Data Processing Agreement (DPA)
Last modified: September 17, 2026
Note: This is a convenience translation. Only the German version of this Data Processing Agreement is legally binding. In case of any discrepancy, the German version prevails.
PONTORA — a product of Haus der Finanzen GmbH
Data Processing Agreement (DPA) pursuant to Art. 9 revDSG (revised Swiss Federal Act on Data Protection) / Art. 28 DSGVO (GDPR)
Version 1.0 As of: 5 May 2026 Language: German (authoritative)
| Party | Details |
|---|---|
| Processor | Haus der Finanzen GmbH Freiburgstrasse 443, 3018 Bern UID: CHE-462.314.248 (trading under the brand “Pontora”) datenschutz@pontora.ch |
| Controller | The Customer pursuant to GTC section 3.1 lit. b (SME Customer) Identification takes place via the Pontora account |
This Data Processing Agreement (hereinafter the “DPA”) sets out in concrete terms the data protection obligations between Haus der Finanzen GmbH (hereinafter the “Provider” or “Processor”) and its SME Customers (hereinafter the “Customer” or “Controller”). The basis of the contractual relationship is formed by the General Terms and Conditions (GTC) and the Privacy Policy of the Pontora platform; these form an integral part of this DPA.
1. Subject matter, duration and specification of the data processing
1.1 The subject matter, duration, nature and purpose of the data processing follow from the GTC and the service description of the Pontora platform. Annex A to this DPA specifies the processing activities, data categories and categories of data subjects.
1.2 The data processing continues for the duration of the Main Agreement. After termination of the Main Agreement, any further data processing is governed by section 8 of this DPA (return and deletion of data).
2. Applicable law and responsibility
2.1 This DPA is governed by the revised Swiss Federal Act on Data Protection (revDSG, in force since 1 September 2023) and the associated ordinance (DSV). Insofar as the EU General Data Protection Regulation (DSGVO / GDPR) applies to a data processing operation (e.g. because data of persons resident in the EU is processed), the relevant provisions of the GDPR apply in addition; in the event of conflicts, the mandatory requirements of the stricter set of rules prevail.
2.2 The Customer is the controller within the meaning of Art. 5 lit. j revDSG or Art. 4 no. 7 DSGVO (GDPR) with respect to the personal data of third parties entered into the platform. The Customer is responsible in particular for the lawfulness of the data collection, for informing the data subjects, and for fulfilling data subject rights.
2.3 The Provider is a processor within the meaning of Art. 9 revDSG and a processor within the meaning of Art. 28 DSGVO (GDPR). It processes personal data exclusively on the instruction of the Customer, unless a statutory obligation requires processing that deviates from those instructions.
2.4 By accepting the GTC and the Privacy Policy upon registration, the Customer grants the Provider the general instruction to process data within the scope of the service description. Specific individual instructions may be issued via the Pontora account, by e-mail to datenschutz@pontora.ch, or in writing to the Provider.
2.5 The Provider shall inform the Customer without delay if it is of the opinion that an instruction infringes applicable data protection law. It is entitled to suspend the execution of the relevant instruction until the Customer confirms or amends it.
3. Obligations of the Provider (Processor)
3.1 The Provider processes personal data exclusively within the scope of the Main Agreement, this DPA and the documented instructions of the Customer, unless a statutory obligation requires processing that deviates from those instructions. In the latter case, the Provider shall notify the Customer of that legal obligation before processing, unless the relevant law prohibits such notification.
3.2 The Provider implements the technical and organisational measures (TOMs) described in Annex B to protect personal data. These are subject to technical progress; the Provider is entitled to implement alternative measures, provided the agreed level of security is not reduced. Material changes are communicated to the Customer as part of the update of this DPA.
3.3 The Provider obliges all persons involved in the processing (employees, commissioned third parties, sub-processors) to maintain confidentiality, or ensures that they are subject to an appropriate statutory duty of confidentiality.
3.4 The Provider supports the Customer in fulfilling the obligations under Art. 22, 24 and 25 revDSG or Art. 32 to 36 DSGVO (GDPR) to the extent possible, in particular with:
- responding to requests from data subjects (access, rectification, erasure, restriction, data portability);
- reporting and documenting data protection breaches (“data breaches”);
- carrying out data protection impact assessments (“DPIA”);
- consulting the competent supervisory authority.
3.5 For extensive support services that go beyond the standard functionality of the platform, the Provider may request reasonable compensation for its effort. It will inform the Customer of the expected costs in advance.
