1. Scope
This DPA applies when AlpineLayer processes personal data on behalf of a customer under covered services and the main agreement incorporates this DPA. It supplements the main agreement.
2. Roles
The customer is controller or processor for another controller, and AlpineLayer is processor or subprocessor for customer personal data. Each party is responsible for its own compliance with applicable data-protection law.
3. Instructions
AlpineLayer processes customer personal data only on documented instructions, including instructions inherent in provisioning, securing, supporting and terminating services, unless law requires otherwise. If an instruction appears unlawful, AlpineLayer may inform the customer and pause the affected processing.
4. Confidentiality
Personnel authorized to process customer personal data are subject to confidentiality duties and role-based access controls.
5. Security measures
AlpineLayer will maintain technical and organizational measures appropriate to risk, which may include MFA, privileged access controls, network segmentation, logging, vulnerability management, backup controls, incident response, supplier management and physical controls provided by data centers.
6. Subprocessors
The customer authorizes AlpineLayer to use subprocessors needed to provide services. AlpineLayer will maintain a Subprocessor List and require appropriate contractual protections. Where law or contract requires it, customers will receive notice of material new subprocessors and a reasonable opportunity to object on legitimate data-protection grounds.
7. International transfers
Where customer personal data is transferred to a destination without the legally required level of protection, AlpineLayer will use an appropriate transfer mechanism, recognized contractual clauses, supplementary measures or another lawful basis. Swiss adaptations will be used where required.
8. Data-subject requests
Taking account of the nature of processing, AlpineLayer will reasonably assist customers with applicable requests when customers cannot fulfill them independently. Requests received directly for customer-controlled data may be referred to the customer unless law requires otherwise.
9. Personal-data breaches
AlpineLayer will notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting customer personal data where notice is required by law or contract. Initial information may be supplemented as investigation continues.
10. Compliance assistance
AlpineLayer will provide reasonable information available to it to support customer compliance, risk assessments and regulator requests. Extraordinary assistance may be chargeable where permitted.
11. Audit and assurance
AlpineLayer may provide security documentation, certifications or third-party reports when available. If further audit is legally required and existing documentation is insufficient, the parties will agree a reasonable process that protects other customers, confidentiality and service security.
12. Government requests
AlpineLayer will review legally binding requests for validity and scope, seek to disclose only what is required, and notify the customer where legally permitted. The Law Enforcement Request Guidelines provide additional detail.
13. Return and deletion
Customers should export data before service termination. AlpineLayer will delete or return data according to the service, customer instructions, retention policy and legal obligations. Backup copies may remain until normal rotation expires.
Annex 1 — Processing details
Data subjects
Customer employees, users, website visitors, end users and other individuals whose data the customer submits.
Data categories
Any personal data selected by the customer, including identity, contact, account, communications, transaction, technical, website or application data.
Processing
Hosting, storage, transmission, retrieval, backup, support, security and deletion needed to deliver the service.
Duration
For the service term plus normal deletion, backup and legal-retention periods.
Annex 2 — Technical and organizational measures
- Role-based identity and access controls.
- Multi-factor authentication for privileged access where supported.
- Network security, segmentation and firewall controls.
- Administrative and security logging.
- Patch, vulnerability and change management.
- Backup and recovery controls for services that include backup.
- Data-center physical security.
- Incident response and escalation.
- Personnel confidentiality and access revocation.
- Subprocessor risk management.
Annex 3 — Subprocessors
The authoritative list is published at subprocessors.html and must contain actual provider names, processing locations and purposes before production customer data is processed.