This Data Processing Agreement ("DPA", Auftragsbearbeitungsvereinbarung) is entered into between the Customer and the operator of Cogniten named in the imprint ("Cogniten") and forms part of the Terms & Conditions. It applies whenever Cogniten processes personal data on behalf of the Customer in providing the Service. Capitalised terms not defined here have the meaning given in the Terms. An individually negotiated data processing agreement takes precedence over this DPA to the extent it deviates from it.
1. Roles and applicable law
For personal data contained in Customer Content, the Customer is the controller and Cogniten processes that data as a processor on the Customer's behalf within the meaning of the Swiss Federal Act on Data Protection ("FADP") and, where applicable, Art. 28 of the EU General Data Protection Regulation ("GDPR"). For account, billing, usage and security data that Cogniten processes for its own purposes, Cogniten is itself the controller; the Privacy & Data Protection information applies to that processing.
2. Subject matter, duration, nature and purpose
The subject matter of the processing is the provision of the Service to the Customer as described in the Terms. Processing lasts for the term of the agreement and, after it ends, until the Customer Content has been deleted in accordance with section 12. The nature and purposes of the processing, the categories of personal data and the categories of data subjects are described in Annex 1.
3. Documented instructions
Cogniten processes personal data only on the Customer's documented instructions. The Terms, this DPA and the Customer's use and configuration of the Service (for example, the documents it uploads, the requests its Users submit, the retention period it selects and the members it admits) constitute the Customer's complete instructions at the time of conclusion. Further instructions must be given in writing (email is sufficient) and must be consistent with the Terms and the functionality of the Service. Cogniten informs the Customer if it considers that an instruction infringes applicable data-protection law. Cogniten may process personal data otherwise only where required by applicable law; in that case it informs the Customer beforehand unless the law prohibits this.
4. Customer's responsibilities
As controller, the Customer decides what personal data it submits and ensures that the processing it instructs is lawful — including a legal basis, informing data subjects where required, and being permitted to disclose information subject to professional secrecy or other confidentiality obligations to a service provider. Cogniten remains responsible for its own obligations under this DPA and applicable law.
5. Confidentiality
Cogniten ensures that persons it authorises to process personal data are bound to confidentiality by contract or by statutory obligation, and that they access Customer Content only to the extent necessary to provide, maintain, secure and support the Service, or where required by law.
6. Security
Cogniten implements appropriate technical and organisational measures designed to protect personal data against unauthorised access, alteration, loss and disclosure, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing and the risks to data subjects. The measures in place are described in Annex 2. Cogniten may adapt the measures as technology develops, provided that the overall level of protection is not reduced. No electronic or internet-based system can guarantee absolute security.
7. Subprocessors
The Customer grants Cogniten a general authorisation to engage subprocessors. The categories of subprocessors engaged at any time, with their purposes and the data concerned, are listed in the subprocessor register, which forms part of this DPA. Cogniten discloses the identity of its subprocessors and their processing locations to the Customer on request. Cogniten concludes a written agreement with each subprocessor that imposes data-protection obligations providing a level of protection substantially equivalent to this DPA, and remains responsible to the Customer for the performance of its subprocessors' obligations in accordance with the Terms.
8. Changes to subprocessors
Cogniten informs the Customer of any intended addition or replacement of a subprocessor by notifying the owners of the Customer's workspace by email (and disclosing the identity of the new subprocessor on request), generally at least 30 days before the new subprocessor begins processing Customer personal data. Where a change is urgently required for security, legal or operational reasons, the notice may be shorter. The Customer may object in writing within 14 days of the notice on reasonable grounds relating to data protection. The parties will then discuss the objection in good faith. If no solution is found within a reasonable period, either party may terminate the affected part of the Service with effect from the date the change takes effect, and Cogniten refunds any prepaid fees for the period after termination. Changes of infrastructure that do not involve a new subprocessor do not require notice.
9. International transfers
Depending on the services and infrastructure used, personal data may be processed in countries outside Switzerland, including countries that the Swiss Federal Council has not recognised as providing an adequate level of data protection (for example, the United States). Where personal data is disclosed to such a country, Cogniten ensures appropriate safeguards as required by the FADP and, where applicable, the GDPR — in particular standard contractual clauses recognised by the Federal Data Protection and Information Commissioner (FDPIC) or the European Commission — or relies on an exception provided by law. Details of the countries concerned are available on request.
10. Assistance
- Data subject requests. Taking into account the nature of the processing, Cogniten assists the Customer with appropriate measures in responding to requests from data subjects exercising their rights. The Service allows Users to view, export and delete their chats and documents, and the Customer to manage its members and workspace. If a data subject contacts Cogniten directly about Customer Content, Cogniten refers them to the Customer where the Customer can be identified.
- Other assistance. Cogniten provides the Customer with the information reasonably necessary for data protection impact assessments and prior consultations with supervisory authorities relating to the Service, to the extent the Customer does not have access to that information itself.
- Assistance beyond what the Service provides as standard may be charged at reasonable rates, unless it is necessary because of a breach of Cogniten's obligations.
11. Security incidents
Cogniten notifies the Customer without undue delay after becoming aware of a breach of data security affecting Customer personal data (a "Security Incident"). The notification describes, to the extent known, the nature of the incident, the categories and approximate number of data subjects and records concerned, its likely consequences and the measures taken or proposed. Information may be provided in stages. Cogniten takes reasonable steps to contain and remedy the incident and supports the Customer in meeting its own notification obligations. A notification is not an acknowledgement of fault or liability.
