Breadcrumb:
Home > DPADPA
Data Processing Agreement (DPA)
Arhon Concept AG — Arhon® Software
1. Subject matter and parties
This Data Processing Agreement (hereinafter the “DPA”) is a standard document applicable to all customers of Arhon Concept AG that have subscribed to the Arhon® software. It is entered into between:
| Controller | Any establishment that has subscribed to the Arhon® software, hereinafter “the Customer” — the entity that determines the purposes and means of the processing of the personal data of its customers and staff. |
| Processor | Arhon Concept AG, a public limited company (Aktiengesellschaft) under Swiss law, Erlenweg 4, 6010 Kriens, Switzerland, UID: CHE-493.917.313, CH-ID: CH-270-3015551-3, FCRO-ID: 1316610, VAT No.: CHE-493.917.313 VAT, hereinafter “Arhon” — which processes personal data on behalf of the Customer in connection with the provision of the Arhon® software. |
This DPA is annexed to the main agreement relating to the Arhon® software and forms an integral part thereof, together with the General Terms and Conditions of Sale and Use (“GTC”) and the SLA. In the event of any conflict, this DPA prevails on all matters relating to the processing of personal data.
2. Definitions
| Term | Definition |
|---|---|
| Personal data | Any information relating to an identified or identifiable natural person (Art. 4(1) GDPR; Art. 5(a) revFADP). Since the 2023 revision, the revFADP no longer protects the data of legal entities. |
| Processing | Any operation performed on personal data, irrespective of the means and procedures used: collection, recording, storage, consultation, use, disclosure, erasure (Art. 4(2) GDPR; Art. 5(d) revFADP). |
| Controller | The entity that determines the purposes and means of the processing — here the Customer (Art. 4(7) GDPR; Art. 5(j) revFADP). |
| Processor | The entity that processes data on behalf of the controller — here Arhon Concept AG (Art. 4(8) and 28 GDPR; Art. 5(k) and 9 revFADP). |
| Sub-processor | Any third party engaged by Arhon to carry out specific processing activities (e.g. 2le for hosting). |
| Data breach | Any breach of security leading to the destruction, loss, alteration or unauthorised disclosure of personal data (Art. 4(12) GDPR; Art. 5(h) revFADP, which refers to a breach of data security). |
| Data subject | Any natural person whose data is processed: persons accommodated or received by the Customer, staff members, etc. |
| GDPR | Regulation (EU) 2016/679 of the European Parliament on the protection of personal data. |
| revFADP | The revised Swiss Federal Act on Data Protection, in force since 1 September 2023, and its implementing ordinance (Data Protection Ordinance, DPO). |
| Sensitive personal data | A concept of the revFADP (Art. 5(c)), close to the special categories of Art. 9 GDPR but broader: it covers in particular data on social assistance measures and on criminal or administrative proceedings or sanctions. The Arhon® software is not intended to process such data. |
3. Nature, purposes and duration of the processing
3.1 Nature of the processing
In connection with the provision of the Arhon® software, Arhon Concept AG carries out the following operations on behalf of the Customer:
- Hosting and storage of the data on the infrastructure operated by 2le
- Access to the data for technical support and maintenance purposes
- Backup and restoration of the data
- Provision of the application features (PMS, invoicing, reporting, etc.)