3.6 Notification of data protection breaches: If the Provider becomes aware of a breach of the protection of personal data processed by it on behalf of the Customer, it shall inform the Customer without delay, and at the latest within 48 hours of becoming aware of it. The notification contains — to the extent available — the following information:
- a description of the nature of the breach;
- the categories and approximate number of data subjects affected;
- the categories and approximate number of data records affected;
- the likely consequences of the breach;
- the measures taken or proposed to remedy it.
3.7 The Provider reviews the effectiveness of the TOMs at regular intervals and adapts them as required.
4. Obligations of the Customer (Controller)
4.1 The Customer is solely responsible for the lawfulness of the collection, processing and transmission of the personal data to the Provider, as well as for fulfilling the information obligations towards the data subjects (in particular its employees, suppliers and business partners).
4.2 The Customer ensures that — to the extent required under applicable law — valid consents of the data subjects are in place or that another legal basis exists. The Customer will inform its employees about the data processing within the scope of the Pontora platform and make the Provider’s Privacy Policy available to them.
4.3 The Customer shall inform the Provider without delay if it identifies errors or irregularities in the processing results or in the data flow, in particular where there are indications of a data protection breach.
4.4 By accepting this DPA and the Privacy Policy, the Customer declares its consent to the engagement by the Provider of the sub-processors listed in Annex A (cf. section 7).
4.5 Obtaining any required consents from data subjects — in particular for the AI-supported processing of receipts and documents with potentially sensitive content — is the responsibility of the Customer.
5. Requests from data subjects
5.1 If a data subject approaches the Provider directly with claims for access, rectification, erasure, restriction or data portability, the Provider shall refer that person to the Customer and forward the request within a reasonable period (as a rule 5 working days) to the data protection contact address of the Customer stored in the Pontora account.
5.2 The Provider is not liable if a data subject’s request is not answered by the Customer, or is not answered in good time or properly.
5.3 The Provider makes suitable functions available to the Customer within the platform so that the Customer can handle access, rectification and erasure requests from its data subjects itself (data export, data correction, data deletion in the modules).
6. Audit and verification options
6.1 The Provider demonstrates compliance with its data protection obligations in a suitable manner, in particular through:
- regular self-audits and internal controls;
- technical and organisational documentation of the TOMs (Annex B);
- on request: provision of relevant audit reports or certifications of its sub-processors (e.g. AWS SOC reports, ISO certificates).
6.2 Inspections by the Customer or by an independent auditor commissioned by the Customer are possible with reasonable advance notice (at least 30 days) and during normal business hours, provided this is required under data protection law or demanded by the competent supervisory authority. The Provider may require the signing of an appropriate non-disclosure agreement (NDA). The auditor must not be in an active consulting or employment relationship with any competitor of the Provider.
6.3 The costs of audits initiated by the Customer are borne by the Customer — subject to proven material breaches of this DPA by the Provider.
7. Sub-processors (further processors)
7.1 The Provider is entitled to engage sub-processors (“further processors”) to fulfil its contractual services. The Provider contractually obliges these sub-processors to a level of data protection equivalent to that of this DPA.
7.2 The current list of sub-processors used is set out in Annex A to this DPA and published on pontora.ch. By accepting the GTC, the Customer consents to the engagement of the sub-processors listed at the time the contract is concluded.
7.3 The Customer will be informed at least 30 days in advance in text form (e.g. by e-mail or in-app notification) of the engagement or replacement of sub-processors. For important reasons relating to data protection, the Customer may object in text form within 14 days of the notification. In the event of a justified objection, each party is entitled to terminate the Main Agreement extraordinarily.
7.4 The Provider is liable for the selection, instruction and supervision of the sub-processors within the scope of the statutory provisions.
8. Termination of the DPA, return and deletion of data
8.1 This DPA terminates automatically upon termination of the Main Agreement. The duty of confidentiality (section 3.3) and the duty of notification in the event of data protection breaches (section 3.6) continue to apply to data still stored by the Provider after the end of the contract.
8.2 At the Customer’s choice, the Provider shall either hand over to the Customer or irrevocably delete all personal data stored in the course of the data processing within 30 days of termination of the Main Agreement.
