Skip to main content
Legal

Data Processing Agreement

The terms on which we process personal data on your behalf. This applies automatically to every HRMZY customer — you do not need to sign anything to rely on it.

Version 1.0 · effective 15 September 2026.

Processor: Tech Gipfel, Seefeldstrasse 69, 8008 Zürich, Switzerland, trading as HRMZY (“HRMZY”, “we”).

Controller: the customer that has an HRMZY subscription (“you”).

This agreement forms part of, and is governed by, the Terms & Conditions. If you need a countersigned copy for your records, write to contact@hrmzy.com.

1. Roles

You are the controller of the personal data you and your people put into HRMZY — employee records, attendance, leave, payroll inputs, documents and anything else you choose to store. We are your processor: we act on your documented instructions and we do not use your data for our own purposes. Using the platform as intended constitutes your instructions.

We are the controller for a narrow, separate set of data: the account and billing details of the person who subscribes, and the operational logs we need to run and secure the service. That is covered by our Privacy Policy, not by this agreement.

2. Subject matter and duration

We process personal data for as long as your subscription is active, and for the short wind-down period described in section 9. The subject matter is the provision of the HRMZY platform: human-resources administration, attendance and leave, payroll records, projects, and the related reporting.

3. Categories of data and data subjects

Data subjects
Your employees and contractors; your administrators; where you use the CRM and client features, your own clients and leads; where you use recruitment, your candidates.
Categories of data
Identity and contact details; employment details such as role, salary, contract and dates; attendance and leave records; payroll inputs and payslip figures; documents you upload; and any custom fields you create.
Special categories
HRMZY does not require special-category data. If you choose to store it — for example health information in a sick-leave note or a document you upload — you remain responsible for having a lawful basis for doing so.

4. Our obligations

  • Process personal data only on your documented instructions, including for transfers.
  • Ensure the people who handle your data are bound by confidentiality.
  • Apply the technical and organisational measures in section 7.
  • Assist you, so far as we reasonably can, with data-subject requests, impact assessments and consultations with a supervisory authority.
  • Tell you without undue delay if we become aware of a personal-data breach affecting your data, with what we know at the time.
  • Make available the information you need to demonstrate compliance with Article 28, and allow an audit as set out in section 10.

5. Sub-processors

You give us general authorisation to engage sub-processors. The current list, what each receives and where it processes, is published and kept current at hrmzy.com/sub-processors. Each is engaged under a written agreement imposing data-protection obligations no less protective than those in this agreement, and we remain responsible to you for their performance.

We will update that page when the list changes. If you would like advance notice of additions, ask us and we will add you to the notification list; if you reasonably object to a new sub-processor on data-protection grounds, tell us and we will work with you to find a solution or you may terminate.

6. Where your data is processed

The application and its database are hosted in the European Union. Some sub-processors listed in section 5 process data outside Switzerland and the EEA — in particular the AI features send the text you submit to a provider in the United States. Those transfers are made under the European Commission’s Standard Contractual Clauses, or another transfer mechanism recognised under the GDPR and the Swiss revised Federal Act on Data Protection, as incorporated into our agreement with that sub-processor.

AI features can be switched off for your entire company by an administrator, from the AI & Data Protection page in settings. With AI off, no content is sent to the AI provider.

7. Security measures

The measures below are in place today. They are stated because they are true, not as aspirations.

  • Transport encryption (HTTPS/TLS) on every request, with HSTS enforced.
  • Strict separation of customer data: every record is scoped to your company and that scoping is enforced at the data layer, not just in the interface.
  • Role-based permissions, so an administrator decides what each person can see.
  • Optional two-factor authentication, and rate limiting on sign-in and other public endpoints.
  • Sensitive documents — payslips, passports, contracts, invoices — stored on a private path that is not readable over the web.
  • Upload validation that rejects executable file types and double-extension filenames.
  • Credentials and third-party keys encrypted at rest.
  • A content-security policy and related hardening headers on every response.

8. Assisting you with data-subject rights

HRMZY includes tools that let you answer most requests yourself: you can export an individual’s data, correct records directly, and anonymise a person who asks to be erased. Where a request needs something the product does not cover, contact us and we will help within the time the law allows.

9. Return and deletion

You can export your data at any time while your subscription is active. When it ends, you may ask us to return or delete your personal data; unless you ask us to keep it, or the law requires us to, we delete it within 90 days of the subscription ending. Backups are overwritten on their normal cycle.

10. Audit

On reasonable written notice, and no more than once a year unless a supervisory authority requires otherwise, we will provide the information needed to demonstrate compliance with this agreement and respond to a reasonable security questionnaire. Audits must respect confidentiality and must not compromise other customers’ data.

11. Liability and governing law

This agreement is governed by Swiss law, and the courts of Zürich, Switzerland have exclusive jurisdiction, in each case as set out in the Terms & Conditions. Liability under this agreement is subject to the limitations in those Terms. Nothing in this agreement limits a data subject’s rights under applicable data-protection law.

12. Contact

Data-protection queries, breach notifications and audit requests: contact@hrmzy.com, or Tech Gipfel, Seefeldstrasse 69, 8008 Zürich, Switzerland.