AlpGuardIA

Data Processing Agreement (DPA)

Pursuant to Art. 9 revFADP

Last updated: 2025-01-01

1. Subject and Roles

This agreement is concluded pursuant to Article 9 of the Swiss Federal Act on Data Protection (revFADP). The Client acts as Controller and [COMPANY_NAME] (AlpGuardIA) as Processor.

2. Nature and Purpose of Processing

The Processor commits to processing personal data solely for dynamic pseudonymisation and routing of the Client's requests.

3. Zero-Persistence Architecture and Technical Measures

Chat requests: The complete mapping table linking original values to pseudonyms is processed exclusively in server RAM during the request. It is irreversibly destroyed after the response is returned.

Documents: Only pseudonyms (without original values) may be stored encrypted in the database.

Error logs: No request content is ever written to application logs or error columns in the database.

4. Confidentiality and Exclusion of Professional Secrecy

The service is not designed for contextual anonymisation of complex files. The Processor does not act as an auxiliary within the meaning of Art. 321 Swiss Criminal Code.

5. Sub-processors

The Client expressly authorises the use of Infomaniak Network SA (Switzerland) as a sub-processor for infrastructure hosting.