Orderagag (AVV)

As of August 18, 2026

1. Subject

Thisag governs the rights and obligations of theagand theagNetstream (hereinafter jointly referred to as the "Parties") in connection with the processing of personal data on behalf of theag (hereinafter referred to as the "ag").

Thisag applies to all activities in which theagprocesses or has processed personal data, in whole or in part, onag of theag.

The terms used in thisag are governed by Swiss data protection law. The terms "personal data", "processing" and "ag" correspond to the terms "personal data", "processing" and "ag" in the General Data Protection Regulation (GDPR).

Theagis subject to Swiss data protection law, in particular the Federal Act on Data Protection (FADP). With thisag theagenables compliance with the applicable data protection requirements foragprocessing, in particular pursuant to Art. 9 FADP and, where applicable, pursuant to Art. 28 GDPR.

The European Commission, in its decision of 26 July 2000, determined that Swiss data protection law ensures an adequate level of protection for personal data. This determination is considered an adequacy decision pursuant to Article 45(1) GDPR.

2. Roles of the parties

Theagprocesses personal data onag theagto the extent necessary for the provision of theagagreed services. Theagis the data controller within the meaning of the GDPR for this processing.

Insofar as thisag provides for processing for theag's own purposes, theagshall act as the controller for this processing. The scope and purposes are conclusively defined in section 4.4.

3. Type, subject matter and purpose of theagprocessing

agprocessing will be carried out in accordance with existing or futureagagreements between the parties. In case of discrepancies, the order of precedence of theagprovisions according to Netstream AGB shall apply.

The processingagencompasses all handling of personal data, regardless of the means and procedures used, in particular the archiving, retention, disclosure, procurement, deletion, storage, alteration, destruction, and use of personal data. Personal data is any information relating to an identified or identifiable natural person.

3.1 Categories of processed personal data

Theagprocesses the following categories of personal data within the scope of the agreed services:

  • Basic and contact details of the contact persons and users of theag
  • Access, authentication and device data
  • technical connection and protocol data
  • Content that theagstores or processes in the systems used, the type and scope of which is determined by theag
  • When using streaming services, additional usage data is collected, including playback data, search terms, profile and configuration data, and recordings

The information refers to categories, not individual data fields.

3.2 Categories of affected persons

The persons concerned are employees andagof theag, persons whose data theagprocesses in the systems used, and, in the case of streaming services, theag's subscribers and their authorized co-users of a subscription.

3.3 Particularly sensitive personal data

Theagwill only process particularly sensitive personal data if this has been agreed upon in advance. Particularly sensitive personal data includes data concerning trade union, political, religious or philosophical views or activities, data concerning health, privacy, sex life, sexual orientation or ethnicity or race, data concerning social assistance measures, data concerning administrative and criminal proceedings or sanctions, biometric data that uniquely identifies a natural person, and genetic data.

When using streaming services, the processing of data is deemed agreed upon in accordance with thisag , insofar as it arises from the nature of the service: Usage data may allow inferences to be made about particularly sensitive personal data. Theagshall implement the protective measures for this data in accordance with section 5.

4. Obligations of the parties

4.1 Duration

Theagwill process personal data indefinitely until the termination of thisagor the lastagagreement between the parties concerningagprocessing.

4.2 Instructions

Theagprocesses personal data exclusively asagagreed or in accordance with documented instructionsagthe client, unless theagis legally or regulatory obligated to process the data in a specific manner. In such a case, theaginforms theagof this obligation, unless such notification is prohibited by law.

Theagmay issue further documented instructions throughout the entire duration of theagprocessing.

Theagshall inform theagimmediately if it believes thatagagreements or instructions given violate applicable data protection requirements.

4.3 Designation of Purpose

Theagprocesses personal data exclusively for the purpose(s) stipulated in theagagreements between the parties, unless theagreceives further documented instructions from theag.

The processing for theagown purposes remains reserved in accordance with section 4.4.

4.4 Usage data

When using streaming services, theagalso processes usage data for the following internal purposes:

  1. Operation, fault analysis, troubleshooting and capacity planning of the platform
  2. Provision of evaluations regarding the use of the services of theagto theag
  3. Creation agaggregated, cross-customer analyses of platform usage
  4. Further development of the application and platform functions
  5. Compilation and management of the program offerings
  6. Providing recommendation features for subscribers
  7. Publication agaggregated evaluations according to section 3

This list is exhaustive.

Evaluations according to sections 3 and 7 are carried out exclusively agform. The Agprocedure, including the minimum number of cases per result cell, is documented by theag. Theagwill disclose the procedure upon justified request, provided that no trade secrets are thereby revealed.

Recommendation functions as described in section 6 are derived from relationships between content. These derivations do not contain any personal data. Personal usage data is used exclusively within the environment of the respectiveag.

Theagwill not disclose usage data and derived insights that can be attributed to an individualagto other clients or third parties. The use agaggregated, cross-client insights for the purposes specified in section 4.4 remains permissible.

Theagdoes not pass on usage data to third parties for advertising or marketing purposes and does not combine it with data from other sources to enrich personal profiles.

