Data Processing Agreement (DPA)
Table of Contents
- § 1 Subject Matter and Duration
- § 2 Nature and Purpose of Processing
- § 3 Type of Personal Data
- § 4 Categories of Data Subjects
- § 5 Obligations of the Processor
- § 6 Obligations of the Controller
- § 7 Sub-processors
- § 8 Technical and Organizational Measures
- § 9 Third Country Transfers
- § 10 Term and Termination
- Appendix 1: Technical and Organizational Measures (TOMs)
- Appendix 2: List of Sub-processors
Appendix to the Service Agreement
between
Controller:
[Customer Name and Address — to be inserted per customer]
hereinafter referred to as «Controller»
and
Processor:
magnet-Xs GmbH
Vordere Hauptgasse 104
4800 Zofingen, Switzerland
hereinafter referred to as «Processor»
The Controller corresponds to the «Customer», the Processor to the «Provider» within the meaning of the General Terms and Conditions (GTC). In the following, the terms «personal data» (GDPR) and «personal data» (Swiss DPA) are used synonymously.
§ 1 Subject Matter and Duration
- The Processor processes personal data on behalf of the Controller within the scope of the service «Authentic Content Pilot» (ACP).
- The processing takes place for the duration of the service agreement.
- The subject matter of the processing includes the automated creation, management, and publication of social media content and blog articles based on photos, videos, texts, and voice interviews provided by the Controller.
§ 2 Nature and Purpose of Processing
The processing includes the following activities:
| Activity | Description |
|---|---|
| Content Submission | Receiving and storing photos, videos, voice recordings, and text inputs |
| Voice Interviews | Conducting structured voice interviews with employees of the Controller, real-time transcription, and storage of transcripts for content generation |
| Text Generation | AI-supported creation of social media texts and blog articles based on submitted content |
| Image Processing | Optimization and branding of photos (badge, format adaptation) |
| Video Processing | Optimization and thumbnail creation for videos |
| Content Management | Providing a cockpit for approval and management of generated content |
| Blog Publishing | Hosting and publishing approved blog articles on the Controller's website |
| Social Media Publishing | Publishing approved content on the platforms designated by the Controller |
§ 3 Type of Personal Data
The following categories of personal data are processed:
- Photographs and videos (possibly with depicted persons)
- Voice recordings (voice interviews): Audio is streamed exclusively in real-time via WebRTC and transcribed by Deepgram STT. Raw audio data is not stored — it is ephemeral and irrevocably discarded after processing. Only the resulting text transcripts are persisted in the database. Biometric evaluation for the unique identification of natural persons (Art. 9 GDPR, Art. 5 lit. c Swiss DPA) does not take place.
- Text inputs with possible personal reference
- Location data (GPS coordinates of submission)
- Login data of cockpit users (email address, password hash)
- Log and audit log data (user ID, timestamp, approval actions)
§ 4 Categories of Data Subjects
- Employees of the Controller (as submitters and persons depicted in media)
- Cockpit users designated by the Controller
- Third parties visibly depicted in submitted photos or videos (e.g., customers of the Controller, passers-by, suppliers)
§ 5 Obligations of the Processor
The Processor undertakes to:
- Adherence to Instructions: Process personal data exclusively in accordance with the documented instructions of the Controller (Art. 28 para. 3 lit. a GDPR; Art. 9 para. 1 Swiss DPA), unless the Processor is required to process by Union, Member State, or Swiss law; in this case, the Processor shall inform the Controller of these legal requirements before processing, unless that law prohibits such notification. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes applicable data protection law.
- Confidentiality: Ensure that persons authorized to process the personal data have committed themselves to confidentiality (Art. 28 para. 3 lit. b GDPR).
- Security Measures: Take all necessary technical and organizational measures in accordance with Art. 32 GDPR (see Appendix 1: TOMs).
- Sub-processors: Engage further processors only within the scope of the general authorization according to § 7 of this agreement (Art. 28 para. 2 GDPR). The current list of sub-processors is provided in Appendix 2.
- Assistance: Assist the Controller in fulfilling data subjects' rights (Art. 15-22 GDPR) and in data protection impact assessments (Art. 35-36 GDPR).
- Deletion/Return: After termination of processing, delete or return all personal data at the Controller's choice, unless there is a legal retention obligation (Art. 28 para. 3 lit. g GDPR).
- Proof of Compliance: Make available to the Controller all information necessary to demonstrate compliance with the obligations and allow for audits (Art. 28 para. 3 lit. h GDPR). Audits shall be conducted after prior notice with reasonable lead time (at least 14 days), at most once per calendar year, during normal business hours, and without disrupting business operations. The Processor may primarily fulfill audits by providing suitable evidence (certifications, audit reports, self-assessments). The costs of an on-site audit shall be borne by the Controller, unless significant violations are found.
- Notification Obligation: Inform the Controller without undue delay, generally within 48 hours, of any personal data breaches (Art. 33 GDPR; Art. 24 Swiss DPA).
§ 6 Obligations of the Controller
The Controller undertakes to:
- Ensure that the necessary consents of the depicted persons are obtained.
- Ensure the lawfulness of processing in accordance with Art. 6 GDPR.
