Data Processing Addendum
Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Contract / Main Agreement, Unique Terms of Service, the Privacy Policy, or other agreements governing the use of Unique’s service (collectively, the “Agreement”) entered by and between you (“you”, “your”, “Customer“, “Client”), and Unique AG (“Unique”, “provider”).
This DPA sets out the terms that apply with regard to the Processing of Personal Data by Unique, on behalf of Customer, in the course of providing the Unique Service to Customer under the Agreement.
1 DEFINITIONS
- Affiliate means any entity that directly or indirectly controls is controlled by or is under common control with the subject entity.
- Control means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.
- Authorized Affiliate means Customer’s Affiliate(s) that is subject to the Data Protection Laws and is permitted to use the Service.
- Authorized User means any individual authorized by Customer to use the Service through Customer’s account.
- Controller means the entity that determines the purposes and means of processing Personal Data.
- Customer Data means what is defined in the Agreement as “Customer Data”.
- Data Protection Laws means all privacy and data protection laws applicable to the processing of personal data under the Agreement.
- Data Subject means an identified or identifiable natural person.
- Deployment options means the different deployment models Unique offers: Multi-tenant, Single tenant, and Customer-managed tenant.
- GDPR means Regulation (EU) 2016/679 on the protection of natural persons concerning personal data processing.
- Personal Data means information identifying or relating to a Data Subject.
- Personal Data Breach means a security breach leading to unauthorized access to Personal Data.
- Personnel means persons authorized by Unique to process Customer’s Personal Data.
- Process means any operation performed on Personal Data, such as collection, use, and storage.
- Processor means the entity that processes Personal Data on behalf of the Controller.
2 PARTIES AND ROLES
Customer is the Data Controller, and Unique is the Data Processor for deployment options on Unique cloud.
3 DATA PROCESSING
3.1 This DPA applies when Personal Data is processed by Unique strictly on behalf of Customer.
3.2 Subject Matter: Unique processes Customer’s Personal Data as part of providing Customer with the Service.
3.3 Processing by Subprocessors: Unique may engage third-party service providers to process Personal Data on behalf of the Customer.
3.4 Technical and organizational measures are specified in Appendix B.
3.5 Competent authorities per jurisdiction are listed, including links to respective regulatory bodies for GDPR, UK GDPR, US privacy laws, and Singapore PDPA.
3.10 Categories of data subjects:
- Prospects, customers, business partners of Customers.
- Employees or contact persons of Customer's business partners.
- Customer’s Users authorized to use the Services.
3.11 Categories of personal data processed: - First and last name
- Title
- Position
- Employer
- Contact information
- ID data
- Professional life data
- Personal life data
- Localization data
- Account Information: Collected when an end user creates an account.
- User Content: Personal Information in file uploads or feedback.
- Communication Information: Collected from support interactions.
3.12 Sensitive categories of data processed: Categories revealing racial, political opinions, or other sensitive data as defined. 3.14 Purposes for Processing Personal Data: Includes voice processing and conversation analysis during meetings.
4 DATA PROTECTION
4.1 Unique must take all necessary security measures to protect against unauthorized access or alteration of Client’s data.
4.2 The Provider shall report any data incident impacting data confidentiality, integrity, and availability to the Client.
5 DATA PROPERTY
All Confidential Information is and remains the Client’s property. The Provider shall not have rights over this information without Client's consent.
6 DATA STORAGE, RETURN, AND DESTRUCTION
6.1 The Provider will maintain information regarding storage locations and methods. At Client’s request, the Provider will return or delete Client’s data.
6.2 The Provider will guarantee a backup policy for recovery of data.
7 GOVERNING LAW AND EXCLUSIVE COURTS
This Agreement shall be governed by Swiss law, with exclusive jurisdiction in Zurich 1, Switzerland.
APPENDIX A – LIST OF SUB-PROCESSORS
| Name | Purpose | Location | More information |
|---|---|---|---|
| Microsoft, Inc. | Infrastructure and services | CH or chosen location | Azure cloud services for transcription, emails, and reports. |
APPENDIX B - TECHNICAL AND ORGANIZATIONAL MEASURES
- Physical Access Control: Measures to prevent unauthorized access to data processing systems.
- System Access Control: Multiple authorization levels for access to sensitive systems.
- Data Access Control: Access granted on a need-to-know basis.
- Data Transmission Control: Data protection measures during transfer.
- Data Integrity Control: Multi-layered defense against unauthorized modifications.
- Job Control: Ensures processing complies with relevant agreements.
ANNEX I: LIST OF PARTIES
Controller(s):
Name: as specified in the DPA
Address: as specified in the DPA
Processor:
Name: Unique AG
Address: Stockerstr. 34, 8002 Zürich
Last updated: July 2025.