12. Deletion and return
During the term, the Customer and its Users can delete Customer Content in the Service at any time, export their chats and personal documents, and download the documents stored in the Service. Owners can delete the entire workspace, which deletes its Customer Content.
When the agreement ends, the Customer decides whether to take its Customer Content along or have it deleted: after the end of a subscription, owners and administrators can still export their data, and the Customer can delete the workspace itself or ask Cogniten in writing to delete it. Cogniten deletes the Customer Content within 30 days after the workspace is deleted or after receiving the Customer's written request, unless applicable law requires further storage. Cogniten may delete the workspace of an agreement that ended more than 12 months earlier after informing its owners in advance. Where backups exist, residual copies are deleted in the regular backup cycle and remain protected in the meantime. Records that Cogniten must keep for its own legal obligations or as evidence (such as billing records and records of acceptance of the Terms) are not Customer Content and are kept as described in the privacy information.
13. Information and audits
Cogniten makes available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, in the first instance through this DPA, its annexes, the subprocessor register and written answers to reasonable questions. Where this information is not sufficient, or where a supervisory authority requires it, the Customer may have an audit carried out, at its own cost, by itself or an independent auditor bound to confidentiality who is not a competitor of Cogniten, with at least 30 days' written notice, no more than once per year (except after a Security Incident or at the request of an authority), during normal business hours and without undue disruption of operations or access to other customers' data. Cogniten may charge reasonable costs for its own effort.
14. Term, liability and precedence
This DPA applies for as long as Cogniten processes personal data on behalf of the Customer. The limitations of liability in the Terms apply to this DPA, except where mandatory law provides otherwise. In the event of a conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails. Cogniten may amend this DPA in accordance with the change provisions of the Terms; material changes that reduce the protection of personal data require the Customer's acceptance. Swiss law applies and the place of jurisdiction is as set out in the Terms.
Annex 1 — Details of the processing
- Nature and purpose: storing, indexing, searching, analysing, summarising and otherwise processing Customer Content to provide the functions of the Service requested by the Customer and its Users — including AI-assisted answers, research, drafting, document and financial-statement analysis, calculations, document generation, sharing and forwarding within the workspace — and securing, maintaining and supporting the Service.
- Processing activities: storing Customer Content and the text extracted from it (including text recognised in scans and images); building search indexes of documents and chats; retrieving and ranking passages; answering questions and drafting with external AI infrastructure, including the relevant conversation context, attached files and emails opened in the Outlook add-in; summarising long chats; saving client notes in client folders; financial-statement analysis and calculations, including in a temporary calculation environment; web searches with queries formulated by the assistant; sharing and forwarding within the workspace; exports and deletion.
- Categories of data subjects: the Customer's Users; the Customer's clients, their employees, representatives and business contacts; other persons named in Customer Content (for example, counterparties, correspondents of emails processed through the Outlook add-in, and persons mentioned in documents or financial statements).
- Categories of personal data: identification and contact data; professional and organisational data; financial, accounting, tax, payroll and business data; content of documents, emails, questions and answers; any other personal data the Customer chooses to include in Customer Content.
- Sensitive personal data (Art. 5 lit. c FADP), such as health information in payroll documents: only where the Customer chooses to submit it; the measures in Annex 2 apply.
- Duration: the term of the agreement plus the deletion period in section 12.
Annex 2 — Technical and organisational measures
- Encryption in transit: connections to the Service use HTTPS; the application instructs browsers to use encrypted connections only (HSTS).
- Encryption at rest: Cogniten encrypts every stored file (uploaded and generated documents) with AES-256 before it is transferred to the storage provider; secrets for two-factor sign-in are also stored encrypted.
- Tenant isolation: every customer record is assigned to its workspace; the database enforces that related records belong to the same workspace, and every query is restricted to the workspace of the signed-in user. Isolation is covered by automated tests.
- Access control within a workspace: role-based permissions (owner, administrator, member); private chats and personal documents; client folders visible only to their members.
- Authentication: passwords are stored only as salted hashes (scrypt) with a minimum length; email addresses are verified; repeated sign-in attempts are rate-limited; sessions are invalidated when a password is changed or reset or when an account is disabled. Two-factor sign-in with an authenticator app is required for owners and administrators of company workspaces, and the Customer can require it for all of its Users.
- Operator access: Cogniten's platform administrators must use two-factor sign-in; the operator console shows workspace metadata and usage figures, not chats or documents.
- Minimising external processing: for searches in the knowledge library, relevant passages are selected rather than sending the entire library with each request.
- Logging: application logs are designed to exclude the content of questions, answers and documents; security-relevant administrative actions are recorded in an audit log without content.
- Abuse protection: rate limits on AI requests, uploads, emails, invitations and exports.
- Deletion: configurable retention period for chats; deleting a document removes the stored file, its extracted text and its search index entries; owners can delete the workspace.
- Organisational measures: confidentiality obligations of authorised persons; access to Customer Content only where necessary for the purposes in section 5; written agreements with subprocessors.
Annex 3 — Subprocessors
See the subprocessor register.
Customers who need a countersigned copy of this DPA can request one at info@cogniten.ch.