Version 1.2 · Date: 14.09.2026
between
Traniva AG
Zimbergstrasse 11
8335 Hittnau
Switzerland
CHE-491.543.762
– hereinafter “Traniva” or “Processor” –
and
the Customer, who accepts this Agreement in connection with an order, registration, licensing or an individual contract for the use of TAOM.AI or TAOM Process Studio
– hereinafter ‘Customer’ or ‘Data Controller’ –
together the ‘Parties’.
1. Subject Matter and Scope
1.1 This Agreement governs the processing of personal data by Traniva on behalf of the Customer in connection with the use of TAOM.AI and, in particular, TAOM Process Studio.
1.2 It supplements the main contract between the Parties, in particular the General Terms and Conditions for TAOM.AI / TAOM Process Studio, as well as, where applicable, individual quotations, orders, enterprise contracts, service level agreements, statements of work or other agreements.
1.3 Insofar as Traniva processes personal data exclusively on behalf of and in accordance with the instructions of the Customer, Traniva acts as a data processor and the Customer as the data controller.
1.4 This agreement serves, in particular, to fulfil the requirements of the Swiss Data Protection Act (DSG), specifically the requirements relating to data processing on behalf of a controller, as well as – where applicable – Article 28 of the General Data Protection Regulation (GDPR).
1.5 Where Traniva processes personal data for its own purposes and under its own responsibility under data protection law, in particular for contract management, invoicing, IT security, prevention of misuse, compliance with legal obligations or the safeguarding of its own legal claims, Traniva is itself the data controller for such processing. Such processing does not fall within the scope of data processing on behalf of the client under this agreement.
2. Subject matter, nature and purpose of the processing
2.1 Traniva provides the Customer with TAOM Process Studio as a cloud-based Software-as-a-Service solution for the modelling, analysis, documentation and management of business processes and organisational structures, as well as for related functions.
2.2 The processing carried out on behalf of the Customer may include, in particular, the following activities:
- Storage and management of process models and process information;
- Creation and editing of BPMN models, process maps and organisational structures;
- Processing of role, responsibility and RACI information;
- Processing of requirements, risks, controls, test cases, audit information and results;
- Storage and processing of documentation and process-related content;
- user, role, authorisation and approval information;
- collaboration between authorised users;
- import, export and integration of data;
- processing of technical metadata and log information;
- AI-supported analysis, structuring, creation, supplementation and editing of process and documentation content;
- further processing operations initiated by the Customer within the scope of the agreed TAOM functions.
2.3 Traniva processes the data provided by the Customer exclusively for the purpose of providing the agreed services and in accordance with the Customer’s documented instructions, provided there is no legal obligation to process the data for any other purpose.
3. Duration of data processing on behalf of the Customer
3.1 The processing on behalf of the client commences when the processing of personal data on the client’s behalf begins and generally continues for the duration of the underlying contractual relationship.
3.2 The obligations under this agreement shall continue beyond the end of the contract for as long as Traniva still stores the client’s personal data in the context of processing on behalf of the client.
3.3 Clause 13 applies to the deletion or return of the data.
4. Categories of data subjects
Depending on the use of TAOM Process Studio, the following categories of data subjects may be affected in particular:
- Employees and former employees of the client;
- Contractors, consultants and project staff;
- Users of TAOM Process Studio;
- contact persons at customers, suppliers and other business partners;
- process owners, role holders, approvers and other persons named in process or organisational models;
- participants in review, approval and governance processes;
- other persons whose data the customer enters, imports or has processed in TAOM Process Studio on its own responsibility.
5. Categories of personal data
Depending on the use, the following categories of personal data in particular may be processed:
- Name and business contact details;
- User, account and technical identifiers;
- Organisational unit, role, function and responsibility;
- Role and authorisation information;
- Release and approval information;
- Process and organisational information;
- Requirements, risks, controls, and test and audit information;
- Content of process descriptions and documentation;
- Technical usage, event and log data;
- Content provided by the customer for AI-supported functions;
- data and documents imported by the customer;
- other personal information which the customer processes on their own responsibility within the platform.
Special categories of personal data pursuant to Article 9 of the GDPR or personal data requiring special protection under the Swiss Data Protection Act (DSG) are not part of the intended standard use of TAOM Process Studio.
If the customer intends to process such data systematically, it must first be checked whether the agreed TAOM configuration is suitable for this purpose and whether additional technical, organisational or contractual measures are required.
