// Legal
Data processing agreement (DPA)
Last updated: 2026-09-25
Data Processing Agreement pursuant to Art. 28(3) GDPR and Art. 9 of the Swiss Federal Act on Data Protection (FADP, SR 235.1).
between
[Customer's company], [address], [country] – hereinafter "Controller" or "Customer" –
and
Netgen Switzerland AG, Seestrasse 356, 8038 Zürich, Switzerland – hereinafter "Processor" or "Netgen" –
This DPA covers, in one document, Art. 28 GDPR (customers in Germany and the EU/EEA) and Art. 9 FADP with the Data Protection Ordinance (DPO) (customers in Switzerland). It forms part of every PIM Gate contract and is accepted together with the Main Agreement.
Agreement
§0 Preamble, scope and definitions
- The parties have concluded an agreement on the use of the SaaS platform PIM Gate (the "Main Agreement", consisting of the offer, the terms of service and the service description). In performing it, Netgen processes personal data on behalf of the Customer. This DPA governs the parties' data-protection obligations.
- This DPA applies to all activities in which Netgen, its staff or engaged sub-processors process personal data of the Customer ("Customer Data").
- Depending on the Customer's seat and activity, Regulation (EU) 2016/679 (GDPR) and/or the Swiss FADP with the Data Protection Ordinance (DPO) apply. For customers in Germany, the BDSG applies in addition.
- Terms are used as defined in the GDPR. For the FADP they apply mutatis mutandis: "processing" corresponds to "Bearbeitung", "processor" to "Auftragsbearbeiter", and "supervisory authority" includes the Swiss Federal Data Protection and Information Commissioner (FDPIC).
- In case of conflict, this DPA prevails over the Main Agreement in data-protection matters.
§1 Subject matter, duration, nature and purpose of processing
- The subject matter is the provision and operation of PIM Gate as a portal layer for the Customer's product data, including customer, supplier and sales portals, interfaces (API, webhooks, SFTP), search, AI-assisted functions (e.g. tagging, translation), and support and maintenance.
- The nature, purpose, categories of data and data subjects are described in Annex 1.
- The duration of this DPA corresponds to the term of the Main Agreement. It does not end as long as Netgen still processes Customer Data.
- Processing takes place in Switzerland and in member states of the EU/EEA. Processing in other third countries takes place only in accordance with §6.
§2 Customer's right to issue instructions
- Netgen processes Customer Data exclusively on the Customer's documented instructions. The instructions are set out conclusively in the Main Agreement, in this DPA and in the settings the Customer configures in PIM Gate. Further instructions are issued by the Customer in text form (e-mail to support@avidia.ai).
- Processing without instructions is permitted only where Netgen is required to do so by Union, member-state or Swiss law. In that case Netgen informs the Customer in advance, unless the law prohibits this.
- If Netgen considers that an instruction infringes data-protection law, it informs the Customer without undue delay. Netgen may suspend execution until the Customer confirms or amends the instruction.
- Instructions exceeding the agreed scope of services are treated as change requests and may be charged on a time-and-materials basis.
§3 Obligations of Netgen
- Netgen processes Customer Data only for the purposes stated in Annex 1 and not for its own purposes.
- Netgen binds all persons with access to Customer Data to confidentiality in writing, unless they are subject to a statutory duty of secrecy. The obligation survives the end of their engagement.
- Netgen ensures that only persons who need access for their tasks have it, and that they are trained in data protection.
- Netgen logically separates Customer Data from the data of other customers (tenant isolation at schema level).
- Netgen maintains a record of processing activities pursuant to Art. 30(2) GDPR and Art. 12 FADP, where legally required.
- Netgen's contact person for data protection is Christian Paredes, Managing Director, support@avidia.ai.
- Netgen informs the Customer without undue delay of inspections or measures by supervisory authorities insofar as they concern Customer Data.
- AI functions: Netgen does not use Customer Data to train or improve AI models, neither its own nor third parties'. Inputs to AI services of sub-processors are made only where these contractually warrant not to use the data for training and not to retain it longer than needed to deliver the service.
- Netgen may use anonymised or aggregated usage and operational data without personal reference to safeguard and develop its operations.
§4 Technical and organisational measures (TOM)
- Netgen implements the measures described in Annex 2 pursuant to Art. 32 GDPR and Art. 8 FADP in conjunction with Art. 1–6 DPO. They ensure a level of protection appropriate to the risk for confidentiality, integrity, availability and resilience.
- Netgen operates an information-security management system certified to ISO/IEC 27001 and an AI management system certified to ISO/IEC 42001, and maintains them for the term of the agreement.
