Data Processing Agreement
Pursuant to Art. 9 of the Swiss Federal Act on Data Protection (nFADP) and, where applicable, Art. 28 of Regulation (EU) 2016/679 (GDPR).
Version 1.0 · In force since 2 August 2026
This agreement governs how Schweizerform processes personal data on behalf of its customers. It forms part of the Terms of Service and is accepted automatically when you create an account — no signature is required.
1. Scope, roles and order of precedence
This Data Processing Agreement ("DPA") governs the processing of personal data that Schweizerform carries out on your behalf when you use the Schweizerform online form service (the "Service"). It is concluded between you as the customer (the "controller") and Balathanusan Jeyarasan, sole proprietorship, trading as «Schweizerform» (the "processor"), whose full details appear at the end of this document.
For the personal data you collect through your forms, you alone determine the purposes and the means of processing. You are the controller within the meaning of Art. 5 lit. j nFADP and Art. 4(7) GDPR. Schweizerform processes that data exclusively on your behalf, as processor within the meaning of Art. 9 nFADP and, where applicable, Art. 28 GDPR.
This DPA forms an integral part of the Terms of Service and prevails over them in all matters concerning the processing of personal data on your behalf. In every other respect — scope of the service, availability, fees, limitation of liability and termination of the subscription — the Terms of Service apply.
For the data Schweizerform processes in order to establish and administer your own contractual relationship with us (your contact, account and billing data), Schweizerform is itself the controller. That processing is governed by our privacy policy and is not the subject of this DPA.
2. Subject matter, nature and purpose of the processing
Schweizerform processes personal data for the sole purpose of providing the Service: collecting the responses submitted through the forms you create, storing them in encrypted form, and making them available for you to retrieve and decrypt.
Through the forms you create, you determine which categories of personal data are collected and from which categories of data subjects. Schweizerform neither reviews the content of your forms nor is able to (section 7). Insofar as you collect sensitive personal data within the meaning of Art. 5 lit. c nFADP, or special categories of personal data within the meaning of Art. 9 GDPR, the measures under this agreement apply to that data as well.
The nature of the processing comprises collection, transmission, storage, provision for retrieval by you, and deletion. It lasts for the term of your subscription.
Schweizerform does not process the data for its own purposes. In particular, there is no processing for advertising, no creation of personality profiles, no disclosure to third parties, and no training of artificial intelligence or machine learning systems on your data.
Schweizerform may evaluate aggregated, fully anonymised usage statistics for the operation, capacity planning and improvement of the Service, provided that no conclusions can be drawn about you, about individual data subjects, or about content.
If you need a processing description specific to your organisation — for your own record of processing activities, for example — request the countersigned version of this agreement at support@schweizerform.ch.
3. Instructions
Schweizerform processes the personal data only within the scope of this agreement and in accordance with your documented instructions. This applies equally to any disclosure of data abroad.
Configuring the Service through the user interface constitutes an instruction within the meaning of this agreement — in particular creating, publishing, changing, closing and deleting forms and submissions, managing access permissions, and enabling optional features. Such instructions require no separate form.
Instructions given outside the user interface are to be issued in text form to the contact address at the end of this document. Instructions given orally are to be confirmed in text form without delay.
If Schweizerform considers that an instruction infringes applicable data protection law, it will inform you without delay. It may suspend execution until the matter is clarified.
Where Schweizerform is legally obliged to carry out further processing, it will inform you before doing so, unless the law prohibits that notice.
Instructions whose implementation would require a change to the Service, additional technical measures, or effort going beyond the contractually owed performance are implemented only by separate written agreement, and are reimbursed at our then-current rates (section 10).
4. Confidentiality
Schweizerform obliges in writing every person who may gain access to the personal data to maintain confidentiality, unless that person is already subject to a statutory duty of secrecy. The obligation continues beyond the end of the respective activity.
At present Schweizerform is operated as a sole proprietorship without employees. The owner is personally and directly bound by the duty of confidentiality. If employees or contractors are engaged, Schweizerform binds them in writing before they take up their activity.
Access is restricted to persons who require it to perform their tasks (principle of least privilege).
