Data Processing Agreement (DPA)
Pursuant to Art. 9 revFADP
Last updated: 2025-01-01
1. Subject and Roles
This agreement is concluded pursuant to Article 9 of the Swiss Federal Act on Data Protection (revFADP). The Client acts as Controller and [COMPANY_NAME] (AlpGuardIA) as Processor.
2. Nature and Purpose of Processing
The Processor commits to processing personal data solely for dynamic pseudonymisation and routing of the Client's requests.
3. Zero-Persistence Architecture and Technical Measures
Chat requests: The complete mapping table linking original values to pseudonyms is processed exclusively in server RAM during the request. It is irreversibly destroyed after the response is returned.
Documents: Only pseudonyms (without original values) may be stored encrypted in the database.
Error logs: No request content is ever written to application logs or error columns in the database.
Documents: Only pseudonyms (without original values) may be stored encrypted in the database.
Error logs: No request content is ever written to application logs or error columns in the database.
4. Confidentiality and Exclusion of Professional Secrecy
The service is not designed for contextual anonymisation of complex files. The Processor does not act as an auxiliary within the meaning of Art. 321 Swiss Criminal Code.
5. Sub-processors
The Client expressly authorises the use of Infomaniak Network SA (Switzerland) as a sub-processor for infrastructure hosting.
Other legal documents