Processor obligations under art. 9 of the nLPD
The revised Federal Act on Data Protection makes your organisation answerable for the personal data it processes. When your apps run with Pilae, part of that processing happens on our machines or under our hands. The Act calls us your processor, and art. 9 says you may only hand work to a processor who guarantees data security and follows your instructions.
That guarantee is written into a signed agreement. Our data processing agreement names the data, the purposes, the location and every sub-processor. It is signed at onboarding, before your first app is migrated.
Data security under art. 8 of the nLPD
Art. 8 asks for security appropriate to the risk. Our answer is concrete. Each app answers only on a private network, with one hardened gate on port 443. Every change is planned, approved and recorded by the Pilae Agent. Your contract specifies encrypted backups and scheduled restore tests. The details are on the security page and in the measures annex of your DPA.
Data location and cross-border transfers
You decide where your data lives: on your own servers, or on dedicated machines in Pilae Cloud in Zurich or an EU region, with six worldwide regions for teams that need them. The location is written into your contract. We do not move data across a border without your written agreement, and any transfer outside Switzerland and the EU follows art. 16 and art. 17. See data residency for the regions.