DPA

Data processing agreement.

Template v0.1 · July 2026 · pending legal review

Published so your review can start today.

This is our standard template. Where your policy requires your own DPA, we work from yours. Either way, nothing waits on us.

It is a template pending legal review. The version both parties sign is the one that governs.

1. Parties and roles

You are the controller. Compl.AI is your processor and acts only on your documented instructions.

Compl.AI SA, in incorporation, Geneva, Switzerland. contact@complai.ch.

This agreement sits under the customer agreement. It covers personal data we process for you in the platform, not the complai.ch website, which is covered by our privacy notice.

2. Subject matter and duration

  • Subject matter: providing the Compl.AI platform, on the modules you license.
  • Duration: the term of the customer agreement, plus the deletion window in section 12.
  • Instructions: the customer agreement, this DPA, and what your users do in the platform. Anything else, in writing.

3. Nature and purpose

One purpose: performing the compliance work you licensed. Nothing else, and no secondary use of any kind.

  • Screening: sanctions, PEP, watchlists, adverse media.
  • Onboarding and KYC review.
  • Corporate mapping: structures, ownership, related parties.
  • AML and transaction monitoring (beta).
  • KYC remediation, in batch.

Agent reasoning has no discretionary decision authority. A small, quick case may complete automatically only under the customer's approved deterministic rules. Exceptions and judgment calls route to a named officer, and every path is logged.

4. Categories of personal data

Only what you submit, and what the platform retrieves to answer the query you raised. Typically:

  • Identification data: name, date and place of birth, nationality, document identifiers.
  • Relationship data: case and account references, risk classification, officer notes.
  • Corporate data: directors, signatories, beneficial owners, shareholdings.
  • Screening results and the evidence behind them: source articles, evidence snapshots, field-level provenance.
  • Platform accounts and audit records for your own staff.

Adverse media surfaces criminal proceedings, allegations and political exposure. We treat that as sensitive, under the same residency and access rules as everything else.

5. Categories of data subjects

  • Your clients and prospective clients, where they are natural persons.
  • Beneficial owners, directors, signatories and related parties of your corporate clients.
  • Persons named in a source that screening surfaced.
  • Your own staff who use the platform.

6. Our obligations as processor

  • Process only on your documented instructions, including on any transfer.
  • Tell you if an instruction appears to us to breach data protection law.
  • Maintain the measures in section 8 for the whole term.
  • Assist you with data protection impact assessments and with prior consultation of your supervisor.
  • Give you the information you need to demonstrate your own compliance.
  • Engage sub-processors only under section 9.
  • Delete or return under section 12.

7. Confidentiality

Everyone with access is bound by confidentiality that survives this agreement. Access is need-to-know, role-based and logged.

Our staff access client data from Switzerland only. Both founders are Geneva-based. No offshore support, no follow-the-sun team.

Where your banking secrecy obligations attach to client identifying data, we treat it the same way, under the same Switzerland-only rule.

8. Security measures

Stated in full on our security page. The measures we commit to here:

  • Encryption in transit (TLS) and at rest (256-bit).
  • Role-based access (admin / privileged / officer), row-level security, maker-checker on screening actions.
  • API access via scoped keys or short-lived signed tokens, with rotation.
  • Outbound-request allow-listing, prompt-injection sanitisation on every field reaching a model, rate limiting, security headers, non-root containers.
  • An append-only, hash-linked audit trail. Database triggers block deletion and rewrite.
  • Backups daily, encrypted, retained 30 days, held in Switzerland.
  • Recovery objectives: service restored within 8 hours, at most 24 hours of data at risk.

A failed source is surfaced to your officer as incomplete coverage, never as a clean result.

SOC 2 and ISO 27001 are planned.

9. Sub-processors

You give general authorisation to the sub-processors published at /security/subprocessors. The definitive list depends on the licensed modules and deployment.

Each one is bound by obligations equivalent to these. We stay responsible for what they do.

We give 30 days written notice before adding or replacing a sub-processor that processes client data.

You may object inside that window. If an objection cannot be resolved, you may terminate the affected service.

The current list is published at security/subprocessors, not held behind a request.

10. Data subject requests

Requests reach you, not us. The data subjects are your clients.

If one reaches us, we forward it to you without undue delay and do not answer it ourselves.

We assist by technical means: export, correction, restriction, deletion, and the record of what was checked, when, and against which source.

Where your anti-money-laundering record-keeping duties conflict with an erasure request, you decide. We act on your instruction.

11. Personal data breach

We notify you within 24 hours of becoming aware, to the contact you name, with what is known at that point. Updates follow as the picture completes.

We do not wait for certainty. Your own notification clock starts before ours finishes, so an early partial notice beats a late complete one.

We assist with your notifications to your supervisor and, where required, to data subjects.

12. Deletion and return

On termination you choose: return or deletion.

Export first. The audit trail comes out in an open format, so your evidence survives the relationship.

Then deletion within 30 days.

Backup copies roll off afterwards, on the backup retention cycle in section 8.

Retention is configurable if your own rules require a different period.

We keep nothing for our own purposes.

13. Audit and information rights

Ask in writing first. We answer vendor-risk questionnaires and hand over the documentation. That settles most of it.

Beyond that, you, your internal audit, your external auditor and your supervisor may inspect and audit us and our sub-processors, on reasonable notice and under confidentiality.

Your outsourcing register needs our sub-contractors and their countries. They are published, so you can complete that entry today rather than after a two-week email loop.

14. Residency and international transfers

Client data at rest is in Switzerland. Always.

Inference runs in Switzerland by default.

  • On the Infomaniak deployment, inference is Switzerland only.
  • On the AWS deployment, inference is Switzerland with the EU as the declared boundary.

The choice is yours, and the boundary is stated in writing for your deployment.

Staff access is Switzerland only, so support and maintenance are not a transfer.

Where the declared boundary includes the EU, the applicable transfer mechanism is documented in the signed deployment agreement after legal review.

15. Governing law and precedence

Swiss law. Place of jurisdiction Geneva, to the extent permitted by law.

If this DPA and the customer agreement conflict on data protection, this DPA governs.

16. Signing

Send this back signed, or send us yours. Either route works: contact@complai.ch.

Compl.AI SA is in incorporation. The signed version names the incorporated entity.

Security & residency · Sub-processors · Privacy