5. Professional secrecy (Art. 321 SCC)
Insofar as you are subject to professional secrecy — as medical practices, law firms, notaries and counselling services are — the following applies.
The data collected through the Service is subject to professional secrecy under Art. 321 of the Swiss Criminal Code. Schweizerform and every person acting for it acts, to that extent, as your auxiliary person within the meaning of that provision.
Schweizerform undertakes to preserve professional secrecy and expressly binds in writing every person who may gain access to the data. The obligation is unlimited in time and continues beyond the end of this agreement.
Schweizerform does not disclose data to third parties, including upon an order of a public authority, without informing you beforehand so that you can examine legal remedies. Where prior information is prohibited by law, Schweizerform informs you as soon as this is permitted. Schweizerform is not obliged to challenge official orders at its own expense.
Sub-processors that may, as intended, gain access to data covered by professional secrecy are engaged only if they are subject to a contractual or statutory duty of confidentiality that corresponds to the protective purpose of Art. 321 SCC. For sub-processors without such access — the payment processing named in section 11 and the sending of transactional e-mails by the provider EuSend named there — the general confidentiality obligation under section 4 applies.
Because of the end-to-end encryption described in section 7, Schweizerform cannot take note of the content of submissions. In practice, this obligation therefore extends to metadata, form content, and all other information that becomes accessible to Schweizerform in the course of performing this agreement.
This clause activates itself. No separate document and no additional agreement is required for it to apply.
6. Technical and organisational measures
Schweizerform takes the technical and organisational measures required by Art. 8 nFADP in conjunction with the Data Protection Ordinance and, where applicable, Art. 32 GDPR, in order to ensure a level of security appropriate to the risk. The measures in place are described below; they describe the agreed security standard.
- •End-to-end encryption. Responses and file attachments are encrypted in the respondent's browser using AES-256-GCM. The key of the individual submission is wrapped with the form's public key (RSA-OAEP-2048). Schweizerform stores exclusively ciphertext and wrapped keys.
- •Key derivation on your side. Your master key is derived in your browser from your Vault key using PBKDF2-HMAC-SHA256 with 600,000 iterations and an individual salt. Your Vault key is at no time transmitted to or stored on Schweizerform's systems, and the master key exists in clear only in your browser's memory. In addition, a copy of the master key encrypted with your recovery code is stored, so that you can regain access with your recovery code; the recovery code itself is at no time transmitted or stored, so that stored copy is of no use to Schweizerform.
- •File attachments. Object names in storage are random UUIDs; the original file name and file type exist exclusively inside the encrypted record.
- •Access control. Account access via personal credentials (email address and password; passwords are stored server-side as a hash only). Security-relevant operations — signup, password change, password reset and Vault-key reset — additionally require a one-time code delivered by email.
- •Blocking mechanisms. Account lockout after repeated failed attempts; rate limiting; automatic blocking of conspicuous IP addresses; protection against cross-site request forgery and verification of request origin.
- •Sessions and automatic locking. Server-side sessions with a limited lifetime; overview and revocation of active sessions; automatic deletion of the master key from browser memory after a configurable period of inactivity (120 minutes by default).
- •Role-based permissions. In team workspaces, graduated roles (owner, administration, member, read access). The workspace key is cryptographically bound to each member's personal key pair.
- •Separation of customers. Logical separation through owner-bound storage paths, referential assignment of every record and a permission check on every access. In addition there is cryptographic separation: every form has its own key pair.
- •Integrity. Encrypted transmission exclusively over TLS. The ciphertext of the responses is cryptographically bound to the form and submission identifiers (authenticated encryption with associated data). File attachments are encrypted under the same submission key.
- •Logging. Security-relevant events are logged with timestamp, acting person, affected object and outcome. IP address and user agent are recorded exclusively for actions of your signed-in users — never for submissions by data subjects.
- •Operation. Operation on the managed infrastructure of a Swiss provider (section 11) in data centres in Switzerland. Separate environments for development and production; access to production systems by the owner only; prompt installation of security updates; central error and event logging.
- •Database backups. Daily automatic backup by the infrastructure provider within Switzerland, with a rolling retention of the last seven daily backups, restorable through the provider's management interface. Data loss noticed more than seven days after it occurs can no longer be remedied from these backups.
