Auftragsdatenbearbeitung (AVV)
Die Vereinbarung zur Auftragsbearbeitung regelt die Rechte und Pflichten von Kunde und FortIT bei der Bearbeitung von Personendaten in fortControl, einschliesslich der eingesetzten Unter-Auftragsbearbeiter.
Die Vereinbarung zur Auftragsbearbeitung regelt die Rechte und Pflichten von Kunde und FortIT bei der Bearbeitung von Personendaten in fortControl, einschliesslich der eingesetzten Unter-Auftragsbearbeiter.
1.1.1. Diese Vereinbarung zur Auftragsbearbeitung («Zusatz» oder «AVV») konkretisiert die Rechte und Pflichten der Parteien in Bezug auf die Auftragsbearbeitung, die sich für sie aus dem anwendbaren Datenschutzrecht ergeben. Sie ergänzt den Nutzungsvertrag zwischen der FortIT AG, Badenerstrasse 281, 8003 Zürich («FortIT»), und dem Kunden in Bezug auf die Bereitstellung der Plattform fortControl (FORTCONTROL) für den Kunden («Vertrag»). Der Vertrag umfasst insbesondere die Nutzungsbestimmungen, abrufbar unter https://www.fortcontrol.swiss/nutzungsbedingungen/, sowie die Offerte bzw. den separat unterzeichneten Vertrag.
1.1.2. Dieser Zusatz gilt nur in Bezug auf Dienstleistungen, bei denen FortIT Personendaten im Auftrag und für Zwecke des Kunden bearbeitet («Auftragsbearbeitung»), wobei der Kunde entweder Verantwortlicher oder Auftragsbearbeiter und FortIT entweder Auftragsbearbeiterin oder Unter-Auftragsbearbeiterin ist.
1.1.3. Dieser Zusatz ist ein integraler Bestandteil des Vertrags. Die Bestimmungen dieses Zusatzes schränken die Rechte und Pflichten der Parteien in Bezug auf die Erbringung der Dienstleistungen unter dem Vertrag nicht ein. Ihren Regelungsgegenstand betreffend gehen die Bestimmungen dieses Zusatzes indes den Bestimmungen des Vertrags vor.
1.1.4. Ist der Kunde ein öffentliches Organ (z.B. Kanton, Gemeinde, öffentlich-rechtliche Anstalt oder Körperschaft), das dem Datenschutzrecht des Bundes, eines Kantons oder einer Gemeinde untersteht, gelten ergänzend die besonderen Bestimmungen in Ziffer 3. Bei Widersprüchen gehen die Bestimmungen in Ziffer 3 den übrigen Bestimmungen dieses Zusatzes vor.
1.2.1. Die Laufzeit dieses Zusatzes entspricht der Dauer des Vertrags, sofern sich aus den Bestimmungen dieses Zusatzes keine zeitlich darüber hinausgehenden Verpflichtungen ergeben. Bei solchen überdauernden Verpflichtungen besteht dieser Zusatz so lange fort, bis die entsprechenden Verpflichtungen erloschen sind.
1.2.2. Durch diese Regelung modifizieren die Parteien nicht die im Vertrag vereinbarten Kündigungsrechte.
1.3.1. Die in diesem Zusatz in Anführungs- und Schlusszeichen gesetzten Begriffe haben im gesamten Zusatz die ihnen darin zugeschriebene Bedeutung.
1.3.2. Die in diesem Zusatz verwendeten datenschutzbezogenen Begriffe wie «Personendaten» (personenbezogene Daten), «betroffene Person», «Verantwortlicher», «Auftragsbearbeiter», «Verletzung der Datensicherheit» oder «Datenschutz-Folgenabschätzung» haben die ihnen im Schweizer Datenschutzgesetz (DSG) bzw. (wo anwendbar) in der EU-Datenschutz-Grundverordnung (DSGVO) oder im anwendbaren kantonalen Datenschutzrecht zugeschriebene Bedeutung.
1.3.3. «Standard-Bereitstellung» bezeichnet die Bereitstellung von FORTCONTROL auf der in Ziffer 2.7.2 Tabelle A beschriebenen Cloud-Infrastruktur mit Datenstandort Schweiz. «Swiss Deployment Option» bezeichnet die Bereitstellung von FORTCONTROL auf der in Ziffer 2.7.2 Tabelle B beschriebenen Infrastruktur, bei der Infrastruktur, Betrieb und E-Mail-Versand ausschliesslich in der Schweiz durch Anbieter mit Sitz in der Schweiz erfolgen. Die für den Kunden geltende Bereitstellungsvariante ergibt sich aus dem Vertrag; ohne ausdrückliche Vereinbarung gilt die Standard-Bereitstellung.
2.1.1. Gegenstand und Zweck der Auftragsbearbeitung ist die Bereitstellung von FORTCONTROL in Form einer Software als Dienstleistung (SaaS) für den Kunden, einschliesslich der damit verbundenen Leistungen wie Betrieb, Wartung, Support und Datensicherung sowie – sofern vom Kunden aktiviert – optionaler KI-Funktionen gemäss Ziffer 3.7 der Nutzungsbestimmungen.
2.1.2. Die Auftragsbearbeitung betrifft die vom Kunden oder dessen Nutzern bei der Nutzung von FORTCONTROL hochgeladenen, eingegebenen, bereitgestellten, gespeicherten oder bearbeiteten Arten von Personendaten («vertragsgegenständliche Personendaten»). Dazu gehören typischerweise Angaben zu Nutzern (Name, E-Mail-Adresse, Rolle), zu Mitarbeitenden und Kontaktpersonen des Kunden sowie zu weiteren Personen, die in Schutzobjekten, Risiken, Massnahmen, Audits oder Dokumenten des Kunden genannt werden. Details zu den vertragsgegenständlichen Personendaten und zum Kreis (Kategorien) betroffener Personen ergeben sich aus dem Vertrag und den Leistungsbeschreibungen in Verbindung mit allfälligen separaten Weisungen des Kunden.
2.1.3. Die Auftragsbearbeitung besteht in der Speicherung, Bereitstellung, Sicherung und Anzeige der vertragsgegenständlichen Personendaten bei der Erbringung der SaaS-Leistungen für den Kunden sowie im Zugriff auf diese Daten, soweit dies für Support, Fehlerbehebung und Wartung erforderlich ist und vom Kunden veranlasst wurde. Bei vom Kunden aktivierten KI-Funktionen umfasst die Bearbeitung zusätzlich die Übermittlung der vom Nutzer ausgewählten Inhalte an den KI-Anbieter gemäss Ziffer 2.7.2 Tabelle C zur automatisierten Analyse und Erzeugung von Vorschlägen. Die Übermittlung erfolgt nur für die jeweilige Anfrage; eine Speicherung beim KI-Anbieter über eine allfällige kurzzeitige Missbrauchskontrolle hinaus und eine Verwendung zum Training von KI-Modellen sind vertraglich ausgeschlossen.
2.1.4. Der Ort der Auftragsbearbeitung bestimmt sich nach der vereinbarten Bereitstellungsvariante: (a) Bei der Standard-Bereitstellung erfolgt die Speicherung der vertragsgegenständlichen Personendaten in der Schweiz; einzelne Unter-Auftragsbearbeiter können Daten im Rahmen von Support-, Wartungs- oder Versandleistungen in Staaten der EU/des EWR oder in den USA bearbeiten. (b) Bei der Swiss Deployment Option erfolgen Speicherung, Betrieb und E-Mail-Versand ausschliesslich in der Schweiz durch Anbieter mit Sitz in der Schweiz; eine Bearbeitung ausserhalb der Schweiz findet ohne ausdrückliche schriftliche Zustimmung des Kunden nicht statt. Einzige Ausnahme sind die optionalen KI-Funktionen: Aktiviert ein Administrator des Kunden diese, werden die dafür ausgewählten Inhalte in beiden Bereitstellungsvarianten durch den in Ziffer 2.7.2 Tabelle C genannten KI-Anbieter in der EU (Frankreich) bearbeitet – nur für die jeweilige Anfrage und ohne Training mit Kundendaten; die Aktivierung gilt als ausdrückliche Zustimmung und Weisung des Kunden zu dieser Bearbeitung.
2.1.5. Die Dauer der Bearbeitung bestimmt sich nach Ziffer 1.2.
2.2.1. FortIT verpflichtet sich und sichert zu, dass FortIT alle vertragsgegenständlichen Personendaten (i) ausschliesslich zu den in Ziffer 2.1 beschriebenen Zwecken, (ii) in Übereinstimmung mit dem Vertrag und den dokumentierten Weisungen des Kunden sowie (iii) in Übereinstimmung mit diesem Zusatz bearbeitet und (iv) darüber hinaus nicht für eigene Zwecke verwendet.
2.2.2. Weisungen des Kunden erfolgen schriftlich oder in Textform (z.B. E-Mail, Support-Ticket) an FortIT. Ist FortIT der Ansicht, dass eine Weisung gegen anwendbares Datenschutzrecht verstösst, informiert FortIT den Kunden unverzüglich und ist berechtigt, die Ausführung der Weisung bis zu deren Bestätigung oder Änderung durch den Kunden auszusetzen.
2.2.3. Der Kunde bleibt für die Rechtmässigkeit der Bearbeitung der vertragsgegenständlichen Personendaten, insbesondere für das Vorliegen einer Rechtsgrundlage und die Wahrung der Betroffenenrechte, verantwortlich.
2.3.1. FortIT verpflichtet sich, im Interesse der Vertraulichkeit, Integrität und vertragsgemässen Verfügbarkeit der vertragsgegenständlichen Personendaten angemessene technische und organisatorische Schutzmassnahmen zu treffen.
2.3.2. FortIT implementiert hierzu insbesondere Zugangskontrollen, Zugriffskontrollen auf Basis von Rollen und dem Need-to-know-Prinzip, Verschlüsselung der Datenübertragung und der gespeicherten Daten, Protokollierung, regelmässige Datensicherungen sowie Verfahren zur regelmässigen Überprüfung, Bewertung und Evaluierung der Wirksamkeit der technischen und organisatorischen Massnahmen. Bei der Auswahl der Massnahmen berücksichtigt FortIT den Stand der Technik, die Implementierungskosten sowie die Art, den Umfang, die Umstände und die Zwecke der Bearbeitung sowie die unterschiedliche Eintrittswahrscheinlichkeit und Schwere des Risikos für betroffene Personen.
2.3.3. Die aktuelle Beschreibung der technischen und organisatorischen Massnahmen (TOM) ist unter https://www.fortcontrol.swiss/tom/ abrufbar und bildet Anhang zu diesem Zusatz; FortIT stellt sie dem Kunden auf Anfrage auch schriftlich zur Verfügung. FortIT kann die Massnahmen weiterentwickeln, sofern das vereinbarte Schutzniveau nicht unterschritten wird.
2.4.1. Wenn FortIT eine Verletzung der Sicherheit bemerkt, die darin besteht, dass vertragsgegenständliche Personendaten unbeabsichtigt oder widerrechtlich verloren gehen, gelöscht, vernichtet oder verändert werden oder Unbefugten offengelegt oder zugänglich gemacht werden («Verletzung der Datensicherheit»), wird FortIT die Verletzung der Datensicherheit so rasch als möglich und ohne schuldhaftes Zögern, in der Regel innert 48 Stunden nach Kenntnisnahme, dem Kunden melden. FortIT wird die Verletzung der Datensicherheit sodann (i) untersuchen und die Auswirkungen ermitteln, (ii) den Kunden detailliert über die Verletzung der Datensicherheit informieren, (iii) angemessene Massnahmen ergreifen, um die Auswirkungen zu mildern und das Risiko, das sich aus der Verletzung der Datensicherheit für betroffene Personen möglicherweise ergibt, so gering wie möglich zu halten, und (iv) den Vorfall dokumentieren.
2.4.2. FortIT wird den Kunden in angemessener Weise dabei unterstützen, seinen Verpflichtungen zur Meldung von Verletzungen der Datensicherheit an zuständige Aufsichtsbehörden oder an betroffene Personen nachzukommen.
2.5.1. FortIT verpflichtet sich, den Kunden so rasch als möglich und von sich aus zu informieren, (i) wenn FortIT der Ansicht ist, dass FortIT in absehbarer Zeit nicht mehr in der Lage ist, den Pflichten gemäss diesem Zusatz nachzukommen; (ii) über jede Anfrage zur Ausübung von Betroffenenrechten, welche FortIT direkt von betroffenen Personen in Bezug auf vertragsgegenständliche Personendaten erhalten hat (vorausgesetzt, FortIT kann eine Zuordnung an den Kunden gestützt auf die Angaben der betroffenen Person vornehmen; andernfalls wird FortIT die betroffene Person bitten, sich an den für die Datenbearbeitung Verantwortlichen zu wenden); sowie (iii) über Anfragen oder Anordnungen von Behörden oder Gerichten, die vertragsgegenständliche Personendaten betreffen, soweit eine solche Information rechtlich zulässig ist.
2.5.2. FortIT wird den Kunden auf Anfrage und gegen separate Vergütung bei der Beantwortung von Anfragen betroffener Personen zur Ausübung datenschutzrechtlicher Betroffenenrechte unterstützen.
