Start for Free Book a Demo Contact
Platform Login
Legal

Data Processing Agreement (DPA)

Agreement on the processing of personal data on behalf of the customer under Art. 9 FADP and Art. 28 GDPR. Part of every contract for the use of the Evoya AI platform. This is a translation; the German version prevails.

Last updated: September 25, 2026

1. Subject matter and applicability

1.1 This data processing agreement ("DPA") governs the rights and obligations of Evoya AI GmbH, Brunnenstrasse 27, 8610 Uster, Switzerland ("Evoya AI"), and the Customer insofar as Evoya AI processes personal data on behalf of the Customer under the Main Contract.

1.2 The "Main Contract" is the contract for the use of the Platform and any Services under the Terms and Conditions ("Terms") of Evoya AI, including quotes and service descriptions.

1.3 This DPA becomes part of the contract upon conclusion of the Main Contract or acceptance of the Terms, without the need for a separate signature. On request, Evoya AI provides the Customer with a signed copy. If the parties have concluded an individual DPA, it takes precedence.

1.4 This DPA applies to processing under the Swiss Federal Act on Data Protection (FADP). Where the EU General Data Protection Regulation (GDPR) applies to the processing, it also constitutes a contract under Art. 28(3) GDPR.

1.5 In the event of conflict, this DPA takes precedence over the Terms in matters of data protection.

2. Definitions

Terms such as "personal data", "processing", "controller", "processor", "data subject" and "data security breach" have the meaning given under the FADP or, where applicable, the corresponding terms of the GDPR (including "personal data breach"). Terms such as "Customer Data", "Users", "AI Models" and "Model Providers" have the meaning given in the Terms.

3. Nature, purpose and scope of processing

3.1 The Customer is the controller and Evoya AI is the processor. If the Customer is itself a processor for a third party, Evoya AI is a sub-processor; the Customer ensures that its instructions are consistent with those of the third party.

3.2 The subject matter, nature and purpose of the processing, the categories of personal data and data subjects, and the duration are set out in Annex 1.

3.3 Evoya AI processes the personal data solely to provide the services under the Main Contract, for support, to ensure security and to prevent abuse. Evoya AI does not use the personal data for its own purposes, in particular not for advertising and not to train AI models.

3.4 This DPA does not cover processing of personal data for which Evoya AI is itself the controller, e.g. account, contract and billing data of the Customer's contact persons and technical usage data for billing and operations. Evoya AI's Privacy Policy applies to such processing.

4. Instructions

4.1 Evoya AI processes personal data only on documented instructions from the Customer, unless required to do so by applicable law. In such a case, Evoya AI informs the Customer of that legal requirement before processing, unless that law prohibits such information.

4.2 Documented instructions are the Main Contract and this DPA, as well as all settings and actions made by the Customer and its Users on the Platform, in particular the selection of AI Models, the setting of retention periods, the connection of third-party systems, the management of Users and the deletion of content.

4.3 The Customer issues further instructions in writing; email is sufficient. Evoya AI may make instructions that go beyond the agreed scope of services subject to remuneration, or refuse them if they are technically not feasible.

4.4 If Evoya AI considers that an instruction infringes data protection law, it informs the Customer without undue delay and may suspend its implementation until the Customer confirms or changes the instruction.

5. Obligations of Evoya AI

5.1 Confidentiality: Evoya AI grants access to the personal data only to persons who need it to provide the services and who are bound by confidentiality or subject to a statutory duty of confidentiality.

5.2 Data security: Evoya AI implements the technical and organisational measures described in Annex 3 to ensure a level of data security appropriate to the risk (Art. 8 FADP, Art. 32 GDPR). Evoya AI may adapt the measures to technical developments provided the level of protection is not reduced.

5.3 Assistance: Taking into account the nature of the processing and the information available to it, Evoya AI reasonably assists the Customer in fulfilling its obligations, in particular with data subject requests (section 11), notifications of data security breaches (section 10), data protection impact assessments and prior consultations with the supervisory authority.

5.4 Records: Where required by law, Evoya AI maintains a record of the processing activities it carries out on behalf of the Customer.

5.5 Requests from authorities: If Evoya AI receives a request from an authority to disclose the Customer's personal data, it refers the authority to the Customer where possible and informs the Customer unless legally prohibited. Evoya AI only discloses personal data if legally required to do so.

5.6 Contact: The contact for data protection matters is Steven Chareonbood, Managing Director, [email protected].

6. Obligations of the Customer

6.1 The Customer is responsible for the lawfulness of the processing, in particular for having the required legal bases and consents and for informing the data subjects appropriately.

6.2 The Customer decides which personal data it enters into the Platform. It only enters sensitive personal data and data subject to professional or official secrecy where this is lawful and it has chosen suitable settings, e.g. Swiss Mode, short retention periods or a restriction of the available models.

6.3 The Customer assesses whether the measures described in Annex 3 are appropriate for its processing. By concluding the Main Contract, it confirms that they are.

