This Data Processing Agreement ("DPA") forms part of the Master Subscription Agreement ("MSA") between the Customer and relyd. It applies to all personal data that relyd processes on behalf of the Customer when providing the Service ("Customer Personal Data"). Terms defined in the MSA have the same meaning here.
"Data Protection Law" means all laws applicable to the processing of Customer Personal Data under this DPA, in particular:
- Regulation (EU) 2016/679 (GDPR);
- the GDPR as retained in UK law (UK GDPR) together with the UK Data Protection Act 2018;
- the Swiss Federal Act on Data Protection (FADP);
- to the extent applicable, US state privacy laws.
1. Roles and scope
1.1 The Customer is the controller of Customer Personal Data. relyd is its processor. Where the Customer itself acts as a processor for a third party, relyd acts as its sub-processor. In that case the Customer shall ensure that its instructions are consistent with those of its controller.
1.2 The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are described in Annex 1.
1.3 This DPA does not apply to personal data for which relyd is itself the controller. Examples are the account, billing and security data of the Customer and its Users; the Privacy Policy covers that data.
2. Instructions
2.1 relyd processes Customer Personal Data only on the documented instructions of the Customer, unless required to do so by law. In that case relyd informs the Customer before processing, unless the law prohibits such information.
2.2 The Customer's instructions are, in full:
- the MSA and this DPA;
- the Customer's configuration and use of the Service, including the modules and features it activates;
- any further written instructions agreed between the parties.
2.3 relyd will inform the Customer without undue delay if it considers that an instruction infringes Data Protection Law. relyd may suspend carrying out the instruction until it is confirmed or amended.
2.4 relyd does not:
- sell Customer Personal Data;
- use it for its own purposes;
- use it for advertising;
- use it to train artificial-intelligence models;
- combine it with other data, except as necessary to provide the Service.
3. Confidentiality
relyd ensures that all persons authorised to process Customer Personal Data are bound by confidentiality obligations, contractually or by law, and are trained in data protection. Access is granted only to the extent necessary for their task.
4. Security
4.1 relyd implements the technical and organisational measures described in Annex 2 to ensure a level of security appropriate to the risk (Art. 32 GDPR).
4.2 relyd may update these measures as technology develops, provided the overall level of security is not reduced.
4.3 The Customer is responsible for the secure use of the Service within its sphere. This includes:
- assigning permissions;
- enabling two-factor authentication;
- protecting its devices and credentials;
- securing the connections to third-party services it chooses.
5. Subprocessors
5.1 The Customer grants relyd a general authorisation to engage subprocessors. The subprocessors engaged at the time of conclusion are listed at legal.relyd.co/subprocessors. That list forms part of this DPA.
5.2 relyd imposes on each subprocessor, by written contract, data protection obligations that offer at least the level of protection of this DPA. relyd remains responsible to the Customer for the performance of its subprocessors.
5.3 relyd will notify the Customer at least thirty (30) days before engaging a new subprocessor or replacing one. Notification is given by e-mail to the account owner or to a contact the Customer designates, and by updating the list. Customers can also subscribe to updates at privacy@relyd.co.
5.4 The Customer may object to a new subprocessor on reasonable data protection grounds by written notice within this period. The parties will discuss the objection in good faith. If relyd cannot offer a reasonable alternative, the Customer may terminate the affected subscription with effect from the date the new subprocessor is engaged. It will receive a pro-rata refund of prepaid fees.
5.5 In urgent cases, for example to maintain security or availability, relyd may engage a subprocessor with shorter notice. It will inform the Customer without undue delay; section 5.4 applies accordingly.
5.6 Services that the Customer itself connects and contracts for are not relyd subprocessors. Examples are its own e-mail accounts, Google or Microsoft accounts, shops, carriers, payment providers, and AI providers used with its own API key.
6. International transfers
6.1 relyd hosts the Service primarily in Germany. It also uses infrastructure in the United Kingdom. Transfers to subprocessors outside the EU, the EEA, the UK and Switzerland take place only in accordance with Data Protection Law, as described in Annex 3.
6.2 To the extent the Customer transfers Customer Personal Data to relyd Inc. or another relyd company outside the EU, the EEA, the UK or Switzerland, the standard contractual clauses in Annex 3 apply.
7. Assistance
7.1 Data subject requests. The Service allows the Customer to access, rectify, export and delete Customer Personal Data. If relyd receives a request from a data subject concerning Customer Personal Data, it will forward it to the Customer without undue delay and will not respond itself, unless instructed. relyd assists the Customer, where the Customer cannot do so itself, with appropriate technical and organisational measures.
7.2 Other obligations. Taking into account the information available to it, relyd assists the Customer in complying with its obligations regarding:
- security (Art. 32 GDPR);
- notification of personal data breaches (Art. 33–34 GDPR);
- data protection impact assessments and prior consultation (Art. 35–36 GDPR).