2.5.3. Zudem wird FortIT den Kunden auf Anfrage und gegen separate Vergütung bei Datenschutz-Folgenabschätzungen und vorherigen Konsultationen von Datenschutzaufsichtsbehörden unterstützen.
2.5.4. FortIT stellt dem Kunden alle Informationen zur Verfügung, welche dieser vernünftigerweise für den Nachweis der Einhaltung seiner Verpflichtungen aus dem anwendbaren Datenschutzrecht in Bezug auf die Auftragsbearbeitung benötigt.
2.6.1. FortIT verpflichtet sich zur Geheimhaltung der vertragsgegenständlichen Personendaten und hat die mit der Auftragsbearbeitung betrauten Personen schriftlich zur Wahrung der Vertraulichkeit zu verpflichten und über die anwendbaren datenschutzrechtlichen Pflichten zu instruieren.
2.6.2. Diese Geheimhaltungsverpflichtungen gelten nach Beendigung des Vertrags für unbeschränkte Dauer weiter.
2.7.1. Unter-Auftragsbearbeiter sind natürliche oder juristische Personen, welche FortIT für die Auftragsbearbeitung beizieht. FortIT ist berechtigt, Unter-Auftragsbearbeiter beizuziehen. FortIT ist in solchen Fällen verpflichtet, mit Unter-Auftragsbearbeitern eine Vereinbarung über die (Unter-)Auftragsbearbeitung zu treffen, die FortIT die Einhaltung der Bestimmungen des vorliegenden Zusatzes ermöglicht, einschliesslich der Geheimhaltungspflichten von FortIT. Bei Anbietern standardisierter Dienste (insbesondere Cloud-, Infrastruktur- und Plattformanbieter) kann FortIT keine individuellen Verträge aushandeln; massgebend sind deren standardisierte Vereinbarungen zur Auftragsbearbeitung. FortIT stellt in diesen Fällen sicher, dass die technischen und organisatorischen Massnahmen, Grundschutzmassnahmen oder sonstigen Vorgaben des Unter-Auftragsbearbeiters ein mindestens gleichwertiges Schutzniveau wie die TOM gewährleisten. FortIT bleibt gegenüber dem Kunden für die Leistungen der Unter-Auftragsbearbeiter wie für eigene Leistungen verantwortlich.
2.7.2. FortIT setzt je nach vereinbarter Bereitstellungsvariante die folgenden Unter-Auftragsbearbeiter ein. Die Unter-Auftragsbearbeiter gemäss Tabelle C werden nur beigezogen, wenn ein Administrator des Kunden die KI-Funktionen gemäss Ziffer 3.7 der Nutzungsbestimmungen aktiviert hat; ohne Aktivierung findet keine Bekanntgabe vertragsgegenständlicher Personendaten an diese Unter-Auftragsbearbeiter statt. Tabelle C gilt für beide Bereitstellungsvarianten: Auch bei der Swiss Deployment Option erfolgt die Bearbeitung durch den KI-Anbieter in der EU (Frankreich), nur für die jeweilige Anfrage und ohne Training mit Kundendaten. Die KI-Funktionen setzen deshalb in jedem Fall die ausdrückliche Aktivierung durch einen Administrator des Kunden voraus. Es gelten die folgenden Tabellen:
Tabelle A – Standard-Bereitstellung
| Name | Bearbeitungsland | Beschrieb |
|---|---|---|
| Microsoft Azure (Microsoft Ireland Operations Limited, Irland) | Schweiz (Datenstandort) | Infrastrukturanbieterin, Application Hosting, Datenspeicher, Datenverarbeitung |
| MongoDB Atlas (MongoDB Limited, Irland) | Schweiz (Datenstandort) | Datenbank und Datenspeicher |
| SendGrid (Twilio Ireland Limited, Irland) | EU | Versand von E-Mail-Benachrichtigungen |
Tabelle B – Swiss Deployment Option
| Name | Bearbeitungsland | Beschrieb |
|---|---|---|
| cloudscale.ch AG, Neugasse 6, 8005 Zürich | Schweiz | Infrastrukturanbieterin (Cloud-Infrastruktur, Rechenzentren ausschliesslich in der Schweiz), Datenspeicher |
| [to be announced] | Schweiz | Bereitstellung und Betrieb von Managed Services (Plattformbetrieb, Datenbank, Datensicherung, Monitoring) |
| mailomat (mailXpert GmbH, Schulstrasse 37, 8050 Zürich) | Schweiz | Versand von E-Mail-Benachrichtigungen |
Tabelle C – Optionale KI-Funktionen (nur bei Aktivierung durch den Kunden)
| Name | Bearbeitungsland | Beschrieb |
|---|---|---|
| Mistral AI, SAS, 15 rue des Halles, 75001 Paris, Frankreich | EU (Frankreich) | Betrieb der KI-Sprachmodelle für die KI-Funktionen von FORTCONTROL; Bearbeitung nur für die jeweilige Anfrage, kein Training mit Kundendaten |
2.7.3. FortIT wird den Kunden frühzeitig vorab in geeigneter Weise schriftlich informieren, wenn FortIT nach Inkrafttreten des Vertrags beabsichtigt, neue Unter-Auftragsbearbeiter beizuziehen oder bestehende auszutauschen. Wenn der Kunde dem Beizug bzw. Austausch des Unter-Auftragsbearbeiters nicht innerhalb von dreissig (30) Tagen nach dem Datum der Mitteilung schriftlich widerspricht, gilt der neue oder ausgetauschte Unter-Auftragsbearbeiter als genehmigt. Widerspricht der Kunde aus begründetem datenschutzrechtlichem Anlass, bemühen sich die Parteien um eine einvernehmliche Lösung; kommt eine solche nicht zustande, kann jede Partei den Vertrag hinsichtlich der betroffenen Leistung auf den Zeitpunkt des vorgesehenen Beizugs kündigen.
2.7.4. Die jeweils aktuelle Liste der Unter-Auftragsbearbeiter ist unter https://www.fortcontrol.swiss/avv/ abrufbar.
2.7.5. Setzt der Kunde eigene KI-Agenten oder andere Systeme ein, die über die Schnittstellen von FORTCONTROL auf vertragsgegenständliche Personendaten zugreifen (Ziffer 3.12 der Nutzungsbestimmungen), so handelt es sich nicht um Unter-Auftragsbearbeiter von FortIT. Der Kunde ist für diese Systeme, deren Anbieter und die dortige Datenbearbeitung allein verantwortlich und schliesst erforderliche Vereinbarungen zur Auftragsbearbeitung selbst ab.
2.8.1. Der Kunde ist berechtigt, die Einhaltung dieses Zusatzes durch FortIT zu überprüfen. FortIT erbringt den Nachweis in erster Linie durch die Bereitstellung geeigneter Unterlagen, insbesondere der Beschreibung der technischen und organisatorischen Massnahmen, von Prüfberichten, Zertifizierungen oder Bestätigungen ihrer Unter-Auftragsbearbeiter sowie durch die Beantwortung schriftlicher Fragen des Kunden.
2.8.2. Soweit diese Nachweise für den Kunden nachweislich nicht ausreichen oder eine Aufsichtsbehörde dies verlangt, kann der Kunde höchstens einmal pro Kalenderjahr sowie zusätzlich bei begründetem Anlass (insbesondere nach einer Verletzung der Datensicherheit) eine Überprüfung bei FortIT durchführen oder durch eine zur Vertraulichkeit verpflichtete, unabhängige Fachperson durchführen lassen. Die Überprüfung ist mindestens dreissig (30) Tage im Voraus schriftlich anzukündigen, während der üblichen Geschäftszeiten durchzuführen und so zu gestalten, dass der Geschäftsbetrieb von FortIT und die Vertraulichkeit der Daten anderer Kunden nicht beeinträchtigt werden. Den durch die Überprüfung bei FortIT entstehenden Aufwand trägt der Kunde; er wird nach Aufwand zu CHF 230 pro Stunde (exkl. MWST) vergütet, sofern die Überprüfung keine wesentlichen Verletzungen dieses Zusatzes aufzeigt.
2.9.1. FortIT wird die vertragsgegenständlichen Personendaten nach Beendigung des Vertrags nach Massgabe der diesbezüglichen Bestimmungen im Vertrag löschen oder, wenn der Kunde dies wünscht, in einem gängigen, maschinenlesbaren Format an den Kunden zurückgeben. Soweit der Vertrag nichts anderes bestimmt, werden die Daten 90 Tage nach Beendigung des Vertrags unwiderruflich gelöscht; der Kunde kann innerhalb dieser Frist die Rückgabe verlangen. Gesetzliche Aufbewahrungspflichten von FortIT bleiben vorbehalten. FortIT bestätigt dem Kunden die Löschung auf Anfrage schriftlich.
3.1.1. Die Bestimmungen dieser Ziffer 3 gelten, wenn der Kunde ein öffentliches Organ ist, das dem Datenschutzrecht eines Kantons oder einer Gemeinde oder dem Datenschutzrecht des Bundes untersteht. Sie konkretisieren die Mindestinhalte, welche das anwendbare öffentlich-rechtliche Datenschutzrecht für Vereinbarungen über die Auftragsbearbeitung vorschreibt, und ergänzen die übrigen Bestimmungen dieses Zusatzes.
3.2.1. Gegenstand, Art, Umfang und Zweck der Auftragsbearbeitung sowie die Kategorien der vertragsgegenständlichen Personendaten und betroffenen Personen ergeben sich aus Ziffer 2.1 und dem Vertrag. Der Kunde kann diese Angaben in einer Leistungsbeschreibung oder in schriftlichen Weisungen präzisieren.
3.2.2. Der Kunde bleibt als verantwortliches Organ für die Rechtmässigkeit der Datenbearbeitung, die Wahrung der Rechte der betroffenen Personen und die Erfüllung seiner gesetzlichen Informations- und Meldepflichten verantwortlich. FortIT bearbeitet die vertragsgegenständlichen Personendaten ausschliesslich im Auftrag und nach den Weisungen des Kunden und nur so, wie es der Kunde selbst tun dürfte.
3.3.1. FortIT nimmt zur Kenntnis, dass die vertragsgegenständlichen Personendaten dem Amtsgeheimnis sowie allenfalls weiteren besonderen gesetzlichen Geheimhaltungspflichten (z.B. Steuergeheimnis, Sozialhilfegeheimnis, Berufsgeheimnis) unterstehen können. FortIT verpflichtet sich, das Amtsgeheimnis und diese besonderen Geheimhaltungspflichten im gleichen Umfang zu wahren, wie sie für den Kunden und dessen Mitarbeitende gelten, und ist sich bewusst, dass Verletzungen des Amtsgeheimnisses gemäss Art. 320 des Schweizerischen Strafgesetzbuchs strafbar sein können.
3.3.2. FortIT verpflichtet alle Mitarbeitenden und Hilfspersonen, die Zugang zu vertragsgegenständlichen Personendaten haben können, vor Aufnahme ihrer Tätigkeit schriftlich auf das Amtsgeheimnis und die besonderen Geheimhaltungspflichten und weist den Kunden auf Anfrage über diese Verpflichtungen nach.
3.3.3. Der Zugriff auf vertragsgegenständliche Personendaten ist auf diejenigen Mitarbeitenden von FortIT beschränkt, die ihn zur Erfüllung des Vertrags zwingend benötigen. Die Geheimhaltungspflichten gelten über das Ende des Vertrags hinaus für unbeschränkte Dauer.
3.4.1. Für öffentliche Organe empfiehlt FortIT die Swiss Deployment Option. Ist diese vereinbart, erfolgen sämtliche Bearbeitungen der vertragsgegenständlichen Personendaten, einschliesslich Datensicherung, Betrieb, Support und E-Mail-Versand, ausschliesslich in der Schweiz durch Unter-Auftragsbearbeiter mit Sitz in der Schweiz gemäss Ziffer 2.7.2 Tabelle B. Eine Bekanntgabe ins Ausland findet nicht statt.
3.4.2. Ist die Standard-Bereitstellung vereinbart, erfolgt die Speicherung der vertragsgegenständlichen Personendaten in der Schweiz; der Kunde nimmt zur Kenntnis, dass einzelne Unter-Auftragsbearbeiter gemäss Ziffer 2.7.2 Tabelle A im Rahmen von Support- und Wartungsleistungen aus dem Ausland auf Daten zugreifen können. Jede weitere Verlagerung des Bearbeitungsorts ins Ausland bedarf der vorgängigen schriftlichen Zustimmung des Kunden.
3.4.3. KI-Funktionen gemäss Ziffer 2.7.2 Tabelle C dürfen bei Kunden gemäss dieser Ziffer 3 nur aktiviert werden, wenn der Kunde die Bekanntgabe an den KI-Anbieter in der EU (Frankreich) nach den für ihn geltenden Vorschriften geprüft und schriftlich genehmigt hat; dies gilt auch bei der Swiss Deployment Option. Ziffer 3.6.1 bleibt vorbehalten. Die Aktivierung durch einen Administrator des Kunden gilt als Bestätigung, dass diese Voraussetzungen erfüllt sind.
