Data Processing Agreement
Pursuant to Art. 9 of the Swiss Federal Act on Data Protection (nFADP) and, where applicable, Art. 28 of Regulation (EU) 2016/679 (GDPR).
In force since 25 September 2026
This edition is published but is not yet in force. It takes effect on 25 September 2026. Until then, the edition currently in force governs your account.
This agreement governs how Schweizerform processes personal data on behalf of its customers. It forms part of the Terms of Service and is accepted automatically when you create an account — no signature is required.
1. Scope, roles and order of precedence
This Data Processing Agreement ("DPA") governs the processing of personal data that Schweizerform carries out on your behalf when you use the Schweizerform online form service (the "Service"). It is concluded between you as the customer (the "controller") and Balathanusan Jeyarasan, sole proprietorship, trading as «Schweizerform» (the "processor"), whose full details appear at the end of this document.
For the personal data you collect through your forms, you alone determine the purposes and the means of processing. You are the controller within the meaning of Art. 5 lit. j nFADP and Art. 4(7) GDPR. Schweizerform processes that data exclusively on your behalf, as processor within the meaning of Art. 5 lit. k in conjunction with Art. 9 nFADP and, where applicable, Art. 28 GDPR.
This DPA forms an integral part of the Terms of Service and prevails over them in all matters concerning the processing of personal data on your behalf. In every other respect — scope of the service, availability, fees, limitation of liability and termination of the subscription — the Terms of Service apply.
For the data Schweizerform processes in order to establish and administer your own contractual relationship with us (your contact, account and billing data), Schweizerform is itself the controller. That processing is governed by our privacy policy and is not the subject of this DPA.
2. Subject matter, nature and purpose of the processing
Schweizerform processes personal data for the sole purpose of providing the Service: collecting the responses submitted through the forms you create, storing them in encrypted form, and making them available for you to retrieve and decrypt.
Where you activate the corresponding optional capabilities (section 8), that purpose additionally comprises: keeping an encrypted directory of the recipients you enter or import; transmitting to recipients you designate the invitations to your forms that you instruct; and sending a person who has filled in one of your forms, at that person's own request and to an address that person supplies at that moment, a receipt confirming that their submission was received. Sections 5, 7, 11 and 12 set out the limits that apply to each of these.
Through the forms you create, you determine which categories of personal data are collected and from which categories of data subjects. Schweizerform neither reviews the content of your forms nor is able to (section 7). Insofar as you collect sensitive personal data within the meaning of Art. 5 lit. c nFADP, or special categories of personal data within the meaning of Art. 9 GDPR, the measures under this agreement apply to that data as well.
The data subjects are the persons who fill in your forms and, where you use the contact directory, the persons you enter in it. The categories of data are those you choose to collect, including, where you so decide, sensitive personal data.
The nature of the processing comprises collection, transmission, storage, provision for retrieval by you, the dispatch of the messages described in the second paragraph, and deletion. It lasts for the term of your subscription.
Schweizerform does not process the data for its own purposes. In particular, there is no processing for advertising, no creation of personality profiles, no disclosure to third parties, and no training of artificial intelligence or machine learning systems on your data.
Schweizerform may evaluate aggregated, fully anonymised usage statistics for the operation, capacity planning and improvement of the Service, provided that no conclusions can be drawn about you, about individual data subjects, or about content.
If you need a processing description specific to your organisation — for your own record of processing activities, for example — write to support@schweizerform.ch. You receive a countersigned copy of this standard agreement in electronic form, with that description attached as a factual annex prepared against reimbursement of the effort (section 10; see the end of this document).
3. Instructions
Schweizerform processes the personal data only within the scope of this agreement and in accordance with your documented instructions. This applies equally to any disclosure of data abroad.
Configuring the Service through the user interface constitutes an instruction within the meaning of this agreement — in particular creating, publishing, changing, closing and deleting forms and submissions, managing access permissions, maintaining your contact directory, sending invitations, and enabling optional features. Such instructions require no separate form.
Instructions given outside the user interface are to be issued in text form to the contact address at the end of this document. Instructions given orally are to be confirmed in text form without delay.
If Schweizerform considers that an instruction infringes applicable data protection law, it will inform you without delay. It may suspend execution until the matter is clarified.
Where Schweizerform is legally obliged to carry out further processing, it will inform you before doing so, unless the law prohibits that notice.
