01 Subject matter and term of the agreement
This agreement governs the rights and duties of Aeberli Treuhand AG, Zimmergasse 17, 8008 Zurich (hereinafter the "processor") and its individual customers (hereinafter individually the "controllers", together the "parties") in connection with data-protection-related processing on instruction. This agreement applies to all activities in which the processor processes personal data, in whole or in part, on behalf of and in accordance with the instructions of the responsible controller, or has them processed.
The processor provides fiduciary and accounting services to the controller based on a separate contractual relationship.
This agreement enables the parties to comply with their obligations under the applicable data protection law when the processor processes personal data for the controller. It specifies the parties' data protection obligations arising from the processing on instruction described in the separate contract. The provisions of this agreement apply to all activities related to the separate contractual relationship in which the processor and its employees, or persons commissioned by the processor, come into contact with personal data originating from the controller or collected on its behalf.
The term of this agreement follows the term of the separate contractual relationship and may only be terminated together with it, ordinarily or extraordinarily.
02 Type of processing and type of data
The processor is granted access to personal data on behalf of the controller. This includes activities described in the separate contractual relationship.
The processor's activities may include, among other things, the following:
- Receipt, processing and dispatch of payroll data
- Preparation and dispatch of payslips
- Management of employee master data
- Preparation of certificates and notifications to authorities and insurance providers
- Access to and processing of data at the controller's premises or directly at its customer's premises
Personal data necessary to perform these activities:
- Master data of natural persons
- Employee master data
- Communication data
- Contract master data
- Payroll data
- Social insurance and health data
- Billing and payment data
- Any other personal data arising from the separate contractual relationship
03 Duties of the processor
3.1 The processor and persons reporting to it who have access to the personal data may process the data only within the scope of the assignment and the controller's instructions (collect, store, retain, use, alter, disclose, archive, delete or destroy etc.), unless an exception applies, e.g. in the case of investigations by law-enforcement authorities. In such a case the processor will inform the controller of the legal order, unless the relevant law prohibits such notification due to an important public interest. In the event of a change of authorised persons or a longer-term unavailability of the named persons, the contracting party shall be informed of the successor or representative. If a controller instruction violates applicable legal provisions, the processor will inform the controller immediately.
3.2 The processor uses the data made available for processing exclusively for the agreed purpose and not for its own purposes. It does not make copies or duplicates of the data without the controller's knowledge, except for backups.
3.3 The processor is not entitled to delete or otherwise destroy data processed on instruction on its own authority. Any deletion or destruction of the data may only take place on the basis of a written instruction from the controller, unless there is a legal reason requiring such measure.
3.4 The processing of data outside the processor's company premises, e.g. in the home offices of employees, is hereby permitted by the controller. In cases where data processing takes place in a private residence, appropriate security measures must be ensured contractually.
3.5 The processor undertakes to treat all personal data that becomes known to it in the context of this data processing agreement confidentially. This obligation continues after the end of this agreement. The processor will ensure that all persons with access to the personal data or assigned to its processing are informed of the confidentiality obligation and contractually bound accordingly.
3.6 The processor is obliged to report any data protection breaches or irregularities to the controller without delay and to disclose all relevant details of the breach, including the nature of the breach, the personal data concerned, possible consequences and the measures taken or planned to contain the incident and minimise potential negative consequences.
3.7 At the controller's request, the processor is obliged to correct data if it is incorrect or incomplete. If a data subject asserts their rights — in particular the right to information, to disclosure or transfer of data, the right to object, or the right to rectification, deletion or destruction of the data — directly to the processor, the processor will not act independently but will refer the person to the controller without delay and await its instructions.
3.8 The processor may only provide information about personal data from the processing relationship to third parties or to the data subject following prior instruction or consent of the controller.
3.9 Upon completion of the contractual work, the processor undertakes to delete or destroy all documents and processing results that have arisen in the context of this data processing agreement in accordance with data protection law and to return to the controller all documents, data and data carriers provided to it under the separate contractual relationship. Deletion or destruction takes place unless a legal reason precludes it. The processor may be legally obliged to retain certain data for a defined period. After this period the affected data will likewise be deleted or destroyed in accordance with data protection law.
3.10 The processor confirms that it is familiar with the relevant data protection regulations and undertakes to comply with them in full.
04 Technical and organisational measures
4.1 The processor undertakes to take appropriate technical and organisational measures to ensure the security of the personal data.
4.2 The processor takes suitable technical measures to protect the personal data from unauthorised access, loss or destruction. This includes the use of firewalls, encryption technologies, access controls and other suitable security precautions.
4.3 In addition, the processor implements appropriate internal organisational measures to ensure that only authorised employees have access to the personal data. These include training of employees in data protection regulations and the implementation of access restrictions.
4.4 These technical and organisational measures are reviewed regularly and updated as necessary to comply with current technological standards and applicable data protection regulations.
05 Place of data processing
5.1 Processing of the data takes place exclusively in Switzerland or in a third country that meets the legal data protection requirements.
5.2 If data processing takes place abroad or data is transferred abroad, it is ensured in advance that data protection requirements are met:
Outsourcing to a sub-processor in a member state of the European Union (EU) or the European Economic Area (EEA) or in a country that, according to applicable Swiss DPA, has an adequate level of data protection, is permissible provided a contractual agreement under the Swiss DPA is concluded (a data processing agreement).
Outsourcing to a sub-processor in a country without an adequate level of data protection is permissible provided the processor and the sub-processor conclude a contractual agreement under the Swiss DPA (a data processing agreement, DPA) and the special requirements of the Swiss DPA are met, in particular:
That the processor ensures appropriate data protection by concluding standard data protection clauses with the sub-processor, which the FDPIC has approved, issued or recognised in advance, and that, where necessary, additional measures have been agreed and implemented in addition to the standard data protection clauses.
06 Sub-processing relationships
6.1 The processor generally provides its services itself. The use of sub-contractors is only permitted with the prior written consent of the controller.
6.2 A sub-contractor relationship requiring consent exists when the processor commissions further processors with the provision of all or part of the services agreed in the contract.
6.3 The processor is obliged to notify the controller in writing of changes relating to the sub-contractor, e.g. the addition or replacement of a sub-contractor.
6.4 The sub-contractor must be selected carefully according to its suitability and reliability. Engagement of further processors in third countries may only take place if the legal data protection requirements are met.
6.5 The processor is obliged to contractually pass on all data-protection obligations under this contract to the sub-contractor and to ensure that the sub-contractor fully complies with the data protection rules and contractual requirements.
07 Liability
7.1 The controller is responsible to the data subject for compensation for damages or other claims arising in connection with the processing of personal data. Direct recourse against the processor is only permissible if the processor has acted with gross negligence or has intentionally violated the provisions of this contract.
08 Final provisions
8.1 Amendments or additions to this contract or to parts of it require written form.
8.2 Should a provision of this contract be invalid or unenforceable, or should this contract have a gap, the validity and enforceability of the remaining provisions of the contract shall not be affected. The invalid or unenforceable provision or the gap shall be replaced by a valid and enforceable provision that, from the parties' perspective, comes economically closest to the objective associated with the invalid or unenforceable provision.
8.3 This agreement is governed exclusively by Swiss law, excluding conflict of laws. The place of jurisdiction is Zurich.
8008 Zurich
Switzerland
Tel: +41 (0) 44 265 66 66
Email: info@aeberli.ch