Data processing agreement (AVV).
This agreement governs MediVault's processing of personal data — including health data — on behalf of a Customer acting as controller, in accordance with Art. 9 of the Swiss Federal Act on Data Protection. It forms part of, and is incorporated into, the Terms of Service.
- Breach to customer
- 24 h
- Breach to EDÖB
- 72 h
- Sub-processor notice
- 30 days
- Legal basis
- FADP Art. 9
MediVault AG is a fictional company built for a portfolio / demo website. This page is illustrative template content only — it is not real legal advice, it has not been reviewed by counsel, and it creates no actual rights or obligations. Do not rely on it for an actual product, business or legal decision.

What this AVV
actually governs.
Subject matter and duration
MediVault (the “Processor”) processes personal data on behalf of the Customer (the “Controller”) solely to provide the Service described in the Terms of Service. This agreement takes effect on the effective date of the underlying Order Form and remains in force for as long as MediVault processes personal data on the Controller's behalf, including during any post-termination export period.
Nature and purpose of processing
Storage, retrieval, structuring, transmission, restriction, erasure and — where configured by the Controller — analytics indexing of the data the Controller submits to the Service, for the sole purpose of operating the Patient Data Vault, Secure Healthcare Portal, Identity & Access Management, Audit & Compliance and Integration modules the Controller has licensed.
Categories of data subjects
Patients and, where relevant, their legal representatives; the Controller's clinical and administrative staff; and, incidentally, any third party named within clinical documentation (e.g. a referring physician or next of kin).
Categories of personal data — including health data
Identification and contact data; medical records, diagnoses, medications and allergies; clinical documents and diagnostic reports; imaging metadata; laboratory results; treatment and care-plan records; consent and intake forms; and insurance documentation. This explicitly includes health data within the meaning of Art. 5(c) FADP, a category of particularly sensitive personal data.
Controller and
processor duties.
Processing on instructions only
MediVault processes personal data only on the Controller's documented instructions — including this AVV, the Order Form and configuration choices made in the platform — unless required to do otherwise by Swiss law, in which case MediVault will inform the Controller of that legal requirement before processing, unless the law prohibits such notice.
Controller obligations
The Controller warrants it has a lawful basis for the personal data it submits, is responsible for the accuracy of that data, and is responsible for its own configuration of access, retention and consent workflows within the platform.
Confidentiality of personnel
MediVault ensures that any person authorised to process personal data has committed to confidentiality, whether by statutory obligation, employment contract clause, or signed non-disclosure undertaking, and has completed data-protection and security training before being granted any access.
Technical and organisational
measures (TOMs).
- Encryption at rest
- AES-256-GCM envelope encryption; per-tenant data-encryption keys
- Key management
- HSM-backed key hierarchy (FIPS 140-2 Level 3); master keys never leave the HSM boundary
- Encryption in transit
- TLS 1.3 only; TLS 1.2 and below refused at the edge
- Data integrity
- 3× sharded storage with cryptographic integrity verification on read
- Audit trail
- Append-only, hash-chained, cryptographically signed audit ledger — tamper-evident by construction
- Access control
- No standing employee access; every access is ticketed, time-boxed, four-eyes approved and recorded
- Data residency
- Swiss data centres only, for all health data processed under this AVV
- Independent verification
- ISO 27001, ISO 27701 and SOC 2 Type II — reports available on request
Who else touches
the data, and how you object.
Authorised sub-processors
The Controller grants MediVault general authorisation to engage sub-processors listed on the published sub-processor register, provided MediVault imposes data-protection obligations on each sub-processor no less protective than this AVV.
30-day notice and right to object
MediVault will give the Controller at least 30 days' written notice — by email and by updating the register — before engaging a new sub-processor or replacing an existing one with access to the Controller's data. The Controller may object in writing within that period on reasonable data-protection grounds; if the parties cannot resolve the objection, either party may terminate the affected module of the Service without further liability.
Data subject requests
and breach notification.
Assistance with data subject requests
MediVault will provide reasonable technical assistance to help the Controller respond to requests from data subjects exercising rights under the FADP — including export, rectification and deletion tooling available directly in the platform, and manual support from the Data Protection Officer for anything the platform cannot do on its own.
Personal data breach notification
MediVault notifies the Controller without undue delay, and in any case within 24 hours of becoming aware of a personal data breach affecting the Controller's data, with the information available at that time and updates as the investigation progresses. Where the breach meets the FADP threshold for likely high risk to data subjects, MediVault separately notifies the Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB), Feldeggweg 1, 3003 Bern within 72 hours.
Verification,
and what happens when it ends.
Audit rights
MediVault makes available its most recent SOC 2 Type II report, ISO 27001 and ISO 27701 certificates, and a summary of its most recent penetration test on request. Enterprise Customers may conduct, or commission an independent auditor to conduct, an on-site or remote audit once per 12-month period, on 30 days' written notice, during business hours, subject to a mutual non-disclosure agreement.
Deletion and return on termination
On termination of the underlying Order Form, MediVault makes the Controller's data available for export for 30 days, then permanently deletes all copies — including backups — within a further 30 days, and confirms deletion in writing on request, consistent with the Terms of Service.
Liability
Liability under this AVV is subject to the limitation of liability set out in the Terms of Service, except that liability for a breach of the core data-protection obligations in Sections 2, 3 and 5 of this AVV is not subject to that cap where doing so would be unlawful under the FADP.
Need a signed
AVV for procurement?
Enterprise and Spital customers receive a countersigned, PDF version of this agreement as part of onboarding. Ask your account team or write to the DPO directly.
Reviewed annually by external counsel · Swiss FADP Art. 9