Data Processing Agreement (DPA)
Version 1.2 · In effect from 03.09.2026
Elchi Studios is the trading name of a sole proprietorship owned by Samuel Krauss, Oberägeri ZG, Switzerland. Samuel Krauss personally is the counterparty.
pursuant to Art. 28 GDPR and Art. 9 FADP (Switzerland)
between
Samuel Krauss (operating as Elchi Studios)
Im Ländli 18, 6315 Oberägeri, Switzerland
– hereinafter "Processor" –
and
the respective client as per the service agreement
– hereinafter "Controller" –
Preamble
This Data Processing Agreement (DPA) governs the processing of personal data by the Processor on behalf of the Controller pursuant to Art. 28 GDPR and Art. 9 of the Swiss Federal Act on Data Protection (FADP). It forms an integral part of the service agreement concluded between the parties.
Section 1: Subject Matter and Duration
1.1 Subject Matter: The Processor provides technical services under the main contract (in particular web development and hosting), in the course of which it may gain access to personal data of the Controller or the Controller's customers.
1.2 Duration: Data processing continues for the duration of the main contract. Upon termination, data is handled in accordance with Section 8.
Section 2: Nature and Purpose of Processing
The processing of personal data includes in particular:
- Access to server data and databases for technical maintenance and development
- Storage and management of user data in hosted projects
- Logging of access and errors for diagnostic purposes
Processing is carried out exclusively for the purpose of fulfilling the main contract.
Section 3: Categories of Personal Data and Data Subjects
Processing may involve the following categories of personal data:
- Contact and identification data (name, email, address)
- Technical usage data (IP addresses, log data)
- Transaction data (depending on project type)
- Other data categories as defined by the Controller
Data subjects may include customers, users and visitors of the Controller's systems and websites.
Section 4: Processor Obligations
The Processor undertakes to:
4.1 Process personal data only on documented instructions from the Controller.
4.2 Ensure that all persons authorised to process personal data are bound to confidentiality or are subject to a statutory obligation of confidentiality.
4.3 Implement all technical and organisational measures required under Art. 32 GDPR / Art. 8 FADP to ensure appropriate data security, in particular:
- Encryption of stored and transmitted data
- Access controls and authentication measures
- Regular security updates and backups
4.4 Comply with the conditions of this DPA when engaging sub-processors (see Section 5).
4.5 Assist the Controller, taking into account the nature of the processing, in fulfilling its obligations (data subject rights, notification obligations, data protection impact assessments).
4.6 Notify the Controller of any personal data breach without undue delay (within 24 hours of becoming aware of it at the latest).
Section 5: Sub-processors
5.1 The Processor uses hosting providers as sub-processors. As the hosting provider may vary by project, the Processor will inform the Controller upon request of the sub-processors currently engaged.
5.2 The Controller hereby grants general authorisation for the engagement of sub-processors in the area of hosting and server infrastructure, provided these are bound to equivalent data protection obligations.
5.3 The Processor ensures that sub-processors are subject to the same data protection obligations as the Processor itself.
5.4 Changes or additions to sub-processors will be communicated to the Controller in advance (at least 14 days' notice). The Controller may object in writing within this period.
Section 6: Data Subject Rights
The Processor shall assist the Controller in responding to data subject requests (access, rectification, erasure, restriction, portability, objection). Where possible, the Processor shall provide technical means or take appropriate measures to support this.
Section 7: Controller Audit Rights
7.1 The Controller has the right to verify compliance with this DPA and data protection requirements at the Processor's premises.
7.2 The Processor shall make all necessary information available to the Controller and permit audits or inspections (with reasonable advance notice of at least 14 days).
Section 8: Return and Deletion of Data
8.1 Upon termination of the main contract, personal data shall be returned or deleted at the Controller's request, unless statutory retention obligations apply.
8.2 The Processor shall confirm deletion in writing upon request.
Section 9: Liability
The liability of the parties is governed by the provisions of the main contract and applicable statutory provisions.
Section 10: Governing Law
Swiss law applies. The place of jurisdiction is Zug, Switzerland.
This DPA is agreed as an integral part upon conclusion of the main service agreement.
Version 1.0 | June 2025