Data Processing Agreement (AVV)
Version 2026-08-31, last updated 31 August 2026
How Lifetime Software AG processes personal data on behalf of its customers, under Art. 28 GDPR and Art. 9 of the Swiss FADP.
1. Parties, purpose and conclusion
This Data Processing Agreement ("DPA", in German: Auftragsverarbeitungsvertrag, AVV) is concluded between the customer using the Aren service (the "customer", acting as controller) and Lifetime Software AG, Dorfstrasse 60, 8835 Feusisberg, Switzerland ("Lifetime", acting as processor).
It forms an integral part of the Terms of Service (together the "agreement") and governs all processing of personal data that Lifetime carries out on the customer's behalf when providing Aren. It is concluded in electronic form when the customer accepts the Terms of Service; Art. 28(9) GDPR expressly permits this. In case of conflict, this DPA prevails over the Terms of Service for data-protection matters.
For the customer's own account, login and billing data, Lifetime is an independent controller; that processing is described in the Privacy Policy and is not subject to this DPA.
2. Subject matter of the processing
| Subject matter | Provision of Aren, a financial-management and bookkeeping service (hosting, storage, transmission, display, AI-assisted extraction and categorization, bank-data import, reporting, export and backup of customer data). |
|---|---|
| Duration | The term of the agreement, plus the wind-down period in Section 10. |
| Nature and purpose | Processing customer data as necessary to provide the contracted features, on the customer's initiative and configuration. |
| Types of personal data | Financial transaction data (dates, amounts, IBANs, counterparty names, payment references and purpose text); bank-account data; uploaded financial documents and the data extracted from them (invoices, receipts, bank statements, tax correspondence and payslips), which may contain employee names, salary details, tax IDs, social-security numbers and health-insurance information; contact and identification data of the customer's business partners. |
| Categories of data subjects | The customer's employees and contractors; the customer's business partners, suppliers and clients and their staff; other persons appearing in the customer's financial records. |
3. Instructions
Lifetime processes personal data only on the customer's documented instructions, including regarding transfers to third countries, unless required to do otherwise by EU, member-state or Swiss law; in that case Lifetime informs the customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest. The agreement, the customer's use and configuration of the service (uploading documents, connecting banks, triggering features), and any documented individual instructions constitute the complete instructions. Lifetime informs the customer without undue delay if, in its opinion, an instruction infringes applicable data-protection law.
4. Confidentiality
Lifetime ensures that all persons authorized to process customer data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and process the data only as needed for their tasks.
5. Security
Lifetime implements and maintains the technical and organizational measures described in Annex 1, which the parties agree provide a level of security appropriate to the risk (Art. 32 GDPR; Art. 8 FADP). Lifetime may update these measures as technology develops, provided the level of security is not reduced.
6. Sub-processors
The customer grants a general authorization for the engagement of the sub-processors listed in Annex 2. Lifetime imposes on each sub-processor, by contract, data-protection obligations essentially equivalent to those in this DPA, and remains fully liable to the customer for the sub-processor's performance.
Lifetime informs the customer of intended additions or replacements at least 30 days before the change takes effect, by email or within the service. If the customer has a justified data-protection reason to object, the parties will seek a solution in good faith; if none is found, the customer may terminate the agreement before the change takes effect. Continued use after the effective date constitutes acceptance of the change.
7. Assistance
Taking into account the nature of the processing, Lifetime assists the customer with appropriate technical and organizational measures in fulfilling its obligations:
- Data-subject rights (Art. 12-23 GDPR; Art. 25 ff. FADP): the service itself lets the customer access, correct, export and delete records; where a request cannot be handled through the service, Lifetime provides reasonable assistance on request.
- Security, breach notification, impact assessments and prior consultation (Art. 32-36 GDPR): Lifetime provides the information reasonably needed, insofar as it is available to Lifetime.
8. Personal data breaches
Lifetime notifies the customer without undue delay after becoming aware of a personal data breach affecting customer data, and provides the information reasonably required for the customer's own notification duties (Art. 33/34 GDPR; Art. 24 FADP): the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.