7.3 Costs. Assistance that goes beyond the functions of the Service and is not caused by a breach by relyd may be charged at the rates in the Terms of Service (Professional Services).
8. Personal data breaches
8.1 relyd will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, in any case within forty-eight (48) hours.
8.2 The notification will include, as far as then known:
- the nature of the breach;
- the categories and approximate number of data subjects and records concerned;
- the likely consequences;
- the measures taken or proposed;
- a contact point.
Information that is not yet available will be provided in phases as it becomes available.
8.3 relyd will take the measures necessary to contain the breach and mitigate its effects. It will support the Customer in its notifications to authorities and data subjects.
8.4 A notification is not an acknowledgement of fault or liability.
9. Deletion and return
9.1 During the subscription the Customer can export and delete Customer Personal Data using the functions of the Service.
9.2 After the end of the subscription, relyd deactivates the Workspace. relyd deletes the Customer Personal Data from its active systems thirty (30) days after the end of the subscription, unless the Customer requests an earlier deletion or an export within this period. Documents in the retention archive are handled as set out in section 3 of the Product-Specific Terms; a retained archive is deleted free of charge on the Customer's written request.
9.3 Copies in encrypted backups are not accessed after deletion from the active systems, other than to restore the Service after an incident. They expire automatically according to the backup cycle described in Annex 2, at the latest twelve (12) months after the end of the subscription.
9.4 The obligation to delete does not apply where relyd is legally required to retain data. In that case relyd keeps the data confidential and processes it only for that purpose.
9.5 relyd confirms the deletion in writing on request.
10. Audits
10.1 relyd makes available to the Customer the information necessary to demonstrate compliance with this DPA. This includes:
- this DPA and its annexes;
- the subprocessor list;
- a description of its security measures;
- on request, the results of its most recent security reviews in summary form;
- where available, certifications or audit reports of its hosting providers.
10.2 If this information is not sufficient, or if a supervisory authority requires it, the Customer may carry out an audit, or have it carried out by an independent auditor bound to confidentiality, under the following conditions:
- at most once per calendar year, unless following a personal data breach;
- with at least thirty (30) days' written notice;
- during normal business hours;
- without disproportionate disruption of operations;
- without access to other customers' data.
Audits of subprocessors are carried out by means of their certifications and reports.
10.3 Each party bears its own costs of an audit. relyd may charge reasonable costs for audit support beyond two (2) working days, unless the audit reveals a material breach by relyd.
11. Liability and duration
11.1 The limitations of liability in the MSA apply to this DPA, to the extent permitted by Data Protection Law. They do not limit the rights of data subjects under Data Protection Law.
11.2 This DPA remains in force for as long as relyd processes Customer Personal Data.
12. Swiss and UK specifics
12.1 For processing subject to the FADP, references to the GDPR are to be read as references to the corresponding provisions of the FADP. The supervisory authority is the Federal Data Protection and Information Commissioner.
12.2 For processing subject to the UK GDPR, references to the GDPR are to be read as references to the UK GDPR. The supervisory authority is the Information Commissioner.
Annex 1 – Description of the processing
Subject matter and duration. The provision of the relyd Service to the Customer during the subscription and the subsequent deletion period (section 9).
Nature and purpose. The following operations, performed through the relyd business software platform:
- hosting, storage and backup;
- display, search and analysis;
- transmission, for example sending e-mails and messages on the Customer's behalf;
- generation of documents such as invoices, payslips and contracts;
- deletion.
These operations serve the business processes the Customer carries out with the modules it activates, for example:
- customer relationship management;
- sales, invoicing and accounting;
- purchasing and inventory;
- human resources and payroll;
- projects and tasks;
- file storage;
- customer support;
- quality management;
- communication (e-mail, chat, direct messages);
- optional artificial-intelligence features (Annex 1, last section).
Categories of data subjects, as determined by the Customer:
- the Customer's employees, applicants and contractors;
- the Customer's customers, prospects and their contact persons;
- suppliers and service providers and their contact persons;
- users of the customer portal and of public forms or links (for example proposal and signature links);
- other persons whose data the Customer enters, such as correspondents in connected mailboxes.
Types of personal data, as determined by the Customer:
- identification and contact data;
- professional data;
- contract, order and transaction data;
- invoicing, payment and bank details;
- communication content (e-mails, messages, chat, attachments);
- documents and files;
- HR data, such as employment details, working time, absences, salary and payroll data, performance and training records, and identity and social-insurance numbers where required by law;
- log-in and usage data of Users;
- electronic signature records (e-mail address, time, IP address, one-time-code verification).
Special categories of data. Special categories of personal data (Art. 9 GDPR) and sensitive personal data (Art. 5(c) FADP) may be processed only within the limits of the Sensitive Data Terms. An example is health-related absence information in HR, to the extent required by employment law.
