DPA

Data Processing Agreement (DPA)

Arhon Concept AG — Arhon® Software

1. Subject matter and parties

This Data Processing Agreement (hereinafter the “DPA”) is a standard document applicable to all customers of Arhon Concept AG that have subscribed to the Arhon® software. It is entered into between:

Controller Any establishment that has subscribed to the Arhon® software, hereinafter “the Customer” — the entity that determines the purposes and means of the processing of the personal data of its customers and staff.
Processor Arhon Concept AG, a public limited company (Aktiengesellschaft) under Swiss law, Erlenweg 4, 6010 Kriens, Switzerland, UID: CHE-493.917.313, CH-ID: CH-270-3015551-3, FCRO-ID: 1316610, VAT No.: CHE-493.917.313 VAT, hereinafter “Arhon” — which processes personal data on behalf of the Customer in connection with the provision of the Arhon® software.

This DPA is annexed to the main agreement relating to the Arhon® software and forms an integral part thereof, together with the General Terms and Conditions of Sale and Use (“GTC”) and the SLA. In the event of any conflict, this DPA prevails on all matters relating to the processing of personal data.

2. Definitions

Term Definition
Personal data Any information relating to an identified or identifiable natural person (Art. 4(1) GDPR; Art. 5(a) revFADP). Since the 2023 revision, the revFADP no longer protects the data of legal entities.
Processing Any operation performed on personal data, irrespective of the means and procedures used: collection, recording, storage, consultation, use, disclosure, erasure (Art. 4(2) GDPR; Art. 5(d) revFADP).
Controller The entity that determines the purposes and means of the processing — here the Customer (Art. 4(7) GDPR; Art. 5(j) revFADP).
Processor The entity that processes data on behalf of the controller — here Arhon Concept AG (Art. 4(8) and 28 GDPR; Art. 5(k) and 9 revFADP).
Sub-processor Any third party engaged by Arhon to carry out specific processing activities (e.g. 2le for hosting).
Data breach Any breach of security leading to the destruction, loss, alteration or unauthorised disclosure of personal data (Art. 4(12) GDPR; Art. 5(h) revFADP, which refers to a breach of data security).
Data subject Any natural person whose data is processed: persons accommodated or received by the Customer, staff members, etc.
GDPR Regulation (EU) 2016/679 of the European Parliament on the protection of personal data.
revFADP The revised Swiss Federal Act on Data Protection, in force since 1 September 2023, and its implementing ordinance (Data Protection Ordinance, DPO).
Sensitive personal data A concept of the revFADP (Art. 5(c)), close to the special categories of Art. 9 GDPR but broader: it covers in particular data on social assistance measures and on criminal or administrative proceedings or sanctions. The Arhon® software is not intended to process such data.

3. Nature, purposes and duration of the processing

3.1 Nature of the processing

In connection with the provision of the Arhon® software, Arhon Concept AG carries out the following operations on behalf of the Customer:

  • Hosting and storage of the data on the infrastructure operated by 2le
  • Access to the data for technical support and maintenance purposes
  • Backup and restoration of the data
  • Provision of the application features (PMS, invoicing, reporting, etc.)
  • Transfer of data between the software modules and authorised partner services

3.2 Purposes of the processing

Purpose Description
Reservation management Creation, modification and cancellation of reservations made by the establishment’s customers
Stay management Check-in, check-out, room allocation, tracking of services
Invoicing Issuing invoices, recording payments, tax archiving
Customer communication Sending confirmations, reminders and notifications by email
Reporting Occupancy, revenue and activity statistics for the establishment
Legal compliance Retention of data required by law (tax, aliens’ police registration, eHESTA)
Technical support Diagnosis and resolution of incidents reported by the Customer

3.3 Categories of data processed

Category Examples Data subjects
Identity data Surname, first name, date of birth, nationality, passport Persons accommodated or received
Contact data Email, telephone, postal address Persons accommodated or received
Stay data Arrival/departure dates, room type, services Persons accommodated or received
Financial data Invoice amounts, payment method Persons accommodated or received
Access data Software login credentials Staff of the establishment
Usage data Usage logs, timestamps of actions Staff of the establishment

Payment card data is neither entered nor stored in the Arhon® software. It is collected and stored by PCI Proxy, a tokenisation solution operated by Datatrans AG (Kreuzbühlstrasse 26, 8008 Zurich, Switzerland — Planet group), in conjunction with the payment service provider with which the Customer contracts directly (Worldline/Saferpay, Nexi/Datatrans or Computop). The Arhon® software handles only aliases (tokens) and transaction references.

