1. Parties and scope
This Data Processing Addendum (DPA) forms part of the agreement between the Customer and 5IP Technology GmbH concerning Due Diligence HQ.
5IP Technology GmbH
c/o Jürgen Samuel
Hurdnerstrasse 98
8640 Hurden
Switzerland
UID: CHE-417.366.049
Commercial Register No.: CH-130.4.037.145-3
Email: 5pt.gmbh@gmail.com
It applies where 5IP Technology GmbH processes personal data contained in Customer Content on behalf of Customer (Customer Personal Data). Capitalised terms not defined here have the meaning in the main agreement.
2. Roles and applicable law
Customer is controller and 5IP Technology GmbH is processor where Customer determines the purposes and means of processing. If Customer is itself a processor, 5IP Technology GmbH is its subprocessor and Customer confirms that its instructions and appointment are authorised by the relevant controller.
Each party must comply with the FADP and other data-protection law applicable to its role. Where the GDPR or UK GDPR applies to the processing, this DPA is intended to satisfy the processor-contract requirements of Article 28.
5IP Technology GmbH remains a separate controller for account administration, security, billing, contractual communications and its own business operations as described in the Privacy Policy.
3. Processing instructions
5IP Technology GmbH will process Customer Personal Data only on Customer's documented instructions, as necessary to provide and secure the Service, or where law requires processing. The agreement, this DPA, Customer's configuration, enabled providers and authorised user actions are documented instructions.
If we believe an instruction infringes applicable data-protection law, we will inform Customer unless prohibited and may suspend the affected processing while the parties resolve the issue. Customer may issue additional lawful instructions that are consistent with the Service; material extra work may require agreed fees and scope.
4. Confidentiality and access
Persons authorised to process Customer Personal Data are bound by confidentiality and receive access only as needed for their role. We maintain access-control and offboarding procedures and require authorised support or review personnel to follow applicable security rules.
5. Security
Taking account of the state of the art, implementation cost, processing and risk, we maintain appropriate technical and organisational measures. The current measures are described in Annex 2. Customer is responsible for secure user administration, appropriate project permissions, lawful content selection and its own endpoints and credentials.
6. Subprocessors
Customer gives general written authorisation for the subprocessors in Annex 3 and for replacements or additions needed to provide the Service. We impose written data-protection and confidentiality obligations appropriate to each subprocessor's service and remain responsible for performance of our DPA obligations to the extent required by applicable law.
We will provide reasonable advance notice of a material new subprocessor that will process Customer Personal Data. Customer may object on reasonable data-protection grounds before the change takes effect. The parties will work in good faith on a reasonable alternative; if none is reasonably available, either party may terminate the affected feature or service without penalty for the unused affected period.
7. AI providers
Customer acknowledges that AI or embedding operations requested through DD HQ may transmit relevant Customer Personal Data to a provider enabled for the workspace, currently including OpenAI or Anthropic depending on configuration. Customer must select providers and models appropriate to its data and may be required to supply workspace credentials. AI providers processing Customer Personal Data for the Service are subprocessors for that processing.
8. International transfers
Where Customer Personal Data is disclosed from Switzerland to a country without an adequate level of protection, we use safeguards permitted by the FADP, including recognised standard contractual clauses with Swiss adaptations and supplementary measures where required. Where the GDPR or UK GDPR applies, the parties use the applicable EU Standard Contractual Clauses, UK addendum or another valid mechanism.
If the EU Standard Contractual Clauses are required between Customer and 5IP Technology GmbH, they are incorporated as follows unless the parties sign another module: Module Two for controller-to-processor transfers or Module Three for processor-to-processor transfers; optional docking applies; subprocessor authorisation is general with the notice period in section 6; the competent supervisory authority and governing law are determined by the exporter's applicable law; and the courts specified by the clauses have jurisdiction. Swiss references and FDPIC authority are added where the FADP applies.
9. Data-subject requests
Taking account of the processing, we will provide reasonable assistance through technical and organisational measures so Customer can respond to requests concerning Customer Personal Data. If we receive a request and can identify Customer as controller, we will refer the requester to Customer unless law requires another response. Customer remains responsible for deciding and communicating the response.
10. Data security incidents
We will notify Customer without undue delay after becoming aware of any personal-data security breach affecting Customer Personal Data. The notice will provide reasonably available information about the nature of the breach, affected data and people, likely consequences, and measures taken or proposed. Information may be supplied in phases as it becomes available.
