Legal
Data Processing Agreement (DPA)
For customers of the AKKON platform (Art. 28 GDPR, Art. 9 FADP).
Version 2026-09-25 · Last updated: 25 September 2026
1. Parties and scope
This agreement applies between the customer of the AKKON platform as controller (hereinafter the “Customer”) and G O L B A N AG, Bahnhofstrasse 57, 9320 Arbon, Switzerland, as processor (hereinafter “AKKON”). AKKON.ai is a business unit of G O L B A N AG. The agreement governs the obligations of the parties under Art. 9 of the Swiss Federal Act on Data Protection (FADP) and, where applicable, under Art. 28 of the General Data Protection Regulation (GDPR). The terms “processor” (Auftragsverarbeiter) and “processing” (Verarbeitung) correspond to the terms “Auftragsbearbeiter” and “Bearbeitung” used in the FADP. The terms and conditions (the “Terms”) apply in addition; in matters of data protection, this agreement takes precedence.
2. Subject matter and duration
The subject matter is the processing by AKKON, in providing the platform, of personal data that the Customer brings into the platform or has generated there (hereinafter “Customer Content”). Processing for which AKKON itself is the controller is not covered, in particular the website, the administration of user accounts, contract handling and billing; the privacy policy applies to such processing.
The agreement applies for the duration of the use of the platform and beyond, until all Customer Content has been deleted or returned in accordance with section 11.
3. Nature and purpose of the processing
AKKON processes Customer Content exclusively in order to provide the platform in accordance with the Terms, in particular for:
- storing, displaying, searching, exporting and deleting Customer Content;
- the processing of tasks by AI agents, including the transmission of the information required for this to AI models and, if switched on, live research on the web;
- the preparation of uploaded documents for the knowledge base so that agents can find relevant excerpts;
- the execution of actions approved by the Customer, such as sending emails or creating tasks, appointments and documents;
- keeping a log of decisions and actions for each company;
- the project room for collaboration with WERKFORM.ai following a handover confirmed by the Customer (section 14).
4. Types of personal data
- Information about users in connection with content: name, email address, role, authorship of entries, approvals and log entries;
- Company and project data, insofar as they relate to individuals, such as information about the team, contact persons, customers or business partners;
- Content of uploaded files and the knowledge base text sections created from them;
- The agents’ results, drafts and source citations;
- Content of approved actions, such as the recipient address, subject and text of emails or information about appointments;
- Messages, milestones, appointments and files in the project room.
AKKON only processes sensitive personal data (Art. 5(c) FADP) or special categories of personal data (Art. 9 GDPR) if the Customer brings them in. The Customer only brings in such data to the extent that this is necessary and permissible for its purpose.
5. Categories of data subjects
- Owners, employees and representatives of the Customer who use the platform;
- Persons named in Customer Content, such as the Customer’s customers, prospective customers, suppliers, business partners, employees and job applicants;
- Recipients of approved emails and appointments;
- WERKFORM.ai specialists, insofar as they work with the Customer in the project room.
6. Instructions
AKKON only processes Customer Content on the documented instructions of the Customer. This agreement, the Terms and the actions of authorised persons in the Cockpit are deemed to be instructions, in particular settings, tasks given to agents, approvals, the handover to WERKFORM.ai, exports and deletions. The Customer issues further instructions in text form to hallo@akkon.ai.
If AKKON is required by law to carry out other processing, AKKON will inform the Customer in advance, unless the law prohibits such notification. If AKKON considers that an instruction infringes data protection law, AKKON will inform the Customer without delay and may suspend its execution until the matter has been clarified.
7. Obligations of the Customer
The Customer is responsible for the lawfulness of the processing of Customer Content, in particular for ensuring that it is permitted to bring the data into the platform and have it processed by AKKON, and that the data subjects have been informed. It assigns roles and permissions in its company with care, keeps login credentials confidential and checks the agents’ results before using them.
8. Confidentiality and security
AKKON only grants access to Customer Content to persons who are bound by confidentiality, and only to the extent necessary for operations, troubleshooting or at the Customer’s request. AKKON takes the technical and organisational measures (TOMs) set out in section 16 (Art. 8 FADP, Art. 32 GDPR) and may develop them further, provided that the level of protection does not decrease.
9. Assistance with the rights of data subjects
AKKON assists the Customer with appropriate technical and organisational measures in responding to requests from data subjects for access, rectification, erasure, restriction, data release or transfer, and objection. The Cockpit functions for editing, exporting and deleting serve this purpose in the first instance. AKKON forwards to the Customer any requests from data subjects that it receives. Insofar as the platform is concerned, AKKON also assists the Customer with the information available in notifications to supervisory authorities, data protection impact assessments and prior consultations.
10. Notification of data security breaches
AKKON notifies the Customer of a data security breach affecting Customer Content without undue delay after becoming aware of it (Art. 24 FADP, Art. 33(2) GDPR). As far as known, the notification contains the nature of the breach, the categories concerned and the approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed and a contact person. Information that is not yet available will be provided subsequently.
11. Deletion and return
The Customer can export its data in the Cockpit at any time (JSON file with the company’s data and the list of files; files can be downloaded individually). It can delete entries, files and accounts; if the last person with the Owner role deletes their account, the company is deleted together with all its data and files.
After the end of the contract, Customer Content remains available for export for 30 days; AKKON then deletes it unless there is a statutory retention obligation. Copies in the hosting provider’s automatic database backups cease to exist when their retention period expires (up to 30 days, depending on the plan). For sub-processors, their deletion periods apply; according to Anthropic, it generally deletes inputs and outputs within 30 days. On request, AKKON will confirm the deletion in text form.
