Data Processing Agreement
Die deutsche Fassung ist massgebend / The German version is binding. Binding German version
1. Subject matter and parties
1.1 This Data Processing Agreement (“DPA”) governs how Ernst & Conte GmbH, Oberneuhofstrasse 8, 6340 Baar, Switzerland (“we”, “processor”) processes personal data on behalf of the customer (“you”, “controller”) when you use our services, currently Tessa Cloud.
1.2 The DPA is part of the contract under the General Terms (“Terms”). On data protection questions it prevails over every other contract document.
1.3 The Swiss Federal Act on Data Protection (FADP) applies. Where you are subject to the EU General Data Protection Regulation (GDPR), this DPA also meets the requirements of Art. 28 GDPR. The terms “processor” and “controller” are used in the sense of both laws.
2. Roles
2.1 You are the controller for the personal data in your customer content: test artifacts with the personal data they contain, and the member list of your organisation (name, e-mail address, profile picture, and role of the invited persons as they appear in the workspace). We are the processor.
2.2 For the sign-in and account data we need to authenticate persons and operate the service securely (identifier at the identity provider, sign-in times, technical logs), and for billing data, we are the controller ourselves. The Privacy Notice for Tessa Cloud informs about this.
2.3 Your AI provider is not our subprocessor. You contract it directly with your own API key; we transmit data to it on your behalf. The same applies to GitHub or GitLab integrations you configure.
3. Description of the processing
- Subject matter: operation of Tessa Cloud for your organisation (hosting, storage, execution of test scenarios, display of reports, support).
- Duration: term of the contract plus the retention period under section 8 of the Terms.
- Nature and purpose: storage, display, analysis, and transmission to the AI provider you contracted, in order to run tests and provide the results.
- Categories of personal data and data subjects: Annex 2.
4. Instructions
4.1 We process personal data only on your documented instructions. Instructions are this DPA, the Terms, the service terms, and the settings and actions your users perform in the product. You give further instructions in text form to [email protected]. If Swiss, EU, or EU member state law obliges us to process differently, we inform you before processing unless that law prohibits it.
4.2 If we consider an instruction unlawful, we tell you and may suspend its execution until you confirm or change the instruction.
4.3 We do not process the data for our own purposes.
5. Confidentiality
Everyone at our end with access to personal data is bound to confidentiality and has only the access their task requires.
6. Security
6.1 We implement the technical and organisational measures in Annex 1 and adapt them to the state of the art without lowering the level of protection.
6.2 You are responsible for ensuring that the data you store in Tessa Cloud may be stored there and for choosing access rights, roles, and test data appropriately.
7. Subprocessors
7.1 You authorise us to engage the companies named in the list of subprocessors. We bind them in writing to data protection and security at least at the level of this DPA and remain responsible to you for their performance.
7.2 We announce new or replaced subprocessors at least 30 days in advance by publishing the list in a new version and informing the owners of your organisation. If you have a substantive reason against the engagement, you may object until it takes effect. If we find no solution, you may terminate the contract with effect from that date; we refund prepaid fees pro rata.
8. Assistance
8.1 We assist you, with the means of the product and the information available to us, in responding to requests from data subjects for access, rectification, deletion, and other rights. Requests that reach us directly we forward to you.
8.2 We assist you, with the information available to us, with your obligations regarding security of processing, notification of personal data breaches, data protection impact assessments, and prior consultation of supervisory authorities (Art. 32 to 36 GDPR, Art. 22 to 24 FADP), to the extent our processing is concerned.
8.3 We notify you of personal data breaches affecting your data without undue delay, and at the latest 48 hours after becoming aware of them, with the information you need for your own notification duties. We supplement the information as soon as we know more.
8.4 Where the effort for assistance exceeds the usual extent, we may charge it at our usual hourly rates. We inform you beforehand.