6. Instructions from the customer
6.1 Traniva processes personal data only on the basis of documented instructions from the customer, including with regard to transfers of personal data to a third country or an international organisation, unless Traniva is obliged to process such data differently under applicable law. In that case, Traniva informs the customer of the legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
6.2 The following, in particular, are considered to be documented instructions:
- the use and configuration of TAOM Process Studio by authorised users;
- settings and authorisations within the platform;
- imports, exports, integrations and AI functions initiated by the Customer;
- the underlying main contract;
- supplementary written or electronic instructions from the Customer.
6.3 Further instructions may be sent to Traniva in writing.
6.4 If Traniva considers that an instruction contravenes applicable data protection law, Traniva shall inform the customer without delay. Traniva is entitled to suspend the execution of the instruction in question until the matter has been clarified.
6.5 If Traniva is legally obliged to carry out processing that deviates from an instruction from the customer, Traniva shall inform the customer prior to such processing, insofar as this is permitted by law.
7. Obligations and Responsibilities of the Customer
7.1 The customer remains responsible for the lawfulness of the processing of personal data initiated by them.
7.2 In particular, the customer shall ensure that:
- there is an adequate legal basis for the processing;
- data subjects are duly informed where necessary;
- only data necessary for the respective purpose is processed;
- users are granted only the access rights necessary for their tasks;
- personal data is kept factually correct and, where necessary, up to date;
- content processed as part of AI functions is suitable and permissible for such processing.
7.3 In particular, the Customer decides which data, processes, documents, roles and users are included in TAOM Process Studio and which available functions are used.
8. Confidentiality and Access Authorisation
8.1 Traniva ensures that persons granted access to personal data processed on its behalf are bound by a duty of confidentiality or are subject to a corresponding statutory duty of confidentiality.
8.2 Access rights are granted in accordance with the principles of ‘need-to-know’ and least privilege .
8.3 Personal customer data may only be processed within Traniva by individuals who require access in order to fulfil their duties.
8.4 The obligation of confidentiality continues even after the relevant individual’s employment has ended.
9. Technical and organisational measures (TOM)
9.1 Traniva shall implement appropriate technical and organisational measures to protect the personal data processed on behalf of the client, taking into account the risk, the state of the art, the nature and scope of the processing, and the implementation costs.
9.2 The measures are designed, in particular, to safeguard:
- confidentiality;
- integrity;
- availability;
- the resilience of the systems and services used.
9.3 The technical and organisational measures include, insofar as relevant to the processing in question, measures in the following areas in particular:
- identity and access management;
- authorisation management;
- client and workspace segregation;
- protection of data transmission;
- protection of stored data;
- logging and traceability;
- data backup and recovery;
- system and infrastructure security;
- patch and vulnerability management;
- development and change management;
- incident response;
- deletion and retention procedures;
- organisational data protection and information security;
- monitoring of subcontractors engaged.
9.4 The technical and organisational measures applicable to TAOM Process Studio are set out in Annex 1 – Technical and Organisational Measures (TOM).
9.5 Traniva may further develop and amend the technical and organisational measures in line with technical developments, provided that this does not result in the agreed level of protection being significantly reduced overall.
10. Sub-processors
10.1 The Customer grants Traniva general authorisation to engage further sub-processors, provided that these are engaged for the purpose of providing the agreed TAOM services.
10.2 Traniva contractually imposes on sub-processors the same data protection obligations as those incumbent on Traniva under this agreement, in so far as they are applicable to the sub-processing concerned. Where a sub-processor fails to fulfil its data protection obligations, Traniva remains responsible to the customer for that sub-processor’s processing.
10.3 Traniva shall maintain a publicly available list of sub-processors engaged for TAOM, which is kept up to date. This list shall contain, in particular, details of the provider, purpose, types of data, place of processing and the legal basis for the processing.
The current TAOM list of sub-processors forms part of Traniva’s transparency and information obligations.
10.4 The sub-processors in place at the time of conclusion of this agreement are deemed to have been approved. The version of the list in force at that time is the relevant one. Every version carries a version number and the date from which it applies; earlier versions are archived under “What’s new” in the customer account, with additions and removals.
10.5 Traniva shall inform customers with an existing data processing agreement in an appropriate manner prior to the appointment of a new sub-processor or the replacement of an existing one.
