Skip to content
Engage366
Home Privacy Policy Terms & Conditions Cookie Policy Contact
Home → Data Processing Agreement

Engage366 Data Processing Agreement (DPA)

Effective Date: August 2026

Processor: SwissHelios S.à.r.l. (UID/IDE: CHE-341.748.617)
Registered Address: Route du Village 1a, 1066 Epalinges, Switzerland
Platform: Engage366
Primary Domain: https://engage366.ch

Table of contents

  1. Purpose and Scope
  2. Definitions
  3. Roles of the Parties
  4. Documented Instructions
  5. Confidentiality
  6. Security of Processing
  7. Subprocessing
  8. International Transfers
  9. Assistance with Data Subject Requests
  10. Personal Data Breaches
  11. Data Protection Impact Assessments and Regulatory Cooperation
  12. Return and Deletion of Customer Personal Data
  13. Audit and Compliance Information
  14. Customer Responsibilities
  15. Records and Documentation
  16. Order of Precedence and Liability
  17. Term and Termination
  18. Governing Law and Jurisdiction
  19. Contact
  20. Annex A - Details of Processing
  21. Annex B - Technical and Organizational Measures
  22. Annex C - Subprocessors
  23. Annex D - International Transfer Safeguards
  24. Signatures

1. Purpose and Scope

This Data Processing Agreement (“DPA”) forms part of the agreement between SwissHelios S.à.r.l. (“SwissHelios,” “Processor,” “we,” “us,” or “our”) and the customer identified in the applicable order, subscription, statement of work, or other agreement (“Customer,” “Controller,” or “you”) governing the Customer’s use of Engage366.

This DPA applies where SwissHelios processes Personal Data on behalf of Customer in connection with the Engage366 platform, related implementation services, integrations, support, or other services covered by the parties’ agreement (the “Services”).

Where Customer acts as a processor on behalf of another controller, SwissHelios will act as Customer’s subprocessor for the relevant processing, and references to “Controller” in this DPA will be interpreted accordingly where required by applicable law.

2. Definitions

“Applicable Data Protection Law” means the data protection and privacy laws applicable to the processing covered by this DPA, including, where applicable, the Swiss Federal Act on Data Protection (nFADP), the EU General Data Protection Regulation (GDPR), the UK GDPR, and implementing or successor legislation.

“Customer Data” means data, content, records, communications, files, or other information submitted to or processed through the Services by or on behalf of Customer.

“Personal Data,” “Controller,” “Processor,” “Processing,” “Data Subject,” and “Personal Data Breach” have the meanings given to them under Applicable Data Protection Law.

“Subprocessor” means a third party engaged by SwissHelios to process Personal Data on behalf of Customer in connection with the Services.

3. Roles of the Parties

Customer determines the purposes and essential means of processing Customer Personal Data and acts as Controller, except where Customer is itself acting as a processor for another controller.

SwissHelios processes Customer Personal Data only on behalf of Customer and in accordance with Customer’s documented instructions, except where processing is required by applicable law. If SwissHelios is legally required to process Personal Data contrary to Customer’s instructions, SwissHelios will inform Customer before the processing unless the law prohibits such notice.

The parties acknowledge that Customer remains responsible for determining whether the Services and Customer’s instructions comply with Applicable Data Protection Law.

4. Documented Instructions

Customer instructs SwissHelios to process Personal Data as necessary to provide, secure, maintain, support, configure, integrate, and improve the Services for Customer; to perform the parties’ agreement and applicable statements of work; and to follow additional documented instructions that are consistent with the Services and this DPA.

SwissHelios will promptly inform Customer if, in SwissHelios’ reasonable opinion, a documented instruction infringes Applicable Data Protection Law, unless prohibited from doing so.

5. Confidentiality

SwissHelios will ensure that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and receive access only to the extent required for their role.

SwissHelios will take reasonable steps to ensure that persons acting under its authority process Customer Personal Data only on documented instructions, except where otherwise required by applicable law.

6. Security of Processing

SwissHelios will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access, taking into account the nature of the processing, the state of the art, implementation costs, and the risks to individuals.

The measures may include, as appropriate to the Services and risk, encryption in transit using TLS, encryption at rest, access controls, multi-factor authentication, logging and monitoring, backup and recovery measures, security testing, incident-management procedures, and organizational controls.

A summary of the technical and organizational measures is included in Annex B. SwissHelios may update security measures over time, provided that the overall level of protection is not materially reduced.

7. Subprocessing

Customer grants SwissHelios general authorization to engage Subprocessors for the processing covered by this DPA, subject to the safeguards in this section.

SwissHelios will impose data protection obligations on each Subprocessor that are materially consistent with the obligations applicable to SwissHelios under this DPA for the processing entrusted to that Subprocessor.

SwissHelios will remain responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Law and the parties’ agreement.

SwissHelios will make its current Subprocessor list available to Customer on request and may publish that list at a designated Engage366 legal or trust page. Where legally required, SwissHelios will provide notice of intended additions or replacements so that Customer has a reasonable opportunity to object on legitimate data-protection grounds.