3.5.1. Ergänzend zu Ziffer 2.8 räumt FortIT dem Kunden sowie der für den Kunden zuständigen Datenschutzaufsichtsbehörde das Recht ein, die Einhaltung der datenschutzrechtlichen Vorgaben und dieses Zusatzes zu kontrollieren. FortIT gewährt hierzu nach angemessener Vorankündigung Zugang zu den relevanten Unterlagen, Systemen und Räumlichkeiten, soweit dies für die Kontrolle erforderlich ist, und erteilt die notwendigen Auskünfte. Der FortIT durch solche Kontrollen entstehende Aufwand für Vorbereitung, Begleitung und Nachbearbeitung wird vom Kunden nach Aufwand zu CHF 230 pro Stunde (exkl. MWST) vergütet; dies gilt auch für Kontrollen der Datenschutzaufsichtsbehörde, sofern die Kontrolle keine wesentlichen Verletzungen dieses Zusatzes aufzeigt.
3.5.2. FortIT informiert den Kunden unverzüglich über Kontrollen von Aufsichtsbehörden, die die Auftragsbearbeitung für den Kunden betreffen, soweit dies rechtlich zulässig ist.
3.6.1. Abweichend von Ziffer 2.7.3 bedarf der Beizug oder Austausch eines Unter-Auftragsbearbeiters bei Kunden gemäss dieser Ziffer 3 der vorgängigen schriftlichen Zustimmung des Kunden. Die in Ziffer 2.7.2 aufgeführten Unter-Auftragsbearbeiter der vereinbarten Bereitstellungsvariante gelten mit Abschluss des Vertrags als genehmigt. Der Kunde verweigert die Zustimmung nur aus sachlichen, datenschutzrechtlichen Gründen.
3.6.2. FortIT stellt sicher, dass ihre Unter-Auftragsbearbeiter Pflichten unterstehen, die den Pflichten aus diesem Zusatz, einschliesslich der Geheimhaltung, mindestens gleichwertig sind. Bei Anbietern standardisierter Dienste gemäss Ziffer 2.7.1 kann FortIT keine individuellen Verträge abschliessen; FortIT stellt in diesen Fällen sicher, dass deren technische und organisatorische Massnahmen, Grundschutzmassnahmen oder sonstige Vorgaben ein mindestens gleichwertiges Schutzniveau wie die TOM gewährleisten. FortIT bleibt gegenüber dem Kunden für die Einhaltung durch ihre Unter-Auftragsbearbeiter verantwortlich.
3.7.1. Verletzt FortIT schuldhaft eine wesentliche Pflicht aus diesem Zusatz, insbesondere die Pflichten zur Weisungsgebundenheit (Ziffer 2.2), zur Datensicherheit (Ziffer 2.3), zur Geheimhaltung und Wahrung des Amtsgeheimnisses (Ziffern 2.6 und 3.3), zum Ort der Datenbearbeitung (Ziffer 3.4) oder zum Beizug Dritter (Ziffer 3.6), schuldet FortIT dem Kunden pro Verletzungsfall eine Konventionalstrafe in der Höhe von 10 Prozent der für das laufende Vertragsjahr geschuldeten Nutzungsgebühren. Die Bezahlung der Konventionalstrafe befreit FortIT nicht von der Erfüllung ihrer Pflichten. Die Geltendmachung eines weitergehenden Schadens bleibt vorbehalten; die Konventionalstrafe wird auf den Schadenersatz angerechnet.
3.7.2. Bei einer wesentlichen Pflichtverletzung ist der Kunde zudem berechtigt, den Vertrag mit sofortiger Wirkung und ohne Kostenfolge zu kündigen. Bereits im Voraus bezahlte Gebühren für die Zeit nach der Kündigung werden anteilig zurückerstattet. Bei anderen Pflichtverletzungen setzt der Kunde FortIT eine angemessene Frist zur Behebung; bleibt diese ungenutzt, kann er den Vertrag ebenfalls mit sofortiger Wirkung kündigen.
3.7.3. Der Kunde kann FortIT zudem anweisen, die Bearbeitung der vertragsgegenständlichen Personendaten ganz oder teilweise einzustellen, bis die Pflichtverletzung behoben ist. Die Rechte und Pflichten bei Vertragsende gemäss Ziffer 3.8 gelten auch bei einer Kündigung nach dieser Ziffer.
3.8.1. Die Dauer dieses Zusatzes bestimmt sich nach Ziffer 1.2. Bei Beendigung des Vertrags, unabhängig vom Beendigungsgrund, gibt FortIT dem Kunden auf dessen Wunsch sämtliche vertragsgegenständlichen Personendaten innert dreissig (30) Tagen in einem gängigen, maschinenlesbaren Format zurück und löscht anschliessend, spätestens jedoch neunzig (90) Tage nach Beendigung, sämtliche bei ihr und ihren Unter-Auftragsbearbeitern vorhandenen Kopien, sofern keine gesetzliche Aufbewahrungspflicht entgegensteht. Kopien in Datensicherungen werden im Rahmen der regulären Aufbewahrungs- und Löschzyklen von FortIT und ihrer Unter-Auftragsbearbeiter gemäss Ziffer 6.2 TOM überschrieben; bis dahin werden sie nicht wiederhergestellt und nicht weiterbearbeitet. FortIT bestätigt dem Kunden die vollständige Löschung schriftlich.
3.9.1. Auf diesen Zusatz ist schweizerisches Recht anwendbar. Die datenschutzrechtlichen Pflichten von FortIT richten sich zusätzlich nach dem für den Kunden geltenden öffentlich-rechtlichen Datenschutzrecht, soweit dieses zwingend auf Auftragsbearbeiter anwendbar ist. Gerichtsstand ist der Sitz des Kunden, sofern der Vertrag nichts anderes bestimmt.
4.1. Änderungen und Ergänzungen dieses Zusatzes bedürfen der Schriftform. FortIT kann diesen Zusatz anpassen, wenn dies aufgrund geänderter gesetzlicher Vorgaben oder geänderter Unter-Auftragsbearbeiter erforderlich ist; FortIT informiert den Kunden darüber schriftlich und im Voraus. Es gilt jeweils die unter https://www.fortcontrol.swiss/avv/ abrufbare Version, sofern die Parteien nichts anderes vereinbart haben.
4.2. Sollte eine Bestimmung dieses Zusatzes unwirksam oder undurchführbar sein oder werden, so wird die Wirksamkeit der übrigen Bestimmungen davon nicht berührt. Die Parteien ersetzen die unwirksame Bestimmung durch eine wirksame, die dem Zweck der unwirksamen Bestimmung möglichst nahekommt.
4.3. Auf diesen Zusatz ist schweizerisches Recht anwendbar. Gerichtsstand ist Zürich, Schweiz, soweit nicht Ziffer 3.9 oder zwingende gesetzliche Bestimmungen etwas anderes vorsehen.
4.4. Dieser Zusatz ist in deutscher Sprache verfasst. Übersetzungen dienen nur der Information; bei Abweichungen ist die deutsche Fassung massgebend.
1.1.1. This Data Processing Agreement ("Addendum" or "DPA") specifies the rights and obligations of the parties with regard to processing on behalf of the customer arising for them under the applicable data protection law. It supplements the user agreement between FortIT AG, Badenerstrasse 281, 8003 Zurich ("FortIT"), and the customer regarding the provision of the fortControl platform (FORTCONTROL) to the customer ("Contract"). The Contract comprises in particular the Terms of Use, available at https://www.fortcontrol.swiss/nutzungsbedingungen/, and the offer or the separately signed contract.
1.1.2. This Addendum applies only to services in which FortIT processes personal data on behalf of and for the purposes of the customer ("processing on behalf"), whereby the customer is either controller or processor and FortIT is either processor or sub-processor.
1.1.3. This Addendum is an integral part of the Contract. The provisions of this Addendum do not limit the rights and obligations of the parties with regard to the provision of the services under the Contract. With respect to their subject matter, however, the provisions of this Addendum take precedence over the provisions of the Contract.
1.1.4. If the customer is a public body (e.g. canton, municipality, institution or corporation under public law) that is subject to the data protection law of the Confederation, a canton or a municipality, the special provisions in section 3 apply in addition. In the event of contradictions, the provisions in section 3 take precedence over the other provisions of this Addendum.
1.2.1. The term of this Addendum corresponds to the duration of the Contract, unless obligations extending beyond that period arise from the provisions of this Addendum. In the case of such continuing obligations, this Addendum remains in force until the corresponding obligations have expired.
1.2.2. By this provision, the parties do not modify the termination rights agreed in the Contract.
1.3.1. Terms placed in quotation marks in this Addendum have the meaning ascribed to them therein throughout the Addendum.
1.3.2. The data protection terms used in this Addendum, such as "personal data", "data subject", "controller", "processor", "data security breach" or "data protection impact assessment", have the meaning ascribed to them in the Swiss Federal Act on Data Protection (FADP) or (where applicable) in the EU General Data Protection Regulation (GDPR) or in the applicable cantonal data protection law.
1.3.3. "Standard deployment" means the provision of FORTCONTROL on the cloud infrastructure described in section 2.7.2, Table A, with data location in Switzerland. "Swiss Deployment Option" means the provision of FORTCONTROL on the infrastructure described in section 2.7.2, Table B, in which infrastructure, operation and e-mail delivery are provided exclusively in Switzerland by providers domiciled in Switzerland. The deployment variant applicable to the customer results from the Contract; in the absence of an express agreement, the standard deployment applies.
2.1.1. The subject matter and purpose of the processing on behalf is the provision of FORTCONTROL in the form of software as a service (SaaS) to the customer, including the associated services such as operation, maintenance, support and data backup as well as – where activated by the customer – optional AI functions pursuant to clause 3.7 of the Terms of Use.
2.1.2. The processing on behalf concerns the types of personal data uploaded, entered, provided, stored or processed by the customer or its users when using FORTCONTROL ("contractual personal data"). These typically include details of users (name, e-mail address, role), of employees and contact persons of the customer and of other persons named in the customer's assets, risks, measures, audits or documents. Details of the contractual personal data and the group (categories) of data subjects result from the Contract and the service descriptions in conjunction with any separate instructions of the customer.
2.1.3. The processing on behalf consists of the storage, provision, backup and display of the contractual personal data in the provision of the SaaS services for the customer, as well as access to this data to the extent required for support, troubleshooting and maintenance and initiated by the customer. Where the customer has activated AI functions, the processing additionally comprises the transmission of the content selected by the user to the AI provider pursuant to section 2.7.2, Table C, for automated analysis and the generation of suggestions. The transmission takes place only for the respective request; storage by the AI provider beyond any short-term abuse monitoring and use for training AI models are contractually excluded.
2.1.4. The place of the processing on behalf is determined by the agreed deployment variant: (a) In the standard deployment, the contractual personal data is stored in Switzerland; individual sub-processors may process data in EU/EEA states or in the USA in the context of support, maintenance or delivery services. (b) In the Swiss Deployment Option, storage, operation and e-mail delivery take place exclusively in Switzerland by providers domiciled in Switzerland; no processing outside Switzerland takes place without the express written consent of the customer. The only exception is the optional AI functions: if an administrator of the customer activates them, the content selected for this purpose is processed in both deployment variants by the AI provider named in section 2.7.2, Table C, in the EU (France) – only for the respective request and without training on customer data; activation is deemed the customer's express consent and instruction for this processing.
2.1.5. The duration of the processing is determined by section 1.2.
2.2.1. FortIT undertakes and warrants that FortIT processes all contractual personal data (i) exclusively for the purposes described in section 2.1, (ii) in accordance with the Contract and the documented instructions of the customer, and (iii) in accordance with this Addendum, and (iv) does not otherwise use it for its own purposes.
2.2.2. Instructions of the customer are given to FortIT in writing or in text form (e.g. e-mail, support ticket). If FortIT is of the opinion that an instruction violates applicable data protection law, FortIT informs the customer without delay and is entitled to suspend the execution of the instruction until it is confirmed or amended by the customer.
2.2.3. The customer remains responsible for the lawfulness of the processing of the contractual personal data, in particular for the existence of a legal basis and for safeguarding the rights of data subjects.
2.3.1. FortIT undertakes to take appropriate technical and organisational protective measures in the interest of the confidentiality, integrity and contractual availability of the contractual personal data.
2.3.2. To this end, FortIT implements in particular access controls, role-based access controls on a need-to-know basis, encryption of data transmission and of stored data, logging, regular data backups and procedures for regularly reviewing, assessing and evaluating the effectiveness of the technical and organisational measures. In selecting the measures, FortIT takes into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing as well as the varying likelihood and severity of the risk to data subjects.
2.3.3. The current description of the technical and organisational measures (TOM) is available at https://www.fortcontrol.swiss/tom/ and forms an annex to this Addendum; FortIT also provides it to the customer in writing on request. FortIT may further develop the measures provided that the agreed level of protection is not reduced.
2.4.1. If FortIT becomes aware of a security breach consisting in contractual personal data being unintentionally or unlawfully lost, deleted, destroyed or altered or disclosed or made accessible to unauthorised persons ("data security breach"), FortIT will notify the customer of the data security breach as quickly as possible and without culpable delay, generally within 48 hours of becoming aware of it. FortIT will then (i) investigate the data security breach and determine its effects, (ii) inform the customer in detail about the data security breach, (iii) take appropriate measures to mitigate the effects and minimise the risk that may arise from the data security breach for data subjects, and (iv) document the incident.
