1. Roles and instructions
The customer is controller and A2Trust is processor only where the customer provides personal data for processing on documented instructions. The accepted order, evidence checklist and written support messages form those instructions.
A2Trust processes the data only to prepare, quality-check, deliver and support the ordered service, unless law requires otherwise.
2. Processing details
The processing may include receiving, viewing, organising, comparing, summarising and securely storing approved exports or view-only evidence. Data can concern website visitors, leads, customers, staff or advertising audiences and may include identifiers, event data, enquiries and business-account metrics.
Customers must avoid unnecessary sensitive data and must have a lawful basis to provide the information.
3. Confidentiality and security
Only authorised people and systems may access the data. A2Trust uses limited permissions, encrypted transport, access controls, backups and operational safeguards appropriate to the risk.
A2Trust personnel and contractors with access are bound by confidentiality. Passwords, recovery codes and unrestricted administrator credentials are not accepted.
4. Subprocessors
The customer authorises providers needed for hosting, secure email, payment-adjacent operations and report delivery. Core infrastructure currently includes Hetzner in Europe. A customer-authorised Google integration or another named source is used only when needed for that order.
A2Trust remains responsible for appropriate contractual protection and will make material subprocessor information available to the customer.
5. International transfers
A2Trust uses European infrastructure for core storage. If an approved source or provider involves another country, an appropriate lawful transfer mechanism is used where required.
The customer should not connect a source if its own instructions or legal duties prohibit that transfer.
6. Requests, incidents and audits
Taking account of the processing, A2Trust will reasonably assist with data-subject requests, security obligations and information needed to demonstrate compliance.
A confirmed personal-data breach affecting customer-provided data will be reported to the customer without undue delay, with available information needed for the customer's assessment.
7. Return and deletion
At the end of the service, A2Trust will delete or return customer-provided personal data on reasonable request unless law requires retention. Delivered reports and accounting records may be retained under the Terms and Privacy Notice.
Backup copies are removed through the normal backup lifecycle and remain protected until deletion.
Service operator
A2Trust is the commercial service name used for this product.
- A2Trust
- A2Arch Sàrl
- Swiss UID
- CHE-458.958.276
- Swiss VAT number
- CHE-458.958.276 MWST
- Registered address
- Rue Neuve 14, 1260 Nyon, Switzerland
- Legal and privacy contact
- desk@a2trust.ch