Data Processing Agreement (DPA)
Contract for the processing of personal data on behalf of — between the Customer as Controller and ZEROVIA GmbH as Processor.
Version: 1.0
Stand: July 19, 2026
ZEROVIA GmbH,Via Casti 52, 7151 Schluein, Switzerland
E-Mail: info@zerovia.ch · privacy@zerovia.ch
Introduction
This Data Processing Agreement («DPA» or «Agreement») is an integral part of the Terms of use and the Subscription conditions between
to the customer (hereinafter «Customer» or «Controller»)
and
ZEROVIA GmbH, Via Casti 52, 7151 Schluein, Switzerland (hereinafter «ZEROvia» or «Processor»)
collectively referred to as the «Parties».
In view of the fact that:
- the customer uses the ZEROvia platform and in doing so, inputs personal data into the services for which they act as the controller.;
- ZEROvia processes this personal data exclusively on behalf and under the instructions of the client and thus acts as a processor;
- The parties wish to establish the terms of this processing in accordance with Article 9 of the Swiss Federal Act on Data Protection (hereinafter «FADP») and Article 28 of Regulation (EU) 2016/679 (hereinafter «GDPR»);
- the parties wish to establish their respective rights and obligations;
- the processing of personal data for which ZEROvia is responsible (in particular, processing within the scope of its own website and customer management in accordance with the data protection declaration) does not fall under this agreement.
The following is agreed upon:
Article 1 — Definitions and Interpretation
1.1 Unless otherwise defined in this Agreement, terms used in this Agreement shall have the following meanings:
1.1.1 «Agreement» means this Data Processing Addendum, including Attachments 1–3;
1.1.2 «Customer Personal Data» means the personal data processed by ZEROvia on behalf of the Customer in connection with the Services, as further described in Appendix 1;
1.1.3 «Data Protection Laws» means the FADP, the GDPR, and, where applicable, other relevant data protection regulations;
1.1.4 «DSG» refers to the Swiss Federal Act on Data Protection (SR 235.1) and its implementing ordinances (DSV, SR 235.11);
1.1.5 «GDPR» refers to Regulation (EU) 2016/679;
1.1.6 «Services» refers to the digital services provided by ZEROvia in accordance with the terms and conditions of use and subscription, in particular the zerovia.app platform;
1.1.7 «Sub-processor» means any person engaged by or on behalf of ZEROvia to process Customer Personal Data;
1.1.8 «Data transmission» refers to the transmission of the customer's personal data to ZEROvia or its subsequent transmission to a subcontractor.
1.2 The terms «controller», «data subject», «personal data», «personal data breach», and «processing» are used with the same meaning as in the FADP and GDPR.
Article 2 — Subject Matter, Nature, Scope, Purpose, and Duration of Processing
2.1 ZEROvia processes customer personal data exclusively for the provision of services in accordance with the main agreement between the parties (terms of use and subscription as well as any individual agreements).
2.2 The subject matter, nature, and purpose of the processing, the categories of data subjects, and the categories of personal data are set out in Annex 1.
2.3 The processing duration corresponds to the term of the main contract plus the deletion and return periods regulated in Article 10.
Article 3 — Bound by Instructions
3.1 ZEROvia processes the customer's personal data exclusively on documented instructions from the customer, unless ZEROvia is legally obligated to process it otherwise; in this case, ZEROvia will inform the customer of these legal requirements before processing, unless prohibited by law.
3.2 The main agreement and the customer's use of and configuration of the services (including role and permission assignments, release and opt-in settings) are considered documented instructions from the customer.
3.3 ZEROvia will immediately inform the customer if it believes an instruction violates data protection laws. ZEROvia is entitled to suspend the execution of an obviously unlawful instruction.
