Data Processing Agreement
The processor terms under Article 28 GDPR and Article 9 of the Swiss FADP for companies that use WritingAnt. Based on the European Commission's standard contractual clauses for controllers and processors (Decision (EU) 2021/915).
Version 5th October 2026How this agreement applies
This Data Processing Agreement ("DPA") is part of the Terms and Conditions between Ögren Digital and every customer that uses WritingAnt in the course of a business, profession or other professional activity ("Business Customer"). It takes effect automatically when a Business Customer, or a user acting for it, uses the Services; no signature is needed. A countersigned copy can be requested at any time from sales@writing-ant.com, and the Clauses can also be concluded separately for an enterprise or Custom Edition agreement.
For private individuals using WritingAnt for personal purposes, Ögren Digital is the controller of their data and the Privacy Policy applies instead of this DPA.
Two roles exist side by side. For the text a Business Customer's users send to the Services (transcripts, selected text, transcripts from spoken instructions and the resulting texts, together "Customer Content") and for personal data of the users and of the people mentioned in that text, the Business Customer is the controller and Ögren Digital is the processor acting on its documented instructions. For account, billing, usage-metering and product-usage event data (such as which setup steps, guides and features a user has used) that Ögren Digital needs for its own purposes (contract performance, invoicing, quota enforcement, service and product analytics, bookkeeping), Ögren Digital is an independent controller, as described in the Privacy Policy, and these Clauses do not apply to that processing.
Section I
Clause 1 — Purpose and scope
The purpose of these Standard Contractual Clauses (the "Clauses") is to ensure compliance with Article 28(3) and (4) of Regulation (EU) 2016/679 (the "GDPR") and, for Business Customers established in Switzerland, with Article 9 of the Swiss Federal Act on Data Protection (the "FADP").
The controller and the processor listed in Annex I have agreed to these Clauses in order to ensure compliance with Article 28(3) and (4) GDPR and Article 9 FADP.
These Clauses apply to the processing of personal data as specified in Annex II.
Annexes I to IV are an integral part of the Clauses.
These Clauses are without prejudice to obligations to which the controller is subject by virtue of the GDPR or the FADP.
These Clauses do not by themselves ensure compliance with obligations related to international transfers in accordance with Chapter V GDPR; Clause 7.8 and Annex IV describe the transfer safeguards in place.
Clause 2 — Invariability of the Clauses
The parties undertake not to modify the Clauses, except for adding information to the Annexes or updating information in them.
This does not prevent the parties from including the Clauses in a broader contract, or from adding other clauses or additional safeguards, provided that they do not directly or indirectly contradict the Clauses or detract from the fundamental rights or freedoms of data subjects.
Clause 3 — Interpretation
Where these Clauses use the terms defined in the GDPR or the FADP, those terms have the same meaning as in those laws. For a controller established in Switzerland, references to the GDPR are to be read as references to the corresponding provisions of the FADP, and references to a supervisory authority as references to the Federal Data Protection and Information Commissioner.
These Clauses shall be read and interpreted in the light of the provisions of the GDPR and the FADP, and shall not be interpreted in a way that conflicts with their rights and obligations or that prejudices the fundamental rights or freedoms of the data subjects.
Clause 4 — Hierarchy
In the event of a contradiction between these Clauses and the provisions of related agreements between the parties existing at the time when these Clauses are agreed or entered into thereafter, including the Terms and Conditions and the End User License Agreement, these Clauses shall prevail.
Section II — Obligations of the parties
Clause 6 — Description of the processing
The details of the processing operations, in particular the categories of personal data and the purposes of processing for which the personal data is processed on behalf of the controller, are specified in Annex II.
