Data Processing Agreement (DPA)

Parties

Silenccio AG ‘Processor’

Client of Silenccio AG who uses the cyber prevention services: ‘Controller’

Introduction

This DPA governs the processing of personal data by Silenccio AG, hereinafter referred to as the ‘Processor’ on behalf of the client, hereinafter referred to as the ‘Controller’, in connection with the use of the platform https://cyberpreventionservicesapp.axa.ch.

1 Subject of processing

The Processor processes personal data as part of the contractually agreed services (contract for the use of Silenccio AG’s cyber prevention services; Main Contract) as instructed by the Controller. Data processing includes storage, management, support and maintenance.

2 Nature and purpose of data processing

Data subjects (natural persons):

  • Controller (if a natural person) or the contact person on the Controller’s side
  • Official bodies of the Controller or their employees
  • Employees and other auxiliaries of the Controller

Type of data:

  • Identification data of the contact person on the Controller’s side: company name, first and last name, postal address, telephone number, email address,
  • Data of employees and auxiliaries, data of the Controller’s official bodies: first name, surname, email address
  • Contract data: scope of the services procured, term, use of the services
  • Connection data: security tokens, password hashes, passwords, IP addresses, cookies

Purpose of processing: 

  • Execution of the contract and provision of services
  • Financial management
  • Sales management

3 Rights and obligations of the Controller

The Controller is responsible for the lawfulness of the data processing and ensures that the processing has a legal basis, in particular the consent of the data subjects or any other legal basis.

4 Obligations of the Processor

The Processor undertakes to:

  • only process data in accordance with (legally compliant) documented instructions from the Controller. If it considers the instructions to be inadmissible, it shall inform the Controller,
  • always ensure an appropriate level of data security in accordance with the applicable Swiss data protection law and take at least the technical and organisational measures (TOM) listed below to protect the data,
  • not to disclose any data to third parties unless contractually regulated or legally prescribed,
  • to oblige all its employees and other auxiliaries to maintain confidentiality, insofar as this is not already required by law;
  • immediately notify the Controller in the event of data breaches,
  • to delete or return data only within the scope of this Agreement,
  • Support the Controller in fulfilling data subjects’ rights (e.g. access, rectification, erasure) within the scope of the statutory provisions.

5 Sub-processors

The Processor may only use sub-processors with the prior consent of the Controller. In this case, the Processor remains responsible towards the Controller.

Approved sub-processors:

NameCountryRole
Google WorkspaceSwitzerlandEmail, documents, hosting of customer data
SalesforceUSACRM/storage of personal data
BrevoFranceSending SMSs
MailjetFranceSending transactional emails
MailgunUSASending transactional emails
PayrexxSwitzerlandPayment processing
EyeOnIDUSACredit card monitoring
QuickmailSwitzerlandProcessing leads/contacts
BreachDirectory (RapidAPI)USAComparison of email addresses against databases of breaches
Have I Been PwnedAustraliaChecking email addresses against known data leaks
BlacklistCheckerUSAComparison of domains/IPs against reputation and blacklist data
Brave SearchUSASearch for and enrichment of publicly available information

6 Duration of processing

Processing is carried out for as long as is necessary for the fulfilment of the contract or as required by law. After termination of the services, all personal data must be deleted or returned immediately and within 60 days at the most.


Description of the data, purposes and duration of the processing

Personal data is processed in accordance with the purposes and deadlines described in the privacy policy on the website. The following is a summary:

Data typePurpose of processingDuration of storage
Identification dataCommunication, support, contract execution5 years
Employee dataExecution of the contract60 days
Contract dataExecution of the contract5 years
Financial dataBilling, payment processing10 years
Connection dataSecurity tokens, password hashes, passwords, IP addresses, cookies1 year

7 Liability

Liability is based on the statutory provisions.

8 Final provisions

Any changes and additions must be made in writing. Should individual provisions be invalid, the validity of the remaining provisions shall remain unaffected.

Technical and organisational measures

1 Confidentiality (Art. 3(1) DPO, Art. 32 GDPR)

  • Access control
    • Processing of productive personal data in the hosting provider’s data centres in Zurich. Physical access protection is guaranteed there and is certified
    • In-house: lockable office, accompanied access for visitors, clean desk principle.
    • Locked storage of physical documents containing personal data.
  • Access control
    • Role and authorisation concept based on the ‘need to know’ principle, assignment of minimum rights
    • Regular review of authorisations and revocation of rights that are no longer required
    • Separate administration and user accounts
    • Logging of access to particularly sensitive personal data
  • User control
    • Personal user accounts, no shared access points for systems containing personal data
    • Password policy and two-factor authentication where possible
  • Separation control
    • Separate processing of data collected for different purposes. Separate environments for development, testing and production

2 Availability and integrity (Art. 3 (2) DPO, Art. 32 GDPR)

  • Data carriers and storage
    • Encryption of end devices
    • System hardening and secure basic configuration
  • Transport control
    • Encrypted transmission (TLS)
    • VPN for remote access
    • Particularly sensitive personal data is not sent in unencrypted form
  • Recovery and availability
    • Backup concept (online and offline, on-site and off-site)
    • Regular and tested recovery
    • Disaster recovery and disaster planning, uninterruptible power supply for Google Cloud
  • System security
    • Protection against malware (firewall, virus protection, endpoint detection and response solution)
    • Patch and update management, current operating systems and software
    • Regular penetration tests
    • Hardening and secure basic configuration of the systems
  • Deletion and backups
    • Personal data is erased or anonymised as soon as it is no longer required, in compliance with statutory retention periods
    • Deletion of personal data at the end of the contract
    • After restoration from the backup, data deleted in the meantime is deleted again before release. Backups are overwritten in the normal cycle

3 Transparency (Art. 3(3) DPO)

  • Transparency (Art. 3(3) DPO)
  • Input control
    • Logging of entries, changes and deletions
    • Document management
  • Identification and rectification
    • Monitoring and alerts for intrusion detection where appropriate
    • Defined process for reporting and processing incidents (incident response)
    • Documented escalation and follow-up

4 Procedures for regular review, evaluation and evaluation

  • Employees
    • Commitment to confidentiality, regular awareness-raising
  • Data protection organisation
    • Clear responsibility
    • Data-minimising default settings (privacy by default)
  • Order processing
    • Processing only on instructions from the Controller
    • Sub-processors, including hosting providers, only used with consent and equivalent measures
    • Breaches of data security are reported to the Controller immediately
    • Support of the Controller with access, rectification and erasure
    • Significant changes to the measures are communicated to the Controller in advance