If the parties cannot resolve a reasonable objection to a new Subprocessor, they will work in good faith to identify a commercially reasonable alternative. If no alternative is reasonably available, either party may exercise any termination rights available under the main agreement with respect to the affected Services.

8. International Transfers

Customer acknowledges that, as described in the Engage366 Privacy Policy and applicable service documentation, processing may occur in Switzerland, the EEA, the United States, or other approved locations used to provide the Services.

Where an international transfer of Personal Data requires additional safeguards under Applicable Data Protection Law, SwissHelios will implement an appropriate transfer mechanism. Depending on the transfer, this may include an adequacy decision, a recognized data privacy framework, applicable Standard Contractual Clauses, Swiss adaptations to such clauses, or another legally recognized safeguard.

Where EU Standard Contractual Clauses or equivalent Swiss transfer clauses are required, the parties agree to cooperate in completing the applicable modules, annexes, and supplementary measures reasonably necessary for the transfer.

9. Assistance with Data Subject Requests

Taking into account the nature of the processing, SwissHelios will provide reasonable assistance to Customer, through appropriate technical and organizational measures where feasible, to enable Customer to respond to requests by Data Subjects exercising rights available under Applicable Data Protection Law.

If SwissHelios receives a request directly from a Data Subject relating to Customer Personal Data, SwissHelios will, where appropriate, direct the request to Customer or notify Customer, unless SwissHelios is legally required to respond directly.

10. Personal Data Breaches

SwissHelios will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

To the extent reasonably available, the notice will provide information that Customer may need to assess the incident and meet applicable notification obligations, including the nature of the breach, categories of affected data or Data Subjects, likely consequences, and remediation or mitigation measures.

SwissHelios’ notification of an incident is not an acknowledgment of fault or liability. Customer remains responsible for determining whether notification to a supervisory authority, Data Subject, or other party is required.

11. Data Protection Impact Assessments and Regulatory Cooperation

Taking into account the nature of processing and the information available to SwissHelios, SwissHelios will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities where such assistance is required by Applicable Data Protection Law and relates to the Services.

The parties will cooperate with competent supervisory authorities to the extent required by applicable law.

12. Return and Deletion of Customer Personal Data

During an active subscription, Customer may use available Service functionality to access or export Customer Data, subject to the capabilities and terms of the Services.

Following termination, Customer will have the export period provided in the applicable Terms & Conditions or agreement, which is currently thirty (30) days unless otherwise agreed. After that period, SwissHelios will delete or anonymize Customer Personal Data in accordance with its standard deletion processes, unless retention is required by law or necessary to establish, exercise, or defend legal claims.

Where Personal Data remains in protected backup systems after deletion from active systems, it may be retained until the applicable backup cycle expires, subject to continued security and access restrictions.

13. Audit and Compliance Information

SwissHelios will make available information reasonably necessary to demonstrate compliance with the processor obligations applicable to the Services, subject to confidentiality, security, privilege, and protection of other customers’ information.

Where required by Applicable Data Protection Law and the information made available is not sufficient, Customer may request an audit relating to the processing covered by this DPA. Audits must be reasonable in scope, coordinated in advance, conducted during normal business hours, and designed to minimize disruption and avoid access to information concerning other customers.

The parties may agree to use relevant independent audit reports, certifications, questionnaires, or other evidence in place of an on-site audit where appropriate.

14. Customer Responsibilities

Customer is responsible for ensuring that it has a lawful basis and all necessary notices, permissions, consents, or other authority to collect and provide Personal Data to SwissHelios and to instruct SwissHelios to process it through the Services.

Customer is responsible for configuring the Services appropriately, managing its users and access rights, protecting credentials, reviewing automated or AI-assisted outputs where appropriate, and complying with applicable communication, marketing, employment, sector-specific, and privacy laws.

Customer must not submit special-category, highly sensitive, regulated, or legally restricted data to the Services unless the applicable Service supports that processing and the parties have agreed any additional safeguards required by law or contract.

15. Records and Documentation

Each party will maintain records and documentation required of it under Applicable Data Protection Law for the processing activities within its responsibility.

SwissHelios will provide Customer with reasonable information about the processing described in this DPA, including the information contained in Annex A and relevant Subprocessor information.

16. Order of Precedence and Liability

If there is a conflict between this DPA and the main agreement regarding the processing of Personal Data, this DPA will control to the extent of that conflict. The remainder of the main agreement remains unchanged.

Any limitations of liability, exclusions, and remedies in the main agreement apply to this DPA to the maximum extent permitted by Applicable Data Protection Law, unless the parties expressly agree otherwise in writing.

Nothing in this DPA limits rights or obligations that cannot lawfully be limited under Applicable Data Protection Law.

17. Term and Termination

This DPA becomes effective when Customer becomes bound by an agreement for Services that involves SwissHelios processing Personal Data on Customer’s behalf and remains in effect for as long as SwissHelios processes Customer Personal Data.

Sections that by their nature should survive termination, including confidentiality, deletion obligations, audit rights for prior processing, liability, and governing law, will survive as applicable.

