Legal
Data processing agreement (DPA)
As of September 2026
This is a translation for your convenience. Only the German version is legally binding.
1. Subject matter
This data processing agreement (DPA) governs the processing of personal data by Elevate Page (Vincent Schmid, hereinafter “provider”) as processor on behalf of the customer as controller within the meaning of Art. 9 of the Swiss Federal Act on Data Protection (FADP). It forms part of the general terms and conditions.
The DPA applies to all personal data the customer enters in Elevate Page or that arrives through the customer’s websites, insofar as the provider acts on instructions.
2. Nature and purpose of the processing
The provider processes personal data to provide the platform, to host, maintain and secure the customer’s websites and to carry out the functions used by the customer.
This concerns in particular:
- content of the customer’s websites (texts, images, contact details)
- enquiries via contact forms (e.g. name, email address, phone number, message)
- appointments, course registrations and waiting lists (e.g. name, contact details, booked service, note)
- orders in the online shop (e.g. name, delivery and billing address, email address, ordered products, payment status)
- visitor statistics of the websites (without IP addresses and without cookies)
Data subjects are the visitors of the customer’s websites, the customer’s clients and the customer’s employees.
3. Instructions of the customer
The provider processes personal data exclusively on the customer’s documented instructions, unless mandatory legal provisions require other processing. The customer’s settings and actions in the platform in particular count as instructions.
The customer is responsible for being entitled to process the data concerned, for the processing on their instructions remaining lawful and for informing the data subjects in the privacy policy of their website.
4. Technical and organisational measures
The provider uses appropriate technical and organisational measures to ensure the confidentiality, integrity, availability and resilience of the systems (Art. 8 FADP).
These include in particular access controls and an authorisation concept, logging of security-relevant events, encrypted transmission (TLS), storage of passwords as a secure hash, operation of the servers in Switzerland and regular backups.
5. Sub-processors
The provider may use suitable sub-processors to operate the platform, provided they are subject to the same data protection obligations and the disclosure of the data is necessary to provide the service. Currently these are:
- Hosting: servers in a data centre in Switzerland
- Email delivery: Infomaniak Network SA, Geneva (Switzerland)
If the customer uses optional functions such as card payments (Stripe) or automatic translation (DeepL), the data required for this is transmitted to these providers; details are set out in the privacy policy. The provider informs the customer in advance of planned changes to the sub-processors.
6. Rights of data subjects
The customer remains responsible for the rights of the data subjects. Within the technical possibilities, the provider supports the customer with requests for access, rectification, erasure and data portability. The customer can view, export and delete much of the data directly in the platform.
7. Notification of data security breaches
The provider informs the customer without delay if it becomes aware of a data security breach affecting the customer’s personal data and supports the customer with any notification obligations (Art. 24 FADP).
8. Termination
After termination of the contractual relationship, the provider deletes the customer’s personal data or returns it according to the customer’s instructions, unless there is a statutory obligation to retain it. If the customer deletes their account themselves, the data is deleted immediately; it remains in backup copies for at most 30 days.