Data Processing Agreement (DPA)
Digital Storm GmbH, Sägestrasse 50, 5600 Lenzburg, Switzerland
1. Subject Matter and Scope
1.1 This Data Processing Agreement (“DPA”) governs the processing of personal data by Digital Storm GmbH (“Digital Storm”) in connection with the Customer’s use of the HOMER SaaS platform.
1.2 This DPA supplements the service agreement between Digital Storm and the Customer, including the General Terms and Conditions (“GTC”). It applies exclusively to the extent that Digital Storm processes personal data on behalf of the Customer.
1.3 To the extent that Digital Storm processes personal data for its own purposes, in particular for contract administration, billing, safeguarding its systems, prevention of misuse and fraud, internal business organisation, compliance with its own legal obligations or the establishment, exercise or defence of its own legal claims, such processing is not carried out on behalf of the Customer. For such processing, Digital Storm acts under its own responsibility in accordance with applicable data protection law.
1.4 Anonymised data in respect of which identification of data subjects is no longer possible shall not be considered personal data for the purposes of this DPA. Digital Storm may use such anonymised or aggregated data, in particular for statistical purposes, analysis, product development and improvement of the services.
1.5 Terms such as “personal data”, “controller”, “processor”, “processing” and comparable terms shall have the meanings assigned to them under the applicable data protection law.
2. Roles and Responsibilities of the Parties
2.1 With regard to personal data processed in connection with HOMER, the Customer acts either as controller or as processor on behalf of a third party. Digital Storm acts accordingly as processor or sub-processor.
2.2 The Customer is responsible for the lawfulness of the processing of Customer Data and for the permissibility of engaging Digital Storm.
This includes, in particular, responsibility for:
a) determining the purposes and permissible means of processing;
b) ensuring the existence of all required legal bases, consents, approvals and other authorisations;
c) fulfilling all information and transparency obligations towards data subjects;
d) the permissibility of collecting, entering, transmitting, storing and otherwise processing Customer Data;
e) defining appropriate retention and deletion periods;
f) the lawfulness of instructions issued to Digital Storm;
g) assessing whether special statutory, regulatory, professional or contractual confidentiality obligations prevent the use of HOMER or require additional measures;
h) carrying out any required data protection impact assessments; and
i) all obligations towards data subjects, authorities or other third parties, unless such obligations apply directly to Digital Storm as processor by operation of law.
2.3 If the Customer itself acts as processor on behalf of a third party, the Customer additionally warrants that it has been validly authorised by the relevant controller to engage Digital Storm and its permitted sub-processors and to issue the instructions required for provision of the services.
The Customer is solely responsible for ensuring that its obligations towards the relevant controller are compatible with this DPA and the use of HOMER.
2.4 Digital Storm is not required to comprehensively verify the lawfulness of the Customer’s business activities, processing purposes, Customer Data, legal bases or instructions.
3. Subject Matter, Nature and Purpose of Processing
3.1 The subject matter of the processing is the provision, development, operation, maintenance, security and further development of HOMER and the provision of the associated contractually agreed SaaS services.
3.2 Processing may include, in particular, the following activities:
-
collecting and receiving;
-
recording;
-
storing;
-
organising and structuring;
-
retrieving and displaying;
-
modifying and updating;
-
combining;
-
calculating and automated processing;
-
transmitting to recipients, systems or integrations designated by the Customer;
-
making data accessible to authorised sub-processors;
-
backing up;
-
restricting;
-
deleting and destroying.
3.3 The purpose and scope of the specific processing result from the Customer’s use of HOMER, the functions and integrations used by the Customer, its settings and instructions and the service agreement.
3.4 Digital Storm does not determine independent purposes for Customer Data processed on behalf of the Customer under this DPA.
4. Categories of Data and Data Subjects
4.1 Depending on the use of HOMER, the following categories of personal data may in particular be processed:
-
master and contact data;
-
company and business contact data;
-
user and account data;
-
roles and permissions;
-
communication data;
-
customer and supplier data;
-
contract and quotation data;
-
invoice and billing data;
-
licence and consumption data;
-
service and time-recording data;
-
ticket, support and service data;
-
documents and content provided by the Customer;
-
technical data;
-
log, access and usage data;
-
other data entered into HOMER by the Customer or its users or transmitted to HOMER through connected systems.