- Netgen may adapt the measures to the state of the art provided the level of protection is not reduced. Material changes are documented and communicated to the Customer on request.
§5 Sub-processors
- The Customer approves the sub-processors listed in Annex 3.
- The Customer grants Netgen general authorisation to engage further sub-processors or replace existing ones. Netgen informs the Customer at least 30 days in advance in text form (e-mail or notice in the platform).
- Within this period the Customer may object for important data-protection reasons. If the parties find no solution, the Customer may terminate the affected part of the Main Agreement extraordinarily as of the date of the change. Fees already paid for the period thereafter are refunded pro rata.
- Netgen contractually imposes on every sub-processor the same data-protection obligations agreed in this DPA, in particular sufficient guarantees for appropriate TOM.
- Netgen is liable to the Customer for its sub-processors' compliance as for its own conduct.
- Ancillary services without access to Customer Data – such as telecommunications, postal services, cleaning or infrastructure maintenance where no access to personal data is possible – do not constitute sub-processing.
§6 Transfers to third countries
- The parties note: Switzerland benefits from an adequacy decision of the European Commission; the EU/EEA states are deemed to provide adequate protection under Annex 1 DPO. Processing by Netgen in Switzerland and by sub-processors in the EU/EEA therefore requires no additional safeguards.
- Transfers to other third countries take place only if (a) an adequacy decision of the European Commission and a corresponding determination by the Swiss Federal Council exist for the country or recipient (e.g. the EU-US or Swiss-US Data Privacy Framework for certified recipients), or (b) the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914) with the amendments required for Switzerland have been concluded and any necessary supplementary measures implemented.
- Netgen states the basis of every third-country transfer in Annex 3.
§7 Assistance to the Customer
- Netgen assists the Customer with appropriate measures in responding to data-subject requests (Art. 12–23 GDPR; Art. 25–32 FADP), in particular access, rectification, erasure, restriction and data portability. Where possible, PIM Gate provides self-service functions for this.
- If a data subject contacts Netgen directly, Netgen forwards the request to the Customer without undue delay and does not answer it itself, except on instruction.
- Netgen assists the Customer with data-protection impact assessments, prior consultations of the supervisory authority and notification duties (Art. 32–36 GDPR; Art. 22–24 FADP) insofar as they concern Netgen's services.
- Assistance beyond self-service functions and legally mandatory cooperation may be charged by Netgen on a time-and-materials basis at the rates of the Main Agreement, unless the cause lies in a breach by Netgen.
§8 Personal data breaches
- Netgen notifies the Customer of a breach affecting Customer Data (Art. 4(12) GDPR; "breach of data security" under Art. 5 lit. h FADP) without undue delay and at the latest within 48 hours of becoming aware of it.
- The notification contains, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken and proposed, and a contact person. Missing information is supplied by Netgen as soon as it is available.
- Netgen takes immediate measures to contain and remedy the breach and documents the incident.
- Notifications to supervisory authorities or data subjects are the Customer's responsibility. Netgen makes them only on instruction.
§9 Evidence and audits
- On request, Netgen makes available to the Customer the information necessary to demonstrate compliance with this DPA. Valid ISO/IEC 27001 and 42001 certificates, audit reports and the current TOM description in particular serve as evidence.
- Where such evidence is insufficient in an individual case, the Customer may carry out an audit on site or remotely, or have it carried out by an auditor bound to confidentiality who is not a competitor of Netgen. Audits are announced at least 30 days in advance, take place during business hours and without disproportionate disruption of operations.
- One audit per calendar year is free of charge for the Customer. Further audits are borne by the Customer on a time-and-materials basis, unless they reveal a material breach by Netgen or are occasioned by an incident under §8.
- The audit rights of supervisory authorities remain unaffected.
§10 Deletion and return
- After the end of the Main Agreement the Customer may export its data for 30 days via the export functions or the API in a common format.
- Thereafter Netgen deletes all Customer Data, including copies, unless a statutory retention obligation applies. Data in backups is overwritten within 30 days in the regular rotation cycle and is no longer actively processed until then.
- Netgen confirms deletion in text form on request.
- During the term, Netgen deletes or rectifies Customer Data on instruction where the Customer cannot do so itself in the platform.
§11 Obligations of the Customer
- The Customer is responsible for the lawfulness of the processing, in particular for the legal basis and for informing data subjects.
- The Customer manages user accounts, roles and permissions in PIM Gate on its own responsibility and protects its credentials and API keys.
- The Customer does not transmit special categories of personal data (Art. 9 GDPR; sensitive personal data under Art. 5 lit. c FADP) unless agreed in writing beforehand.
