Data Processing Addendum

Last updated: 6 August 2026

This addendum forms part of the Gastro Lab Terms and Conditions and applies whenever a client company registers employees on the platform. It governs the processing of personal data that Gastro Lab carries out on that company's behalf, in accordance with Article 28 of Regulation (EU) 2016/679 and with the Swiss Federal Act on Data Protection. By registering its first employee, the client company accepts this addendum. No separate signature is required; a signed copy will be provided on request.

1. Subject matter and scope

Gastro Lab provides the client company with an online professional training service. To provide it, it processes personal data of the people that company registers. This addendum governs that processing and prevails over any conflicting data protection provision of the Terms and Conditions. It does not apply to the data of the person contracting on behalf of the company, nor to individual users who register on their own account. In those cases Gastro Lab is the controller and only the Privacy Policy applies.

2. Role of each party

The client company is the controller: it decides which people are registered, with what data and for what training purpose. Gastro Lab is the processor and processes that data solely on the client company's behalf and on its instructions. The client company warrants that it has a legal basis for providing its staff's data and that it has informed the individuals concerned as required by applicable law. Gastro Lab does not verify this and is not liable for its absence.

3. Duration

This addendum is in force for as long as the client company maintains at least one employee account on the platform and, in any event, for as long as Gastro Lab holds personal data processed on its behalf. Confidentiality obligations survive termination.

4. Nature and purpose of the processing

The processing consists of hosting, recording, organising, consulting, modifying, disclosing to the client company itself and erasing the data, by automated means. Its sole purpose is to provide the training service: creating and maintaining accounts, assigning courses, recording progress and results, issuing and verifying certificates and sending the associated operational notices. Gastro Lab does not use this data for its own purposes, does not disclose it to third parties other than the sub-processors listed in section 9, does not build profiles from it and does not use it for advertising.

5. Categories of data and of data subjects

Data subjects: the employees the client company registers on the platform. Categories of data: · Identification: full name and email address. · Professional: job title or role, the company the account is associated with and language of use. · Credentials: password stored using a salted key derivation function, never in clear text and never reversibly. · Training: assigned courses, progress per module, answers and results of evaluations, certificates issued and their validity period. · Minimal technical: date and time of access and server logs. No special categories of data are processed. The client company undertakes not to enter health data, offence-related data or any other special category into the platform's free-text fields.

6. Instructions

Gastro Lab processes the data solely in accordance with the client company's documented instructions. Using the platform as intended — registering people, assigning courses, consulting progress, downloading certificates and deactivating accounts — constitutes the ordinary instruction. Further instructions are to be given in writing to adrian@gastrolabacademy.com. Gastro Lab will inform the client company if, in its opinion, an instruction infringes applicable law, and may suspend its execution until the matter is clarified. If a legal obligation required Gastro Lab to process the data otherwise, it will give notice before doing so unless that same law prohibits it.

7. Confidentiality

Gastro Lab warrants that every person authorised to process the data is bound by a duty of confidentiality, contractual or statutory, which survives the end of their relationship. Access is limited to those who need it to provide or maintain the service.

8. Security measures

Gastro Lab applies the technical and organisational measures described in Annex B, appropriate to the risk of the processing. It may modify them provided the resulting level of security is not lower.

9. Sub-processors

The client company gives general authorisation for the use of the sub-processors listed in Annex C. Gastro Lab imposes on each sub-processor data protection obligations equivalent to those in this addendum and remains liable for their acts as for its own. Any addition or replacement of a sub-processor will be notified at least thirty calendar days in advance, by email to the client company's contact address. Within that period the client company may object on reasonable grounds relating to data protection. If the objection cannot be resolved, either party may terminate the contract in respect of the affected services, with a refund of the unused proportional part.

10. International transfers

Processing takes place principally on infrastructure located in the European Economic Area and in Switzerland. Where a sub-processor processes data outside those territories, the transfer relies on an adequacy decision or on the European Commission's standard contractual clauses, with the adaptations recognised by the Swiss authority, together with any supplementary measures that prove necessary.

11. Assistance to the client company

Gastro Lab assists the client company, to the extent the company cannot resolve it itself from within the platform, in handling requests for access, rectification, erasure, restriction, objection and portability, and in complying with its obligations regarding security, breach notification and impact assessment. If an employee addresses a request directly to Gastro Lab, it will pass it on to the client company without delay and will not respond on its own account unless so instructed. This assistance is free of charge in reasonable use. Work that manifestly exceeds that scope may be invoiced against an accepted quotation.

12. Personal data breaches

Gastro Lab will notify the client company of any security breach affecting data processed on its behalf without undue delay and, in any event, within forty-eight hours of becoming aware of it. The notification will describe the nature of the incident, the categories and approximate number of individuals affected, the likely consequences and the measures taken or proposed. Gastro Lab will provide the cooperation the client company needs to meet its own notification obligations towards the supervisory authority and towards the individuals affected.

13. Information and audit

Gastro Lab will make available to the client company the information necessary to demonstrate compliance with this addendum. The client company may request an audit once a year, on thirty calendar days' notice, during business hours and without interrupting the service, either itself or through an independent auditor bound by confidentiality who is not a competitor of Gastro Lab. The request may be answered with existing documentation or certifications where these reasonably cover the subject of the audit. Costs are borne by the client company, unless the audit reveals a material breach.

14. Return and deletion of data

On termination of the service, and at the client company's choice, Gastro Lab will return the data in a structured, commonly used format or erase it together with existing copies, within ninety calendar days. This excludes data Gastro Lab must retain by legal obligation and certificates already issued: their verification code must remain checkable for the diploma to retain its value towards third parties. For that purpose only the minimum data needed to answer that verification is retained.

15. Liability

The parties' liability arising from this addendum is governed by the Terms and Conditions, without prejudice to the liability that data protection law attributes directly to each party towards data subjects and towards supervisory authorities.

16. Governing law

This addendum is governed by Swiss law, without prejudice to the mandatory application of Regulation (EU) 2016/679 where applicable. Jurisdiction is as provided in the Terms and Conditions.

Annex A · Processing details

Subject matter: provision of an online professional training service. Duration: as stated in section 3. Nature and purpose: as stated in section 4. Categories of data and of data subjects: as stated in section 5. Controller: the client company. Processor: Gastro Lab.

Annex B · Technical and organisational measures

· Encryption in transit via TLS for all communication with the platform. · Encryption at rest of the database on the provider's infrastructure. · Passwords stored using a salted key derivation function; never in clear text and never reversibly. · Role-based access control: each person sees only the data their function requires, and a company's manager accesses only their own company's data. · Authenticated sessions using a signed, expiring credential. · Logical isolation of each client company's data. · Logging of access and of relevant operations. · Backups managed by the infrastructure provider, with point-in-time restore. · Least-privilege principle for administrative access, limited to the strictly necessary people. · Review of these measures on any significant change to the service.

Annex C · Authorised sub-processors

· Cloudflare — application hosting, database and content delivery network. Processing on infrastructure in the European Union and Switzerland. · Resend — transactional email delivery: access credentials, course invitations, reminders and operational notices. When a payment provider is added, it will be included in this list in accordance with section 9 before it begins to process any data.

Version 1.0 — in force since 6 August 2026.