4.2 Data subjects may include, in particular:
-
employees and users of the Customer;
-
customers and end customers of the Customer;
-
prospects;
-
suppliers and their employees;
-
business partners;
-
contact persons; and
-
other persons whose data is processed by the Customer through HOMER.
4.3 The nature and scope of the data actually processed in HOMER are substantially determined by the Customer. Digital Storm is not required to review, classify or assess all data entered by the Customer in advance for its permissibility under data protection law.
5. Sensitive Personal Data
5.1 HOMER is generally not intended, without corresponding necessity or an express agreement, for the processing of sensitive personal data, special categories of personal data under Art. 9 GDPR, criminal data or data subject to special statutory or professional confidentiality obligations.
5.2 If the Customer processes such data in HOMER, the Customer is responsible for ensuring that:
a) the processing is necessary and lawful for the HOMER function used;
b) all required legal bases, consents and approvals are in place;
c) all additional statutory or regulatory requirements are complied with; and
d) the risks associated with the processing have been appropriately assessed.
5.3 Digital Storm is not required to examine data entered by the Customer for sensitive content or to separately monitor the processing of such data.
5.4 Digital Storm may prohibit or restrict the processing of certain categories of data or make such processing subject to additional contractual, organisational or technical requirements where this appears necessary for security, compliance, regulatory or operational reasons.
6. Customer Instructions
6.1 Digital Storm processes Customer Data in principle only within the scope of the service agreement, this DPA, the configurations made by the Customer and the Customer’s documented instructions.
6.2 The use and configuration of HOMER and the activation of functions, integrations and automated processes shall be deemed documented instructions from the Customer.
6.3 Instructions must:
a) be lawful;
b) correspond to the agreed services;
c) be technically feasible; and
d) be issued to Digital Storm in text form or through the product functions provided for this purpose.
6.4 Individual instructions extending beyond the standard functionality or agreed scope of HOMER require Digital Storm’s consent.
Digital Storm is entitled to charge the Customer at its then-current rates for the time and effort required to review, implement, document and execute such instructions.
6.5 If Digital Storm considers that an instruction infringes applicable data protection law, Digital Storm shall inform the Customer to the extent required by law.
Digital Storm is entitled to suspend the relevant instruction and temporarily suspend the affected processing or function until the matter has been clarified.
6.6 Digital Storm is not required to carry out instructions that are unlawful, technically impossible, disproportionate, security-threatening or outside the agreed scope of services.
7. Confidentiality and Authorised Persons
7.1 Digital Storm shall ensure that persons under its responsibility who have access to Customer Data process such data only within the scope of their duties and the permitted processing.
7.2 Persons with access to Customer Data shall be appropriately bound by confidentiality obligations or shall be subject to corresponding statutory duties of confidentiality.
7.3 Digital Storm may restrict access to Customer Data to persons whose access is necessary for operation, development, support, security, maintenance, troubleshooting or other contractual services.
7.4 Authorised persons may also include independent external developers and technical specialists, provided that they have been contractually bound to appropriate data protection, confidentiality and security obligations and their engagement is permitted under the provisions governing sub-processors.
8. Technical and Organisational Measures
8.1 Taking into account the state of the art, implementation costs and the nature, scope, context and purposes of processing, Digital Storm shall implement appropriate technical and organisational measures to protect the personal data processed by it.
8.2 The measures shall be based on the respective risk and may include, in particular, measures relating to:
-
access control;
-
permissions management;
-
authentication;
-
confidentiality;
-
integrity;
-
availability;
-
recoverability;
-
logging;
-
system and network security;
-
backups;
-
vulnerability and patch management;
-
incident management;
-
organisational security requirements;
-
oversight of service providers and sub-processors.
8.3 Digital Storm does not owe absolute security and does not warrant, in particular, that security incidents, cyberattacks, security vulnerabilities or unauthorised access can be completely excluded.
8.4 Digital Storm is entitled to modify, replace or further develop technical and organisational measures at any time, provided that the overall level of protection remains appropriate taking into account the relevant risk.
The Customer has no entitlement to specific technical solutions, manufacturers, technologies, architectures or security procedures unless expressly agreed in writing.
8.5 Digital Storm’s security concepts, architecture information, audit reports, penetration test results and comparable information are confidential.
