Data Processing Agreement
Last updated: July 16, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Controller") and MyData AG, Bern, Switzerland ("Processor" or "Nolen") on the use of the Nolen platform (the "Main Agreement"). It implements the requirements of Art. 9 of the Swiss Federal Act on Data Protection (FADP/nDSG) and, where applicable, Art. 28 of the EU General Data Protection Regulation (GDPR).
1. Subject matter and roles
The Processor processes personal data on behalf of the Controller to the extent necessary to provide the services under the Main Agreement. The Controller remains responsible for the lawfulness of the processing; the Processor processes the data exclusively on behalf of and for the purposes of the Controller. The details of the processing (subject matter, nature, purpose, categories of data and data subjects) are set out in Annex 1.
2. Instructions
The Processor processes personal data only on documented instructions from the Controller, unless required to do otherwise by law applicable to the Processor, in which case the Processor will inform the Controller before processing unless the law prohibits this. The Main Agreement, this DPA and the configuration options used by the Controller within the platform constitute the Controller's instructions. The Processor will inform the Controller without undue delay if, in its opinion, an instruction infringes applicable data protection law.
3. Responsibility of the Controller
The Controller is responsible for the lawfulness of the personal data it submits to the platform and of the instructions it gives, including any required legal bases and information of data subjects. The Controller will provide the Processor with reasonable cooperation where the Processor requires it to comply with its obligations under this DPA.
4. Confidentiality of personnel
The Processor ensures that all persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they process the data only on instruction.
5. Security of processing
The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Art. 8 FADP, Art. 32 GDPR), including encryption of data in transit, access and authorisation controls, logging, and regular review of the effectiveness of the measures. The Processor may update these measures provided the level of protection is not reduced. A current description of the measures is available on request.
6. Sub-processors
The Controller grants the Processor general authorisation to engage sub-processors for the provision of the services. The Processor maintains a list of the sub-processors used, which is available on request at [email protected], and will inform the Controller of intended additions or replacements at least 14 days in advance. The Controller may object to a change on justified data protection grounds; if no mutually acceptable solution is found, the Controller may terminate the affected services. The Processor imposes on each sub-processor data protection obligations essentially equivalent to those in this DPA and remains fully liable to the Controller for the performance of its sub-processors.
7. Data location and international transfers
Personal data is processed in Switzerland and the EU/EEA by default. The Processor transfers personal data to a country without an adequate level of data protection only if appropriate safeguards within the meaning of Art. 16 et seq. FADP and Art. 44 et seq. GDPR are in place, in particular standard contractual clauses supplemented where necessary by additional measures.
8. Data subject rights
Taking into account the nature of the processing, the Processor supports the Controller with appropriate technical and organisational measures in fulfilling its obligation to respond to requests of data subjects (access, rectification, erasure, restriction, portability, objection). If a data subject contacts the Processor directly, the Processor will forward the request to the Controller without undue delay.
9. Notification and assistance
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, providing the information reasonably available to it. The Processor further assists the Controller, taking into account the nature of the processing and the information available to it, with data protection impact assessments, prior consultations with supervisory authorities, and the Controller's own notification obligations.
10. Deletion and return of data
During the term of the Main Agreement, the Controller can export its data through the functions of the platform. After the end of the Main Agreement, the Processor deletes the personal data processed on behalf of the Controller within 30 days, unless statutory retention obligations require continued storage; in that case the data is blocked for any other use and deleted once the obligation ends.
11. Audits
The Processor makes available to the Controller the information necessary to demonstrate compliance with this DPA, in particular suitable documentation and, where available, current audit reports or certifications. Where this is not sufficient in an individual case, the Controller may carry out an audit, itself or through a qualified third party bound to confidentiality, during business hours, with reasonable advance notice, no more than once per year unless there is a specific reason, and without disrupting the Processor's operations. The Processor may restrict access where necessary to protect the confidentiality of other customers' data or the security of its systems.
12. Liability
Liability under this DPA is governed by the liability provisions of the Main Agreement. Mandatory statutory liability, including liability towards data subjects under Art. 82 GDPR where applicable, remains unaffected.
13. Term
This DPA applies for as long as the Processor processes personal data on behalf of the Controller under the Main Agreement and, beyond its end, until the data has been deleted or returned in accordance with section 10.
14. Final provisions
If individual provisions of this DPA are invalid, the remaining provisions remain unaffected. In case of conflict between this DPA and the Main Agreement, this DPA prevails with regard to the processing of personal data on behalf of the Controller. This DPA is governed by the same law and jurisdiction as the Main Agreement.
Annex 1: Details of the processing
Subject matter and nature: hosting, storage and processing of data submitted to the Nolen platform, including transmission to AI model providers for the generation of outputs, and related support services.
Purpose: provision of the AI-powered business assistant and related services under the Main Agreement.
Categories of data: account and user data (name, business email address, role), content data (prompts, documents and other content submitted to the platform), configuration data, usage and log data, and support communication.
Categories of data subjects: the Controller's employees and other users authorised by the Controller, as well as third parties whose personal data is contained in the content submitted by the Controller (for example customers, suppliers and business contacts of the Controller).
Duration: term of the Main Agreement plus the deletion period under section 10.
Annex 2: Sub-processors
Content submitted to the platform is not used to train AI models. The current list of sub-processors, including the AI model providers used, their locations and the applicable transfer safeguards, is available on request at [email protected]. For self-hosted or on-premises deployments, data remains within the Controller's own infrastructure and this annex applies only to the extent the Processor processes data in connection with support services.