Skip to main content

Data Processing Agreement (DPA)

This Data Processing Agreement (DPA, the Agreement) is the single, binding document governing how Zation AG, Suurstoffi 18b, CH-6343 Rotkreuz (Zation, the Processor) processes personal data on behalf of its customers (each a Controller, you) when delivering the Zation FinOps Platform (the Platform).

It is compliant with both the EU General Data Protection Regulation (GDPR) and the revised Swiss Federal Act on Data Protection (revDSG / FADP).

Binding version

This online page is the binding Data Processing Agreement. There is no separate PDF or signed copy — the DPA as published here is the agreement that applies. For questions, contact info@zation.io.

1. Scope and effect

1.1 This Agreement takes effect when the Platform services begin and governs all processing of personal data under all orders and quotes between the parties, without the need for separate execution per order.

1.2 Where this Agreement and your master agreement with Zation conflict on a data-protection matter, this Agreement prevails.

2. Definitions

  • Personal Data — any information relating to an identified or identifiable natural person, as defined under applicable data protection laws.
  • Processing — any operation performed on personal data, including collection, recording, storage, use, disclosure, and deletion.
  • Data Protection Laws — all applicable laws on the processing of personal data, including the GDPR and the revDSG / FADP.
  • Sub-Processor — any third party engaged by Zation to process personal data on your behalf.

3. Roles and instructions

3.1 You are the controller and Zation is the processor (Art. 28 GDPR, Art. 9 revDSG).

3.2 Zation processes personal data only on your documented instructions, including for transfers, unless required otherwise by law — in which case Zation informs you before processing, unless that law prohibits it.

4. Details of the processing

See Annex 1 — Details of Processing for the subject matter, duration, nature, purpose, data categories, and data subjects.

5. Processor obligations

5.1 Instructions — process only as instructed (Clause 3.2).

5.2 Security — implement and maintain technical and organizational measures that ensure a level of security appropriate to the risk. The current measures are described under Security and form part of this Agreement.

5.3 Confidentiality — ensure everyone authorized to process personal data is bound by confidentiality obligations.

5.4 Assistance — assist you, taking into account the nature of the processing, with: responding to data subject requests (Clause 9); data protection impact assessments and prior consultations (Art. 35–36 GDPR); and your own breach-notification duties.

5.5 Breach notification — notify your admin contact without undue delay, and no later than 48 hours, after becoming aware of a personal data breach affecting your data, covering the nature of the breach, the data categories affected, and the measures taken (Clause 10).

6. Sub-processors

6.1 You give a general written authorization for Zation to engage Sub-Processors. The current list is published under Sub-Processors and forms part of this Agreement.

6.2 Zation imposes on each Sub-Processor, by written contract, data protection obligations equivalent to those in this Agreement, and remains liable for the Sub-Processor's performance.

6.3 Zation gives you at least 30 days' advance notice of any addition or replacement, by updating the list and posting a notice in the Platform under Notifications. You may object in writing on reasonable data-protection grounds within the notice period. If the parties cannot resolve the objection, you may terminate the affected service under Clause 13.

7. Data residency and international transfers

7.1 Customer content and personal data is hosted and processed in Switzerland North. Backups stay within Switzerland.

7.2 Limited operational metadata required to authenticate and route requests may be processed by Microsoft identity Sub-Processors within the EEA, which Switzerland recognizes as providing adequate protection (Annex 1 of the Swiss Data Protection Ordinance, DSV).

7.3 Any transfer to a country without adequate protection relies on the EU Standard Contractual Clauses together with the Swiss addendum, or another mechanism recognized under Art. 16–17 revDSG.

8. Audit and inspection

8.1 Zation makes available the information necessary to demonstrate compliance with this Agreement, primarily through current third-party audit reports and certifications.

8.2 On reasonable prior notice, and no more than once per year unless required by a supervisory authority or following a breach, you may audit Zation's processing, subject to confidentiality and to not disrupting Zation's operations or other customers' data.

9. Data subject rights

Because Zation processes data only on your instructions, data subject requests (for example, access or deletion) are handled through you as the controller. Zation assists you in responding, including by appropriate technical and organizational measures.

10. Personal data breach

On becoming aware of a personal data breach affecting your data, Zation notifies you per Clause 5.5. This supports your duty to notify the Federal Data Protection and Information Commissioner (FDPIC) under Art. 24 revDSG and the supervisory authority under Art. 33 GDPR.

11. Return and deletion

11.1 On termination, you choose whether Zation returns or deletes all personal data processed on your behalf, within 30 days.

11.2 Deletion includes backups — residual backup copies are overwritten within the normal backup rotation cycle. Zation confirms deletion in writing on request, unless retention is required by law.

12. Liability

Liability for breach of this Agreement or of Data Protection Laws is governed by, and subject to the limitations and caps in, your master agreement with Zation (see the General Terms and Conditions, Section VIII). Nothing in this Clause limits liability that cannot be limited under Data Protection Laws.

13. Term and termination

This Agreement runs for as long as Zation processes personal data on your behalf. Either party may terminate with 90 days' written notice; termination of the master agreement terminates this Agreement.

14. Governing law and jurisdiction

This Agreement is governed by Swiss law, to the exclusion of conflict-of-law rules. The exclusive place of jurisdiction is the competent court at Zation's registered office (Zug, Switzerland), subject to any mandatory forum under Data Protection Laws.


Annex 1 — Details of processing

ItemDetail
Subject matterAnalysis of software and cloud usage and consumption
DurationFor the term of the Platform services
Nature & purposeAnalyze usage and consumption to optimize, modernize, reduce cost, and increase utilization
Data subjectsTechnical Microsoft Entra ID users in your tenant (members and guests)

Categories of personal data

CategoryExamples
User credentialsUsernames, user principal names (UPNs), Microsoft Entra ID directory data
Application usage dataSign-in activity, feature and license usage
Consumption owner dataAttribution of cloud and software consumption to individuals

Annex 2 — Technical and organizational measures

The technical and organizational measures required under Clause 5.2 are described under Security.

Annex 3 — Sub-processors

The current sub-processor list required under Clause 6 is published under Sub-Processors.