6.4 The Customer informs Evoya AI without undue delay if it detects errors or irregularities relating to data protection.

7. Sub-processors

7.1 The Customer grants Evoya AI general authorisation to engage sub-processors. The categories of sub-processors used are set out in Annex 2. Evoya AI provides the current list with names, registered offices and processing locations to the Customer on request. Section 8 additionally applies to AI Model Providers.

7.2 Evoya AI informs the Customer at least 30 days in advance by email or on the Platform of any intended addition or replacement of a sub-processor. Within this period, the Customer may object in writing for important data protection reasons. The parties then seek an amicable solution. If none is reached, the Customer may terminate the affected service effective as of the change; fees already paid for the period after termination are refunded pro rata. If the Customer does not object in time, the engagement is deemed approved.

7.3 Evoya AI contractually binds each sub-processor to data protection obligations that are essentially equivalent to those of this DPA and selects it carefully, in particular with regard to data security.

7.4 Ancillary services where third parties have no or only incidental access to personal data, e.g. telecommunications and transport services or hardware maintenance, do not constitute sub-processing.

8. AI Model Providers

8.1 The Platform enables the use of AI Models from various Model Providers. For each model, the Platform shows which provider supplies it and in which country it is operated. Models from providers in countries without an adequate level of data protection are labelled.

8.2 If the Customer or an authorised User selects a model, this constitutes an instruction to transmit the Inputs and the content required for the response to the respective Model Provider. The Model Providers displayed on the Platform are deemed approved sub-processors. Section 7.2 does not apply to them; new models are displayed on the Platform and the Customer decides on their use through its selection.

8.3 Via the Platform administration, the Customer can determine which models are available to its Users and thereby exclude individual Model Providers or countries.

8.4 Evoya AI connects third-party models exclusively via their business interfaces (APIs), under which the providers commit in their terms not to use the transmitted data to train their models. Some Model Providers temporarily store Inputs and Outputs under their terms, e.g. for up to 30 days for abuse monitoring. Whether a provider offers zero data retention is indicated on the Platform or communicated on request.

8.5 In Swiss Mode, only models operated in Switzerland are used.

9. International transfers

9.1 By default, Evoya AI stores Customer Data in data centres in Switzerland. Disclosure abroad only takes place where necessary to provide the services, in particular when models from foreign Model Providers are used or foreign sub-processors are engaged.

9.2 Where data is disclosed to a country without an adequate level of data protection under Annex 1 of the Swiss Data Protection Ordinance (DPO) or without an adequacy decision of the European Commission, Evoya AI ensures data protection by appropriate safeguards, in particular the European Commission's standard contractual clauses with the adaptations required for Switzerland or the recipient's certification under the Swiss-U.S. or EU-U.S. Data Privacy Framework.

9.3 If a Model Provider labelled on the Platform does not offer such safeguards, the disclosure takes place solely on the basis of the Customer's or its Users' selection of the model (section 8.2). The Customer is responsible for ensuring that an exception under Art. 17 FADP or Art. 49 GDPR applies to such disclosure, or it excludes such models in accordance with section 8.3.

10. Data security breaches

10.1 Evoya AI notifies the Customer of a data security breach affecting the Customer's personal data without undue delay after becoming aware of it, where possible within 48 hours.

10.2 The notification contains, as far as known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. Evoya AI provides information not yet available at a later stage.

10.3 Evoya AI takes appropriate measures without undue delay to remedy the breach and mitigate its consequences. Notification to supervisory authorities and data subjects is the Customer's responsibility; Evoya AI assists it in doing so.

10.4 A notification under this section does not constitute an acknowledgement of fault or liability.

11. Data subject rights

11.1 If a data subject contacts Evoya AI directly with a request concerning Customer Data, Evoya AI forwards the request to the Customer without undue delay and does not respond itself unless instructed otherwise by the Customer.

11.2 The Customer can delete content such as chat histories and manage Users on the Platform itself. Where the Customer cannot implement access, rectification, erasure or data portability itself via the Platform, Evoya AI assists it on request. Evoya AI may charge for effort beyond the usual scope at the agreed or customary rates.

12. Evidence and audits

12.1 On request, Evoya AI provides the Customer with the information necessary to demonstrate compliance with this DPA, in particular a description of the measures under Annex 3, the list of sub-processors and available certificates or audit reports of the data centres.

12.2 If this evidence is insufficient in an individual case or a supervisory authority so requires, the Customer may carry out an audit itself or have it carried out by an auditor bound by confidentiality who is not a competitor of Evoya AI. Audits must be announced at least 30 days in advance, take place during business hours, must not unreasonably disrupt operations and are permitted at most once per calendar year, except in the event of a justified suspicion of a breach. They do not extend to data of other customers or to facilities of sub-processors, for which their own evidence applies.

12.3 The Customer bears the costs of an audit, including Evoya AI's internal effort at customary rates. If the audit reveals a material breach of this DPA by Evoya AI, Evoya AI bears its own costs.

