Pilae as your processor under art. 28 of the GDPR
When Pilae operates your apps, we process personal data on your behalf. The GDPR calls your organisation the controller and Pilae the processor. Art. 28 says you may only use a processor that gives sufficient guarantees, bound by a written agreement that lists what it may do with the data.
Our data processing agreement is that agreement. It names the apps, the data, the purposes, the location and every sub-processor. It also covers the Swiss revised FADP, so an organisation with users in the EU and Switzerland signs one document. See the Swiss nLPD page for the Swiss side.
EU data residency, or Switzerland under an adequacy decision
You choose where each app runs. Pilae Cloud offers dedicated machines in 12 regions, six of them in Switzerland and the EU: Zurich, Frankfurt, Falkenstein, Gravelines, Amsterdam and Helsinki. They are hosted in ISO 27001-certified datacentres. Your data, backups and logs stay in the region you choose, with backups on a second site in the same jurisdiction. Data residency explains how the region is written into your contract.
Your own premises are also an option. The European Commission has recognised Switzerland as adequate since 2000 and confirmed it in January 2024, so data processed in Zurich needs no extra transfer tool. The six worldwide regions, London, Ashburn, Hillsboro, Singapore, Tokyo and Sydney, are there for teams that need them. If you place personal data in one of them, the transfer rules of chapter V apply: London benefits from an adequacy decision, and for the others the DPA attaches the standard contractual clauses. Where a sub-processor sits outside the EU and outside an adequate country, the DPA also attaches the standard contractual clauses adopted by the Commission in 2021.
Security of processing and breach notice
Art. 32 asks for security appropriate to the risk. Your apps answer only on a private network, run on hardened machines and are backed up daily, encrypted and offsite. Every change is planned, approved and recorded by the Pilae Agent, and every login and action lands in the audit log. The security page lists each control.
If a breach affects your data, we tell you without undue delay, with what happened, which data and people it touched, and what we have done. You then have what you need to notify your supervisory authority within the 72 hours art. 33 allows.
Data subject requests across every app
A person who asks for their data expects one answer, not one per system. Because your apps run on machines we operate, we can search the whole estate for a person’s records. We then export, correct or delete them on your instruction and record the result. Nextcloud, Keycloak and Open WebUI each export in open formats.
For a proposal covering your estate, see pricing or talk to us.