Sharpsoft, Luc Baumann (processor) and the customer (controller). Version 1.2 of 8 October 2026. This annex applies in accordance with Art. 9 of the Federal Act on Data Protection (FADP) when Sharpsoft processes personal data for the customer. It forms part of every contract for hosting, maintenance, migration or the integration of systems.
1. Subject matter
1.1 Sharpsoft processes personal data only to the extent necessary for the agreed services:
- Hosting: operating and backing up the website and its database. Which hosting target a website uses (Sharpsoft's server or Google Firebase Hosting) is stated in the handover information in the portal.
- Maintenance: fixing errors and installing updates.
- Migration and integration: transferring data from existing systems.
1.2 Data subjects: visitors to the website, the customer's customers and prospective customers, and the customer's employees.
1.3 Categories of data:
- contact details (name, address, email, telephone)
- content of enquiries
- order and invoicing data
- access data for customer accounts (passwords stored only in encrypted form)
- technical data (IP address, time, browser) in server logs
Sharpsoft processes sensitive personal data (e.g. health data) only on the basis of an express written agreement.
2. Obligations of Sharpsoft
2.1 Sharpsoft processes the data only in accordance with the customer's instructions and only for the agreed purposes, not for its own purposes.
2.2 Sharpsoft protects the data with appropriate technical and organisational measures:
- Access: encrypted connections (HTTPS, SSH); access to servers only with a personal key and two-factor authentication, where available.
- Keeping up to date: operating systems and software are updated continuously.
- Backups: daily, encrypted and separate from the server.
- Work devices: hard disks encrypted, passwords in a password manager.
- Data minimisation: copies of customer data on work devices only for as long as necessary. Anonymised data is used for development and testing wherever possible.
2.3 Anyone at Sharpsoft who has access to the data is bound by confidentiality.
2.4 Sharpsoft notifies the customer as quickly as possible, and no later than 72 hours after becoming aware of it, of any data security breach affecting the customer's data. Sharpsoft supports the customer in investigating it and in any notifications to the Federal Data Protection and Information Commissioner (FDPIC) and to data subjects.
2.5 On request, Sharpsoft supports the customer with requests from data subjects for information, correction and deletion. Effort exceeding a few minutes is personal work (GTC clause 7.1: CHF 40 per quarter hour or part thereof, only with the customer's consent and with the price stated in advance).
3. Sub-processors
3.1 The customer authorises Sharpsoft to engage the following sub-processors:
3.1a The following are not sub-processors within the meaning of this annex:
- Payment providers for Sharpsoft's invoices (currently the bank for QR-bills, possibly further payment providers later). They process the customer's payment data as a customer of Sharpsoft, not personal data that Sharpsoft processes for the customer. This is governed by Sharpsoft's privacy policy.
- Payment providers in the customer's shop. The customer concludes a separate contract with the provider for this purpose. The provider collects the payment data of the customer's clientele on its own payment page.
3.2 The customer grants Sharpsoft general authorisation to engage the sub-processors listed in clause 3.1. Sharpsoft notifies the customer of new or different sub-processors at least 30 days in advance by email and in the portal. The customer may object in text form within 30 days on objective grounds relating to data protection. If no solution is reached, either party may terminate the affected services with effect from the change; prepaid fees are refunded pro rata. If there is no objection, the change is deemed approved. Sharpsoft remains responsible to the customer for the services of its sub-processors.
3.3 Sharpsoft contractually obliges sub-processors to provide an equivalent level of data protection. Data is transferred only to countries with adequate data protection under Annex 1 of the Data Protection Ordinance (DPO) or with appropriate safeguards.
4. Rights of the customer
4.1 The customer may request information about the measures under clause 2.2. An on-site audit is possible with 30 days' advance notice. Sharpsoft's effort for this is personal work under GTC clause 7.1.
4.2 The customer is responsible for the lawfulness of the processing, in particular for informing the data subjects (privacy policy on the customer's website).
5. End of processing
After the end of the contract, Sharpsoft hands over the data on request in a common format and deletes it no later than 30 days after the end of the contract, including in the backups once they expire, provided there is no statutory retention obligation.