Version 2026-07-30
Data Processing Agreement (DPA)
Introduction
This Data Processing Agreement ("DPA") forms part of the agreement between Nothon's GmbH ("Processor", "we", "us", or "our") and the applicable Tenant Organization ("Controller", "you", or "your") governing the use of the Cadence Platform.
This DPA applies where Nothon's GmbH processes Personal Data on behalf of a Tenant Organization in connection with the Platform.
Capitalised terms have the meanings defined in the Legal Overview, unless otherwise stated.
1. Scope
This DPA applies whenever the Processor processes Personal Data on behalf of the Controller in connection with the provision of the Platform.
Where applicable privacy laws require a data processing agreement, this DPA forms part of the contractual relationship between the parties.
2. Roles of the Parties
For the purposes of this DPA:
- the Controller determines the purposes and means of processing Personal Data;
- the Processor processes Personal Data solely on behalf of the Controller.
Each party remains responsible for complying with its own obligations under applicable data protection laws.
3. Processing of Personal Data
The Processor shall process Personal Data only:
- on documented instructions from the Controller;
- as necessary to provide the Platform;
- to comply with applicable law.
If the Processor believes that an instruction infringes applicable law, it will inform the Controller unless prohibited from doing so.
The Processor shall not process Personal Data for its own purposes except where permitted or required by applicable law.
4. Confidentiality
The Processor shall ensure that persons authorised to process Personal Data:
- are subject to appropriate confidentiality obligations; or
- are bound by statutory duties of confidentiality.
Access to Personal Data shall be limited to personnel who require such access to perform their responsibilities.
5. Security Measures
The Processor shall implement appropriate technical and organisational measures designed to ensure a level of security appropriate to the risks associated with the processing.
The current Technical and Organisational Measures are described in Annex II.
The Processor may update these measures from time to time provided that the overall level of protection is not materially reduced.
6. Subprocessors
The Controller authorises the Processor to engage Subprocessors necessary for operating the Platform.
The current list of approved Subprocessors is maintained in the Subprocessors document, which forms part of this DPA.
The Processor shall ensure that Subprocessors are subject to contractual obligations providing a level of protection substantially equivalent to this DPA.
Where required by applicable law, the Processor will provide notice of material changes to its Subprocessors.
7. International Transfers
Where Personal Data is transferred outside the jurisdiction in which it was collected, the Processor shall implement appropriate safeguards required by applicable law.
Such safeguards may include:
- adequacy decisions;
- Standard Contractual Clauses;
- other legally recognised transfer mechanisms.
8. Assistance
Taking into account the nature of the processing and the information available, the Processor shall provide reasonable assistance to the Controller in relation to:
- requests from data subjects;
- security obligations;
- personal data breaches;
- data protection impact assessments;
- consultations with supervisory authorities.
9. Personal Data Breaches
The Processor maintains procedures for identifying, investigating, and responding to Personal Data breaches.
Where required by applicable law, the Processor shall notify the Controller without undue delay after becoming aware of a Personal Data breach affecting Personal Data processed under this DPA.
The notification shall include available information reasonably necessary for the Controller to fulfil its legal obligations.
10. Audits
Upon reasonable written request, the Processor shall make available information reasonably necessary to demonstrate compliance with this DPA.
Where applicable law requires an audit, the Controller may conduct or appoint an independent auditor, subject to:
- reasonable notice;
- appropriate confidentiality obligations;
- normal business hours;
- minimal disruption to the Platform;
- protection of confidential information relating to other customers.
Where appropriate, independent third-party audit reports or certifications may satisfy audit requests.
11. Return or Deletion of Personal Data
Upon termination of the applicable agreement, the Processor shall delete or return Personal Data at the Controller's request unless:
- applicable law requires continued retention; or
- temporary retention is necessary as part of standard backup processes or to establish, exercise, or defend legal claims.
12. Liability
The liability of each party under this DPA shall be governed by the applicable Terms of Use except where mandatory law provides otherwise.
Nothing in this DPA excludes or limits liability that cannot legally be excluded or limited.
13. Changes to this DPA
The Processor may update this DPA where reasonably necessary to reflect:
- changes in applicable law;
- regulatory guidance;
- Platform functionality;
- operational practices.
Material changes will be communicated in accordance with the Terms of Use.
14. Contact
Questions relating to this DPA may be directed to:
Nothon's GmbH
Weiherallee 11b
CH-8610 Uster
Annex I — Description of Processing
Controller
The applicable Tenant Organization using the Cadence Platform.
Processor
Nothon's GmbH
B. Subject Matter
The provision, operation, maintenance, support, and improvement of the Cadence Platform.
C. Duration
Processing begins when Personal Data is first made available to the Processor and continues for the duration of the applicable agreement, including any applicable retention periods required by law or necessary for secure backup and recovery.
D. Nature and Purpose of Processing
Processing activities may include:
- collection;
- recording;
- organisation;
- storage;
- hosting;
- retrieval;
- consultation;
- transmission;
- synchronisation;
- backup;
- support;
- deletion;
- other processing necessary for operating the Platform.
The purpose of the processing is to provide the services requested by the Controller.
E. Categories of Data Subjects
Depending on the Controller's use of the Platform, Personal Data may relate to:
- Administrators;
- End Users;
- employees;
- contractors;
- customers;
- clients;
- patients;
- students;
- participants;
- other individuals whose Personal Data is entered into the Platform.
F. Categories of Personal Data
Depending on how the Platform is used, Personal Data may include:
- identity information;
- contact information;
- account information;
- scheduling information;
- communications;
- billing information;
- technical information;
- usage information;
- any additional Personal Data uploaded by the Controller.
G. Special Categories of Personal Data
The Platform is not intended for the routine processing of special categories of Personal Data.
Where the Controller chooses to process such data using the Platform, the Controller remains responsible for ensuring that an appropriate legal basis exists and that such processing complies with applicable law.
The Processor maintains technical and organisational measures appropriate to the nature of the services provided and the risks associated with the processing of Personal Data.
Information Security
- Information security policies and procedures.
- Regular review of security practices.
Access Control
- Role-based access controls.
- Least-privilege principles.
- Access reviews.
Authentication
- Secure authentication mechanisms.
- Multi-factor authentication for administrative access where appropriate.
Encryption
- Encryption of data in transit using industry-standard protocols.
- Encryption of data at rest where appropriate.
Infrastructure Security
- Managed cloud infrastructure.
- Network security controls.
- Security monitoring.
Availability
- Redundant infrastructure where appropriate.
- Disaster recovery planning.
- Business continuity procedures.
Backup and Recovery
- Regular backups.
- Tested recovery procedures.
- Controlled restoration processes.
Logging and Monitoring
- Security logging.
- Operational monitoring.
- Incident detection.
Incident Response
- Documented incident response procedures.
- Security event investigation.
- Breach notification processes.
Secure Development
- Secure software development practices.
- Code review.
- Dependency management.
- Security updates.
Personnel Security
- Confidentiality obligations.
- Appropriate staff training.
- Access granted only where required for job responsibilities.
Vendor Management
- Assessment of Subprocessors.
- Contractual data protection obligations.
- Ongoing review of service providers.
The current list of approved Subprocessors is maintained in the separate Subprocessors document.
That document forms part of this DPA and may be updated in accordance with Section 6.