Skip to content

Order processing

General agreement on order processing for customers of the Lua application.

Version 1.1 from June 12, 2026

contracting parties

This order processing contract is concluded between the organization that uses the Lua application based on an offer or a contract from Datascale GmbH, hereinafter referred to as the client or responsible party, and:

Datascale GmbH
Bankstrasse 1
8610 Uster
Switzerland

hereinafter referred to as the processor or contractor, collectively the parties.

Contact data protection: Ramon Egger, info@Lua.ch

1. Purpose and subject matter

The client uses the Lua software developed and operated by the contractor as a client information system. As part of this use, Datascale GmbH processes personal data on behalf of the client. This contract regulates the data protection rights and obligations of the parties in connection with order processing.

2. Roles of the parties

The client is responsible for the personal data recorded and processed in Lua. It decides on the purpose, content, scope and means of professional data processing. Datascale GmbH is the order processor. It processes personal data exclusively on behalf of and according to the instructions of the client, unless there is a legal obligation to process it differently.

3. Subject of processing

The subject of processing is the provision, operation, maintenance, security and support of the Lua application. These include in particular:

  • storage of data;

  • Display and editing in the application;

  • User and rights management;

  • file storage and object-based storage;

  • backup and restore;

  • technical logging;

  • Support and troubleshooting;

  • security monitoring;

  • use of AI functions;

  • Export, deletion or anonymization according to instructions.

4. Type and purpose of processing

Processing is carried out for the following purposes:

  • Operation of a client information system;

  • Administration of clients;

  • Documentation of care, medicine, housing, attendance, absences, processes, tariffs and orders;

  • collaboration within the institution;

  • legal, technical and organizational documentation obligations of the client;

  • Security, availability and traceability of the application;

  • Support, maintenance and further development.

5. Categories of data subjects

In particular, the following may be affected:

  • clients;

  • minors;

  • relatives;

  • legal representatives;

  • contact persons;

  • employees of the client;

  • external specialists;

  • doctors, therapists;

  • contacts with authorities;

  • payer;

  • other people who are recorded by the client in Lua.

6. Categories of processed data

In particular, the following can be edited:

  • master data;

  • Contact and address details;

  • identification data;

  • dossier data;

  • progress reports;

  • care data;

  • medical information;

  • diagnoses;

  • medications;

  • health data;

  • Data on social assistance measures;

  • attendances and absences;

  • performance and tariff data;

  • orders;

  • contact persons and network data;

  • uploaded documents and files;

  • user, role and permission data;

  • Login, security and audit logs as well as technical usage and error data.

Particularly sensitive personal data may be processed, in particular health data, data about social assistance measures and data about minors.

7. Duration of processing

Processing takes place for the duration of the contractual cooperation in connection with Lua, in particular in accordance with the accepted offer or contract and any additional agreements between the parties.

After the collaboration has ended, personal data will be deleted, returned or anonymized according to the client's instructions, unless there is a legal obligation or a legitimate reason for further storage.

Backups are generally retained for 35 days and then overwritten or deleted as part of the regular backup cycle.

8. Instructions from the client

Datascale GmbH only processes personal data in accordance with documented instructions from the client. Instructions can arise in particular from the following documents and actions:

  • offer or contract;

  • this order processing agreement;

  • Configuration of the Lua application;

  • support requests;

  • written instructions via email or via a ticket system;

  • documented admin actions of the client.

Datascale GmbH informs the client if, from Datascale GmbH's perspective, an instruction could violate data protection law.

9. Confidentiality

Datascale GmbH obliges all persons who can gain access to personal data to maintain confidentiality. Only people who need this access to fulfill their tasks are granted access to customer data.

Support access to customer data only occurs:

  • in an emergency;

  • in case of disruptions;

  • at the request of the client;

  • to the extent necessary for security or contract fulfillment.

