As at 18 August 2026
Data Processing Agreement (DPA)
Between the commissioning club (as controller) and espressino GmbH, Talbächliweg 19, 8048 Zurich, UID CHE-140.311.613 (as processor), for the Software-as-a-Service application strokebook.
This is a convenience translation. The legally authoritative version of this agreement is the German one.
This DPA is concluded automatically and without any further declaration upon acceptance of espressino's General Terms and Conditions for strokebook (hereinafter «GTC»).
1. Subject matter and duration
1.1 The subject matter of this DPA is the processing of personal data by espressino on behalf of the club in connection with the provision of strokebook in accordance with the GTC. The scope, nature and purpose of the processing, the categories of personal data and the categories of data subjects are described in Annex 1.
1.2 The duration of this DPA is governed by the term of the main contract in accordance with the GTC. In case of doubt, termination of the main contract also constitutes termination of this DPA. This DPA cannot be terminated separately during the term of the main contract.
1.3 The substantive administration of the club data and responsibility for the lawfulness of the data processing lie with the club. espressino processes the club data exclusively on behalf of and on the instructions of the club.
2. Applicable data protection law
2.1 The governing law is the Swiss Federal Act on Data Protection (FADP) together with its ordinance. Where Regulation (EU) 2016/679 (GDPR) additionally applies to the club's data processing, this DPA also satisfies the requirements of Art. 28 GDPR; in that case, terms used in this DPA shall be construed within the meaning of the GDPR (the FADP term «Bearbeiten» corresponds to the GDPR term «Verarbeiten», and «Personendaten» corresponds to «personenbezogene Daten»).
3. Allocation of roles: club context and personal member accounts
3.1 This DPA applies to personal data processed in the club context, that is, to data that the club or its members enter in strokebook as part of the club's organisation or that are generated in the process (in particular logbook entries, boat reservations and member master data administered by the club). In this respect, the club is the controller and espressino is the processor. This DPA also applies to the processing of personal data in the club context in connection with features marked as «Beta» or «experimental» (Section 3.4 of the GTC); service providers used for such features are deemed to be sub-processors within the meaning of Section 7.
3.2 This DPA does not cover personal data that a member records or generates in their personal account in the personal context (for example personal account settings as well as future personal features such as individual training data). In this respect, espressino is an independent controller; the Terms of Use for Personal Accounts and espressino's Privacy Policy apply. Personal accounts are tied to membership of the club; if the membership or the club's main contract ends, the account is closed in accordance with the Terms of Use.
3.3 Where the same data record is used in both contexts (for example a session that appears both in the club logbook and in the member's personal account), the following applies: for the copy or view in the club context the club is the controller, and for the copy or view in the personal context espressino is. Deletion in one context does not affect the other context.
4. Instructions
4.1 espressino processes the personal data exclusively within the scope of the agreements entered into and in accordance with the documented instructions of the club (including as regards the disclosure of personal data abroad), unless there is a legal obligation to process. In such a case, espressino shall inform the club of the legal requirement before the processing, unless the law prohibits such notification.
4.2 The club issues its general instructions through the functions, entries and configurations provided in strokebook. espressino is not obliged to carry out individual instructions of a different kind; an exception is the instruction to delete all data processed on the club's behalf, which espressino shall always carry out where it is established that the instruction originates from a person authorised to represent the club. Deletion instructions must be given at least in text form.
4.3 If espressino considers an instruction to be contrary to data protection law, it shall inform the club without delay and may suspend execution until the instruction is confirmed or amended.
4.4 Instructions may be issued by the persons who can validly represent the club and by the persons defined in strokebook as administrators of the club. In the event of conflicting instructions, Section 6.7 of the GTC applies.
5. Confidentiality
5.1 espressino engages only persons for the processing who have undertaken to maintain confidentiality or are subject to a statutory duty of secrecy and who have previously been familiarised with the data protection provisions relevant to them.
6. Technical and organisational measures
6.1 espressino takes the technical and organisational measures described in Annex 2 in order to ensure a level of protection appropriate to the risk as regards the confidentiality, integrity, availability and resilience of the systems.
6.2 The measures are subject to technical progress. espressino may implement alternative adequate measures, provided that the security level of the measures specified is not reduced. espressino shall notify the club of material changes in text form.