Datatrans AG has been certified PCI DSS Level 1 since 2006, the highest level applicable to payment service providers, and undergoes an annual on-site audit conducted by an independent Qualified Security Assessor (QSA). Datatrans AG further states that it processes personal data in accordance with the GDPR. Fully outsourcing card data to PCI Proxy reduces the scope of the Customer’s PCI DSS obligations to a simplified self-assessment questionnaire, the exact type of which depends on the integration method chosen.
The Arhon® software is not designed to process special categories of personal data within the meaning of Article 9 GDPR or sensitive personal data within the meaning of Art. 5(c) revFADP (health data, political opinions, biometric data, etc.). The Customer shall refrain from recording such data, in particular in free-text fields such as remarks, unless Arhon Concept AG has given its prior written consent.

3.4 Duration of the processing

Arhon Concept AG processes the data for the term of the main agreement.

Downloading and backing up its data is the Customer’s responsibility. Throughout the term of the agreement, and thereafter during the read-only access maintained for 30 days after its end, the Customer downloads the data itself from the software, in CSV, Excel and PDF formats, free of charge.

Upon expiry or termination of the agreement, the Customer may also request in writing, within three months, a full export of its data performed by Arhon, which is delivered within 30 days of the request in CSV or XML format. Any extraction performed by Arhon at the Customer’s request is a chargeable service, invoiced at the rate then in force, including where it is required by applicable regulations or in connection with an audit or request from the tax authorities, another authority or legal proceedings.

At the end of this three-month period, Arhon securely deletes the data, subject to the retention periods imposed by applicable law. Backup copies are purged at the end of their rotation cycle, no later than 90 days after that date.

The applicable retention periods are those set out in Article 15 of the General Terms and Conditions of Sale and Use and, for guest registration and check-in data, including identity documents where recorded, those provided for by the regulations applicable to the Customer’s establishment: federal, cantonal or municipal in Switzerland, national or local in France and Italy, as specified in the country annex to the general terms and conditions. This DPA does not set any retention period of its own.

Compliance with these periods, their configuration in the software and the corresponding purge are the responsibility of the Customer in its capacity as controller.

4. Obligations of Arhon Concept AG

4.1 Documented instructions

Arhon Concept AG processes personal data only on the documented instructions of the Customer, as expressed in the main agreement, the configuration of the Software and this DPA. Where Arhon is required to carry out processing under a legal obligation, it informs the Customer beforehand, unless the law prohibits this.

If, in the opinion of Arhon Concept AG, an instruction from the Customer infringes applicable data protection law, Arhon informs the Customer immediately and may suspend the execution of that instruction until it is confirmed or amended in writing.

4.2 Confidentiality

Arhon Concept AG ensures that persons authorised to process the data have committed themselves to confidentiality. Access is strictly limited to staff who need it to perform their duties.

4.3 Data security

In accordance with Article 32 GDPR and Article 8 revFADP, Arhon Concept AG implements the following technical and organisational measures, which reflect the state of the art as at the date of this version:

Measure Implementation
Encryption in transit TLS 1.3 for all network communications
Encryption at rest AES-256 for stored data
Access control Authentication by individual credentials and role-based permissions; named user accounts, unlimited in number and at no additional cost
Two-factor authentication Technically enforced by Arhon Concept AG for all access to the Arhon® software, on every account; each user sets it up on their own device
High availability HA cluster architecture across two datacentres, with automatic failover to the secondary infrastructure if the primary node fails
Backup Daily off-site backup, 90-day retention, Kiwi Backup solution
Logging Timestamped logs of all access and interventions, retained for 6 years
Annual restoration test Full restoration of backups to an isolated environment, with data consistency checks and verification that the application functions correctly, in accordance with Art. 32(1)(d) GDPR. The test is documented in a written report kept by Arhon Concept AG and provided to the Customer on request
Annual review Compliance audit of the infrastructure by 2le, report sent to Arhon
These measures may evolve with the state of the art. Arhon Concept AG may replace a measure with one providing an equivalent or higher level of protection, informing the Customer when this version is updated. No change may lower the overall level of security.

