Template pursuant to Art. 28 GDPR · Effective from: February 10, 2026
For organizations in the Czech Republic, also applies GDPR + zák. č. 110/2019 Sb.; for organizations in Slovakia GDPR + z. č. 18/2018 Z.z.; for organizations in Switzerland (CH), also applies nDSG (SR 235.1) (among others Art. 9 nDSG — data processing on behalf). nDSG is compatible with GDPR principles. Fedlex (nDSG). For organizations in Germany (DE): Art. 28 GDPR is directly applicable, also applies GDPR + BDSG. For organizations in Austria (AT): Art. 28 GDPR is directly applicable, also applies GDPR + DSG.
Notice: This agreement becomes effective upon acceptance by the controller (organization) during registration or in the organization settings. Acceptance is recorded with a timestamp and administrator identifier.
Controller: Organization (association, HOA, interest group) registered on the verwalt.ch platform, represented by the organization administrator („Controller“ or „Organization“).
Processor: TimeDeals Pavelka, Berglistrasse 28a, 8180 Bülach, Švýcarsko, UID: CHE-393.597.780, operator of the verwalt.ch platform („Processor“).
2.1 The Processor processes personal data on behalf of the Controller exclusively for the purpose of providing verwalt.ch platform services (membership management, voting, documents, communication, audit records).
2.2 This agreement is effective for the duration of the Controller's use of the platform. After termination of use, the provisions on return and deletion of data (Art. 9) apply.
Data subjects:
Data categories:
6.1 The Controller agrees to the use of the following sub-processors:
| Sub-processor | Purpose | Seat / data location |
|---|---|---|
| Vercel Inc. | Server infrastructure, database | USA (EU-U.S. DPF) |
| Postmark (ActiveCampaign, LLC) | Transactional email delivery | USA (EU-U.S. DPF) |
| Stripe, Inc. | Payment processing | USA (EU-U.S. DPF) |
| Sentry (Functional Software, Inc.) | Technical error diagnostics | USA (EU-U.S. DPF) |
6.2 The Processor informs the Controller of intended changes to sub-processors with 30 days' notice. The Controller may object to the change; if it does so and the Processor insists on the change, the Controller has the right to terminate the agreement.
6.3 The Processor shall ensure that each sub-processor provides at least the same level of personal data protection as set forth in this agreement and the applicable legislation (GDPR / revDSG), in particular through contractual obligations.
6.4 The Processor shall be liable to the Controller for the acts and omissions of its sub-processors as if they were the Processor's own acts.
7.1 The transfer of data to Switzerland is covered by a European Commission adequacy decision. The transfer to the USA (Vercel, Postmark, Stripe, Sentry) is ensured through the EU-U.S. Data Privacy Framework.
7.2 For the processing of personal data of data subjects in Switzerland, these provisions shall apply in accordance with the revised Swiss Federal Act on Data Protection (revDSG).
7.3 In the event that an adequacy decision ceases to be valid, transfers to third countries shall be secured through standard contractual clauses (SCCs).
8.1 The Processor will allow the Controller or an independent auditor designated by it access to information necessary to demonstrate compliance with obligations pursuant to Art. 28 GDPR, in reasonable scope and after prior notice (min. 30 days in advance).
8.2 The Processor may condition the audit on the signing of a confidentiality agreement by the auditor.
9.1 After termination of the Controller's use of the platform, the Processor will enable export of organization data (members, voting, documents, audit) in machine-readable format.
9.2 After expiration of a reasonable period for export (60 days), the Processor will delete the organization's data, except for data whose retention is required by law or legitimate interest (audit logs, delivery evidence).
10.1 This agreement is governed by Swiss law. For dispute resolution, the courts in Bülach, Switzerland, have jurisdiction.
10.2 This agreement becomes effective upon acceptance by the organization administrator on the platform (checking the consent box during organization registration or in organization settings). Acceptance is recorded with a timestamp.
10.3 In case of conflict between this agreement and the Terms of Use this agreement takes precedence in the scope of data protection.
The organization administrator accepts this agreement during organization registration or in organization settings by checking the corresponding field. Acceptance is recorded in the platform's audit log with the administrator identifier and timestamp.
Contact for inquiries: privacy@verwalt.ch
Last updated: February 10, 2026