1. Scope and definitions
This Data Processing Addendum (DPA) is between the Customer identified in the applicable agreement and Boundlane AG, Switzerland (Processor). It applies whenever Processor handles Customer Personal Data to provide Boundlane and the Customer is a controller or processor of that data.
Data Protection Law means the Swiss Federal Act on Data Protection and its ordinance, the GDPR and EEA implementing laws where applicable, the UK GDPR and Data Protection Act 2018 where applicable, and other mandatory privacy law identified in an Order Form. Security Incident means a confirmed accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data processed by Processor. Other defined terms have the meanings in the agreement or applicable Data Protection Law.
2. Roles and documented instructions
The Customer is controller of Customer Personal Data or a processor acting under its controller’s authority. Boundlane AG is a processor or subprocessor. Each party will comply with the obligations that apply to its role.
The Customer instructs Processor to process Customer Personal Data to provide, secure, support and maintain the Service; to follow actions initiated by authorised users and automations; and as otherwise documented in the agreement, an Order Form or written instruction consistent with the Service. Processor will not process Customer Personal Data for its own advertising or sell it.
If Processor believes an instruction violates Data Protection Law, it will inform the Customer and may suspend the affected processing until the parties resolve it. Processor may process where required by law after informing the Customer before processing unless law prohibits notice.
3. Customer obligations
The Customer warrants that its instructions and processing have a valid legal basis; that it has given all required notices and obtained required permissions; and that it is entitled to make Customer Personal Data available to Processor. The Customer determines whether the Service, plan, region, retention settings, model route and approval design are appropriate for its processing and risk.
The Customer will not provide sensitive personal data, children’s data or data subject to sector-specific localisation or secrecy duties unless the agreement and configuration expressly support it and the Customer has completed any required impact assessment and consultation.
4. Confidentiality and personnel
Processor will ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations, receive appropriate security and privacy instruction, and access data only as needed for their duties. Processor remains responsible for their compliance with this DPA.
5. Security measures
Taking account of the state of the art, implementation cost, processing context and risks to people, Processor will maintain appropriate technical and organisational measures. Current measures include:
- tenant-scoped data access and PostgreSQL row-level security for pooled workspaces, with a dedicated database option;
- TLS in transit and provider encryption at rest, with envelope encryption and KMS options for Customer credentials;
- role-based access, scoped sessions, SSO/SAML/SCIM options, four-eyes approval controls and periodic access-review evidence;
- credential references instead of secrets in automation packages, hostname allowlists and policy checks before tool execution;
- versioned packages, static checks, tests, evaluation gates and controlled rollout stages;
- hash-chained change audit, trace recording, optional external audit anchoring, backups and recovery controls;
- logging, rate limits, vulnerability management, incident response and secure development review; and
- data minimisation, sample-redaction rules, retention controls and verified tenant-erasure procedures.
Processor may update measures without materially reducing the overall protection of Customer Personal Data. Deployment-specific evidence is available through the Service and security-review process.
6. Subprocessors
The Customer gives general written authorisation for the subprocessors on the Subprocessor page. Processor will impose data-protection obligations appropriate to the services they perform and remains responsible for their performance to the extent required by Data Protection Law.
Processor will notify workspace owners of a new subprocessor as early as reasonably practicable. Where Processor receives sufficient advance notice, it will give at least 30 days’ notice; where an upstream provider gives a shorter period or an urgent replacement is needed for security or availability, Processor will notify the Customer without undue delay and before use where reasonably possible. The Customer may object during the available notice period on reasonable data-protection grounds. The parties will try in good faith to use a reasonable alternative; if none is available, the Customer may stop the affected function or terminate it without penalty and receive a pro-rata refund of prepaid unused fees for that function.
Customer-selected connected systems and Customer-provided model, storage, identity or notification endpoints are engaged on the Customer’s instruction and are not Processor’s subprocessors.
7. International transfers
Processor will not transfer Customer Personal Data across national borders except as documented in the Subprocessor page, selected by the Customer, or permitted by this DPA. It will ensure a lawful transfer mechanism and provide information reasonably needed for the Customer’s transfer assessment.
Where Customer Personal Data protected by the GDPR is transferred to a country without an applicable adequacy decision, the applicable module of the European Commission Standard Contractual Clauses adopted by Decision 2021/914 (EU SCCs) is incorporated by reference: Module Two where the Customer is controller and Module Three where it is processor. Option 2 applies to Clause 9; the notice period is the one above; optional Clause 7 applies; the supervisory authority and governing law are determined under Clauses 13 and 17; and competent courts are determined under Clause 18.