Clause 7 — Obligations of the parties
7.1 Instructions. The processor shall process the personal data only on documented instructions from the controller, unless required to do so by Union, Member State or Swiss law to which the processor is subject; in that case the processor shall inform the controller of that legal requirement before processing, unless the law prohibits this on important grounds of public interest. The controller's instructions are given by using the Services and configuring them (choosing writing styles, languages, the local Basic style or a cloud style, Application Aware presets, and the content submitted for processing); further written instructions may be given to info@oegren-digital.ch. These Clauses, Annex II and the configuration chosen by the controller constitute the documented instructions; each request a user submits is an instruction to process that content as described in Annex II, and the processor keeps no copy on its side of the content of a request beyond the request logs stated in Annex II (up to 30 days, on its cloud services hosted by Microsoft Azure); for metering it keeps only the usage data listed in Annex II, such as the timing of a request, the tokens consumed and the model used, without the content. Its AI sub-processor OpenAI keeps the content only in abuse-monitoring logs for up to 30 days and holds no other copy, as stated in Annex II and Annex IV. The processor shall immediately inform the controller if, in its opinion, an instruction infringes the GDPR, the FADP or applicable data protection provisions.
7.2 Purpose limitation. The processor shall process the personal data only for the specific purposes of the processing set out in Annex II, unless it receives further instructions from the controller. In particular, the processor does not use Customer Content to train or improve AI models, and its AI sub-processor OpenAI is contractually bound not to use it to develop or improve its services without explicit agreement. Custom writing-style descriptions and teaching examples that a user creates (including with the 'Train by examples' function) are stored on the user's computer and are sent, together with the text to be processed, in each request that uses that style, as part of the instructions to the AI model; this improves the results for that user through prompting, not by training a model. They serve only the requests of that user and of other users of the Business Customer with whom the user has chosen to share the style by exporting it, and are not used to train or improve any model for the processor, its sub-processors or any other customer.
7.3 Duration of the processing. Processing by the processor shall only take place for the duration specified in Annex II.
7.4 Security of processing. The processor shall at least implement the technical and organisational measures specified in Annex III to ensure the security of the personal data, including protection against a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access to the data. In assessing the appropriate level of security, the parties have taken due account of the state of the art, the costs of implementation, the nature, scope, context and purposes of processing and the risks involved for the data subjects. The processor shall grant access to the personal data undergoing processing to members of its personnel only to the extent strictly necessary for implementing, managing and monitoring the contract, and shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
7.5 Sensitive data. The Services are not designed for special categories of personal data (Article 9 GDPR), data relating to criminal convictions (Article 10 GDPR) or sensitive personal data under Article 5 FADP. The controller shall not submit such data unless it is lawfully entitled to and has informed the processor in writing in advance so that specific restrictions and additional safeguards can be agreed. The processor recommends that users avoid personal or sensitive information in dictated and selected text; the local Basic writing style processes everything on the user's own computer and is the appropriate choice where no content may leave it; in that case only the account and usage data described in Annex II are exchanged with the processor, not the dictated or selected text.
7.6 Documentation and compliance. The parties shall be able to demonstrate compliance with these Clauses. The processor shall deal promptly and properly with all reasonable inquiries from the controller that relate to the processing under these Clauses. The processor shall make available to the controller all information necessary to demonstrate compliance with the obligations set out in these Clauses and stemming directly from the GDPR and the FADP. At the controller's request, the processor shall also permit and contribute to audits of the processing activities covered by these Clauses, at reasonable intervals or if there are indications of non-compliance. In deciding on a review or an audit, the controller may take into account relevant certifications held by the processor and its sub-processors. The controller may choose to conduct the audit by itself or mandate an independent auditor. Audits may also include inspections at the premises or physical facilities of the processor and shall, where appropriate, be carried out with reasonable notice (at least 30 days, unless a personal data breach or a supervisory authority requires otherwise), no more than once in any twelve-month period, during business hours, under confidentiality, and at the controller's cost. Audits are conducted first on the basis of documentation and remote interviews; an on-site inspection takes place only where that does not resolve the controller's questions. For sub-processors, the processor satisfies the controller's audit right by providing their current certifications and independent audit reports (such as SOC 2 Type II and ISO/IEC 27001) and by exercising its own audit rights under the sub-processor agreements on the controller's reasonable request; on-site inspections of sub-processor data centres are not available. The parties shall make the information referred to in this Clause, including the results of any audits, available to the competent supervisory authority on request.
