does not answer it on the Customer’s behalf unless instructed. Taking into account the nature of the processing, the Operator assists the Customer with appropriate technical and organisational measures in answering such requests, and in meeting the Customer’s obligations on security, breach notification, data protection impact assessments and prior consultation.

The Operator notifies the organisation’s administrators of a personal data breach affecting the Customer’s data without undue delay after becoming aware of it, with the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact. Information not available at first is provided as it becomes available.

12. Audits

The Operator makes available the information necessary to demonstrate compliance with this DPA, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates. An audit takes place at most once a year, on 30 days’ written notice, during business hours, under confidentiality, at the Customer’s cost and without disrupting the Service, unless a supervisory authority requires one or a personal data breach has occurred. A current third-party audit report or certification of the Operator or a sub-processor may be provided to satisfy a request.

13. Return and deletion

During the term, and for 30 days after it ends, the Customer may export its organisation’s data in the Service’s export formats. After that period, or earlier on the Customer’s written instruction, the Operator deletes the organisation’s data from the active systems. The purge is irreversible.

Backup copies under the Operator’s control are overwritten or permanently deleted within 30 days of the purge. Copies held by sub-processors are deleted under the applicable sub-processor agreement and its documented retention schedule. Records the Operator must keep by law are retained for that purpose only, and deleted when the obligation ends.

14. Liability, law and changes

The limitation of liability, the governing law and the venue in the Terms of Use apply to this DPA. Changes to this DPA follow the notice procedure in the Terms; a change to the sub-processor list follows Section 7.

Atrekos uses only its own, technically necessary cookies to operate.