This Data Processing Agreement (“DPA”) supplements the Master Subscription Agreement (“MSA”) and the General Terms of Sale held between relyd (“Provider”, “Processor”) and the contracting corporate entity (“Customer”, “Controller”). This DPA governs the systemic processing of all third-party Personal Data hosted, stored, or processed within the Customer's isolated databases on the relyd Cloud Platform or during infrastructure maintenance cycles.
1. Scope, Interpretation, and Legal Status
1.1 Contractual Roles: The parties explicitly acknowledge and agree that regarding the processing of Personal Data within the Customer's hosted environment, the Customer operates strictly as the Data Controller (retaining full ownership, structural control, and legal liability over the data points). The Provider operates exclusively as the Data Processor, acting solely upon the automated configurations and explicit written instructions of the Customer.
1.2 Statutory Compliance: Both parties covenant to maintain strict compliance with applicable data protection legislation throughout the duration of the subscription, including the Swiss Federal Act on Data Protection (FADP), the European General Data Protection Regulation (GDPR), the United Kingdom General Data Protection Regulation (UK GDPR) read in conjunction with the Data Protection Act 2018 (DPA 2018), and applicable United States federal and state data privacy laws (including, to the extent applicable, the California Consumer Privacy Act as amended).
1.3 Categories of Data Subjects and Data Classes: The Personal Data injected into the platform is determined solely by the Customer and typically encompasses information regarding their employees, clients, suppliers, and transactional counter-parties. This includes contact indices, financial transactions, operational metadata, and localized business telemetry.
2. Operational Processing Protocols
The Provider binds itself to execute all data handling operations strictly under the following operational boundaries:
a) Instruction-Bound Processing: The Provider shall process Personal Data exclusively to fulfill its contractual service delivery obligations as outlined in the MSA. It shall not process, manipulate, or analyze Customer data for independent commercial, profiling, or monetization purposes unless mandated to do so by applicable Swiss, European, United Kingdom, or United States statutory law.
b) Boundary Notifications: If the Provider believes that an operational instruction delivered by the Customer violates data protection directives or creates architectural compliance risks, it shall notify the Customer immediately.
3. Technical and Organizational Measures (TOMs)
The Provider guarantees the continuous implementation and auditing of premier technical and organizational security controls designed to safeguard Customer data assets against unauthorized access, accidental alteration, unlawful disclosure, or malicious exfiltration. These controls include:
a) Cryptographic Isolation: Full cryptographic encryption of all client data assets at rest utilizing industry-standard encryption methods, paired with active 256-bit TLS/HTTPS transmission security for all data paths in transit.
b) Absolute Tenant Separation: Architectural enforcement of strict tenant isolation within our multi-tenant database backbone, rendering any cross-database leakage or unauthorized environment intersection impossible.
c) Infrastructure Resilience: Deployment of cloud instances exclusively within Tier-III certified or equivalent high-resilience data centres featuring comprehensive N+1 physical and electrical redundancy, automatic fire suppression, and biometric perimeter access validation.
4. Personnel Confidentiality Assurances
The Provider covenants that all internal systems engineers, helpdesk personnel, and authorized contractors who are granted access to underlying infrastructure nodes hosting Customer data are contractually bound by comprehensive, legally binding non-disclosure agreements and strict professional confidentiality obligations.
5. Management of Subprocessors
5.1 Authorized Engagement: The Customer grants a general written authorization to the Provider to engage third-party infrastructure hosts, routing networks, and cloud backup providers (“Subprocessors”) to maintain platform stability and performance.
5.2 Contractual Alignment: The Provider guarantees that all engaged Subprocessors are bound by written data protection frameworks that enforce technical security obligations at least as stringent as those outlined within this DPA.
5.3 Notification of Structural Changes: The Provider maintains an active, transparent directory of primary infrastructure Subprocessors (such as OVHcloud, Google Cloud, and Scaleway) within its published Privacy Policy. The Provider will communicate any planned structural modifications or additions to this directory via administrative control panel updates.
6. Incident Response and Breach Notification
In the event of a confirmed, verified security breach resulting in the accidental, unauthorized, or unlawful access, alteration, or exfiltration of the Customer’s hosted Personal Data, the Provider shall:
a) Notify the Customer’s designated data protection contact person without undue delay (and in any case, within 48 hours of confirmation).
b) Deliver comprehensive technical parameters regarding the incident, including affected database scopes, estimated impact metrics, and immediate remediation countermeasures deployed.
c) Cooperate diligently with the Customer’s legal and technical teams to mitigate reputational or operational exposure.
7. Audit Framework and Regulatory Verification
7.1 Compliance Documentation: The Provider shall make available to the Customer all technical documentation and certifications reasonably required to demonstrate compliance with this DPA.
7.2 Structural Inspection Rights: The Provider agrees to contribute reasonably to independent security audits or technical infrastructure inspections mandated directly by the Customer, provided that such reviews are conducted with at least thirty (30) days advance written notice, executed during standard business hours, restricted to once per calendar year, and performed under strict confidentiality constraints so as not to compromise the security of other tenants.
8. Systematic Data Return and Permanent Deletion
8.1 Post-Termination Grace Period: Upon the formal termination, expiration, or dissolution of the underlying subscription contract, the live database environment is systematically deactivated and held in a secure state for an operational grace period of twenty-one (21) calendar days, during which the Customer may export their data assets.
8.2 Definitive Purge: Upon the expiry of the 21-day grace period, the production database is permanently and securely purged from the Provider's active production nodes.
8.3 Backup Erasure Lifecycle: Due to the immutable and highly secured nature of sequential system backup loops, historical fragments of the purged database may persist within encrypted backup systems for a maximum duration of twelve (12) months, until they are automatically and completely overwritten. The Provider covenants not to interact with or access these backup fragments for any operational purpose during this retention cycle.