Updated: · providers-2026-09-11
01Scope and acceptance
These terms apply when a service provider expressly accepts them as part of its EAID registration or service agreement with Swissi Holding AG. They govern that providerâs integration and receipt or use of EAID information and authority. A separately signed agreement takes precedence for an expressly conflicting provision within its scope; mandatory law prevails. The prohibition on sale, advertising and data brokerage and the requirement for holder-signed recipient authority are minimum conditions of EAID participation and prevail over a conflicting provider agreement.
The provider identifies its legal entity, service, accountable contacts, purposes, approved client applications, callback addresses and recipient keys. It keeps that information current and ensures that its personnel and contractors act within their recorded authority.
02Data-protection roles
Swissi determines the purposes and essential means of operating the EAID identity and authority service. A provider determines the purposes and essential means of its own service and its use of received information. Each fulfils its duties as controller for that processing, including transparency, lawful grounds, rights, security, retention and international transfers.
A particular operation performed solely on documented instructions requires a processing agreement meeting GDPR Article 28 and applicable Swiss law before that operation begins. Jointly determined purposes require an appropriate joint-controller arrangement. The actual allocation of purposes and decisions determines the role. Acceptance of these provider terms alone establishes neither of those additional arrangements.
03Requests and recipient limits
Request only the facts, representations and confirmation quality necessary for a specified lawful purpose. Present the recipient identity, exact fields, purpose, retention, onward recipients, destination countries and any future-update scope before holder approval. Establish the legal basis for your own collection and use, including the additional conditions for sensitive information.
Use information only within the approved package and applicable law. A fresh purpose or expanded disclosure requires the necessary fresh approval and legal basis. Sale of received personal information and sharing for advertising or data brokerage are prohibited. Combining profiles or using an EAID identifier to track a person across services requires a separately lawful, transparent and expressly authorised purpose within the permitted service scope.
Onward processing by your contractors must remain within the disclosed purpose, scope and safeguards, with appropriate processing agreements. A separate recipient or expanded purpose requires the applicable holder approval. A legal compulsion is assessed, limited and documented, with notification where permitted.
04Authority, validation and reliance
Validate the issuer, audience, signature, expiry, requested scope, selected profile and current authority before relying on an EAID response. Apply the relevant revocation and current-authority checks for each operation. A stored receipt records the event it covers; continuing authority requires its own current validation.
Define and own the requirements for your service. Evaluate confirmation source, fact coverage, binding, freshness, jurisdiction and any correlated evidence. A confirmation concerns an exact fact and version. Decisions affecting a person must support correction, challenge and human review as required by law.
For business acts, define the payload, parties, rights and consequences presented for signature and validate the resulting business transition. Record the actual actor and any organisational or machine authority. Apply the legal form and signature standard required for the transaction.
05Revocation, retention and rights
Stop future retrieval and use of authority when it is revoked, expires or fails current-authority validation. Restrict information already received to the retained lawful purpose and period. Delete or anonymise it when that purpose ends, subject to a specific preservation duty or legitimate claim.
Provide your own accessible route for access, correction, erasure, restriction, objection and portability requests. Cooperate with Swissi to locate relevant disclosures and correct inaccurate inputs. Keep sufficient request, approval, delivery, reliance and revocation evidence while limiting that evidence to its lawful retention purpose.
06Security and incidents
Protect client credentials and recipient keys, restrict staff access, maintain current software and implement appropriate technical and organisational measures. Separate production and test data and protect received information to a standard appropriate to its sensitivity.
Notify hello@swissi-ai.institute without undue delay after discovering a compromise affecting EAID credentials, authority or received information. Provide the known scope, time, affected records and containment steps through an appropriately secure channel, and update the notice as facts become available. Each party fulfils its own regulatory and affected-person notification duties within the applicable deadlines.
Provide proportionate evidence of compliance on a justified request. Any inspection must protect confidential material and unrelated personsâ data. Swissi can restrict an affected integration to contain a substantiated threat or material breach and provides the reason and a review route to the extent legally permitted.
07Commercial terms and closure
Charges, service levels and any support commitment require the separately accepted provider agreement. The Terms of Service provisions on intellectual property, business liability, changes, Swiss law and Zug jurisdiction apply to this provider relationship, with âaccountâ read as the provider integration where necessary.
On termination, the provider stops new EAID operations, revokes integration credentials and deals with retained information and evidence under these terms and applicable law. It informs affected customers of the consequences for its service and supplies an appropriate alternative access or closure route. Confidentiality, lawful retention, data rights and accrued claims continue for as long as their subject matter requires.