Preamble
This data processing agreement (hereinafter the “DPA”) governs the processing of personal data by Foldercrate (hereinafter the “Processor”) on behalf of the customer (hereinafter the “Controller”) in connection with the use of the Logiwolf web analytics platform.
The DPA applies to the processing of personal data of end users that the Controller records on their own websites by means of the Logiwolf pixel. Together with the general terms and conditions, it formsTerms the contractual basis of the processing relationship.
1. Contracting parties
Processor:
Foldercrate
E-Mail: privacy@logiwolf.com
Controller: The Logiwolf customer, identified by the master data stored in the Logiwolf account.
2. Subject matter and duration of the processing
2.1 The subject matter of the processing is the provision of the Logiwolf web analytics services in accordance with the GTC. In doing so, personal data of end users of the Controller's websites is processed.
2.2 The processing takes place for the duration of the underlying main contract (Logiwolf subscription). The DPA ends upon termination of the main contract. Sections 12 (return and deletion) and any statutory obligations survive its termination.
3. Nature and purpose of the processing
3.1 The Processor processes personal data exclusively for the purpose of providing the Logiwolf web analytics services. This comprises:
- Recording and storage of pageviews and session data
- Creation of anonymised statistics and reports
- Recording and storage of heatmap data and anonymised session recordings
- Provision of the data in the Logiwolf dashboard and via API
- Datenexport auf Anforderung des Verantwortlichen
3.2 The processing is fully automated and takes place without human access by the Processor's staff, except for maintenance and support purposes at the Controller's request.
4. Types of personal data and categories of data subjects
4.1 Categories of data subjects: Visitors to the Controller's websites.
4.2 Types of data processed:
- Requested URLs and timestamps
- HTTP referrer (visitor source)
- Anonymised device information (browser, operating system, screen resolution)
- Approximate geographic location (country, optionally region) based on the hashed IP address
- UTM parameters and campaign identifiers
- Custom events defined by the Controller and their properties
- Anonymised click, scroll and mouse movement data (heatmaps)
- Anonymised session recordings with automatic masking of sensitive fields
4.3 Data not processed: Cookies, real names, email addresses, phone numbers, persistent user IDs, device fingerprints, cross-site tracking data. The collection of special categories of personal data (Art. 9 GDPR) is not intended and is contractually excluded.
5. Obligations of the Processor
5.1 The Processor processes personal data exclusively within the scope of the agreements made and in accordance with the documented instructions of the Controller. The functional configuration in the Logiwolf dashboard counts as an instruction.
5.2 The Processor informs the Controller without delay if an instruction appears to violate applicable data protection law.
5.3 The Processor ensures that all persons authorised to process the data are bound to confidentiality or are subject to an appropriate statutory duty of confidentiality.
5.4 The Processor implements all technical and organisational measures required under Art. 32 GDPR (TOMs, see Annex 1).
5.5 The Processor supports the Controller in fulfilling data subjects' rights and in complying with the obligations under Art. 32 to 36 GDPR.
5.6 The Processor informs the Controller without delay – at the latest within 24 hours of becoming aware – of any personal data breaches.
5.7 The Processor maintains a record of all processing activities pursuant to Art. 30 para. 2 GDPR and makes it available to the Controller upon request.
6. Obligations of the Controller
6.1 The Controller ensures the lawfulness of the processing and is solely responsible for safeguarding the rights of data subjects.
6.2 The Controller ensures that a suitable privacy policy is available on their websites that transparently discloses the use of Logiwolf.
6.3 The Controller notifies the Processor without delay of data subject requests where the Processor's cooperation is required.
7. Place of processing and third-country transfers
7.1 The processing takes place exclusively in Switzerland. The data is stored in the following data centres:
- Primary location: Zurich, Switzerland
- Secondary location (redundancy): Geneva, Switzerland
7.2 No transfer of data to third countries (outside Switzerland and the EU/EEA) takes place.
7.3 Should the place of processing change in the future, the Processor will inform the Controller at least 30 days in advance. The Controller may object; section 8.3 applies accordingly.