9. Return and deletion
9.1 You can export your data at any time (Terms, section 11; page Your data).
9.2 After the contract ends we delete all personal data of your organisation following the schedule in section 8 of the Terms: 90 days after the lock; backups that still contain this data are overwritten at the latest 30 days after that. On your request we delete earlier. Statutory retention duties remain reserved.
10. Evidence and audits
10.1 We provide all information you need to demonstrate compliance with this DPA: the description of the measures under Annex 1, the current list of subprocessors, and answers to your questions about the processing.
10.2 If that is not sufficient, you or an auditor mandated by you and bound to confidentiality may conduct an audit, including on site: with 30 days’ notice, at most once a year unless a specific reason or a supervisory authority requires more, during usual business hours, and without access to other customers’ data. We contribute to the audit. You bear your own costs; we may charge our effort, to a reasonable extent, at our usual hourly rates.
11. Place of processing and international transfers
11.1 We process personal data in Switzerland and in the EU or EEA. Hosting takes place in Germany and Finland; for Enterprise customers in Switzerland where the order form provides for it.
11.2 Where a subprocessor processes data in a country without adequate data protection, currently Cloudflare, Inc. (USA) for bot protection at signup and delivery of the website, we base the transfer on the EU standard contractual clauses with the Swiss addendum or on another legally recognised safeguard. Details are in the list of subprocessors.
11.3 Transfers to your AI provider happen on your documented instruction (your configuration in the product) and under your responsibility. Choose a provider and a region that meet your requirements, and make sure the safeguards under Chapter V GDPR or Art. 16 and 17 FADP are in place.
12. Duration and final provisions
12.1 This DPA applies as long as we process personal data for you.
12.2 Liability, changes, governing law, place of jurisdiction, and language follow the Terms. The limitation of liability in the Terms also applies to claims under this DPA, to the extent the law allows.
Annex 1: Technical and organisational measures
- Hosting: data centres of Hetzner Online GmbH in Germany and Finland (Enterprise per order form: a data centre in Switzerland) with physical access control, redundant power supply, and network connectivity provided by the data centre operator.
- Encryption in transit: TLS for all connections between browser, CLI, executors, and server, and between system components across the internet.
- Tenant isolation: every organisation has its own database and its own storage for reports, artifacts, and settings. Assignment happens through the organisation in the signed access token; access across organisation boundaries is not provided for in the product.
- Access control: sign-in through an identity broker (OpenID Connect) with Google or GitHub accounts or, for Enterprise, with your own identity provider (single sign-on); signed, time-limited access tokens for browser, CLI, WebSockets, and executors; roles within the organisation; devices are bound to their authenticated executor and can be made private.
- Administrative access: only named Ernst & Conte staff with personal accounts and keys, on a need-to-know basis. Access to customer data only for troubleshooting or at your request.
- Operations: regular security updates, monitoring and logging of operations, separate environments for development and production.
- Backups: regular backups at the hosting location (EU; in Switzerland for Enterprise with Swiss hosting), overwritten at the latest 30 days after a deletion.
- AI provider: data from test runs flows only to the provider you configure in the product with your own key.
- Organisation: staff are bound to confidentiality and instructed in data protection and security. A process for security incidents with notification under section 8.3 is in place.
Annex 2: Data subjects and data categories
Data subjects: users of your organisation; persons whose data appears in your applications under test, test data, screenshots, recordings, and logs (such as test accounts, employees, and depending on the application also customers of your application); persons named in your scenarios, comments, or issues.
Data categories:
- Member list: name, e-mail address, profile picture, and role of the persons in your organisation.
- Usage and log data: timestamps, actions in the product, IP address, browser.
- Test artifacts: scenarios, test plans, schedules, reports, screenshots, recordings, application logs, App Map, and uploaded test builds, with all personal data your application and test data contain.
- Integration data: issue texts, repository names, and access tokens you store for GitHub or GitLab.
We process special categories of personal data only if your application or your test data contain them. Use synthetic test data where possible.