Annex to the GTC: Processing of personal data on behalf of the customer

Version 1.2 · Last updated: 8 October 2026

Translation. Only the German version is legally binding.

Sharpsoft, Luc Baumann (processor) and the customer (controller). Version 1.2 of 8 October 2026. This annex applies in accordance with Art. 9 of the Federal Act on Data Protection (FADP) when Sharpsoft processes personal data for the customer. It forms part of every contract for hosting, maintenance, migration or the integration of systems.

1. Subject matter

1.1 Sharpsoft processes personal data only to the extent necessary for the agreed services:

  • Hosting: operating and backing up the website and its database. Which hosting target a website uses (Sharpsoft's server or Google Firebase Hosting) is stated in the handover information in the portal.
  • Maintenance: fixing errors and installing updates.
  • Migration and integration: transferring data from existing systems.

1.2 Data subjects: visitors to the website, the customer's customers and prospective customers, and the customer's employees.

1.3 Categories of data:

  • contact details (name, address, email, telephone)
  • content of enquiries
  • order and invoicing data
  • access data for customer accounts (passwords stored only in encrypted form)
  • technical data (IP address, time, browser) in server logs

Sharpsoft processes sensitive personal data (e.g. health data) only on the basis of an express written agreement.

2. Obligations of Sharpsoft

2.1 Sharpsoft processes the data only in accordance with the customer's instructions and only for the agreed purposes, not for its own purposes.

2.2 Sharpsoft protects the data with appropriate technical and organisational measures:

  • Access: encrypted connections (HTTPS, SSH); access to servers only with a personal key and two-factor authentication, where available.
  • Keeping up to date: operating systems and software are updated continuously.
  • Backups: daily, encrypted and separate from the server.
  • Work devices: hard disks encrypted, passwords in a password manager.
  • Data minimisation: copies of customer data on work devices only for as long as necessary. Anonymised data is used for development and testing wherever possible.

2.3 Anyone at Sharpsoft who has access to the data is bound by confidentiality.

2.4 Sharpsoft notifies the customer as quickly as possible, and no later than 72 hours after becoming aware of it, of any data security breach affecting the customer's data. Sharpsoft supports the customer in investigating it and in any notifications to the Federal Data Protection and Information Commissioner (FDPIC) and to data subjects.

2.5 On request, Sharpsoft supports the customer with requests from data subjects for information, correction and deletion. Effort exceeding a few minutes is personal work (GTC clause 7.1: CHF 40 per quarter hour or part thereof, only with the customer's consent and with the price stated in advance).

3. Sub-processors

3.1 The customer authorises Sharpsoft to engage the following sub-processors:

ProviderPurposeData location
Hetzner Online GmbH (Germany)Servers and storage for websites with a backend or high traffic and for backupsGermany (EU)
Google Firebase Hosting (Google LLC or Google Cloud EMEA Limited, Ireland)Hosting of static websites; delivery to visitors, including processing of their IP addresses (technical data under clause 1.3)worldwide, USA, no fixed location; Swiss-U.S. Data Privacy Framework, otherwise standard contractual clauses under the Firebase Data Processing and Security Terms
GitHub, Inc. (Microsoft)The customer's source code in a dedicated repository: website, any backend, configuration and automated tests, only with test data (without personal data of end customers)USA; Swiss-U.S. Data Privacy Framework
Cloudflare, Inc.DNS, protection against attacks, delivery (if used for the website)worldwide, USA; Swiss-U.S. Data Privacy Framework
Anthropic Ireland, Limited (with Anthropic, PBC, USA)AI agents that handle change requests and questions from the customer portal and via the interface and prepare changes. Anthropic does not use the data to train its AI models and usually deletes it after 30 days. The customer does not enter confidential data in the portal or via the interface (GTC clause 4.8). With the option “AI with data processing agreement” (available in the quote), the agents run exclusively through a business account with a data processing agreement (DPA). Without the option, Sharpsoft may also use another account with training switched off; Anthropic then processes the data in accordance with its own privacy policyIreland, USA; Anthropic is not certified under the Data Privacy Framework. With the option: standard contractual clauses with a Swiss addendum in Anthropic's data processing agreement (DPA)
Google Workspace (Google Cloud EMEA Limited, Ireland, with Google LLC, USA)Email of luc@sharpsoft.ch and notifications from the portal, if the customer sends personal data by emailIreland, USA; Swiss-U.S. Data Privacy Framework, otherwise standard contractual clauses with a Swiss addendum

3.1a The following are not sub-processors within the meaning of this annex:

  • Payment providers for Sharpsoft's invoices (currently the bank for QR-bills, possibly further payment providers later). They process the customer's payment data as a customer of Sharpsoft, not personal data that Sharpsoft processes for the customer. This is governed by Sharpsoft's privacy policy.
  • Payment providers in the customer's shop. The customer concludes a separate contract with the provider for this purpose. The provider collects the payment data of the customer's clientele on its own payment page.

3.2 The customer grants Sharpsoft general authorisation to engage the sub-processors listed in clause 3.1. Sharpsoft notifies the customer of new or different sub-processors at least 30 days in advance by email and in the portal. The customer may object in text form within 30 days on objective grounds relating to data protection. If no solution is reached, either party may terminate the affected services with effect from the change; prepaid fees are refunded pro rata. If there is no objection, the change is deemed approved. Sharpsoft remains responsible to the customer for the services of its sub-processors.

3.3 Sharpsoft contractually obliges sub-processors to provide an equivalent level of data protection. Data is transferred only to countries with adequate data protection under Annex 1 of the Data Protection Ordinance (DPO) or with appropriate safeguards.

4. Rights of the customer

4.1 The customer may request information about the measures under clause 2.2. An on-site audit is possible with 30 days' advance notice. Sharpsoft's effort for this is personal work under GTC clause 7.1.

4.2 The customer is responsible for the lawfulness of the processing, in particular for informing the data subjects (privacy policy on the customer's website).

5. End of processing

After the end of the contract, Sharpsoft hands over the data on request in a common format and deletes it no later than 30 days after the end of the contract, including in the backups once they expire, provided there is no statutory retention obligation.