Data Processing Agreement
EqualVoice-Assistant

This Data Processing Agreement (“DPA“) is entered into between the Customer (acting as Controller) and Ringier AG (acting as Processor) and is incorporated into the Terms of Service.

 

1. Definitions

1.1. “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, and “Processing” shall have the meanings given in the GDPR.

1.2. “Applicable Data Protection Law” means the Swiss FADP and the GDPR.

 

2. Subject Matter of Processing

2.1. The Processor shall process Personal Data on behalf of the Controller for the purpose of providing the Service as described in the Terms of Service.

2.2. The details of the processing activities are set out in Annex 1 to this DPA.

 

3. Processor’s Obligations

3.1. Instructions: The Processor shall process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country, unless required to do so by Union or Member State law.

3.2. Confidentiality: The Processor shall ensure that persons authorised to process the Personal Data have committed themselves to confidentiality.

3.3. Security: The Processor shall implement the technical and organisational measures specified in Annex 2 (TOMs) to ensure a level of security appropriate to the risk. The Processor may update the TOMs from time to time to reflect technical progress or organisational changes, provided that such updates do not result in a lower level of protection for personal data.

3.4. Sub-processing: The Controller provides a general authorisation for the Processor to engage sub-processors. The Processor shall maintain an up-to-date list of its sub-processors (see below Annex 3) and shall inform the Controller of any intended changes concerning the addition or replacement of other sub-processors, thereby giving the Controller the opportunity to object to such changes within 20 days of receiving notice. The Processor shall impose the same data protection obligations on its sub-processors as set out in this DPA.
3.5. Data Subject Rights: The Processor shall, to the extent legally permissible, assist the Controller with appropriate technical and organisational measures in fulfilling the Controller’s obligation to respond to requests for exercising the Data Subject’s rights.

3.6. Personal Data Breach: The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data Breach. In line with regulatory requirements, notifications will be made as soon as possible under the FADP and within 72 hours where feasible under the GDPR.

3.7. Data Deletion and Return: Upon termination of the Service, the Processor shall, at the choice of the Controller, delete or return all Personal Data contained in the Account Data to the Controller, and delete existing copies unless applicable laws require storage of the Personal Data for a longer time. Backup data will be purged according to the Processor’s standard backup rotation policy.

 

4. International Transfers

4.1. The Processor will process data in the EEA. Any transfer of Personal Data to a third country by the Processor shall be done only on the basis of documented instructions from the Controller and in compliance with Chapter V of the GDPR.

4.2. Where such transfers are not covered by an adequacy decision, they shall be governed by the Standard Contractual Clauses (SCCs) issued by the European Commission, which are incorporated by reference.

 

5. Documents and Audit 

The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and shall allow for audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, provided such audits are subject to reasonable notice, confidentiality, and frequency limitations.

 

6. Assistance with Controller Obligations

Upon request, and taking into account the nature of the processing and the information available to the Processor, the Processor will assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 GDPR (security of processing, personal data breach notification, data protection impact assessment, and prior consultation).

 

7. Applicable Law and Jurisdiction

This Data Processing Agreement (“DPA”) is entered into between the Customer (acting as Controller) and Ringier AG (acting as Processor) and is incorporated into the Terms of Service.

This DPA applies exclusively to organizational or business customers. It does not apply to individual private users utilizing the Service in a personal capacity.

This DPA shall be governed by and construed in accordance with Swiss substantive law, to the exclusion of its conflict-of-law rules (including the Swiss Private International Law Act, IPRG).

The exclusive place of jurisdiction for all disputes arising out of or in connection with this DPA shall be Zofingen, Switzerland.

July 2026


Annex I: Details of the Processing

  • Subject-matter: Processing of Personal Data to provide the AI text-generation service.
  • Duration: For the term of the agreement between the parties.
  • Nature and Purpose: To process user Input, generate Output, manage user accounts, and ensure the security and performance of the Service provided to the Customer.
  • Categories of Data Subjects: Users of the Service authorized by the Controller.
  • Categories of Personal Data: Account Data (email, name, etc.), Content Data (as submitted by users). The Service is not intended for special categories of data.

 


Annex II: Technical and Organisational Measures (TOMs)

This Annex describes the security measures implemented by Ringier AG.

1. Confidentiality

  1. Access Control: Access to systems is restricted based on the principle of least privilege using roles and permissions. Authentication is enforced using SSO, MFA, and passkeys.
  2. Encryption: All data is encrypted in transit using TLS 1.2 or higher. Data at rest is encrypted using AES-256 via AWS-managed services (e.g., AWS KMS).
  3. Secrets Management: Application secrets and keys are managed using AWS Secrets Manager.

2. Integrity

  1. We implement measures to ensure the accuracy and integrity of data, including input and output validation.

3. Availability and Resilience

  1. Infrastructure: The service is hosted on Amazon Web Services (AWS) in the EU (Frankfurt) region, leveraging its high-availability infrastructure.
  2. Backups: Regular, encrypted backups are taken. The backup retention period is 35 days (rolling purge), managed per AWS rotation policy. Restore procedures are tested periodically.
  3. Disaster Recovery: Our disaster recovery objectives are a Recovery Time Objective (RTO) of 48 hours and a Recovery Point Objective (RPO) of 24 hours.

4. Testing and Assessment

We perform regular security testing to identify and mitigate vulnerabilities across our products and infrastructure. Our security scanning is an integral part of the development lifecycle and includes:

  1. Vulnerability Scanning: Products are scanned for vulnerabilities on a regular basis and at key stages of development using tools such as JFrog Xray and Amazon Inspector. Critical vulnerabilities are resolved on an ongoing basis.
  2. Penetration Testing: Independent penetration tests are conducted periodically and after major releases or architectural changes to validate the system’s resistance to external attacks.

5. Logging and Monitoring

  1. Administrative actions and system events are logged to ensure traceability and support security investigations.

6. Incident Management

  1. We have an incident response plan to handle security incidents, including Personal Data Breaches. Notification timelines are “as soon as possible” for the Swiss FADP and within 72 hours where feasible for the GDPR.

 


Annex III: Sub-Processor List

Last updated: July 2026

Ringier AG uses the following sub-processors to support the delivery of our Services.

Provider Country Role/Purpose Data Categories Processed Transfer Mechanism
Amazon Web Services (AWS) EU / US Cloud Hosting and Infrastructure Account Data, Content Data, Usage and Telemetry Data Standard Contractual Clauses
OpenAI, L.L.C. US AI Model Processing Content Data (Inputs/Outputs) Standard Contractual Clauses
Langfuse EU Observability and Logging Content Data, Usage and Telemetry Data N/A (Processing in EU)
Ringier Axel Springer Poland Poland EqualVoice-Assistant Stand-Alone Account Data, Content Data, Usage and Telemetry Data Development Service Contract

Payment service providers are not included as subprocessors in the above list to the extent that they process personal data as independent controllers in connection with payment transactions. Information on such providers is set out in the Privacy Notice.

Representing reality

Ready to elevate visibility and inclusion in your communication?

The EqualVoice-Assistant is now available.