Digital Storm is not required to disclose source code, complete internal security documentation, information relating to other customers or information whose disclosure could impair the security of the systems.
9. Sub-Processors
9.1 The Customer grants Digital Storm general authorisation to engage sub-processors for the provision, development, maintenance, security and support of the HOMER services.
9.2 Sub-processors may include, in particular:
-
cloud and hosting providers;
-
database and infrastructure providers;
-
communication and messaging providers;
-
monitoring, logging and security services;
-
development, project management and documentation systems;
-
software, interface and integration providers;
-
providers of artificial intelligence functions; and
-
independent external software developers and technical specialists.
9.3 Digital Storm shall maintain a current confidential register of material sub-processors (“Sub-Processor Register”).
To the extent required, this register shall include, in particular, the identity or provider, registered office or processing location, the material purpose of the processing and, where applicable, the safeguards used for international transfers of personal data.
9.4 The complete Sub-Processor Register is not required to be published publicly.
Digital Storm shall provide existing or prospective customers with the information required under applicable data protection law on a confidential electronic basis, in particular through a non-public customer area, direct electronic transmission or upon a substantiated request.
The Customer undertakes to keep non-public information relating to natural persons, security structures and sub-processors confidential and to use such information solely for the purpose of assessing the data protection aspects of the processing.
9.5 On publicly accessible overviews, Digital Storm may identify natural persons or groups of natural persons in a categorised or anonymised form for reasons of privacy and system security, provided that any additional information required for the exercise of mandatory statutory rights is made available confidentially.
9.6 Digital Storm shall inform the Customer of the intended engagement or replacement of a material sub-processor to the extent such information is required under applicable data protection law.
Such information may be provided in particular by email, product notification, customer portal or another suitable electronic means.
9.7 The Customer may object to a new or replacement sub-processor within ten calendar days of such notification on specifically substantiated data protection grounds.
If no objection is raised within this period, use of the relevant sub-processor shall be deemed accepted.
9.8 An objection is only permissible if the Customer specifically demonstrates why use of the relevant sub-processor would breach data protection law applicable to the specific processing.
Purely commercial, business-related or general preferences shall not constitute sufficient grounds for objection.
9.9 In the event of a justified objection, Digital Storm may, at its own discretion:
a) refrain from using the relevant sub-processor;
b) use another sub-processor;
c) implement additional appropriate safeguards;
d) restrict or discontinue the affected function or service; or
e) terminate the affected service agreement or parts thereof.
To the extent permitted by law, the Customer shall have no entitlement to damages, reimbursement or other claims as a result.
9.10 Digital Storm shall impose appropriate data protection, confidentiality and security obligations on sub-processors to the extent required by law.
9.11 To the extent Digital Storm is required under mandatory data protection law to be responsible towards the Customer for compliance by a sub-processor, the exclusions and limitations of liability pursuant to Section 15 of this DPA and Sections 9 and 10 of the GTC shall remain applicable to the extent permitted by law.
10. Hosting, Development Services and Processing Abroad
10.1 Digital Storm determines, at its own discretion and subject to applicable data protection law, the technical infrastructure used for HOMER and the providers engaged for such infrastructure.
10.2 The primary production HOMER data is currently stored on Microsoft Azure cloud infrastructure in Switzerland.
This does not give the Customer any entitlement to the continued use of an unchanged provider, a particular cloud platform, a specific data centre or a particular processing location unless expressly agreed otherwise in writing.
Digital Storm is in particular entitled to supplement or replace Microsoft Azure with other suitable providers such as Amazon Web Services, Google Cloud Platform or other comparable infrastructure and cloud providers.
To the extent this results in a material change under data protection law to a sub-processor or processing location, the provisions of this DPA and applicable data protection law shall apply.
10.3 To the extent personal data is processed in, or made accessible to a person or recipient in, a country for which no legally recognised adequate level of data protection exists, Digital Storm shall implement the appropriate safeguards required by law for transfers initiated by it.
Such safeguards may include, in particular, standard data protection clauses recognised by the Swiss Federal Data Protection and Information Commissioner (“FDPIC”) as well as additional technical, organisational or contractual safeguards.
10.4 In connection with the development, maintenance, troubleshooting and technical support of HOMER, Digital Storm engages independent external software developers with a working and processing location in Vietnam.
