Skip to content
Auftragsverarbeitungsvertrag

Data processing agreement (AVV).

This agreement governs MediVault's processing of personal data — including health data — on behalf of a Customer acting as controller, in accordance with Art. 9 of the Swiss Federal Act on Data Protection. It forms part of, and is incorporated into, the Terms of Service.

Breach to customer
24 h
Breach to EDÖB
72 h
Sub-processor notice
30 days
Legal basis
FADP Art. 9
Last updated: 25 August 2026Document version 2.4
Demonstration content

MediVault AG is a fictional company built for a portfolio / demo website. This page is illustrative template content only — it is not real legal advice, it has not been reviewed by counsel, and it creates no actual rights or obligations. Do not rely on it for an actual product, business or legal decision.

A surgical team working beneath an operating theatre light.
Where the data in this AVV comes from
Illustrative only — this is the clinical work behind the records this agreement governs. MediVault processes them strictly on the Controller's documented instructions, set out below.

What this AVV
actually governs.

1.1

Subject matter and duration

MediVault (the “Processor”) processes personal data on behalf of the Customer (the “Controller”) solely to provide the Service described in the Terms of Service. This agreement takes effect on the effective date of the underlying Order Form and remains in force for as long as MediVault processes personal data on the Controller's behalf, including during any post-termination export period.

1.2

Nature and purpose of processing

Storage, retrieval, structuring, transmission, restriction, erasure and — where configured by the Controller — analytics indexing of the data the Controller submits to the Service, for the sole purpose of operating the Patient Data Vault, Secure Healthcare Portal, Identity & Access Management, Audit & Compliance and Integration modules the Controller has licensed.

1.3

Categories of data subjects

Patients and, where relevant, their legal representatives; the Controller's clinical and administrative staff; and, incidentally, any third party named within clinical documentation (e.g. a referring physician or next of kin).

1.4

Categories of personal data — including health data

Identification and contact data; medical records, diagnoses, medications and allergies; clinical documents and diagnostic reports; imaging metadata; laboratory results; treatment and care-plan records; consent and intake forms; and insurance documentation. This explicitly includes health data within the meaning of Art. 5(c) FADP, a category of particularly sensitive personal data.

Controller and
processor duties.

2.1

Processing on instructions only

MediVault processes personal data only on the Controller's documented instructions — including this AVV, the Order Form and configuration choices made in the platform — unless required to do otherwise by Swiss law, in which case MediVault will inform the Controller of that legal requirement before processing, unless the law prohibits such notice.

2.2

Controller obligations

The Controller warrants it has a lawful basis for the personal data it submits, is responsible for the accuracy of that data, and is responsible for its own configuration of access, retention and consent workflows within the platform.

2.3

Confidentiality of personnel

MediVault ensures that any person authorised to process personal data has committed to confidentiality, whether by statutory obligation, employment contract clause, or signed non-disclosure undertaking, and has completed data-protection and security training before being granted any access.

Technical and organisational
measures (TOMs).

Encryption at rest
AES-256-GCM envelope encryption; per-tenant data-encryption keys
Key management
HSM-backed key hierarchy (FIPS 140-2 Level 3); master keys never leave the HSM boundary
Encryption in transit
TLS 1.3 only; TLS 1.2 and below refused at the edge
Data integrity
3× sharded storage with cryptographic integrity verification on read
Audit trail
Append-only, hash-chained, cryptographically signed audit ledger — tamper-evident by construction
Access control
No standing employee access; every access is ticketed, time-boxed, four-eyes approved and recorded
Data residency
Swiss data centres only, for all health data processed under this AVV
Independent verification
ISO 27001, ISO 27701 and SOC 2 Type II — reports available on request

Who else touches
the data, and how you object.

4.1

Authorised sub-processors

The Controller grants MediVault general authorisation to engage sub-processors listed on the published sub-processor register, provided MediVault imposes data-protection obligations on each sub-processor no less protective than this AVV.

4.2

30-day notice and right to object

MediVault will give the Controller at least 30 days' written notice — by email and by updating the register — before engaging a new sub-processor or replacing an existing one with access to the Controller's data. The Controller may object in writing within that period on reasonable data-protection grounds; if the parties cannot resolve the objection, either party may terminate the affected module of the Service without further liability.

Data subject requests
and breach notification.

5.1

Assistance with data subject requests

MediVault will provide reasonable technical assistance to help the Controller respond to requests from data subjects exercising rights under the FADP — including export, rectification and deletion tooling available directly in the platform, and manual support from the Data Protection Officer for anything the platform cannot do on its own.

5.2

Personal data breach notification

MediVault notifies the Controller without undue delay, and in any case within 24 hours of becoming aware of a personal data breach affecting the Controller's data, with the information available at that time and updates as the investigation progresses. Where the breach meets the FADP threshold for likely high risk to data subjects, MediVault separately notifies the Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB), Feldeggweg 1, 3003 Bern within 72 hours.

Verification,
and what happens when it ends.

6.1

Audit rights

MediVault makes available its most recent SOC 2 Type II report, ISO 27001 and ISO 27701 certificates, and a summary of its most recent penetration test on request. Enterprise Customers may conduct, or commission an independent auditor to conduct, an on-site or remote audit once per 12-month period, on 30 days' written notice, during business hours, subject to a mutual non-disclosure agreement.

6.2

Deletion and return on termination

On termination of the underlying Order Form, MediVault makes the Controller's data available for export for 30 days, then permanently deletes all copies — including backups — within a further 30 days, and confirms deletion in writing on request, consistent with the Terms of Service.

6.3

Liability

Liability under this AVV is subject to the limitation of liability set out in the Terms of Service, except that liability for a breach of the core data-protection obligations in Sections 2, 3 and 5 of this AVV is not subject to that cap where doing so would be unlawful under the FADP.

Data processing

Need a signed
AVV for procurement?

Enterprise and Spital customers receive a countersigned, PDF version of this agreement as part of onboarding. Ask your account team or write to the DPO directly.

Reviewed annually by external counsel · Swiss FADP Art. 9