7.7 Use of sub-processors. The controller gives the processor general authorisation to engage the sub-processors listed in Annex IV. The processor shall specifically inform the controller in writing (by email to the account holder's address and by updating the published list at writing-ant.com/privacy#subprocessors) of any intended changes to that list through the addition or replacement of sub-processors at least 30 days in advance, thereby giving the controller sufficient time to object before the engagement of the sub-processor concerned. The processor shall provide the controller with the information necessary to enable it to exercise its right to object. Where the controller objects on reasonable data protection grounds and the parties cannot resolve the objection, the controller may terminate the affected Services. Where the processor engages a sub-processor to carry out specific processing activities on behalf of the controller, it shall do so by way of a contract which imposes on the sub-processor, in substance, the same data protection obligations as those imposed on the processor in accordance with these Clauses. The processor shall ensure that the sub-processor complies with the obligations to which the processor is subject pursuant to these Clauses, the GDPR and the FADP. At the controller's request, the processor shall provide a copy of such a sub-processor agreement and any subsequent amendments; to the extent necessary to protect business secrets or other confidential information, the processor may redact the text beforehand. The processor shall remain fully responsible to the controller for the performance of the sub-processor's obligations under its contract with the processor, and shall notify the controller of any failure by the sub-processor to fulfil those obligations.
7.8 International transfers. The WritingAnt cloud services and database run on Microsoft Azure in Switzerland (Switzerland North) and the EU, where Microsoft stores the data at rest. The processor uses Microsoft's standard cloud terms, like every Microsoft customer: under the Microsoft Products and Services Data Protection Addendum and its EU Data Boundary commitments for the EU and EFTA (including Switzerland), Microsoft may still process limited data in the United States, for example for service operations, security and technical support, under the Standard Contractual Clauses and the EU-U.S. and Swiss-U.S. Data Privacy Framework. The same applies to the processor's Microsoft 365 environment (Outlook and Teams), which holds support correspondence. The AI inference step is performed by OpenAI: the processor contracts with OpenAI Ireland Ltd under the OpenAI Data Processing Addendum, and OpenAI processes the text on its infrastructure in the United States, under the Standard Contractual Clauses incorporated in that addendum. Account and billing data may be transferred to the United States as set out in Annex IV. Any transfer of data to a third country or an international organisation by the processor or a sub-processor shall be done only on the basis of documented instructions from the controller, which the controller gives for the transfers listed in Annex IV, or in order to fulfil a specific requirement under Union, Member State or Swiss law, and shall take place in compliance with Chapter V GDPR and Articles 16 and 17 FADP. The safeguards relied on are the Standard Contractual Clauses adopted by the European Commission (with the Swiss supplements required by the Federal Data Protection and Information Commissioner), the EU-U.S., Swiss-U.S. and UK Data Privacy Framework certifications of the sub-processors concerned, and the adequacy decision of the European Commission for Switzerland. The processor shall provide the controller with information about the safeguards in place, and a copy of them, on request.
Clause 8 — Assistance to the controller
The processor shall promptly notify the controller of any request it has received from the data subject. It shall not respond to the request itself, unless authorised to do so by the controller.
The processor shall assist the controller in fulfilling its obligations to respond to data subjects' requests to exercise their rights, taking into account the nature of the processing. In practice, Customer Content is not kept by the processor beyond the short-term request logs described in Annex II, and local application data (dictation history, settings, optional saved recordings) is stored encrypted on the user's own computer under the controller's control, where the user can export or delete it at any time.
In addition to the processor's obligation to assist the controller pursuant to Clause 8(2), the processor shall furthermore assist the controller in ensuring compliance with the following obligations, taking into account the nature of the data processing and the information available to the processor: (a) the obligation to carry out an assessment of the impact of the envisaged processing operations on the protection of personal data (a "data protection impact assessment") where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons; (b) the obligation to consult the competent supervisory authority prior to processing where a data protection impact assessment indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk; (c) the obligation to ensure that personal data is accurate and up to date, by informing the controller without delay if the processor becomes aware that the personal data it is processing is inaccurate or has become outdated; (d) the obligations in Article 32 GDPR.
The parties shall set out in Annex III the appropriate technical and organisational measures by which the processor is required to assist the controller in the application of this Clause as well as the scope and the extent of the assistance required.
Clause 9 — Notification of personal data breach
In the event of a personal data breach, the processor shall cooperate with and assist the controller for the controller to comply with its obligations under Articles 33 and 34 GDPR and Article 24 FADP, where applicable, taking into account the nature of processing and the information available to the processor.
