Data Processing Agreement (DPA)
Agreement regarding the processing of personal data on behalf of another party pursuant to Art. 9 FADP and Art. 28 GDPR – between Audienzz AG and the Client in connection with the use of adconsole.
Background and purpose
Under the main agreement entered into by the Parties, Audienzz will process personal data of the Client. This DPA governs the rights and obligations of the Parties in relation to that processing.
Audienzz operates the adconsole platform, which records and manages the Client's advertising orders by way of an automated workflow. In the course of this activity, Audienzz gains insight into, or access to, the Client’s personal data, or processes such data on the Client’s behalf.
The Parties enter into this Data Processing Agreement to satisfy the legal requirements governing the processing of personal data on behalf of another party pursuant to Art. 9 of the Swiss Federal Act on Data Protection (FADP) and, to the extent applicable, Art. 28 of Regulation (EU) 2016/679 (GDPR).
The subject matter, nature and scope of the data processing, as well as the categories of data subjects and personal data concerned, are described in Appendix 1. The technical and organisational measures (TOMs) are set out in Appendix 2. The approved sub-processors are listed in Appendix 2.
1. Definitions and scope
1.1 The terms used in this DPA correspond to the definitions in the FADP and the GDPR. In particular, ‘personal data’ means any information relating to an identified or identifiable natural person, and ‘processing’ means any operation involving personal data.
1.2 The Client is the ‘controller’ of the data or ‘the owner of the data file’; Audienzz is the ‘processor’ or ‘data processor’ within the meaning of the abovementioned laws.
1.3 This DPA applies to all processing carried out by Audienzz on the Client’s behalf in connection with the main agreement and the use of adconsole, regardless of whether such processing was already ordered at the time the agreement was concluded or only at a later date.
2. Rights and obligations of the Client
2.1 The Client is responsible for assessing the lawfulness of the data processing and for protecting the rights of data subjects.
2.2 The Client shall generally issue instructions to Audienzz in writing (by email shall suffice). Verbal instructions must be confirmed in writing immediately.
2.3 The Client’s right to issue instructions shall be limited by the main agreement and this DPA. Where instructions result in additional effort on the part of Audienzz and exceed the agreed scope of services, this shall be separately compensated by the Client.
3. Rights and obligations of Audienzz
3.1 Audienzz processes personal data solely within the scope of this DPA and in accordance with the Client’s instructions. Processing by Audienzz for its own purposes is excluded, other than when such processing is necessary for the operation of the platform (e.g. logs, backups, security measures).
3.2 Whenever possible, Audienzz processes personal data in Switzerland or in Member States of the EU/EEA. Processing in third countries is permitted, providing an adequate level of data protection exists, or appropriate safeguards – in particular, the EU Standard Contractual Clauses and any necessary additional measures – have been agreed upon.
3.3 Audienzz undertakes to implement the technical and organisational measures described in Appendix 2 and to comply with them at all times. These measures may be further developed but must not fall below the level of protection described there. Material changes shall be documented and communicated to the Client.
3.4 Audienzz shall support the Client in ensuring the rights of data subjects are upheld. Requests for access, rectification or erasure shall be forwarded to the Client without delay; Audienzz shall proactively provide the information necessary for this purpose.
3.5 Audienzz shall provide the client with an appropriate level of support in conducting data protection impact assessments and in responding to enquiries from the relevant supervisory authorities.
3.6 Audienzz shall notify the Client of personal data breaches immediately upon becoming aware of them, providing the Client’s personal data is affected and the breach is likely to pose a risk to the data subjects concerned.
3.7 If the Client issues an instruction that, in Audienzz’s opinion, violates applicable data protection law, Audienzz shall notify the Client without delay and is entitled to suspend execution of the instruction until it is confirmed or amended.
3.8 Audienzz shall designate an internal or external Data Protection Officer and provide the Client with that person’s contact details. Current contact details are provided in Appendix 1.
3.9 Audienzz shall maintain a record of processing activities in accordance with the applicable legal requirements.
4. Sub-processors
4.1 The Client grants Audienzz general prior approval to engage the sub-processors listed in Appendix 2.
4.2 Audienzz shall notify the Client in writing (by email shall suffice) in a timely manner before engaging a new sub-processor or replacing an existing one. The Client may object, in writing, to the planned change within 30 days of receiving such notification, citing important data protection reasons.
If no objection is raised during this period, the new sub-processor shall be deemed approved.
4.3 If the Client raises a justified objection, the Parties shall work together in good faith to find a solution. If no agreement is reached within 30 days, either Party may terminate, on an extraordinary basis, the portion of the main agreement affected by the change.
4.4 Audienzz shall require each sub-processor, through a written contract, to comply with the same data protection obligations as agreed in this DPA, including the right to audit under Section 5.
