DPA
Data processing agreement (DPA) under revDSG between the customer (property management or advertising client) as the controller and Quartiero as the processor. It applies together with the main contract and prevails on data protection questions in the event of conflict.
Subject matter and duration
Quartiero operates the platform through which the customer maintains its content and plays it on the screens. The processing on behalf of the customer lasts as long as the main contract and ends when that contract ends.
Nature and purpose of processing
Quartiero processes the data in order to provide and operate the platform: managing accounts and organisations, storing the maintained content, assembling and delivering the playlist to the assigned devices, and technical operation and troubleshooting.
The anonymous counts from the screens (movement and click without any link to a person) are not personal data and are not covered by this agreement. See the privacy page.
Categories of data subjects and data
Affected are the users of the portals (the customer's staff) with their account data such as email address and name, as well as persons whose details appear in the maintained content, for example the contact details of a management or a caretaker in a notice.
Customer instructions
Quartiero processes the data only on the customer's documented instructions and for the agreed purposes. As a rule the customer gives instructions through the use of the portals and their settings, otherwise in text form to the contact point named below. If Quartiero considers an instruction unlawful, it informs the customer and may suspend execution until the matter is clarified.
Obligations of the processor
The persons involved in the processing are bound to confidentiality. Quartiero supports the customer with data subjects' access, rectification and deletion requests and in meeting its own data protection obligations, as far as the platform's technical means allow.
Technical and organisational measures
Quartiero takes appropriate technical and organisational measures to protect the data. The measures are structured by protection goal and are kept in line with the state of the art.
Confidentiality. Access only for authorised persons, controlled through sign-in (Amazon Cognito) and role-based permissions per organisation. Separation of the data per organisation (tenant isolation). Encryption of the data in transit and at rest. Device authentication via cryptographic keys, so that only paired devices receive their playlist.
Integrity. Control of data transfer and input through the portals and the programming interfaces. Logging of security-relevant events, so that processing remains traceable.
Availability and resilience. Operation on a managed cloud infrastructure (Amazon Web Services) with redundancy, automatic backups and the ability to recover after an outage.
Procedures for regular review. Regular updates of the software in use, the principle of data minimisation, and anonymous capture of the sensor data without any reference to a person.
Sub-processors
The customer authorises Quartiero to engage the following sub-processors (as of July 2026):
- K-I-Soft IT&Holding GmbH, Bernstrasse 27b, 3122 Kehrsatz (Switzerland): development, technical operation, maintenance and support of the platform on behalf of Quartiero.
- Amazon Web Services, eu-central-2 region (Zurich, Switzerland): hosting, database, storage and delivery of the content.
- Amazon Web Services, eu-central-1 region (Frankfurt, Germany): technical real-time connection of the devices. Only technical and anonymous data is transmitted there in real time, such as device status and control commands. No data is stored in eu-central-1. It merely passes through the region for the moment of delivery and is neither written nor retained there.
- Amazon Cognito (Amazon Web Services, eu-central-2 region, Zurich): sign-in and account management.
- Amazon Simple Email Service (SES) (Amazon Web Services, eu-central-2 region, Zurich): sending the platform's transactional emails, for example for sign-in and account confirmation.
Quartiero binds every sub-processor to an equivalent level of data protection and keeps this list up to date. Further sub-processors, such as a payment provider once billing is introduced, are communicated to the customer in advance, so that the customer can object.
Place of processing
Processing takes place as a rule in Switzerland (AWS region eu-central-2, Zurich). For the technical real-time connection of the devices, the eu-central-1 region (Frankfurt, Germany) is also used. Only technical and anonymous data is transmitted there in real time, such as device status and control commands. No data is stored in eu-central-1. It merely passes through the region for the moment of delivery and is neither written nor retained there. From a Swiss perspective, Germany provides an adequate level of data protection.
Reporting of data security breaches
If Quartiero becomes aware of a data security breach affecting data processed on behalf of the customer, it reports this to the customer without delay and supports the customer with the available information, so that the customer can meet its own reporting obligations.
Customer rights
The customer may verify compliance with this agreement. Quartiero provides the necessary information and evidence on request. An on-site review is possible after prior arrangement and without disrupting operations; the customer bears the cost of a review it initiates.
Return and deletion
At the end of the contract Quartiero deletes the data processed on behalf of the customer or, at the customer's request, returns it in a common format. Statutory retention obligations remain reserved.
Contact
The customer directs data protection questions and instructions to Quartiero GmbH, Bernstrasse 27b, 3122 Kehrsatz, info@quartiero.ch.
Last updated: July 2026