Skip to content
Back to Legal & Privacy

Data Processing Agreement

smartNsales AG, version 0.2

This Data Processing Agreement (“DPA”) forms part of the Agreement between smartNsales AG (“smartNsales”) and the Customer and applies where smartNsales Processes Personal Data on behalf of the Customer in connection with the Services.

Capitalised terms not defined in this DPA have the meaning given to them in the Agreement or applicable Data Protection Law.

1. Scope and Roles

1.1 This DPA applies to the Processing of Personal Data contained in Customer Data (“Customer Personal Data”) by smartNsales on behalf of the Customer.

1.2 Where the Customer acts as Controller, smartNsales acts as Processor. Where the Customer acts as Processor on behalf of another Controller, smartNsales acts as Subprocessor.

1.3 Each Party shall comply with the obligations applicable to it under applicable data protection law, including, where applicable, the Swiss Federal Act on Data Protection (“FADP”) and Regulation (EU) 2016/679 (“GDPR”).

1.4 The Customer is responsible for the lawfulness of its collection and Processing of Customer Personal Data and for ensuring that it has all rights, permissions, notices, consents and lawful bases required to instruct smartNsales to Process such Personal Data.

1.5 Processing by smartNsales as an independent Controller for its own purposes, including account administration, billing, security, fraud prevention, legal compliance and business communications, is outside the scope of this DPA and is governed by the smartNsales Privacy Policy.

2. Customer Instructions

2.1 smartNsales shall Process Customer Personal Data only:

  1. on documented instructions from the Customer;
  2. as reasonably necessary to provide, operate, secure, maintain and support the Services; or
  3. where required by applicable law.

2.2 The Agreement, applicable Order Forms, the Customer’s use and configuration of the Services and documented instructions submitted through agreed channels constitute the Customer’s documented instructions.

2.3 Where applicable law requires smartNsales to Process Customer Personal Data other than on the Customer’s instructions, smartNsales shall inform the Customer before such Processing unless prohibited by law.

2.4 If smartNsales reasonably believes that an instruction infringes applicable Data Protection Law, smartNsales shall inform the Customer without undue delay and may suspend execution of the affected instruction until the matter has been clarified.

2.5 Instructions requiring material changes to the Services or assistance materially beyond smartNsales’ obligations under applicable Data Protection Law may be subject to a separate Order Form and additional Fees.

3. Confidentiality and Security

3.1 smartNsales shall ensure that persons authorised to Process Customer Personal Data are subject to appropriate confidentiality obligations and access such data only where necessary for their duties.

3.2 smartNsales shall implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access.

3.3 Such measures shall take into account the state of the art, implementation costs, the nature, scope, context and purposes of the Processing and the risks associated with the Processing.

3.4 A description of the principal categories of technical and organisational measures is set out in Annex 2. Further security information may be made available through the smartNsales Trust Center.

3.5 smartNsales may update its technical and organisational measures from time to time, provided that the overall level of protection for Customer Personal Data is not materially reduced.

4. Subprocessors

4.1 The Customer grants smartNsales general authorisation to engage third-party subprocessors (“Subprocessors”) to Process Customer Personal Data in connection with the Services.

4.2 smartNsales shall maintain an up-to-date list of Subprocessors and make such list available to the Customer, including through the smartNsales Trust Center or another location notified to the Customer.

4.3 smartNsales shall impose appropriate contractual data protection obligations upon its Subprocessors and shall remain responsible for their performance to the extent required by applicable Data Protection Law.

4.4 Where required by applicable Data Protection Law, smartNsales shall provide reasonable notice before appointing a new Subprocessor that will materially Process Customer Personal Data.

4.5 The Customer may object to such appointment within fifteen (15) days on reasonable and documented data-protection grounds.

4.6 If the Parties cannot resolve a reasonable objection, smartNsales may, where reasonably practicable, provide an alternative solution or cease using the relevant Subprocessor for that Customer. If neither is reasonably practicable, either Party may terminate the affected Services upon reasonable notice.

