Data Processing Agreement (DPA)
Parties
Silenccio AG ‘Processor’
Client of Silenccio AG who uses the cyber prevention services: ‘Controller’
Introduction
This DPA governs the processing of personal data by Silenccio AG, hereinafter referred to as the ‘Processor’ on behalf of the client, hereinafter referred to as the ‘Controller’, in connection with the use of the platform https://cyberpreventionservicesapp.axa.ch.
1 Subject of processing
The Processor processes personal data as part of the contractually agreed services (contract for the use of Silenccio AG’s cyber prevention services; Main Contract) as instructed by the Controller. Data processing includes storage, management, support and maintenance.
2 Nature and purpose of data processing
Data subjects (natural persons):
- Controller (if a natural person) or the contact person on the Controller’s side
- Official bodies of the Controller or their employees
- Employees and other auxiliaries of the Controller
Type of data:
- Identification data of the contact person on the Controller’s side: company name, first and last name, postal address, telephone number, email address,
- Data of employees and auxiliaries, data of the Controller’s official bodies: first name, surname, email address
- Contract data: scope of the services procured, term, use of the services
- Connection data: security tokens, password hashes, passwords, IP addresses, cookies
Purpose of processing:
- Execution of the contract and provision of services
- Financial management
- Sales management
3 Rights and obligations of the Controller
The Controller is responsible for the lawfulness of the data processing and ensures that the processing has a legal basis, in particular the consent of the data subjects or any other legal basis.
4 Obligations of the Processor
The Processor undertakes to:
- only process data in accordance with (legally compliant) documented instructions from the Controller. If it considers the instructions to be inadmissible, it shall inform the Controller,
- always ensure an appropriate level of data security in accordance with the applicable Swiss data protection law and take at least the technical and organisational measures (TOM) listed below to protect the data,
- not to disclose any data to third parties unless contractually regulated or legally prescribed,
- to oblige all its employees and other auxiliaries to maintain confidentiality, insofar as this is not already required by law;
- immediately notify the Controller in the event of data breaches,
- to delete or return data only within the scope of this Agreement,
- Support the Controller in fulfilling data subjects’ rights (e.g. access, rectification, erasure) within the scope of the statutory provisions.
5 Sub-processors
The Processor may only use sub-processors with the prior consent of the Controller. In this case, the Processor remains responsible towards the Controller.
Approved sub-processors:
| Name | Country | Role |
| Google Workspace | Switzerland | Email, documents, hosting of customer data |
| Salesforce | USA | CRM/storage of personal data |
| Brevo | France | Sending SMSs |
| Mailjet | France | Sending transactional emails |
| Mailgun | USA | Sending transactional emails |
| Payrexx | Switzerland | Payment processing |
| EyeOnID | USA | Credit card monitoring |
| Quickmail | Switzerland | Processing leads/contacts |
| BreachDirectory (RapidAPI) | USA | Comparison of email addresses against databases of breaches |
| Have I Been Pwned | Australia | Checking email addresses against known data leaks |
| BlacklistChecker | USA | Comparison of domains/IPs against reputation and blacklist data |
| Brave Search | USA | Search for and enrichment of publicly available information |
6 Duration of processing
Processing is carried out for as long as is necessary for the fulfilment of the contract or as required by law. After termination of the services, all personal data must be deleted or returned immediately and within 60 days at the most.
Description of the data, purposes and duration of the processing
Personal data is processed in accordance with the purposes and deadlines described in the privacy policy on the website. The following is a summary:
| Data type | Purpose of processing | Duration of storage |
| Identification data | Communication, support, contract execution | 5 years |
| Employee data | Execution of the contract | 60 days |
| Contract data | Execution of the contract | 5 years |
| Financial data | Billing, payment processing | 10 years |
| Connection data | Security tokens, password hashes, passwords, IP addresses, cookies | 1 year |
7 Liability
Liability is based on the statutory provisions.
8 Final provisions
Any changes and additions must be made in writing. Should individual provisions be invalid, the validity of the remaining provisions shall remain unaffected.
Technical and organisational measures
1 Confidentiality (Art. 3(1) DPO, Art. 32 GDPR)
- Access control
- Processing of productive personal data in the hosting provider’s data centres in Zurich. Physical access protection is guaranteed there and is certified
- In-house: lockable office, accompanied access for visitors, clean desk principle.
- Locked storage of physical documents containing personal data.
- Access control
- Role and authorisation concept based on the ‘need to know’ principle, assignment of minimum rights
- Regular review of authorisations and revocation of rights that are no longer required
- Separate administration and user accounts
- Logging of access to particularly sensitive personal data
- User control
- Personal user accounts, no shared access points for systems containing personal data
- Password policy and two-factor authentication where possible
- Separation control
- Separate processing of data collected for different purposes. Separate environments for development, testing and production
2 Availability and integrity (Art. 3 (2) DPO, Art. 32 GDPR)
- Data carriers and storage
- Encryption of end devices
- System hardening and secure basic configuration
- Transport control
- Encrypted transmission (TLS)
- VPN for remote access
- Particularly sensitive personal data is not sent in unencrypted form
- Recovery and availability
- Backup concept (online and offline, on-site and off-site)
- Regular and tested recovery
- Disaster recovery and disaster planning, uninterruptible power supply for Google Cloud
- System security
- Protection against malware (firewall, virus protection, endpoint detection and response solution)
- Patch and update management, current operating systems and software
- Regular penetration tests
- Hardening and secure basic configuration of the systems
- Deletion and backups
- Personal data is erased or anonymised as soon as it is no longer required, in compliance with statutory retention periods
- Deletion of personal data at the end of the contract
- After restoration from the backup, data deleted in the meantime is deleted again before release. Backups are overwritten in the normal cycle
3 Transparency (Art. 3(3) DPO)
- Transparency (Art. 3(3) DPO)
- Input control
- Logging of entries, changes and deletions
- Document management
- Identification and rectification
- Monitoring and alerts for intrusion detection where appropriate
- Defined process for reporting and processing incidents (incident response)
- Documented escalation and follow-up
4 Procedures for regular review, evaluation and evaluation
- Employees
- Commitment to confidentiality, regular awareness-raising
- Data protection organisation
- Clear responsibility
- Data-minimising default settings (privacy by default)
- Order processing
- Processing only on instructions from the Controller
- Sub-processors, including hosting providers, only used with consent and equivalent measures
- Breaches of data security are reported to the Controller immediately
- Support of the Controller with access, rectification and erasure
- Significant changes to the measures are communicated to the Controller in advance
