Movemio · Version 2026-08-09
Data Processing Agreement (DPA)
This agreement governs the processing of personal data by Flow Force One GmbH, Weierstrasse 1, 8712 Stäfa, Switzerland, as the operator of Movemio on behalf of the moving company using the service. It applies to Movemio functions for which the company determines the purposes and essential means of processing and Movemio processes the data for the company.
1. Roles and scope
The moving company is the controller or principal for processing it commissions. To that extent, Flow Force One GmbH acts as processor under the Swiss Data Protection Act and, where the General Data Protection Regulation applies, as processor within the meaning of Article 28 GDPR.
Processing for which Movemio determines its own purposes and essential means – in particular company accounts, contract administration, billing, platform security, abuse prevention and legal records – is covered by the company privacy information. These areas of Movemio’s own responsibility are not part of processing on behalf of the company.
2. Subject matter, purpose and duration
The subject matter is the technical provision of digital captures through customer links and on-site visits, including structured capture, delivery of necessary communications, storage, provision of results in the company workspace, and associated operations and support services.
Processing begins when a commissioned function is used and continues until the company account or relevant matter is closed. Specific link and access periods limit public access but do not automatically delete every matter, contract or evidence record.
3. Nature of processing
Depending on the function used, processing may include collecting, recording, organising, storing, structuring, analysing, transmitting, making available, matching, restricting, deleting and anonymising data. Movemio does not process the data for its own advertising purposes under this agreement.
4. Types of data and data subjects
Data may include contact and address details, moving and appointment data, property and access details, inventory, quantity, volume and weight data, photographs and resulting structured outputs, voluntary notes, and technical delivery, access and security data.
Data subjects include in particular the company’s customers, people moving, household members, contacts at the origin or destination, and the company’s staff and contractors. Special categories of personal data should be entered only where required for the specific instruction, legally permitted and expressly instructed by the company.
5. Company instructions
Movemio processes commissioned data only under this agreement, the selected product functions and the company’s documented instructions. Use of a function, an entry in the company workspace or a support instruction given in text form may constitute a documented instruction.
If Movemio considers an instruction to infringe data-protection law, Movemio informs the company and suspends the affected instruction pending clarification, unless mandatory law requires otherwise. The company remains responsible for the lawfulness of its collection, instructions and use of results.
6. Movemio obligations
- Commissioned data is processed only on documented instructions and for the agreed purpose.
- Authorised persons are bound by confidentiality and receive only the permissions required for their duties.
- Movemio maintains required records and evidence and provides the information needed to assess compliance with this agreement.
- Any divergent processing required by law is disclosed to the company in advance where such disclosure is legally permitted.
7. Technical and organisational measures
Movemio protects commissioned data according to risk through role and permission controls, tenant separation, encryption in transit and at rest, logging of security-relevant events, secured development and operating processes, backup and recovery procedures, vulnerability and abuse protection, and controlled retention and deletion processes.
The measures are reviewed and developed regularly, taking into account the state of the art, implementation costs, and the nature, scope, context and risks of processing. Material changes must not reduce the agreed level of protection.
8. Subprocessors
The company gives Movemio general authorisation to use the subprocessors required for hosting, databases, transactional email and SMS, payment, analysis, security and technical operations. The current service-provider categories form part of the transparency for this agreement.
Movemio binds subprocessors to at least equivalent data-protection, confidentiality and security requirements. The company is informed of material changes before they take effect and may object on objectively justified data-protection grounds. If no appropriate solution can be found, the affected function or contractual relationship may be terminated under the platform terms.
9. Processing abroad
Where commissioned data is processed outside Switzerland or the EU/EEA, Movemio first ensures a permitted basis and appropriate safeguards. These may include an adequacy decision, recognised standard contractual clauses and supplementary technical or organisational measures. On request, the company receives the information needed for its accountability.
10. Assistance and security incidents
Taking account of the nature of processing, Movemio assists the company with access, correction, deletion, restriction, objection, data delivery, data-protection impact assessments and supervisory-authority consultations. Data-subject requests concerning commissioned data are forwarded to the company without Movemio making its own decision.
Movemio informs the company without undue delay of any commissioned-data security breach of which it becomes aware and provides available information about its nature, scope, possible consequences and measures taken. The company decides on notifications to authorities or data subjects unless Movemio has its own legal notification duty.
11. Return and deletion
At the end of processing on behalf of the company, Movemio returns commissioned data in an available standard format or deletes or anonymises it, at the company’s choice and documented instruction. Legal retention duties and required contract, billing, security or evidence data remain unaffected; that data is restricted and used only for the relevant mandatory purpose.
12. Evidence and audits
Movemio provides the information and appropriate available evidence required to verify compliance with this agreement. Where there is a justified need, the company may, on reasonable notice, conduct a proportionate audit itself or through a qualified party bound by confidentiality.
Audits must protect trade secrets, other customers’ security and ongoing operations. Equivalent current reports or evidence are used first where sufficient. If there is a substantiated suspected breach of this agreement, Movemio’s assistance is not limited to existing reports.
13. Contractual status and precedence
This DPA forms part of the Movemio platform terms for moving companies. If it conflicts with general provisions, this DPA prevails for processing on behalf of the company. Mandatory Swiss data-protection law and, where applicable, the GDPR remain unaffected.