Data Processing Agreement (DPA)

Version: 15 November 2025

Introduction

This Data Processing Agreement (DPA) governs the rights and obligations of QR Labeling GmbH, a Swiss company (hereinafter the “Processor”), and individual clients (hereinafter each the “Controller” and together the “Parties”) in connection with the processing of personal data on behalf of the Controller (hereinafter uniformly the “Commissioned Processing” and the “Personal Data”).

This DPA applies to all activities in which the Processor processes Personal Data, in whole or in part, on behalf of the Controller or has such data processed (hereinafter uniformly “process”).

The Processor is subject to Swiss data protection law, in particular the Federal Act on Data Protection (Data Protection Act, FADP). With this DPA, the Processor enables the Controller to comply with the applicable data protection requirements for the Commissioned Processing.

Nature, Subject Matter and Purpose of the Commissioned Processing

The Commissioned Processing takes place in accordance with existing contractual agreements between the Parties or agreements yet to be concluded. In the event of a contradiction between the provisions of this DPA and the General Terms and Conditions (GTC) of the Processor, the provisions of this DPA take precedence.

The Commissioned Processing comprises any handling of Personal Data, irrespective of the means and procedures applied, in particular the archiving, retention, disclosure, collection, erasure, storage, alteration, destruction and use of Personal Data. Personal Data is all information relating to an identified or identifiable person.

The Commissioned Processing comprises the categories of Personal Data set out in Annex 1.

The Commissioned Processing comprises the categories of data subjects whose Personal Data is processed, as set out in Annex 2.

Obligations of the Parties

The Processor processes Personal Data exclusively for the purpose or purposes set out in the contractual agreements between the Parties, unless the Processor receives further documented instructions from the Controller.

The Processor processes Personal Data exclusively as directly agreed by contract with the Controller or in accordance with further documented instructions of the Controller within the contractually agreed framework, unless the Processor is legally or regulatorily obliged to carry out a specific processing. The Processor is not obliged to review contractual agreements or instructions issued for violations of applicable data protection and other legal requirements.

Throughout the entire duration of the Commissioned Processing, the Controller may issue further documented instructions within the contractually agreed framework. The Controller bears the expenses of the Processor arising from such further instructions.

The Processor processes Personal Data for an indefinite period until termination of this DPA or until termination of the last contractual agreement between the Parties concerning Commissioned Processing.

Data Security

The Processor takes suitable technical and organisational measures (TOM) to ensure a level of security of the processed Personal Data appropriate to the risk. The measures include in particular the protection of the processed Personal Data against a breach of security that, whether accidental or unlawful, leads to the unauthorised disclosure of or unauthorised access to Personal Data, or to the alteration, loss or destruction of Personal Data (hereinafter collectively the “Data Security Breaches”).

The Processor grants its personnel access to Personal Data only to the extent that such access is necessary for the performance, monitoring and administration of this DPA. The Processor ensures that the persons authorised to carry out the Commissioned Processing have committed themselves to confidentiality or are subject to an appropriate statutory obligation of confidentiality.

Documentation and Audit Options

The Parties must be able to demonstrate compliance with this DPA. The Processor handles requests of the Controller regarding the Commissioned Processing under this DPA in an appropriate manner and as soon as possible.

On request, the Processor enables the Controller to audit the Commissioned Processing under this DPA at reasonable intervals or where there are documented indications of non-compliance.

The Controller may carry out an audit itself or have it carried out by an independent auditor. An audit may also include inspections of the physical facilities or premises of the Processor, provided that such inspections are necessary, take place during normal business hours without disrupting operations, and are announced with reasonable advance notice. Such inspections are only permissible if and to the extent that the audit cannot be carried out by means of suitable evidence such as reports, documentation, certificates or certifications, in particular in the case of data centres.

The Controller bears the expenses of the Processor for such audits.

Sub-processing

The Controller grants the Processor general authorisation to engage the sub-processors listed in Annex 3.

The Processor informs the Controller in electronic or written form at least 30 days in advance of any intended changes to this list by replacing or adding sub-processors. The Processor thereby gives the Controller sufficient time to object, where applicable, to the intended changes.

If no objection is raised in time, the intended changes are deemed approved. If, in the event of an objection, no amicable resolution regarding the planned changes is possible between the Parties and the Controller is not prepared to waive its objection, either Party is entitled to terminate this DPA extraordinarily as of the date of the planned changes. If the Controller does not terminate the DPA extraordinarily, the intended changes are deemed approved despite the original objection.

The Processor must contractually impose on sub-processors engaged to carry out the Commissioned Processing essentially the same obligations as those that apply to the Processor under this DPA.

Commissioned Processing Abroad

As a rule, the Commissioned Processing takes place in Switzerland and in countries whose data protection law, according to the Swiss Federal Council, ensures an adequate level of protection for Personal Data. These include in particular the countries of the European Economic Area (EEA).