4.4 Sub-processing

The Customer authorises Arhon Concept AG to engage the following sub-processor:

Sub-processor Role Data location
2le Infrastructure hosting, backups, monitoring, technical maintenance and development France (OVH datacentres)

Partners with which the Customer contracts directly, in particular online booking platforms and payment service providers, act on their own behalf or on behalf of the Customer. They are not sub-processors of Arhon Concept AG.

Arhon Concept AG undertakes to impose equivalent data protection obligations on any sub-processor and remains fully liable to the Customer, within the limits set out in Article 13 of the GTC.

In the event that a sub-processor is added or replaced, Arhon informs the Customer at least 30 days in advance. The Customer may object in writing within that period, on reasonable and documented data protection grounds. The parties then seek a solution within a reasonable time; failing agreement, the Customer may terminate the main agreement with effect from the scheduled date of the change, without compensation on either side and without reimbursement of fees already due. If no objection is raised within that period, the change is deemed accepted.

4.5 Assistance to the Customer

Arhon Concept AG assists the Customer in:

  • Responding to requests from data subjects exercising their rights
  • Notifying data breaches to the supervisory authority within the required time limits
  • Carrying out data protection impact assessments (DPIAs) where necessary
  • Providing the information needed to demonstrate compliance with GDPR obligations

Requests for assistance must be sent to support@arhon.ch. Arhon responds to and takes charge of them within 2 to 3 business days of the date of the request; full execution of a request takes place within the time limits set out in Article 7 for requests from data subjects and, for other requests, within a reasonable time communicated to the Customer when the request is taken in charge.

4.6 Notification of data breaches

In the event of a personal data breach, Arhon Concept AG informs the Customer without undue delay after becoming aware of it, and in any event within a time frame that allows the Customer to meet its own notification obligations, at the latest within 48 hours. The notification specifies the nature of the breach, the categories and approximate number of data records and persons concerned, the likely consequences and the measures taken or proposed. Where this information cannot be provided at once, it is provided in phases without further undue delay.

It is the responsibility of the Customer, as controller, to notify the breach to the competent supervisory authority (FDPIC in Switzerland, CNIL in France, Garante in Italy) and, where applicable, to the data subjects, within the time limits laid down by the applicable regulations — in particular 72 hours under Article 33 GDPR and as soon as possible under Article 24 revFADP. The notification period set out above is intended to preserve that time limit.

5. Obligations of the Customer

As controller, the Customer undertakes to:

  • Provide Arhon Concept AG with lawful and documented instructions
  • Ensure that the collection of data processed via Arhon® is lawful
  • Inform data subjects in accordance with Articles 13 and 14 GDPR
  • Handle requests from data subjects exercising their rights
  • Notify Arhon without delay of any change to its instructions regarding the processing
  • Not use Arhon® to process special categories of data or sensitive personal data without the prior written consent of Arhon Concept AG

5.1 Duty to inform — Article 13(2)(c) GDPR

Pursuant to Article 13(2)(c) GDPR, the Customer, as controller, is required to inform its customers (the data subjects) of the existence of their rights over their personal data at the time the data is collected.

This information must explicitly mention the following rights:

  • Right of access to personal data (Art. 15 GDPR)
  • Right to rectification of inaccurate data (Art. 16 GDPR)
  • Right to erasure (“right to be forgotten”) (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to object to processing (Art. 21 GDPR)
  • Right to data portability (Art. 20 GDPR)

This obligation rests solely with the Customer. It must be fulfilled through a privacy policy accessible to data subjects, typically:

  • On the establishment’s website (“Privacy policy” or “Data protection” page)
  • In the online booking forms
  • At the establishment’s reception (notice or document handed over at check-in)
On request, Arhon Concept AG provides the Customer with a template privacy policy compliant with the GDPR and the revFADP, adapted to its business and mentioning Arhon’s role as processor. This assistance is covered by Article 4.5 of this DPA.