12. Evidence and audits
On request, AKKON provides the Customer with the information required to demonstrate compliance with this agreement, in particular a description of the measures under section 16 and the list of sub-processors. The Customer, or an auditor appointed by it and bound by confidentiality, may carry out audits after giving timely notice, during normal business hours and without disproportionate disruption to operations. Audits of sub-processors are governed by their contractual terms and the evidence they provide. The Customer bears the costs of an audit unless it reveals a material breach by AKKON.
13. Sub-processors
By accepting this agreement, the Customer approves the engagement of the following sub-processors, including those that are only used once the relevant function has been activated:
- Cloudflare, Inc. – Role: hosting and operation of the platform (Workers, D1 database, Durable Objects, Queues, Vectorize knowledge base, R2 file storage) and AI processing via Workers AI – Registered office: USA – Place of processing: Cloudflare data centres, including outside the EU and Switzerland; files in R2 with EU jurisdiction, stored in the EU.
- Anthropic (Anthropic Ireland, Limited, Ireland, or Anthropic, PBC, USA, depending on the provider’s contractual terms) – Role: AI processing via the Claude API, including optional live research on the web – only if activated by the operator – Place of processing: USA.
- Resend, Inc. – Role: sending platform emails (invitations, password resets, notifications, approved email actions) – only if activated – Registered office: USA.
- Stripe Payments Europe, Limited – Role: payment processing; processes only payment data, no Customer Content, and partly under its own responsibility – only if online payment is activated – Registered office: Ireland.
The sub-processors’ own terms on data processing (Data Processing Addendum) apply to them. AKKON remains responsible to the Customer for the sub-processors’ compliance with data protection obligations.
AKKON informs the Customer in good time before adding or replacing a sub-processor, as a rule at least 30 days in advance, by email or in the Cockpit. The Customer may object within this period on legitimate data protection grounds. If no solution is reached, it may terminate the agreement with effect from the date of the change.
14. Handover to WERKFORM.ai
WERKFORM.ai is not a sub-processor of AKKON but a separate contracting party of the Customer. Data is only handed over if an authorised person of the Customer confirms the handover step in the Cockpit and gives consent; this confirmation is deemed to be an instruction from the Customer. Only the selected scope (profile, goals, briefing, results, files) is handed over; the time and the person are stored. The contract between the Customer and WERKFORM.ai applies to processing by WERKFORM.ai. AKKON continues to operate the project room on the platform under this agreement.
15. Transfer abroad
If Customer Content is transferred to a country without an adequate level of data protection, in particular to the USA, the transfer is based, depending on the provider, on certification under the Swiss-U.S. or EU-U.S. Data Privacy Framework and/or on the European Commission’s standard contractual clauses (SCCs) with the adjustments required for Switzerland. Transfers between Switzerland and the EU or EEA are based on the mutual recognition of an adequate level of data protection.
16. Technical and organisational measures (TOMs)
- Transmission: the connection between browser and platform is encrypted with TLS (HTTPS); browsers are instructed via HSTS to use only encrypted connections.
- Passwords: stored only as a salted hash (PBKDF2-SHA-256, 100 000 iterations); minimum length 10 characters.
- Sessions: random session identifier, stored in the database only as a hash; cookie with the attributes HttpOnly, Secure and SameSite=Lax, valid for 30 days; logging out ends the session, other sessions can be ended in the Cockpit.
- Access: by invitation only; invitation and password links are time-limited; the “Forgot password” function does not reveal whether an email address is registered.
- Roles and approvals: permissions by role (Owner, Admin, Member, Read-only); actions with financial, legal, personal-data or external risk only after approval by an Owner or Admin; budget limits for AI costs.
- Separation: data is kept separately for each company; access is restricted on the server side to the company of the logged-in person.
- File storage: Cloudflare R2 with EU jurisdiction; permitted file types and size restricted (maximum 20 MB per file).
- Log: decisions and actions are logged for each company with the person and time.
- Abuse protection: limiting of requests per IP address (rate limiting), for example at login; checking the origin of requests.
- Keys: access keys to third-party services are stored as protected secrets with the hosting provider, not in the program code.
- Availability: automatic database backups by the hosting provider with restoration to earlier points in time (up to 30 days, depending on the plan).
- Rights of data subjects: export and deletion functions in the Cockpit.
- Organisation: obligation of confidentiality; access to Customer Content only when needed; physical security of the data centres in accordance with the hosting provider’s terms.
17. Liability
The provisions of the Terms (section 10) apply to liability. Mandatory statutory liability provisions, in particular towards data subjects, remain unaffected.
18. Final provisions
Swiss law applies. The place of jurisdiction is Arbon, Switzerland. Mandatory provisions of the GDPR and, for consumers, the mandatory provisions of the law of their country of residence remain unaffected.
The agreement is accepted in the Cockpit by a person with the Owner or Admin role of the Customer. In doing so, AKKON stores the version of this agreement, the time of acceptance and the accepting person; acceptance in electronic form is sufficient. An amended version will be communicated to the Customer and presented in the Cockpit as a new version for acceptance; section 13 applies to changes to sub-processors.
If any provision is invalid, the remainder of the agreement remains valid. It shall be replaced by a provision that comes closest to its purpose and meets the legal requirements.
Contact for questions about this agreement: hallo@akkon.ai