Instructions whose implementation would require a change to the Service, additional technical measures, or effort going beyond the contractually owed performance are implemented only by separate written agreement, and are reimbursed at our then-current rates (section 10).
4. Confidentiality
Schweizerform obliges in writing every person who may gain access to the personal data to maintain confidentiality, unless that person is already subject to a statutory duty of secrecy. The obligation continues beyond the end of the respective activity.
The owner is personally and directly bound by the duty of confidentiality. Employees or contractors, where engaged, are bound in writing before they take up their activity.
Access is restricted to persons who require it to perform their tasks (principle of least privilege).
5. Professional secrecy (Art. 321 SCC)
Insofar as you are subject to professional secrecy — as medical practices, law firms, notaries and counselling services are — the following applies.
Insofar as the data collected through the Service is subject to professional secrecy under Art. 321 of the Swiss Criminal Code, Schweizerform and every person acting for it acts, to that extent, as your auxiliary person within the meaning of that provision.
Schweizerform undertakes to preserve professional secrecy and expressly binds in writing every person who may gain access to the data. The obligation is unlimited in time and continues beyond the end of this agreement.
Schweizerform does not disclose data to third parties, including upon an order of a public authority, without informing you beforehand so that you can examine legal remedies. Where prior information is prohibited by law, Schweizerform informs you as soon as this is permitted. Schweizerform is not obliged to challenge official orders at its own expense.
Sub-processors that may, as intended, gain access to data covered by professional secrecy are engaged only if they are subject to a contractual or statutory duty of confidentiality that corresponds to the protective purpose of Art. 321 SCC. For sub-processors without such intended access — the delivery of transactional e-mail by the mail delivery provider listed in section 11 — the general confidentiality obligation under section 4 applies, subject to the following paragraph.
Invitations and receipts (section 2) are capabilities that operate only on your instruction: an invitation is sent only when you instruct it, and receipts are offered only on forms for which you have switched them on. Where you use them, the recipient's e-mail address and the name of your organisation become known to the mail delivery provider listed in section 11. The message names your organisation; it names the form only where you have chosen to include the form name, and it contains no submission, no response and no answer content. Before using these capabilities you assess whether that disclosure is admissible for processing subject to professional secrecy, and you remain free not to use them; receipts are switched off by default, and no invitation is sent without your instruction.
Because of the end-to-end encryption described in section 7, Schweizerform cannot take note of the content of submissions. In practice, this obligation therefore extends to metadata, form content, and all other information that becomes accessible to Schweizerform in the course of performing this agreement.
This clause activates itself. No separate document and no additional agreement is required for it to apply.
6. Technical and organisational measures
Schweizerform takes the technical and organisational measures required by Art. 8 nFADP in conjunction with the Data Protection Ordinance and, where applicable, Art. 32 GDPR, in order to ensure a level of security appropriate to the risk. The measures in place are described below; they describe the agreed security standard.
- •End-to-end encryption. Responses and file attachments are encrypted in the respondent's browser; Schweizerform stores exclusively ciphertext and wrapped keys. The architecture and its limits are described in section 7.
- •Key derivation on your side. Your master key is derived in your browser from your Vault key and exists in clear only there; the Vault key and the recovery code are at no time transmitted to or stored on Schweizerform's systems (section 7).
- •File attachments. Object names in storage are random UUIDs; the original file name and file type exist exclusively inside the encrypted record.
- •Access control. Account access via personal credentials; passwords are stored server-side as a hash only. Security-relevant operations additionally require a one-time code delivered by email.
- •Blocking mechanisms. Account lockout after repeated failed attempts; rate limiting; automatic blocking of conspicuous IP addresses; protection against cross-site request forgery and verification of request origin. IP addresses processed for these purposes are held in short-lived records or on a block list. Where you set a form to accept one submission per connection, a keyed value derived from the respondent's IP address is stored on the submission concerned; the address itself is not stored, the value cannot be read back to an address, and it is deleted together with the submission.
- •Sessions and automatic locking. Server-side sessions with a limited lifetime; overview and revocation of active sessions; automatic sign-out of the browser and deletion of the master key from its memory after a configurable period of inactivity.
- •Role-based permissions. In team workspaces, graduated roles with different levels of access. The workspace key is cryptographically bound to each member's personal key pair.
- •Separation of customers. Logical separation through owner-bound storage paths and a permission check on every access, and cryptographic separation: every form has its own key pair, and every contact directory its own key.