9.1 Data breach concerning data processed by the controller. In the event of a personal data breach concerning data processed by the controller, the processor shall assist the controller in notifying the personal data breach to the competent supervisory authority without undue delay after the controller has become aware of it, where relevant (unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons); in obtaining the information which, pursuant to Article 33(3) GDPR, shall be stated in the controller's notification, and which must at least include the nature of the personal data breach including, where possible, the categories and approximate number of data subjects and personal data records concerned, the likely consequences of the breach, and the measures taken or proposed to address the breach; and in complying, pursuant to Article 34 GDPR, with the obligation to communicate without undue delay the personal data breach to the data subject, when the breach is likely to result in a high risk to the rights and freedoms of natural persons.
9.2 Data breach concerning data processed by the processor. In the event of a personal data breach concerning data processed by the processor, the processor shall notify the controller without undue delay after the processor has become aware of the breach, and no later than 48 hours thereafter, by email to the account holder's address. Such notification shall contain, at least: (a) a description of the nature of the breach (including, where possible, the categories and approximate number of data subjects and data records concerned); (b) the details of a contact point where more information concerning the personal data breach can be obtained; (c) its likely consequences and the measures taken or proposed to be taken to address the breach, including to mitigate its possible adverse effects. Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay.
Section III — Final provisions
Clause 10 — Non-compliance with the Clauses and termination
Without prejudice to any provisions of the GDPR or the FADP, in the event that the processor is in breach of its obligations under these Clauses, the controller may instruct the processor to suspend the processing of personal data until the latter complies with these Clauses or the contract is terminated. The processor shall promptly inform the controller in case it is unable to comply with these Clauses, for whatever reason.
The controller shall be entitled to terminate the contract insofar as it concerns processing of personal data in accordance with these Clauses if: (a) the processing of personal data by the processor has been suspended by the controller pursuant to point (a) and if compliance with these Clauses is not restored within a reasonable time and in any event within one month following suspension; (b) the processor is in substantial or persistent breach of these Clauses or its obligations under the GDPR or the FADP; (c) the processor fails to comply with a binding decision of a competent court or the competent supervisory authority regarding its obligations pursuant to these Clauses or to the GDPR or the FADP.
The processor shall be entitled to terminate the contract insofar as it concerns processing of personal data under these Clauses where, after having informed the controller that its instructions infringe applicable legal requirements in accordance with Clause 7.1, the controller insists on compliance with the instructions.
Following termination of the contract, the processor shall, at the choice of the controller, delete all personal data processed on behalf of the controller and certify to the controller that it has done so, or return all the personal data to the controller and delete existing copies unless Union, Member State or Swiss law requires storage of the personal data. Until the data is deleted or returned, the processor shall continue to ensure compliance with these Clauses. In practice: Customer Content held in request logs at the sub-processors expires within 30 days; account data is deleted 30 days after the account is deleted; bookkeeping records are kept for 10 years as required by Swiss law; local application data on the users' computers is under the controller's own control and is removed by uninstalling the application or deleting its data folders, as described in the Privacy Policy.
Clause 11 — Liability, governing law and language
The liability of each party under these Clauses is governed by the Terms and Conditions, without prejudice to the rights of data subjects and the liability regime of Article 82 GDPR.
These Clauses are governed by Swiss law. Where the controller is established in a Member State of the European Union or the European Economic Area and the law of that State mandatorily applies to the processor relationship, the Clauses are governed by the law of that Member State in that respect. The courts at the seat of the processor in Zug, Switzerland, have jurisdiction, without prejudice to mandatory venues for the controller or for data subjects.
These Clauses are concluded in English. Translations are provided for convenience only; the English version prevails.
Annex I — List of parties
Controller: the Business Customer, identified by the organisation and the account holder's email address given when signing up for or purchasing WritingAnt, or named in a separate enterprise agreement. Contact person: the account holder, or the data protection contact the Business Customer notifies to the processor.
Processor: Ögren Digital, Loretostrasse 1, 6300 Zug, Switzerland. Data protection contact: info@oegren-digital.ch. Commercial contact and countersigned copies: sales@writing-ant.com.