8.3 Retention beyond the period set out in section 8.2 is only permissible to the extent that statutory retention obligations require it (in particular Art. 958f OR (Swiss Code of Obligations) — 10 years for business records; Art. 70 MWSTG (Swiss VAT Act) — 10 years for VAT-relevant documents; Art. 35 BVG (Swiss Occupational Pensions Act) — retention obligations for social insurance). The data required for statutory retention is technically isolated (archive storage) and is no longer accessible to any active processing.
9. International data transfers
9.1 The Provider stores productive personal data exclusively on infrastructure in Switzerland (AWS Region “Switzerland (Zurich)” / eu-central-2).
9.2 Insofar as data is transferred to sub-processors in third countries for individual functions — in particular the AI-supported OCR recognition of cash book and accounts payable receipts — (in particular to Anthropic, PBC, USA, for the use of “Claude”), such transfer takes place on the basis of:
- the standard contractual clauses of the Swiss Federal Data Protection and Information Commissioner (EDÖB) or the standard contractual clauses of the EU Commission (GDPR-compliant);
- supplementary technical and organisational protective measures, in particular encryption in transit, pseudonymisation where possible, and limitation of the transferred data fields to what is necessary to fulfil the purpose;
- the contractual obligation of the sub-processor to use the transferred data exclusively for the provision of the commissioned service and not for its own purposes (in particular not for training AI models).
9.3 The Provider makes the contractual documents relevant to the transfer (standard contractual clauses, data processing agreements) available to the Customer on request.
10. Liability
10.1 The liability of the parties is governed by the corresponding provisions of the GTC. Furthermore, the Provider is not liable for data protection breaches that are based on incorrect instructions or insufficient diligence on the part of the Customer, in particular in the case of:
- entry of unlawfully collected personal data into the platform;
- failure by the Customer to inform the data subjects;
- disclosure of access credentials to unauthorised persons;
- improper configuration of permissions in the Pontora account.
11. Final provisions
11.1 In all other respects, the provisions of the GTC and the Privacy Policy apply. In the event of contradictions between this DPA and the GTC, the provisions of this DPA prevail insofar as data protection matters are concerned.
11.2 Should individual provisions of this DPA be invalid, void or unenforceable, the validity of the remaining provisions remains unaffected. The parties shall replace the invalid provision with a valid one that comes closest to its economic and legal purpose.
11.3 This DPA is subject exclusively to Swiss law. The place of jurisdiction is Bern, Switzerland.
11.4 Annex A (subject matter and sub-processors) and Annex B (TOMs) form an integral part of this DPA.
Annex A — Subject matter, data categories, sub-processors
A.1 Subject matter and purpose of the processing
| Subject matter | Processing of personal data in connection with the operation of the Pontora SaaS platform for SME and HR management |
| Purpose | Provision, operation and further development of the platform; in particular: • Employee onboarding (HR master data, documents) • Task and workflow management • Forms (accident report, sickness report, etc.) • Provision of system documents (contracts, terminations) • Digital cash book (with OCR) • Management of accounts payable receipts (with OCR) • Uploading and managing company and employee documents • Working time recording • Daily revenue recording (hospitality) by revenue and payment type • Multi-client / multi-location administration |
| Duration | For the duration of the Main Agreement plus any statutory retention periods |
A.2 Categories of data subjects
- Employees of the Customer (including former employees);
- Trustees who access the platform on behalf of the Customer;
- Management and administrator accounts of the Customer;
- Suppliers and business partners of the Customer (in connection with accounts payable management);
- Customers of the Customer (in connection with revenue recording — no personal data of end customers, only aggregates).
A.3 Categories of personal data
| Category | Data |
|---|---|
| HR master data | Surname, first name, date of birth, AHV number (Swiss social security number), address, contact details, bank details, photo, details of children |
| Employment data | Function, workload, start/end date, employment contracts, terminations, references, salary details |
| Working time data | Working hours, breaks, absences, holidays, overtime |
| Particularly sensitive data | Sickness notifications (including medical certificates) Accident reports and accident notifications Salary and remuneration data Where applicable: social assistance / guardianship relationships, wage garnishments |
| Supplier / receipt data | Supplier master data, invoices, receipts, cash book entries |
| Usage data | Login times, IP addresses, browser type, activity logs (audit logs) |
A.4 Current sub-processors
| Sub-processor | Purpose | Location | Data location |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Cloud infrastructure, data storage, compute | Luxembourg / EU | Zurich, Switzerland (eu-central-2) |
| Supabase Inc. | Database platform (PostgreSQL), auth, storage | Delaware, USA | Zurich, Switzerland (on AWS eu-central-2) |
| Anthropic, PBC | AI-supported OCR recognition of receipts (cash book, accounts payable); Anthropic “Claude API” | San Francisco, USA | USA (with SCC safeguards, no-training) |
| Vercel Inc. | Hosting of the public website and marketing front ends (no productive data) | San Francisco, USA | EU region (Frankfurt, fra1) |
| Cloudflare Inc. | CDN, DDoS protection, DNS | San Francisco, USA | Global edge network; Swiss/EU PoPs prioritised |
| EnacTon Infotech LLP | Software development; access exclusively to development and staging environments, no access to productive data | India | No access to productive personal data |
Annex B — Technical and organisational measures (TOMs)
The following measures meet the requirements of Art. 8 revDSG / Art. 1 et seq. DSV as well as Art. 32 DSGVO (GDPR) and are continuously adapted to the state of the art.