- •Integrity. Encrypted transmission exclusively over TLS. The ciphertext of the responses is cryptographically bound to the form and submission identifiers (authenticated encryption with associated data). File attachments are encrypted under the same submission key.
- •Logging. Security-relevant events are logged with timestamp, acting person, affected object and outcome. IP address and user agent are recorded in the security log exclusively for actions of your signed-in users — never for submissions by data subjects.
- •Operation. Operation on the managed infrastructure of a Swiss provider (section 11) in data centres in Switzerland. Separate environments for development and production; prompt installation of security updates; central error and event logging.
- •Backups. The database is backed up daily by the infrastructure provider within Switzerland. The object storage holding submission ciphertexts and file attachments is redundant at the provider but is not separately backed up by Schweizerform; redundancy is not a substitute for a backup, and restoration of data deleted or lost at the provider is not guaranteed. You can generate complete exports of your data in decrypted form at any time and are expected to do so regularly (section 14).
- •Public form pages and usage counters. On the public form pages there is no analytics session, no browser fingerprint and no third-party analytics, advertising or tracking service. What Schweizerform records about the use of a form is limited to aggregate counters and coarse technical metadata per submission. Extended counters are recorded only on forms for which you switch them on; that setting is off by default. None of these values contains an IP address, a user agent, a per-visit record or any answer, and all of them are deleted together with the form.
Expressly not provided, to avoid misunderstandings: multi-factor authentication at login (the one-time code secures signup and security-relevant operations, not the login itself); certification under ISO 27001 or SOC 2; external penetration tests or security audits; a guaranteed availability rate or recovery time. Schweizerform owes no measures beyond those described in this section unless separately agreed in writing.
The measures are subject to technical progress. Schweizerform may adapt them provided the level of protection is not reduced; a change that reduces it is made only under the procedure in section 17. It notifies material changes in advance in text form.
7. End-to-end encryption and its limits
The responses of data subjects and the files they upload are encrypted in the data subject's browser and transmitted to and stored on Schweizerform's systems exclusively in encrypted form. The key of the individual submission is wrapped with the form's public key.
The master key required for decryption is derived exclusively in your browser from your Vault key by a key-derivation function that follows current recommendations. Your Vault key is at no time transmitted to or stored on Schweizerform's systems, and the master key exists in clear only in your browser's memory. In addition, a copy of the master key encrypted with your recovery code is stored, so that you can regain access with your recovery code; the recovery code itself is at no time transmitted or stored, so that stored copy is of no use to Schweizerform. Schweizerform has no access to the plaintext content of submissions and will take no measures to obtain such access.
Scope of the encryption. The encryption covers the responses and file attachments of data subjects. It does not cover — and the following is therefore accessible to Schweizerform in plaintext — in particular: names and question texts of forms; form settings and branding information; account and contact data of your users; timestamps and technical metadata of submissions; and the security logs described in section 6. You are responsible for not entering personal data of data subjects into question texts, form names or settings.
The contact directory. The details you keep about a contact are encrypted in your browser under a key of their own, which is in turn encrypted with your master key or, for a directory held in a team workspace, with that workspace's key. Schweizerform stores that data exclusively as ciphertext and cannot read it. Not covered by that encryption are the technical values that make the directory work — in particular values derived from the e-mail address that allow duplicates and objections to be recognised, the assignment of contacts to groups, and timestamps. None of these values can be read as an identity. Some of them are retained after a contact is deleted, so that an objection is still honoured (section 14).
Receipts. Where a person who has filled in one of your forms asks for a receipt, the address that person supplies is used to send that one message and is then discarded. It is not stored on the submission and not written to the e-mail delivery log. A keyed value derived from it is held briefly to prevent the same address being targeted repeatedly through the Service; it is stored nowhere else.
Consequences of key loss. You are solely responsible for the safe keeping of your Vault key and your recovery code. If both are lost, the encrypted data remains, for technical reasons, unreadable for as long as neither of the two codes is regained. Resetting the Vault key without the Vault key and without a recovery code does not re-encrypt existing data; instead it moves all of your personal forms, submissions and contacts into a locked set of data, which remains readable only if one of the old codes is later regained. Forms and contacts held in a team workspace are not moved; instead your copy of the workspace key is invalidated and must be re-granted by another administrator of that workspace. If no other administrator holds it, that workspace content can no longer be decrypted, and regaining an old code does not restore it. Schweizerform cannot restore it; Schweizerform's liability for the resulting loss is excluded to the extent permitted by law.