8. Sub-processors
8.1 The Controller grants general authorisation for the engagement of the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Logiwolf-Infrastruktur (Foldercrate) | Hosting of the Logiwolf platform, data storage, processing | Switzerland (Zurich, Geneva) |
| Hostpoint AG | Hosting of the website logiwolf.com | Switzerland (Rapperswil-Jona) |
| Stripe Payments Europe Ltd. | Abrechnung kostenpflichtiger Abonnements | Irland (EU) |
8.2 The Processor informs the Controller of any intended change concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object to such changes.
8.3 In the event of justified objections by the Controller, the Processor may choose to refrain from engaging the new sub-processor or to allow the Controller to terminate the contract at the time the change takes effect.
8.4 The Processor contractually binds its sub-processors to data protection obligations at least equivalent to those in this DPA.
9. Support with data subject rights
9.1 The Processor supports the Controller with appropriate technical and organisational measures in fulfilling the rights of data subjects under Chapter III of the GDPR.
9.2 To this end, the Processor provides the following functions in the dashboard:
- Export of all data collected for a website as CSV or JSON
- Deletion of individual sessions or entire data ranges
- Complete data deletion at the end of the contract
9.3 If a data subject contacts the Processor directly, the Processor forwards the request to the Controller without delay.
10. Technical and organisational measures (TOMs)
The technical and organisational measures implemented by the Processor are described inAnhang 1 of this DPA. The Processor is entitled to adjust the TOMs provided the level of protection is not reduced.
11. Audit rights
11.1 The Controller has the right to verify the Processor's compliance with this DPA.
11.2 Verification is generally carried out by presentation of current certificates, audit reports or a written self-assessment by the Processor.
11.3 On-site audits are possible with at least 30 days' prior notice during normal business hours. The costs of such an audit are borne by the Controller unless material violations are found.
12. Return and deletion of the data
12.1 After termination of the main contract, the personal data is completely deleted within 30 days.
12.2 At the Controller's express request, the data is handed over before deletion in a common, machine-readable format (CSV or JSON).
12.3 Statutory retention obligations (e.g. invoicing data under Art. 958f of the Swiss Code of Obligations) remain unaffected. Such data is not subject to this DPA.
13. Liability
13.1 The parties' liability is governed by the provisions of the GTC and the applicable statutory provisions.
13.2 Vis-à-vis data subjects, the Processor is jointly liable in accordance with Art. 82 GDPR. Internally, the limitation of liability agreed in the GTC applies.
14. Final provisions
14.1 In the event of conflicts between this DPA and the GTC, the provisions of this DPA prevail.
14.2 Amendments or additions to this DPA require written or text form.
14.3 Should any provision of this DPA be invalid, the validity of the remaining provisions remains unaffected.
14.4 Applicable law and place of jurisdiction are governed by the GTC (Swiss law, place of jurisdiction Solothurn).
Annex 1: Technical and organisational measures (TOMs)
Confidentiality (Art. 32 para. 1 lit. b GDPR)
- Physical access control: Swiss data centres with physical access barriers, video surveillance and 24/7 security staff
- System access control: Multi-factor authentication for administrative access; password hashing with bcrypt/argon2
- Data access control: Role-based access rights on a need-to-know basis
- Trennungsgebot: Logical tenant separation per customer; separate databases for different processing purposes
- Pseudonymisation: IP addresses are hashed before storage; session recordings are anonymised with automatic masking of input fields, passwords and sensitive data
Integrity (Art. 32 para. 1 lit. b GDPR)
- Transfer control: TLS 1.3 encryption of all data transfers; at-rest data encryption with AES-256
- Input control: Complete logging of data changes with timestamp and user ID
Availability and resilience (Art. 32 para. 1 lit. b and c GDPR)
- Availability control: Redundant infrastructure at two Swiss locations (Zurich + Geneva); daily backups; recovery time objective (RTO) of 4 hours< 4 Stunden
- Rapid recoverability: Documented disaster recovery processes; regular test restores
Procedures for regular review (Art. 32 para. 1 lit. d GDPR)
- Data protection management: Documented records of processing; annual internal data protection audits
- Incident response management: Defined reporting chains and response times for security incidents (24-hour notification to the Controller)
- Datenschutzfreundliche Voreinstellungen (Art. 25 DSGVO): Cookieless-First-Architektur; Datensparsamkeit by Design
Sub-processor control
- Written contracts with all sub-processors, with data protection obligations at least at the level of this DPA
- Regular review of sub-processors (at least annually)