Centimo← Back to home

Data Processing Agreement, appendix to the Centimo General Terms and Conditions

Centimo, version 1.0.0, effective as of 01.04.2027

Translation notice. This document is an English translation provided for convenience only. The French version is the sole legally binding version. In case of any discrepancy, the French text prevails.


Preamble

This Data Processing Agreement (hereinafter the "Agreement") supplements the General Terms and Conditions of the Centimo Service (hereinafter the "Terms") and forms an integral part thereof. It applies to personal data that the Customer processes by means of the Service and for which it is the controller (for example, data appearing in its invoices, accounting entries, or customer files), as opposed to the Customer's own account and organization data, which is governed by Centimo's Privacy Policy.

In the event of a conflict between this Agreement and the Terms on data protection matters, this Agreement prevails.


Article 1: Definitions

The terms "personal data", "processing", "controller", and "processor" have the meaning given to them by the Federal Act on Data Protection (FADP).


Article 2: Role of the Parties

2.1 The Customer acts as controller for the personal data it enters, imports, or generates by means of the Service and which relates to third parties (for example, its own customers, suppliers, or employees).

2.2 Centimo (company sa) acts as processor of this data, and processes it only on the Customer's documented instructions, as expressed through the configuration and normal use of the Service.


Article 3: Description of the Processing

Nature of the processing Hosting, storage, backup, and provision of data via the Service
Purpose Enabling the Customer to carry out its accounting and administrative management activity
Categories of data concerned Any personal data the Customer chooses to enter, import, or generate by means of the Service in connection with its accounting and administrative activity
Categories of data subjects Customers, suppliers, employees, or other third parties of the Customer, depending on how the Customer uses the Service
Duration of the processing Duration of the contract concluded between Centimo and the Customer, extended by the retention period set out in Article 9

Article 4: Centimo's Obligations as Processor

Centimo undertakes to:

4.1 process the data only on the Customer's documented instructions, as resulting from the configuration and normal use of the Service, unless otherwise required by law (in which case Centimo informs the Customer, unless legally prohibited from doing so);

4.2 as a standing documented instruction covering the entire term of the Agreement, access the data, through its authorized personnel and to the extent strictly necessary, for the purposes of incident resolution, bug fixing, and technical support, whether the issue is reported by the Customer or detected by Centimo itself, without requiring the Customer's prior authorization on a case-by-case basis for each intervention;

4.3 ensure that persons authorized to process the data are bound by a confidentiality obligation;

4.4 implement the technical and organizational security measures described in Article 7;

4.5 comply with the conditions set out in Article 5 with respect to the use of sub-processors;

4.6 assist the Customer, to a reasonable extent and taking into account the nature of the processing, in responding to requests for the exercise of data subjects' rights and in complying with its obligations regarding security and breach notification;

4.7 inform the Customer if, in Centimo's opinion, an instruction given by the Customer infringes the FADP or any other applicable provision.


Article 5: Sub-processors

5.1 The Customer authorizes Centimo to engage the following sub-processor, necessary for the provision of the Service for the data covered by this Agreement (Article 3):

Sub-processor Service Location
Infomaniak Infrastructure hosting Switzerland

Stripe (payment of the Centimo subscription), Microsoft/Microsoft Graph (sending of transactional e-mails related to the account), Twilio (routing of phone calls to Centimo support), Anthropic (processing of the transcript of such calls by the automated voice assistant) and Cloudflare (bot/spam protection via CAPTCHA on account registration and the public contact/data-protection forms) process only data relating to the contractual relationship between the Customer and Centimo itself (account, subscription billing, exchanges with support), and not the data the Customer processes by means of the Service concerning its own customers, which is the subject of this Agreement. These providers are accordingly addressed in Centimo's Privacy Policy, not in this Agreement.

The Customer shall accordingly refrain from communicating, in its exchanges with support and in particular during phone calls, personal data concerning its own customers beyond what is necessary to handle its request.

