How this DPA applies
This Data Processing Addendum supplements an agreement between Vilgot Moeschlin (“Processor”) and the customer identified in that agreement (“Controller”). It becomes binding only when executed by both parties or expressly incorporated into an order or service agreement. If there is a conflict about processing personal data, this DPA controls.
1. Roles and instructions
Controller determines the purposes and means of processing customer personal data. Processor will process it only to provide and secure the service, follow documented lawful instructions, comply with applicable law, or as otherwise agreed in writing. Controller is responsible for lawful collection, notices, instructions, and legal bases.
2. Processing details
3. Confidentiality and security
Processor will ensure authorised personnel are bound by confidentiality and maintain appropriate technical and organisational measures proportionate to risk, including access control, encrypted transport, managed infrastructure, secret management, logging, backups where configured, and incident response. Final production schedules must document the verified measures in detail.
4. Subprocessors
Controller gives general authorisation to use the subprocessors listed at https://tervane.dev/privacy. Processor will impose appropriate data-protection obligations and provide 30 days' notice of material additions. Controller may object on reasonable data-protection grounds.
5. International transfers
Where protected data is transferred outside its originating jurisdiction, the parties will use an applicable lawful mechanism. For EEA transfers requiring safeguards, the parties incorporate the applicable 2021 EU Standard Contractual Clauses, generally Module Two (controller to processor), with Integritetsskyddsmyndigheten (IMY), Sweden, and the security and subprocessor schedules completed before execution. The UK Addendum applies where required.
6. Assistance
Taking into account the processing and information available, Processor will reasonably assist Controller with data-subject requests, security obligations, breach notifications, impact assessments, and regulator consultations. Processor will notify Controller without undue delay after confirming a personal-data breach affecting customer personal data and provide available material details.
7. Deletion and return
At the end of services, Processor will delete or return customer personal data on request, unless law requires retention. Deletion may be subject to documented backup cycles, security records, legal holds, and data Controller has exported or published outside the service. Final retention and backup periods: Account and project data is retained while the account is active and deleted on account deletion, subject to backup cycles and records required for tax, security, fraud prevention, disputes, or legal holds..
8. Audit information
Processor will provide information reasonably necessary to demonstrate compliance. If that is insufficient, the parties may arrange an audit no more than annually, subject to confidentiality, reasonable notice, scope limits, security protections, and reimbursement of reasonable costs unless an audit identifies material non-compliance.
9. Contact and execution
Privacy contact: vilgot@moeschlin.com. This public draft is not signed and is not a substitute for completing the company, transfer, security, subprocessor, retention, liability, and signature details with counsel.