6. International data transfers

The data is hosted in France by 2le on OVH infrastructure. No transfer to a third country outside the European Union or Switzerland takes place without appropriate safeguards.

Switzerland benefits from an adequacy decision of the European Commission. Transfers between Switzerland and the European Union therefore take place without any additional mechanism.

7. Rights of data subjects

Arhon Concept AG responds to any request for assistance from the Customer within 2 to 3 business days of the date of the request (Article 4.5). The time limits below are the time limits for full execution of the request.

Right Description Execution time by Arhon
Right of access (Art. 15) Provide a copy of the data processed 5 business days
Right to rectification (Art. 16) Correct inaccurate data 5 business days
Right to erasure (Art. 17) Delete data upon a justified request 10 business days
Right to data portability (Art. 20) Export data in a structured format 10 business days
Right to object (Art. 21) Cease processing upon a justified request 5 business days
Right to restriction (Art. 18) Temporarily suspend processing 5 business days

8. Audit and demonstration of compliance

  • Arhon Concept AG keeps a record of the processing activities carried out on behalf of the Customer
  • The Customer may request a compliance audit by an independent auditor, subject to 30 days’ notice
  • The annual audit reports on the 2le infrastructure are provided to the Customer on request
  • Arhon undertakes to implement any corrective measure identified during an audit within a reasonable time

Verification is first carried out on the basis of documents, by questionnaire or by providing the certificates and reports available to Arhon. An on-site audit takes place only if these prove insufficient, during business hours, without disrupting operations and while respecting the confidentiality of other customers.

The costs of an audit requested by the Customer are borne by the Customer, unless the audit reveals a proven breach by Arhon Concept AG.

9. Term and end of the DPA

This DPA takes effect on the date of acceptance of the main agreement, the offer or the order form incorporating the GTC, and remains applicable throughout the contractual relationship and, solely for those obligations which must survive its end, until the data has been returned or deleted in accordance with this DPA and Article 15 of the GTC.

Upon termination of the DPA, Arhon Concept AG undertakes to enable the return of the data to the Customer under the conditions and within the time limits set out in Article 3.4 of this DPA and Article 15 of the General Terms and Conditions of Sale and Use, then to securely delete all personal data, and to provide a written certificate of deletion on request.

10. General provisions

  • Governing law: this DPA is governed by Swiss law. The GDPR applies to processing falling within its material and territorial scope, in particular pursuant to its Articles 2 and 3, irrespective of the nationality of the data subjects
  • Jurisdiction: the competent courts of Lucerne (Canton of Lucerne, Switzerland), in accordance with Article 20 of the GTC, subject to any mandatory places of jurisdiction
  • This DPA prevails over any conflicting provision of the main agreement relating to data processing
  • Order of precedence: the General Terms and Conditions of Sale and Use form the foundation; this DPA prevails over them for the processing of personal data; the service level agreement (SLA) prevails for availability and service levels; the annex specific to the Customer’s country of establishment prevails solely for the provisions it covers
  • Should any provision be held invalid, the remaining provisions remain valid
  • Any amendment to this DPA follows the procedure set out in the preamble to the GTC. It is notified to the Customer in writing, by email or within the Software at least 30 days before it takes effect. Adjustments strictly necessary to comply with a law, a regulation, a decision of an authority, or a documented security or certification requirement may take effect immediately. For any other significant amendment unfavourable to the Customer, the Customer may object under the conditions set out in the preamble to the GTC.
  • Languages: available in French, German and English — the French version is authoritative

11. Contact — Data protection

For any questions relating to this DPA or to the processing of personal data:

Arhon Concept AG
Kriens, Canton of Lucerne, Switzerland
Email: support@arhon.ch
Telephone: +41 61 222 21 59

12. Acceptance and enforceability

This DPA is a public document applicable to all customers of Arhon Concept AG. It is binding upon signature or acceptance of the main licence agreement for the Arhon® software, without any separate signature being required.

The Customer acknowledges having read this Data Processing Agreement and accepts its provisions by subscribing to the Arhon® software. Any change to the DPA follows the amendment procedure set out in the preamble to the General Terms and Conditions of Sale and Use.

Text content to come...