6.3 espressino reviews the effectiveness of the measures regularly and maintains a record of the categories of processing activities carried out on behalf of the club.
7. Sub-processors
7.1 The club consents to the use of the sub-processors listed in Annex 3. Sub-processors are service providers whose services relate directly to the provision of the main service; ancillary services (for example telecommunications or the disposal of data carriers) are not deemed to be sub-processing relationships, whereby espressino also takes appropriate confidentiality and control measures in respect of them.
7.2 espressino concludes an agreement with each sub-processor that imposes on that sub-processor essentially the same data protection obligations as this DPA imposes on espressino. If a sub-processor fails to fulfil its data protection obligations, espressino is liable to the club for the performance of that sub-processor's obligations as for its own conduct.
7.3 New sub-processors. If espressino intends to engage a new sub-processor or to replace an existing one, it shall inform the club in text form at least 30 days in advance. The club may object to the change within this period in text form on legitimate data protection grounds. If the parties are unable to reach agreement in the event of an objection, the club may terminate the main contract extraordinarily with effect from the date on which the new sub-processor is scheduled to be used; until that date, espressino shall not use the new sub-processor for the club's data.
8. Place of processing and data exports
8.1 Processing takes place in Switzerland and in the European Economic Area (EEA) and, for individual services identified in Annex 3 (in particular the delivery of the web application via a worldwide CDN as well as support and operational access from third countries), in states outside Switzerland and the EEA; this is subject to Section 8.2. The hosting region of the production systems is identified in Annex 3.
8.2 Personal data are disclosed to states without an adequate level of data protection only on the basis of appropriate safeguards, in particular the standard contractual clauses issued by the EU Commission and recognised by the FDPIC, with the adaptations required for Switzerland, or on the basis of another transfer mechanism permitted by law. If espressino intends to rely on a different mechanism in future, it shall notify the club in advance.
9. Support for the club
9.1 If a data subject (for example a club member) contacts espressino directly regarding their rights in the club context, espressino shall forward the request to the club or refer the data subject to the club and inform the club accordingly. espressino does not itself decide on such requests.
9.2 espressino supports the club, as far as it is able, with appropriate technical and organisational measures in fulfilling the rights of data subjects (in particular access, rectification, erasure, release of data) and in complying with the obligations relating to data security, the notification of data security breaches, data protection impact assessments and any consultations of the supervisory authority.
9.3 For support services that go beyond the functions provided in strokebook and are not attributable to misconduct on the part of espressino, espressino may charge appropriate additional remuneration based on time and effort.
10. Notification of data security breaches
10.1 espressino shall notify the club without delay of any data security breach affecting personal data within the club's area of responsibility. The notification shall contain, in so far as known, the nature of the breach, the categories of data and of persons affected, the likely consequences and the measures taken and proposed.
10.2 The assessment and any notification to the competent supervisory authority and the notification of the data subjects are incumbent on the club as controller. espressino supports the club in this in accordance with Section 9.
11. Evidence and audit rights
11.1 espressino shall, on request, make available to the club the information necessary to demonstrate compliance with the obligations under this DPA.
11.2 The club may audit compliance with this DPA at most once a year, as well as where there is specific cause, or have it audited by a suitable third party that is bound to confidentiality and is not in a competitive relationship with espressino. Audits take place subject to prior notice of, as a rule, at least four weeks, during normal business hours, at the club's expense and without disrupting operations.
11.3 espressino may instead furnish evidence by means of current attestations, reports or certifications from independent bodies (for example ISO 27001 or SOC 2 of the infrastructure providers used), provided that these enable the club to make an appropriate assessment. espressino's trade secrets and other customers' data are excluded from the audit. espressino may charge appropriate additional remuneration based on time and effort for supporting audits.
12. Deletion and return
12.1 espressino creates copies or duplicates of the club data only in so far as this is necessary for the proper provision of the services (for example backups, tests in connection with releases, error analysis).
12.2 After the end of the contract, the export window of 60 days under Section 10.5 of the GTC applies. Once it has expired, espressino deletes all personal data processed on behalf of the club within a reasonable technical period; backups are overwritten in the regular rotation cycle of a maximum of seven days. espressino confirms the deletion to the club in text form on request. Excepted from this are data that espressino must continue to retain on the basis of statutory retention obligations, and data in personal member accounts (Section 3.2); for the latter espressino is an independent controller, and their deletion is governed by the Privacy Policy. If the main contract ends, the personal accounts of the club's members are also closed; the members are informed in advance in accordance with the Terms of Use for Personal Accounts, and the data are deleted within 30 days, subject to statutory retention obligations.