10.6 The customer may, within 30 days of notification, object to the use of a new sub-processor on verifiable data protection grounds.
10.7 In such a case, the parties shall endeavour to find a reasonable solution. If Traniva is unable to provide the service in question without the sub-processor concerned, or cannot do so in a commercially reasonable manner, and if no suitable alternative can be agreed, the parties may terminate the service affected in accordance with the main contract.
10.8 Traniva remains liable to the customer for the fulfilment of its sub-processors’ data protection obligations to the extent required by law.
11. AI-supported processing
11.1 TAOM Process Studio may use external language models and other AI services to perform certain functions.
11.2 Insofar as personal customer data is transferred to an external provider in the context of such a function and processed there on behalf of the Customer, that provider shall be treated as a sub-processor in accordance with Clause 10.
11.3 The content and contextual information processed within the scope of an AI function are determined by the function triggered by the Customer or its authorised users and the content provided for this purpose.
11.4 The customer is responsible for ensuring that no data is fed into AI functions where its processing is not permitted for the intended purpose. The principles of lawfulness and data minimisation must be observed.
11.5 The external providers used in each case and their processing locations are set out in the current list of sub-processors.
11.6 Where specific requirements regarding model providers, models, hosting, processing region, data retention or the customer’s own infrastructure are agreed for an Enterprise configuration, these individual agreements shall take precedence over the standard provisions.
11.7 Zero data retention and special configurations. A specific technical feature of an external AI service, in particular zero data retention (ZDR), a specific processing region or a defined data retention setting, shall only be deemed assured if it has been expressly agreed for the specific customer configuration and confirmed in writing by Traniva. The assurance applies exclusively to the providers, models, API endpoints and technical functions agreed in that context. Changes to these components may require the availability to be examined again.
12. International data transfers
12.1 Traniva shall ensure that cross-border transfers of personal data in the context of order processing are carried out in compliance with the applicable data protection law.
12.2 Where personal data is transferred to countries for which there is no recognised adequate level of data protection, Traniva shall ensure that a transfer mechanism permissible under applicable law is in place.
These may include, in particular, recognised standard contractual clauses, any necessary Swiss supplementary provisions or other legally permissible safeguards.
12.3 Where required following a specific risk assessment, supplementary technical and organisational measures shall be implemented.
12.4 The known processing locations of the sub-processors engaged are set out in the current list of sub-processors.
13. Return and erasure
13.1 Upon completion of the agreed services, Traniva shall, at the customer’s choice, erase all personal data processed on the customer’s behalf or make it available to the customer in a customary technical format, and shall erase existing copies, unless there is a statutory obligation to retain them.
13.2 Statutory retention obligations and other mandatory legal grounds for retention remain unaffected.
13.3 Data contained in technical backup copies may remain there until the relevant backup copy is routinely overwritten or deleted. During this period, it must not, in principle, be further processed for any other purposes.
13.4 The retention and deletion periods applicable to individual data types and functions are additionally set out in the main contract, the privacy policy, the agreed licence tier and the relevant technical configuration.
13.5 Upon a justified request, Traniva shall confirm to the customer that the data has been deleted, insofar as this is necessary to fulfil data protection-related obligations to provide evidence.
14. Support with data subjects’ rights
14.1 Traniva shall provide the customer with appropriate support, taking into account the nature of the processing and the information available, through suitable technical and organisational measures to enable the customer to fulfil its obligations towards data subjects.
14.2 This applies in particular, insofar as provided for under the applicable law:
- access;
- rectification;
- erasure;
- restriction of processing;
- data portability;
- objection.
14.3 If Traniva receives a request from a data subject that clearly relates exclusively to data processed by Traniva on behalf of the client, Traniva shall, as a general rule, forward the request to the client concerned and shall not respond to the substance of the request without the client’s instructions, unless there is a legal obligation to provide a direct response.
15. Assistance with further data protection obligations
Traniva shall provide the client with appropriate assistance in fulfilling statutory obligations, taking into account the nature of the processing and the information available to Traniva, in particular with regard to:
- security of processing;
- assessment of data protection and security incidents;
- data protection impact assessments;
- required prior consultations with supervisory authorities;
- enquiries from competent data protection authorities.
16. Data security breaches
16.1 Traniva shall inform the customer without delay upon becoming aware of a breach of data security or the protection of personal data, insofar as data covered by the scope of this Agreement is affected.
