Legal
Data processing agreement
Last updated: 11 July 2026
This agreement governs the processing of personal data by Mandact on behalf of its customers. It applies under Art. 9 of the revised Swiss FADP and Art. 28 GDPR and becomes part of the contractual relationship when the terms of service are accepted — no separate signature is required.
1. Parties
The controller is the customer — the party that decides why and how personal data is processed. The processor is Innopulse Consulting GmbH, Zug, Switzerland, which processes that data on the customer's instructions.
2. Subject matter and duration
The subject matter is the operation of Mandact: issuing, checking, and revoking mandates for AI agents, and keeping the associated evidence chain. The agreement runs for as long as the customer relationship, and ends with it — subject to the retention rules in section 8.
3. Categories of data and data subjects
Processed are account data (email address, name, organisation, role), mandate data (what an agent is authorised to do, for whom, within which limits), decision data (verifications with reason code, timestamp, and signature), and technical log data. Data subjects are the customer's users, its authorised signatories, and, where a mandate names them, counterparties.
4. Bound by instructions
Mandact processes personal data only on the documented instructions of the controller. Use of the service is itself such an instruction. Where Mandact considers an instruction to breach data protection law, it says so.
5. Confidentiality
Everyone with access to personal data is bound to confidentiality and instructed in data protection obligations.
6. Technical and organisational measures
Encryption in transit and at rest, tenant isolation enforced at database level, second factor for administrative actions, an append-only hash-chained evidence log, least-privilege access, and logging of administrative access. The German version lists the measures individually.
7. Sub-processors
Mandact uses sub-processors for hosting, database, email delivery, and payments. Primary data residency is the EU (Frankfurt). The current list, including any transfer outside the EU/EEA and the safeguards that apply, is maintained in the German version and in the sub-processor document. Changes are announced in advance, and the controller may object.
8. Deletion and return
On termination, personal data is deleted or returned. Verification receipts are retained in anonymised form: they are the record that a check happened before an action, and deleting them would remove the protection of both sides of a transaction that already occurred. Statutory retention periods apply independently.
9. Assistance to the controller
Mandact assists the controller in responding to data subject requests, in data protection impact assessments, and in consultations with a supervisory authority. A full JSON export is available directly in the app.
10. Personal data breach
Mandact notifies the controller without undue delay after becoming aware of a personal data breach, and provides the information the controller needs for its own notification.
11. Evidence and audit
The controller may satisfy itself that these obligations are met. Mandact provides the necessary information and supports audits, including inspections, within reasonable limits and subject to reasonable notice.
12. Transfers to third countries
Transfers outside Switzerland and the EU/EEA take place only on a valid legal basis — an adequacy decision or standard contractual clauses with supplementary measures. The German version states which sub-processors this concerns.
13. Liability
Liability follows the terms of service and the mandatory provisions of Art. 82 GDPR.
14. Order of precedence
Where this agreement and the terms of service conflict, this agreement prevails for matters of data processing.
Questions about this agreement: hello@mandact.com · See also: Privacy notice · Terms of Service · Verbindliche deutsche Fassung