18. Governing Law and Jurisdiction

Unless Applicable Data Protection Law requires otherwise, this DPA is governed by the same governing law and jurisdiction provisions as the Engage366 Terms & Conditions. The current Terms & Conditions provide for the substantive laws of Switzerland and the competent courts of Lausanne, Canton of Vaud, Switzerland.

19. Contact

Questions regarding this DPA or data protection matters may be directed to:

SwissHelios S.à.r.l.
Attn: Legal & Data Privacy Department
Route du Village 1a
1066 Epalinges, Switzerland
Email: juliosalgado@swisshelios.com
Phone: +41 21 652 59 56 / +41 79 791 59 56
Website: https://swisshelios.com

Annex A - Details of Processing

Item Description
Subject matterProcessing of Personal Data to provide Engage366 CRM, customer engagement, automation, communications, AI-enabled workflow features, implementation, integration, support, and related Services.
DurationFor the term of the applicable Services agreement, plus the post-termination export and deletion period described in this DPA and the main agreement.
Nature of processingCollection, recording, organization, structuring, storage, retrieval, consultation, use, transmission, routing, synchronization, analysis, automation, modification, export, deletion, and other operations necessary to provide the Services.
PurposesCRM and contact management; lead and opportunity management; customer communication; appointment scheduling; workflow automation; campaign execution; reporting; integrations; support; security; service administration; and other documented Customer instructions consistent with the Services.
Categories of Data SubjectsCustomer’s prospects, leads, customers, members, participants, suppliers, business contacts, employees, contractors, representatives, platform users, and other individuals whose Personal Data Customer chooses to process through Engage366.
Categories of Personal DataIdentity and contact data; company and professional data; CRM records; lead and opportunity data; communication history; appointment and calendar data; marketing preferences; support interactions; forms and survey responses; uploaded files/content; technical and usage information; and other Customer-configured fields.
Special categories / sensitive dataNot intended as a default processing category. Customer must not submit sensitive or specially regulated data unless the relevant Service supports it and the parties have agreed the required safeguards.
FrequencyContinuous or as initiated by Customer and its users during the term of the Services.

Annex B - Technical and Organizational Measures

Control Area Summary
Access controlRole-based or permission-based access controls appropriate to the Service; access is limited to authorized personnel and users.
AuthenticationSecure authentication controls, including multi-factor authentication where supported or required for applicable administrative access.
Encryption in transitTLS or comparable encryption is used for data transmitted over public networks where supported by the Service architecture.
Encryption at restEncryption at rest is applied to supported production storage systems, including AES-256 or comparable controls where described in Engage366 privacy/security documentation.
ConfidentialityPersonnel with access to Personal Data are subject to confidentiality obligations and access is limited according to role.
Logging and monitoringSecurity-relevant logging, monitoring, and diagnostic controls are used as appropriate to identify operational or security events.
Availability and recoveryBackup, recovery, redundancy, or restoration measures are maintained as appropriate to the Services and risk.
Incident managementProcesses are maintained to identify, investigate, contain, remediate, and communicate relevant security incidents.
Security reviewTechnical and organizational controls are reviewed and updated over time in light of risk, service changes, and applicable legal requirements.
Subprocessor managementSubprocessors are selected and managed through contractual and organizational controls appropriate to the processing they perform.
Data deletionProcesses support deletion or anonymization following termination or when data is no longer required, subject to legal retention and backup cycles.
Business continuityReasonable continuity and resilience measures are maintained for production services based on service criticality and risk.

Annex C - Subprocessors

Customer grants general authorization for SwissHelios to use Subprocessors in accordance with Section 7.

The current Subprocessor list will be made available by SwissHelios on request and may be published on a designated Engage366 legal or trust page. The list should identify, at minimum, the provider, purpose of processing, and relevant processing location or transfer information.

Annex D - International Transfer Safeguards

Where required by Applicable Data Protection Law, the parties will use an appropriate transfer mechanism, which may include an adequacy decision, a recognized data privacy framework, the applicable EU Standard Contractual Clauses, Swiss adaptations, or another legally recognized safeguard.

The parties will complete any legally required modules, appendices, transfer-impact information, or supplementary measures based on the actual transfer and roles of the parties.

Signatures

This DPA may be accepted by signature, incorporation into an order or master agreement, or another legally valid method agreed by the parties.

SwissHelios S.à.r.l.

Name: ______________________________
Title: _______________________________
Date: ________________________________
Signature: ____________________________

Customer

Legal Entity: _________________________
Name: ______________________________
Title: _______________________________
Date: ________________________________
Signature: ____________________________

Back to top

Engage366

CRM, sales pipelines, customer communication, appointments, workflow automation, and reporting in one connected platform.

Part of SwissHelios

Navigation

Platform How it works Services Industries Clients Pricing FAQ Contact

Contact

info@engage366.ch +41 21 784 00 73 WhatsApp

Rte du Village 1A, 1066 Epalinges, Switzerland

Legal documents

Privacy Policy Terms & Conditions Cookie Policy Data Processing Agreement

© Engage366. All rights reserved.