4.5 Sub-processors shall be domiciled, and process personal data, whenever possible in Switzerland or in a Member State of the EU/EEA, or in a country recognised as offering an adequate level of data protection as determined by the competent authority.
4.6 Audienzz is liable to the Client, to the same extent as it is for its own actions, for compliance by the engaged sub-processor with data protection obligations.
5. Data security, confidentiality and auditing
5.1 Audienzz shall ensure a level of protection appropriate to the risk through the technical and organisational measures described in Appendix 2.
5.2 Audienzz shall require all individuals authorised to process the Client’s personal data, before commencing their work, to give a written undertaking of confidentiality. This obligation continues to apply after termination of the relevant employment relationship.
5.3 Audienzz shall review the technical and organisational measures on a regular basis and as circumstances require, adapting them where necessary.
5.4 The Client is entitled to verify compliance with this DPA. Audienzz shall support the Client in doing so, in particular by providing the following:
- current documentation of the technical and organisational measures
- audits and certifications (where available) answers to specific questions regarding the level of protection.
5.5 Onsite inspections shall be conducted with reasonable advance notice and during normal business hours. They must not unreasonably disrupt Audienzz’s business operations. Third parties engaged by the Client for this purpose may not be competitors of Audienzz and shall be bound by confidentiality obligations.
5.6 Audit costs are generally borne by the Client. Where an audit identifies significant deficiencies for which Audienzz is responsible, Audienzz shall bear the direct costs of the follow-up review.
6. Term, termination and return of data
6.1 This DPA shall enter into force upon signature by both Parties and remains in effect for the duration of the main agreement. It terminates automatically upon termination of the main agreement.
6.2 Obligations to protect personal data continue to apply beyond the end of the agreement, until all personal data has been returned to the Client or deleted in a manner compliant with data protection law. Agreed confidentiality obligations continue to apply for an indefinite period.
6.3 Upon termination of the main agreement, Audienzz shall delete the personal data processed on the Client’s behalf in accordance with the applicable deletion policy, or return it to the Client, providing no statutory retention obligations or legitimate interests prevent this. Data contained in backups shall be deleted or overwritten as part of the regular backup cycle and shall not be used productively in the meantime.
7. Liability
7.1 Audienzz is liable to the Client for damage arising from a breach of this DPA in accordance with the applicable statutory provisions and subject to the following provisions.
7.2 To the extent permitted by law, Audienzz's liability is limited to the total amount of compensation actually paid by the Client under the main agreement during the twelve months preceding the event giving rise to the damage. This limit does not apply in cases of wilful misconduct or gross negligence, nor to damage resulting from injury to life, limb or health.
7.3 Vis-à-vis data subjects, each Party is liable in accordance with the applicable statutory provisions. As between the Parties, each Party is liable for damage caused by its own fault.
7.4 To the extent permitted by law, claims for damages become time-barred twelve months after the claimant becomes aware of the damage and of the party liable to pay compensation.
8. Final provisions
8.1 Should any provision of this DPA be or become invalid, in whole or in part, the remaining provisions shall remain unaffected. The Parties shall replace the invalid provision with a valid one that most closely reflects the economic purpose of the invalid provision.
8.2 In the event of a conflict between this DPA and the main agreement, the provisions of this DPA shall prevail with regard to the processing of personal data.
8.3 Amendments and additions to this DPA must be made in writing; this also applies to the waiver of this written-form requirement. An email bearing a qualified electronic signature, or confirmed by countersignature, shall suffice.
8.4 This DPA is governed by Swiss law, excluding its conflict-of-rules laws under the Swiss Federal Act on Private International Law and excluding the UN Convention on Contracts for the International Sale of Goods. The exclusive place of jurisdiction is Zurich.
Appendix 1: Object of the data processing
Description of the nature, purpose and scope of the data processing, as well as the categories of data subjects and data, pursuant to Art. 9 FADP and Art. 28(3) GDPR.
A. Purpose of the data processing
The personal data is processed for the workflow-based handling of the Client’s advertising campaigns. This includes, in particular, the recording, maintenance and management of advertising orders, communication with the relevant parties involved and reporting to the Client.
B. Nature and scope of the processing
- Recording and storing advertising order data
- Managing user accounts and access rights
- Sending system notifications and reports
- Backing up and performing technical maintenance of the platform
- Logging for securing and traceability purposes
Categories of data subjects and data
Categories of data subjects:
Employees of the Client
Individuals who use adconsole on the Client’s behalf (for case handling, media planning, accounting).
Advertising customers/contacts
Contact persons on the side of the Client's advertising customers, providing their data is stored in adconsole.
Categories of personal data:
Mandatory data
Name, email address, gender, language, login/user ID.
Optional data
Job title, date of birth, address, telephone number.
Technical data
IP address, log data, activity timestamps.
C. Audienzz AG Data Protection Officer
Name: Genoud Fabienne
Function: Data protection officer
Organisation: Audienzz AG
Email: [email protected]