Article 4 — Obligations of the Processor
4.1 ZEROvia commits to:
4.1.1 to comply with all applicable data protection laws when processing the customer's personal data;
4.1.2 process the customer's personal data only in accordance with the customer's instructions and exclusively for the provision of services;
4.1.3 The customer's personal data may not be viewed or used for own purposes, especially not for training AI models that are accessible to third parties; the use of anonymized aggregate data for internal model improvement will only be done with the customer's explicit opt-in.;
4.1.4 ensuring that persons authorized to process the data are subject to an obligation of confidentiality or are under an appropriate statutory obligation of confidentiality;
4.1.5 strictly limit access to the customer's personal data to individuals who need it to perform their duties («need-to-know» principle);
4.1.6 to implement and maintain technical and organizational measures in accordance with Article 5;
4.1.7 to inform the customer — to the extent legally permissible — about binding requests from an authority regarding the customer's personal data and to limit disclosure to what is legally required.
Article 5 — Technical and organizational measures
5.1 ZEROvia takes appropriate technical and organizational measures, taking into account the state of the art, implementation costs, and the nature, scope, and purpose of processing, to ensure a level of security appropriate to the risk (Art. 32 GDPR; Art. 8 DPA in conjunction with Art. 3 DPCR).
5.2 The measures are described in Appendix 2. Part of the infrastructure-related measures will be provided by the subcontractors (especially Infomaniak) and are contractually guaranteed to ZEROvia.
5.3 ZEROvia continuously reviews and improves these measures. ZEROvia may adjust individual measures if the level of protection is not reduced.
Article 6 – Subcontractors
6.1 The customer grants ZEROvia general authorization to use subcontractors for the provision of services. The subcontractors used at the time of the conclusion of the contract are listed in Appendix 3.
6.2 ZEROvia informs the customer in advance about the intended engagement or replacement of a sub-processor. The customer may object in writing (email sufficient) for an important data protection reason within 30 days of notification. If the customer objects in due time and this prevents continuation, either party is entitled to terminate the affected service.
6.3 ZEROvia contractually obliges every sub-processor to at least the same data protection obligations that apply to ZEROvia under this agreement (Art. 28 para. 4 GDPR). ZEROvia remains fully responsible to the customer for the sub-processor's compliance with these obligations.
Article 7 — Rights of Data Subjects
7.1 ZEROvia will support the customer, within the technically feasible scope, with appropriate technical and organizational measures in responding to data subject requests regarding their rights (access, rectification, erasure, restriction, data portability, objection).
7.2 If an affected person submits such a request directly to ZEROvia, ZEROvia will forward it to the customer immediately and only respond upon documented instruction from the customer or as required by law.
Article 8 — Support for the Controller
8.1 ZEROvia supports the customer in fulfilling their obligations regarding the security of processing, data breach notification, data protection impact assessment (Art. 35 GDPR), and prior consultation of the supervisory authority (Art. 36 GDPR) or the corresponding provisions of the DSG, taking into account the nature of the processing and the information available to them.
Article 9 - Notification of Data Breaches
9.1 ZEROvia shall notify the customer without undue delay after becoming aware of a breach of the customer's personal data protection and shall provide the customer with the information necessary to fulfill its own reporting and notification obligations.
9.2 ZEROvia cooperates with the customer and takes appropriate measures to investigate, contain, and remediate the breach.
9.3 Communication is sent to the contact address stored by the customer in their account or to their data protection contact; from ZEROvia to privacy@zerovia.ch.
Article 10 – Deletion and Return of Personal Data
10.1 Upon the customer's choice, ZEROvia shall delete or return all personal data of the customer as soon as the provision of the relevant services is terminated, in any case within 30 days of termination, provided that no statutory retention obligation prevents this.
10.2 The customer is responsible for making any necessary exports, backups, or transfers of their data prior to the termination of services; ZEROvia will assist the customer in doing so to the extent technically feasible.
10.3 ZEROvia confirms the deletion to the customer in writing upon request.
Article 11 — Evidence and Audits
11.1 ZEROvia will provide the customer with the information required to demonstrate compliance with this agreement. Standard documentation is available on the website or by contacting support upon request.