2.4.2. FortIT will reasonably support the customer in fulfilling its obligations to notify data security breaches to competent supervisory authorities or data subjects.
2.5.1. FortIT undertakes to inform the customer as quickly as possible and on its own initiative (i) if FortIT is of the opinion that FortIT will no longer be able to comply with the obligations under this Addendum in the foreseeable future; (ii) of any request to exercise data subject rights that FortIT has received directly from data subjects in relation to contractual personal data (provided that FortIT can attribute the request to the customer on the basis of the information provided by the data subject; otherwise FortIT will ask the data subject to contact the controller responsible for the data processing); and (iii) of requests or orders from authorities or courts concerning contractual personal data, insofar as such information is legally permissible.
2.5.2. FortIT will support the customer, on request and against separate remuneration, in responding to requests from data subjects to exercise their data protection rights.
2.5.3. In addition, FortIT will support the customer, on request and against separate remuneration, in data protection impact assessments and prior consultations with data protection supervisory authorities.
2.5.4. FortIT provides the customer with all information that the customer reasonably requires to demonstrate compliance with its obligations under the applicable data protection law in relation to the processing on behalf.
2.6.1. FortIT undertakes to keep the contractual personal data confidential and must oblige the persons entrusted with the processing on behalf in writing to maintain confidentiality and instruct them on the applicable data protection obligations.
2.6.2. These confidentiality obligations continue to apply for an unlimited period after termination of the Contract.
2.7.1. Sub-processors are natural or legal persons engaged by FortIT for the processing on behalf. FortIT is entitled to engage sub-processors. In such cases, FortIT is obliged to conclude with sub-processors an agreement on (sub-)processing that enables FortIT to comply with the provisions of this Addendum, including FortIT's confidentiality obligations. With providers of standardised services (in particular cloud, infrastructure and platform providers), FortIT cannot negotiate individual contracts; their standardised data processing agreements apply. In such cases, FortIT ensures that the sub-processor's technical and organisational measures, baseline security measures or other requirements guarantee a level of protection at least equivalent to the TOM. FortIT remains responsible to the customer for the services of the sub-processors as for its own services.
2.7.2. Depending on the agreed deployment variant, FortIT uses the following sub-processors. The sub-processors listed in Table C are only engaged if an administrator of the customer has activated the AI functions pursuant to clause 3.7 of the Terms of Use; without activation, no contractual personal data is disclosed to these sub-processors. Table C applies to both deployment variants: with the Swiss Deployment Option, too, processing is carried out by the AI provider in the EU (France), only for the respective request and without training on customer data. The AI functions therefore always require express activation by an administrator of the customer. The following tables apply:
Table A – Standard deployment
| Name | Country of processing | Description |
|---|---|---|
| Microsoft Azure (Microsoft Ireland Operations Limited, Ireland) | Switzerland (data location) | Infrastructure provider, application hosting, data storage, data processing |
| MongoDB Atlas (MongoDB Limited, Ireland) | Switzerland (data location) | Database and data storage |
| SendGrid (Twilio Ireland Limited, Ireland) | EU | Delivery of e-mail notifications |
Table B – Swiss Deployment Option
| Name | Country of processing | Description |
|---|---|---|
| cloudscale.ch AG, Neugasse 6, 8005 Zurich | Switzerland | Infrastructure provider (cloud infrastructure, data centres exclusively in Switzerland), data storage |
| [to be announced] | Switzerland | Provision and operation of managed services (platform operation, database, data backup, monitoring) |
| mailomat (mailXpert GmbH, Schulstrasse 37, 8050 Zurich) | Switzerland | Delivery of e-mail notifications |
Table C – Optional AI functions (only upon activation by the customer)
| Name | Country of processing | Description |
|---|---|---|
| Mistral AI, SAS, 15 rue des Halles, 75001 Paris, France | EU (France) | Operation of the AI language models for the AI functions of FORTCONTROL; processing only for the respective request, no training with customer data |
2.7.3. FortIT will inform the customer in writing, in an appropriate manner and in good time in advance, if FortIT intends to engage new sub-processors or replace existing ones after the Contract has entered into force. If the customer does not object in writing to the engagement or replacement of the sub-processor within thirty (30) days of the date of the notification, the new or replaced sub-processor is deemed approved. If the customer objects for justified data protection reasons, the parties endeavour to find an amicable solution; if no such solution is reached, either party may terminate the Contract with regard to the affected service as of the date of the intended engagement.
2.7.4. The current list of sub-processors is available at https://www.fortcontrol.swiss/avv/.
2.7.5. Where the customer uses its own AI agents or other systems that access contractual personal data via the interfaces of FORTCONTROL (clause 3.12 of the Terms of Use), these are not sub-processors of FortIT. The customer is solely responsible for these systems, their providers and the data processing carried out there and concludes any required data processing agreements itself.
2.8.1. The customer is entitled to verify FortIT's compliance with this Addendum. FortIT provides evidence primarily by making available suitable documents, in particular the description of the technical and organisational measures, audit reports, certifications or confirmations of its sub-processors, and by answering written questions of the customer.
2.8.2. Insofar as this evidence is demonstrably insufficient for the customer or a supervisory authority so requires, the customer may carry out an audit at FortIT, or have it carried out by an independent expert bound to confidentiality, at most once per calendar year and additionally for justified cause (in particular after a data security breach). The audit must be announced in writing at least thirty (30) days in advance, carried out during normal business hours and designed in such a way that FortIT's business operations and the confidentiality of other customers' data are not impaired. The customer bears the expenses incurred by FortIT as a result of the audit; they are remunerated on a time basis at CHF 230 per hour (excl. VAT), unless the audit reveals material violations of this Addendum.
2.9.1. After termination of the Contract, FortIT will delete the contractual personal data in accordance with the relevant provisions of the Contract or, if the customer so wishes, return it to the customer in a common, machine-readable format. Unless the Contract provides otherwise, the data is irrevocably deleted 90 days after termination of the Contract; the customer may request the return of the data within this period. Statutory retention obligations of FortIT are reserved. FortIT confirms the deletion to the customer in writing on request.
3.1.1. The provisions of this section 3 apply if the customer is a public body that is subject to the data protection law of a canton or a municipality or to the data protection law of the Confederation. They specify the minimum content that the applicable public data protection law prescribes for agreements on processing on behalf and supplement the other provisions of this Addendum.
3.2.1. The subject matter, nature, scope and purpose of the processing on behalf as well as the categories of contractual personal data and data subjects result from section 2.1 and the Contract. The customer may specify these details in a service description or in written instructions.
3.2.2. As the responsible body, the customer remains responsible for the lawfulness of the data processing, for safeguarding the rights of data subjects and for fulfilling its statutory information and notification obligations. FortIT processes the contractual personal data exclusively on behalf of and in accordance with the instructions of the customer and only in the manner in which the customer itself would be permitted to do so.
3.3.1. FortIT acknowledges that the contractual personal data may be subject to official secrecy and, where applicable, to further special statutory confidentiality obligations (e.g. tax secrecy, social welfare secrecy, professional secrecy). FortIT undertakes to observe official secrecy and these special confidentiality obligations to the same extent as they apply to the customer and its employees, and is aware that violations of official secrecy may be punishable under Art. 320 of the Swiss Criminal Code.
3.3.2. FortIT obliges all employees and auxiliary persons who may have access to contractual personal data in writing to observe official secrecy and the special confidentiality obligations before they commence their activities, and provides the customer with evidence of these obligations on request.
3.3.3. Access to contractual personal data is restricted to those employees of FortIT who strictly require it to perform the Contract. The confidentiality obligations continue to apply for an unlimited period beyond the end of the Contract.
3.4.1. For public bodies, FortIT recommends the Swiss Deployment Option. If this has been agreed, all processing of the contractual personal data, including data backup, operation, support and e-mail delivery, takes place exclusively in Switzerland by sub-processors domiciled in Switzerland in accordance with section 2.7.2, Table B. No disclosure abroad takes place.
3.4.2. If the standard deployment has been agreed, the contractual personal data is stored in Switzerland; the customer acknowledges that individual sub-processors pursuant to section 2.7.2, Table A, may access data from abroad in the context of support and maintenance services. Any further relocation of the place of processing abroad requires the prior written consent of the customer.
3.4.3. For customers pursuant to this section 3, AI functions pursuant to section 2.7.2, Table C, may only be activated if the customer has assessed the disclosure to the AI provider in the EU (France) in accordance with the rules applicable to it and approved it in writing; this also applies to the Swiss Deployment Option. Section 3.6.1 remains reserved. Activation by an administrator of the customer is deemed confirmation that these requirements are met.
3.5.1. In addition to section 2.8, FortIT grants the customer and the data protection supervisory authority competent for the customer the right to verify compliance with the data protection requirements and this Addendum. For this purpose, FortIT grants access, after reasonable advance notice, to the relevant documents, systems and premises to the extent necessary for the control, and provides the necessary information. The expenses incurred by FortIT for preparing, accompanying and following up such controls are remunerated by the customer on a time basis at CHF 230 per hour (excl. VAT); this also applies to controls by the data protection supervisory authority, unless the control reveals material violations of this Addendum.
3.5.2. FortIT informs the customer without delay of controls by supervisory authorities concerning the processing on behalf of the customer, insofar as this is legally permissible.
3.6.1. Notwithstanding section 2.7.3, the engagement or replacement of a sub-processor for customers pursuant to this section 3 requires the prior written consent of the customer. The sub-processors of the agreed deployment variant listed in section 2.7.2 are deemed approved upon conclusion of the Contract. The customer refuses consent only for objective, data protection reasons.
3.6.2. FortIT ensures that its sub-processors are subject to obligations at least equivalent to the obligations under this Addendum, including confidentiality. With providers of standardised services pursuant to section 2.7.1, FortIT cannot conclude individual contracts; in such cases, FortIT ensures that their technical and organisational measures, baseline security measures or other requirements guarantee a level of protection at least equivalent to the TOM. FortIT remains responsible to the customer for compliance by its sub-processors.
3.7.1. If FortIT culpably breaches a material obligation under this Addendum, in particular the obligations regarding compliance with instructions (section 2.2), data security (section 2.3), confidentiality and observance of official secrecy (sections 2.6 and 3.3), the place of data processing (section 3.4) or the engagement of third parties (section 3.6), FortIT owes the customer a contractual penalty per breach in the amount of 10 per cent of the usage fees owed for the current contract year. Payment of the contractual penalty does not release FortIT from the performance of its obligations. The right to claim further damages is reserved; the contractual penalty is credited against the damages.
3.7.2. In the event of a material breach of obligations, the customer is furthermore entitled to terminate the Contract with immediate effect and without cost consequences. Fees already paid in advance for the period after termination are refunded pro rata. In the case of other breaches, the customer sets FortIT a reasonable period for remedy; if this period expires without result, the customer may likewise terminate the Contract with immediate effect.
3.7.3. The customer may also instruct FortIT to cease processing the contractual personal data in whole or in part until the breach of obligations has been remedied. The rights and obligations upon termination of the Contract pursuant to section 3.8 also apply to a termination under this section.
3.8.1. The duration of this Addendum is determined by section 1.2. Upon termination of the Contract, irrespective of the reason for termination, FortIT returns all contractual personal data to the customer at the customer's request within thirty (30) days in a common, machine-readable format and subsequently deletes, but no later than ninety (90) days after termination, all copies held by it and its sub-processors, unless a statutory retention obligation prevents this. Copies in data backups are overwritten within the regular retention and deletion cycles of FortIT and its sub-processors pursuant to section 6.2 TOM; until then, they are neither restored nor further processed. FortIT confirms the complete deletion to the customer in writing.
3.9.1. This Addendum is governed by Swiss law. FortIT's data protection obligations are additionally governed by the public data protection law applicable to the customer, insofar as it is mandatorily applicable to processors. The place of jurisdiction is the customer's registered seat, unless the Contract provides otherwise.
4.1. Amendments and additions to this Addendum must be made in writing. FortIT may amend this Addendum if this is necessary due to changed legal requirements or changed sub-processors; FortIT informs the customer thereof in writing and in advance. The version available at https://www.fortcontrol.swiss/avv/ applies at the relevant time, unless the parties have agreed otherwise.
4.2. Should any provision of this Addendum be or become invalid or unenforceable, the validity of the remaining provisions shall not be affected. The parties shall replace the invalid provision with a valid one that comes as close as possible to the purpose of the invalid provision.
4.3. This Addendum is governed by Swiss law. The place of jurisdiction is Zurich, Switzerland, unless section 3.9 or mandatory statutory provisions provide otherwise.
4.4. This Addendum is written in German. Translations are for information purposes only; in the event of discrepancies, the German version is authoritative.
1.1.1. Le présent contrat de sous-traitance («Annexe» ou «CST») précise les droits et obligations des parties en matière de traitement de données pour le compte d'autrui qui découlent pour elles du droit applicable en matière de protection des données. Il complète le contrat d'utilisation conclu entre FortIT AG, Badenerstrasse 281, 8003 Zurich («FortIT»), et le client concernant la mise à disposition de la plateforme fortControl (FORTCONTROL) au client («Contrat»). Le Contrat comprend notamment les conditions d'utilisation, disponibles sous https://www.fortcontrol.swiss/nutzungsbedingungen/, ainsi que l'offre ou le contrat signé séparément.
