Data Processing Agreement

Last updated: September 25, 2026

1. What this agreement covers

This Data Processing Agreement is part of our Terms of Service. It applies whenever the sites you build with frascati.app collect personal data of your visitors through frascati.app: form messages, entries in Cloud tables, bookings, orders, contact requests from the AI chat for visitors, and page view statistics. For this data, you are the controller, and Frascati GmbH, Binningerstrasse 95, 4123 Allschwil BL, Switzerland ("we", "us"), is your processor within the meaning of Art. 9 of the Swiss Federal Act on Data Protection (DSG) and Art. 28 of the GDPR. The agreement applies automatically when you use these features; you do not need to sign anything. For the processing of personal data, this agreement takes precedence over the Terms of Service.

2. What we do with the data

We process the data only to run the features you use on your sites. We receive and store form messages, table entries, bookings and orders, show them to you in the editor and let you export and delete them. We notify you by email. When your site uses online booking or payments, we send emails to your visitors in your name: confirmations, reminders and cancellations of bookings, and confirmations of orders. When you switch on the AI chat, we answer your visitors' questions and pass contact requests on to you. When you set a webhook address, we send new data to it. We count page views. We do not use the data for our own purposes, and we do not sell it.

3. Types of data and people concerned

The people concerned are the visitors of your sites, such as guests, buyers and people who contact you. The data can include contact details (name, email address, phone number), the content of messages, notes and table entries, booking details (service, date, time, number of people), order details (items, amount, currency, shipping address, reference of the Stripe payment), questions asked in the AI chat, and the technical data needed to deliver the site and prevent abuse. Page view statistics contain the page, the referring page and the time, without IP addresses. Do not use forms, tables or booking notes to collect health data or other sensitive personal data, unless the law allows it and you have taken the measures it requires.

4. Your instructions

We process the data only on your documented instructions. Your instructions are these terms and the settings you choose in frascati.app, for example switching on the AI chat, setting up booking or payments, or setting a webhook address. If we believe that an instruction breaks data protection law, we tell you. We process data without your instruction only where the law requires it, and we tell you beforehand unless the law forbids it.

5. Confidentiality

Everyone at Frascati GmbH who can access the data is bound to confidentiality.

6. Security

We protect the data with technical and organizational measures that fit the risk. Every transfer is encrypted (HTTPS/TLS). The database is operated by Neon in Frankfurt, Germany, which encrypts stored data with AES-256. Stripe keys that you connect are additionally encrypted by us with AES-256-GCM and are never shown in the browser or passed to the AI. Passwords are stored only as hashes. Your data is accessible to your account and, where needed to operate and support the Service, to authorized staff of Frascati GmbH. Public forms and online booking have limits and spam checks. Our database provider makes automatic backups. We review these measures and improve them as technology develops.

7. Subprocessors

You allow us to use these subprocessors: Vercel (USA) for hosting frascati.app and the published sites; Neon (a US company, database in Frankfurt, Germany) for storing the data named in section 3; Resend (USA) for sending emails to you and to your visitors; OpenRouter (USA) and Anthropic (USA) for the answers of the AI chat for visitors, only if you switch it on; and Sentry (USA) for error reports, which can contain technical data. Each is bound by written data protection obligations that protect the data at least as well as this agreement. We inform you at least 30 days before we add or replace a subprocessor, by email or in the app. You can object for reasons of data protection; if we cannot resolve your objection, you can stop using the affected feature or end your account before the change applies. Payments on your sites are processed by Stripe under your own agreement with Stripe, so Stripe is not our subprocessor. Photos from Pexels and fonts from Bunny Fonts load directly in your visitors' browsers; they are named in our Privacy Policy and should also be named in yours.

8. Transfers outside Switzerland and the EU

Some subprocessors are in the USA. We transfer data there only where adequate protection is ensured: under the Swiss-US or EU-US Data Privacy Framework for certified companies, or on the basis of the standard contractual clauses of the European Commission, with the adjustments that Swiss law requires.

9. Helping you with your duties

You can view, export as CSV and delete form messages, table entries, bookings and orders yourself in the editor. If a visitor asks you for access to their data, a correction or a deletion that you cannot carry out yourself, we help you. If a visitor contacts us directly about data we process for you, we pass the request on to you. As far as we can, we also help you with security, the notification of data breaches and data protection impact assessments.

10. Data breaches

If we become aware of a breach of the security of the data we process for you, we inform you without undue delay, with the information we have: what happened, which data and roughly how many people are affected, the likely consequences, and what we are doing about it.

11. Deletion

When you delete an entry, a table, a booking, a site or your account, we delete the data from our live database. Copies in the backups of our database provider are overwritten automatically at the end of the backup period. When our contract ends, we delete the data, unless the law requires us to keep it. Before you delete your account, you can export your data.

12. Proof and audits

We give you the information you need to show that we meet this agreement. If that is not enough, you may have us audited once a year, with 30 days' notice, during business hours and at your own cost, by an auditor who is bound to confidentiality.

13. Term, liability and law

This agreement applies as long as we process personal data for you. The liability rules of the Terms of Service apply. The agreement is governed by Swiss law, and the place of jurisdiction is the one set in the Terms of Service.

14. Contact

Questions about this agreement: Frascati GmbH, Binningerstrasse 95, 4123 Allschwil BL, Switzerland, email office@frascatisystems.com.