The names of these natural persons are not published publicly for privacy and security reasons.
Their full identification and contractual information is documented confidentially by Digital Storm and made available to customers only to the extent required under applicable data protection law and on a confidential basis.
10.5 Where technically necessary for their activities and authorised by Digital Storm, the external developers may access production HOMER systems and Customer Data contained therein from Vietnam by means of controlled remote access.
Production HOMER data is not thereby intentionally or permanently stored in Vietnam.
In particular, without Digital Storm’s express authorisation, the external developers are prohibited from:
-
permanently storing Customer Data on local devices;
-
copying Customer Data to private or unauthorised cloud storage;
-
synchronising Customer Data;
-
copying Customer Data to external media;
-
printing Customer Data;
-
making Customer Data accessible to third parties;
-
creating independent local datasets or backups.
Technically unavoidable temporary data must be limited to the minimum necessary and deleted as soon as it is no longer required for the authorised activity.
10.6 The external developers are contractually required to process personal data exclusively on Digital Storm’s instructions and only to the extent necessary for their activities.
They may not engage additional persons or subcontractors with access to Customer Data without Digital Storm’s prior written approval.
10.7 Digital Storm may use Atlassian cloud services for software development, project management, issue tracking, tickets, roadmaps, documentation and comparable development processes, including in particular Jira, Confluence and related Atlassian products.
Atlassian systems are not intended to serve as the primary storage location for production HOMER Customer Data.
However, where necessary for development, troubleshooting or support, limited technical information, extracts, references, contact details or other information required for a specific matter may be processed in such systems.
Digital Storm shall, where possible, limit such data to the minimum required for the relevant purpose.
Processing locations and international transfers by such providers shall be governed by the relevant product configuration used by Digital Storm and the applicable data protection and transfer terms of the respective provider.
Digital Storm is entitled to supplement or replace Atlassian products with other comparable development, ticketing, documentation or project management systems.
10.8 The Customer shall inform Digital Storm if its data is subject to special requirements concerning processing locations or data transfers due to statutory, regulatory, contractual or professional confidentiality obligations.
Unless expressly agreed otherwise, Digital Storm does not owe a restriction to a particular provider, country, data centre location or technical platform, provided applicable data protection law is complied with.
10.9 The Customer is solely responsible for assessing whether its use of HOMER, including integrations used or third-party providers activated by the Customer, is compatible with any additional statutory, regulatory, contractual or professional requirements applicable to the Customer.
11. Rights of Data Subjects
11.1 The Customer is generally responsible for handling and responding to requests from data subjects.
11.2 If a data subject submits a request directly to Digital Storm concerning Customer Data, Digital Storm is entitled to forward such request to the Customer.
Digital Storm shall generally not respond to such request itself unless Digital Storm is directly required by law to do so or has been instructed accordingly by the Customer.
11.3 Taking into account the nature of the processing and the available technical means, Digital Storm shall assist the Customer to the extent required by law in fulfilling its obligations towards data subjects.
11.4 To the extent such assistance is not already provided through standard HOMER functionality, Digital Storm is entitled to charge the Customer at its then-current rates for the resulting effort, unless mandatory law requires such assistance to be provided free of charge.
12. Personal Data Breaches
12.1 If Digital Storm becomes aware of a personal data security breach affecting personal data processed by Digital Storm on behalf of the Customer, Digital Storm shall inform the Customer as soon as possible in accordance with applicable data protection law or, where the GDPR applies, without undue delay.
12.2 The initial notification shall contain the information reasonably available to Digital Storm at that time.
If not all information is available at the same time, Digital Storm may provide it in phases.
12.3 To the extent available and legally required, the notification may include in particular information regarding:
-
the nature of the breach;
-
affected categories of data;
-
known or expected consequences;
-
measures already taken or planned; and
-
a contact point for further information.
12.4 A notification by Digital Storm shall not constitute an acknowledgement of a defect, an admission of fault or an acknowledgement of liability.
12.5 The Customer is responsible for determining whether notification to data protection authorities, other authorities, data subjects, its own customers or other third parties is required, unless applicable law imposes such obligation directly on Digital Storm.
12.6 Digital Storm shall assist the Customer with such obligations to the extent required by law and based on the information available to Digital Storm.
