Data Processing Agreement (DPA)
This document supplements the Privacy Policy and describes the processing of personal data on behalf of the customer under Art. 28 GDPR and the corresponding provisions of the Swiss FADP.
Parties
Controller: the customer using AI Swarm Hive. Processor: wservices GmbH, Freiburgstrasse 562, 3172 Niederwangen, Switzerland.
Subject matter and duration
Provision of the AI Swarm Hive platform including hosting of company workspaces, authentication, billing, and metered LLM usage via connected gateways, for the duration of the customer's use of the Service.
Nature, purpose and scope of processing
We process personal data only to provide the Service. Categories of data may include identification and contact data, workspace content submitted by the customer or its agents, and usage and technical metadata. Categories of data subjects may include the customer's staff, its own customers and contacts, and other individuals referenced in workspace content. The customer determines these categories by what it submits.
Instructions
Processing is carried out only on documented instructions of the controller, including this DPA and the product configuration in the customer account. We inform the controller if, in our opinion, an instruction infringes applicable data protection law.
Confidentiality
Personnel authorised to process personal data are bound by confidentiality and process it only on the controller's instructions.
Security
Technical and organisational measures include encryption of secrets (sealed vault), access controls, tenant isolation, and logging of security-relevant events.
No training on your data
We do not use customer content to train AI models; model providers are used in no-train API mode. Customer content is used to improve the Service only where the customer has explicitly opted in.
List of sub-processors
The customer authorises the following sub-processors. In addition, the optional model providers reached through the Requesty gateway are authorised by the customer's own model choices. Material changes will be communicated appropriately.
| Name | Purpose | Location / region |
|---|---|---|
| Stripe, Inc. / Stripe Payments Europe, Ltd. | Payment processing, invoicing, and card vaulting | USA / EU (Ireland), depending on account configuration |
| Requesty | LLM gateway / model routing for agent completions | EU option available; see provider DPA |
| Model providers (via the Requesty gateway) | LLM inference for the models you select (e.g. OpenAI, Anthropic, Perplexity). Optional and customer-authorised — enabling a model authorises its provider. | Varies by provider; some outside the EU/CH and may not offer GDPR-level protection — under SCCs where available |
| DjangoEurope (wservices) | Managed hosting API for per-company environments (system users, DNS, TLS, databases, reverse proxies) | EU / Switzerland (wservices group infrastructure) |
| netcup GmbH | Cloud / server infrastructure for platform or tenant workloads (where provisioned) | EU (Germany and other EU regions) |
| Hetzner Online GmbH | Cloud / server infrastructure for platform or tenant workloads (where provisioned) | EU (Germany, Finland) |
| OVHcloud (OVH SAS) | Cloud / server infrastructure for platform or tenant workloads (where provisioned) | EU (France and other EU regions) |
| IONOS SE | Cloud / server infrastructure for platform or tenant workloads (where provisioned) | EU (Germany and other EU regions) |
| Infomaniak Network SA | Cloud / server infrastructure for platform or tenant workloads (where provisioned) | Switzerland / EU |
Only providers that may process customer personal data for AI Swarm Hive are listed. Self-hosted components (e.g. Headscale VPN control plane, Mattermost, password manager) run in the customer environment and are not third-party cloud sub-processors. The model providers reached through the Requesty gateway are optional and customer-selected: by enabling a given model the customer authorises its provider and accepts that some providers operate outside the EU/CH and may not offer GDPR-level protection. DjangoEurope is the managed hosting platform of the wservices group used to provision tenants.
International transfers
Where a sub-processor processes data outside the EEA/Switzerland, appropriate safeguards (EU Standard Contractual Clauses and the Swiss addendum) apply unless an adequacy decision covers the transfer. Customer-selected model providers may fall outside these safeguards; the customer authorises such processing by choosing those models.
Assistance with data-subject requests
Taking into account the nature of the processing, we assist the controller with appropriate technical and organisational measures in responding to data-subject requests (access, rectification, erasure, portability, objection), insofar as possible.
Personal data breaches
We notify the controller without undue delay after becoming aware of a personal data breach affecting the controller's data, and provide the information the controller reasonably needs to meet its own notification obligations.
Return and deletion
On termination the customer may export its data. We then delete the customer's workspace content within 30 days (sooner on request), except where retention of limited records is required by law.
Information and audits
We make available the information reasonably necessary to demonstrate compliance with these obligations and allow for and contribute to audits, subject to reasonable confidentiality and security conditions.
Contact
DPA requests: info@hermes-agents.com · Legal notice