- Transfer of data between the software modules and authorised partner services
3.2 Purposes of the processing
| Purpose | Description |
|---|---|
| Reservation management | Creation, modification and cancellation of reservations made by the establishment’s customers |
| Stay management | Check-in, check-out, room allocation, tracking of services |
| Invoicing | Issuing invoices, recording payments, tax archiving |
| Customer communication | Sending confirmations, reminders and notifications by email |
| Reporting | Occupancy, revenue and activity statistics for the establishment |
| Legal compliance | Retention of data required by law (tax, aliens’ police registration, eHESTA) |
| Technical support | Diagnosis and resolution of incidents reported by the Customer |
3.3 Categories of data processed
| Category | Examples | Data subjects |
|---|---|---|
| Identity data | Surname, first name, date of birth, nationality, passport | Persons accommodated or received |
| Contact data | Email, telephone, postal address | Persons accommodated or received |
| Stay data | Arrival/departure dates, room type, services | Persons accommodated or received |
| Financial data | Invoice amounts, payment method | Persons accommodated or received |
| Access data | Software login credentials | Staff of the establishment |
| Usage data | Usage logs, timestamps of actions | Staff of the establishment |
Payment card data is neither entered nor stored in the Arhon® software. It is collected and stored by PCI Proxy, a tokenisation solution operated by Datatrans AG (Kreuzbühlstrasse 26, 8008 Zurich, Switzerland — Planet group), in conjunction with the payment service provider with which the Customer contracts directly (Worldline/Saferpay, Nexi/Datatrans or Computop). The Arhon® software handles only aliases (tokens) and transaction references.
3.4 Duration of the processing
Arhon Concept AG processes the data for the term of the main agreement.
Downloading and backing up its data is the Customer’s responsibility. Throughout the term of the agreement, and thereafter during the read-only access maintained for 30 days after its end, the Customer downloads the data itself from the software, in CSV, Excel and PDF formats, free of charge.
Upon expiry or termination of the agreement, the Customer may also request in writing, within three months, a full export of its data performed by Arhon, which is delivered within 30 days of the request in CSV or XML format. Any extraction performed by Arhon at the Customer’s request is a chargeable service, invoiced at the rate then in force, including where it is required by applicable regulations or in connection with an audit or request from the tax authorities, another authority or legal proceedings.
At the end of this three-month period, Arhon securely deletes the data, subject to the retention periods imposed by applicable law. Backup copies are purged at the end of their rotation cycle, no later than 90 days after that date.
The applicable retention periods are those set out in Article 15 of the General Terms and Conditions of Sale and Use and, for guest registration and check-in data, including identity documents where recorded, those provided for by the regulations applicable to the Customer’s establishment: federal, cantonal or municipal in Switzerland, national or local in France and Italy, as specified in the country annex to the general terms and conditions. This DPA does not set any retention period of its own.
Compliance with these periods, their configuration in the software and the corresponding purge are the responsibility of the Customer in its capacity as controller.
4. Obligations of Arhon Concept AG
4.1 Documented instructions
Arhon Concept AG processes personal data only on the documented instructions of the Customer, as expressed in the main agreement, the configuration of the Software and this DPA. Where Arhon is required to carry out processing under a legal obligation, it informs the Customer beforehand, unless the law prohibits this.
If, in the opinion of Arhon Concept AG, an instruction from the Customer infringes applicable data protection law, Arhon informs the Customer immediately and may suspend the execution of that instruction until it is confirmed or amended in writing.
4.2 Confidentiality
Arhon Concept AG ensures that persons authorised to process the data have committed themselves to confidentiality. Access is strictly limited to staff who need it to perform their duties.
4.3 Data security
In accordance with Article 32 GDPR and Article 8 revFADP, Arhon Concept AG implements the following technical and organisational measures, which reflect the state of the art as at the date of this version:
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS 1.3 for all network communications |
| Encryption at rest | AES-256 for stored data |
| Access control | Authentication by individual credentials and role-based permissions; named user accounts, unlimited in number and at no additional cost |
| Two-factor authentication | Technically enforced by Arhon Concept AG for all access to the Arhon® software, on every account; each user sets it up on their own device |
| High availability | HA cluster architecture across two datacentres, with automatic failover to the secondary infrastructure if the primary node fails |
| Backup | Daily off-site backup, 90-day retention, Kiwi Backup solution |
| Logging | Timestamped logs of all access and interventions, retained for 6 years |
| Annual restoration test | Full restoration of backups to an isolated environment, with data consistency checks and verification that the application functions correctly, in accordance with Art. 32(1)(d) GDPR. The test is documented in a written report kept by Arhon Concept AG and provided to the Customer on request |
| Annual review | Compliance audit of the infrastructure by 2le, report sent to Arhon |
4.4 Sub-processing
The Customer authorises Arhon Concept AG to engage the following sub-processor:
| Sub-processor | Role | Data location |
|---|---|---|
| 2le | Infrastructure hosting, backups, monitoring, technical maintenance and development | France (OVH datacentres) |
Partners with which the Customer contracts directly, in particular online booking platforms and payment service providers, act on their own behalf or on behalf of the Customer. They are not sub-processors of Arhon Concept AG.