Form of any return. A return of data by Schweizerform takes place in the format in which Schweizerform holds the data, that is, as ciphertext together with the associated metadata. A return in plaintext is technically impossible for Schweizerform. You acknowledge that a return after the end of the contract is worthless without your Vault key, and ensure that you carry out your own export in good time before the contract ends.
Schweizerform informs you without delay in text form if a change to the architecture would mean that the first two paragraphs of this section no longer apply. In that case you may terminate this agreement and the Terms of Service extraordinarily with effect from the date on which the change takes effect.
8. Your obligations as controller
You are solely responsible for ensuring that the collection, processing and use of the data, as well as the design and content of your forms, are lawful, that a valid legal basis exists, and that data subjects are properly informed (Art. 19 ff. nFADP). Schweizerform reviews neither the content nor the admissibility of your forms and is neither obliged nor — because of the encryption under section 7 — able to do so.
You collect through the Service only personal data that is necessary for your purpose.
You manage the accesses to your account and, insofar as used, to team workspaces on your own responsibility. You grant and withdraw permissions promptly, choose secure passwords and Vault keys, and keep them secret. Actions carried out through your accesses are deemed to have been initiated by you.
You inform Schweizerform without delay if you have any indication that your credentials have been compromised or that data security has been breached within your sphere of responsibility.
Before enabling optional features that involve processing by third parties — the AI-assisted translation and form creation named in section 11 — you examine whether their use is admissible for your processing. These features are disabled by default and are used only upon your express activation; they process exclusively form texts written by you and at no time submissions of data subjects.
The same applies to the contact directory, to invitations, to receipts, to the copy for respondents and to the extended counters described in section 6. None of them operates except on your instruction (section 3): the contact directory and invitations only when you use them, and receipts, the copy for respondents and the extended counters only after you have switched them on for the form concerned — each of these is switched off by default. Before using or enabling them you assess whether their use is admissible for your processing — in particular, where you are subject to professional secrecy, whether the disclosure described in section 5 is admissible for you. You determine which recipients are addressed, and you warrant that you have a lawful basis for contacting the people you enter in your contact directory and for the messages you instruct.
9. Personal data breach
Schweizerform notifies you of any breach of data security affecting your data without delay, and at the latest within 48 hours of becoming aware of it, in text form.
Notification is sent to the email address held for your account. You keep that address up to date.
The notification contains, insofar as known at the time of notification: the nature of the breach, the categories of data affected, the approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Schweizerform supplies missing information as soon as it becomes available; an incomplete initial notification is deemed to meet the deadline.
Schweizerform supports you in your notification duties towards the Federal Data Protection and Information Commissioner under Art. 24 nFADP and, where applicable, under Art. 33 and 34 GDPR. Assessing the duty to notify, and making the notification itself, is incumbent on you.
Schweizerform documents breaches of data security including the remedial measures taken.
Notifications under this section are made in fulfilment of statutory obligations and do not constitute an admission of fault or liability.
10. Rights of data subjects and support
Safeguarding the rights of data subjects is incumbent on you. The Service provides you with the functions required for this, in particular viewing, exporting and deleting individual submissions, and viewing, exporting and deleting the entries in your contact directory.
Schweizerform supports you with reasonable measures insofar as you cannot fulfil requests yourself through the functions of the Service. Because Schweizerform cannot decrypt the content, its support is necessarily limited to encrypted data and metadata.
If a data subject addresses a request directly to Schweizerform, Schweizerform forwards it to you without delay and does not answer it itself. Where a recipient of an invitation objects to receiving further messages, Schweizerform records that objection and enforces it for future sends, in fulfilment of its own obligations as the sender of the message; it does not thereby answer any further request on your behalf.
Schweizerform supports you with data protection impact assessments and with consultations of the supervisory authority, insofar as the necessary information originates from Schweizerform's sphere of responsibility.
Support services under sections 9 and 10 are provided free of charge to the usual extent. If the effort exceeds the usual extent — in particular in the case of repeated or extensive requests, individual evidence, questionnaires, on-site inspections or separate analyses — Schweizerform informs you in advance and begins the work only after your approval in text form, against reimbursement at our then-current rates. This does not apply insofar as the effort is attributable to a breach of duty for which Schweizerform is responsible.