Additional services, investigations, reports, customer-specific documentation or assistance may be charged to the Customer based on effort incurred, unless mandatory law provides otherwise.
13. Additional Assistance to the Customer
13.1 Digital Storm shall assist the Customer to the extent required by law and taking into account the nature of the processing and the information available to Digital Storm, in particular with:
a) security of processing;
b) handling personal data breaches;
c) data protection impact assessments;
d) consultations with data protection authorities; and
e) compliance with mandatory statutory documentation and information obligations.
13.2 Responsibility for conducting, assessing and documenting such procedures remains with the Customer to the extent such obligations are assigned by law to the controller.
13.3 Digital Storm is not required to provide legal advice to the Customer or to assess the data protection lawfulness of the Customer’s business model, processing purposes or data processing activities.
13.4 Any assistance exceeding the standard functions included in HOMER or Digital Storm’s own mandatory statutory obligations may be charged by Digital Storm based on effort incurred at its then-current rates.
14. Evidence and Audits
14.1 Upon request, Digital Storm shall provide the Customer with such information as is reasonably required to demonstrate compliance with the statutory obligations applicable to Digital Storm as processor.
14.2 Evidence shall primarily be provided by means of existing documentation, including in particular:
-
descriptions of technical and organisational measures;
-
certificates;
-
audit reports;
-
standardised questionnaires;
-
security information; or
-
comparable appropriate evidence.
14.3 An on-site audit or inspection is only permitted to the extent that:
a) applicable data protection law requires it;
b) the necessary information cannot reasonably be provided through other evidence; and
c) the audit is proportionate.
14.4 Audits must generally be announced in writing at least 30 calendar days in advance and carried out during Digital Storm’s usual business hours.
Cases in which a shorter period is required by mandatory law or an order of a competent authority remain reserved.
14.5 Without a specific data protection-related reason, no more than one audit may be conducted within any twelve-month period.
14.6 Any external auditor engaged by the Customer must:
a) be independent;
b) possess appropriate professional qualifications;
c) be bound by confidentiality obligations; and
d) not be a direct competitor of Digital Storm.
14.7 Audits may in particular not:
-
impair the security or operation of HOMER;
-
enable access to data of other customers;
-
disclose source code;
-
unnecessarily disclose trade secrets or security-sensitive internal information; or
-
require disproportionate technical or organisational intervention.
14.8 The Customer shall bear all of its own costs as well as the costs incurred by Digital Storm in preparing, supporting, conducting and following up on an audit.
Digital Storm may charge such costs at its then-current rates unless mandatory law provides otherwise.
14.9 Mandatory audit, information and supervisory rights of authorities remain reserved.
15. Liability and Indemnification
15.1 All claims arising from or in connection with this DPA shall be subject to the warranty exclusions, exclusions of liability and limitations of liability set out in Sections 9 and 10 of Digital Storm’s applicable GTC.
This applies in particular to claims relating to data protection, information security, breaches of confidentiality, sub-processors, international transfers, data loss, disclosure of data and security incidents, unless mandatory law provides otherwise.
15.2 This DPA does not create any liability of Digital Storm beyond that arising from mandatory data protection law and the GTC.
In particular, the assumption of an obligation under this DPA does not constitute a guarantee or representation of a specific result unless expressly identified as such.
15.3 Mandatory statutory claims of data subjects or powers of data protection or other authorities are not restricted by this DPA.
However, as between Digital Storm and the Customer, the contractual liability and recourse provisions shall apply to the extent permitted by law.
15.4 To the extent permitted by law, the Customer shall indemnify and hold harmless Digital Storm and its shareholders, corporate bodies, managing directors, employees, agents and auxiliary persons from and against third-party claims and associated reasonable costs and expenses to the extent arising in particular from:
a) unlawful processing by the Customer;
b) absent or insufficient legal bases, consents or approvals;
c) a breach by the Customer of information obligations;
d) unlawful or impermissible instructions issued by the Customer;
e) impermissible entry or processing of sensitive or specially regulated data;
f) a breach by the Customer of statutory, regulatory, professional or contractual confidentiality obligations;
g) lack of authorisation by the Customer to engage Digital Storm or its sub-processors;
h) claims by customers, end customers, employees or other data subjects of the Customer to the extent the cause falls within the Customer’s area of responsibility; or
i) any other breach by the Customer of this DPA or applicable data protection law.
