ACP Logo
ACP — Authentic Content Pilot
Home Packages & Pricing Guide Industries
Free Visibility Check→
de en fr it es

Data Processing Agreement (DPA)

Version 1.0 · Status: June 12, 2026 · According to Art. 9 Swiss DPA and Art. 28 GDPR

Table of Contents

  1. § 1 Subject Matter and Duration
  2. § 2 Nature and Purpose of Processing
  3. § 3 Type of Personal Data
  4. § 4 Categories of Data Subjects
  5. § 5 Obligations of the Processor
  6. § 6 Obligations of the Controller
  7. § 7 Sub-processors
  8. § 8 Technical and Organizational Measures
  9. § 9 Third Country Transfers
  10. § 10 Term and Termination
  11. Appendix 1: Technical and Organizational Measures (TOMs)
  12. Appendix 2: List of Sub-processors

Appendix to the Service Agreement

between

Controller:
[Customer Name and Address — to be inserted per customer]
hereinafter referred to as «Controller»

and

Processor:
magnet-Xs GmbH
Vordere Hauptgasse 104
4800 Zofingen, Switzerland
hereinafter referred to as «Processor»

The Controller corresponds to the «Customer», the Processor to the «Provider» within the meaning of the General Terms and Conditions (GTC). In the following, the terms «personal data» (GDPR) and «personal data» (Swiss DPA) are used synonymously.

§ 1 Subject Matter and Duration

  1. The Processor processes personal data on behalf of the Controller within the scope of the service «Authentic Content Pilot» (ACP).
  2. The processing takes place for the duration of the service agreement.
  3. The subject matter of the processing includes the automated creation, management, and publication of social media content and blog articles based on photos, videos, texts, and voice interviews provided by the Controller.

§ 2 Nature and Purpose of Processing

The processing includes the following activities:

ActivityDescription
Content SubmissionReceiving and storing photos, videos, voice recordings, and text inputs
Voice InterviewsConducting structured voice interviews with employees of the Controller, real-time transcription, and storage of transcripts for content generation
Text GenerationAI-supported creation of social media texts and blog articles based on submitted content
Image ProcessingOptimization and branding of photos (badge, format adaptation)
Video ProcessingOptimization and thumbnail creation for videos
Content ManagementProviding a cockpit for approval and management of generated content
Blog PublishingHosting and publishing approved blog articles on the Controller's website
Social Media PublishingPublishing approved content on the platforms designated by the Controller

§ 3 Type of Personal Data

The following categories of personal data are processed:

  • Photographs and videos (possibly with depicted persons)
  • Voice recordings (voice interviews): Audio is streamed exclusively in real-time via WebRTC and transcribed by Deepgram STT. Raw audio data is not stored — it is ephemeral and irrevocably discarded after processing. Only the resulting text transcripts are persisted in the database. Biometric evaluation for the unique identification of natural persons (Art. 9 GDPR, Art. 5 lit. c Swiss DPA) does not take place.
  • Text inputs with possible personal reference
  • Location data (GPS coordinates of submission)
  • Login data of cockpit users (email address, password hash)
  • Log and audit log data (user ID, timestamp, approval actions)

§ 4 Categories of Data Subjects

  • Employees of the Controller (as submitters and persons depicted in media)
  • Cockpit users designated by the Controller
  • Third parties visibly depicted in submitted photos or videos (e.g., customers of the Controller, passers-by, suppliers)

§ 5 Obligations of the Processor

The Processor undertakes to:

  1. Adherence to Instructions: Process personal data exclusively in accordance with the documented instructions of the Controller (Art. 28 para. 3 lit. a GDPR; Art. 9 para. 1 Swiss DPA), unless the Processor is required to process by Union, Member State, or Swiss law; in this case, the Processor shall inform the Controller of these legal requirements before processing, unless that law prohibits such notification. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes applicable data protection law.
  2. Confidentiality: Ensure that persons authorized to process the personal data have committed themselves to confidentiality (Art. 28 para. 3 lit. b GDPR).
  3. Security Measures: Take all necessary technical and organizational measures in accordance with Art. 32 GDPR (see Appendix 1: TOMs).
  4. Sub-processors: Engage further processors only within the scope of the general authorization according to § 7 of this agreement (Art. 28 para. 2 GDPR). The current list of sub-processors is provided in Appendix 2.
  5. Assistance: Assist the Controller in fulfilling data subjects' rights (Art. 15-22 GDPR) and in data protection impact assessments (Art. 35-36 GDPR).
  6. Deletion/Return: After termination of processing, delete or return all personal data at the Controller's choice, unless there is a legal retention obligation (Art. 28 para. 3 lit. g GDPR).
  7. Proof of Compliance: Make available to the Controller all information necessary to demonstrate compliance with the obligations and allow for audits (Art. 28 para. 3 lit. h GDPR). Audits shall be conducted after prior notice with reasonable lead time (at least 14 days), at most once per calendar year, during normal business hours, and without disrupting business operations. The Processor may primarily fulfill audits by providing suitable evidence (certifications, audit reports, self-assessments). The costs of an on-site audit shall be borne by the Controller, unless significant violations are found.
  8. Notification Obligation: Inform the Controller without undue delay, generally within 48 hours, of any personal data breaches (Art. 33 GDPR; Art. 24 Swiss DPA).

§ 6 Obligations of the Controller

The Controller undertakes to:

  1. Ensure that the necessary consents of the depicted persons are obtained.
  2. Ensure the lawfulness of processing in accordance with Art. 6 GDPR.
  3. Immediately inform the Processor of any data subject requests, insofar as they concern the service.

§ 7 Sub-processors

The Controller hereby grants its general authorization for the engagement of the sub-processors listed in Appendix 2.

The current list of sub-processors is publicly available at acp-authentic-content-pilot.com/sub-processors.html.

In the event of changes or additions of sub-processors, the Processor shall immediately inform the Controller via a notification in the ACP cockpit. The Controller has the right to object to the engagement of new sub-processors within 14 days of becoming aware. If the Controller does not object within this period, the change shall be deemed approved.

§ 8 Technical and Organizational Measures

The Processor implements the following measures in accordance with Art. 32 GDPR (details in Appendix 1):

  • Encryption (TLS 1.2+ in Transit, AES-256 at Rest)
  • Access Control (JWT token, Row-Level Security)
  • Data Segregation (Multi-Tenant with client_id isolation)
  • Regular Backups
  • Logging of Accesses

§ 9 Third Country Transfers

Insofar as personal data is transferred to third countries (outside EU/EEA or Switzerland), the Processor ensures that appropriate safeguards exist in accordance with Art. 46 GDPR or Art. 16/17 Swiss DPA:

RecipientContracting Party EntityLocationProcessing LocationTransfer Mechanism
Anthropic (Claude API)Anthropic Ireland LtdIrelandUSADPA with SCCs, EU Entity
DeepgramDeepgram Inc.USAEUEU-Endpoint (api.eu.deepgram.com), DPA with SCCs
CloudflareCloudflare Inc.USAGlobalEU-U.S. DPF + Swiss-U.S. DPF, DPA
OpenRouterOpenRouter Inc.USAUSADPA with SCCs; downstream LLM providers according to current list
VercelVercel Inc.USAEU RegionEU-U.S. DPF + Swiss-U.S. DPF, DPA

§ 10 Term and Termination

  1. This DPA is valid for the duration of the underlying service agreement.
  2. Upon termination, all personal data will be deleted or returned to the Controller within 30 days. Data in backups will be overwritten as part of the regular backup rotation after 90 days at the latest. Restoration of deleted data from backups will not occur, except to prevent data loss; in this case, the data to be deleted will be immediately deleted again.
  3. The Processor confirms the complete deletion in writing.

