Last updated: August 2026
Preamble
This Data Processing Agreement (the “AVV”) is entered into between:
Frank Business Insights (“Echo”, “Processor”, or “we”), operator of the platform startecho.ch
and
the registering Organization (“Customer”, “Controller”, or “you”), as specified in the organization account.
In providing the Echo service, Echo processes personal data on behalf of the Customer. This AVV governs the parties’ rights and obligations in that processing under Art. 9 of the Swiss Federal Act on Data Protection (nFADP).
1. Subject matter and duration of processing
1.1 Subject matter
Echo provides the Customer with the following services:
- Provision of a dashboard to manage Echo letters
- Creation and administration of Echo vouchers
- Administration of letter quotas
- Physical printing and mailing of Echo letters
- Delivery of cover letters (Pro package only)
1.2 Duration
Processing continues for the duration of the contractual relationship between the parties (Terms for organizations). After that relationship ends, the deletion rules in section 9 of this AVV apply.
2. Nature and purpose of processing
2.1 Purpose
Personal data are processed solely for the purpose of providing the services listed in section 1.1 and performing the contractual relationship.
2.2 Nature of processing
Processing includes the following activities:
- Collection and storage of recipient data (name, status, delivery date)
- Administration of letter quotas and Echo vouchers
- Creation of print jobs
- Transmission of shipping data to printing partners and the postal service
- Making data available in the Customer’s dashboard
2.3 Bound by instructions
Echo processes data solely on the Customer’s instructions and in accordance with this AVV and the Terms for organizations. Echo will not use the data for its own purposes.
3. Categories of data subjects and data
3.1 Data subjects
- Employees, customers, clients, or other recipients of the Customer (“Recipients”)
- Administrative contacts of the Customer (organization admins)
3.2 Categories of data processed
Recipient data (collected by the Customer):
- Recipient name
- Echo letter status (“voucher open”, “writing”, “scheduled”, “dispatched”)
- Delivery date chosen by the Customer
- Voucher code
Recipient data (entered by the Recipient):
- Recipient postal delivery address
- Private letter content (encrypted; not visible to the Customer)
Organization data:
- Company name, UID/VAT number
- Billing address
- Name and email address of the administrative contact
- Selected package, letter quotas, transaction history
3.3 Privacy principle
Through technical encryption, Echo ensures that the Recipient’s private letter content and postal address are never visible to the Customer. The private letter content is decrypted solely for the duration of printing and afterwards re-encrypted or deleted.
4. Rights and obligations of the Controller (Customer)
4.1 Responsibility
The Customer is the controller under Art. 5 nFADP for processing Recipient data. The Customer alone determines the purposes and means of processing.
4.2 Lawfulness of processing
The Customer is responsible for ensuring a valid legal basis under the nFADP for processing Recipient data (e.g. consent, performance of a contract, or legitimate interest).
4.3 Information duties
The Customer undertakes to inform Recipients, before handing over the Echo voucher or link, transparently that:
- The Customer can see the status of the Echo letter
- The Customer can see the planned delivery date
- The private letter content and postal address are not visible to the Customer
- Depending on the package, a Customer cover letter may be enclosed in the envelope
4.4 Right to issue instructions
The Customer may instruct Echo on processing data, provided the instructions fall within the contractual relationship and this AVV. Instructions must be in writing.
4.5 Information and support
The Customer may request information from Echo about the data processed. Echo supports the Customer in responding to data-subject access requests and in exercising data-subject rights (rectification, deletion, data portability).
5. Obligations of the Processor (Echo)
5.1 Processing bound by instructions
Echo processes data solely in accordance with the Customer’s instructions and this AVV.
5.2 Confidentiality
Echo and its employees undertake to keep confidential all data that become known in the course of processing. This duty continues after the contractual relationship ends.
5.3 Data security
Echo implements appropriate technical and organizational measures under section 6 of this AVV to protect processed data against unauthorized access, loss, destruction, or alteration.
5.4 No disclosure
Echo does not disclose data to third parties unless required to perform the contract (see section 7: sub-processors) or required by law.
5.5 Duty to report data breaches
Echo informs the Customer without delay, and no later than 24 hours after becoming aware of a data breach that poses a high risk to data subjects. The notice includes:
- Description of the nature of the breach
- Categories of data concerned and approximate number of data subjects
- Likely consequences of the breach
- Measures taken or planned to remedy the breach
5.6 No visibility for the Customer
The Recipient’s private letter content and postal address are never visible to the Customer. Echo decrypts letter content solely for the duration of printing and afterwards deletes it in accordance with the retention periods.