Customer is responsible for notifications to authorities and affected people unless law assigns that duty to us. We will reasonably assist. A notification is not an admission of fault or liability.
11. DPIAs and regulatory assistance
Taking account of the processing and information available to us, we will reasonably assist Customer with security obligations, data-protection impact assessments, prior consultation and regulator enquiries relating to the Service. Material assistance beyond standard documentation may require agreed fees unless caused by our breach.
12. Deletion and return
During the term, Customer may use available export and deletion controls. On termination or Customer's documented request, we will delete or return Customer Personal Data in accordance with the agreement, unless law requires retention. Deletion from backups occurs through ordinary overwrite cycles; retained backup data remains protected and is not restored for ordinary processing except for disaster recovery.
13. Audit information
We will make information reasonably necessary to demonstrate compliance with this DPA available to Customer, ordinarily through policies, security descriptions, certifications or written responses. If that is insufficient and law requires further verification, Customer may conduct one audit in a 12-month period through an independent auditor, on reasonable notice, during business hours, under confidentiality, without accessing other customers' data or unreasonably disrupting operations. Additional audits are permitted after a material incident or regulator request. Each party bears its own costs unless the audit identifies a material breach by us.
14. Customer obligations
Customer is responsible for lawful instructions, legal bases, notices, consents where required, data accuracy, data minimisation, responding to rights requests, and ensuring it does not submit data that the Service is not appropriate to process. Customer must not unnecessarily submit sensitive personal data and must configure access and provider choices appropriately.
15. Liability, term and law
The liability provisions and governing law in the main agreement apply to this DPA, subject to mandatory data-protection law and the incorporated transfer clauses. This DPA remains effective while we process Customer Personal Data.
Annex 1 — Processing details
Subject matter and purpose: providing DD HQ functionality and related support requested by Customer.
Duration: the service term plus the return, deletion, backup and legally required retention periods.
Nature of processing: collection, receipt, storage, organisation, retrieval, parsing, indexing, extraction, classification, analysis, AI processing, embedding, summarisation, generation, transmission, human review where agreed, logging, backup, export and deletion.
Data subjects: Customer users; employees; directors; executives; founders; shareholders; beneficial owners; investors; applicants; interview participants; customers; suppliers; advisers; consultants; counterparties; and other people appearing in Customer Content.
Data types: identifiers, business contacts, account and permission data, employment and professional data, financial and transaction information, contract and company information, communications, interview responses and recordings where enabled, public-source information, and other personal data Customer submits. Sensitive or special-category data is not required and should be submitted only where necessary, lawful and appropriate.
Annex 2 — Technical and organisational measures
- organisation-scoped models and membership checks for tenant isolation;
- project-level roles and permissions on project-bound reads and writes;
- authentication controls, secure session and CSRF cookies, and enforced authenticator-app MFA for platform administrators;
- encryption in transit and production private object storage with server-side encryption where configured;
- encrypted storage of workspace AI provider credentials and environment-based secret management;
- private file delivery and expiring signed object-storage URLs where configured;
- audit logging for critical access, policy, billing, security and administrative actions;
- upload type and size validation, asynchronous processing controls and persisted job status;
- vulnerability and dependency management, logging, monitoring and incident-response procedures;
- retention automation for export files, IP data, billing payloads, recordings and recruitment data; and
- confidentiality, least-privilege access and subprocessor contracting.
Annex 3 — Subprocessor categories and current supported providers
Use of a provider depends on deployment and Customer configuration. Processing may occur in Switzerland, the EEA, the United Kingdom, the United States and provider locations disclosed for the selected service.
- Cloud infrastructure, private object storage and email delivery: Amazon Web Services where enabled; hosts application artifacts or delivers operational email.
- AI generation and embeddings: OpenAI; processes prompts, selected Customer Content and generated output for enabled workflows and embeddings.
- AI generation: Anthropic; processes prompts, selected Customer Content and generated output when selected.
- Billing and tax: Stripe; processes Customer billing contacts, subscription, invoice, tax and payment information. Stripe does not receive Customer Content through the ordinary DD HQ analysis workflow.
- Identity: Google; processes identity and authentication data when a user chooses Google sign-in. Google does not receive Customer Content through sign-in.
- Consent-gated analytics: Google Tag Manager and configured tags; processes website usage data only after the required analytics consent and does not receive Customer Content through the ordinary tag configuration.
Customer may request the current provider legal entity, service location and transfer-mechanism information at 5pt.gmbh@gmail.com.