1.1.2. La présente Annexe s'applique uniquement aux prestations dans le cadre desquelles FortIT traite des données personnelles pour le compte et aux fins du client («traitement pour le compte d'autrui»), le client étant soit responsable du traitement soit sous-traitant, et FortIT soit sous-traitant soit sous-traitant ultérieur.
1.1.3. La présente Annexe fait partie intégrante du Contrat. Les dispositions de la présente Annexe ne restreignent pas les droits et obligations des parties concernant la fourniture des prestations prévues par le Contrat. En ce qui concerne leur objet, les dispositions de la présente Annexe priment toutefois sur celles du Contrat.
1.1.4. Si le client est un organe public (p. ex. canton, commune, établissement ou corporation de droit public) soumis au droit de la protection des données de la Confédération, d'un canton ou d'une commune, les dispositions particulières du chiffre 3 s'appliquent en complément. En cas de contradiction, les dispositions du chiffre 3 priment sur les autres dispositions de la présente Annexe.
1.2.1. La durée de la présente Annexe correspond à celle du Contrat, sauf si des obligations excédant cette durée découlent des dispositions de la présente Annexe. En présence de telles obligations persistantes, la présente Annexe reste en vigueur jusqu'à l'extinction des obligations correspondantes.
1.2.2. Par cette disposition, les parties ne modifient pas les droits de résiliation convenus dans le Contrat.
1.3.1. Les termes placés entre guillemets dans la présente Annexe ont, dans l'ensemble de l'Annexe, la signification qui leur y est attribuée.
1.3.2. Les termes relatifs à la protection des données utilisés dans la présente Annexe, tels que «données personnelles», «personne concernée», «responsable du traitement», «sous-traitant», «violation de la sécurité des données» ou «analyse d'impact relative à la protection des données», ont la signification qui leur est attribuée dans la loi fédérale suisse sur la protection des données (LPD) ou (le cas échéant) dans le règlement général de l'UE sur la protection des données (RGPD) ou dans le droit cantonal applicable en matière de protection des données.
1.3.3. «Déploiement standard» désigne la mise à disposition de FORTCONTROL sur l'infrastructure cloud décrite au chiffre 2.7.2, tableau A, avec localisation des données en Suisse. «Swiss Deployment Option» désigne la mise à disposition de FORTCONTROL sur l'infrastructure décrite au chiffre 2.7.2, tableau B, dans laquelle l'infrastructure, l'exploitation et l'envoi d'e-mails sont assurés exclusivement en Suisse par des prestataires ayant leur siège en Suisse. La variante de déploiement applicable au client résulte du Contrat; en l'absence d'accord explicite, le déploiement standard s'applique.
2.1.1. L'objet et la finalité du traitement pour le compte d'autrui sont la mise à disposition de FORTCONTROL sous forme de logiciel en tant que service (SaaS) au client, y compris les prestations associées telles que l'exploitation, la maintenance, le support et la sauvegarde des données ainsi que – si le client les a activées – les fonctions d'IA optionnelles selon le chiffre 3.7 des Conditions d'utilisation.
2.1.2. Le traitement pour le compte d'autrui porte sur les types de données personnelles téléversées, saisies, fournies, enregistrées ou traitées par le client ou ses utilisateurs lors de l'utilisation de FORTCONTROL («données personnelles contractuelles»). Il s'agit typiquement d'indications relatives aux utilisateurs (nom, adresse e-mail, rôle), aux collaborateurs et personnes de contact du client ainsi qu'à d'autres personnes mentionnées dans les objets à protéger, risques, mesures, audits ou documents du client. Les détails relatifs aux données personnelles contractuelles et au cercle (catégories) des personnes concernées résultent du Contrat et des descriptions de prestations, en relation avec d'éventuelles instructions séparées du client.
2.1.3. Le traitement pour le compte d'autrui consiste en l'enregistrement, la mise à disposition, la sauvegarde et l'affichage des données personnelles contractuelles dans le cadre de la fourniture des prestations SaaS au client, ainsi qu'en l'accès à ces données dans la mesure nécessaire au support, à la correction d'erreurs et à la maintenance et à la demande du client. Lorsque le client a activé des fonctions d'IA, le traitement comprend en outre la transmission des contenus sélectionnés par l'utilisateur au fournisseur d'IA selon le chiffre 2.7.2, tableau C, en vue d'une analyse automatisée et de la génération de propositions. La transmission n'a lieu que pour la requête concernée; une conservation chez le fournisseur d'IA au-delà d'un éventuel contrôle des abus de courte durée et une utilisation pour l'entraînement de modèles d'IA sont contractuellement exclues.
2.1.4. Le lieu du traitement pour le compte d'autrui dépend de la variante de déploiement convenue: (a) Dans le déploiement standard, les données personnelles contractuelles sont enregistrées en Suisse; certains sous-traitants ultérieurs peuvent traiter des données dans des États de l'UE/de l'EEE ou aux États-Unis dans le cadre de prestations de support, de maintenance ou d'envoi. (b) Dans la Swiss Deployment Option, l'enregistrement, l'exploitation et l'envoi d'e-mails ont lieu exclusivement en Suisse par des prestataires ayant leur siège en Suisse; aucun traitement hors de Suisse n'a lieu sans le consentement écrit explicite du client. Seule exception: les fonctions d'IA optionnelles. Si un administrateur du client les active, les contenus sélectionnés à cet effet sont traités, dans les deux variantes de mise à disposition, par le fournisseur d'IA désigné au chiffre 2.7.2, tableau C, dans l'UE (France) – uniquement pour la requête concernée et sans entraînement avec des données des clients; l'activation vaut consentement et instruction explicites du client pour ce traitement.
2.1.5. La durée du traitement est déterminée par le chiffre 1.2.
2.2.1. FortIT s'engage et garantit que FortIT traite toutes les données personnelles contractuelles (i) exclusivement aux fins décrites au chiffre 2.1, (ii) conformément au Contrat et aux instructions documentées du client ainsi que (iii) conformément à la présente Annexe, et (iv) ne les utilise pas par ailleurs à ses propres fins.
2.2.2. Les instructions du client sont données à FortIT par écrit ou sous forme de texte (p. ex. e-mail, ticket de support). Si FortIT estime qu'une instruction viole le droit applicable en matière de protection des données, FortIT en informe le client sans délai et est en droit de suspendre l'exécution de l'instruction jusqu'à sa confirmation ou sa modification par le client.
2.2.3. Le client demeure responsable de la licéité du traitement des données personnelles contractuelles, en particulier de l'existence d'une base légale et du respect des droits des personnes concernées.
2.3.1. FortIT s'engage à prendre des mesures de protection techniques et organisationnelles appropriées dans l'intérêt de la confidentialité, de l'intégrité et de la disponibilité conforme au contrat des données personnelles contractuelles.
2.3.2. À cet effet, FortIT met notamment en œuvre des contrôles d'accès physiques, des contrôles d'accès logiques fondés sur les rôles et le principe du besoin d'en connaître, le chiffrement de la transmission des données et des données enregistrées, la journalisation, des sauvegardes régulières des données ainsi que des procédures visant à tester, analyser et évaluer régulièrement l'efficacité des mesures techniques et organisationnelles. Lors du choix des mesures, FortIT tient compte de l'état de la technique, des coûts de mise en œuvre ainsi que de la nature, de la portée, du contexte et des finalités du traitement, de même que de la probabilité et de la gravité variables du risque pour les personnes concernées.
2.3.3. La description actuelle des mesures techniques et organisationnelles (TOM) est disponible sous https://www.fortcontrol.swiss/tom/ et fait partie intégrante de la présente Annexe; FortIT la met également à la disposition du client par écrit sur demande. FortIT peut faire évoluer les mesures pour autant que le niveau de protection convenu ne soit pas abaissé.
2.4.1. Si FortIT constate une violation de la sécurité consistant en ce que des données personnelles contractuelles sont perdues, effacées, détruites ou modifiées de manière involontaire ou illicite, ou divulguées ou rendues accessibles à des personnes non autorisées («violation de la sécurité des données»), FortIT annonce la violation de la sécurité des données au client aussi rapidement que possible et sans retard fautif, en règle générale dans les 48 heures suivant la prise de connaissance. FortIT procède ensuite (i) à l'examen de la violation de la sécurité des données et à la détermination de ses effets, (ii) à l'information détaillée du client sur la violation de la sécurité des données, (iii) à la prise de mesures appropriées pour en atténuer les effets et réduire autant que possible le risque pouvant en résulter pour les personnes concernées, et (iv) à la documentation de l'incident.
2.4.2. FortIT assiste le client de manière appropriée dans l'accomplissement de ses obligations d'annonce des violations de la sécurité des données aux autorités de surveillance compétentes ou aux personnes concernées.
2.5.1. FortIT s'engage à informer le client aussi rapidement que possible et de sa propre initiative (i) si FortIT estime que FortIT ne sera plus en mesure, dans un avenir prévisible, de remplir les obligations découlant de la présente Annexe; (ii) de toute demande d'exercice des droits des personnes concernées que FortIT a reçue directement de personnes concernées en relation avec des données personnelles contractuelles (à condition que FortIT puisse l'attribuer au client sur la base des indications de la personne concernée; à défaut, FortIT invitera la personne concernée à s'adresser au responsable du traitement des données); ainsi que (iii) des demandes ou décisions d'autorités ou de tribunaux concernant des données personnelles contractuelles, dans la mesure où une telle information est légalement admissible.
2.5.2. FortIT assiste le client, sur demande et contre rémunération séparée, dans la réponse aux demandes de personnes concernées relatives à l'exercice de leurs droits en matière de protection des données.
2.5.3. FortIT assiste en outre le client, sur demande et contre rémunération séparée, dans les analyses d'impact relatives à la protection des données et les consultations préalables des autorités de surveillance de la protection des données.
2.5.4. FortIT met à la disposition du client toutes les informations dont celui-ci a raisonnablement besoin pour démontrer le respect de ses obligations découlant du droit applicable en matière de protection des données en relation avec le traitement pour le compte d'autrui.
2.6.1. FortIT s'engage à garder confidentielles les données personnelles contractuelles et doit obliger par écrit les personnes chargées du traitement pour le compte d'autrui à respecter la confidentialité et les instruire sur les obligations applicables en matière de protection des données.
2.6.2. Ces obligations de confidentialité subsistent pour une durée illimitée après la fin du Contrat.
2.7.1. Les sous-traitants ultérieurs sont des personnes physiques ou morales auxquelles FortIT fait appel pour le traitement pour le compte d'autrui. FortIT est en droit de faire appel à des sous-traitants ultérieurs. Dans ce cas, FortIT est tenue de conclure avec les sous-traitants ultérieurs un accord de (sous-)traitance qui permette à FortIT de respecter les dispositions de la présente Annexe, y compris les obligations de confidentialité de FortIT. Avec les fournisseurs de services standardisés (en particulier les fournisseurs de cloud, d'infrastructure et de plateforme), FortIT ne peut pas négocier de contrats individuels; leurs accords de sous-traitance standardisés font foi. Dans ces cas, FortIT s'assure que les mesures techniques et organisationnelles, les mesures de protection de base ou les autres prescriptions du sous-traitant ultérieur garantissent un niveau de protection au moins équivalent aux TOM. FortIT demeure responsable envers le client des prestations des sous-traitants ultérieurs comme de ses propres prestations.
2.7.2. Selon la variante de déploiement convenue, FortIT fait appel aux sous-traitants ultérieurs suivants. Les sous-traitants ultérieurs selon le tableau C ne sont sollicités que si un administrateur du client a activé les fonctions d'IA selon le chiffre 3.7 des Conditions d'utilisation; sans activation, aucune donnée personnelle contractuelle n'est communiquée à ces sous-traitants ultérieurs. Le tableau C s'applique aux deux variantes de mise à disposition: avec la Swiss Deployment Option également, le traitement est effectué par le fournisseur d'IA dans l'UE (France), uniquement pour la requête concernée et sans entraînement avec des données des clients. Les fonctions d'IA requièrent donc dans tous les cas l'activation explicite par un administrateur du client. Les tableaux suivants s'appliquent:
Tableau A – Déploiement standard
| Nom | Pays de traitement | Description |
|---|---|---|
| Microsoft Azure (Microsoft Ireland Operations Limited, Irlande) | Suisse (lieu de stockage des données) | Fournisseur d'infrastructure, hébergement d'applications, stockage de données, traitement de données |
| MongoDB Atlas (MongoDB Limited, Irlande) | Suisse (lieu de stockage des données) | Base de données et stockage de données |
| SendGrid (Twilio Ireland Limited, Irlande) | UE | Envoi de notifications par e-mail |
Tableau B – Swiss Deployment Option
| Nom | Pays de traitement | Description |
|---|---|---|
| cloudscale.ch AG, Neugasse 6, 8005 Zurich | Suisse | Fournisseur d'infrastructure (infrastructure cloud, centres de données exclusivement en Suisse), stockage de données |
| [to be announced] | Suisse | Mise à disposition et exploitation de services gérés (exploitation de la plateforme, base de données, sauvegarde des données, surveillance) |
| mailomat (mailXpert GmbH, Schulstrasse 37, 8050 Zurich) | Suisse | Envoi de notifications par e-mail |
Tableau C – Fonctions d'IA optionnelles (uniquement après activation par le client)
| Nom | Pays de traitement | Description |
|---|---|---|
| Mistral AI, SAS, 15 rue des Halles, 75001 Paris, France | UE (France) | Exploitation des modèles de langage d'IA pour les fonctions d'IA de FORTCONTROL; traitement uniquement pour la requête concernée, pas d'entraînement avec des données des clients |
2.7.3. FortIT informe le client par écrit, de manière appropriée et suffisamment à l'avance, si FortIT entend, après l'entrée en vigueur du Contrat, faire appel à de nouveaux sous-traitants ultérieurs ou remplacer des sous-traitants ultérieurs existants. Si le client ne s'oppose pas par écrit au recours au sous-traitant ultérieur ou à son remplacement dans les trente (30) jours suivant la date de la communication, le nouveau sous-traitant ultérieur ou le sous-traitant ultérieur de remplacement est réputé approuvé. Si le client s'oppose pour des motifs fondés relevant de la protection des données, les parties s'efforcent de trouver une solution à l'amiable; à défaut, chaque partie peut résilier le Contrat en ce qui concerne la prestation affectée à la date prévue pour le recours.
