Privacy policy
How this platform processes personal data — under the revised Swiss Federal Act on Data Protection (revFADP / revDSG).
Note
Draft / template
Before go-live, [FIRMENNAME] must fill in the real details and have this text reviewed legally. All placeholders in square brackets still need to be replaced; this text is not legal advice and is not yet binding.
Data controller
Responsible for processing personal data in connection with this platform ([PRODUKTNAME]):
- [FIRMENNAME]
- [ADRESSE]
- [PLZ ORT], Switzerland
- Data protection contact: [DATENSCHUTZ-KONTAKT]
What data is processed
Only personal data that is necessary to operate the platform is processed:
- Account and company data: name, email address, company name, role and any further details provided during registration or in the settings.
- Content data: data created through use of the platform — such as customer and contact records in the CRM, documents, receipts and accounting data, and website content.
- Usage and log data: technical details such as IP address, time of access, browser and device information, and security-relevant events (audit log).
- Communication data: content and metadata of messages sent through the platform (e.g. transactional emails).
Purposes of processing
The data listed above is processed for the following purposes:
- Providing, operating and maintaining the platform and its modules (CRM, documents, accounting, marketing, website, lead acquisition).
- Performing the usage contract and managing the customer account.
- Security, abuse prevention, error analysis and traceability (audit log, rate limiting).
- Complying with legal obligations, in particular the retention requirements for business and financial records.
- Communicating with users (e.g. invitations, notifications, support).
Legal basis
Personal data is processed in line with the principles of the revised FADP: lawfully, in good faith, proportionately and for a specific purpose.
Processing takes place where it is necessary to perform the contract, is based on an overriding legitimate interest of [FIRMENNAME], is required by law, or is covered by consent. Any consent given may be withdrawn at any time with effect for the future.
Data processors
Carefully selected data processors are used to operate the platform. They process personal data solely on instructions and under a data processing agreement:
- Supabase — database, authentication and hosting of application data (data centre in the EU region). Data processing agreement: [LINK ZU DEREN DPA].
- Vercel — hosting and delivery of the web application. Data processing agreement: [LINK ZU DEREN DPA].
- Resend — sending of transactional emails. Data processing agreement: [LINK ZU DEREN DPA].
- Anthropic — AI-assisted processing of content (receipt recognition / OCR, document polishing, lead briefings and assistant features). Data processing agreement: [LINK ZU DEREN DPA].
AI processing of content
Only the content required for the respective feature is transmitted to Anthropic (e.g. the photo of a receipt). Processing is governed by the data processing agreement ([LINK ZU DEREN DPA]). Every AI use is logged internally.
Disclosure and transfer abroad
Personal data is not sold to unauthorised third parties. Disclosure takes place to the data processors named above and, where legally required, to authorities.
Individual processors may process data abroad (in particular in the EU and the USA). Data is transferred abroad only where an adequate level of data protection is ensured — for example by a recognised adequacy decision, standard contractual clauses, or equivalent safeguards within the meaning of the revised FADP.
Retention
Personal data is retained only for as long as necessary for the stated purposes or required by law.
Business and financial records (e.g. invoices, receipts, bookings) are retained for ten years in accordance with the statutory retention obligation (Art. 958f Swiss Code of Obligations). During this period, financial data is not deleted but only reversed or archived.
Log and security data is deleted automatically after an appropriate period.
Your rights
Within the scope of applicable law, data subjects have in particular the following rights:
- Access to whether and which personal data is processed.
- Rectification of inaccurate personal data.
- