One agreement for the revised FADP and the GDPR
When Pilae operates your apps, we process personal data on your behalf. Swiss law (art. 9 of the revised FADP) and European law (art. 28 of the GDPR) both require a written agreement for that. Our standard DPA covers both, so an organisation with users in Switzerland and the EU signs one document. How it fits your wider obligations is on the Swiss nLPD page.
The DPA is available on request before you sign and is signed at onboarding, before any data is migrated. Where a sub-processor sits outside Switzerland and the EU, the agreement relies on standard contractual clauses or on an adequacy decision for that country.
Where your data is processed
On your own premises, your application data stays on your servers and no hosting provider holds it. In Pilae Cloud, your data sits on dedicated machines in ISO 27001-certified datacentres in the region you chose. Pilae Cloud has 12 regions, six of them in Switzerland and the EU. Details of each region are on the regions page and the data residency page.
Every sub-processor for your service is named in your signed DPA, with what it does and where. We notify you in advance of any addition or replacement, and you can object before it takes effect.