Data Processing Agreement

Last updated: 2026-08-10

This Data Processing Agreement ("DPA") supplements the Terms of Service and applies whenever codebar Solutions AG processes personal data on behalf of a workspace's operating organisation, in the role of processor (or sub-processor, where the Customer itself acts as processor for the data subjects concerned).

1. Parties

Processor: codebar Solutions AG, Hauptstrasse 91, CH-4455 Zunzgen, Switzerland.

Controller: the organisation that operates the flows.codebar.ch workspace and determines what documents and data are processed through it.

2. Subject matter and duration

The Processor processes personal data on the Controller's behalf for the purpose of providing flows.codebar.ch — DocuWare connectivity, document OCR and field extraction, flow automation, AI-assisted interpretation the Controller configures, and the hosted MCP gateway — for as long as the Controller's workspace remains active, and thereafter only as needed to fulfil the deletion obligation in §8.

3. Nature and purpose of processing

Processing consists of: receiving documents and index data from the Controller's DocuWare system (by webhook or scheduled poll); storing the original document file in the Controller's own Azure Blob Storage container; extracting text and structured fields from it via OCR/AI extraction; running the Controller's configured flow logic against that data, which may include sending extracted content to an AI provider or MCP server the Controller has configured; and writing results back to DocuWare. The extracted text, structured data, and processing history are held in the Processor's own application database, hosted in the EU as described in the Privacy Policy, not inside the Controller's own cloud subscription. The Processor therefore holds this data as processor for the full duration described in §2, not merely as a conduit.

4. Controller's instructions

The Processor processes personal data only on the Controller's documented instructions, which are given by configuring flows, DocuWare connections, AI providers, and MCP servers in the product, and as otherwise agreed in writing. The Processor will inform the Controller if, in its view, an instruction infringes applicable data protection law.

5. Confidentiality

The Processor ensures that persons authorised to process personal data (its employees and contractors) are bound by an obligation of confidentiality.

6. Sub-processors

The Processor uses the sub-processors listed in Annex B. The Controller authorises their use generally; the Processor will make reasonable efforts to give notice before adding a new sub-processor that handles document content. Where the Controller itself configures a third-party AI provider or MCP server (Annex B, entries marked "customer-controlled"), that vendor is engaged by the Controller directly and is not a sub-processor of the Processor — the Processor cannot warrant that vendor's safeguards.

7. Assistance with data subject rights and security

The Processor will provide reasonable assistance to the Controller in responding to data subject requests and in meeting obligations around security of processing, breach notification, and data protection impact assessments, to the extent the required information is available to the Processor. The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting data processed under this DPA.

8. Deletion or return of data on termination

On termination of the underlying agreement, the Processor will delete or return Customer data within 90 days of the Controller's request, except: (a) the account-security audit log, which the Processor retains as described in §5 of the Privacy Policy for security and accountability purposes even after a workspace is closed, and (b) data the Processor is required to retain by law.

9. Audits

The Processor will make available to the Controller the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable advance notice and confidentiality.

10. Liability and governing law

Liability under this DPA follows the limitation of liability in the Terms of Service. This DPA is governed by Swiss law; the place of jurisdiction is Zunzgen, Canton of Basel-Landschaft, Switzerland, to the extent permitted by mandatory law.

Annex A — Categories of data subjects and data

  • Data subjects: the Controller's own users of flows.codebar.ch, and any natural persons whose personal data appears in the documents the Controller's workspace processes (for example names, addresses, or identifiers on an invoice or contract).
  • Categories of data: the categories itemised in §5 and §6 of the Privacy Policy. Document content and metadata are under the Controller's control and unknown to the Processor in advance — they can be any category of personal data the Controller chooses to run through a workspace, including special categories if the Controller's documents contain them.

Annex B — Sub-processors

The Processor's sub-processors are those listed in §9 of the Privacy Policy, which forms Annex B to this DPA and is maintained as the single authoritative list. That section states, for each one, what it is used for, what it receives, and where it processes. Entries marked "customer-controlled" are engaged by the Controller directly and are not sub-processors of the Processor, as set out in §6 above.

Transfers outside Switzerland or the EU/EEA rely on Standard Contractual Clauses, an applicable adequacy decision, or Data Privacy Framework certification, as described in §11 of the Privacy Policy.

Annex C — Technical and organisational measures

The Processor's technical and organisational measures are those set out in §13 of the Privacy Policy, which forms Annex C to this DPA. Suspected vulnerabilities and incidents can be reported to helpdesk@codebar.ch.