SITE SERVICES / DATA PROCESSING AGREEMENT
Data Processing Agreement
Last updated: 21 September 2026
About this summary
This page summarises how Squibble GmbH processes personal data on behalf of Site Services customers, as a processor under Article 9 of the Swiss Federal Act on Data Protection and, where it applies, Article 28 GDPR. The signed data processing agreement is provided with the customer’s offer or on request at hello@squibble.ch and takes precedence over this summary. The Site Services website itself is covered by the privacy notice.
Roles and instructions
The customer is the controller for the form submissions it collects through Site Services; Squibble is the processor. Squibble processes this data only on the customer’s documented instructions, given through the contract and the form configuration, unless the law requires otherwise.
Subject matter and purpose
Squibble receives, validates and stores form submissions from the customer’s websites, checks them for automated and abusive submissions, makes them available to the customer through the application and API, notifies designated recipients by email where configured, and deletes them when their retention period ends. Processing lasts for the term of the contract and until deletion is complete.
Data subjects and categories of data
Data subjects are people who submit forms on the customer’s websites and people named in those submissions. The data consists of the fields the customer configures, for example name, email address and message, file attachments where a form accepts them, and technical metadata: receipt time, the origin of the submitting website, a keyed hash of the IP address whose key rotates daily, a browser user-agent truncated to 256 characters and the spam assessment. Notification records contain recipient addresses and delivery status. Customers do not collect special categories of personal data through Site Services unless this is agreed.
Retention and deletion
Submissions are kept for 365 days by default; a different period can be set per workspace and per form. Suspected spam is deleted after seven days. An hourly job deletes expired submissions together with their attachments and notification records. Individual submissions can be deleted earlier on request. Database backups are made every six hours and kept on the server for 14 days, so deleted data can remain in backups until they are rotated out. When the contract ends, Squibble deletes the customer’s data or, at the customer’s choice, returns it, unless the law requires it to be kept.
Where data is processed
The application and its database run on servers operated by Squibble and rented from Hetzner in Germany. File attachments are stored in the Zurich region (eu-central-2) of Amazon Web Services in Switzerland. Email notifications are sent through Squibble’s own mail infrastructure unless the customer configures its own SMTP server.
Sub-processors
Hetzner (Germany): server hosting for the application and its database. Amazon Web Services: storage of file attachments in Zurich. WorkOS (USA): sign-in for users of the Site Services application; it receives the account data of customer users, not form submissions. Transfers to the USA are governed by the EU and Swiss Standard Contractual Clauses in WorkOS’s data processing agreement. Squibble informs customers in advance of intended changes to its sub-processors and gives them the opportunity to object.
Technical and organisational measures
Connections are encrypted with TLS. Submission contents and email addresses are encrypted in the database, and attachments are encrypted at rest in storage. Row-level security in the database separates each customer workspace. The raw IP address is never stored. Request logs contain no field values. Submission endpoints check the permitted website origin and apply rate limits; API keys are stored only as keyed hashes and can be revoked. Relevant actions such as key changes, deletions and retention runs are recorded in an audit log.
Confidentiality and staff access
Only authorised Squibble staff who are bound to confidentiality have access to customer data. Their access across customer workspaces is read-only and serves operation and support.
Personal data breaches
Squibble notifies the customer without undue delay after becoming aware of a breach of data security affecting the customer’s data and provides the information the customer needs for its own notification duties.
Assistance and audits
Squibble supports the customer in responding to requests from data subjects, for example by finding and deleting submissions. It provides the information needed to demonstrate compliance with these obligations and allows audits by the customer or an auditor bound to confidentiality after reasonable notice.
Contact
Questions about data processing and requests for the signed agreement: hello@squibble.ch.