Legal
Data Processing Agreement (DPA)
Last updated: August 2026
Why this document exists
Under the EU GDPR (Art. 28) and Swiss nFADP, when a company (the controller) puts personal data into a SaaS product, the vendor (the processor) must process that data only on documented instructions, with appropriate security, and under a written contract — a Data Processing Agreement (DPA), in German often called an AVV.
Enterprise and public-sector buyers routinely ask for a DPA before paying. Without one, procurement and legal teams often block the deal even if the product works.
1. Parties
Processor: Patrik Seitz (Einzelunternehmen), trading as SolutionBoard, Rüggisingerstraße 18a, 6020 Emmenbrücke, Schweiz, solutionboardmp@gmail.com.
Controller: the organisation that holds a paid SolutionBoard subscription and decides the purposes of processing personal data in the Service.
By using a paid plan, the Controller accepts this DPA unless the parties have signed a different written agreement that expressly replaces it.
2. Subject matter and nature of processing
The Processor hosts and processes personal data that the Controller (and its authorised users) enter into SolutionBoard, solely to provide, secure, support, and improve the Service. Categories typically include: account and profile data, company membership, project and whiteboard content, comments, activity logs, support messages, and billing metadata handled via the payment provider.
3. Duration and deletion
Processing lasts for the term of the paid subscription. After termination or company soft-deletion, data is retained only as needed for the published restore window, backups, or legal duties, then permanently deleted or anonymised (including the scheduled purge of soft-deleted companies).
4. Instructions and confidentiality
The Processor processes personal data only on documented instructions from the Controller (including configuration and use of the Service) and applicable law. Personnel with access are bound to confidentiality.
5. Sub-processors
The Controller authorises the following sub-processors:
- Supabase — database, authentication, object storage
- Vercel — application hosting
- Resend — transactional email
- Paddle — payment processing (Merchant of Record)
- Sentry — error monitoring (when enabled)
The Processor will announce material changes to this list with a reasonable objection window before they apply to existing Controllers, except for urgent security replacements.
6. Security
The Processor maintains appropriate technical and organisational measures (access control, encryption in transit, isolation by company tenancy via RLS, logging, and backup practices appropriate to a SaaS product of this scale). Absolute security cannot be guaranteed.
7. Assistance
Taking into account the nature of processing, the Processor will assist the Controller, where reasonably possible, with data-subject requests, breach notification obligations, and data-protection impact assessments related to use of the Service.
8. International transfers
Where sub-processors process data outside Switzerland / the EEA, the Processor relies on appropriate safeguards required by applicable law (e.g. adequacy decisions or standard contractual clauses as offered by those providers).
9. Governing law
Swiss law applies. Place of jurisdiction is Luzern, Schweiz, unless mandatory law requires otherwise.
10. Contact
Privacy / DPA requests: solutionboardmp@gmail.com