9. Audits and information
Lifetime makes available the information necessary to demonstrate compliance with this DPA, primarily through documentation, including this DPA, Annex 1 and available third-party attestations of its sub-processors. Where this is insufficient, the customer (or an independent auditor mandated by it that is not a competitor of Lifetime) may audit compliance no more than once per year, with at least 30 days' notice, during business hours, without disrupting operations, subject to confidentiality, and at the customer's expense, unless the audit follows a personal data breach or is required by a supervisory authority.
10. Deletion and return
Upon termination of the agreement, Lifetime deletes or returns the customer data, at the customer's choice, within 60 days, and deletes existing copies, except where EU, member-state or Swiss law requires continued storage, in which case the data is isolated, protected and deleted once the retention duty ends. Backup copies are purged in the normal backup cycle. The customer can export its transaction data self-service at any time before termination.
11. International transfers
Customer data is stored in the European Union (Germany). Some sub-processors in Annex 2 process data in, or are controlled from, the United States. For such transfers, Lifetime relies on the EU-US Data Privacy Framework where the recipient is certified, and otherwise (or in parallel) on the EU Standard Contractual Clauses (Decision 2021/914) with supplementary technical measures. For Swiss data, the same mechanisms apply as recognized by the FDPIC (Swiss-US DPF; SCCs with the Swiss annex). Details per provider are in Annex 2 and the Privacy Policy.
12. Swiss law (revFADP)
Where the customer is subject to the Swiss Federal Act on Data Protection (FADP/revDSG) instead of or in addition to the GDPR, this DPA applies mutatis mutandis as a processing agreement under Art. 9 FADP: references to the GDPR are read as references to the corresponding FADP provisions, "supervisory authority" means the Swiss Federal Data Protection and Information Commissioner (FDPIC), and "personal data" includes data of legal entities only to the extent the FADP still provides for this.
13. Final provisions
Governing law and jurisdiction follow the Terms of Service. If individual provisions of this DPA are invalid, the remainder stays in effect. Changes to this DPA follow the change mechanism in the Terms of Service; Lifetime will not change it in a way that lowers the level of protection for customer data.
Annex 1: Technical and organizational measures
- Encryption in transit: TLS for all connections, with HTTP Strict Transport Security (HSTS).
- Encryption at rest: bank-connection credentials and tokens are encrypted at the application layer (AES-128-CBC with HMAC-SHA256 authentication); storage volumes are encrypted by the hosting providers.
- Tenant isolation: each customer workspace lives in its own database schema, strictly separating customer data at the database level.
- Access control: role-based permissions within each workspace (owner, accountant, assistant); administrative access to production systems is limited to authorized personnel; passwordless authentication with short-lived, single-use login links.
- Data-processor discipline: no advertising or analytics trackers; sub-processors bound by data processing agreements; AI processing under terms that prohibit training on customer data.
- Availability: managed database hosting with automated backups; documents stored on redundant object storage in the EU.
Annex 2: Approved sub-processors
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Application servers and object storage for uploaded documents | Germany (EU) | None needed (EU) |
| finAPI GmbH | Regulated open-banking aggregation (bank accounts, balances, transactions) | Munich, Germany (EU) | None needed (EU) |
| Neon, Inc. | Managed PostgreSQL database hosting | Frankfurt, Germany (EU); US-controlled operator | Data stored in the EU; EU SCCs for the US operator |
| Google Ireland Ltd / Google LLC | AI-assisted document reading and transaction categorization (Gemini API, paid tier, no training on customer data); address autocomplete (Places API) | Ireland (EU) / USA | EU-US & Swiss-US DPF; EU SCCs |
| AC PM LLC (Postmark) | Transactional email delivery | USA | EU-US & Swiss-US DPF; EU SCCs |
| logo.dev | Company-logo lookup (receives only company names and domains) | USA | EU SCCs with supplementary measures |
The current list is always available at this page. Changes are announced as described in Section 6.