2.7.4. La liste actuelle des sous-traitants ultérieurs est disponible sous https://www.fortcontrol.swiss/avv/.
2.7.5. Si le client utilise ses propres agents d'IA ou d'autres systèmes qui accèdent aux données personnelles contractuelles via les interfaces de FORTCONTROL (chiffre 3.12 des Conditions d'utilisation), il ne s'agit pas de sous-traitants ultérieurs de FortIT. Le client est seul responsable de ces systèmes, de leurs fournisseurs et du traitement des données qui y est effectué et conclut lui-même les contrats de sous-traitance nécessaires.
2.8.1. Le client est en droit de vérifier le respect de la présente Annexe par FortIT. FortIT apporte la preuve en premier lieu par la mise à disposition de documents appropriés, notamment la description des mesures techniques et organisationnelles, des rapports d'audit, des certifications ou des attestations de ses sous-traitants ultérieurs, ainsi que par la réponse aux questions écrites du client.
2.8.2. Dans la mesure où ces preuves sont manifestement insuffisantes pour le client ou qu'une autorité de surveillance l'exige, le client peut procéder à un contrôle auprès de FortIT, ou le faire effectuer par un expert indépendant tenu à la confidentialité, au plus une fois par année civile et, en outre, pour un motif fondé (en particulier après une violation de la sécurité des données). Le contrôle doit être annoncé par écrit au moins trente (30) jours à l'avance, être effectué pendant les heures de bureau habituelles et être organisé de manière à ne pas perturber les activités de FortIT ni la confidentialité des données d'autres clients. Le client supporte les frais occasionnés à FortIT par le contrôle; ils sont rémunérés au temps passé à CHF 230 par heure (hors TVA), à moins que le contrôle ne révèle des violations importantes de la présente Annexe.
2.9.1. Après la fin du Contrat, FortIT efface les données personnelles contractuelles conformément aux dispositions correspondantes du Contrat ou, si le client le souhaite, les lui restitue dans un format courant et lisible par machine. Sauf disposition contraire du Contrat, les données sont irrévocablement effacées 90 jours après la fin du Contrat; le client peut en demander la restitution dans ce délai. Les obligations légales de conservation de FortIT sont réservées. FortIT confirme l'effacement au client par écrit sur demande.
3.1.1. Les dispositions du présent chiffre 3 s'appliquent lorsque le client est un organe public soumis au droit de la protection des données d'un canton ou d'une commune ou au droit de la protection des données de la Confédération. Elles précisent le contenu minimal que le droit public applicable en matière de protection des données prescrit pour les accords de traitement pour le compte d'autrui et complètent les autres dispositions de la présente Annexe.
3.2.1. L'objet, la nature, l'étendue et la finalité du traitement pour le compte d'autrui ainsi que les catégories de données personnelles contractuelles et de personnes concernées résultent du chiffre 2.1 et du Contrat. Le client peut préciser ces indications dans une description de prestations ou dans des instructions écrites.
3.2.2. En tant qu'organe responsable, le client demeure responsable de la licéité du traitement des données, du respect des droits des personnes concernées et de l'accomplissement de ses obligations légales d'information et d'annonce. FortIT traite les données personnelles contractuelles exclusivement pour le compte et selon les instructions du client, et uniquement de la manière dont le client serait lui-même autorisé à le faire.
3.3.1. FortIT prend acte que les données personnelles contractuelles peuvent être soumises au secret de fonction ainsi que, le cas échéant, à d'autres obligations légales particulières de confidentialité (p. ex. secret fiscal, secret de l'aide sociale, secret professionnel). FortIT s'engage à respecter le secret de fonction et ces obligations particulières de confidentialité dans la même mesure qu'elles s'appliquent au client et à ses collaborateurs, et est consciente que les violations du secret de fonction peuvent être punissables en vertu de l'art. 320 du Code pénal suisse.
3.3.2. FortIT soumet par écrit, avant le début de leur activité, tous les collaborateurs et auxiliaires susceptibles d'avoir accès à des données personnelles contractuelles au secret de fonction et aux obligations particulières de confidentialité, et en justifie auprès du client sur demande.
3.3.3. L'accès aux données personnelles contractuelles est limité aux collaborateurs de FortIT qui en ont impérativement besoin pour l'exécution du Contrat. Les obligations de confidentialité subsistent au-delà de la fin du Contrat pour une durée illimitée.
3.4.1. Pour les organes publics, FortIT recommande la Swiss Deployment Option. Si celle-ci est convenue, tous les traitements des données personnelles contractuelles, y compris la sauvegarde des données, l'exploitation, le support et l'envoi d'e-mails, ont lieu exclusivement en Suisse par des sous-traitants ultérieurs ayant leur siège en Suisse conformément au chiffre 2.7.2, tableau B. Aucune communication à l'étranger n'a lieu.
3.4.2. Si le déploiement standard est convenu, les données personnelles contractuelles sont enregistrées en Suisse; le client prend acte que certains sous-traitants ultérieurs selon le chiffre 2.7.2, tableau A, peuvent accéder aux données depuis l'étranger dans le cadre de prestations de support et de maintenance. Tout autre déplacement du lieu de traitement à l'étranger requiert le consentement écrit préalable du client.
3.4.3. Pour les clients selon le présent chiffre 3, les fonctions d'IA selon le chiffre 2.7.2, tableau C, ne peuvent être activées que si le client a examiné la communication au fournisseur d'IA dans l'UE (France) conformément aux prescriptions qui lui sont applicables et l'a approuvée par écrit; cela vaut également pour la Swiss Deployment Option. Le chiffre 3.6.1 est réservé. L'activation par un administrateur du client vaut confirmation que ces conditions sont remplies.
3.5.1. En complément du chiffre 2.8, FortIT accorde au client ainsi qu'à l'autorité de surveillance de la protection des données compétente pour le client le droit de contrôler le respect des prescriptions en matière de protection des données et de la présente Annexe. À cet effet, FortIT donne accès, après préavis raisonnable, aux documents, systèmes et locaux pertinents dans la mesure nécessaire au contrôle, et fournit les renseignements nécessaires. Les frais occasionnés à FortIT pour la préparation, l'accompagnement et le suivi de tels contrôles sont rémunérés par le client au temps passé à CHF 230 par heure (hors TVA); cela vaut également pour les contrôles de l'autorité de surveillance de la protection des données, à moins que le contrôle ne révèle des violations importantes de la présente Annexe.
3.5.2. FortIT informe le client sans délai des contrôles d'autorités de surveillance concernant le traitement pour le compte du client, dans la mesure où cela est légalement admissible.
3.6.1. En dérogation au chiffre 2.7.3, le recours à un sous-traitant ultérieur ou son remplacement requiert, pour les clients visés par le présent chiffre 3, le consentement écrit préalable du client. Les sous-traitants ultérieurs de la variante de déploiement convenue énumérés au chiffre 2.7.2 sont réputés approuvés à la conclusion du Contrat. Le client ne refuse son consentement que pour des motifs objectifs relevant de la protection des données.
3.6.2. FortIT s'assure que ses sous-traitants ultérieurs sont soumis à des obligations au moins équivalentes à celles découlant de la présente Annexe, y compris en matière de confidentialité. Avec les fournisseurs de services standardisés au sens du chiffre 2.7.1, FortIT ne peut pas conclure de contrats individuels; dans ces cas, FortIT s'assure que leurs mesures techniques et organisationnelles, mesures de protection de base ou autres prescriptions garantissent un niveau de protection au moins équivalent aux TOM. FortIT demeure responsable envers le client du respect par ses sous-traitants ultérieurs.
3.7.1. Si FortIT viole de manière fautive une obligation essentielle de la présente Annexe, en particulier les obligations relatives au respect des instructions (chiffre 2.2), à la sécurité des données (chiffre 2.3), à la confidentialité et au respect du secret de fonction (chiffres 2.6 et 3.3), au lieu du traitement des données (chiffre 3.4) ou au recours à des tiers (chiffre 3.6), FortIT doit au client, par cas de violation, une peine conventionnelle d'un montant de 10 pour cent des redevances d'utilisation dues pour l'année contractuelle en cours. Le paiement de la peine conventionnelle ne libère pas FortIT de l'exécution de ses obligations. La prétention à des dommages-intérêts plus étendus est réservée; la peine conventionnelle est imputée sur les dommages-intérêts.
3.7.2. En cas de violation essentielle des obligations, le client est en outre en droit de résilier le Contrat avec effet immédiat et sans frais. Les redevances déjà payées d'avance pour la période postérieure à la résiliation sont remboursées au prorata. En cas d'autres violations, le client fixe à FortIT un délai raisonnable pour y remédier; si ce délai expire sans résultat, le client peut également résilier le Contrat avec effet immédiat.
3.7.3. Le client peut en outre enjoindre à FortIT de cesser tout ou partie du traitement des données personnelles contractuelles jusqu'à ce qu'il ait été remédié à la violation des obligations. Les droits et obligations à la fin du contrat selon le chiffre 3.8 s'appliquent également en cas de résiliation selon le présent chiffre.
3.8.1. La durée de la présente Annexe est déterminée par le chiffre 1.2. À la fin du Contrat, quel qu'en soit le motif, FortIT restitue au client, à sa demande, l'ensemble des données personnelles contractuelles dans les trente (30) jours dans un format courant et lisible par machine, puis efface, au plus tard nonante (90) jours après la fin du Contrat, toutes les copies détenues par elle et ses sous-traitants ultérieurs, à moins qu'une obligation légale de conservation ne s'y oppose. Les copies contenues dans les sauvegardes sont écrasées dans le cadre des cycles réguliers de conservation et d'effacement de FortIT et de ses sous-traitants ultérieurs conformément au chiffre 6.2 des TOM; jusque-là, elles ne sont ni restaurées ni traitées ultérieurement. FortIT confirme l'effacement complet au client par écrit.
3.9.1. La présente Annexe est soumise au droit suisse. Les obligations de FortIT en matière de protection des données sont en outre régies par le droit public de la protection des données applicable au client, dans la mesure où celui-ci s'applique impérativement aux sous-traitants. Le for est le siège du client, sauf disposition contraire du Contrat.
4.1. Les modifications et compléments de la présente Annexe requièrent la forme écrite. FortIT peut adapter la présente Annexe lorsque cela est nécessaire en raison de modifications des prescriptions légales ou de changements de sous-traitants ultérieurs; FortIT en informe le client par écrit et à l'avance. La version disponible sous https://www.fortcontrol.swiss/avv/ s'applique, sauf accord contraire des parties.
4.2. Si une disposition de la présente Annexe est ou devient invalide ou inapplicable, la validité des autres dispositions n'en est pas affectée. Les parties remplacent la disposition invalide par une disposition valide se rapprochant le plus possible du but de la disposition invalide.
4.3. La présente Annexe est soumise au droit suisse. Le for est Zurich, Suisse, sauf disposition contraire du chiffre 3.9 ou de dispositions légales impératives.
4.4. La présente Annexe est rédigée en langue allemande. Les traductions servent uniquement à l'information; en cas de divergences, la version allemande fait foi.
1.1.1. Il presente contratto di trattamento dei dati per conto terzi («Allegato» o «CTD») concretizza i diritti e gli obblighi delle parti in materia di trattamento per conto terzi che derivano loro dal diritto applicabile in materia di protezione dei dati. Esso integra il contratto d'utilizzo tra FortIT AG, Badenerstrasse 281, 8003 Zurigo («FortIT»), e il cliente relativo alla messa a disposizione della piattaforma fortControl (FORTCONTROL) al cliente («Contratto»). Il Contratto comprende in particolare le condizioni d'uso, disponibili all'indirizzo https://www.fortcontrol.swiss/nutzungsbedingungen/, nonché l'offerta o il contratto firmato separatamente.
1.1.2. Il presente Allegato si applica soltanto alle prestazioni nell'ambito delle quali FortIT tratta dati personali per conto e per gli scopi del cliente («trattamento per conto terzi»), laddove il cliente è titolare del trattamento oppure responsabile del trattamento e FortIT è responsabile del trattamento oppure subresponsabile.
