Legal information
Data Processing Agreement (DPA)
The Data Processing Agreement for customers of the Formdia Property platform.
a product of Formdia GmbH
Frohheimstrasse 8
9325 Roggwil TG
Switzerland
VAT no. CHE-220.558.499
Phone: +41 71 511 43 99
Commercial register: Kanton Thurgau
Legal contact: legal@formdiaproperty.com
Version: 2026-08-30 · Language: English
> This agreement governs the processing of personal data that the customer, as controller, itself records in the course of using Formdia Property (in particular case, photo, signature, and participant data). It supplements the GTC and becomes part of the main agreement once accepted by both parties.
Formdia Property is a product of Formdia GmbH, Frohheimstrasse 8, 9325 Roggwil TG, Switzerland. Legal and data-protection-related inquiries may be addressed to `legal@formdiaproperty.com`.
Registration and account data (company/admin master data, a hashed, never plaintext-stored email verification token, and versioned legal-consent metadata within the existing tenant context) is Formdia Property's own processing (Privacy Policy Category B) and is not subject to processing on behalf of the customer under this agreement — it is mentioned here for information only and is not listed as an Annex A processing data type (see Section 3 and Annex A).
1. Subject Matter
The subject matter of this agreement is the processing of personal data by Formdia Property on behalf of the customer in the course of providing the Formdia Property SaaS platform pursuant to Annex A.
2. Relationship to the Main Agreement
This DPA supplements the GTC between the parties. In the event of contradictions between this DPA and the GTC, this DPA takes precedence with respect to the processing of personal data.
3. Definitions
Unless defined otherwise, the terms "personal data," "processing," "controller," and "processor" apply within the meaning of applicable data protection law. Not every data processing activity by Formdia Property is automatically processing within the meaning of this agreement; Formdia Property's own purposes (e.g., invoicing the customer itself, if active) are assessed separately and outside the scope of this DPA.
4. Term
The operational usage phase of this agreement runs for the duration of the main agreement, including the grace period pursuant to GTC Section 34 (day 0–30 after the end of the contract), and ends upon its expiry. Insofar as, thereafter, processed Customer Data continues to exist at Formdia Property in the course of the restricted retention phase and the subsequently intended deletion pursuant to Section 15 (day 31–90, as well as a possible technical backup residual period until day 120), the obligations of this agreement — in particular confidentiality (Section 9), security/TOMs (Section 10), and, insofar as still applicable during this retention phase, adherence to instructions (Section 6) — continue unchanged to apply to this remaining data until it has been removed in accordance with the agreed retention/deletion process.
5. Nature and Purpose of Processing
The nature and purpose of processing follow from Annex A. Processing takes place exclusively to provide the contractually agreed SaaS service.
6. Instructions
Formdia Property processes personal data exclusively on documented instructions of the customer, in particular in the course of functions triggered by the customer via the platform (recording, storage, display, PDF generation, export, deletion within the scope of retention pursuant to Annex A). Formdia Property will promptly notify the customer of any instructions that Formdia Property considers unlawful.
7. Obligations of the Controller
The customer ensures that it is authorized to issue the instructions, that it has a sufficient legal basis for the personal data it records, and that it informs data subjects where required.
8. Obligations of Formdia Property
Formdia Property processes personal data only within the scope of this agreement, implements the technical and organizational measures described in Annex B, supports the customer, within the scope of what is technically possible, in fulfilling data subject rights (Section 11), and reports personal data breaches pursuant to Section 12.
9. Confidentiality
Formdia Property ensures that persons authorized to process data are bound by confidentiality or subject to an appropriate statutory duty of secrecy.
10. Technical and Organizational Measures
The measures described in Annex B apply. Annex B is updated upon material technical changes; material deteriorations in the level of protection are communicated to the customer.
11. Support for Data Subject Rights
Formdia Property supports the customer, within the scope of what is technically possible and reasonable, in responding to requests from data subjects, in particular by providing the tenant export pursuant to Annex A and the platform's existing read and administration functions.