16.2 The notification shall include, in particular, the following information, insofar as it is available and applicable at that time:
- a description of the nature of the incident;
- the data or categories of data affected;
- the likely consequences;
- countermeasures already taken or planned;
- a contact person for further information.
16.3 Where not all information is available at the time of the initial notification, this may be supplemented in stages.
16.4 Traniva shall take appropriate measures to contain, investigate and remedy the incident.
17. Evidence and Rights of Audit
17.1 Upon reasonable request, Traniva shall provide the customer with the information necessary to demonstrate compliance with the obligations under this Agreement.
17.2 Existing documentation, technical and organisational measures, security information, audit reports or comparable suitable evidence shall be used as the primary means of verification.
17.3 Where required by law and where the evidence provided is insufficient for an appropriate audit, the Customer may carry out an audit itself or through an independent auditor bound by a duty of confidentiality.
17.4 An audit shall be carried out with reasonable notice and, as a general rule, during normal business hours.
17.5 Audits must not:
- must not compromise the security of the TAOM platform;
- must not disclose any data relating to other customers;
- must not infringe any trade or business secrets of third parties;
- must not unreasonably disrupt Traniva’s business operations.
17.6 The parties shall agree in advance on the scope, timing and conduct of any necessary audit.
18. Processing by Traniva on its own behalf
18.1 Insofar as Traniva processes personal data on its own responsibility for the purposes of contract administration, invoicing, compliance with its own legal obligations, IT and platform security, the prevention of misuse, or the safeguarding of its own legal claims, Traniva does not act as a data processor in respect of such processing.
18.2 The details of such processing are set out in the main contract and the applicable privacy policy.
18.3 The roles of the parties may therefore vary depending on the processing operation. This agreement applies exclusively to processing operations in which Traniva processes personal data on behalf of the customer.
19. Order of Precedence
19.1 In the event of any conflict between this Agreement and the General Terms and Conditions or other general contractual terms, the provisions of this Agreement shall take precedence with regard to the processing of personal data on behalf of the Customer.
19.2 Data protection provisions agreed individually between the parties shall take precedence over this Agreement, unless expressly agreed otherwise.
19.3 Mandatory applicable data protection law remains unaffected.
20. Amendments
20.1 Traniva may amend this Agreement to reflect changes in legal requirements or technical or organisational developments.
20.2 Material amendments shall be communicated to the Customer in an appropriate manner before they take effect. Amendments are recorded per version as release notes; these are available to the Customer in their login area and set out what has changed with the version concerned. This also applies to amendments to Annex 1 – Technical and Organisational Measures (TOM).
20.3 Amendments which, under applicable law or by virtue of the existing contractual relationship, require the customer’s renewed consent shall only take effect for the customer concerned once such consent has been given.
20.4 Traniva shall document the version of this agreement accepted by the customer and the date of consent. The wording in force at the time of conclusion is recorded as contract documentation and is available in the customer account. Where consent is obtained for a later version, that version and its date are recorded as well; until then, the last version confirmed applies in accordance with clause 20.3.
21. Term and Termination
21.1 This Agreement shall enter into force upon its acceptance by the Customer, but no later than the commencement of any order processing covered by it.
21.2 It shall remain in force for the duration of the underlying contractual relationship and, beyond that, for as long as Traniva processes the Customer’s personal data in the context of order processing.
21.3 Obligations regarding confidentiality and the protection of any remaining personal data shall continue to apply even after the termination of this Agreement.
22. Governing Law and Jurisdiction
22.1 To the extent permitted by law, the governing law and jurisdiction shall be determined in accordance with the underlying main contract or the agreed General Terms and Conditions of TAOM.AI / TAOM Process Studio.
22.2 Mandatory data protection powers of public authorities and the mandatory rights of data subjects remain unaffected.
23. Electronic Conclusion and Evidence
23.1 This agreement may be concluded in writing or electronically.
23.2 The customer’s express electronic consent during the registration, ordering, licensing or contractual process shall be deemed acceptance of this agreement.
23.3 The person accepting this agreement on behalf of an organisation confirms that they are duly authorised to do so.
23.4 Traniva shall document at least:
- the customer or the organisation;
- the accepted version of this Agreement (DPA);
- the date and time of consent;
- the relevant order, licence or contractual relationship.
23.5 The version of this Agreement (DPA) applicable to the customer’s contractual relationship shall be made available to the customer electronically or rendered permanently accessible.