- The Customer informs Netgen without undue delay if it detects errors or irregularities in the processing.
§12 Liability
- Liability is governed by the provisions of the Main Agreement, including any limitations of liability agreed there, to the extent permitted by law.
- Liability towards data subjects under Art. 82 GDPR and mandatory statutory liability remain unaffected. Internally, each party bears the damage attributable to its own breach.
§13 Term and final provisions
- This DPA enters into force upon signature or acceptance as part of the Main Agreement and ends with it. Obligations that by their nature continue (confidentiality, deletion, evidence) survive termination.
- Amendments require text form. Netgen may adapt this DPA where changes in law or regulatory requirements so require; the Customer is informed at least 30 days in advance.
- Governing law and place of jurisdiction follow the Main Agreement; unless agreed otherwise there, Swiss law applies to the exclusion of conflict-of-law rules and the place of jurisdiction is Zürich. Mandatory provisions of the GDPR and the BDSG remain unaffected for customers in the EU.
- Should a provision be invalid, the remainder remains valid. The parties replace the invalid provision with one that comes closest to its purpose and the legal requirements.
- Annexes 1–3 form part of this DPA.
Signatures
| For the Customer | For Netgen Switzerland AG |
|---|---|
| Place, date: | Zürich, date: |
| Name, function: | Christian Paredes, Managing Director |
| Signature: | Signature: |
Annex 1 – Description of the processing
| Item | Description |
|---|---|
| Purpose | Operation of the SaaS platform PIM Gate: import, normalisation and provision of product data and assets in portals; user and permission management; interfaces; AI-assisted tagging and translation; support, troubleshooting, backup |
| Nature of processing | Collection, storage, indexing, querying, matching, transmission to portal users, logging, deletion |
| Data subjects | Employees of the Customer; users of the portals at the Customer's customers, suppliers, dealers and sales partners; contact persons named in product, ERP or CRM data |
| Categories of data | Master data (name, company, function); contact data (e-mail, phone); credentials (username, password hash, SSO identifiers, API keys); roles and permissions; log and usage data (IP address, timestamps, audit log); content in product data, documents and assets insofar as it relates to persons |
| Special categories | None intended |
| Storage location | Hetzner data centre, Falkenstein (DE); backups at Hetzner at a separate location in Germany |
| Retention | For the term of the Main Agreement; audit logs 12 months, up to 10 years at the Customer's request; deletion pursuant to §10 |
Annex 2 – Technical and organisational measures
Netgen is certified to ISO/IEC 27001, ISO 9001 and ISO/IEC 42001. Details are documented in the ISMS and evidenced to the Customer on request pursuant to §9.
| Area | Measures |
|---|---|
| Physical access | Hosting in an ISO 27001-certified data centre with access control, video surveillance, 24/7 security staff; offices with locking system |
| System access | Individual accounts; strong passwords; two-factor authentication for administrative access; SSH keys; IP restriction for server access; automatic lock-out |
| Data access | Role-based permission model in the platform ("permission-aware"); need-to-know principle for staff; regular permission reviews; logging of administrative access |
| Separation | Tenant isolation at database-schema level; separate test/stage tenants; separate development and production systems |
| Transfer | Encryption in transit (TLS 1.2+); SFTP for file transfer; API access only with key/token |
| Input control | Audit log of all actions in the platform with user and timestamp |
| Availability | Daily snapshots; off-site backups at a separate location; monitoring; restore tests at least annually; hosting provider's firewall and DDoS protection |
| Encryption at rest | Encrypted backups; disk encryption in accordance with the ISMS policy |
| Organisation | Confidentiality undertaking and training of all staff; incident-response process; patch and vulnerability management; review of sub-processors; annual internal and external audits |
| AI | No training with Customer Data; AI services used only after a risk assessment under ISO/IEC 42001; AI output labelled as suggestions |
Annex 3 – Approved sub-processors
| Sub-processor | Seat | Service | Place of processing | Basis |
|---|---|---|---|---|
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen | Germany | Hosting, data centre, backups | Falkenstein (DE), backups Germany | EU, Art. 28 GDPR |
| Netgen d.o.o. | Croatia | Development, operations, support | Zagreb / Osijek (HR) | EU, intra-group DPA |
| Resend, Inc. | USA | Delivery of system e-mails (invitations, notifications) | EU region (Ireland) | EU Standard Contractual Clauses with Swiss amendments |
| Anthropic, PBC | USA | AI language models for tagging and translation; no training with Customer Data | USA | EU-US / Swiss-US Data Privacy Framework, EU Standard Contractual Clauses |
Changes to this list are announced at least 30 days in advance pursuant to §5. The current version is this page.