11. Sub-processors
You grant Schweizerform the general authorisation to engage sub-processors in accordance with this section (Art. 9 para. 3 nFADP). The sub-processors engaged at the time this version was published are listed below. This list is the authoritative one; the Terms of Service refer to it.
| Provider | Service | Place of processing | Notes |
|---|---|---|---|
| Infomaniak Network SA, Geneva | Application servers, database and object storage; delivery of transactional email; optional AI services for translating and creating form texts | Switzerland | Submission content exclusively as ciphertext; no plaintext access to responses. No submission content is sent by email. The AI services are optional, disabled by default, process exclusively form texts written by you, and never submissions. |
| Bjørnerås Labs (the «EuSend» service), org. no. 938 162 336, Norway | Sending of transactional e-mails: one-time codes and account messages; invitations to join a team workspace; and, where you activate them, invitations to your forms addressed to recipients you designate, and receipts requested by a person who has filled in one of your forms | Norway (provider); processing and delivery in Germany and Finland | Processes the recipient address, subject and content of the message concerned. No submissions and no responses of data subjects. An invitation to one of your forms names your organisation, names the form only where you have chosen to include the form name, and carries no name of the recipient, no free text written by you and no submission content. A receipt confirms that a submission was received and contains no answer; its recipient address is the one supplied by the person requesting it. Message content is processed and stored exclusively on infrastructure in the EEA (Germany, Finland); the provider deletes delivery logs including the rendered message content automatically, at the latest after 90 days. For the operation of its own website, for DNS and for error diagnostics the provider additionally engages service providers in the United States; these are not involved in the delivery path for message content, and those disclosures rely on the EU-US Data Privacy Framework or the standard contractual clauses. The provider's data processing agreement applies. |
Payment processing (Stripe Payments Europe, Ltd., Ireland) concerns exclusively your own contact, account and billing data, which Schweizerform processes as controller (section 1); it is described in the privacy policy and is not sub-processing under this agreement.
If Schweizerform intends to engage a further sub-processor or to replace an existing one, it notifies you at least 30 days in advance in text form.
You may object to the change within 30 days of receipt of the notification, in text form, on substantiated data protection grounds. If no objection is made within that period, the change is deemed approved.
If you object and the parties do not find an amicable solution within 30 days, either party may terminate this agreement and the Terms of Service with ordinary notice as of the planned date of the change. No further claims arise from the objection.
The removal of a sub-processor without replacement requires no prior notification and no objection procedure; it takes effect with the publication of the new edition of this agreement (section 17).
Schweizerform may replace a sub-processor without prior notification where this is necessary to avert an immediate danger to the security or availability of the Service. In that case it informs you without delay afterwards.
Schweizerform contractually binds sub-processors to obligations that correspond in substance to the obligations under this agreement, including the confidentiality under section 4 and, where applicable, section 5.
Schweizerform is liable for its sub-processors' compliance with data protection obligations as for its own conduct, within the framework of the liability provisions in section 15.
Ancillary services without intended access to your personal data — in particular telecommunications services and maintenance by third parties without data access — do not constitute sub-processing.
12. Place of processing and disclosure abroad
Submissions. All submissions of data subjects — responses and file attachments — are processed and stored exclusively in Switzerland (application servers, database, object storage). No processing of this data takes place outside Switzerland. The contact directory is likewise stored exclusively in Switzerland, and in encrypted form (section 7).
Ancillary services outside Switzerland. Outside Switzerland, only the delivery of transactional e-mail by the mail delivery provider listed in section 11 (Norway; processing and delivery in Germany and Finland) takes place. E-mail delivery comprises no submissions, no responses and no answer content. It comprises personal data of a data subject only in two cases — where you instruct an invitation to a recipient you designate, and where a person who has filled in one of your forms asks for a receipt to be sent to them — and in each case only the recipient's e-mail address and the message described in section 11. Your own billing data is processed by the payment provider named in the privacy policy (section 1); that is not processing on your behalf. Any further processing outside Switzerland takes place only after prior notification in accordance with section 11.
E-mail delivery by the provider listed in section 11 takes place entirely within the European Economic Area. The states concerned — Norway, Germany and Finland — provide adequate data protection according to Annex 1 of the Data Protection Ordinance. That disclosure is therefore permissible under Art. 16 para. 1 nFADP without additional safeguards.