10. Technical and organizational measures

Datascale GmbH takes appropriate technical and organizational measures to protect personal data. These include in particular:

  • Hosting in Switzerland;

  • Web Application Firewall (WAF);

  • encrypted transport via TLS;

  • encrypted storage at Infomaniak Public Cloud;

  • role-based permissions;

  • client separation;

  • two-factor authentication;

  • secure password procedures;

  • Need-to-know access restriction;

  • Logging of security-related events;

  • regular backups;

  • Backup retention of 35 days;

  • monthly patches;

  • vulnerability and dependency checks;

  • monitoring;

  • error tracking;

  • incident response processes;

  • regular review of security measures.

11. Subcontractors

Datascale GmbH may use subcontractors to the extent this is necessary to provide Lua. The client grants general authorization for the sub-processors listed in Appendix 1. Datascale GmbH informs the client about significant changes to subcontractors. The client can object for objective data protection reasons. Datascale GmbH ensures that subcontractors are required to take appropriate data protection and security measures.

12. Data processing abroad

The primary operation of Lua takes place in Switzerland. Data processing outside of Switzerland can take place if the services used require this, in particular for:

  • Laravel Nightwatch;

  • Laravel Forge;

  • Snyk for security checks;

If personal data is transferred to countries without an adequate level of data protection, Datascale GmbH ensures appropriate guarantees, for example standard contractual clauses or equivalent contractual protection mechanisms, where necessary.

13. AI features

Datascale GmbH does not use customer data to train its own AI models unless the client explicitly and separately instructs this. Prompts, outputs and other AI-related content are treated as customer data.

14. Support for the rights of those affected

Datascale GmbH provides the client with appropriate support in processing inquiries from data subjects, as long as they relate to data in Lua. This includes, as far as technically possible and proportionate:

  • search;

  • information;

  • exports;

  • rectification;

  • deletion;

  • limitation;

  • Protocol evaluation.

The primary responsibility for answering inquiries from those affected lies with the client.

15. Data Breaches

Datascale GmbH will inform the client as quickly as possible about any identified data security breaches that affect customer data.

The message contains, where available:

  • type of incident;

  • categories of data affected;

  • affected systems;

  • suspected or known consequences;

  • measures already taken;

  • recommended further measures.

The client remains responsible for any reports to authorities or affected persons, unless the law provides otherwise.

16. Support with data protection impact assessments

If the client has to carry out a data protection impact assessment or a similar risk analysis due to the use of Lua, Datascale GmbH will provide the client with appropriate support with information on the technical and organizational security of Lua.

17. Evidence and Audits

Upon request, Datascale GmbH will provide the client with appropriate information to demonstrate compliance with this contract. Audits or inspections must be announced in advance, must not endanger the operations and security of Datascale GmbH or other customers and must be limited to an appropriate level. Datascale GmbH can also provide evidence through security documentation, certifications, third-party reports or written information.

18. Responsibilities of the client

The client is particularly responsible for:

  • legality of data collection;

  • information about data subjects;

  • obtaining necessary consents;

  • Authorization concept within the institution;

  • Granting and revoking user access;

  • technical accuracy of the data;

  • legal retention and documentation obligations;

  • Processing of requests from those affected;

  • Report to authorities if necessary.

19. Final provisions

This order processing agreement supplements the contractual cooperation between the parties in connection with Lua, in particular the accepted offer or the contract as well as any additional agreements.

In the event of contradictions, the data protection regulations of this order processing contract take precedence over the other agreements between the parties as far as the processing of personal data in the order is concerned.

Swiss law applies.

The place of jurisdiction is the headquarters of Datascale GmbH.

Appendix 1: Subcontractors

Subcontractor Purpose Data categories Location
Infomaniak Server hosting, object storage, infrastructure and backup Customer data, files, databases and backups Switzerland
EveryWare Server hosting, object storage, infrastructure and backup Customer data, files, databases and backups Switzerland
Microsoft 365 Email communication Communication data, email metadata and, if applicable, content Switzerland
Azure AI AI features Prompts, outputs and, if applicable, selected customer data Switzerland
Laravel Forge Deployment and server management Infrastructure, deployment and, if applicable, technical metadata International
Laravel Nightwatch Error tracking, performance and technical analysis Error data and context International
Snyk Security testing of code and dependencies code and repository metadata; no productive customer data International

Consent

This site uses third party services that need your consent.