Data Processing Agreement
Last updated: September 2026
1. Parties and Scope
This Data Processing Agreement ("DPA") is entered into between the customer that holds a Weqly workspace ("Customer") and Franco Novoa, a sole proprietor based in Muri bei Bern, Kanton Bern, Switzerland, operating Weqly ("Weqly").
This DPA forms part of the Terms of Service and applies automatically whenever Weqly processes personal data on the Customer's behalf. No signature is required. Customers who need a signed copy for their records can request one at help@weqly.com.
This DPA is designed to meet the requirements of the Swiss Federal Act on Data Protection ("FADP") and, where applicable, Article 28 of the EU General Data Protection Regulation ("GDPR"). Terms such as "controller", "processor", "personal data" and "personal data breach" have the meaning given to them in those laws.
2. Roles
The Customer is the controller of the personal data it and its users enter into Weqly. Weqly is the processor. For the personal data Weqly processes for its own purposes (such as account administration, billing and security), Weqly is a controller, as described in our Privacy Policy.
3. Details of the Processing
- Subject matter: provision of the Weqly scheduling and workforce management service.
- Duration: for as long as the Customer uses Weqly, plus the deletion period in section 11.
- Nature and purpose: storing, displaying, organising and transmitting data so the Customer can plan shifts, manage leave, track time and breaks, and notify its users.
- Data subjects: the Customer's employees, contractors, managers and other users it invites to its workspace.
- Categories of personal data: names, email addresses, profile pictures, team membership and roles, shifts and schedules, leave requests and balances, clock-in and break times, messages such as kudos, and technical data such as IP addresses and browser information.
- Special categories: Weqly is not designed to process special categories of data (such as health data). If the Customer records such data, for example a medical reason in a leave note, it is responsible for having a legal basis to do so.
4. Customer Instructions
Weqly processes personal data only on the Customer's documented instructions. The Terms of Service, this DPA and the Customer's use and configuration of Weqly are the Customer's complete instructions. Weqly will inform the Customer if, in its opinion, an instruction violates applicable data protection law. Weqly may process personal data beyond these instructions only where required by law, in which case it will inform the Customer first unless the law prohibits it.
5. Confidentiality
Weqly ensures that every person authorised to process the Customer's personal data is bound by an obligation of confidentiality. Weqly does not sell personal data, does not use it for advertising, and does not use it to track users.
6. Security
Weqly maintains appropriate technical and organisational measures to protect personal data, including:
- encryption of all data in transit (TLS);
- hosting in ISO 27001 certified data centres in the European Union;
- passwords stored only as salted hashes, with optional two-factor authentication;
- role-based access inside each workspace, so users only see what their role allows;
- production access limited to the people who need it to operate the service;
- regular backups and the ability to restore data;
- audit logging of administrative changes and continuous error monitoring;
- regular dependency and security updates.
Weqly may update these measures over time, provided the overall level of protection is not reduced.
7. Subprocessors
The Customer gives Weqly general authorisation to engage subprocessors. The current list, including each subprocessor's purpose and location, is published at weqly.com/subprocessors.
Weqly announces changes by updating that page and its "last updated" date before a new subprocessor starts processing the Customer's personal data. The Customer may object to a change on reasonable data protection grounds by contacting Weqly. If the parties cannot resolve the objection, the Customer may terminate its use of Weqly as its sole remedy.
Weqly imposes data protection obligations on each subprocessor that are at least as protective as those in this DPA, and remains responsible to the Customer for its subprocessors' performance.
8. International Transfers
Customer data is hosted in the European Union. Where a subprocessor processes personal data in a country without an adequacy decision under Swiss or EU law, Weqly ensures appropriate safeguards are in place, such as the European Commission's Standard Contractual Clauses with the Swiss addendum recognised by the FDPIC.
9. Assistance
Taking into account the nature of the processing, Weqly assists the Customer in responding to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability and objection). Much of this is possible directly in Weqly; for anything else, the Customer can contact Weqly. If Weqly receives such a request directly, it will refer the data subject to the Customer.
Weqly also provides reasonable assistance with data protection impact assessments and consultations with supervisory authorities, to the extent they relate to Weqly's processing.
10. Personal Data Breaches
Weqly notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data. The notification describes, as far as known, the nature of the breach, the data and data subjects concerned, its likely consequences, and the measures taken or proposed. Weqly takes reasonable steps to contain the breach and limit its effects.
11. Return and Deletion
The Customer can request a copy of all its personal data at any time, and Weqly will provide it in a common machine-readable format. When the Customer deletes its workspace, Weqly permanently deletes the Customer's personal data after a 30-day grace period, unless the law requires Weqly to keep it. Residual copies in backups are deleted as backups rotate out.
12. Audits
Weqly makes available the information reasonably necessary to demonstrate compliance with this DPA. Where that information is not enough, the Customer may carry out an audit, or have one carried out by an independent auditor bound by confidentiality, with at least 30 days' notice, no more than once a year, during normal business hours, and at the Customer's expense.
13. Liability and Precedence
Each party's liability under this DPA is subject to the limitations in the Terms of Service, except where the law does not allow those limitations. If this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails.
14. Changes, Governing Law and Jurisdiction
Weqly may update this DPA to reflect changes in law or in the service. Changes will not reduce the protection of the Customer's personal data. This DPA is governed by the laws of Switzerland, and the place of jurisdiction is Bern, Switzerland, as set out in the Terms of Service.