Commissioned Processing in a country whose data protection law does not ensure an adequate level of protection of Personal Data may take place if a suitable level of protection is ensured for other reasons in accordance with the applicable data protection requirements, in particular under intergovernmental agreements or on the basis of applicable standard data protection clauses recognised, issued or approved by the Federal Data Protection and Information Commissioner (FDPIC). Where necessary, the Processor is entitled to adapt and supplement standard data protection clauses of the European Commission in accordance with the recommendations of the FDPIC so that the standard data protection clauses also meet the applicable data protection requirements in Switzerland.

Support of the Controller towards Data Subjects

The Processor informs the Controller without delay of any request it has received from a data subject that concerns the Commissioned Processing. The Processor is entitled to confirm receipt to the data subject but otherwise does not answer the request itself, unless it has been authorised to do so by the Controller.

Taking into account the nature of the Commissioned Processing, the Processor supports the Controller in fulfilling its obligation to respond to requests by data subjects to exercise their rights. In providing this support, the Processor follows the instructions of the Controller.

The Controller bears the expenses of the Processor for such support.

Support and Cooperation in the Event of Data Security Breaches

In the event of a Data Security Breach, the Processor cooperates with the Controller and supports it accordingly so that the Controller can fulfil its obligations to notify Data Security Breaches to the competent supervisory authority or authorities and to inform the persons affected by Data Security Breaches, whereby the Processor takes into account the nature of the Commissioned Processing and the information available to it.

In the event of a Data Security Breach in connection with the Personal Data processed by it, the Processor informs the Controller without delay after becoming aware of the breach.

The Controller bears the expenses of the Processor for such support and cooperation.

Suspension of the Commissioned Processing

In the event that the Processor fails to comply with its obligations under this DPA, the Controller may instruct the Processor to suspend the processing of Personal Data until the Processor complies with this DPA or this DPA is terminated. The Processor informs the Controller without delay if, for whatever reason, it considers itself unable to comply with this DPA.

Liability

The Parties are jointly and severally liable towards data subjects for damage suffered by such persons as a result of incorrect or impermissible Commissioned Processing. Each Party may, if and to the extent that it is not at fault for such damage, seek recourse against the other Party.

In all other respects, liability is governed by any liability provisions in the contractual agreements between the Parties.

Termination

The Controller is entitled to terminate this DPA extraordinarily and without notice if:

  • the Processor, despite a written warning, persistently or materially breaches this DPA or fails to meet the applicable data protection requirements for the Commissioned Processing;
  • the Processor fails to comply with a binding decision of a competent supervisory authority or a competent court concerning the obligations of the Processor under the applicable data protection requirements for the Commissioned Processing.

The Processor is entitled to terminate this DPA extraordinarily and without notice if the Controller insists on the performance of a contractual agreement or instruction after having been informed by the Processor that the contractual agreement or instruction violates applicable data protection requirements.

The Parties are entitled to terminate this DPA by ordinary notice of three months to the end of a month, unless contractual agreements between the Parties provide for no notice period or a different notice period.

After termination of this DPA, the Processor erases all Personal Data processed on behalf of the Controller, unless the Processor is legally or regulatorily entitled or obliged to retain the Personal Data. Until the Personal Data is erased, the Processor ensures compliance with this DPA.

Final Provisions

This DPA may be concluded in electronic or written form or by reference in other contractual agreements between the Parties. Amendments to this DPA may be made in electronic form.

The Parties inform each other of any data protection adviser or data protection officer in accordance with the applicable data protection requirements.

Should individual provisions of this DPA prove to be incomplete, void or ineffective, the validity and effectiveness of the remaining provisions shall not be affected. In such a case, the Parties will adjust, interpret or replace the affected provisions in such a way that the purpose pursued by the incomplete, void or ineffective provisions is achieved as far as possible.

This DPA is governed exclusively by Swiss law. The exclusive place of jurisdiction is the registered office of the Processor. Irrespective of this, the Processor is entitled, at its own discretion, to assert claims also at the registered office of the Controller.

Annex 1 – Categories of Personal Data Processed

The Commissioned Processing comprises the following categories of Personal Data:

  • Equipment and system data
  • Identification and contact data
  • Communication data
  • Usage data
  • Contract data
  • Other categories of processed Personal Data

The Controller informs the Processor in documented form if the Controller wishes to expressly list individual other or additional categories of Personal Data in this Annex.

Annex 2 – Categories of Data Subjects Whose Data Is Processed

The Commissioned Processing comprises the following categories of data subjects whose Personal Data is processed:

  • Customers
  • Employees
  • Users
  • Other categories of data subjects

The Controller informs the Processor in documented form if the Controller wishes to expressly list individual other or additional categories of data subjects whose Personal Data is processed in this Annex.

Annex 3 – List of Sub-processors

  • Pelephant GmbH (Switzerland), hosting
  • Plus Five Five Inc. (USA), e-mail delivery