- •Object storage. The object storage holding submission ciphertexts and file attachments is redundant at the provider. There is no separate backup of the object storage by Schweizerform. Redundancy is not a substitute for a backup: if data is deleted or lost at the provider, restoration by Schweizerform is not guaranteed.
- •Your own responsibility for backups. You can generate complete exports of your data in decrypted form at any time and are expected to do so regularly (section 14).
- •No third-party analysis. On the public form pages there is no analytics session, no browser fingerprint, no country evaluation and no third-party analytics, advertising or tracking service. What is collected is: aggregate counters per form and per day (number of views, number of submissions, device class — desktop, mobile, tablet — and access channel, link or QR code); aggregate counters per question (how often a question was shown and how often it was answered); and, per submission, the time taken to fill in the form, the number of questions, the number answered, the total stored size of the submission (the encrypted answers plus any encrypted attachments), and the display language used. The device class is derived server-side at the time of submission from the user agent; the user agent itself is not stored. The aggregate counters are never cross-tabulated with one another, with questions or with individual submissions. They are deleted together with the form.
Expressly not provided, to avoid misunderstandings: multi-factor authentication at login (the one-time code secures signup and security-relevant operations, not the login itself); certification under ISO 27001 or SOC 2; external penetration tests or security audits; a guaranteed availability rate or recovery time. Schweizerform owes no measures beyond those described in this section unless separately agreed in writing.
The measures are subject to technical progress. Schweizerform may adapt them provided the level of protection is not reduced. It notifies material changes in advance in text form.
Schweizerform maintains a record of the categories of processing activities carried out on your behalf (Art. 12 nFADP).
7. End-to-end encryption and its limits
The responses of data subjects and the files they upload are encrypted in the data subject's browser (AES-256-GCM) and transmitted to and stored on Schweizerform's systems exclusively in encrypted form. The key of the individual submission is wrapped with the form's public key (RSA-OAEP-2048).
The master key required for decryption is derived exclusively in your browser from your Vault key using PBKDF2-HMAC-SHA256 with 600,000 iterations and an individual salt. Your Vault key is at no time transmitted to or stored on Schweizerform's systems, and the master key exists in clear only in your browser's memory. In addition, a copy of the master key encrypted with your recovery code is stored, so that you can regain access with your recovery code; the recovery code itself is at no time transmitted or stored, so that stored copy is of no use to Schweizerform. Schweizerform has no access to the plaintext content of submissions and will take no measures to obtain such access.
Scope of the encryption. The encryption covers the responses and file attachments of data subjects. It does not cover — and the following is therefore accessible to Schweizerform in plaintext — in particular: names and question texts of forms; form settings and branding information; account and contact data of your users; timestamps and technical metadata of submissions; and the security logs described in section 6. You are responsible for not entering personal data of data subjects into question texts, form names or settings.
Consequences of key loss. You are solely responsible for the safe keeping of your Vault key and your recovery code. If both are lost, the encrypted data remains, for technical reasons, unreadable for as long as neither of the two codes is regained. Resetting the Vault key without the Vault key and without a recovery code does not re-encrypt existing data; instead it moves all of your personal forms and submissions into a locked set of data, which remains readable only if one of the old codes is later regained. Forms held in a team workspace are not moved; instead your copy of the workspace key is invalidated and must be re-granted by another administrator of that workspace. If no other administrator holds it, that workspace content can no longer be decrypted, and regaining an old code does not restore it. Schweizerform cannot restore it; Schweizerform's liability for the resulting loss is excluded to the extent permitted by law.
Form of any return. A return of data by Schweizerform takes place in the format in which Schweizerform holds the data, that is, as ciphertext together with the associated metadata. A return in plaintext is technically impossible for Schweizerform. You acknowledge that a return after the end of the contract is worthless without your Vault key, and ensure that you carry out your own export in good time before the contract ends.
Schweizerform informs you without delay in text form if a change to the architecture would mean that the first two paragraphs of this section no longer apply. In that case you may terminate this agreement and the Terms of Service extraordinarily with effect from the date on which the change takes effect.