Appendix 1: Technical and Organizational Measures (TOMs)

According to Art. 32 GDPR and Art. 8 Swiss DPA

1. Access Control (physical)

  • Server infrastructure at Google Cloud (Zurich, europe-west6) — Certified data center with physical access control.

2. Access Control (logical)

  • Authentication via JWT token and Supabase Auth
  • Row-Level Security (RLS) in the database — tenant separation at data level
  • Role-based permissions (Owner, Admin, Viewer)
  • SSH key-based access to infrastructure, no password login

3. Authorization Control

  • Multi-tenant isolation via client_id — strict data separation between customers
  • Authorization system with explicit role assignments
  • Audit log: Every approval action is logged (user ID, timestamp, content)

4. Transmission Control / Encryption

  • Transport encryption: TLS 1.2+ for all connections
  • Encryption at Rest: AES-256 (Supabase, GCP)
  • API keys and secrets in environment variables, not in code

5. Input Control

  • Audit log documents: Who approved/changed what content when
  • Versioning of content changes in the cockpit

6. Availability and Resilience

  • Regular automated backups (Borg Backup)
  • Monitoring with Telegram alerting (3-minute cascade)
  • Infrastructure on Google Cloud Platform (GCE europe-west6)

7. Separation Principle

  • Multi-tenant architecture with strict client_id isolation
  • Separate database schemas per functional area
  • Separate test and production environments

Appendix 2: List of Sub-processors

Sub-processorLocationPurpose of ProcessingLocation of ProcessingTransfer Mechanism
Google Cloud PlatformUSAInfrastructure (VM, Functions, Storage, LiveKit, n8n)Zurich, Switzerland (europe-west6)No third country transfer (CH)
Supabase Inc.USADatabase, AuthenticationIreland, EU (eu-west-1)EU Processing, DPA
Anthropic (Ireland Ltd.)IrelandAI Text GenerationUSADPA with SCCs, EU Entity
Deepgram Inc.USASpeech-to-Text (Transcription)EUEU-Endpoint, DPA with SCCs
Cloudflare Inc.USACDN, Image Delivery, Video StreamingGlobalEU-U.S. DPF + Swiss-U.S. DPF, DPA
ARBICHAT, S.L. (Zernio/Late.dev)Spain (EU)Social Media PublishingEUEU Processing, DPA concluded
OpenRouter Inc.USALLM Routing/Failover for Text GenerationUSADPA with SCCs; downstream LLM providers according to current list
Vercel Inc.USAHosting Blog FrontendEU RegionEU-U.S. DPF + Swiss-U.S. DPF, DPA

Acceptance of this DPA occurs digitally by confirmation in the ACP cockpit. By using the ACP platform, the Controller confirms knowledge and validity of this Data Processing Agreement.

Version 1.0 — Status: 12.06.2026

ACP Logo
ACP — Authentic Content Pilot
Ein Produkt von mXs Tec.
Instagram LinkedIn Facebook X (Twitter)
Swiss-Made · Engineered in Zofingen
Swiss Data Protection · FADP-compliant
Digitalized · Infrastructure in Zurich
Home Packages & Pricing Guide Industries Free Visibility Check
Imprint Privacy Policy T&C DPA Subprocessors Cookie Settings
Vordere Hauptgasse 104 · 4800 Zofingen · Schweiz
© 2026 magnet-Xs gmbh — All rights reserved

Cookie-Einstellungen

Wir nutzen Cookies und ähnliche Technologien, um das B2B-Erlebnis auf unserer Landingpage zu optimieren und die Nutzung zu analysieren.

Notwendig für den Betrieb der Website (z. B. cookiefreie Cloudflare Analytics, Sicherheits-Tokens).

Ermöglicht uns anonyme Statistiken über die Interaktionen der Besucher zu erfassen (GA4).

Hilft uns zu verstehen, wie Nutzer durch unsere Seite navigieren (Sitzungsaufzeichnungen, Heatmaps).

Erlaubt die Erfolgsmessung von Kampagnen (z. B. Meta Pixel, LinkedIn Insight Tag).