11.2 If this information is insufficient, ZEROvia shall permit the customer or an auditor commissioned by the customer, who is bound by confidentiality, to conduct reviews under reasonable conditions and with reasonable notice. The conditions shall not compromise the security of other ZEROvia customers; reasonable additional costs may be charged.
Article 12 — International Data Transfer
12.1 Customer personal data is primarily processed in Switzerland (hosting by Infomaniak, Geneva). There is a mutually recognized adequate level of data protection between Switzerland and the EU/EEA (EU adequacy decision in favor of Switzerland, confirmed on January 15, 2024; Swiss adequacy list according to FADP Annex 1); corresponding transfers do not require additional safeguards.
12.2 A transfer to sub-processors in third countries shall only take place if appropriate safeguards are in place, in particular through the Standard Contractual Clauses approved by the EU Commission – supplemented by a Transfer Impact Assessment (TIA) and technical protective measures – with the adjustments for Switzerland recognized by the FDPIC, or with certified recipients based on the Swiss-U.S. Data Privacy Framework. The affected sub-processors and the respective transfer mechanism are listed in Appendix 3.
Article 13 - Liability
13.1 The liability of the parties shall be governed by the liability provisions of the Principal Agreement. In relation to data subjects and supervisory authorities, the allocation of liability according to Art. 82 GDPR or the relevant provisions of the DSG shall apply.
Article 14 — Duration, Priority, and Final Provisions
14.1 This agreement enters into force with the main contract and applies for its duration as well as for the post-contractual period according to Article 10.
14.2 In data protection matters concerning processing on behalf of another, this agreement shall take precedence over the terms of use and subscription. Otherwise, the following order of precedence shall apply: (1) individual agreement, (2) subscription terms, (3) this DPA, (4) terms of use.
14.3 Modifications and additions require written form. Should a provision be ineffective, the validity of the remaining provisions shall remain unaffected.
Article 15 - Governing Law and Jurisdiction
15.1 This Agreement shall be governed exclusively by Swiss law.
15.2 The place of jurisdiction for all disputes arising from or in connection with this agreement is Chur (GR).
This agreement becomes effective electronically upon conclusion of the main contract and is valid without a signature.
Appendix 1 — Processing Details
| Aspect | Description |
|---|---|
| Object | Provision of the ZEROvia SaaS platform (ESG data management, supplier management, procurement, reporting) in accordance with the master agreement. |
| Type of processing | Raise, Capture, Store, Structure, Read, AI-assisted Text Design, Display, Transmit (only with customer opt-in), Delete. |
| Purpose | Exclusive provision of services commissioned by the customer. |
| Categories of affected persons | Customers and client employees; contact persons and ESG contact persons; client supplier contact persons; other individuals whose data is included in uploaded documents. |
| Categories of personal data | Contact and master data (name, function, business email, phone), account and usage data, log/metadata, contents of uploaded documents and receipts. Special categories of personal data only insofar as they are provided by the customer – their provision should be omitted in accordance with the terms of use. |
| Duration | Term of the main contract plus deletion/return periods according to Article 10. |
Appendix 2 — Technical and Organizational Measures (TOMs)
In addition to the infrastructure measures implemented by the sub-processors (in particular Infomaniak), ZEROvia is implementing the following:
| Measures Category | Implementation |
|---|---|
| Access control | Betrieb in Schweizer Rechenzentren der Unterauftragsverarbeiter mit Zutrittsbeschränkung, Zugangsmanagement und physischen Sicherheitsmassnahmen. |
| Zugangskontrolle | Authentifizierung von Nutzern und Administratoren; rollen- und rechtebasierte Zugangsverwaltung (RBAC); optionale Zwei-Faktor-Authentifizierung (2FA); Schutz administrativer Funktionen. |
| Zugriffskontrolle | Prinzip der minimalen Berechtigung und «Kenntnis nur, wenn nötig»; protokollierter Zugriff im Rahmen von Support und Störungsbehebung. |
| Netzwerk- und Systemsicherheit | Firewalls, Intrusion-Detection/-Prevention (IDS/IPS) und laufendes System-Monitoring. |
| Trennungskontrolle | Logische bzw. physische Trennung der Kundenmandanten; regelmässige Sicherheitstests, um sicherzustellen, dass keine Daten zwischen Kunden zirkulieren. |
| Verschlüsselung | Verschlüsselte Übertragung (SSL/TLS) sowie Verschlüsselung ruhender Daten nach Stand der Technik. |
| KI-Verarbeitung | Keine Verwendung von Kundendaten zum Training öffentlich zugänglicher KI-Modelle; bei KI-Anbietern mit US-Verarbeitung ergänzende Schutzmassnahmen (SCC, TIA, Verschlüsselung, Pseudonymisierung soweit möglich). |
| Eingabe-/Nachvollziehbarkeit | Protokollierung sicherheitsrelevanter Ereignisse und administrativer Zugriffe. |
| Verfügbarkeit & Wiederherstellbarkeit | Redundante Speicherung und regelmässige Sicherungen bei den Unterauftragsverarbeitern; Wiederherstellungsprozesse. |
| Vorfallmanagement | Prozess zur Erkennung, Meldung und Behebung von Datenschutzverletzungen (vgl. Artikel 9). |
| Prüfung & Audits | Interne Audits und externe Sicherheitstests; Orientierung der Sicherheitsarchitektur an ISO/IEC 27001 und den Empfehlungen des EDÖB. |
| Auftragskontrolle | Vertragliche Bindung der Unterauftragsverarbeiter auf gleichwertige Datenschutzpflichten; Weisungsgebundenheit. |
| Deletion | Definierte Lösch- und Aufbewahrungsprozesse gemäss Artikel 10. |
| Personal | Verpflichtung aller zugriffsberechtigten Personen zur Vertraulichkeit. |
Anhang 3 — Genehmigte Unterauftragsverarbeiter
| Unterauftragsverarbeiter | Sitz / Verarbeitungsort | Purpose | Übermittlungsmechanismus |
|---|---|---|---|
| Infomaniak Network SA | Genf, CH | Hosting der Plattform zerovia.app, Speicherung der Plattformdaten | Schweiz — kein Drittlandtransfer |
| OpenAI Ireland Ltd. | Irland (EU); Verarbeitung teils USA | Generative KI (GPT) für Textentwürfe und Konsistenzprüfung | EU-Angemessenheit; für US-Verarbeitung SCC + TIA + technische Schutzmassnahmen |
| Anthropic PBC | USA | Generative KI (Claude) für Textentwürfe und Konsistenzprüfung | SCC + TIA + technische Schutzmassnahmen |
| Mistral AI | Frankreich (EU) | Generative KI als europäischer Fallback (geplant) | Innerhalb EU |
| Uvensys GmbH | Gießen, DE (EU) | Hosting Entwicklungs-/Testumgebung (DEV/TEST) | Innerhalb EU |
Nicht in dieser Liste geführt sind Dienste, bei denen ZEROvia als Verantwortliche und nicht als Auftragsverarbeiterin im Kundenauftrag handelt: das Hosting der Marketing-Website zerovia.ch (derzeit cyon GmbH, Basel; Umzug zu Infomaniak bis Ende Juli 2026 geplant), das CRM (HubSpot), weitere Website-/Marketing-Dienste (Google Site Kit, TranslatePress, SpeedyCache, CookieAdmin) sowie die Tools der EU-Vertretung und Betroffenenrechte (Prighter, Hetzner). Diese sind in §8 der Datenschutzerklärung auszuweisen. Vor Publikation zu klären: ob die DEV/TEST-Umgebung (Uvensys) echte Personendaten von Kunden enthält — andernfalls entfällt dieser Eintrag.
EU-Vertreter (Art. 27 DSGVO):
iuro Rechtsanwälte GmbH t/a Prighter, Schellinggasse 3, 1010 Wien, Österreich — privacy@zerovia.ch
Portal: app.prighter.com/portal/zerovia.
Zuständige Aufsichtsbehörde (CH):
Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB), Bern.