1.1.3. Il presente Allegato è parte integrante del Contratto. Le disposizioni del presente Allegato non limitano i diritti e gli obblighi delle parti relativi alla fornitura delle prestazioni previste dal Contratto. Per quanto riguarda il loro oggetto, le disposizioni del presente Allegato prevalgono tuttavia su quelle del Contratto.
1.1.4. Se il cliente è un organo pubblico (p. es. Cantone, Comune, istituto o corporazione di diritto pubblico) soggetto al diritto sulla protezione dei dati della Confederazione, di un Cantone o di un Comune, si applicano a titolo complementare le disposizioni particolari della cifra 3. In caso di contraddizioni, le disposizioni della cifra 3 prevalgono sulle altre disposizioni del presente Allegato.
1.2.1. La durata del presente Allegato corrisponde a quella del Contratto, a meno che dalle disposizioni del presente Allegato non derivino obblighi che si estendono oltre tale periodo. In presenza di tali obblighi persistenti, il presente Allegato rimane in vigore fino all'estinzione dei relativi obblighi.
1.2.2. Con questa disposizione le parti non modificano i diritti di disdetta convenuti nel Contratto.
1.3.1. I termini posti tra virgolette nel presente Allegato hanno, nell'intero Allegato, il significato ivi attribuito loro.
1.3.2. I termini relativi alla protezione dei dati utilizzati nel presente Allegato, quali «dati personali», «persona interessata», «titolare del trattamento», «responsabile del trattamento», «violazione della sicurezza dei dati» o «valutazione d'impatto sulla protezione dei dati», hanno il significato loro attribuito dalla legge federale svizzera sulla protezione dei dati (LPD) o (ove applicabile) dal regolamento generale dell'UE sulla protezione dei dati (GDPR) o dal diritto cantonale applicabile in materia di protezione dei dati.
1.3.3. «Messa a disposizione standard» designa la messa a disposizione di FORTCONTROL sull'infrastruttura cloud descritta alla cifra 2.7.2, tabella A, con localizzazione dei dati in Svizzera. «Swiss Deployment Option» designa la messa a disposizione di FORTCONTROL sull'infrastruttura descritta alla cifra 2.7.2, tabella B, in cui infrastruttura, esercizio e invio di e-mail sono assicurati esclusivamente in Svizzera da fornitori con sede in Svizzera. La variante di messa a disposizione applicabile al cliente risulta dal Contratto; in assenza di un accordo esplicito si applica la messa a disposizione standard.
2.1.1. Oggetto e scopo del trattamento per conto terzi è la messa a disposizione di FORTCONTROL sotto forma di software as a service (SaaS) al cliente, comprese le prestazioni connesse quali esercizio, manutenzione, supporto e salvataggio dei dati nonché – se attivate dal cliente – le funzioni di IA opzionali secondo la cifra 3.7 delle Condizioni di utilizzo.
2.1.2. Il trattamento per conto terzi riguarda i tipi di dati personali caricati, inseriti, forniti, memorizzati o trattati dal cliente o dai suoi utenti nell'utilizzo di FORTCONTROL («dati personali contrattuali»). Vi rientrano tipicamente indicazioni relative agli utenti (nome, indirizzo e-mail, ruolo), ai collaboratori e alle persone di contatto del cliente nonché ad altre persone menzionate negli oggetti da proteggere, nei rischi, nelle misure, negli audit o nei documenti del cliente. I dettagli relativi ai dati personali contrattuali e alla cerchia (categorie) delle persone interessate risultano dal Contratto e dalle descrizioni delle prestazioni, in combinazione con eventuali istruzioni separate del cliente.
2.1.3. Il trattamento per conto terzi consiste nella memorizzazione, messa a disposizione, salvataggio e visualizzazione dei dati personali contrattuali nell'ambito della fornitura delle prestazioni SaaS al cliente, nonché nell'accesso a tali dati nella misura necessaria per supporto, correzione di errori e manutenzione e su iniziativa del cliente. Se il cliente ha attivato funzioni di IA, il trattamento comprende inoltre la trasmissione dei contenuti selezionati dall'utente al fornitore di IA secondo la cifra 2.7.2, tabella C, ai fini dell'analisi automatizzata e della generazione di proposte. La trasmissione avviene solo per la rispettiva richiesta; una conservazione presso il fornitore di IA oltre un eventuale controllo degli abusi di breve durata e un utilizzo per l'addestramento di modelli di IA sono contrattualmente esclusi.
2.1.4. Il luogo del trattamento per conto terzi dipende dalla variante di messa a disposizione convenuta: (a) Nella messa a disposizione standard, i dati personali contrattuali sono memorizzati in Svizzera; singoli subresponsabili possono trattare dati in Stati dell'UE/del SEE o negli USA nell'ambito di prestazioni di supporto, manutenzione o invio. (b) Nella Swiss Deployment Option, memorizzazione, esercizio e invio di e-mail avvengono esclusivamente in Svizzera da parte di fornitori con sede in Svizzera; senza il consenso scritto esplicito del cliente non ha luogo alcun trattamento al di fuori della Svizzera. Unica eccezione sono le funzioni di IA opzionali: se un amministratore del cliente le attiva, i contenuti selezionati a tale scopo sono trattati, in entrambe le varianti di messa a disposizione, dal fornitore di IA indicato nella cifra 2.7.2, tabella C, nell'UE (Francia) – solo per la rispettiva richiesta e senza addestramento con dati dei clienti; l'attivazione vale quale consenso e istruzione espliciti del cliente per tale trattamento.
2.1.5. La durata del trattamento è determinata dalla cifra 1.2.
2.2.1. FortIT si impegna e garantisce che FortIT tratta tutti i dati personali contrattuali (i) esclusivamente per gli scopi descritti alla cifra 2.1, (ii) conformemente al Contratto e alle istruzioni documentate del cliente nonché (iii) conformemente al presente Allegato, e (iv) non li utilizza altrimenti per scopi propri.
2.2.2. Le istruzioni del cliente sono impartite a FortIT per iscritto o in forma di testo (p. es. e-mail, ticket di supporto). Se FortIT ritiene che un'istruzione violi il diritto applicabile in materia di protezione dei dati, FortIT ne informa senza indugio il cliente ed è autorizzata a sospendere l'esecuzione dell'istruzione fino alla sua conferma o modifica da parte del cliente.
2.2.3. Il cliente rimane responsabile della liceità del trattamento dei dati personali contrattuali, in particolare dell'esistenza di una base legale e della tutela dei diritti delle persone interessate.
2.3.1. FortIT si impegna ad adottare misure di protezione tecniche e organizzative adeguate nell'interesse della confidenzialità, dell'integrità e della disponibilità conforme al contratto dei dati personali contrattuali.
2.3.2. A tal fine FortIT attua in particolare controlli degli accessi fisici, controlli degli accessi logici basati sui ruoli e sul principio need-to-know, cifratura della trasmissione dei dati e dei dati memorizzati, registrazione (logging), salvataggi regolari dei dati nonché procedure per testare, verificare e valutare regolarmente l'efficacia delle misure tecniche e organizzative. Nella scelta delle misure FortIT tiene conto dello stato della tecnica, dei costi di attuazione nonché della natura, dell'ampiezza, del contesto e degli scopi del trattamento, come pure della diversa probabilità e gravità del rischio per le persone interessate.
2.3.3. La descrizione aggiornata delle misure tecniche e organizzative (TOM) è disponibile all'indirizzo https://www.fortcontrol.swiss/tom/ e costituisce parte integrante del presente Allegato; su richiesta FortIT la mette a disposizione del cliente anche per iscritto. FortIT può sviluppare ulteriormente le misure, purché il livello di protezione convenuto non venga ridotto.
2.4.1. Se FortIT rileva una violazione della sicurezza consistente nel fatto che dati personali contrattuali vengono involontariamente o illecitamente persi, cancellati, distrutti o modificati oppure divulgati o resi accessibili a persone non autorizzate («violazione della sicurezza dei dati»), FortIT notifica la violazione della sicurezza dei dati al cliente il più rapidamente possibile e senza ritardo colpevole, di regola entro 48 ore dalla presa di conoscenza. FortIT provvede quindi (i) a esaminare la violazione della sicurezza dei dati e a determinarne gli effetti, (ii) a informare dettagliatamente il cliente sulla violazione della sicurezza dei dati, (iii) ad adottare misure adeguate per attenuarne gli effetti e ridurre al minimo il rischio che può derivarne per le persone interessate, e (iv) a documentare l'incidente.
2.4.2. FortIT assiste il cliente in modo adeguato nell'adempimento dei suoi obblighi di notifica delle violazioni della sicurezza dei dati alle autorità di vigilanza competenti o alle persone interessate.
2.5.1. FortIT si impegna a informare il cliente il più rapidamente possibile e di propria iniziativa (i) se FortIT ritiene che FortIT non sarà più in grado, in un futuro prevedibile, di adempiere agli obblighi derivanti dal presente Allegato; (ii) su qualsiasi richiesta di esercizio dei diritti delle persone interessate che FortIT ha ricevuto direttamente da persone interessate in relazione a dati personali contrattuali (a condizione che FortIT possa attribuirla al cliente sulla base delle indicazioni della persona interessata; in caso contrario FortIT inviterà la persona interessata a rivolgersi al titolare del trattamento dei dati); nonché (iii) su richieste o ordini di autorità o tribunali concernenti dati personali contrattuali, nella misura in cui tale informazione sia legalmente ammissibile.
2.5.2. Su richiesta e contro remunerazione separata, FortIT assiste il cliente nel rispondere alle richieste delle persone interessate relative all'esercizio dei loro diritti in materia di protezione dei dati.
2.5.3. Inoltre, su richiesta e contro remunerazione separata, FortIT assiste il cliente nelle valutazioni d'impatto sulla protezione dei dati e nelle consultazioni preliminari delle autorità di vigilanza sulla protezione dei dati.
2.5.4. FortIT mette a disposizione del cliente tutte le informazioni di cui questi ha ragionevolmente bisogno per dimostrare il rispetto dei propri obblighi derivanti dal diritto applicabile in materia di protezione dei dati in relazione al trattamento per conto terzi.
2.6.1. FortIT si impegna a mantenere confidenziali i dati personali contrattuali e deve obbligare per iscritto le persone incaricate del trattamento per conto terzi al rispetto della confidenzialità e istruirle sugli obblighi applicabili in materia di protezione dei dati.
2.6.2. Tali obblighi di confidenzialità permangono per una durata illimitata dopo la fine del Contratto.
2.7.1. I subresponsabili sono persone fisiche o giuridiche cui FortIT ricorre per il trattamento per conto terzi. FortIT è autorizzata a ricorrere a subresponsabili. In tali casi FortIT è tenuta a concludere con i subresponsabili un accordo sul (sub)trattamento che consenta a FortIT di rispettare le disposizioni del presente Allegato, compresi gli obblighi di confidenzialità di FortIT. Con i fornitori di servizi standardizzati (in particolare fornitori di cloud, infrastruttura e piattaforma) FortIT non può negoziare contratti individuali; fanno stato i loro accordi standardizzati sul trattamento dei dati. In tali casi FortIT garantisce che le misure tecniche e organizzative, le misure di protezione di base o le altre prescrizioni del subresponsabile assicurino un livello di protezione almeno equivalente alle TOM. FortIT rimane responsabile nei confronti del cliente per le prestazioni dei subresponsabili come per le proprie prestazioni.
2.7.2. A seconda della variante di messa a disposizione convenuta, FortIT ricorre ai seguenti subresponsabili. I subresponsabili secondo la tabella C sono coinvolti solo se un amministratore del cliente ha attivato le funzioni di IA secondo la cifra 3.7 delle Condizioni di utilizzo; senza attivazione non ha luogo alcuna comunicazione di dati personali contrattuali a tali subresponsabili. La tabella C si applica a entrambe le varianti di messa a disposizione: anche con la Swiss Deployment Option il trattamento è effettuato dal fornitore di IA nell'UE (Francia), solo per la rispettiva richiesta e senza addestramento con dati dei clienti. Le funzioni di IA presuppongono pertanto in ogni caso l'attivazione esplicita da parte di un amministratore del cliente. Si applicano le seguenti tabelle:
Tabella A – Messa a disposizione standard
| Nome | Paese di trattamento | Descrizione |
|---|---|---|
| Microsoft Azure (Microsoft Ireland Operations Limited, Irlanda) | Svizzera (ubicazione dei dati) | Fornitore di infrastruttura, hosting di applicazioni, memorizzazione dei dati, elaborazione dei dati |
| MongoDB Atlas (MongoDB Limited, Irlanda) | Svizzera (ubicazione dei dati) | Banca dati e memorizzazione dei dati |
| SendGrid (Twilio Ireland Limited, Irlanda) | UE | Invio di notifiche e-mail |
Tabella B – Swiss Deployment Option
| Nome | Paese di trattamento | Descrizione |
|---|---|---|
| cloudscale.ch AG, Neugasse 6, 8005 Zurigo | Svizzera | Fornitore di infrastruttura (infrastruttura cloud, centri di calcolo esclusivamente in Svizzera), memorizzazione dei dati |
| [to be announced] | Svizzera | Messa a disposizione ed esercizio di managed services (esercizio della piattaforma, banca dati, salvataggio dei dati, monitoraggio) |
| mailomat (mailXpert GmbH, Schulstrasse 37, 8050 Zurigo) | Svizzera | Invio di notifiche e-mail |
Tabella C – Funzioni di IA opzionali (solo dopo attivazione da parte del cliente)
| Nome | Paese di trattamento | Descrizione |
|---|---|---|
| Mistral AI, SAS, 15 rue des Halles, 75001 Parigi, Francia | UE (Francia) | Gestione dei modelli linguistici di IA per le funzioni di IA di FORTCONTROL; trattamento solo per la rispettiva richiesta, nessun addestramento con dati dei clienti |
2.7.3. FortIT informa il cliente per iscritto, in modo adeguato e con sufficiente anticipo, se FortIT intende, dopo l'entrata in vigore del Contratto, ricorrere a nuovi subresponsabili o sostituire quelli esistenti. Se il cliente non si oppone per iscritto al ricorso al subresponsabile o alla sua sostituzione entro trenta (30) giorni dalla data della comunicazione, il subresponsabile nuovo o sostitutivo è considerato approvato. Se il cliente si oppone per motivi fondati attinenti alla protezione dei dati, le parti si adoperano per trovare una soluzione consensuale; in mancanza di tale soluzione, ciascuna parte può disdire il Contratto relativamente alla prestazione interessata con effetto alla data prevista per il ricorso.