- Immediately inform the Processor of any data subject requests, insofar as they concern the service.
§ 7 Sub-processors
The Controller hereby grants its general authorization for the engagement of the sub-processors listed in Appendix 2.
The current list of sub-processors is publicly available at acp-authentic-content-pilot.com/sub-processors.html.
In the event of changes or additions of sub-processors, the Processor shall immediately inform the Controller via a notification in the ACP cockpit. The Controller has the right to object to the engagement of new sub-processors within 14 days of becoming aware. If the Controller does not object within this period, the change shall be deemed approved.
§ 8 Technical and Organizational Measures
The Processor implements the following measures in accordance with Art. 32 GDPR (details in Appendix 1):
- Encryption (TLS 1.2+ in Transit, AES-256 at Rest)
- Access Control (JWT token, Row-Level Security)
- Data Segregation (Multi-Tenant with client_id isolation)
- Regular Backups
- Logging of Accesses
§ 9 Third Country Transfers
Insofar as personal data is transferred to third countries (outside EU/EEA or Switzerland), the Processor ensures that appropriate safeguards exist in accordance with Art. 46 GDPR or Art. 16/17 Swiss DPA:
| Recipient | Contracting Party Entity | Location | Processing Location | Transfer Mechanism |
|---|---|---|---|---|
| Anthropic (Claude API) | Anthropic Ireland Ltd | Ireland | USA | DPA with SCCs, EU Entity |
| Deepgram | Deepgram Inc. | USA | EU | EU-Endpoint (api.eu.deepgram.com), DPA with SCCs |
| Cloudflare | Cloudflare Inc. | USA | Global | EU-U.S. DPF + Swiss-U.S. DPF, DPA |
| OpenRouter | OpenRouter Inc. | USA | USA | DPA with SCCs; downstream LLM providers according to current list |
| Vercel | Vercel Inc. | USA | EU Region | EU-U.S. DPF + Swiss-U.S. DPF, DPA |
§ 10 Term and Termination
- This DPA is valid for the duration of the underlying service agreement.
- Upon termination, all personal data will be deleted or returned to the Controller within 30 days. Data in backups will be overwritten as part of the regular backup rotation after 90 days at the latest. Restoration of deleted data from backups will not occur, except to prevent data loss; in this case, the data to be deleted will be immediately deleted again.
- The Processor confirms the complete deletion in writing.
Appendix 1: Technical and Organizational Measures (TOMs)
According to Art. 32 GDPR and Art. 8 Swiss DPA
1. Access Control (physical)
- Server infrastructure at Google Cloud (Zurich, europe-west6) — Certified data center with physical access control.
2. Access Control (logical)
- Authentication via JWT token and Supabase Auth
- Row-Level Security (RLS) in the database — tenant separation at data level
- Role-based permissions (Owner, Admin, Viewer)
- SSH key-based access to infrastructure, no password login
3. Authorization Control
- Multi-tenant isolation via client_id — strict data separation between customers
- Authorization system with explicit role assignments
- Audit log: Every approval action is logged (user ID, timestamp, content)
4. Transmission Control / Encryption
- Transport encryption: TLS 1.2+ for all connections
- Encryption at Rest: AES-256 (Supabase, GCP)
- API keys and secrets in environment variables, not in code
5. Input Control
- Audit log documents: Who approved/changed what content when
- Versioning of content changes in the cockpit
6. Availability and Resilience
- Regular automated backups (Borg Backup)
- Monitoring with Telegram alerting (3-minute cascade)
- Infrastructure on Google Cloud Platform (GCE europe-west6)
7. Separation Principle
- Multi-tenant architecture with strict client_id isolation
- Separate database schemas per functional area
- Separate test and production environments
Appendix 2: List of Sub-processors
| Sub-processor | Location | Purpose of Processing | Location of Processing | Transfer Mechanism |
|---|---|---|---|---|
| Google Cloud Platform | USA | Infrastructure (VM, Functions, Storage, LiveKit, n8n) | Zurich, Switzerland (europe-west6) | No third country transfer (CH) |
| Supabase Inc. | USA | Database, Authentication | Ireland, EU (eu-west-1) | EU Processing, DPA |
| Anthropic (Ireland Ltd.) | Ireland | AI Text Generation | USA | DPA with SCCs, EU Entity |
| Deepgram Inc. | USA | Speech-to-Text (Transcription) | EU | EU-Endpoint, DPA with SCCs |
| Cloudflare Inc. | USA | CDN, Image Delivery, Video Streaming | Global | EU-U.S. DPF + Swiss-U.S. DPF, DPA |
| ARBICHAT, S.L. (Zernio/Late.dev) | Spain (EU) | Social Media Publishing | EU | EU Processing, DPA concluded |
| OpenRouter Inc. | USA | LLM Routing/Failover for Text Generation | USA | DPA with SCCs; downstream LLM providers according to current list |
| Vercel Inc. | USA | Hosting Blog Frontend | EU Region | EU-U.S. DPF + Swiss-U.S. DPF, DPA |
Acceptance of this DPA occurs digitally by confirmation in the ACP cockpit. By using the ACP platform, the Controller confirms knowledge and validity of this Data Processing Agreement.
Version 1.0 — Status: 12.06.2026