Version 1.1 from June 12, 2026
contracting parties
This order processing contract is concluded between the organization that uses the Lua application based on an offer or a contract from Datascale GmbH, hereinafter referred to as the client or responsible party, and:
Datascale GmbH
Bankstrasse 1
8610 Uster
Switzerland
hereinafter referred to as the processor or contractor, collectively the parties.
Contact data protection: Ramon Egger, info@Lua.ch
1. Purpose and subject matter
The client uses the Lua software developed and operated by the contractor as a client information system. As part of this use, Datascale GmbH processes personal data on behalf of the client. This contract regulates the data protection rights and obligations of the parties in connection with order processing.
2. Roles of the parties
The client is responsible for the personal data recorded and processed in Lua. It decides on the purpose, content, scope and means of professional data processing. Datascale GmbH is the order processor. It processes personal data exclusively on behalf of and according to the instructions of the client, unless there is a legal obligation to process it differently.
3. Subject of processing
The subject of processing is the provision, operation, maintenance, security and support of the Lua application. These include in particular:
storage of data;
Display and editing in the application;
User and rights management;
file storage and object-based storage;
backup and restore;
technical logging;
Support and troubleshooting;
security monitoring;
use of AI functions;
Export, deletion or anonymization according to instructions.
4. Type and purpose of processing
Processing is carried out for the following purposes:
Operation of a client information system;
Administration of clients;
Documentation of care, medicine, housing, attendance, absences, processes, tariffs and orders;
collaboration within the institution;
legal, technical and organizational documentation obligations of the client;
Security, availability and traceability of the application;
Support, maintenance and further development.
5. Categories of data subjects
In particular, the following may be affected:
clients;
minors;
relatives;
legal representatives;
contact persons;
employees of the client;
external specialists;
doctors, therapists;
contacts with authorities;
payer;
other people who are recorded by the client in Lua.
6. Categories of processed data
In particular, the following can be edited:
master data;
Contact and address details;
identification data;
dossier data;
progress reports;
care data;
medical information;
diagnoses;
medications;
health data;
Data on social assistance measures;
attendances and absences;
performance and tariff data;
orders;
contact persons and network data;
uploaded documents and files;
user, role and permission data;
Login, security and audit logs as well as technical usage and error data.
Particularly sensitive personal data may be processed, in particular health data, data about social assistance measures and data about minors.
7. Duration of processing
Processing takes place for the duration of the contractual cooperation in connection with Lua, in particular in accordance with the accepted offer or contract and any additional agreements between the parties.
After the collaboration has ended, personal data will be deleted, returned or anonymized according to the client's instructions, unless there is a legal obligation or a legitimate reason for further storage.
Backups are generally retained for 35 days and then overwritten or deleted as part of the regular backup cycle.
8. Instructions from the client
Datascale GmbH only processes personal data in accordance with documented instructions from the client. Instructions can arise in particular from the following documents and actions:
offer or contract;
this order processing agreement;
Configuration of the Lua application;
support requests;
written instructions via email or via a ticket system;
documented admin actions of the client.
Datascale GmbH informs the client if, from Datascale GmbH's perspective, an instruction could violate data protection law.
9. Confidentiality
Datascale GmbH obliges all persons who can gain access to personal data to maintain confidentiality. Only people who need this access to fulfill their tasks are granted access to customer data.
Support access to customer data only occurs:
in an emergency;
in case of disruptions;
at the request of the client;
to the extent necessary for security or contract fulfillment.
10. Technical and organizational measures
Datascale GmbH takes appropriate technical and organizational measures to protect personal data. These include in particular:
Hosting in Switzerland;
Web Application Firewall (WAF);
encrypted transport via TLS;
encrypted storage at Infomaniak Public Cloud;
role-based permissions;
client separation;
two-factor authentication;
secure password procedures;
Need-to-know access restriction;
Logging of security-related events;
regular backups;
Backup retention of 35 days;
monthly patches;
vulnerability and dependency checks;
monitoring;
error tracking;
incident response processes;
regular review of security measures.
11. Subcontractors
Datascale GmbH may use subcontractors to the extent this is necessary to provide Lua. The client grants general authorization for the sub-processors listed in Appendix 1. Datascale GmbH informs the client about significant changes to subcontractors. The client can object for objective data protection reasons. Datascale GmbH ensures that subcontractors are required to take appropriate data protection and security measures.
12. Data processing abroad
The primary operation of Lua takes place in Switzerland. Data processing outside of Switzerland can take place if the services used require this, in particular for:
Laravel Nightwatch;
Laravel Forge;
Snyk for security checks;
If personal data is transferred to countries without an adequate level of data protection, Datascale GmbH ensures appropriate guarantees, for example standard contractual clauses or equivalent contractual protection mechanisms, where necessary.
13. AI features
Datascale GmbH does not use customer data to train its own AI models unless the client explicitly and separately instructs this. Prompts, outputs and other AI-related content are treated as customer data.
14. Support for the rights of those affected
Datascale GmbH provides the client with appropriate support in processing inquiries from data subjects, as long as they relate to data in Lua. This includes, as far as technically possible and proportionate:
search;
information;
exports;
rectification;
deletion;
limitation;
Protocol evaluation.
The primary responsibility for answering inquiries from those affected lies with the client.
15. Data Breaches
Datascale GmbH will inform the client as quickly as possible about any identified data security breaches that affect customer data.
The message contains, where available:
type of incident;
categories of data affected;
affected systems;
suspected or known consequences;
measures already taken;
recommended further measures.
The client remains responsible for any reports to authorities or affected persons, unless the law provides otherwise.
16. Support with data protection impact assessments
If the client has to carry out a data protection impact assessment or a similar risk analysis due to the use of Lua, Datascale GmbH will provide the client with appropriate support with information on the technical and organizational security of Lua.
17. Evidence and Audits
Upon request, Datascale GmbH will provide the client with appropriate information to demonstrate compliance with this contract. Audits or inspections must be announced in advance, must not endanger the operations and security of Datascale GmbH or other customers and must be limited to an appropriate level. Datascale GmbH can also provide evidence through security documentation, certifications, third-party reports or written information.
18. Responsibilities of the client
The client is particularly responsible for:
legality of data collection;
information about data subjects;
obtaining necessary consents;
Authorization concept within the institution;
Granting and revoking user access;
technical accuracy of the data;
legal retention and documentation obligations;
Processing of requests from those affected;
Report to authorities if necessary.
19. Final provisions
This order processing agreement supplements the contractual cooperation between the parties in connection with Lua, in particular the accepted offer or the contract as well as any additional agreements.
In the event of contradictions, the data protection regulations of this order processing contract take precedence over the other agreements between the parties as far as the processing of personal data in the order is concerned.
Swiss law applies.
The place of jurisdiction is the headquarters of Datascale GmbH.
Appendix 1: Subcontractors
| Subcontractor | Purpose | Data categories | Location |
|---|---|---|---|
| Infomaniak | Server hosting, object storage, infrastructure and backup | Customer data, files, databases and backups | Switzerland |
| EveryWare | Server hosting, object storage, infrastructure and backup | Customer data, files, databases and backups | Switzerland |
| Microsoft 365 | Email communication | Communication data, email metadata and, if applicable, content | Switzerland |
| Azure AI | AI features | Prompts, outputs and, if applicable, selected customer data | Switzerland |
| Laravel Forge | Deployment and server management | Infrastructure, deployment and, if applicable, technical metadata | International |
| Laravel Nightwatch | Error tracking, performance and technical analysis | Error data and context | International |
| Snyk | Security testing of code and dependencies | code and repository metadata; no productive customer data | International |