For any onward disclosures by these sub-processors to recipients outside the European Economic Area, Schweizerform engages only sub-processors whose own terms provide a basis compliant with Art. 16 and 17 nFADP and, where applicable, with Chapter V GDPR for such onward disclosures, in particular an adequacy decision or the standard contractual clauses of the European Commission. Schweizerform passes on the corresponding documentation of the sub-processors on request.
13. Evidence and audits
On request, Schweizerform demonstrates compliance with the obligations under this agreement, primarily through an up-to-date description of the measures taken, through self-assessment, and through certificates or audit reports of its sub-processors.
If this evidence is insufficient in a substantiated individual case, you may carry out an audit, at most once per calendar year, or have it carried out by an independent third party bound to secrecy and not in competition with Schweizerform. The audit is carried out remotely, on the basis of documents and written answers, upon at least 30 days' prior notice and with the least possible disruption to operations; it does not exceed two working days of Schweizerform's effort.
An audit on Schweizerform's premises takes place only in the case of a substantiated suspicion of a serious breach of data security; in that case the restrictions of the previous paragraph as to frequency, notice period, form and duration do not apply.
You bear the costs of an audit and reimburse Schweizerform's effort at our then-current rates. If material breaches of duty by Schweizerform are established, Schweizerform bears those costs.
Access to systems, premises and data of third parties, as well as to trade and business secrets of Schweizerform, remains reserved. Direct access to production systems is not granted.
14. Retention, deletion and return
During the term of the contract you can obtain your data yourself at any time through the export functions of the Service. This self-service constitutes handing over the data within the meaning of Art. 9 nFADP.
You may request the deletion of individual submissions at any time during the term of the contract; the corresponding function is directly available to you in the Service. If the request is made exceptionally through Schweizerform, Schweizerform carries out the deletion within 30 days.
- •Security log. IP address and user agent are automatically removed from log entries after 90 days; the event entry itself (time, action, object, outcome) is retained as evidence.
- •Email delivery log. Entries including the rendered message content are automatically deleted after 90 days. Invitations to your forms and receipts requested by a respondent are not entered in this log at all — neither the recipient address nor the message content is recorded (see the 'Invitation records' entry below).
- •Contact directory. Entries in your contact directory are kept for as long as you keep them and are deleted when you delete them, at the latest when your account or the workspace concerned is deleted. Where you delete a contact who has objected to receiving further messages, values derived from their e-mail address are retained so that the objection is still honoured if the address is imported again. That residue holds no readable address, is used for no other purpose, and is deleted together with your account or the workspace concerned.
- •Invitation records. For each invitation sent, a record of the delivery status is kept for as long as the form exists and is deleted together with it. It contains no recipient address, no name and no message content. For a receipt, and for the copy a person generates for themselves on the confirmation page, only the time is recorded on the submission concerned.
- •Saved partial forms. Where you switch on saving and resuming for a form, the partly completed answers a respondent saves are stored encrypted in the same way as submissions and are deleted automatically 30 days after they were last saved, at the latest together with the form.
- •Backup copies. A deletion takes effect immediately in the production systems. Data in backup copies is overwritten in the course of the ordinary backup cycle, at the latest within 30 days (the backup cycle of the database is currently seven days). Until then it remains blocked exclusively for the purpose of restoration and is not otherwise processed.
After the end of the contract, Schweizerform returns or deletes the personal data at your choice, including existing copies. You communicate your choice in text form within 30 days of the end of the contract. If no communication is made, Schweizerform deletes the data after expiry of that period. Section 7 applies to the form of the return. If you delete your account yourself through the function of the Service, this is deemed to be a choice of deletion; in that case the deletion takes place immediately and irreversibly, and the period under this paragraph does not apply. You carry out your exports beforehand.
Schweizerform confirms the deletion in text form on request. Retention beyond the end of the contract is permissible insofar as statutory retention obligations exist; in that case Schweizerform limits the processing to the purpose of retention.
15. Liability
The parties are liable in accordance with the statutory provisions.
The limitation of liability agreed in the Terms of Service — in particular the limitation of total liability to the fees paid to Schweizerform in the twelve months preceding the damaging event, as well as the exclusion of indirect and consequential damage — also applies to claims under this agreement.
That limitation of liability does not apply to damage arising from gross negligence or intent (Art. 100 para. 1 CO), nor in the case of injury to life, limb or health.
Schweizerform's liability is excluded for damage attributable to: the loss of the Vault key or the recovery code (section 7); the design, content or lawfulness of your forms; the lawfulness of the messages you instruct and of the recipients you designate; your management of accesses and permissions; or instructions of yours whose questionable nature Schweizerform pointed out in accordance with section 3.
