Data Processing Agreement (AVV)

Agreement on the processing of personal data on behalf of organizations.

Last updated: August 2026

Preamble

This Data Processing Agreement (the “AVV”) is entered into between:

Frank Business Insights (“Echo”, “Processor”, or “we”), operator of the platform startecho.ch

and

the registering Organization (“Customer”, “Controller”, or “you”), as specified in the organization account.

In providing the Echo service, Echo processes personal data on behalf of the Customer. This AVV governs the parties’ rights and obligations in that processing under Art. 9 of the Swiss Federal Act on Data Protection (nFADP).

1. Subject matter and duration of processing

1.1 Subject matter

Echo provides the Customer with the following services:

  • Provision of a dashboard to manage Echo letters
  • Creation and administration of Echo vouchers
  • Administration of letter quotas
  • Physical printing and mailing of Echo letters
  • Delivery of cover letters (Pro package only)

1.2 Duration

Processing continues for the duration of the contractual relationship between the parties (Terms for organizations). After that relationship ends, the deletion rules in section 9 of this AVV apply.

2. Nature and purpose of processing

2.1 Purpose

Personal data are processed solely for the purpose of providing the services listed in section 1.1 and performing the contractual relationship.

2.2 Nature of processing

Processing includes the following activities:

  • Collection and storage of recipient data (name, status, delivery date)
  • Administration of letter quotas and Echo vouchers
  • Creation of print jobs
  • Transmission of shipping data to printing partners and the postal service
  • Making data available in the Customer’s dashboard

2.3 Bound by instructions

Echo processes data solely on the Customer’s instructions and in accordance with this AVV and the Terms for organizations. Echo will not use the data for its own purposes.

3. Categories of data subjects and data

3.1 Data subjects

  • Employees, customers, clients, or other recipients of the Customer (“Recipients”)
  • Administrative contacts of the Customer (organization admins)

3.2 Categories of data processed

Recipient data (collected by the Customer):

  • Recipient name
  • Echo letter status (“voucher open”, “writing”, “scheduled”, “dispatched”)
  • Delivery date chosen by the Customer
  • Voucher code

Recipient data (entered by the Recipient):

  • Recipient postal delivery address
  • Private letter content (encrypted; not visible to the Customer)

Organization data:

  • Company name, UID/VAT number
  • Billing address
  • Name and email address of the administrative contact
  • Selected package, letter quotas, transaction history

3.3 Privacy principle

Through technical encryption, Echo ensures that the Recipient’s private letter content and postal address are never visible to the Customer. The private letter content is decrypted solely for the duration of printing and afterwards re-encrypted or deleted.

4. Rights and obligations of the Controller (Customer)

4.1 Responsibility

The Customer is the controller under Art. 5 nFADP for processing Recipient data. The Customer alone determines the purposes and means of processing.

4.2 Lawfulness of processing

The Customer is responsible for ensuring a valid legal basis under the nFADP for processing Recipient data (e.g. consent, performance of a contract, or legitimate interest).

4.3 Information duties

The Customer undertakes to inform Recipients, before handing over the Echo voucher or link, transparently that:

  • The Customer can see the status of the Echo letter
  • The Customer can see the planned delivery date
  • The private letter content and postal address are not visible to the Customer
  • Depending on the package, a Customer cover letter may be enclosed in the envelope

4.4 Right to issue instructions

The Customer may instruct Echo on processing data, provided the instructions fall within the contractual relationship and this AVV. Instructions must be in writing.

4.5 Information and support

The Customer may request information from Echo about the data processed. Echo supports the Customer in responding to data-subject access requests and in exercising data-subject rights (rectification, deletion, data portability).

5. Obligations of the Processor (Echo)

5.1 Processing bound by instructions

Echo processes data solely in accordance with the Customer’s instructions and this AVV.

5.2 Confidentiality

Echo and its employees undertake to keep confidential all data that become known in the course of processing. This duty continues after the contractual relationship ends.

5.3 Data security

Echo implements appropriate technical and organizational measures under section 6 of this AVV to protect processed data against unauthorized access, loss, destruction, or alteration.

5.4 No disclosure

Echo does not disclose data to third parties unless required to perform the contract (see section 7: sub-processors) or required by law.

5.5 Duty to report data breaches

Echo informs the Customer without delay, and no later than 24 hours after becoming aware of a data breach that poses a high risk to data subjects. The notice includes:

  • Description of the nature of the breach
  • Categories of data concerned and approximate number of data subjects
  • Likely consequences of the breach
  • Measures taken or planned to remedy the breach

5.6 No visibility for the Customer

The Recipient’s private letter content and postal address are never visible to the Customer. Echo decrypts letter content solely for the duration of printing and afterwards deletes it in accordance with the retention periods.