5. International Data Transfers

5.1 smartNsales shall ensure that transfers of Customer Personal Data to a country that does not provide an adequate level of data protection are subject to a lawful transfer mechanism where required by applicable Data Protection Law.

5.2 Such mechanisms may include an adequacy decision, the European Commission Standard Contractual Clauses (“SCCs”), the SCCs as adapted for Swiss data protection law, or another lawful transfer mechanism.

5.3 Where the SCCs are required for a transfer, they are incorporated into this DPA by reference to the extent necessary for the relevant transfer.

5.4 smartNsales may implement supplementary technical, contractual or organisational safeguards where reasonably required in connection with an international transfer.

6. Assistance to the Customer

6.1 Taking into account the nature of the Processing and the information available to smartNsales, smartNsales shall provide reasonable assistance to the Customer with its obligations under applicable Data Protection Law relating to:

  1. requests from Data Subjects;
  2. security of Processing;
  3. notification of Personal Data Breaches;
  4. data protection impact assessments; and
  5. consultations with competent supervisory authorities.

6.2 If smartNsales receives a Data Subject request relating to Customer Personal Data for which the Customer is responsible, smartNsales shall not respond substantively except where required by law or authorised by the Customer and shall, where reasonably practicable, refer the request to the Customer.

6.3 Assistance requiring material effort beyond smartNsales’ statutory obligations or the ordinary functionality of the Services may be subject to reasonable additional Fees to the extent permitted by applicable law.

7. Personal Data Breaches

7.1 smartNsales shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data where notification to the Customer is required under applicable Data Protection Law.

7.2 The notification shall include such information concerning the nature, likely consequences and mitigation of the Personal Data Breach as is reasonably available to smartNsales.

7.3 Information may be provided in phases where complete information is not reasonably available at the time of the initial notification.

7.4 smartNsales shall take reasonable measures to investigate, contain and mitigate Personal Data Breaches within its responsibility.

7.5 Notification of a Personal Data Breach shall not constitute an admission of fault or liability.

7.6 Except where smartNsales has an independent legal obligation, the Customer remains responsible for determining whether notification to Data Subjects, supervisory authorities or other persons is required.

8. Audit and Compliance Information

8.1 smartNsales shall make available information reasonably necessary to demonstrate compliance with this DPA.

8.2 smartNsales may satisfy this obligation through security documentation, Trust Center materials, questionnaires, independent assessments, certifications or other appropriate documentary evidence.

8.3 The Customer shall first use such available information before requesting an additional audit.

8.4 Where such information is insufficient to satisfy a legal obligation of the Customer under applicable Data Protection Law, the Customer may request an audit relating to smartNsales’ Processing of Customer Personal Data.

8.5 Unless otherwise required by a competent supervisory authority or following a material Personal Data Breach, an audit shall:

  1. occur no more than once in any twelve (12)-month period;
  2. be subject to at least thirty (30) days’ prior written notice;
  3. occur during normal business hours;
  4. not unreasonably interfere with smartNsales’ operations;
  5. be subject to appropriate confidentiality and security requirements; and
  6. not permit access to information relating to other customers, privileged information or information the disclosure of which would materially compromise security.

8.6 Audit rights do not include penetration testing, vulnerability scanning, source-code review or unrestricted access to smartNsales systems.

8.7 The Customer shall bear its own audit costs and, to the extent permitted by applicable law, reimburse smartNsales for reasonable costs associated with an audit unless the audit identifies a material breach of this DPA by smartNsales.

9. Return and Deletion

9.1 Upon written request made within thirty (30) days following expiration or termination of the applicable Services, smartNsales shall make Customer Personal Data available for export in a commonly used format where technically practicable.

9.2 Customer Personal Data shall be deleted from active systems no later than ninety (90) days following expiration or termination of the applicable Services, unless continued retention is required by applicable law or expressly agreed between the Parties.

9.3 Customer Personal Data may remain in protected backup systems until deleted or overwritten in accordance with smartNsales’ ordinary backup lifecycle.

9.4 Customer Personal Data retained in backups shall remain subject to the protections of this DPA and shall not be restored or otherwise actively Processed except for disaster recovery, security, legal compliance or comparable legitimate operational purposes.

