Data Processing Agreement
Last updated: 18 July 2026 Processor: Envestis SA, Via Pretorio 13A, 6900 Lugano, Switzerland — legal@ciaopost.com
This Data Processing Agreement (“DPA”) forms part of, and is incorporated into, the ciaopost Terms of Service between Envestis SA and the Business. By accepting the Terms of Service, the Business accepts this DPA. It governs the processing of End Customer personal data that ciaopost carries out on the Business’s behalf.
1. Parties and roles
1.1. The Business (the “Controller”) — the merchant, company, or professional who holds a ciaopost account and collects testimonials from its own customers.
1.2. Envestis SA, operating ciaopost (the “Processor”, “we”, “us”) — processes End Customer personal data only on the Controller’s documented instructions, to provide the Service.
1.3. Scope of this DPA. This DPA applies only to the personal data of End Customers (the Controller’s customers who provide testimonials). It does not apply to the Business’s own account data, for which Envestis SA is itself the controller (see the Privacy Policy, Section 2).
1.4. This DPA gives effect to the obligations of Article 28 of the EU General Data Protection Regulation (GDPR) and the equivalent obligations under the Swiss Federal Act on Data Protection (nLPD/FADP).
2. Subject matter of the processing
| Item | Detail |
|---|---|
| Subject matter | Production and distribution of customer testimonials collected by the Controller |
| Duration | For the term of the Controller’s ciaopost account, plus the retention periods in Section 9 |
| Nature and purpose | Storing, transcribing, subtitling, formatting, and publishing testimonials to the Controller’s connected social accounts; recording consent |
| Type of personal data | End Customer first name; image and voice within the testimonial; testimonial content (video, voice, photo, text); consent record and signature; transcription |
| Categories of data subjects | The Controller’s own customers (End Customers) who provide a testimonial |
3. The Processor’s obligations
Envestis SA shall:
3.1. Process only on instructions. Process End Customer personal data only on the Controller’s documented instructions, including as to international transfers, unless required by law, in which case we inform the Controller first, unless the law prohibits it. The Controller’s instructions are: to store, transcribe, subtitle, caption, format, and publish testimonials to the Controller’s connected accounts, and to keep consent records. We do not use End Customer data for our own purposes, and we never edit the customer’s own words — subtitles are reproduced verbatim.
3.2. Confidentiality. Ensure that persons authorised to process the data are bound by confidentiality.
3.3. Security. Implement appropriate technical and organisational measures, as set out in Section 7.
3.4. Sub-processors. Engage sub-processors only in accordance with Section 8.
3.5. Assist the Controller — taking into account the nature of the processing — in responding to End Customer rights requests (access, rectification, erasure, restriction, portability, objection, withdrawal of consent), and in ensuring security, breach notification, and data protection impact assessments.
3.6. Data subject requests. If an End Customer contacts us directly about their data, we will, without undue delay, direct them to the Controller, who is the controller of that data, and inform the Controller.
3.7. Breach notification. Notify the Controller without undue delay after becoming aware of a personal data breach affecting End Customer data, with the information the Controller needs to meet its own notification obligations.
3.8. Deletion or return. At the end of the provision of the Service, delete or return all End Customer personal data as the Controller chooses, and delete existing copies unless law requires retention, as set out in Section 9.
3.9. Demonstrate compliance. Make available to the Controller the information necessary to demonstrate compliance with these obligations, and allow for and contribute to audits as set out in Section 10.
3.10. Warn on unlawful instructions. Immediately inform the Controller if, in our opinion, an instruction infringes the GDPR, the nLPD, or other data protection law.
4. The Controller’s obligations
4.1. The Controller warrants that it has a lawful basis — the End Customer’s consent, obtained through the Service — to collect and publish each testimonial, and that it has provided the End Customer with any required information.
4.2. The Controller is responsible for the accuracy and legality of the testimonial content it captures and instructs us to publish.
4.3. The Controller’s instructions to us must comply with data protection law. The Controller must not instruct us to process End Customer data unlawfully.
5. International transfers
5.1. Envestis SA is established in Switzerland. Where End Customer data is transferred to a sub-processor outside Switzerland or the EEA, as set out in Section 8, such transfer relies on an appropriate safeguard: Standard Contractual Clauses, the Swiss-US and EU-US Data Privacy Framework where the recipient is certified under it, or another lawful mechanism.
5.2. A copy of the safeguard relied on for any given recipient is available to the Controller on request.
6. Instructions
6.1. This DPA, the Terms of Service, and the Controller’s configuration of the Service — the accounts it connects, the testimonials it captures, the consent it collects — constitute the Controller’s complete and final documented instructions.
6.2. Additional instructions outside the scope of the Service require a separate written agreement.
7. Security measures
7.1. Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, Envestis SA implements appropriate technical and organisational measures, including:
- encryption of connected-account tokens at rest;
- access controls limiting access to authorised personnel;
- secure, access-controlled infrastructure;
- measures to restore availability and access to personal data after an incident;
- a process for regularly testing and evaluating the effectiveness of these measures.
8. Sub-processors
8.1. General authorisation. The Controller authorises Envestis SA to engage the sub-processors listed below, each of which is bound by data protection obligations no less protective than this DPA.
8.2. Current sub-processors for End Customer data:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting and storage | Germany (EU) |
| Stripe | Payment processing | EU and US |
| Brevo | Transactional email | EU |
| OpenRouter (Whisper-family model) | Transcription and AI captions | US |
| Sentry | Error monitoring | EU and US |
| Firebase Cloud Messaging | Push notifications | US |
Reverse-geocoding (converting device location into a city name) runs on our own self-hosted infrastructure and is not a sub-processor.
8.3. Changes. We will inform the Controller of any intended addition or replacement of a sub-processor, giving the Controller the opportunity to object on reasonable data protection grounds.
8.4. We remain fully liable to the Controller for a sub-processor’s performance of its data protection obligations.
9. Retention and deletion
9.1. End Customer testimonials and consent records are retained in accordance with the Controller’s instructions and the retention periods in the Privacy Policy: consent records are kept as evidence for ten years; testimonials for as long as the Controller keeps them in the account.
9.2. On termination of the account, or on the Controller’s instruction, we delete or return End Customer data, subject to any retention required by law.
9.3. The fraud-prevention record — a hashed identifier derived from a connected social account, described in the Privacy Policy — is retained beyond deletion on the basis of legitimate interest; it does not contain End Customer testimonial content.
10. Audit
10.1. Envestis SA makes available to the Controller the information necessary to demonstrate compliance with its obligations under this DPA, and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates.
10.2. To avoid disruption and to protect the confidentiality and security of other customers’ data, audits are conducted on reasonable prior notice, during business hours, and no more than once per year, except where required by a supervisory authority or following a personal data breach, and are subject to confidentiality. Providing an up-to-date compliance report or certification may satisfy an audit request.
11. Liability and term
11.1. Liability under this DPA is subject to the limitations of liability in the Terms of Service, to the extent permitted by law.
11.2. This DPA takes effect when the Controller accepts the Terms of Service and continues for as long as Envestis SA processes End Customer personal data on the Controller’s behalf.
11.3. In case of conflict between this DPA and the Terms of Service on the subject of End Customer data processing, this DPA prevails.
12. Governing law
12.1. This DPA is governed by the law of Switzerland and, where the GDPR applies, is interpreted to give effect to Article 28 GDPR.
Contact
Data protection contact: Envestis SA, Via Pretorio 13A, 6900 Lugano, Switzerland — legal@ciaopost.com