Representative of the processor in the European Union (Article 27 GDPR): Instant EU GDPR Representative Ltd, Office 2, 12A Lower Main Street, Lucan Co., Dublin K78 X5P8, Ireland, contact@gdprlocal.com, request portal oegrendigital.gdprlocal.com/eu.
Representative of the processor in Switzerland (Article 14 FADP): ALTRION Sagl, Via Luigi Lavizzari 8, 6850 Mendrisio, Switzerland, contact@gdprlocal.com.
Annex II — Description of the processing
Subject matter. Provision of WritingAnt: speech-to-text with AI-powered editing for Windows and macOS. Speech recognition runs locally on the user's computer. Two functions involve the processor's cloud services. Dictation: when a user chooses a cloud ("polished") writing style, the text transcript of the dictation is sent to the processor's cloud services to be rewritten, corrected and formatted in the chosen style, and the result is inserted at the user's cursor. Editing of selected text: the user highlights text in any application and starts WritingAnt, either choosing a writing style to apply to the highlighted text or speaking an instruction (for example to shorten, rephrase, translate or answer the text); the highlighted text, together with the transcript of the spoken instruction where one was given, is sent to the processor's cloud services to be rewritten in the chosen style or edited, rewritten or used to generate new text as instructed, and the result replaces the highlighted text. In both cases the text is forwarded to the AI sub-processor listed in Annex IV and the result is returned to the user.
Nature and purpose of the processing. Transmission, temporary storage and automated processing of text by large language models hosted by the sub-processors in Annex IV, solely to return the edited or generated text to the user; authentication of users; metering of usage against the subscription plan and recording of product-usage events for service analytics.
Categories of data subjects.
- Users of the Business Customer (employees, contractors) who dictate or select text
- Third parties mentioned in that text: the Business Customer's clients, prospects, candidates, colleagues, partners and other correspondents
Categories of personal data.
- Customer Content: text transcripts of dictation, text selected for editing, transcripts from spoken instructions, the resulting edited or generated text, language and writing-style settings, custom writing-style descriptions and teaching examples
- User account data: full name, email address, IP address, browser user agent, login sessions
- Request metadata: user ID, timestamps, IP address, user agent, request headers, language settings
- Usage and product-usage data: number and timing of requests, tokens consumed, model used, language, application version, operating system, situation profile, product-usage events (setup and onboarding progress, permission status during setup, interface choices and interface language, writing-guide steps completed, use of the custom-style Teach function) and the other items listed in the Privacy Policy. These contain no Customer Content; Ögren Digital processes them as independent controller, as stated in the introduction, and lists them here for transparency
Audio is never part of the processing: voice recordings are transcribed on the user's computer and are not transmitted to the processor or its sub-processors, except for a saved recording that a user chooses to share in a support request, as described below.
Special categories of data. None intended; see Clause 7.5.
Frequency of the processing. Continuous, each time a user submits a request.
Duration of the processing and retention. For the term of the Business Customer's subscription or free account. Customer Content is kept by OpenAI only in abuse-monitoring logs for up to 30 days, then deleted automatically; no application state is kept. The processor's own cloud services keep request logs for up to 30 days. Account data is kept for the life of the account and deleted within 30 days after account deletion. Usage and product-usage data is kept linked to the user account for up to two years for metering and business analysis; after that the processor irreversibly anonymises it by removing the user identifier and reducing timestamps to the day, and keeps only the resulting aggregate statistics, as described in the Privacy Policy. Bookkeeping data is kept for 10 years under Swiss law.
Customer Content and other material in support requests. Users of the Business Customer may include Customer Content in a support request, that is, a transcript or a text that WritingAnt produced, whether pasted as text or shown in a screenshot, for example a transcript that was not processed as expected. They may also share other material to resolve a request, such as screenshots of other applications, log files, settings exports or a saved recording. The processor treats all such material as an instruction from the controller to use it solely to resolve the request; a recording that a user shares in a support request, for example to show a recognition problem, is the only case in which audio reaches the processor, and it is never forwarded to the AI sub-processors. The approved channels for such material are email and Microsoft Teams; it is then stored in the processor's Microsoft 365 environment (Annex IV) and kept for the support retention period stated in the Privacy Policy. Messaging platforms such as WhatsApp and LinkedIn are not approved channels for such material; material nevertheless received there is used only to resolve the request and is deleted from the conversation once the request is closed. The support conversation itself, such as the question asked, the answer given and the contact details used, is not Customer Content; the processor handles it as an independent controller under the Privacy Policy.