13. Liability
13.1 The liability rules of the GTC, in particular the limitation of liability under Section 13 of the GTC, apply to liability arising from or in connection with this DPA. This is subject to mandatory statutory liability provisions.
13.2 If a data subject contacts espressino directly and obtains damages from espressino, the club shall compensate espressino for the loss thereby incurred, in so far as espressino would not have been liable to the club for the breach in question under this DPA and the GTC, in particular where espressino has complied with the agreements and instructions of the club.
14. Final provisions
14.1 In so far as this DPA does not contain any special provisions, the GTC apply. Amendments to this DPA are made in accordance with the procedure set out in Section 17 of the GTC.
14.2 This DPA is governed by Swiss law, excluding its conflict-of-law rules and the United Nations Convention on Contracts for the International Sale of Goods. The exclusive place of jurisdiction is Zurich.
Annex 1: Subject matter of the processing
A1.1 Subject matter and purpose
Provision of strokebook as Software-as-a-Service for the administration of the club's rowing operations, in particular: keeping the digital logbook, boat reservation, administration of boat and equipment data, administration of the member data recorded by the club, dispatch of transactional e-mails in the club context and related support and maintenance services. If the club activates AI features, the subject matter also includes the provision of language and assistance features on club data, with the involvement of the sub-processor listed for that purpose in Annex 3.
A1.2 Categories of personal data
- Master data of the members, in so far as recorded by the club: surname, first name, e-mail address, member category, rowing authorisations and qualifications
- Logbook data: date, time, boat, crew, destination or route, distance, any remarks
- Reservation data: boat, period, reserving person
- Usage and log data in the club context: logins, change history, technical log data
- Where applicable, in connection with beta features, GPS and route data of sessions in so far as they are assigned to the club logbook
- Where AI features are activated by the club: free-text entries by users as well as the club data referenced in the process, in so far as the processing thereof is necessary in order to provide the feature
Sensitive personal data are not the subject of the intended processing. The club is obliged not to record any sensitive personal data (for example health data) in free-text fields.
A1.3 Categories of data subjects
- Members of the club
- Other persons authorised by the club (for example guests, coaches, officials)
A1.4 Duration
The processing takes place for the duration of the main contract plus the export window of 60 days under Section 10.5 of the GTC.
Annex 2: Technical and organisational measures (TOMs)
A2.1 Confidentiality and access control
- Hosting of the production systems with certified cloud providers (hosting region Switzerland, see Annex 3); no data storage on local systems of espressino; physical security provided by the providers' data centres (including ISO 27001, SOC 2)
- Encryption of data transmission by means of TLS; encryption of stored data (Encryption at Rest)
- Tenant separation: logical separation of the data of each club at database level by means of Row Level Security
- Role-based authorisation concept in strokebook (for example administrator, member, kiosk); assignment of access rights on a need-to-know basis
- Passwords are stored exclusively as hash values; espressino's administrative access to the infrastructure is protected by multi-factor authentication
A2.2 Integrity
- Logging of logins and write access; change history with time stamp and user
- Protection of e-mail dispatch by means of SPF, DKIM and DMARC via the dispatch service provider named in Annex 3
- Separate development, test and production environments; code review before deployment
A2.3 Availability and resilience
- Daily automated backups of the database; retention of the backup copies for seven days (rolling); restore procedure documented
- Redundant infrastructure of the cloud providers; monitoring of key components with alerting
A2.4 Organisation and review
- Confidentiality undertaking by all persons involved in the processing
- Incident response process for security incidents, including internal escalation and notification in accordance with Section 10 of this DPA
- Privacy-friendly default settings in strokebook (for example minimal mandatory fields, predefined roles)
- Regular review and adaptation of the measures to the state of the art
Annex 3: Sub-processors
The approved sub-processors are listed in the separate strokebook list of sub-processors, which forms an integral part of this DPA. The current version is available at strokebook.club. Section 7.3 of this DPA applies to the addition of new sub-processors.