This data processing agreement ("DPA") forms part of the terms of service between Ampersand Labs by Davide Morotti, Einzelunternehmen, Flüelastrasse 10, 8048 Zürich, Switzerland (the "Processor") and the customer using Consent by Ampersand (the "Customer", acting as controller). It applies automatically when the Customer uses the Service and meets the requirements of Art. 9 of the Swiss Federal Act on Data Protection (FADP) and Art. 28 of the EU General Data Protection Regulation (GDPR). If the Customer needs a signed copy, write to legal@ampersand.ch.
1. Subject matter and duration
The Processor processes personal data on behalf of the Customer to provide the Service as described in the terms of service. The processing lasts for the term of the Customer's subscription and ends when all personal data have been deleted or returned under section 9.
2. Nature, purpose and data concerned
The processing consists of collecting, storing, displaying, exporting and deleting the following data through the components the Customer embeds on its websites or uses in the Service:
| Component | Personal data |
|---|---|
| Consent banner and consent log | Random consent ID, consent choices, date and time, banner configuration version, page URL, language, browser user agent. IP addresses are not stored. |
| Consent withdrawal | Email address, used only to send the withdrawal link and not stored; withdrawal date on the affected form consents. |
| Form consent API | Email address and its hash, purpose, consent wording, form and source URL, language, IP address, user agent, date of grant and withdrawal. |
| Privacy request form | Name, email address, request type, message, language, IP address, handling status and notes, deadlines. |
| Accessibility feedback | Message, optional email address, page URL, user agent. |
| Sub-processor change notifications and client portal | Email addresses of subscribers and of the Customer's invited clients. |
| Registers (vendors, processing activities, breaches, DPIA) | Personal data the Customer chooses to enter, typically names and contact details of contact persons. |
Data subjects are visitors of the Customer's websites, persons submitting requests or consents through them, and contact persons of the Customer and its clients. The Service is not intended for special categories of personal data; the Customer shall not enter such data into free-text fields.
3. Instructions
The Processor processes personal data only on documented instructions from the Customer. The terms of service, this DPA and the Customer's configuration of the Service constitute the Customer's instructions. The Processor informs the Customer if it believes an instruction violates data protection law, and processes data otherwise only where required by law, in which case it informs the Customer beforehand unless the law prohibits this.
4. Confidentiality
The Processor ensures that persons authorised to process the personal data are bound to confidentiality and process the data only as needed to provide, secure and support the Service.
5. Technical and organisational measures
The Processor maintains appropriate measures to protect the personal data, in particular:
- encryption of all connections (TLS) and encrypted storage of backups;
- hosting in data centres in Switzerland or the EU/EEA with physical access control;
- logical separation of customer data by team, with role-based access within each team;
- hashed passwords, optional two-factor authentication and passkeys for user accounts;
- administrative server access restricted to named personnel via SSH keys;
- data minimisation by design: the consent log stores no IP addresses, withdrawal requests do not store the email address;
- rate limiting of public endpoints, regular security updates, and daily backups with tested restoration;
- an audit log of changes within each team and a documented incident response process.
The Processor may update these measures as long as the level of protection is not reduced.
6. Sub-processors
The Customer authorises the Processor to engage the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server hosting, database and backups | Germany / Finland (EU) |
| Brevo (Sendinblue SAS) | Transactional email delivery | France (EU) |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Payment processing, subscriptions and invoicing | Ireland / USA (EU-US / Swiss-US Data Privacy Framework, SCCs) |
| Anthropic, PBC | AI analysis of publicly available vendor terms and privacy policies; no customer or visitor personal data is sent | USA (SCCs) |
The Processor informs the Customer by email at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within that period; if no solution is found, the Customer may terminate the affected subscription with effect from the change. The Processor imposes data protection obligations on each sub-processor that are equivalent to this DPA and remains responsible for their compliance.
7. International transfers
Personal data of the Customer's website visitors are stored in Switzerland or the EU/EEA. Where a sub-processor processes personal data in a country without an adequate level of data protection, the transfer is based on the EU-US or Swiss-US Data Privacy Framework or on the European Commission's standard contractual clauses, including the adjustments required by the Swiss FDPIC.
8. Assistance and data breaches
The Processor supports the Customer with appropriate measures in responding to data subject requests, in particular through the export, correction and deletion functions of the Service, and forwards requests it receives directly to the Customer. It assists the Customer with security, data protection impact assessments and consultations with authorities, as far as the information available to it allows.
The Processor notifies the Customer without undue delay, and at the latest within 48 hours, after becoming aware of a personal data breach affecting the Customer's data, and provides the information the Customer needs to meet its own notification obligations.
9. Deletion and return
The Customer can delete websites, together with their consent log and related data, at any time in the Service. Within 30 days after the end of the subscription, the Customer can export its consent records and request an export of its other data. The Processor then deletes all personal data, including copies, unless the law requires it to keep them; backups are overwritten within a further 30 days.
10. Audits
The Processor provides the Customer on request with the information needed to demonstrate compliance with this DPA. The Customer may carry out an audit, itself or through a bound-to-secrecy auditor, once per year with 30 days' notice, during business hours and without disrupting operations; additional audits are possible after a data breach. The Customer bears its own costs, and the Processor may charge reasonable costs for extensive on-site audits.
11. Final provisions
Liability is governed by the terms of service, subject to mandatory data protection law. In the event of conflict, this DPA takes precedence over the terms of service with respect to the processing of personal data. This DPA is governed by Swiss law; where the GDPR applies to the processing, its provisions prevail. The place of jurisdiction is Zurich, Switzerland.