Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between DCHUB, a sole proprietorship under Swiss law, Seestrasse 216, 8810 Horgen, Switzerland (“Revnetic”, the “Processor”), and the workshop that creates a Revnetic account (the “Controller”). It governs the processing of personal data that the Controller entrusts to Revnetic and is drafted to satisfy Art. 28 of the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (revFADP). It is accepted electronically at sign-up and is binding without signature.

1. Subject matter and duration

The subject matter of the processing is the provision of the Revnetic workshop-management platform. This DPA applies for as long as the Controller holds a Revnetic account, plus the post-termination retention window in Section 10.

2. Nature and purpose of the processing

Revnetic hosts, stores, displays, transmits, and otherwise processes personal data entered by the Controller solely to provide the features of the Service — customer and vehicle records, job scheduling, quotes and invoicing, the customer portal, email communication, and the AI assistant. Revnetic does not process this data for its own purposes and never uses it to train AI models.

3. Types of personal data

Names; contact details (email, phone, postal address); vehicle data (VIN, registration plate, make/model, odometer, service and repair history); appointment and job details; quote and invoice data; insurance-claim details where entered; and communication content with delivery metadata.

4. Categories of data subjects

The Controller's customers and prospective customers, their contact persons, and the Controller's own staff members holding user accounts.

5. Obligations of the Processor

Revnetic shall: (a) process personal data only on the Controller's documented instructions, including as regards transfers, unless required by law to do otherwise; (b) ensure that persons authorised to process the data are bound by confidentiality; (c) implement the security measures in Section 6; (d) comply with the sub-processor conditions in Section 7; (e) assist the Controller as set out in Sections 8 and 9; (f) delete or return data as set out in Section 10; and (g) make available the information necessary to demonstrate compliance as set out in Section 11.

6. Security measures

Revnetic implements appropriate technical and organisational measures, including encryption in transit (TLS), strict per-tenant data isolation, hashed credentials, short-lived access tokens, role-based access control, multi-factor authentication, audit logging of administrative actions, and regular backups.

7. Sub-processors

The Controller grants general authorisation to engage the sub-processors listed in the Privacy Policy: Hetzner (hosting and object storage, EU), Cloudflare (DNS, CDN, and network security), Stripe (payment processing), Resend (email delivery and inbound capture), Anthropic (AI assistant), Sentry (error monitoring), and BetterStack (uptime monitoring). Revnetic imposes data-protection obligations on each sub-processor equivalent to those in this DPA and remains fully liable for their performance. Revnetic will announce intended additions or replacements in advance, giving the Controller the opportunity to object on reasonable data-protection grounds.

8. Assistance with data-subject rights

Taking into account the nature of the processing, Revnetic assists the Controller with appropriate technical and organisational measures in fulfilling requests from data subjects (access, rectification, erasure, restriction, portability, objection). Requests that reach Revnetic directly from a workshop's end customers are forwarded to the Controller. Contact: [email protected].

9. Personal data breach notification

Revnetic notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and provides the information reasonably required for the Controller to meet its own notification obligations.

10. Deletion and return of data

The Controller can export its data at any time while the account is active. Upon termination, uploaded files and documents are deleted promptly. Remaining tenant data is retained to allow reactivation and is permanently deleted upon the Controller's request, except where statutory retention duties (for example, 10 years for accounting records under Art. 958f of the Swiss Code of Obligations) require otherwise.

11. Audits and information

Revnetic makes available all information reasonably necessary to demonstrate compliance with this DPA and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by it — at most once per year, with reasonable prior notice, during business hours, and without disrupting operations. In the first instance, audit requests are satisfied through written information and existing documentation.

12. International transfers

Personal data is hosted in Switzerland or the EU/EEA. Where a sub-processor processes personal data outside Switzerland or the EEA (for example in the US), the transfer is protected by the EU Standard Contractual Clauses together with the Swiss addendum recognised by the FDPIC.

13. Final provisions

In case of conflict between this DPA and the Terms of Service, this DPA prevails with respect to the processing of personal data. This DPA is governed by Swiss law; the exclusive place of jurisdiction is Zürich, Switzerland.

Data Processing Agreement · Revnetic