Projet — en cours d'examen juridique

Informations légales

Data Processing Agreement (DPA)

Version :

Traduction à venir — la version allemande fait foi. Le texte ci-dessous est la version anglaise. Version allemande →

This agreement governs how HS-Soft AG processes personal data on behalf of its customers when they use RunMyHub. It meets the requirements of Art. 9 FADP and Art. 28 GDPR and forms part of the Terms of Use. The German version is binding; this translation is for information.

1. Parties and roles

  1. The controller is the customer that uses RunMyHub for its business.
  2. The processor is HS-Soft AG, Hinterbergstrasse 16, 6312 Steinhausen, Switzerland (“HS-Soft”).
  3. HS-Soft processes the data only on the customer’s documented instructions. The Terms of Use, this agreement and the settings the customer makes in RunMyHub count as instructions. If HS-Soft considers an instruction unlawful, it tells the customer.

2. Subject, duration, nature and purpose

  1. The subject is operating RunMyHub for the customer: point of sale, orders, inventory, administration, reports, integrations, AI features and support.
  2. The processing lasts as long as the RunMyHub contract runs and ends with the return or deletion of the data under section 9.
  3. The sole purpose is providing these services, including error analysis and support.

3. Data subjects and categories of data

Data subjects Categories of data
The customer’s employees and users Name, email, role, sign-ins, working times and cashier events, where the customer uses these modules
The customer’s own customers (guests, buyers, business clients) Name, contact details, orders, customer card and loyalty data, invoices
Suppliers and contact persons Name, contact details, orders, invoices
All users of the web application Session recording: page structure, navigation, clicks (text and input masked), email of the signed-in person

Special categories of personal data (e.g. health data) are not intended. If the customer records such data anyway, for example in free-text fields, it is responsible for that.

4. Session recording

  1. HS-Soft records the use of the web application to resolve support cases and analyse errors. It records the page structure, not images or sound. Text and input are masked in the browser. Pages on payroll, personnel, absences, scheduling, time tracking, banking and receivables are not recorded.
  2. Recordings may be viewed only to resolve a support case or analyse an error, and only by authorised HS-Soft staff. They are never used to assess the performance or behaviour of the customer’s employees, and are not handed to the customer for that purpose.
  3. Every viewing of a recording is logged and visible to the customer.
  4. Recordings are deleted automatically after 12 months. The customer can have recording switched off for its company at any time.
  5. The customer informs its employees about session recording and clarifies whether its employee representatives must be involved.

5. HS-Soft’s obligations

  1. HS-Soft binds everyone with access to the data to confidentiality.
  2. HS-Soft takes the technical and organisational measures in Annex 1 and keeps them up to date without lowering the level of protection.
  3. HS-Soft supports the customer with data subject requests, data protection impact assessments and notifications to authorities, as far as they concern HS-Soft’s processing.
  4. HS-Soft notifies the customer of a data security breach affecting its data without undue delay, at the latest within 48 hours of becoming aware of it, with the known details of its nature, scope and the measures taken.

6. Sub-processors

  1. The customer authorises the use of the providers listed under Sub-processors.
  2. HS-Soft informs the customer at least 30 days in advance of new or replaced sub-processors. The customer can object within that period for a material data protection reason; if the parties find no solution, it can terminate the affected service or the contract.
  3. HS-Soft binds every sub-processor by contract to an equivalent level of protection and remains responsible to the customer for their compliance.

7. Data location and transfers abroad

  1. The customer’s data is stored in its jurisdiction: Switzerland in Zurich, the EU in Frankfurt.
  2. Some sub-processors process data outside Switzerland or the EEA, in particular AI providers in the USA. HS-Soft secures such transfers with an adequacy decision, the Data Privacy Framework or the European Commission’s standard contractual clauses with the Swiss addendum.

8. Audit rights

The customer can verify compliance with this agreement. HS-Soft provides the information needed. On-site audits are possible with at least 30 days’ notice, during business hours and at most once a year, except in case of justified suspicion. [Open: who bears the cost.]

9. End of processing

After the end of the contract, HS-Soft keeps the customer’s data available for export for [open: e.g. 30 days] and then deletes it, including backups within their usual deletion cycle, unless a legal retention duty applies. On request, HS-Soft confirms the deletion in writing.

10. Liability and final provisions

Liability follows the Terms of Use. If this agreement and the Terms of Use conflict, this agreement prevails on data protection matters. Swiss law and the place of jurisdiction under the Terms of Use apply.

Annex 1: Technical and organisational measures

Area Measures
Physical access Amazon Web Services data centres (ISO 27001, SOC 2) in Frankfurt and Zurich
System access Sign-in through Amazon Cognito; passkeys and Google sign-in available; no self-registration, accounts by invitation only
Data access Role-based rights; HS-Soft staff only through time-limited, justified and logged support sessions
Separation Separate databases per jurisdiction; all data separated by customer
Transfer TLS encryption
Storage Encryption of stored data
Input control Change log per customer; changes during support sessions are flagged
Availability Backups; the till keeps working without an internet connection
Deletion Automatic deletion periods per data type, e.g. session recordings after 12 months