15.5 To the extent permitted by law, the indemnity shall also include reasonable legal advisory, defence, court, investigation and other costs as well as regulatory fees and financial burdens to the extent attributable to the Customer’s area of responsibility.
15.6 The indemnity shall not apply to the extent the relevant claim was demonstrably caused exclusively by conduct of Digital Storm for which Digital Storm is liable under mandatory law.
15.7 Digital Storm is the Customer’s sole contractual counterparty under this DPA. Digital Storm’s shareholders, managing directors, corporate bodies, employees, agents and auxiliary persons do not assume any personal guarantee, surety or other personal contractual obligation towards the Customer.
Mandatory statutory claims against natural persons remain reserved.
16. Return and Deletion of Data
16.1 The Customer is responsible for securing any data it wishes to retain after termination of the service agreement through the export or access options provided by HOMER before the service agreement ends.
16.2 To the extent applicable data protection law gives the Customer a choice between return and deletion, the Customer must exercise such choice no later than upon termination of the service agreement.
If the Customer does not make a choice, deletion shall be deemed selected.
16.3 Return shall generally take place through the standard export or access options provided by HOMER.
Digital Storm is not required to prepare data in a customer-specific format, migrate data or transfer data to a successor system unless separately agreed.
Such additional services may be charged based on effort incurred.
16.4 After termination of the agreement, Digital Storm is entitled to delete Customer Data from production systems.
16.5 Data contained in backups, logs, backup copies or technically required redundant copies may continue to exist until expiry of the respective regular backup, retention and deletion cycles.
During this period, such data shall generally no longer be used for operational purposes and shall be deleted or overwritten as part of the regular processes unless a statutory retention obligation applies.
16.6 The existence of internal backups does not give the Customer any entitlement to restoration of individual data.
16.7 Statutory retention obligations and Digital Storm’s right to retain data to the extent necessary for the establishment, exercise or defence of its own legal claims remain reserved.
17. Costs and Additional Services
17.1 Data protection services included within the regular scope of HOMER are covered by the agreed subscription fees.
17.2 Digital Storm is entitled to charge additional effort based on time incurred at its then-current rates, in particular for:
-
individual instructions;
-
customer-specific information;
-
assistance with data subject requests;
-
data exports outside standard functionality;
-
data protection impact assessments;
-
authority requests;
-
investigations and special reports;
-
customer-specific security questionnaires;
-
audits and inspections;
-
migrations;
-
special deletion requests;
-
recovery attempts; and
-
other services outside the standard scope of services.
17.3 This also applies where Digital Storm’s assistance is necessary for the Customer to fulfil one of its obligations, unless mandatory law expressly requires Digital Storm to provide such assistance free of charge.
18. Term and Termination
18.1 This DPA enters into force together with the service agreement and remains applicable for as long as Digital Storm processes personal data on behalf of the Customer.
18.2 Upon termination of the service agreement, this DPA shall generally also terminate.
Provisions which by their nature are intended to survive termination, in particular confidentiality, deletion, liability, indemnification and evidence obligations, shall remain in force to the extent required.
19. Amendments
19.1 Digital Storm is entitled to amend this DPA due to legal, regulatory, security-related, technical, economic or operational developments.
19.2 The current version shall be made available electronically by Digital Storm. Individual notification to the Customer is not required unless expressly required by applicable data protection law.
19.3 Amendments shall apply to newly concluded agreements upon publication and to existing contractual relationships no later than from the beginning of the next contractual period.
Amendments required to comply with mandatory legal or regulatory requirements or for security reasons may, to the extent permitted by law, apply from an earlier date determined by Digital Storm.
19.4 Statutory information and objection rights relating to changes in sub-processors remain reserved.
20. Relationship with the GTC and Final Provisions
20.1 In the event of a conflict between this DPA and the GTC, this DPA shall take precedence exclusively with respect to specific data protection processing obligations.
The warranty and liability provisions pursuant to Sections 9 and 10 of the GTC remain expressly reserved.
20.2 Deviating or additional obligations of Digital Storm shall only exist if Digital Storm has expressly agreed to them in writing.