8. Your obligations as controller
You are solely responsible for ensuring that the collection, processing and use of the data, as well as the design and content of your forms, are lawful, that a valid legal basis exists, and that data subjects are properly informed (Art. 19 ff. nFADP). Schweizerform reviews neither the content nor the admissibility of your forms and is neither obliged nor — because of the encryption under section 7 — able to do so.
You collect through the Service only personal data that is necessary for your purpose.
You manage the accesses to your account and, insofar as used, to team workspaces on your own responsibility. You grant and withdraw permissions promptly, choose secure passwords and Vault keys, and keep them secret. Actions carried out through your accesses are deemed to have been initiated by you.
You inform Schweizerform without delay if you have any indication that your credentials have been compromised or that data security has been breached within your sphere of responsibility.
Before enabling optional features that involve processing by third parties — the AI-assisted translation and form creation named in section 11 — you examine whether their use is admissible for your processing. These features are disabled by default and are used only upon your express activation; they process exclusively form texts written by you and at no time submissions of data subjects.
9. Personal data breach
Schweizerform notifies you of any breach of data security affecting your data without delay, and at the latest within 48 hours of becoming aware of it, in text form.
Notification is sent to the email address held for your account. You keep that address up to date.
The notification contains, insofar as known at the time of notification: the nature of the breach, the categories of data affected, the approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Schweizerform supplies missing information as soon as it becomes available; an incomplete initial notification is deemed to meet the deadline.
Schweizerform supports you in your notification duties towards the Federal Data Protection and Information Commissioner under Art. 24 nFADP and, where applicable, under Art. 33 and 34 GDPR. Assessing the duty to notify, and making the notification itself, is incumbent on you.
Schweizerform documents breaches of data security including the remedial measures taken.
Notifications under this section are made in fulfilment of statutory obligations and do not constitute an admission of fault or liability.
10. Rights of data subjects and support
Safeguarding the rights of data subjects is incumbent on you. The Service provides you with the functions required for this, in particular viewing, exporting and deleting individual submissions.
Schweizerform supports you with reasonable measures insofar as you cannot fulfil requests yourself through the functions of the Service. Because Schweizerform cannot decrypt the content, its support is necessarily limited to encrypted data and metadata.
If a data subject addresses a request directly to Schweizerform, Schweizerform forwards it to you without delay and does not answer it itself.
Schweizerform supports you with data protection impact assessments and with consultations of the supervisory authority, insofar as the necessary information originates from Schweizerform's sphere of responsibility.
Support services under sections 9 and 10 are provided free of charge to the usual extent. If the effort exceeds the usual extent — in particular in the case of repeated or extensive requests, individual evidence, questionnaires, on-site inspections or separate analyses — Schweizerform informs you in advance and begins the work only after your approval in text form, against reimbursement at our then-current rates. This does not apply insofar as the effort is attributable to a breach of duty for which Schweizerform is responsible.
11. Sub-processors
You grant Schweizerform the general authorisation to engage sub-processors in accordance with this section (Art. 9 para. 3 nFADP). The sub-processors engaged at the time this version was published are listed below. This list is the authoritative one; the Terms of Service refer to it.
| Provider | Service | Place of processing | Notes |
|---|---|---|---|
| Infomaniak Network SA, Geneva | Application servers, database and object storage; delivery of transactional email; optional AI services for translating and creating form texts | Switzerland | Submission content exclusively as ciphertext; no plaintext access to responses. No submission content is sent by email. The AI services are optional, disabled by default, process exclusively form texts written by you, and never submissions. |
| Stripe Payments Europe, Ltd., Dublin | Payment and subscription processing | Ireland | Schweizerform's contractual counterparty is the Irish company. Processes exclusively your billing data; no personal data of data subjects, no access to forms or submissions. Intra-group onward transfer to Stripe, Inc. (USA) in accordance with Stripe's own data processing addendum on the basis of the EU standard contractual clauses. |
| Bjørnerås Labs (the «EuSend» service), org. no. 938 162 336, Norway | Sending of transactional e-mails (one-time codes, account and invitation messages) | Norway (provider); processing and delivery in Germany and Finland | Processes the recipient address, subject and content of the message concerned (one-time codes, account and invitation messages). No submissions and no responses of data subjects. Message content is processed and stored exclusively on infrastructure in the EEA (Germany, Finland); the provider deletes delivery logs including the rendered message content after 30 days. For the operation of its own website, for DNS and for error diagnostics the provider additionally engages service providers in the United States; these are not involved in the delivery path for message content, and those disclosures rely on the EU-US Data Privacy Framework or the standard contractual clauses. The provider's data processing agreement applies. |
No further sub-processors are engaged at present.