13. Deletion and return

13.1 During the term of the contract, content is retained in accordance with the settings chosen by the Customer on the Platform.

13.2 After the Main Contract ends, Evoya AI provides the Customer Data in a common electronic format on request, which must be received no later than 30 days after the end of the contract.

13.3 After 30 days following the end of the contract, Evoya AI deletes the Customer Data unless there is a statutory retention obligation. Copies in backups are deleted in the regular backup cycle, no later than 60 days thereafter; until then they are protected against further processing. On request, Evoya AI confirms the deletion in writing.

13.4 Deletion by Model Providers is governed by their terms (section 8.4).

14. Liability

The liability provisions of the Main Contract and the Terms apply to the parties' liability under this DPA to the extent permitted by law. Mandatory liability provisions, in particular Art. 82 GDPR in relation to data subjects, remain reserved.

15. Term

This DPA applies for the term of the Main Contract and thereafter for as long as Evoya AI processes the Customer's personal data. It ends automatically upon complete deletion or return of the personal data under section 13. Separate termination of this DPA is excluded.

16. Final provisions

16.1 Evoya AI may amend this DPA in accordance with the procedure for amending the Terms, in particular in the event of changed legal requirements. Amendments must not materially reduce the level of protection for the personal data.

16.2 If any provision of this DPA is invalid, the validity of the remaining provisions is not affected.

16.3 Governing law and place of jurisdiction are determined by the Main Contract and the Terms. Mandatory provisions of the GDPR remain reserved where applicable.

16.4 This DPA is available in German and English. In the event of discrepancies, the German version prevails.

Annex 1: Description of processing

Subject matter and purpose

Provision of the Evoya AI platform as software-as-a-service, including AI chat, knowledge bases, AI agents, chatbots, email functions, APIs and integrations, as well as support, maintenance, security and abuse prevention. For Services (e.g. implementation, configuration, development), processing of Customer Data to the extent Evoya AI requires access for this purpose.

Nature of processing

Collection, storage, organisation, indexing (e.g. for semantic search), retrieval, transmission to AI Models and sub-processors, processing to generate Outputs, display, backup and deletion.

Categories of data subjects

  • the Customer's Users (e.g. employees, teachers, pupils),
  • persons whose data is contained in Inputs, documents, knowledge bases or connected systems (e.g. the Customer's customers, patients, suppliers, business partners),
  • end users of chatbots and email functions that the Customer uses towards third parties.

Categories of personal data

  • identification and contact data of Users (name, email address, role, organisation),
  • content of Inputs, documents, knowledge bases, chat histories and Outputs, which may contain any personal data,
  • content from connected systems (e.g. emails, calendars, files), to the extent the Customer grants access,
  • technical usage data (e.g. IP address, timestamps, logs).

Sensitive personal data

Not processed deliberately, but may be contained in Customer Data if the Customer or its Users enter it (e.g. health data). See section 6.2.

Duration

For the term of the Main Contract in accordance with the Customer's retention settings, thereafter until deletion under section 13.

Place of processing

Customer Data is stored in Switzerland by default. Processing by Model Providers takes place in the country of the model selected (sections 8 and 9).

Annex 2: Sub-processors

Evoya AI uses sub-processors in the following categories. The Customer can obtain the current list with names, registered offices and processing locations on request at [email protected].

  • Hosting and infrastructure: operation of the Platform, databases and backups in ISO 27001-certified data centres in Switzerland.
  • AI Model Providers: processing of Inputs to generate Outputs. The provider and country of each model are shown on the Platform (section 8).
  • Email delivery: sending system emails (e.g. invitations, notifications) and email functions of the Platform.
  • Speech and document processing: transcription, text recognition (OCR) and document conversion, where the Customer uses these functions; the provider and country are shown on the Platform.
  • Implementation partners: only if the Customer requests their involvement in the individual case.

Annex 3: Technical and organisational measures

Confidentiality

  • operation in ISO 27001-certified data centres with physical access control by the data centre operator,
  • system access for authorised persons only, personal accounts, strong passwords, two-factor authentication for administrative access,
  • role-based permission concept on the Platform, separation of different customers' data (multi-tenancy separation),
  • staff access to Customer Data only where required for support, operations or troubleshooting,
  • confidentiality obligations for all staff and contractors.

Integrity

  • encrypted transmission over the internet via TLS,
  • logging of administrative access and security-relevant events,
  • transmission to Model Providers exclusively via their encrypted interfaces.

Availability and resilience

  • regular backups, separate from the production system,
  • system monitoring, protection against malware and overload,
  • timely installation of security updates.

Data protection by design and by default

  • retention periods configurable by the Customer, down to zero data retention,
  • Swiss Mode using only models operated in Switzerland,
  • display of provider and server location for each model, labelling of models from countries without an adequate level of data protection, restriction of available models by the Customer,
  • no use of Customer Data to train AI models.

Review

  • regular review and adjustment of the measures,
  • defined process for handling security incidents,
  • careful selection and contractual obligation of sub-processors.