Arhon Concept AG undertakes to impose equivalent data protection obligations on any sub-processor and remains fully liable to the Customer, within the limits set out in Article 13 of the GTC.
In the event that a sub-processor is added or replaced, Arhon informs the Customer at least 30 days in advance. The Customer may object in writing within that period, on reasonable and documented data protection grounds. The parties then seek a solution within a reasonable time; failing agreement, the Customer may terminate the main agreement with effect from the scheduled date of the change, without compensation on either side and without reimbursement of fees already due. If no objection is raised within that period, the change is deemed accepted.
4.5 Assistance to the Customer
Arhon Concept AG assists the Customer in:
- Responding to requests from data subjects exercising their rights
- Notifying data breaches to the supervisory authority within the required time limits
- Carrying out data protection impact assessments (DPIAs) where necessary
- Providing the information needed to demonstrate compliance with GDPR obligations
Requests for assistance must be sent to support@arhon.ch. Arhon responds to and takes charge of them within 2 to 3 business days of the date of the request; full execution of a request takes place within the time limits set out in Article 7 for requests from data subjects and, for other requests, within a reasonable time communicated to the Customer when the request is taken in charge.
4.6 Notification of data breaches
In the event of a personal data breach, Arhon Concept AG informs the Customer without undue delay after becoming aware of it, and in any event within a time frame that allows the Customer to meet its own notification obligations, at the latest within 48 hours. The notification specifies the nature of the breach, the categories and approximate number of data records and persons concerned, the likely consequences and the measures taken or proposed. Where this information cannot be provided at once, it is provided in phases without further undue delay.
5. Obligations of the Customer
As controller, the Customer undertakes to:
- Provide Arhon Concept AG with lawful and documented instructions
- Ensure that the collection of data processed via Arhon® is lawful
- Inform data subjects in accordance with Articles 13 and 14 GDPR
- Handle requests from data subjects exercising their rights
- Notify Arhon without delay of any change to its instructions regarding the processing
- Not use Arhon® to process special categories of data or sensitive personal data without the prior written consent of Arhon Concept AG
5.1 Duty to inform — Article 13(2)(c) GDPR
Pursuant to Article 13(2)(c) GDPR, the Customer, as controller, is required to inform its customers (the data subjects) of the existence of their rights over their personal data at the time the data is collected.
This information must explicitly mention the following rights:
- Right of access to personal data (Art. 15 GDPR)
- Right to rectification of inaccurate data (Art. 16 GDPR)
- Right to erasure (“right to be forgotten”) (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to data portability (Art. 20 GDPR)
This obligation rests solely with the Customer. It must be fulfilled through a privacy policy accessible to data subjects, typically:
- On the establishment’s website (“Privacy policy” or “Data protection” page)
- In the online booking forms
- At the establishment’s reception (notice or document handed over at check-in)
6. International data transfers
The data is hosted in France by 2le on OVH infrastructure. No transfer to a third country outside the European Union or Switzerland takes place without appropriate safeguards.
Switzerland benefits from an adequacy decision of the European Commission. Transfers between Switzerland and the European Union therefore take place without any additional mechanism.