If Schweizerform intends to engage a further sub-processor or to replace an existing one, it notifies you at least 30 days in advance in text form.
You may object to the change within 30 days of receipt of the notification, in text form, on substantiated data protection grounds. If no objection is made within that period, the change is deemed approved.
If you object and the parties do not find an amicable solution within 30 days, either party may terminate this agreement and the Terms of Service with ordinary notice as of the planned date of the change. No further claims arise from the objection.
Schweizerform may replace a sub-processor without prior notification where this is necessary to avert an immediate danger to the security or availability of the Service. In that case it informs you without delay afterwards.
Schweizerform contractually binds sub-processors to obligations that correspond in substance to the obligations under this agreement, including the confidentiality under section 4 and, where applicable, section 5.
Schweizerform is liable for its sub-processors' compliance with data protection obligations as for its own conduct, within the framework of the liability provisions in section 15.
Ancillary services without intended access to your personal data — in particular telecommunications services and maintenance by third parties without data access — do not constitute sub-processing.
12. Place of processing and disclosure abroad
Submissions. All submissions of data subjects — responses and file attachments — are processed and stored exclusively in Switzerland (application servers, database, object storage). No processing of this data takes place outside Switzerland.
Ancillary services outside Switzerland. Outside Switzerland, only the payment processing named in section 11 (Ireland) and the sending of transactional e-mails through the provider EuSend named there (Norway; processing in Germany and Finland) take place. Both services take place entirely within the European Economic Area, comprise no submissions and no personal data of the data subjects who fill in your forms. Any further processing outside Switzerland takes place only after prior notification in accordance with section 11.
The states in which the processing described in the previous paragraph takes place — Ireland, Norway, Germany and Finland — provide adequate data protection according to Annex 1 of the Data Protection Ordinance. The disclosure is therefore permissible under Art. 16 para. 1 nFADP without additional safeguards.
For any onward disclosures by these sub-processors to recipients outside the European Economic Area, Schweizerform engages only sub-processors whose own terms provide a basis compliant with Art. 16 and 17 nFADP and, where applicable, with Chapter V GDPR for such onward disclosures, in particular an adequacy decision or the standard contractual clauses of the European Commission. Schweizerform passes on the corresponding documentation of the sub-processors on request.
13. Evidence and audits
On request, Schweizerform demonstrates compliance with the obligations under this agreement, primarily through an up-to-date description of the measures taken, through self-assessment, and through certificates or audit reports of its sub-processors.
If this evidence is insufficient in a substantiated individual case, you may carry out an audit, at most once per calendar year, or have it carried out by an independent third party bound to secrecy and not in competition with Schweizerform. The audit takes place upon at least 30 days' prior notice, during ordinary business hours and with the least possible disruption to operations.
In the case of a substantiated suspicion of a serious breach of data security, the restrictions of the previous paragraph as to frequency and notice period do not apply.
You bear the costs of an audit and reimburse Schweizerform's effort at our then-current rates. If material breaches of duty by Schweizerform are established, Schweizerform bears those costs.
Access to systems, premises and data of third parties, as well as to trade and business secrets of Schweizerform, remains reserved. Direct access to production systems is not granted.
14. Retention, deletion and return
During the term of the contract you can obtain your data yourself at any time through the export functions of the Service. This self-service constitutes handing over the data within the meaning of Art. 9 nFADP.
You may request the deletion of individual submissions at any time during the term of the contract; the corresponding function is directly available to you in the Service. If the request is made exceptionally through Schweizerform, Schweizerform carries out the deletion within 30 days.
