Legal

VNCprm Data Processing Agreement

VNClagoon · VNCprm
Version v1.0 · vnclagoon.com/VNCprm-data-processing
VNC – Virtual Network Consult AG, Poststrasse 24, CH-6302 Zug, Switzerland

This Data Processing Agreement (the "DPA") is published by VNC – Virtual Network Consult AG, Poststrasse 24, CH-6302 Zug, Switzerland ("VNC") and governs VNC's processing of personal data on behalf of each VNClagoon partner (the "Partner") in connection with VNCprm.

This DPA is governed by the Swiss Federal Act on Data Protection (nDSG), in force since 1 September 2023. For Partners or End Customers in the EEA, it is also intended to satisfy the processor requirements of Art. 28 GDPR. The Swiss Code of Obligations applies to the contractual relationship.

1. Scope and parties

1.1 This DPA governs VNC's processing of personal data on behalf of the Partner in connection with VNCprm. It supplements the Master Partner Contract or, where no Master Partner Contract exists, the Portal Agreement.

1.2 In case of conflict, the Master Partner Contract prevails on commercial terms. This DPA prevails on data-protection obligations.

1.3 Defined terms from the Master Partner Contract apply. Where no Master Partner Contract exists, defined terms from the Portal Agreement apply.

1.4 For Partner-entered data in VNCprm, the Partner is the data controller and VNC is the data processor. VNC processes its own partner-registration and portal-user data as an independent controller. That processing is outside the scope of this DPA.

2. Subject matter and nature of processing

2.1 VNC operates VNCprm for the Partner. In doing so, VNC processes personal data that the Partner enters into VNCprm, including customer and prospect contact data, deal data, pipeline records and communication records.

2.2 VNC processes this data solely to provide and maintain VNCprm for the Partner, and for no other purpose.

2.3 Processing includes storage, retrieval, organisation, transmission within VNCprm, backup and deletion, as required to operate the service.

3. Categories of data and data subjects

3.1 Data categories. Business contact information (name, email, phone, employer, role), deal and pipeline data, communication records, and any other data the Partner chooses to enter into VNCprm.

3.2 Data subjects. The Partner's customers, prospects and contacts.

3.3 Special-category data. The Partner shall not enter special-category data (Art. 5 nDSG / Art. 9 GDPR) into VNCprm without VNC's prior written agreement.

4. Instructions

4.1 VNC processes Partner-entered data only on the Partner's documented instructions.

4.2 The Master Partner Contract (or Portal Agreement) and this DPA constitute the Partner's initial processing instructions.

4.3 The Partner may issue further instructions in writing via the VNCprm user interface or by written notice to VNC.

4.4 VNC shall inform the Partner immediately if, in VNC's opinion, an instruction infringes applicable data-protection law.

5. Confidentiality

5.1 VNC ensures that persons authorised to process Partner-entered data are bound by confidentiality obligations.

5.2 VNC does not disclose Partner-entered data to third parties except as required by law or as permitted under clause 6 (subprocessors).

5.3 Where disclosure is legally required, VNC notifies the Partner in advance to the extent permitted by law.

6. Subprocessors

6.1 VNC may engage subprocessors (infrastructure providers, hosting services) to operate VNCprm.

6.2 VNC publishes its current subprocessor list at vnclagoon.com/subprocessors and notifies the Partner of any addition or replacement at least fourteen (14) days in advance.

6.3 The Partner may object to a new subprocessor on reasonable data-protection grounds within that period. If the Parties cannot agree, either Party may terminate the Master Partner Contract (or, where applicable, Portal access) on thirty (30) days' notice.

6.4 VNC remains fully responsible for each subprocessor's compliance with this DPA.

7. Technical and organisational measures

7.1 VNC implements and maintains appropriate technical and organisational security measures to protect Partner-entered data against accidental or unlawful loss, destruction, alteration, disclosure or access.

7.2 VNC may update the measures provided the overall level of protection is not reduced.

8. Data subject rights

8.1 VNC assists the Partner, at the Partner's request, in fulfilling data-subject requests (access, correction, deletion, portability, objection) relating to Partner-entered data, to the extent VNC has the technical ability to do so.

8.2 The Partner remains responsible for responding to data subjects.

9. Security incidents

9.1 VNC notifies the Partner within forty-eight (48) hours of becoming aware of a security incident affecting Partner-entered data.

9.2 The notification includes: the nature of the incident; the categories and approximate volume of data affected; the likely consequences; and the measures taken or proposed.

9.3 VNC cooperates with the Partner in managing the incident and fulfilling any notification obligations the Partner may have.

10. Data location and transfers

10.1 VNC stores and processes Partner-entered data in Switzerland or the EU/EEA.

10.2 Any transfer outside Switzerland or the EU/EEA requires appropriate safeguards (Swiss standard contractual clauses or EU SCCs, as applicable).

11. Audit

11.1 On the Partner's written request, VNC provides the Partner with information necessary to demonstrate compliance with this DPA, including the results of any third-party security audit (under confidentiality).

11.2 Where that information is insufficient, the Partner may conduct or commission an audit at the Partner's cost, with fourteen (14) days' advance written notice, no more than once per year absent cause, and subject to VNC's reasonable confidentiality and operational requirements.

12. Data portability and deletion

12.1 The Partner may export all Partner-entered data from VNCprm at any time using the export function. VNC may not condition this right on payment or resolution of any dispute.

12.2 On termination of the Master Partner Contract (or, where applicable, Portal access), VNC provides a complete data export within thirty (30) days.

12.3 VNC then deletes all Partner-entered personal data from its systems, unless retention is required by law, and confirms deletion in writing on request.

13. Secondary use prohibited

13.1 VNC does not use Partner-entered data for any purpose beyond operating VNCprm for the Partner.

13.2 Prohibited secondary uses include: AI model training, analytics, benchmarking, competitive intelligence, and direct marketing.

13.3 VNC may use genuinely anonymised, non-attributable, aggregated platform-usage data for product improvement and security analytics. That use does not constitute processing of personal data under this DPA.

14. Partner obligations as controller

14.1 The Partner: (a) has a lawful basis for entering customer and prospect data into VNCprm; (b) has informed its customers and prospects that their data is processed in VNCprm; (c) does not enter special-category data without VNC's written agreement; (d) complies with applicable data-protection law in its jurisdiction; and (e) ensures its own customers' data-protection rights are respected.

15. Governing law

15.1 This DPA is governed by Swiss law, excluding the CISG.

15.2 Disputes are subject to the exclusive jurisdiction of the courts of Zug, Switzerland, as set out in the Master Partner Contract.

15.3 For EEA Partners, this DPA is intended to satisfy the requirements of GDPR Art. 28.

16. Updates

16.1 VNC may update this DPA to reflect changes in applicable law or processing activities, giving thirty (30) days' advance notice via the Partner Portal or email.

16.2 Continued use of VNCprm after that period constitutes acceptance.

16.3 Material changes that reduce the Partner's data-protection rights require the Partner's written consent.

Published at vnclagoon.com/VNCprm-data-processing. No separate signature is required.

Version v1.0