2.7.4. L'elenco aggiornato dei subresponsabili è disponibile all'indirizzo https://www.fortcontrol.swiss/avv/.
2.7.5. Se il cliente impiega propri agenti di IA o altri sistemi che accedono ai dati personali contrattuali tramite le interfacce di FORTCONTROL (cifra 3.12 delle Condizioni di utilizzo), non si tratta di subresponsabili di FortIT. Il cliente è l'unico responsabile di tali sistemi, dei loro fornitori e del trattamento dei dati ivi effettuato e conclude autonomamente i contratti di trattamento dei dati per conto terzi necessari.
2.8.1. Il cliente è autorizzato a verificare il rispetto del presente Allegato da parte di FortIT. FortIT fornisce la prova in primo luogo mettendo a disposizione documenti idonei, in particolare la descrizione delle misure tecniche e organizzative, rapporti di verifica, certificazioni o attestazioni dei suoi subresponsabili, nonché rispondendo alle domande scritte del cliente.
2.8.2. Nella misura in cui tali prove siano dimostrabilmente insufficienti per il cliente o un'autorità di vigilanza lo richieda, il cliente può effettuare una verifica presso FortIT, o farla effettuare da un esperto indipendente vincolato alla confidenzialità, al massimo una volta per anno civile e inoltre per motivi fondati (in particolare dopo una violazione della sicurezza dei dati). La verifica deve essere annunciata per iscritto con almeno trenta (30) giorni di anticipo, essere effettuata durante i normali orari d'ufficio ed essere organizzata in modo da non pregiudicare l'attività di FortIT né la confidenzialità dei dati di altri clienti. Il cliente sostiene i costi sostenuti da FortIT per la verifica; essi sono remunerati in base al tempo impiegato a CHF 230 all'ora (IVA esclusa), a meno che la verifica non riveli violazioni sostanziali del presente Allegato.
2.9.1. Dopo la fine del Contratto, FortIT cancella i dati personali contrattuali conformemente alle relative disposizioni del Contratto oppure, se il cliente lo desidera, li restituisce al cliente in un formato comune e leggibile meccanicamente. Salvo diversa disposizione del Contratto, i dati sono cancellati irrevocabilmente 90 giorni dopo la fine del Contratto; entro tale termine il cliente può chiederne la restituzione. Restano riservati gli obblighi legali di conservazione di FortIT. Su richiesta, FortIT conferma per iscritto al cliente la cancellazione.
3.1.1. Le disposizioni della presente cifra 3 si applicano se il cliente è un organo pubblico soggetto al diritto sulla protezione dei dati di un Cantone o di un Comune o al diritto sulla protezione dei dati della Confederazione. Esse concretizzano i contenuti minimi che il diritto pubblico applicabile in materia di protezione dei dati prescrive per gli accordi sul trattamento per conto terzi e integrano le altre disposizioni del presente Allegato.
3.2.1. Oggetto, natura, ampiezza e scopo del trattamento per conto terzi nonché le categorie di dati personali contrattuali e di persone interessate risultano dalla cifra 2.1 e dal Contratto. Il cliente può precisare tali indicazioni in una descrizione delle prestazioni o in istruzioni scritte.
3.2.2. In quanto organo responsabile, il cliente rimane responsabile della liceità del trattamento dei dati, della tutela dei diritti delle persone interessate e dell'adempimento dei propri obblighi legali di informazione e di notifica. FortIT tratta i dati personali contrattuali esclusivamente per conto e secondo le istruzioni del cliente e soltanto nel modo in cui il cliente stesso sarebbe autorizzato a farlo.
3.3.1. FortIT prende atto che i dati personali contrattuali possono essere soggetti al segreto d'ufficio nonché, eventualmente, ad altri obblighi legali particolari di confidenzialità (p. es. segreto fiscale, segreto dell'aiuto sociale, segreto professionale). FortIT si impegna a rispettare il segreto d'ufficio e tali obblighi particolari di confidenzialità nella stessa misura in cui essi si applicano al cliente e ai suoi collaboratori, ed è consapevole che le violazioni del segreto d'ufficio possono essere punibili ai sensi dell'art. 320 del Codice penale svizzero.
3.3.2. FortIT vincola per iscritto, prima dell'inizio della loro attività, tutti i collaboratori e gli ausiliari che possono avere accesso a dati personali contrattuali al segreto d'ufficio e agli obblighi particolari di confidenzialità, e su richiesta ne fornisce prova al cliente.
3.3.3. L'accesso ai dati personali contrattuali è limitato ai collaboratori di FortIT che ne hanno imperativamente bisogno per l'esecuzione del Contratto. Gli obblighi di confidenzialità permangono oltre la fine del Contratto per una durata illimitata.
3.4.1. Per gli organi pubblici FortIT raccomanda la Swiss Deployment Option. Se questa è convenuta, tutti i trattamenti dei dati personali contrattuali, compresi salvataggio dei dati, esercizio, supporto e invio di e-mail, avvengono esclusivamente in Svizzera da parte di subresponsabili con sede in Svizzera conformemente alla cifra 2.7.2, tabella B. Non ha luogo alcuna comunicazione all'estero.
3.4.2. Se è convenuta la messa a disposizione standard, i dati personali contrattuali sono memorizzati in Svizzera; il cliente prende atto che singoli subresponsabili secondo la cifra 2.7.2, tabella A, possono accedere ai dati dall'estero nell'ambito di prestazioni di supporto e manutenzione. Qualsiasi ulteriore trasferimento del luogo di trattamento all'estero richiede il previo consenso scritto del cliente.
3.4.3. Per i clienti ai sensi della presente cifra 3, le funzioni di IA secondo la cifra 2.7.2, tabella C, possono essere attivate solo se il cliente ha esaminato la comunicazione al fornitore di IA nell'UE (Francia) secondo le prescrizioni a lui applicabili e l'ha approvata per iscritto; ciò vale anche per la Swiss Deployment Option. È fatta salva la cifra 3.6.1. L'attivazione da parte di un amministratore del cliente vale quale conferma che tali presupposti sono soddisfatti.
3.5.1. A complemento della cifra 2.8, FortIT concede al cliente nonché all'autorità di vigilanza sulla protezione dei dati competente per il cliente il diritto di controllare il rispetto delle prescrizioni in materia di protezione dei dati e del presente Allegato. A tal fine FortIT concede, con ragionevole preavviso, l'accesso ai documenti, ai sistemi e ai locali pertinenti nella misura necessaria al controllo, e fornisce le informazioni necessarie. I costi sostenuti da FortIT per la preparazione, l'accompagnamento e il follow-up di tali controlli sono remunerati dal cliente in base al tempo impiegato a CHF 230 all'ora (IVA esclusa); ciò vale anche per i controlli dell'autorità di vigilanza sulla protezione dei dati, a meno che il controllo non riveli violazioni sostanziali del presente Allegato.
3.5.2. FortIT informa senza indugio il cliente sui controlli di autorità di vigilanza concernenti il trattamento per conto del cliente, nella misura in cui ciò sia legalmente ammissibile.
3.6.1. In deroga alla cifra 2.7.3, il ricorso a un subresponsabile o la sua sostituzione richiede, per i clienti di cui alla presente cifra 3, il previo consenso scritto del cliente. I subresponsabili della variante di messa a disposizione convenuta elencati alla cifra 2.7.2 sono considerati approvati con la conclusione del Contratto. Il cliente rifiuta il consenso soltanto per motivi oggettivi attinenti alla protezione dei dati.
3.6.2. FortIT garantisce che i propri subresponsabili siano soggetti a obblighi almeno equivalenti a quelli derivanti dal presente Allegato, inclusa la confidenzialità. Con i fornitori di servizi standardizzati ai sensi della cifra 2.7.1 FortIT non può concludere contratti individuali; in tali casi FortIT garantisce che le loro misure tecniche e organizzative, misure di protezione di base o altre prescrizioni assicurino un livello di protezione almeno equivalente alle TOM. FortIT rimane responsabile nei confronti del cliente del rispetto da parte dei propri subresponsabili.
3.7.1. Se FortIT viola colpevolmente un obbligo essenziale del presente Allegato, in particolare gli obblighi relativi al vincolo alle istruzioni (cifra 2.2), alla sicurezza dei dati (cifra 2.3), alla confidenzialità e al rispetto del segreto d'ufficio (cifre 2.6 e 3.3), al luogo del trattamento dei dati (cifra 3.4) o al ricorso a terzi (cifra 3.6), FortIT deve al cliente, per ogni caso di violazione, una pena convenzionale pari al 10 per cento delle tariffe d'utilizzo dovute per l'anno contrattuale in corso. Il pagamento della pena convenzionale non libera FortIT dall'adempimento dei propri obblighi. Resta riservata la pretesa di un risarcimento più ampio; la pena convenzionale è computata nel risarcimento del danno.
3.7.2. In caso di violazione essenziale degli obblighi, il cliente è inoltre autorizzato a disdire il Contratto con effetto immediato e senza conseguenze di costo. Le tariffe già pagate in anticipo per il periodo successivo alla disdetta sono rimborsate proporzionalmente. In caso di altre violazioni, il cliente fissa a FortIT un termine adeguato per porvi rimedio; decorso infruttuosamente tale termine, il cliente può parimenti disdire il Contratto con effetto immediato.
3.7.3. Il cliente può inoltre ordinare a FortIT di sospendere in tutto o in parte il trattamento dei dati personali contrattuali fino a quando la violazione degli obblighi non sia stata rimediata. I diritti e gli obblighi alla fine del contratto secondo la cifra 3.8 si applicano anche in caso di disdetta ai sensi della presente cifra.
3.8.1. La durata del presente Allegato è determinata dalla cifra 1.2. Alla fine del Contratto, indipendentemente dal motivo, FortIT restituisce al cliente, su sua richiesta, tutti i dati personali contrattuali entro trenta (30) giorni in un formato comune e leggibile meccanicamente e cancella successivamente, al più tardi però novanta (90) giorni dopo la fine del Contratto, tutte le copie presenti presso di sé e presso i propri subresponsabili, salvo che vi si opponga un obbligo legale di conservazione. Le copie contenute nei salvataggi vengono sovrascritte nell'ambito dei regolari cicli di conservazione e cancellazione di FortIT e dei propri subresponsabili ai sensi della cifra 6.2 TOM; fino ad allora non vengono né ripristinate né ulteriormente trattate. FortIT conferma per iscritto al cliente la cancellazione completa.
3.9.1. Al presente Allegato si applica il diritto svizzero. Gli obblighi di FortIT in materia di protezione dei dati sono inoltre disciplinati dal diritto pubblico sulla protezione dei dati applicabile al cliente, nella misura in cui questo sia imperativamente applicabile ai responsabili del trattamento. Il foro è la sede del cliente, salvo diversa disposizione del Contratto.
4.1. Le modifiche e le integrazioni del presente Allegato richiedono la forma scritta. FortIT può adeguare il presente Allegato qualora ciò sia necessario a causa di prescrizioni legali modificate o di subresponsabili modificati; FortIT ne informa il cliente per iscritto e in anticipo. Si applica di volta in volta la versione disponibile all'indirizzo https://www.fortcontrol.swiss/avv/, salvo diverso accordo tra le parti.
4.2. Qualora una disposizione del presente Allegato sia o divenga inefficace o inapplicabile, la validità delle restanti disposizioni non ne è pregiudicata. Le parti sostituiscono la disposizione inefficace con una disposizione efficace che si avvicini il più possibile allo scopo della disposizione inefficace.
4.3. Al presente Allegato si applica il diritto svizzero. Il foro è Zurigo, Svizzera, salvo che la cifra 3.9 o disposizioni legali imperative prevedano altrimenti.
4.4. Il presente Allegato è redatto in lingua tedesca. Le traduzioni servono unicamente a scopo informativo; in caso di divergenze fa stato la versione tedesca.
Lernen Sie fortControl in einer persönlichen Demo kennen.
fortControl – Risikomanagement und Informationssicherheit einfach steuern.