- •Security log. IP address and user agent are automatically removed from log entries after 90 days; the event entry itself (time, action, object, outcome) is retained as evidence.
- •Email delivery log. Entries including the rendered message content are automatically deleted after 90 days.
- •Enforcement. Both periods are enforced by a recurring, automatic process and are not triggered manually.
- •Backup copies. A deletion takes effect immediately in the production systems. Data in backup copies is overwritten in the course of the ordinary backup cycle, at the latest within 30 days (the backup cycle of the database is currently seven days). Until then it remains blocked exclusively for the purpose of restoration and is not otherwise processed.
After the end of the contract, Schweizerform returns or deletes the personal data at your choice, including existing copies. You communicate your choice in text form within 30 days of the end of the contract. If no communication is made, Schweizerform deletes the data after expiry of that period. Section 7 applies to the form of the return. If you delete your account yourself through the function of the Service, this is deemed to be a choice of deletion; in that case the deletion takes place immediately and irreversibly, and the period under this paragraph does not apply. You carry out your exports beforehand.
Schweizerform confirms the deletion in text form on request. Retention beyond the end of the contract is permissible insofar as statutory retention obligations exist; in that case Schweizerform limits the processing to the purpose of retention.
15. Liability
The parties are liable in accordance with the statutory provisions.
The limitation of liability agreed in the Terms of Service — in particular the limitation of total liability to the fees paid to Schweizerform in the twelve months preceding the damaging event, as well as the exclusion of indirect and consequential damage — also applies to claims under this agreement.
That limitation of liability does not apply to damage arising from gross negligence or intent (Art. 100 para. 1 CO), nor in the case of injury to life, limb or health.
Schweizerform's liability is excluded for damage attributable to: the loss of the Vault key or the recovery code (section 7); the design, content or lawfulness of your forms; your management of accesses and permissions; or instructions of yours whose questionable nature Schweizerform pointed out in accordance with section 3.
If one party is held liable by data subjects or authorities on account of a breach of duty by the other party, the party in breach indemnifies the other party to the extent of its share of responsibility. The second and third paragraphs of this section remain reserved.
16. Term, termination and discontinuation of the Service
This agreement enters into force when you create an account and applies for the term of the Terms of Service. It ends automatically upon their termination; no separate notice of termination is required. For accounts that already existed at the time this version enters into force, this agreement enters into force upon that entry into force; continued use of the Service after corresponding notification is deemed to be acceptance in accordance with the Terms of Service.
Termination of the Terms of Service is governed by the Terms of Service. Schweizerform is entitled to discontinue the Service in accordance with the Terms of Service; in that case it informs you at least 90 days in advance in text form and enables you to export your data during that period.
The right to extraordinary termination for good cause remains reserved to both parties.
The obligations of confidentiality (section 4) and of professional secrecy (section 5) continue beyond the end of this agreement.
17. Changes to this agreement
Schweizerform may amend this agreement insofar as this is necessary to adapt to a changed legal situation, case law, regulatory practice, or to a further development of the Service.
Changes are published as a new version of this document. Schweizerform notifies the change at least 30 days before it takes effect in text form. You may object in text form within 30 days; in that case section 11 applies accordingly.
Changes that lower the level of protection for data subjects always require your express consent.
Published versions are never edited retroactively. The version and the effective date of the version in force are stated at the end of this page.
18. Governing law and place of jurisdiction
Swiss law applies, excluding its conflict-of-law rules and the United Nations Convention on Contracts for the International Sale of Goods.
The exclusive place of jurisdiction for all disputes arising out of or in connection with this agreement is Pfäffikon SZ, Switzerland.
Acceptance, version and contact
This Data Processing Agreement forms part of the Schweizerform Terms of Service and is accepted automatically when you create an account. No signature is required, and this document intentionally contains no signature block.
Version 1.0 · In force since 2 August 2026
If you need a countersigned, customer-specific data processing agreement — for example including a processing description for your own records — write to support@schweizerform.ch.
The processor
Balathanusan JeyarasanSole proprietorship, trading as «Schweizerform»c/o ExpertFid & Audit SAChurerstrasse 1588808 PfäffikonSwitzerlandsupport@schweizerform.ch