Processing locations. The WritingAnt cloud services (Microsoft Azure, Switzerland North) receive the text and forward it to OpenAI for inference; OpenAI processes it in the United States under its Data Processing Addendum and Standard Contractual Clauses (contracting entity OpenAI Ireland Ltd). Account authentication and payment processing take place in the United States and the EU, under the safeguards in Annex IV. Microsoft stores data at rest in the chosen Swiss and EU regions and may process limited data in the United States under its standard terms, as described in Clause 7.8; this also applies to the processor's Microsoft 365 environment (email and Teams).
Processing by sub-processors. Subject matter, nature and duration as above; the parties and the data each receives are listed in Annex IV.
Annex III — Technical and organisational measures
Measures to ensure the security of the processing, implemented by the processor and, through contract, by its sub-processors.
- Data minimisation by design: speech recognition runs locally; only the text transcript, never the audio, is sent for cloud processing. The local Basic writing style processes everything on the user's computer, so neither audio nor text leaves it.
- Encryption in transit: all communication between the application and the processor's services and between the processor and its sub-processors uses TLS (HTTPS).
- Encryption at rest on the user's computer: settings, credentials, dictation history, custom styles and optional saved recordings are encrypted with AES with HMAC authentication; the key is held in the operating system's secure key store (macOS Keychain, Windows Credential Manager) and never leaves the device.
- Local inter-process communication is encrypted and restricted to one client on the local computer.
- Processing locations: the WritingAnt cloud services, database and backups run in Microsoft Azure regions in Switzerland and the EU; AI inference by OpenAI in the United States under OpenAI's Data Processing Addendum and Standard Contractual Clauses; limited processing by Microsoft in the United States under its standard terms (Clause 7.8).
- Retention limits: request data and logs at the AI sub-processors are deleted automatically after at most 30 days; account data 30 days after account deletion; consent records 12 months; usage data linked to an account at most two years, then irreversibly anonymised.
- No model training: Customer Content is not used by the processor to train or improve models, and OpenAI commits in its Services Agreement not to use Customer Content to develop or improve its services unless the customer explicitly agrees (API data has not been used for training since 1 March 2023). Custom writing-style descriptions and teaching examples are sent as part of the instructions in each request that uses that style and improve the results for that user through prompting only; see Clause 7.2.
- Pseudonymisation: pre-login startup telemetry is reported under a random, per-launch identifier that is never linked to the user account.
- Access control: access to production systems and data is limited to the processor's personnel who need it, protected by strong authentication, and bound by confidentiality.
- Sub-processor management: written data protection terms with each sub-processor (Annex IV), transfer safeguards documented, list published and change notice given per Clause 7.7.
- User control: users can turn off the clipboard restoration snapshot, keyboard and mouse monitoring and Application Aware detection; they can delete local data, saved recordings and their account at any time.
- Incident management: personal data breaches are notified per Clause 9; the processor keeps records of incidents and of the measures taken.
- Assistance to the controller (Clause 8): the processor answers data subject requests forwarded by the controller, provides the information in this DPA and the Privacy Policy for data protection impact assessments, and provides copies of transfer safeguards and sub-processor terms on request.
Annex IV — List of sub-processors
The controller has authorised the use of the following sub-processors. The same list is published, and kept current, in the Privacy Policy at writing-ant.com/privacy#subprocessors; changes are announced per Clause 7.7. The rows marked as handling Customer Content are the only parties that may see Customer Content: Microsoft Azure and OpenAI for the text users send for editing, and Microsoft 365 only for material a user includes in a support request; the others process account, billing or consent data.
Sub-processors handling Customer Content
Sub-processors handling account, billing and consent data
Questions and signed copies
Questions about this DPA: info@oegren-digital.ch. A countersigned PDF, a transfer impact assessment summary or copies of sub-processor terms: sales@writing-ant.com.