Open-source apps for data protection officers: DPA, residency and exit

One DPA under the revised FADP and the GDPR, data kept where your contract names, sub-processors named in your contract, and your data returned and deleted when the contract ends.

Start with one workloadBook a 30-minute briefing

Agreement
Revised FADP (art. 9) and GDPR (art. 28)
Location
Your premises, or any of 12 Pilae Cloud regions
Sub-processors
Listed in the DPA, changes notified in advance
Contact
privacy@pilae.com

The questions a data protection officer asks first

Before an app goes live you need to record the processing, assess the risk and answer the people whose data it holds. These are the answers we put in writing.

Where does the data live?

On your servers, or on dedicated machines in the Pilae Cloud region you choose: Zurich for Swiss data, five EU regions, or six worldwide regions if you need them. A change needs your written agreement.

Who else touches it?

The sub-processors listed in the DPA, each with its role and location. On premises, the hosting providers do not hold your application data.

Where are the backups?

Daily, encrypted before they leave the machine, and stored offsite in the country you chose. The storage provider holds data it cannot read.

What happens to logs?

Application logs stay on the machines that produced them. The console reads them on demand, so they are not gathered in a second location.

Is AI processing personal data?

Only where you enable it. AI features can run on a model hosted inside your own perimeter. An external AI provider is optional and off unless you switch it on.

Can we answer data subject requests?

Yes. You remain the controller. We help you find, export, correct or delete a person's data in the apps we run, in time for you to answer within the legal deadline.

Personal data you can point to

Every SaaS service adds a processor, a location and a set of sub-processors to your record of processing, and each one changes on the vendor’s schedule. When Pilae runs open-source apps for you, the answer to where data lives is the location written into your contract: your own servers, or dedicated machines in the region you chose. The data residency page describes each option. Two processors are easy to miss: web analytics and online surveys. Matomo and LimeSurvey keep visitor statistics and survey answers on the same machines, under the same agreement.

One agreement for both laws

Our data processing agreement covers the revised FADP and the GDPR in one document, with a security annex and the full sub-processor list. It is signed before any data is migrated. How it fits your wider obligations is set out on the Swiss nLPD and GDPR pages.

Minimal copies by design

Logs stay on the machines that produced them, and the console reads them only when someone opens them. Backups are encrypted before they leave the machine and stored in the country your data lives in, as described on the backups page. AI features run inside your perimeter unless you choose otherwise, which is how private AI works in practice.

At the end of the contract

Every plan includes a written exit plan. Your data comes back in open formats, and we then delete it from our machines and backups and confirm the deletion in writing.

How data protection is handled during onboarding

  1. DPA before any data moves

    You receive the standard DPA with its security annex and sub-processor list, or we review your own template. It is signed before migration starts.

  2. Location recorded

    The hosting location for each app is written into the contract, so your record of processing can name it.

  3. Information for your assessment

    We give you what your data protection impact assessment needs: data flows, security measures, sub-processors and retention.

  4. Return and deletion at the end

    When the contract ends, your data comes back in open formats under the exit plan, then we delete it from machines and backups.

What you get in writing

Data processing agreement
The standard DPA on every plan, covering the revised FADP and the GDPR. Your own template reviewed on request.
Sub-processor changes
Notified in advance, with a right to object before the change takes effect.
Breach notification
Reported without undue delay, with the facts you need for the FDPIC or your supervisory authority.
Audit rights
Included on every plan, with access to the audit trail for your auditors.
Return and deletion
Data returned in open formats under the written exit plan, then deleted from machines and backups.

The apps behind it

Questions

Is Pilae a processor or a controller?

For the apps we operate for you, Pilae is a processor acting on your instructions, and your organisation remains the controller. The DPA sets out that relationship.

Does any personal data leave Switzerland or the EU?

Your application data stays where your contract names. Some services, such as the network edge, operate globally. Where a transfer needs it, the DPA relies on standard contractual clauses or an adequacy decision.

Do Pilae engineers see our data?

Only when a task needs it, such as a restore or a migration. Access is by named engineers with least privilege, and every session is recorded in the audit trail.

Can we read the DPA before we sign?

Yes. Write to privacy@pilae.com and we send the standard DPA, the security annex and the sub-processor list.

How long are backups kept after deletion in an app?

Deleted data remains in backups until they expire under the retention period of your plan. The retention period is written into the contract, so your privacy notice can state it.

Related

Get the DPA to your desk.

Ask for the standard agreement, the security annex and the sub-processor list. We answer your questions in the same exchange.