6. Technical and organizational measures (TOMs)

Echo implements the following measures to protect processed data:

6.1 Technical measures

MeasureDescription
Encryption at restLetter are stored using AES-256 encryption (encryption at rest)
Encryption in transitAll data transfers use SSL/TLS-encrypted connections
Letter content encryptionPrivate letter content is stored encrypted and decrypted solely for the duration of printing
Access controlSystem access is password-protected and role-based
Password hashingPasswords are stored only as hashes
Hosting in SwitzerlandAll data are stored physically in Switzerland with Infomaniak Network SA
Regular backupsData are backed up regularly
Firewall and intrusion detectionSystems are protected by firewalls and security systems

6.2 Organizational measures

MeasureDescription
Confidentiality obligationAll employees are bound by confidentiality
Access conceptAccess to data only for authorized employees on a need-to-know basis
TrainingEmployees are trained regularly on data protection and security
No advertising toolsEcho does not use third-party advertising or behavioral analytics tools
Data minimizationOnly data required for the service are collected

7. Sub-processors

7.1 Approved sub-processors

To perform the contractual relationship, Echo engages the sub-processors listed on the current sub-processors page (startecho.ch/en/legal/sub-processors). That list forms part of this AVV. Changes to the list are governed by section 7.3.

7.2 Obligations of sub-processors

Echo ensures that all sub-processors are contractually obliged to comply with data-protection requirements. Processing is carried out solely in accordance with Echo’s instructions and this AVV.

7.3 Changes to sub-processors

Echo may change sub-processors or add further ones, provided the level of data protection is maintained. The Customer will be informed of changes by email. If the Customer does not object within 30 days, the change is deemed approved.

7.4 Deletion by sub-processors

The specific deletion periods for each sub-processor are listed on the sub-processors page (startecho.ch/en/legal/sub-processors).

8. Controller’s audit rights

8.1 Information and evidence

The Customer may request information from Echo on compliance with this AVV. Echo will provide the necessary information on request.

8.2 Audits

The Customer may verify Echo’s technical and organizational measures. Audits take place after prior notice of at least 30 days and during normal business hours. Echo may charge a reasonable fee for audits.

8.3 Support for data protection impact assessments

Echo supports the Customer in carrying out a data protection impact assessment under Art. 22 nFADP where required.

9. Deletion and return of data after the contract ends

9.1 Deletion on request

After the contractual relationship ends, the Customer’s operational data (dashboard credentials, recipient metadata, vouchers) are deleted at the Customer’s express request.

9.2 Statutory retention obligations

Financial data, invoices, and contractual documents are retained for 10 years in accordance with statutory retention periods (Art. 958f CO).

9.3 Letter content

The Recipient’s private letter content and postal address are permanently deleted from the active database 30 days after the letter is handed over to Swiss Post.

9.4 Cover letters

Cover letters written by the Customer are deleted 30 days after the envelope is handed over to Swiss Post.

9.5 No automatic deletion

Unless the Customer requests deletion and no statutory retention obligations require otherwise, operational data remain in the system and may be deleted at any time on request.

10. Liability and indemnification

10.1 Liability of Echo

Echo is liable for damage arising from breach of this AVV in accordance with the Terms for organizations (section 9).

10.2 Indemnification by the Customer

The Customer indemnifies Echo against all claims arising from breach of the Customer’s obligations under section 4 of this AVV, in particular from:

  • Lack of a legal basis for processing Recipient data
  • Insufficient information of Recipients
  • Violations of applicable data-protection laws by the Customer

10.3 Limitation of liability

Echo’s liability is limited to the amount paid for the relevant contract year. Liability for indirect damages, lost profits, and consequential damages is excluded to the extent permitted by law.

11. Final provisions

11.1 Governing law

Swiss law applies exclusively.

11.2 Jurisdiction

The place of jurisdiction for all disputes arising out of or in connection with this AVV is the registered office of Frank Business Insights.

11.3 Amendments

Amendments to this AVV require written form. Echo may adapt this AVV if the legal situation or technical infrastructure changes. The Customer will be informed of changes by email.

11.4 Severability

If any provision of this AVV is invalid, the validity of the remaining provisions remains unaffected.

11.5 Priority

In the event of conflict between this AVV and the Terms for organizations, this AVV prevails to the extent the conflict concerns data processing.

Echo. The time capsule by letter.

Ready to start?

Create your account and send your first letter to the future.