Legal

Data Processing Agreement

Last updated June 2026

This Data Processing Agreement ("DPA") forms part of the agreement between you (the "Controller") and unaxus GmbH, the company behind HyperLogin (the "Processor"), where we process personal data on your behalf — for example, data about your organization's members and devices.

Roles

You are the controller of the personal data you submit. HyperLogin acts as processor and processes that data only on your documented instructions.

Subject matter and duration

We process personal data to provide the Service, for the duration of your subscription and as needed to comply with the law.

Categories of data and subjects

  • Data subjects — your members, administrators, and end users.
  • Data — account identifiers, device metadata, and session metadata. Session content is end-to-end encrypted and not accessible to us.

Our obligations

We will process data only on your instructions; ensure personnel are bound by confidentiality; implement appropriate technical and organizational measures; and assist you with data subject requests and security obligations.

Subprocessors

You authorize us to engage the subprocessors listed on our Subprocessors page. We impose data-protection terms on each and remain responsible for their performance. We give notice before adding a new subprocessor.

Security

We maintain end-to-end encryption of session content, encryption in transit, least-privilege access, and regular independent testing. A summary is on our security overview.

Data subject requests

We will promptly inform you of any request we receive relating to your data and assist you in responding.

Breach notification

We will notify you without undue delay after becoming aware of a personal data breach affecting your data.

Audits

We will make available the information necessary to demonstrate compliance and allow for reasonable audits, subject to confidentiality.

Return and deletion

On termination, we will delete or return personal data as you choose, except where retention is required by law.

International transfers

Where data is transferred outside Switzerland or the EEA, we rely on appropriate safeguards such as standard contractual clauses.

Governing law

This DPA is governed by Swiss law. To request a signed copy, contact dpa@hyperlogin.com.

Data Processing Agreement · HyperLogin