Data Processing Agreement (DPA)
This DPA supplements the Eichi.me product contract where Eichi.me processes personal data on behalf of the customer.
1. Subject matter and roles
This Data Processing Agreement (DPA) supplements the Eichi.me product contract where Eichi.me processes personal data contained in the customer's hosted websites, databases, mailboxes, files, applications, backups or technical logs solely on behalf of the customer. The customer acts as controller or, where applicable, as processor for another controller; Eichi.me acts as processor.
2. Duration, nature and purpose
Processing lasts for the term of the relevant hosting service plus the technically and legally required deletion/backup run-off period. Processing operations may include hosting, storage, transmission, retrieval, organisation, technical administration, security monitoring, troubleshooting, support, backup/restoration and deletion. Processing is limited to providing, securing, maintaining, supporting and terminating the contracted services and to documented customer instructions, unless applicable law requires otherwise.
3. Data subjects and categories of data
Depending on the customer's use, data subjects may include the customer's website visitors, users, employees, contractors, members, suppliers, business contacts and end customers. Data may include names, contact/account data, communications, website/form content, files, database records, email content, IP/log data, identifiers and other information uploaded or generated by the customer. The customer must assess whether special-category or otherwise particularly sensitive data may lawfully be hosted and whether additional safeguards are required.
4. Instructions, confidentiality and access
Eichi.me processes the data only on documented instructions from the customer, including instructions inherent in use of the control panel, support system and configured services. Persons authorised to access customer data are subject to confidentiality obligations and access is limited according to role and necessity. If an instruction appears to violate applicable data-protection law, Eichi.me may inform the customer and suspend the affected instruction where legally appropriate.
5. Technical and organisational measures
Eichi.me applies risk-appropriate measures designed to protect confidentiality, integrity, availability and resilience. These include account and permission controls, password hashing, secure session/CSRF controls, server-side API credentials, transport encryption where supported, logging of security-relevant actions, patch/update processes, logical separation of customer resources, backup controls and restoration procedures. Measures may evolve with technology and risk provided the overall protection level is not materially reduced.
6. Sub-processors and international processing
The customer grants general authorisation for sub-processors necessary to operate the service. The current hosting infrastructure is provided by velia.net at St. Louis, Missouri, USA. Additional technical sub-processors may be used for infrastructure, security, backup or support where configured. Eichi.me will impose appropriate data-protection obligations and remains responsible for its processor obligations. Material changes to sub-processors will be communicated where required so the customer can raise substantiated data-protection objections. International processing is handled subject to applicable Swiss and, where applicable, EU transfer requirements.
7. Assistance to the customer
Taking into account the nature of processing and the information available, Eichi.me provides reasonable assistance with data-subject requests, security obligations, personal-data-breach assessment, data-protection impact assessments and supervisory-authority enquiries. The customer remains responsible for deciding how to respond to data-subject requests and for the lawfulness of its processing.
8. Personal-data breaches
Eichi.me notifies the customer without undue delay after becoming aware of a relevant personal-data breach affecting data processed on the customer's behalf and provides available information reasonably required for the customer's assessment and notification duties. Notifications do not constitute an admission of fault or liability.
9. Return, export and deletion
The customer is responsible for exporting required content before contract termination. After termination Eichi.me may delete customer content and related service data in accordance with the contract, configured backup cycles and legal retention duties. Data contained in existing backups may remain until the ordinary rotation cycle removes or overwrites it and will not be used for ordinary production purposes.
10. Evidence and audits
Eichi.me provides information reasonably necessary to demonstrate compliance with this DPA. Audits must be proportionate, protect other customers and trade/security secrets, and should normally use documentation or remote evidence before an on-site inspection. Costs caused by exceptional customer-specific audits may be charged where legally permissible and agreed in advance.
11. Customer obligations
The customer is responsible for having a lawful basis for the personal data it places on the service, for giving required privacy information, for configuring access rights appropriately and for issuing lawful instructions. The customer must not instruct Eichi.me to process data unlawfully.
12. Priority and legal framework
This DPA forms part of the product contract and is intended to address in particular Article 9 of the Swiss Federal Act on Data Protection and, where applicable, Article 28 GDPR. Mandatory law prevails. In the event of a conflict concerning commissioned processing, this DPA takes precedence over general product terms to the extent of that conflict.
Version: 2026-08-24-v1