5.2 Centimo informs the Customer of any planned change regarding the addition or replacement of sub-processors, giving the Customer the opportunity to object for a legitimate data-protection-related reason.

5.3 Centimo imposes on each sub-processor data protection obligations equivalent to those set out in this Agreement, and remains fully liable to the Customer for the performance of its sub-processors' obligations.


Article 6: International Transfers

6.1 The data covered by this Agreement is hosted exclusively in Switzerland (Infomaniak) and is not currently subject to any international transfer.

6.2 Should Centimo come to engage a new sub-processor processing data from abroad for the purposes of this Agreement, it would first ensure that such transfer benefits from one of the following safeguards, in accordance with the FADP, and would inform the Customer under the conditions of Article 5.2:

  • the destination country appears on the list of States recognized by the Federal Council as ensuring an adequate level of protection; or
  • standard contractual clauses recognized as offering appropriate safeguards (in particular the European Commission's standard contractual clauses, adapted as necessary to the Swiss context) are entered into with the sub-processor concerned; or
  • another appropriate safeguard within the meaning of art. 16 FADP is put in place.

Article 7: Security

Centimo implements the technical and organizational measures described in the Appendix to this Agreement, appropriate to the risk presented by the processing.


Article 8: Data Breach Notification

In the event of a security breach resulting in the accidental or unlawful loss, destruction, alteration, disclosure of, or unauthorized access to, data processed on the Customer's behalf, Centimo informs the Customer as promptly as possible after becoming aware of it, and provides the reasonably available information to enable the Customer to comply with its own legal obligations, in particular notification to the Federal Data Protection and Information Commissioner (FDPIC) where applicable.


Article 9: Fate of the Data at the End of the Agreement

9.1 Upon termination of the contract concluded between the Customer and Centimo, and unless the Customer requests otherwise, the data remains accessible until the account is deleted. This retention is intended to allow the Customer to meet its own legal retention obligations (in particular art. 958f CO); in any event, the data is deleted at the latest 10 years after the end of the contractual relationship.

9.2 An account's data is deleted only at the express request of its holder, following the identity verification procedure described in article 11.2 of the Privacy Policy, intended to ensure that only the legitimately authorized person may request the permanent deletion of the data.

9.3 The Customer's legal retention obligations (in particular accounting and tax obligations) remain reserved and may justify retention beyond the deletion request, to the extent strictly necessary.


Article 10: Liability

Centimo's liability under this Agreement is governed by Article 13 of the Terms.


Article 11: Term

This Agreement applies for the entire duration of the main contract concluded between the Customer and Centimo (the Terms), and survives its termination with respect to obligations which, by their nature, must continue (in particular confidentiality and the fate of the data).


Appendix: Technical and Organizational Security Measures

In accordance with Article 7, Centimo implements in particular the following measures:

Infrastructure and hosting

  • Hosting of the infrastructure and data in Switzerland (Infomaniak).
  • Regular, automated backups of the database, enabling restoration in the event of an incident.
  • In the event of an incident affecting the Service's availability, Centimo publishes and updates the Service's status on a publicly accessible status page (status.centimo.ch), and carries out restoration from the regular backups mentioned above.

Data transport and storage

  • Encryption of communications between the Customer and the Service (HTTPS/TLS).
  • Passwords stored exclusively in hashed form, never in plain text.

Access control and authentication

  • Support for two-factor authentication (TOTP) and passkeys (passkeys, WebAuthn standard) for user accounts.
  • Limiting each account to a single active session at a time, with detection of and alert in the event of abnormal reuse of an already invalidated session.
  • Controlled management of infrastructure secrets (application secrets encrypted, never stored in plain text).
  • Internal access by Centimo staff limited according to the principle of least privilege, to only those persons who need it in the course of their duties, with logging of administrator access.

Traceability

  • Logging of actions performed within the Service (audit log), retained for 180 days, enabling incident detection and reconstruction of events where needed.

Limitations As with any Internet-accessible service, the Service cannot be subject to an absolute security guarantee; the measures above are reviewed and updated as risks and the state of the art evolve.