DATA PROCESSING

Data Processing (DPA)

Where Dxzio processes personal data on behalf of customers: principles of data processing under Art. 9 revFADP and Art. 28 GDPR.

Note — draft version

DRAFT and summary, not yet legally approved. This page states the essential principles; the legally binding data processing agreement (DPA) is concluded individually per engagement. To be reviewed by admitted counsel before use. The German version is authoritative. As of: 2026-08.

Role and scope

Where, within an engagement, Dxzio processes personal data solely on the customer's instructions and for the customer's purposes, Dxzio acts as processor and the customer as controller. For this constellation the parties conclude a data processing agreement (DPA).

Legal bases

The DPA is based on Art. 9 of the revised Swiss Data Protection Act (revFADP) and, where the GDPR applies, on its Art. 28. It governs the subject matter, duration, nature and purpose of the processing, the categories of data subjects and data, and the obligations of both parties.

Technical and organisational measures (TOMs)

Dxzio operates the processing environment to the state of the art: data kept in Switzerland or the EU (never in a US-incorporated entity), encryption in transit and at rest (BYOK possible), an Ed25519-signed, tamper-evident audit chain, WASM-isolated execution, self-hosted identity and secrets management, and need-to-know access. The concrete TOMs are recorded as an annex to the DPA.

Sub-processors

Sub-processors are engaged only with the customer's authorisation per the DPA and by passing on equivalent data protection obligations. The customer is informed of intended changes in advance with reasonable notice (usually 60 days) and has a right to object.

Data subject rights, notification and deletion

Dxzio supports the customer in fulfilling data subject rights (access, rectification, erasure, portability) and notification duties following data breaches. On termination of the engagement, the processed personal data is returned or deleted at the customer's choice, unless a statutory retention obligation applies.

Cross-border disclosure

Personal data is disclosed abroad only where an adequate level of data protection exists or suitable safeguards (including standard contractual clauses) are agreed. The architecture is designed to keep personal data in Switzerland or the EU.

Request the DPA

We provide the full data processing agreement to business customers during contract initiation. Requests: contact@dxzio.one. The authoritative version is the German one.