6. Technical and organizational measures (TOMs)
Echo implements the following measures to protect processed data:
6.1 Technical measures
| Measure | Description |
|---|---|
| Encryption at rest | Letter are stored using AES-256 encryption (encryption at rest) |
| Encryption in transit | All data transfers use SSL/TLS-encrypted connections |
| Letter content encryption | Private letter content is stored encrypted and decrypted solely for the duration of printing |
| Access control | System access is password-protected and role-based |
| Password hashing | Passwords are stored only as hashes |
| Hosting in Switzerland | All data are stored physically in Switzerland with Infomaniak Network SA |
| Regular backups | Data are backed up regularly |
| Firewall and intrusion detection | Systems are protected by firewalls and security systems |
6.2 Organizational measures
| Measure | Description |
|---|---|
| Confidentiality obligation | All employees are bound by confidentiality |
| Access concept | Access to data only for authorized employees on a need-to-know basis |
| Training | Employees are trained regularly on data protection and security |
| No advertising tools | Echo does not use third-party advertising or behavioral analytics tools |
| Data minimization | Only data required for the service are collected |
7. Sub-processors
7.1 Approved sub-processors
To perform the contractual relationship, Echo engages the sub-processors listed on the current sub-processors page (startecho.ch/en/legal/sub-processors). That list forms part of this AVV. Changes to the list are governed by section 7.3.
7.2 Obligations of sub-processors
Echo ensures that all sub-processors are contractually obliged to comply with data-protection requirements. Processing is carried out solely in accordance with Echo’s instructions and this AVV.
7.3 Changes to sub-processors
Echo may change sub-processors or add further ones, provided the level of data protection is maintained. The Customer will be informed of changes by email. If the Customer does not object within 30 days, the change is deemed approved.
7.4 Deletion by sub-processors
The specific deletion periods for each sub-processor are listed on the sub-processors page (startecho.ch/en/legal/sub-processors).
8. Controller’s audit rights
8.1 Information and evidence
The Customer may request information from Echo on compliance with this AVV. Echo will provide the necessary information on request.
8.2 Audits
The Customer may verify Echo’s technical and organizational measures. Audits take place after prior notice of at least 30 days and during normal business hours. Echo may charge a reasonable fee for audits.
8.3 Support for data protection impact assessments
Echo supports the Customer in carrying out a data protection impact assessment under Art. 22 nFADP where required.
9. Deletion and return of data after the contract ends
9.1 Deletion on request
After the contractual relationship ends, the Customer’s operational data (dashboard credentials, recipient metadata, vouchers) are deleted at the Customer’s express request.
9.2 Statutory retention obligations
Financial data, invoices, and contractual documents are retained for 10 years in accordance with statutory retention periods (Art. 958f CO).
9.3 Letter content
The Recipient’s private letter content and postal address are permanently deleted from the active database 30 days after the letter is handed over to Swiss Post.
9.4 Cover letters
Cover letters written by the Customer are deleted 30 days after the envelope is handed over to Swiss Post.
9.5 No automatic deletion
Unless the Customer requests deletion and no statutory retention obligations require otherwise, operational data remain in the system and may be deleted at any time on request.
10. Liability and indemnification
10.1 Liability of Echo
Echo is liable for damage arising from breach of this AVV in accordance with the Terms for organizations (section 9).
10.2 Indemnification by the Customer
The Customer indemnifies Echo against all claims arising from breach of the Customer’s obligations under section 4 of this AVV, in particular from:
- Lack of a legal basis for processing Recipient data
- Insufficient information of Recipients
- Violations of applicable data-protection laws by the Customer
10.3 Limitation of liability
Echo’s liability is limited to the amount paid for the relevant contract year. Liability for indirect damages, lost profits, and consequential damages is excluded to the extent permitted by law.
11. Final provisions
11.1 Governing law
Swiss law applies exclusively.
11.2 Jurisdiction
The place of jurisdiction for all disputes arising out of or in connection with this AVV is the registered office of Frank Business Insights.
11.3 Amendments
Amendments to this AVV require written form. Echo may adapt this AVV if the legal situation or technical infrastructure changes. The Customer will be informed of changes by email.
11.4 Severability
If any provision of this AVV is invalid, the validity of the remaining provisions remains unaffected.
11.5 Priority
In the event of conflict between this AVV and the Terms for organizations, this AVV prevails to the extent the conflict concerns data processing.