The contracting parties commit to maintaining confidentiality regarding facts and data that are neither obvious nor publicly accessible. This obligation must also be imposed on third parties involved. In case of doubt, facts and data should be treated as confidential. The confidentiality obligations exist prior to contract conclusion and continue after the termination of the contractual relationship or after the fulfillment of the agreed services.
Statutory disclosure and information obligations remain reserved.
The service provider may disclose the fact and essential content of the request for proposal to potential subcontractors but must otherwise treat the request as confidential.
Advertising and publications related to project-specific services require the prior written consent of the contracting party, including the use of the contracting party as a reference.
If a contracting party or a third party involved by them violates the aforementioned confidentiality obligations, the violating party owes the other party a contractual penalty unless they can prove that neither they nor the involved third parties are at fault. This penalty amounts to 10% of the total remuneration per case, but no more than CHF 50,000 per case. Payment of the contractual penalty does not release the violating party from the confidentiality obligations.
Compensation claims based on general liability principles (OR 97 ff.) or clause 17 remain reserved, with the contractual penalty being offset against any compensation owed.
The service provider commits itself and its personnel to comply with the operational, technical, and security-relevant regulations of the contracting party, particularly access guidelines, system access requirements, etc., provided these are communicated in writing to the service provider before the conclusion of the contract or agreed upon thereafter.
Applicable data protection and security regulations, as well as the provisions on official or professional secrecy (Art. 320 and 321 StGB), must be adhered to. In particular, the service provider is obligated to process personal data passed on to or accessible to them from the contracting party only to the extent necessary for the fulfillment of the contract and exclusively for the purposes necessary for fulfilling the contract.
The service provider is obligated to take the technical and organizational measures required to ensure data protection and information security, as required by law, administrative instructions, regulatory orders, and/or the contract, insofar as they relate to the services provided by the service provider. The service provider documents these measures and makes these documents available to the contracting party.
The service provider is obligated to inform the contracting party immediately if they become aware of or suspect that information they are processing for the contracting party has been exposed to unauthorized access, disclosed to unauthorized third parties, lost, or damaged, or has otherwise been processed unlawfully or in violation of the contract.
The service provider must also immediately take the necessary immediate measures to secure the data and prevent or minimize any potential adverse consequences.
The service provider must allow the contracting party to effectively monitor compliance with the requirements relating to data protection and information security that apply to the contracting party according to law, administrative instructions, regulatory orders, and/or the contract (e.g., by providing security audit reports or allowing on-site inspections of the service provider).
The service provider is obligated to cooperate in any regulatory proceedings relating to the services they provide and to provide requested information and documents. If the effort required for the service provider exceeds the normal scope of contractual reporting and accountability, the service provider is entitled to appropriate compensation for their cooperation.
Upon contract termination, the service provider must, unless otherwise stipulated in the contract, transfer or destroy data (including any copies) that they have processed for the contracting party in accordance with the express instructions of the contracting party. The destruction of data must be documented by the service provider, and a copy of the corresponding evidence must be sent to the contracting party without being requested.
The parties may enter into additional or deviating agreements in the contract, including confidentiality agreements or agreements on commissioned data processing.