10. Government and Regulatory Requests

10.1 Where smartNsales receives a legally binding request from a governmental, judicial, regulatory or law-enforcement authority requiring disclosure of Customer Personal Data, smartNsales shall disclose only the information legally required.

10.2 To the extent legally permitted, smartNsales shall notify the Customer before disclosure.

10.3 Where legally and reasonably appropriate, smartNsales may challenge a request it reasonably considers unlawful or excessive.

10.4 smartNsales shall reasonably cooperate with competent supervisory authorities to the extent required under applicable Data Protection Law.

11. Liability and Relationship with the Agreement

11.1 The limitations and exclusions of liability set out in the Agreement apply to this DPA.

11.2 This DPA does not create a separate or additional liability cap. Any liability arising under this DPA shall count toward the aggregate liability cap applicable under the Agreement.

11.3 Nothing in this DPA excludes or limits liability to the extent such liability cannot lawfully be excluded or limited.

11.4 In the event of a conflict between this DPA and another part of the Agreement, this DPA shall prevail solely with respect to matters concerning the Processing of Personal Data.

11.5 This DPA remains effective for as long as smartNsales Processes Customer Personal Data on behalf of the Customer.

Annex 1 — Details of Processing

Subject Matter and Purpose

smartNsales Processes Customer Personal Data as reasonably necessary to provide, operate, secure, maintain and support the Services and to perform the Customer’s documented instructions.

Depending on the Services purchased and used by the Customer, Processing may include data import, organisation, storage, retrieval, search, analysis, classification, extraction, commercial planning, document processing, AI-assisted functionality, meeting preparation, recommendations and related functionality.

Duration

For the duration of the applicable Services and the limited retention periods provided under the Agreement and this DPA.

Categories of Data Subjects

Depending on the Customer’s use of the Services, Data Subjects may include:

  • Customer employees, contractors and Authorised Users;
  • employees and representatives of the Customer’s customers;
  • employees and representatives of retailers, distributors, suppliers and other commercial partners;
  • business contacts and prospects; and
  • other individuals whose Personal Data the Customer elects to Process through the Services.

Categories of Personal Data

Depending on the Customer’s use of the Services:

  • names and professional contact information;
  • job titles, employer and organisational information;
  • user and account identifiers;
  • business communications and meeting notes;
  • customer, account and activity information;
  • contractual and commercial information relating to identifiable individuals;
  • information contained in documents uploaded, imported or connected by the Customer;
  • technical identifiers; and
  • other Personal Data submitted by or on behalf of the Customer.

The Services are not intended for the systematic Processing of special categories of Personal Data or similarly sensitive Personal Data unless expressly agreed between the Parties.

Annex 2 — Technical and Organisational Measures

smartNsales shall maintain technical and organisational measures appropriate to the nature and risks of the Processing, including, as applicable:

Access and confidentiality: authentication, role-based access, least-privilege principles, access provisioning and revocation, confidentiality obligations and measures designed to maintain logical separation between customer environments.

Data security: appropriate protection of data in transit and at rest, secure handling of credentials and secrets, and measures designed to prevent unauthorised access to Customer Personal Data.

Availability and resilience: appropriate infrastructure, backup and recovery processes, system monitoring and incident-management procedures.

Security operations: relevant logging and monitoring, vulnerability and patch-management processes and procedures for investigating material security events.

Development and change management: appropriate development, review, testing and change-management practices designed to reduce unauthorised or insecure changes to production systems.

Subprocessor management: reasonable due diligence, appropriate contractual protections and lawful international-transfer mechanisms where required.

Data lifecycle: measures supporting appropriate access, retention, return and deletion of Customer Personal Data.

Organisational security: assignment of relevant security and data-protection responsibilities, personnel confidentiality obligations, appropriate awareness and training and periodic review of relevant controls.

Further information concerning smartNsales’ security measures may be made available through the smartNsales Trust Center.

smartNsales may update individual measures as technology, threats and industry practices evolve, provided that the overall level of protection for Customer Personal Data is not materially reduced.