Legal

Data Processing Agreement (DPA)

This Data Processing Agreement ("DPA") is entered into between Bucher & Ambühl GmbH ("Processor") and the client ("Controller") as defined in the service agreement. It governs the processing of personal data by the Processor on behalf of the Controller.

1. Scope

The Processor provides managed infrastructure, hosting, and automation services. The Controller determines the purposes and means of data processing. This DPA applies to all personal data processed by the Processor in connection with the services.

2. Data Categories

The Processor processes the following categories of personal data on behalf of the Controller:

  • Contact data of the Controller's clients (name, email, phone, address)
  • Business records (invoices, accounting entries, CRM data)
  • Documents uploaded to the Controller's cloud storage
  • Website visitor analytics (anonymized)
3. Purpose Limitation

The Processor processes data only for the purpose of providing the agreed services. The Processor shall not process personal data for any other purpose, including its own commercial purposes.

4. Isolation

Each client receives a dedicated virtual private server (VPS). Data is not shared between clients. Each client has isolated databases, cloud storage, and application instances. No client can access another client's data.

5. Security Measures

The Processor implements the following technical and organizational measures:

  • TLS encryption for all data in transit (HTTPS)
  • Firewall (UFW) and intrusion prevention (Fail2Ban)
  • Daily encrypted offsite backups (30-day retention)
  • SSH key-based access only (no password authentication)
  • Access restricted to authorized personnel (2 individuals)
  • Access logging and audit trail
  • Disk encryption (LUKS) available upon request
6. Subprocessors

The Processor uses the following subprocessors:

  • Hostinger (EU) — VPS hosting
  • Infomaniak (CH) — Email, DNS, backup storage
  • OpenRouter — AI model API (optional, per client)

The Controller is notified of any changes to subprocessors at least 30 days in advance.

7. Data Location

All data is stored on servers located in the European Union (VPS) and Switzerland (email, DNS, backups). No data is transferred to or stored in the United States or other non-adequate jurisdictions.

8. Data Deletion

Upon termination of the service agreement, the Processor deletes all client data from production systems within 30 days. Backups containing client data are deleted within 30 days of the deletion of production data. The Controller may request earlier deletion at any time.

9. Audit Rights

The Controller has the right to audit the Processor's compliance with this DPA once per calendar year, upon 14 days' notice. The Processor provides access to relevant documentation and systems logs.

10. Breach Notification

The Processor notifies the Controller of any personal data breach within 48 hours of becoming aware of it. The notification includes the nature of the breach, the data affected, and the measures taken.

11. Governing Law

This DPA is governed by Swiss law, specifically the revised Data Protection Act (DSG, in force since 1 September 2023). Place of jurisdiction is Zurich, Switzerland.

Contact

Bucher & Ambühl GmbH
Im Fronberg 7, 8172 Niederglatt ZH, Switzerland
contact@bucherambuehl.com

Version

Version 1.0 — August 2026

← Back home