12. Personal Data Breaches
Formdia Property informs the affected customer without undue delay, but no later than within 24 hours after Formdia Property becomes aware of a breach of the protection of personal data affecting the customer, and supports the customer in fulfilling any notification obligations. This 24-hour period is a contractual business rule between the parties; it does not mean that a statutory notification obligation (e.g., to supervisory authorities) generally prescribes a period of exactly 24 hours — the applicable statutory notification obligations and periods remain unaffected by this.
13. Subprocessors
Formdia Property is entitled to engage subprocessors in accordance with the current list maintained on the dynamic "Subprocessors" page. If Formdia Property engages a new or replacement subprocessor with access to Customer Data, Formdia Property informs the customer at least 30 days in advance. The customer may object within this period on legitimate data-protection grounds; there is no blanket, groundless right of veto. In such a case, Formdia Property will first examine a practicable alternative; if no reasonable alternative is possible, the affected service, or, absent agreement, the main agreement with respect to the affected service, may be terminated for cause.
14. International Data Transfer
Insofar as subprocessors engaged process personal data outside Switzerland, Formdia Property ensures the safeguards required under applicable law.
15. Return / Deletion
After the end of the contract, Formdia Property provides the customer with read and export access during the 30-day grace period (day 0–30) pursuant to GTC Section 34. A restricted internal retention phase without operational customer access follows (day 31–90). From day 90 after the end of the contract, operational Customer Data is intended to be deleted; for technical reasons, residual data may still exist for up to a further 30 days (at most until day 120) in technical backup copies, which serve exclusively for disaster recovery and are removed in the regular backup cycle. Statutorily required contract, invoice, or tax/accounting data is retained separately, independently of this, in accordance with the respectively applicable statutory periods; these periods are not stated numerically here. Independently of this, the package-dependent retention pursuant to Annex A applies to original photos. For as long as processed Customer Data actually still exists in this restricted retention phase (day 31–90) or as a technical backup residual (until day 120), the protective obligations of this agreement pursuant to Sections 4 and 18 continue to apply unchanged.
16. Evidence / Audit
Upon request, Formdia Property provides the customer with reasonable information to demonstrate compliance with this agreement. If the customer additionally requires an audit, the following business rule applies:
Standard Procedure. An audit is primarily conducted as a remote/documentary review (e.g., provision of reasonable evidentiary documents). A regular audit requested by the customer is generally possible at most once per calendar year and is announced at least 30 days in advance.
Additional Audits. Beyond the annual limitation, the customer may request an additional audit in the event of a specific security or data protection incident, a reasonable suspicion of a material breach of duty by Formdia Property under this agreement, or insofar as required due to a mandatory statutory or regulatory requirement.
On-Site Audit. An on-site audit takes place only insofar as a remote/documentary review is objectively insufficient. Date and procedure are coordinated appropriately. Formdia Property ensures that an on-site audit preserves confidentiality, grants no insight into other tenants' data, discloses no secrets (secrets, keys), and that security-critical information is disclosed only to the extent necessary for the audit purpose.
Costs. The costs of a regular audit requested by the customer are generally borne by the customer. If an audit reveals a material breach of duty by Formdia Property under this agreement, Formdia Property bears the reasonably incurred audit costs.
17. Liability / Relation to the Agreement
The liability provisions of the GTC apply accordingly to liability in connection with this agreement, insofar as mandatory data protection law does not prescribe deviating provisions.
18. Termination
The operational usage phase of this agreement ends upon termination of the main agreement, including the grace period pursuant to Section 4. Obligations that by their nature continue beyond that point — in particular confidentiality, security/TOMs, and the obligations regarding return/deletion pursuant to Section 15 — remain unaffected with respect to processed Customer Data still held by Formdia Property and continue to apply until it has been removed in accordance with the agreed retention/deletion process.
19. Final Provisions
The final provisions of the GTC (including the severability clause, governing law, and jurisdiction) apply in addition, insofar as not otherwise provided in this agreement.
Annex A — Subject Matter, Nature, Purpose, Data Types, Data Subjects
Subject Matter: Provision of the Formdia Property SaaS platform for digital handovers, acceptances, and inspections.
