These terms set out which particularly sensitive data the Customer may process in the relyd Service, and under which conditions. They form part of the Master Subscription Agreement ("MSA"). They apply in addition to the Data Processing Agreement ("DPA").
1. Principle
The Service is designed for business administration: CRM, sales, finance, purchasing, inventory, HR, projects, files, support and quality. The Customer decides which data it processes. It is responsible for having a legal basis, for informing data subjects and, where required, for carrying out a data protection impact assessment.
2. Permitted sensitive data (with conditions)
2.1 Employee data. The Customer may process the special categories of personal data and sensitive personal data of its employees and applicants that are necessary for the administration of the employment relationship and for compliance with employment, social-security and tax law. Examples are:
- sickness absences, without diagnoses;
- information required for payroll, such as religious affiliation where church tax applies, or disability status for statutory entitlements;
- identity and social-insurance numbers.
The Customer shall restrict access to such data through the permission settings of the Service.
2.2 Password vault. The Customer may store access credentials for its own customers' systems in the password vault of the CRM module. The Customer shall:
- grant access only to Users who need it;
- require two-factor authentication for these Users;
- delete credentials that are no longer needed.
2.3 Identity documents. Copies of identity documents may be stored only where the Customer is legally required, or has a legitimate need, to verify identity. Access must be restricted.
3. Prohibited data
Unless relyd has agreed otherwise in writing, the Customer shall not store or process the following in the Service:
- (a) payment card data, i.e. full card numbers, security codes or magnetic-stripe data. Card payments must be processed through a payment service provider connected to the Service, which stores such data itself;
- (b) medical records, such as diagnoses, treatment and patient files, beyond the absence information permitted under section 2.1;
- (c) genetic data and biometric data used to uniquely identify a person, such as fingerprint or facial-recognition templates;
- (d) data on criminal convictions and offences, unless the Customer is legally required to process it, for example a certificate of good conduct where legally required;
- (e) classified information of a state;
- (f) data whose processing is subject to specific certification or localisation requirements that the Service does not meet. Examples are health data subject to specific hospital or health-insurance regulations, and data of public authorities subject to specific cloud requirements.
4. Artificial intelligence
The Customer shall not use the optional AI features of the Service to make decisions based solely on automated processing that produce legal or similarly significant effects for individuals. This applies in particular to decisions on hiring, promotion, dismissal or pay. Results of AI features must be reviewed by a person before they are used for such decisions. The Customer is responsible for complying with applicable rules on artificial intelligence, in particular the EU Artificial Intelligence Act.
5. Electronic signatures
Documents signed through the Service, such as proposals, contracts and agreements, are signed with a simple electronic signature. The signatory confirms their identity with a one-time code sent to their e-mail address. The Service records the time, the e-mail address and the IP address.
This is not a qualified electronic signature within the meaning of the EU eIDAS Regulation or the Swiss Federal Act on Electronic Signatures (ZertES). It does not satisfy legal requirements for the written form, for example under Art. 13–14 of the Swiss Code of Obligations, or for notarisation. The Customer is responsible for choosing a suitable form of signature for the transaction concerned.
6. Consequences of a breach
6.1 If the Customer processes prohibited data, relyd may require it to delete the data or to take other measures within a reasonable period. In urgent cases relyd may block access to the data concerned.
6.2 The Customer shall indemnify relyd against third-party claims, fines and reasonable costs arising from a breach of these terms by the Customer. This indemnity is not subject to the liability cap in section 13.2 of the MSA.