7. Rights of data subjects
Arhon Concept AG responds to any request for assistance from the Customer within 2 to 3 business days of the date of the request (Article 4.5). The time limits below are the time limits for full execution of the request.
| Right | Description | Execution time by Arhon |
|---|---|---|
| Right of access (Art. 15) | Provide a copy of the data processed | 5 business days |
| Right to rectification (Art. 16) | Correct inaccurate data | 5 business days |
| Right to erasure (Art. 17) | Delete data upon a justified request | 10 business days |
| Right to data portability (Art. 20) | Export data in a structured format | 10 business days |
| Right to object (Art. 21) | Cease processing upon a justified request | 5 business days |
| Right to restriction (Art. 18) | Temporarily suspend processing | 5 business days |
8. Audit and demonstration of compliance
- Arhon Concept AG keeps a record of the processing activities carried out on behalf of the Customer
- The Customer may request a compliance audit by an independent auditor, subject to 30 days’ notice
- The annual audit reports on the 2le infrastructure are provided to the Customer on request
- Arhon undertakes to implement any corrective measure identified during an audit within a reasonable time
Verification is first carried out on the basis of documents, by questionnaire or by providing the certificates and reports available to Arhon. An on-site audit takes place only if these prove insufficient, during business hours, without disrupting operations and while respecting the confidentiality of other customers.
The costs of an audit requested by the Customer are borne by the Customer, unless the audit reveals a proven breach by Arhon Concept AG.
9. Term and end of the DPA
This DPA takes effect on the date of acceptance of the main agreement, the offer or the order form incorporating the GTC, and remains applicable throughout the contractual relationship and, solely for those obligations which must survive its end, until the data has been returned or deleted in accordance with this DPA and Article 15 of the GTC.
Upon termination of the DPA, Arhon Concept AG undertakes to enable the return of the data to the Customer under the conditions and within the time limits set out in Article 3.4 of this DPA and Article 15 of the General Terms and Conditions of Sale and Use, then to securely delete all personal data, and to provide a written certificate of deletion on request.
10. General provisions
- Governing law: this DPA is governed by Swiss law. The GDPR applies to processing falling within its material and territorial scope, in particular pursuant to its Articles 2 and 3, irrespective of the nationality of the data subjects
- Jurisdiction: the competent courts of Lucerne (Canton of Lucerne, Switzerland), in accordance with Article 20 of the GTC, subject to any mandatory places of jurisdiction
- This DPA prevails over any conflicting provision of the main agreement relating to data processing
- Order of precedence: the General Terms and Conditions of Sale and Use form the foundation; this DPA prevails over them for the processing of personal data; the service level agreement (SLA) prevails for availability and service levels; the annex specific to the Customer’s country of establishment prevails solely for the provisions it covers
- Should any provision be held invalid, the remaining provisions remain valid
- Any amendment to this DPA follows the procedure set out in the preamble to the GTC. It is notified to the Customer in writing, by email or within the Software at least 30 days before it takes effect. Adjustments strictly necessary to comply with a law, a regulation, a decision of an authority, or a documented security or certification requirement may take effect immediately. For any other significant amendment unfavourable to the Customer, the Customer may object under the conditions set out in the preamble to the GTC.
- Languages: available in French, German and English — the French version is authoritative
11. Contact — Data protection
For any questions relating to this DPA or to the processing of personal data:
Arhon Concept AG
Kriens, Canton of Lucerne, Switzerland
Email: support@arhon.ch
Telephone: +41 61 222 21 59
12. Acceptance and enforceability
This DPA is a public document applicable to all customers of Arhon Concept AG. It is binding upon signature or acceptance of the main licence agreement for the Arhon® software, without any separate signature being required.
The Customer acknowledges having read this Data Processing Agreement and accepts its provisions by subscribing to the Arhon® software. Any change to the DPA follows the amendment procedure set out in the preamble to the General Terms and Conditions of Sale and Use.
Published on 30 September 2026. Applicable to agreements concluded from that date and, for agreements in progress, from 30 October 2026.
It is published by Arhon Concept AG, Kriens (Lucerne), Switzerland, in its capacity as processor within the meaning of Article 28 GDPR.
Legal basis: GDPR (EU) 2016/679 and revFADP (Swiss Federal Act on Data Protection).
Provided together with the General Terms and Conditions of Sale and Use. In the event of any discrepancy between language versions, the French version prevails.
Text content to come...