If one party is held liable by data subjects or authorities on account of a breach of duty by the other party, the party in breach indemnifies the other party to the extent of its share of responsibility. The second and third paragraphs of this section remain reserved.
16. Term, termination and discontinuation of the Service
This agreement enters into force when you create an account and applies for the term of the Terms of Service. It ends automatically upon their termination; no separate notice of termination is required. For accounts that already existed when this version enters into force, it enters into force upon that entry into force, and continued use of the Service thereafter is deemed to be acceptance in accordance with the Terms of Service. Where a new edition is published without notification because section 17 does not require one, continued use of the Service after the date on which that edition enters into force is deemed to be acceptance.
Termination of the Terms of Service is governed by the Terms of Service. Schweizerform is entitled to discontinue the Service in accordance with the Terms of Service; in that case it informs you at least 90 days in advance in text form and enables you to export your data during that period.
The right to extraordinary termination for good cause remains reserved to both parties.
The obligations of confidentiality (section 4) and of professional secrecy (section 5) continue beyond the end of this agreement.
17. Changes to this agreement
Schweizerform may amend this agreement insofar as this is necessary to adapt to a changed legal situation, case law, regulatory practice, or to a further development of the Service.
Every change is published as a new edition of this document, bearing its own date of entry into force and a changelog entry. Published editions are never edited retroactively and remain retrievable; only corrections that do not change the meaning of a clause may be made in place.
A change is material if it widens the processing carried out on your behalf or weakens a protection or a right under this agreement — in particular: a new category of personal data or of data subjects, or a new purpose (section 2); a new sub-processor or the replacement of an existing one (section 11); a new country of processing (section 12); a longer retention period (section 14); the weakening of a measure under section 6 or of a guarantee under section 7; and a change to section 5, 9, 13 or 15, or to this section 17, that reduces your rights. Not material are, in particular, a change that only narrows the processing — such as the removal of a sub-processor without replacement, the removal of a place of processing, the shortening of a retention period or the strengthening of a protection —, a more precise description of processing that already takes place, and an additional value recorded under section 6 that identifies no person and is either an aggregate count per form or per question or recorded only on your instruction or on a setting you switch on. Where it is doubtful whether a change is material, it is treated as material.
Schweizerform notifies material changes at least 30 days before they take effect, in text form, to the e-mail address held for your account. Text form within the meaning of this agreement includes e-mail.
Changes that are not material take effect when the new edition is published. That dispenses with the advance notice only; it does not dispense with the new edition, with its date of entry into force, or with the changelog entry.
Where the notification concerns the engagement of a new sub-processor or the replacement of an existing one (section 11), you may object within 30 days of receipt, in text form, on substantiated data protection grounds; the procedure and the consequences set out in section 11 apply. For other changes there is no right to object; the following paragraph remains reserved.
Where a change weakens a measure under section 6 or a guarantee under section 7, you may terminate this agreement and the Terms of Service, in text form before the change takes effect, with effect from the date on which it takes effect; until then the previous edition continues to apply to you. A change that would remove or curtail the content that Art. 9 nFADP and Art. 28(3) GDPR require this agreement to contain never takes effect by silence and requires your express agreement in every case.
The date on which the edition in force took effect is stated at the end of this page.
18. Governing law and place of jurisdiction
Swiss law applies, excluding its conflict-of-law rules and the United Nations Convention on Contracts for the International Sale of Goods.
The exclusive place of jurisdiction for all disputes arising out of or in connection with this agreement is Pfäffikon SZ, Switzerland.
Acceptance, edition and contact
This Data Processing Agreement forms part of the Schweizerform Terms of Service and is accepted automatically when you create an account. No signature is required, and this document intentionally contains no signature block.
In force since 25 September 2026
If you need a countersigned copy of this agreement — for your own records, for example — write to support@schweizerform.ch. The countersigned copy is provided in electronic form and contains this standard text unchanged; a description of your own processing, if you need one, is attached to it as a factual annex which describes facts and does not vary the clauses of this agreement, and is prepared against reimbursement of the effort (section 10).
The processor
Balathanusan JeyarasanSole proprietorship, trading as «Schweizerform»c/o ExpertFid & Audit SAChurerstrasse 1588808 PfäffikonSwitzerlandsupport@schweizerform.ch