For transfers governed by Swiss law, references in the EU SCCs to the GDPR include the Swiss FADP, the competent authority is the FDPIC, data subjects in Switzerland may enforce the clauses in Switzerland, and the clauses protect personal data as defined by the FADP. The EU SCCs are used with the adaptations recognised by the FDPIC. If the UK GDPR applies, the UK International Data Transfer Addendum is incorporated to the extent required. A mandatory transfer instrument prevails over conflicting terms of this DPA.
8. Data-subject requests and compliance assistance
Taking account of the nature of processing, Processor will provide reasonable assistance for access, correction, deletion, restriction, portability, objection and automated-decision requests. If Processor receives a request concerning Customer Personal Data, it will not respond substantively except on the Customer’s instruction or as legally required, and will direct or forward the request to the Customer where reasonably possible.
Processor will provide reasonable information and assistance for the Customer’s security obligations, impact assessments, consultations with authorities, records of processing and legally required notices, considering the information available to Processor. Extraordinary assistance may be charged at agreed professional-service rates where permitted by law.
9. Security Incidents
Processor will notify the Customer without undue delay after confirming a Security Incident affecting Customer Personal Data. Notice will include information reasonably available about the nature of the incident, affected data and people, likely consequences, containment and remediation. Information may be provided in phases and notice is not an admission of fault.
Processor will take reasonable steps to contain, investigate and remediate the incident, preserve relevant evidence and cooperate with the Customer’s legally required notifications. The Customer is responsible for notifications it must make as controller unless the parties agree otherwise.
10. Return, deletion and retention
During the term, the Customer may use available export functions. On termination or validated workspace erasure, Processor will delete Customer Personal Data from active tenant systems and trace storage unless return is requested and reasonably available or law requires retention. The erasure operation fails rather than reporting success if configured trace storage cannot be cleared.
Customer Personal Data in protected backups is put beyond ordinary use and expires through provider rotation schedules. Processor may retain narrowly limited information required by law, a legal hold, security defence or establishment of claims, and will protect it and use it only for that purpose. The public Retention schedule describes current criteria.
11. Information and audits
Processor will make information reasonably necessary to demonstrate compliance available to the Customer, including product-generated evidence, current policies and relevant third-party reports when available and subject to confidentiality. Once per year, or after a material Security Incident, the Customer may conduct a reasonable audit through an independent qualified auditor.
Audits require at least 30 days’ notice unless urgency is legally justified, must avoid access to another customer’s data and unreasonable disruption, and must use existing reports first. The Customer bears its costs and reimburses reasonable Processor costs for an audit beyond standard evidence, unless the audit finds a material breach by Processor.
12. Duration, conflict and contact
This DPA begins with the agreement and continues until Processor has deleted Customer Personal Data as described above. If this DPA conflicts with the agreement on personal-data processing, this DPA controls; a mandatory transfer instrument controls over both. Liability is governed by the agreement except where Data Protection Law does not allow that limitation.
This DPA is executed when the Customer accepts the Terms or signs an Order Form incorporating it. A separately signed copy is available on request. Contact hello@boundlane.com for privacy and DPA matters.
Annex A — Details of processing
Subject and duration. Building, testing, operating, observing, securing, supporting and deleting Customer automations for the agreement term plus the deletion period above.
Nature and purpose. Collection, recording, organisation, storage, retrieval, consultation, redaction, model inference, execution, transmission to Customer-selected systems, audit, restriction, export and deletion, solely to provide the Service and follow documented instructions.
People. Customer users and personnel; the Customer’s candidates, suppliers, customers, patients, counterparties and other people represented in Customer Personal Data.
Data. Identity and role data; process documents and communications; financial, commercial, HR, support, operational and connected-system records; automation inputs, outputs, decisions and traces; technical identifiers and audit evidence.
Sensitive data. Not required by the Service. It may be present only where the Customer lawfully chooses to process it under an appropriate agreement and configuration.
Frequency. Continuous or event-driven for the duration of use.
Annex B — Customer instructions and contacts
The Customer’s workspace configuration, authorised-user actions, connected systems, automation packages, retention settings, model settings and support requests are its instructions. The workspace owner is the operational privacy contact unless an Order Form names another. Processor’s privacy contact is hello@boundlane.com.