Data Processing Agreement
This DPA forms part of the Agreement between the professional customer (“Customer”) and Amrachi where Amrachi processes Customer Personal Data on the Customer’s behalf.
Last updated: 4 September 2026
1. Scope and law
This DPA applies where Amrachi processes personal data on behalf of Customer in connection with the Service (“Customer Personal Data”). It is intended to address applicable requirements of the Swiss Federal Act on Data Protection (“FADP”) and, where applicable, Article 28 GDPR.
2. Roles
Customer acts as controller of Customer Personal Data or, where Customer itself processes data on behalf of another controller, as processor. Amrachi acts as processor or subprocessor, as applicable, when processing Customer Personal Data to provide the Service. Customer is responsible for ensuring its instructions comply with applicable law.
3. Instructions
Amrachi processes Customer Personal Data only on documented instructions from Customer, including as necessary to provide, maintain and secure the Service and perform the Agreement, unless otherwise required by applicable law. Where legally permitted, Amrachi will inform Customer before processing required by law. If Amrachi reasonably believes an instruction infringes applicable data-protection law, it may inform Customer and suspend the affected processing while the Parties address the issue.
4. Confidentiality
Amrachi ensures that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations and access such data only as necessary for authorised functions.
5. Security
Amrachi implements and maintains technical and organisational measures appropriate to the nature, scope, context and purposes of processing and the risks to affected individuals. Measures include, as applicable, authenticated access, organisation/role controls, tenant-isolation controls, encrypted network connections, managed encryption at rest, logging and monitoring, diagnostic-data minimisation, controlled deployment/versioning, vendor governance, incident response and managed backup/recovery capabilities.
Amrachi may update measures as technology and risks evolve provided the overall level of protection is not materially reduced. No fixed RTO, RPO or backup-retention commitment applies unless expressly agreed in an Order Form or SLA.
6. Subprocessors
Customer grants Amrachi general authorisation to engage subprocessors for Customer Personal Data. Amrachi maintains a current Subprocessor List and imposes appropriate data-protection obligations on relevant subprocessors.
Amrachi will provide at least 30 days’ advance notice of an intended material addition or replacement where reasonably practicable, so Customer may object on reasonable data-protection grounds. For emergency or security-driven substitutions where advance notice is not reasonably practicable, Amrachi may make the substitution and notify Customer as soon as reasonably practicable.
| Provider | Purpose | Processing / transfer context |
|---|---|---|
| Supabase | Database, authentication, storage and backend infrastructure | Primary production database in Zurich, Switzerland. Other provider-side processing or access remains subject to the applicable contractual terms and transfer safeguards. |
| Resend | Transactional email delivery | Processing in the United States for the service used. Transfers from Switzerland/EEA are governed by the mechanisms in Resend’s DPA, including Standard Contractual Clauses where applicable. |
| Cloudflare Turnstile | Bot protection on authentication flows | Global service. Turnstile may involve processing outside Switzerland; safeguards under Cloudflare’s DPA and applicable transfer mechanisms apply. Cloudflare DNS is disclosed separately in the Privacy Policy and is not part of this Customer Personal Data subprocessing chain. |
| Sentry | Application error and performance monitoring | Data-storage region configured in the European Union. Other provider-side access or processing remains subject to Sentry’s DPA and applicable transfer safeguards. |
7. International transfers
Amrachi will not disclose Customer Personal Data to a recipient in a jurisdiction requiring additional safeguards unless an appropriate transfer mechanism is in place. Safeguards may include recognised adequacy decisions, standard contractual clauses or other legally recognised mechanisms.
8. Data-subject requests
Taking into account the nature of processing, Amrachi provides reasonable assistance to Customer in responding to requests concerning Customer Personal Data. Unless legally required otherwise, Amrachi does not independently determine the merits of a request where Customer is the relevant controller. Direct requests may be referred to Customer.
9. Personal-data breaches
Amrachi will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and will provide information reasonably available concerning the nature of the incident, affected data/persons, likely consequences and measures taken or proposed, to the extent reasonably required for Customer to assess and fulfil its obligations. Notification is not an admission of fault or liability.
10. DPIAs and regulatory cooperation
Taking into account the nature of processing and information available, Amrachi provides reasonable assistance where Customer is required to conduct a data-protection impact assessment or consult a competent data-protection authority regarding Customer’s use of the Service. This does not make Amrachi responsible for Customer’s broader financial-regulatory obligations.
11. Demonstrating compliance and audits
Amrachi makes information reasonably necessary to demonstrate compliance with processor obligations available to Customer. Customer should first use available documentation, questionnaires, security materials and reasonable remote assessments. Where reasonably insufficient, Customer may request an additional audit subject to reasonable advance notice, confidentiality, security, scope and operational conditions and without unreasonable interference.
12. Return and deletion
During the Agreement and applicable exit period, Customer may retrieve Customer Personal Data using available export functionality or another agreed secure mechanism. Following termination and expiry of the applicable exit period, Amrachi will delete or return Customer Personal Data in accordance with Customer instructions and applicable retention/backup procedures, unless continued retention is required by law.
Data removed from active systems may remain temporarily in protected backups until deleted or overwritten under the applicable lifecycle. Historical supervision evidence may require treatment different from an active user account; where appropriate and permitted, the Parties may preserve, dissociate or otherwise appropriately process historical evidence required for legitimate customer record-keeping.
13. Liability and duration
Liability under this DPA is governed by the liability provisions of the Agreement except where applicable law prohibits limitation. This DPA remains in effect for as long as Amrachi processes Customer Personal Data on behalf of Customer.
Annex 1 — Processing details
- Subject matter: provision of the Amrachi portfolio-supervision Service.
- Duration: term of the Agreement and applicable exit/retention period.
- Nature and purpose: hosting, organising, presenting, securing and otherwise processing Customer Personal Data as necessary to provide portfolio-supervision workflow, supervision evidence, support and security functionality.
- Data subjects may include Customer personnel and authorised users, Customer clients or client references, and other individuals represented in Customer Personal Data.
- Data categories may include professional identity/account information, client-reference information, portfolio-related information, supervision/review/decision/follow-up information and technical/security metadata.
Annex 2 — Technical and organisational measures
The security measures described above form the public contractual summary. More detailed TOM documentation may be supplied to qualified Customers for due diligence and may be incorporated into an Order Form or DPA schedule where agreed.
Annex 3 — Subprocessors
The current Subprocessor List is maintained by Amrachi. Attio, Google Analytics 4 and Vercel are not included in the Customer DPA subprocessor list: Attio and Google Analytics 4 are used for Amrachi-controller CRM and public-website analytics respectively, and Vercel provides application-shell hosting and delivery for the public website and the application bundle. None of them processes Customer Personal Data submitted through the authenticated Service, whose data path runs directly between the user’s browser and Supabase.