5. Safety

The contractoragat least the technical and organizational measures (TOMs) published at https://netstream.ch/tom/netstreamimplement to ensure the security of the processed personal data. These TOMs formagthese measures include protecting the processed personal data against security breaches that, whether unintentional or unlawful, lead to the unauthorized disclosure of, unauthorized access to, alteration, loss, or destruction of personal data (hereinafter collectively referred to as "data breaches").

Theagmay adapt the technical and organizational measures in line with technical developments. The level of protection achieved with the existing measures must not be reduced.

Theaggrants its staff access to personal data only to the extent absolutely necessary for the execution, monitoring, and administration of thisag. Theagguarantees that persons authorized to process theaghave committed themselves to confidentiality or are subject to an appropriate statutory duty of confidentiality.

6. Documentation, evidence and testing options

The parties must be able to prove compliance with thisag.

Theagshall process requests from theagforagprocessing in accordance with thisagin an appropriate manner andagdelay.

6.1 Evidence and Information

Theagshall provide theagwith the evidence and information necessary to fulfill its data protection obligations. The published information is accessible via the information on information security published by theag.

Theagwill provide further evidence upon justified request and under a confidentiality agreement in a suitable form. The scope and form will depend on theag's need for evidence and theag's security interests.

If the effort exceeds a reasonable level, particularly in the case of customer-specificag, verification formats, or audits, theagmay invoice the client accordingly. Theagwill inform theagof the anticipated effort in advance.

6.2 Examinations

Theagshall, upon request, enable theagto inspect the processing of theagin accordance with thisag at reasonable intervals or in the event of documented indications of non-compliance and shall contribute to such an inspection.

Theagmay conduct an audit itself or have it conducted by an independent auditor. Such audits are limited to oneag per calendar year. An audit may also include inspections of theag's physical facilities or premises, provided such inspections are necessary, take place during normal business hours without disrupting operations, and are announced with reasonable advance notice. Furthermore, such inspections are only permitted if and to the extent that the audit cannot be conducted using suitable evidence such as certificates or certifications, particularly in the case of data centers.

Theagshall bear the costsagby the contractor for examinations in accordance with this clause 6.2.

The parties shall, uponag, provide the competent supervisory authority(ies) with the information referred to in this Clause 6, including the results of audits, unless such provision is prohibited by law.

7.agprocessing

The clientagthe contractoragauthorization to engageagsubcontractorsagat .netstreamhttps://netstream.ch/unterauftragsbearbeitung/agThis formsag.

Theagshall communicate any changes to this list by replacing or addingagin an appropriate manner. The amendment procedure according to AGB applies to objections and their consequences.

In the event of significant changes, theagwill inform the client in advance if possible. This does not constitute a deadline.

Theagmustagimpose essentially the same obligations onagsubcontractorsagto carry out the processingagthe order as those that apply to theagunder thisag . Theagshall ensure that eachagfulfills the obligations to which theagis subject under thisag and under applicable data protection requirements.

Theagis liable to theagfor ensuring that anyagfulfills its obligations under theagagconcluded with the contractor. Theagaginform the client if aagfails to fulfill itsagobligations.

8. Export of personal data

8.1 Principle

Personal data is processed in Switzerland. Content that theagplaces or edits in the systems used is processed and stored exclusively in Switzerland.

8.2 Support Services

For support services, in particular the processing of supportagand fault reports, as well as communication with theag, the involvement ofagin accordance with section 7 may include processing in other countries. This includes the information transmitted by theagin itsagand reports, but not the content stored in the systems used.

If a malfunction cannot be resolved by theagand the involvement of the software manufacturer as a third support level is required, access to the content stored in the systems used may exceptionally be necessary. Such access is limited in time and scope to what is necessary for troubleshooting and will only occur after prior authorization by theag.

8.3 When using streaming services

When using streaming services, error andagreports are processed by aag, as per section 7, even outside of Switzerland. Such reports include the technical status of the application and device, the account and device information used for identification, and the usage processes preceding the event.

8.4 Protection level

If processing takes place outside of Switzerland, theagensures an appropriate level of protection in accordance with the applicable data protection requirements, in particular through an adequacy decision of the Federal Council or through standardagclauses recognized by the FDPIC.

8.5 Further Export

Any further export will only take place ifagagreed, upon documented instructions from theag, or due to a legal obligation. In the latter case, theagwill inform theagunless prohibited by law.

9. Support of theag

Theagshall inform theagimmediately of anyagreceived from a data subject that relates to the processingagthe order. Theagis entitled to confirm receipt of the request to the data subject but shall not otherwise respond to theag itself unless authorized to do so by theag.

Theagsupports theag, taking into account the nature of theag, in fulfilling its obligation to respond to requests from data subjects to exercise their rights. In providing this support, theagfollows theag's instructions.