20.3 If individual provisions of this DPA are invalid or unenforceable, the validity of the remaining provisions shall remain unaffected.
20.4 To the extent permitted by law, the exclusive place of jurisdiction shall be Digital Storm’s registered office.
20.5 This DPA shall be governed exclusively by substantive Swiss law. To the extent the GDPR directly applies to specific processing activities, its mandatory provisions remain reserved.
Annex 1 – Description of the Processing
Subject Matter of the Processing
Provision, development, operation, maintenance and support of the HOMER SaaS platform and the functions, integrations and services activated by the Customer.
Duration of the Processing
For the duration of the service agreement and thereafter for technically and legally required retention, backup and deletion periods.
Nature of the Processing
Collecting, recording, organising, structuring, storing, retrieving, displaying, modifying, linking, calculating, automated processing, transmitting, backing up, restricting, deleting and destroying.
Purpose of the Processing
Provision of the HOMER services purchased by the Customer and the functions and integrations activated by the Customer.
Categories of Personal Data
In particular master, contact, company, user, communication, customer, supplier, contract, quotation, invoice, billing, licence, consumption, service, time-recording, ticket, support, document, content, log, access and usage data as well as other data provided by the Customer.
Categories of Data Subjects
In particular users and employees of the Customer, customers and end customers, prospects, suppliers, business partners, contact persons and other persons whose data is processed by the Customer through HOMER.
Sensitive Personal Data
Not generally intended as a necessary component of the HOMER services. To the extent the Customer processes such data, Section 5 of this DPA shall apply in particular.
Instructions
The service agreement, use and configuration of HOMER, functions and integrations activated by the Customer and additional lawful documented instructions pursuant to Section 6.
Annex 2 – Overview of Material Services and Sub-Processors
Cloud Infrastructure / Production Hosting
Current primary provider: Microsoft Azure
Current primary processing location: Switzerland
Purpose: Hosting, databases, computing capacity, storage, networking and technical infrastructure for HOMER
Note: Digital Storm may change or supplement the provider or processing location in accordance with Sections 9 and 10 of this DPA.
Development and Project Management Systems
Provider: Atlassian Cloud or the relevant Atlassian entity
Products: In particular Jira, Confluence and related development, ticketing, roadmap and documentation services
Purpose: Software development, project management, tickets, troubleshooting, roadmaps and technical documentation
Scope of data: Generally no primary storage of production HOMER Customer Data; where required for development or support, limited technical or customer-related information may be processed
Processing location: According to the relevant Atlassian configuration, product and applicable provider terms
External Software Development and Technical Support
Processing location: Vietnam
Services: Software development, maintenance, troubleshooting and technical support of HOMER
Data access: Controlled remote access to production HOMER systems where technically necessary
Local storage: Generally prohibited
Purpose: Development, operation, maintenance, troubleshooting and technical support of HOMER
Safeguards: Contractual data protection, confidentiality, security and international data transfer obligations
The personal identities of the external developers are not published publicly.
Digital Storm documents their full identification and contractual information confidentially and makes such information available to customers only to the extent required under applicable data protection law and on a confidential basis.
Digital Storm may engage additional material providers and sub-processors. Changes shall be governed by Section 9 of this DPA.
Annex 3 – Technical and Organisational Measures
Digital Storm implements appropriate and risk-based technical and organisational measures pursuant to Section 8 of this DPA.
Depending on the respective system and risk, such measures include in particular:
-
individual user accounts;
-
role-based permissions;
-
multi-factor authentication where technically available and appropriate;
-
restriction of production access to persons who require such access;
-
controlled remote access for external developers;
-
prohibition of unauthorised local storage of Customer Data;
-
logging of security-relevant access and events;
-
encrypted transmission of data;
-
appropriate protection of end-user devices;
-
security updates and patch management;
-
backup and recovery procedures;
-
incident management;
-
confidentiality obligations for authorised persons;
-
regular review of permissions;
-
appropriate organisational requirements for external developers and other sub-processors.
The specific implementation of these measures may be continuously adapted due to technical, organisational, regulatory and security-related developments.
Upon substantiated request, Digital Storm may provide the Customer with a current description of the material technical and organisational measures.
Such information is confidential and may be used exclusively for the purpose of assessing the data protection aspects of the processing.
V 2.4 (26 August 2026)