Purposes of Processing:
- digital handover, acceptance, and inspection documentation
- storage and provision of case data
- photo processing (storage, image optimization for display/preview)
- signature processing in the course of case documentation
- PDF creation for completed cases
- user and role administration within the company account
- structured tenant export triggered by Owner/Admin
Data Types:
- personal master data (name)
- contact data (email, phone where applicable)
- company/organizational data
- property/address data of the documented premises/rooms
- case and process data
- findings/defect information
- key/inventory information
- photos
- signatures
- generated documents/PDFs
- time/activity data (including creation, modification, and completion timestamps)
- technical metadata (including file format, size, checksum)
Special categories of personal data are not systematically collected; should a customer nevertheless record special categories in the course of a case, this constitutes a decision and responsibility of the customer outside the intended regular purpose of use.
Categories of Data Subjects:
- customer administrators (Owner/Admin users of the customer)
- the customer's employees (Employee users)
- owners
- landlords
- property managers
- tenants
- buyers
- experts/surveyors
- service providers
- other participants recorded in the course of a case
Persons who use the public Formdia Property contact form are not the subject of this Annex: the contact form is not processing on behalf of a Formdia Property customer, but Formdia Property's own data processing as controller pursuant to Section D of the Privacy Policy.
Annex B — Technical and Organizational Measures (TOMs)
This list contains exclusively measures that have been verified against the current Formdia Property codebase. It is updated upon material technical changes.
B.1 Access Control and Permissions
- Strict tenant isolation: all data access is restricted server-side to the respective company account; tenant membership is determined exclusively server-side from the session, never from client-side parameters.
- Role-based access control with the roles Owner, Admin, and Employee; permissions are checked server-side for every action.
- Server-side permission checks on every access to case, photo, document, and administration functions.
B.2 Authentication
- Password hashing using PBKDF2 (SHA-256, high iteration count); no plaintext or reversible storage of passwords.
- Optional two-factor authentication (TOTP) with encrypted storage of the secret.
- Recovery codes are stored exclusively as a hash value (not retrievable in plaintext).
- Management of trusted devices to controllably reduce repeated two-factor prompts, with a limited validity period.
- Re-authentication for security-relevant actions.
- Secure, "HttpOnly" session cookies with a limited validity period.
B.3 Network and Transport Security
- End-to-end encryption of data transmission (TLS).
- Security headers (including Content Security Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy) on the public website; corresponding protective mechanisms also for the application interface within the existing security architecture.
- Protection against cross-origin abuse through server-side origin/referer verification of security-relevant endpoints.
- Rate limiting for login, password change, two-factor verification, re-authentication, and the tenant export.
B.4 Separation of Environments and Data
- Separate staging and production environments.
- Separate storage systems for structured data (D1 database) and private binary objects (R2 object storage). Original photos and generated PDF documents are stored in the same private R2 object storage, each under separate, randomly generated storage paths per file; access takes place exclusively via authenticated, permission-protected application paths.
- Private, non-publicly accessible storage of photos and documents.
- Secrets (keys) are managed separately from the source code and are not stored in code or documentation.
B.5 Logging and Traceability
- Logging of login activity for security purposes.
- Revision/history logic for cases (reopening, refinalization) with traceability of change timestamps.
- Logging of tenant export operations (time, triggering user, scope, checksum), without logging the export content itself.
B.6 Data Minimization in Exports
- The tenant export (Annex A) technically verifiably excludes password hashes, two-factor secrets, recovery code hashes, session and trusted-device tokens, as well as internal storage keys.
B.7 Retention and Lifecycle
- Technically defined, package-dependent retention mechanism for original photos; deletion of only the original, with display/preview versions preserved; deletion takes place only after confirmed removal from object storage.
- Server-time-based contract lifecycle logic (active, ending, grace period, restricted) for controlled allocation of rights after the end of the contract.
- No data loss upon downgrade: existing Customer Data is not deleted as a result of a package reduction.
B.8 Measures Expressly Not Assured
Formdia Property does not operate its own physical data center, its own physical access control, its own uninterruptible power supply (UPS), or its own hardware firewall; Formdia Property uses the infrastructure of the cloud providers it engages for this purpose. Formdia Property does not assure an exclusively Swiss hosting guarantee, ISO certification, guaranteed compliance with Swiss bookkeeping ordinance (GeBüV) requirements, audit-proof security in the strict sense, tamper-proof external timestamps, complete immutability, or absolute security.