Artificial-intelligence features. If the Customer uses optional AI features, relyd transmits the content required for the specific request to the AI provider listed as a subprocessor. Examples are the text to be summarised, an e-mail to be drafted, or an invoice document to be read. The provider processes the content to generate the result. Under its contract with relyd it may not use the content to train its models. The Customer can refrain from using AI features, or disable them for its Workspace, without affecting the rest of the Service. If the Customer uses its own AI provider key, the provider is engaged by the Customer (section 5.6).
Annex 2 – Technical and organisational measures
Physical security. The Service runs exclusively in data centres of professional hosting providers (see subprocessor list), with access control, video surveillance, fire protection and redundant power supply. relyd operates no servers of its own on its premises.
Network and transport security.
- All connections to the Service are encrypted with TLS.
- Public traffic passes through a network protection service with web application firewall, DDoS protection and load balancing.
- Application servers accept HTTPS connections only from that service.
- Plain HTTP requests are redirected to HTTPS.
- Databases are not reachable from the internet. The application servers reach them only through encrypted tunnels.
Tenant separation.
- Customer data is kept separate per workspace; new workspaces receive their own database.
- In addition, the application restricts every data access to the customer's own workspace.
- Real-time communication data (chat, messages, mailbox mirrors) is accessible only to signed-in members of the respective workspace, and e-mail data only to the respective User.
- Automated tests check the separation.
Access control (users).
- Personal accounts with role-based permissions.
- Passwords are stored as bcrypt hashes.
- Two-factor authentication by authenticator app or six-digit e-mail code, with limits on wrong attempts and temporary locks.
- Sign-in with Google or Microsoft is bound to the verified provider identity.
- Automatic sign-out after inactivity.
- Protection against cross-site request forgery.
Access control (relyd staff and systems).
- Administrative server access only via SSH keys (no passwords).
- Access limited to authorised personnel.
- Firewalls and automatic blocking of repeated failed attempts.
- Production credentials are kept out of source code and rotated regularly.
- Access by relyd support to a customer workspace is logged.
Encryption.
- Data is encrypted in transit.
- Backups are encrypted before leaving the server, with a key whose secret part is not stored on any server.
- Stored access credentials for customer-connected systems (for example mailbox passwords and API tokens) and two-factor secrets are encrypted at application level.
- Files, the retention archive and backups in object storage are additionally encrypted at rest by the storage provider.
Availability and resilience.
- Hourly database backups.
- Encrypted copies are stored in a separate data centre region, protected against deletion and modification (write-once storage):
- hourly copies for 7 days;
- daily copies for 30 days;
- monthly copies for 12 months.
- Regular restore tests.
- Monitoring of availability.
- Load balancing across more than one application server.
Integrity and input control.
- Audit logs of relevant changes and administrative actions.
- Validation of inputs.
- Protection against script injection.
- Controlled deployment process with automated tests and security checks before every release.
Separation of purposes. Customer Personal Data is processed only for the provision of the Service. Development and testing take place in a separate environment that does not use customer data.
Organisational measures.
- Confidentiality obligations and data protection training for staff.
- Weekly internal security review.
- Documented handling of security incidents.
- Monthly rotation of credentials and review of server hardening.
- Selection and contractual obligation of subprocessors.
Annex 3 – International transfers
-
Standard contractual clauses. Where a transfer requires appropriate safeguards, the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 apply. Module 2 applies to transfers from the Customer (controller) to relyd (processor). Module 3 applies where the Customer is a processor, and between relyd and its subprocessors. The following options apply:
- Clause 7 (docking) applies;
- Clause 9(a), option 2 (general authorisation), with the notice period in section 5.3;
- Clause 11, the optional wording does not apply;
- Clause 17: the law of Ireland;
- Clause 18: the courts of Ireland.
Annex I of the clauses is completed by Annex 1 of this DPA and Annex II by Annex 2.
-
United Kingdom. For transfers subject to the UK GDPR, the International Data Transfer Addendum issued by the Information Commissioner applies in addition. Table 4 is completed so that both parties may end the Addendum.
-
Switzerland. For transfers subject to the FADP:
- the standard contractual clauses apply with the adaptations recognised by the FDPIC;
- references to the GDPR are read as references to the FADP;
- the FDPIC is the competent authority;
- "Member State" includes Switzerland, so that data subjects in Switzerland can enforce their rights there.
-
Adequacy. Where a recipient is located in a country with an adequacy decision, no further safeguards are required. The same applies where a recipient is certified under a recognised framework such as the EU-US Data Privacy Framework and its UK and Swiss extensions, for as long as the decision or certification is valid.
-
Additional measures. relyd assesses the laws of the recipient countries and applies additional measures where necessary. These include:
- encryption in transit;
- data minimisation;
- challenging disproportionate requests by authorities.