Swiss software from Cham (Zug)
AI analysis in the EUFADP & GDPR compliant
PDF Splitter

Data processing agreement (DPA)

This is a translation. Only the German version is legally binding.

Last updated: October 2026. This data processing agreement (DPA) is confirmed in the customer account with the company name; company, time and version are stored as proof. It is also deemed agreed as soon as an account is opened with PDF Splitter or a plan is taken out. We will send a signed version by e-mail on request.

1. Parties and subject matter

The controller is the customer of PDF Splitter (hereinafter "Controller"). The processor is Agenturen Mani, sole proprietorship, owner: Sepehr Mani, Hinterbergstrasse 21, 6330 Cham, Switzerland (hereinafter "Processor"). This agreement specifies the obligations under Art. 9 of the Swiss Federal Act on Data Protection (FADP) and Art. 28 GDPR for the processing of personal data in connection with PDF Splitter.

2. Nature, purpose and duration of processing

The Processor analyses uploaded PDF documents using artificial intelligence in order to detect document boundaries and to suggest file names and document data. The documents are processed only for the duration of the analysis and are neither stored nor logged. The agreement applies for the duration of the use of PDF Splitter.

3. Types of data and data subjects

All personal data contained in the Controller's documents is processed, for example names, addresses, financial and payroll data and, in some cases, sensitive personal data. Data subjects are in particular clients, employees and business partners of the Controller.

4. Obligations of the Processor

  • The Processor processes personal data only on documented instructions from the Controller; use of PDF Splitter in accordance with its range of functions is deemed to constitute an instruction.
  • The Processor obliges all persons with access to maintain confidentiality.
  • The Processor takes the technical and organisational measures set out in section 7.
  • The Processor assists the Controller with requests from data subjects and with data protection impact assessments, insofar as this is possible with reasonable effort.
  • The Processor reports data security breaches without delay, as a rule within 72 hours of becoming aware of them.
  • As documents are not stored, no return or deletion of documents is necessary after the end of processing. Account data is deleted on request after cancellation.

5. Sub-processors

The Controller authorises the engagement of the following sub-processors:

Sub-processorServicePlace of processing
Google Cloud EMEA Ltd. (Vertex AI)AI analysis of the documentsEU (multi-region "eu")
Cloudflare, Inc.Hosting, database, encrypted relay of mobile phone scansEU (database), global network
Hostpoint AGE-mail deliverySwitzerland

The Processor will inform the Controller of planned changes by e-mail at least 30 days in advance. The Controller may object for good cause and, in this case, terminate the agreement.

6. Place of processing

The documents are processed in Switzerland and in the EU. Documents are not transferred to third countries without an adequate level of data protection.

7. Technical and organisational measures

  • Encryption of all transmissions (TLS); end-to-end encryption for mobile phone scans via QR code.
  • No storage of documents, extracted text or AI results; no content in logs.
  • Splitting and naming of files in the Controller's browser.
  • Passwords only as a cryptographic hash; protected session cookies; limitation of login attempts.
  • Bot protection and misuse limitation; access to administrative functions only for authorised administrators.
  • Regular updating of the software used.

8. Audit rights

The Controller may verify compliance with this agreement by obtaining information. On-site inspections are possible by arrangement and at the Controller's expense.

9. Liability and final provisions

Liability is governed by the GTC. Swiss law applies; the place of jurisdiction is Cham (ZG). In the event of contradictions, this agreement takes precedence over the GTC insofar as the protection of personal data is concerned.