Furthermore, theagsupports theagin complying with the following obligations, taking into account the nature of theagprocessing and the information available to her:

  1. Maintaining any necessary record of processing activities
  2. Conducting a data protection impact assessment if the planned processing of personal data by theagis likely to pose a high risk to the fundamental rights or the personality of the data subjects
  3. Consultation with the competent supervisory authorities before processing personal data if a data protection impact assessment reveals that the planned processing, despite the measures taken, poses a high risk to the fundamental rights or the personality of the data subjects
  4. Ensuring that the processed personal data is factually correct and up-to-date by theagimmediately informing theagif it discovers that the personal data it has processed is incorrect or outdated
  5. Ensuring data security appropriate to the risk, in particular through suitable technical and organizational measures in accordance with section 5

Theagshall bear the costsagby the contractor for the support provided in accordance with this clause 9.

10. Reporting of data breaches

In the event of a data security breach, theagshall cooperate with and support theagaccordingly so that theagcan fulfill its obligations to report data security breaches to the relevant supervisory authorities or to notify the data subjects, takingagaccount the nature of theagprocessing and the information available to it.

10.1 Breach of the security of personal data processed by theag

In the event of a data security breach related to personal data processed by theag, theagshall support theagas follows:

  1. when reporting the data security breach to the competent supervisory authorities after theaghas become aware of the breach, if relevant, and, in each case as soon as available, when obtaining the information that must be included in the report in accordance with the applicable data protection requirements
  2. when notifying the data subjects in accordance with applicable data protection requirements, if it is necessary to protect the data subjects or is required by a competent supervisory authority

Theagshall bear the costsagby the contractor for the support provided in accordance with this clause 10.1.

10.2 Breach of the security of personal data processed by theag

Theagshall inform theagwithin 48 hours of becoming aware of a data security breach involving the personal dataagprocesses, using the information available at that time. Anyagagreed notification periods shall take precedence.

Theagwill provide supplementary information as soon as it is available, in particular:

  1. Description of the nature of the breach, if possible including the categories and approximate number of affected persons and the approximate number of affected data records
  2. Contact details of a contact point where further information about the data breach can be obtained
  3. The likely consequences of the data security breach, as well as measures taken oragto remedy and mitigate the potential adverse effects

Theagshall bear the costs for the support in accordance with this clause 10.2.

11. Official access requests

If theagreceives an official request for the release of theag's personal data, it will only release data to the extent that there is a legal obligation to do so and will limit the release to the requested scope. Theagwill inform theagof the request to the extent legally permissible.

12. Suspension ofagprocessing

In the event that theagfails to comply with its obligations under thisag , theagmay instruct theagtoagthe processing of personal data until theagcomplies with thisag or thisag is terminated. Theagshall inform theagimmediately if it is unable to complyag ag.

13. Liability

The liability arrangement is governed by any liability arrangements stipulated in theagagreements between the parties.

14. Termination

For termination, deadlines, and cost implications, the procedure according to AGB applies. During the termagtheag, the client has access to the data it has stored in the systems used and is responsible for backing up or exporting this data before termination. The return of personal data processed under thisag will be carried out in this manner. There is no right to the return of data that theagprocesses as the data controller according to section 4.4.

If there is no possibility of independently exporting personal data processed onag the client, to which theaghas a right, theagshall provide this data in a common format upon request, insofar as this is technically possible. Theagmay charge for any exports beyond this scope.

Upon completion of the project, theagwill delete the personal data processed onag theag. Theagmay request confirmation of the deletion. Technical restrictions imposed by theagremain reserved.

Until its cancellation, theagguarantees compliance with thisag.

Data that theagis required to retain due to legal or regulatory obligations, or to maintain the integrity of security protocols, as well as data whose preservation is necessary for evidentiary purposes in ongoing or foreseeable legal proceedings, are excluded from deletion. This data will be blocked and used exclusively for this purpose.

When using streaming services, recordings are deleted upon termination of access. There is no right to the release of recordings.

15. Amendments to thisag

Theagmay amend thisag . Changes will be communicated in an appropriate form and will apply from the notified date.

16. Final Provisions

Thisag is part of the Netstream AGB.

The parties are obligated to treat all knowledge of the other party's trade secrets and personal data acquired within the scope of thisagas confidential, even after the termination of thisag, unless a party is legally obligated to disclose a specific information. In such a case, the obligated party shall inform the other party of this legal obligation, provided such disclosure is not prohibited by law. If a party has any doubt as to whether information is subject to this confidentiality obligation, the information shall be treated as confidential until expressly released by the other party.

Should individual provisions of thisagbe unenforceable, invalid or ineffective, this shall not affect the enforceability, validity or effectiveness of the remaining provisions and the parties shall replace the individual provision with an enforceable, valid or effective provision that comes as close as possible to the intended data protection result of the individual provision.

Thisag is governed exclusively by Swiss law. Conflict of laws rules and the UN Convention on Contracts for the International Sale of Goods (CISG) are excluded. The exclusive place of jurisdiction is the registered office of theag.

Netstream Logo White

Do you haveagabout our services or need more information? Please contact us via the form or directly at hello(at)netstream

Alternatively, you can use our LiveChat in the bottom right corner or call us on 058 058 40 00.

Netstream Logo White

Learn more.

Learn more about your options with the Netstream Cloud. Leave your contact details and we'll get in touch.

Or call us at:
058 058 40 00