I. Confidentiality
I.1 Physical access control
- Physical access to the servers exclusively via AWS security measures in the data centres in Zurich;
- Complete logging of all access events by AWS;
- Employees of the Provider have no physical access to the servers.
I.2 System access control (authentication)
- Authentication by e-mail/password with minimum password complexity requirements;
- Support for magic link authentication;
- Mandatory two-factor authentication (2FA) for administrator and super administrator accounts;
- Automatic lockout after multiple failed login attempts;
- Secure password hashing algorithm (bcrypt or equivalent).
I.3 Data access control (authorisation concept)
- Role-based authorisation concept with clear roles: employee, company admin, trustee, system admin;
- Principle of least privilege: each role receives only the permissions necessary to perform its tasks;
- Super administrator access to productive customer data is deactivated by default;
- Activation of super administrator access only with the express consent of the affected Customer in the individual case;
- Complete logging of every administrative access (audit log) including timestamp, acting person, affected data records, purpose;
- Regular review of access permissions (at least quarterly).
I.4 Separation requirement (multi-tenant isolation)
- Data of different customers is strictly separated at database level (row-level security in PostgreSQL/Supabase);
- No cross-customer data access is technically possible, except through explicitly authorised access relationships (e.g. the trustee of an SME Customer);
- Development, staging and production environments are strictly separated from one another;
- External development partners have access exclusively to anonymised test or development data.
II. Integrity
II.1 Input control
- Complete logging of data entries, changes and deletions (audit trail) at application and database level;
- Versioning of security-relevant configurations and documents;
- Traceability of all relevant data changes for at least 12 months.
II.2 Transport control
- Encrypted data transmission (TLS 1.2 or higher) between end device and server;
- Encrypted internal communication between application and database level;
- Encryption of data at rest (AES-256 at storage and database level);
- Machine authentication at external interfaces (API tokens with limited lifetime).
III. Availability and resilience
- Daily automated backups of the entire database;
- Backup retention in accordance with internal policies (retention: 30 days point-in-time, 12 months daily backups);
- Backup storage in a geographically separate AWS availability zone (within the same region);
- Emergency and disaster recovery plan including documented Recovery Time Objective (RTO) and Recovery Point Objective (RPO);
- Regular testing of backup restoration (at least every six months);
- Round-the-clock monitoring of application availability.
IV. Procedures for regular review (resilience)
- Regular internal review of the TOMs (at least annually) and adaptation to the state of the art;
- Security incident management: documented process for detecting, escalating and remedying security incidents;
- Training of employees on data protection and data security (at least annually);
- Contractual obligation of all employees, suppliers and sub-processors to maintain confidentiality;
- Auditing of sub-processors at least every 24 months.
V. Pseudonymisation and data minimisation
- Data minimisation at collection: only the data fields necessary to fulfil the purpose are collected;
- Pseudonymisation in AI-supported processing: in OCR recognition, no direct personal data is transmitted to the AI as far as technically possible; pseudonymisation options are continuously evaluated;
- Anonymisation for statistical analyses for internal product improvement.
VI. Privacy by default
- Most restrictive permission settings by default for new accounts;
- AI functions deactivated by default for SME Customers, with explicit opt-in;
- No disclosure of data to trustees by default without explicit approval by the SME Customer;
- No marketing trackers by default in the authenticated areas of the platform.
Pontora · a product of Haus der Finanzen GmbH · datenschutz@pontora.ch · Version 1.0 · 5 May 2026
Secure Your Operations with Pontora
Allows you to streamline company settings, locations, timesheets, tasks, documents, and trustee approvals from a single dashboard.