Data Processing Agreement (DPA)
This document is provided as a template for demonstration purposes and does not constitute legal advice.
Last updated: 2026-07-26
This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Customer") and the applicable Wahlen Software contracting entity ("Processor") for the provision of the merlon service. It governs the Processor's processing of personal data on the Customer's behalf under the nFADP, GDPR, and other applicable data protection laws.
1. Roles (controller / processor)
For personal data contained in Customer Content, the Customer acts as the controller (or processor on behalf of a third-party controller), and Wahlen Software acts as the processor (or sub-processor). Each party will comply with its respective obligations under applicable data protection law. Where Wahlen Software determines the means and purposes of processing (for example, for its own account administration), it acts as an independent controller as described in the Privacy Policy.
2. Subject-matter & duration
The subject-matter of processing is the provision of the merlon service. Processing continues for the duration of the subscription term and any wind-down period, after which personal data is deleted or returned in accordance with Section 10.
3. Nature & purpose
The Processor processes personal data to host, store, transmit, secure, and otherwise make available the documents, vaults, workflows, and audit records that the Customer creates within the Service, and to provide support, in each case in accordance with the Customer's documented instructions.
4. Categories of data subjects & personal data
- Data subjects — the Customer's employees, contractors, counterparties, and any individuals whose personal data appears in Customer Content.
- Categories of personal data — identity and contact details, professional information, and any personal data the Customer chooses to include in documents and files. Special categories of data may be processed if the Customer includes them; the Customer is responsible for ensuring an appropriate legal basis.
5. Processor obligations
- process personal data only on documented instructions from the Customer;
- ensure persons authorised to process data are bound by confidentiality;
- implement the technical and organisational measures set out in Section 7 and the Annexes;
- assist the Customer in meeting its obligations, taking into account the nature of processing;
- not engage sub-processors except as permitted under Section 6.
6. Sub-processors
The Customer provides general authorisation for the Processor to engage sub-processors, provided the Processor imposes data protection obligations no less protective than this DPA and remains responsible for their performance. The current list of sub-processors is maintained in our Trust Center. The Processor will give notice of intended changes and provide an opportunity to object on reasonable data protection grounds.
7. Security measures
The Processor maintains appropriate technical and organisational measures, described in Annex A below and on our Security & Compliance page, including AES-256 encryption at rest, TLS 1.2+ in transit, MFA/SSO, least-privilege access, network segmentation, logging, and 24/7 monitoring by in-house Blue and Purple Teams.
8. Data subject assistance
Taking into account the nature of the processing, the Processor will assist the Customer by appropriate technical and organisational measures, insofar as possible, in responding to requests from data subjects exercising their rights (access, rectification, deletion, portability, objection, and restriction).
9. Breach notification
The Processor will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Content, and will provide information reasonably necessary to enable the Customer to meet its own breach-notification obligations to supervisory authorities and data subjects.
10. Deletion & return
Upon termination or expiry of the Service, the Processor will, at the Customer's choice, delete or return all personal data and delete existing copies, unless applicable law requires continued storage. A limited export window is provided before deletion.
11. Audit rights
The Processor will make available information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer, subject to reasonable confidentiality and security safeguards. Where available, third-party audit reports and certifications may be provided to satisfy audit requests.
12. International transfers
Where processing involves a transfer of personal data across borders, the parties rely on the mechanisms set out in the Annexes: the Swiss–US and EU–US Data Privacy Frameworks, and Standard Contractual Clauses (with the Swiss addendum) as a fallback. Customer Content is stored in the data residency region matching the Customer's account.
Annex A — EU / CH (SCCs + Swiss addendum)
For transfers of personal data from the EEA or Switzerland that are not covered by an adequacy decision or the applicable DPF, the parties incorporate the EU Standard Contractual Clauses (Module Two: controller-to-processor), completed as follows, together with the Swiss addendum recognising the FDPIC as competent authority and referencing the nFADP:
- Data exporter: the Customer. Data importer: the Processor.
- Governing law / forum: as specified in the SCCs, aligned with Swiss law where the Swiss addendum applies.
- Technical & organisational measures: AES-256 at rest, TLS 1.2+ in transit, MFA/SSO, least-privilege access, segmentation, continuous monitoring, and documented incident response.
Annex B — US (DPF commitments)
For transfers to the United States, the Processor relies on its participation in (and self-certification under) the EU–US Data Privacy Framework and the Swiss–US Data Privacy Framework, and commits to the DPF Principles including notice, choice, accountability for onward transfer, security, data integrity and purpose limitation, access, and recourse, enforcement and liability. Where the DPF is unavailable, the SCCs in Annex A apply as a fallback.
Contracting entity by region
EU / EFTA / Switzerland / Rest of World: the Processor is Wahlen Software GmbH (Zürich, Switzerland, UID CHE-139.189.280).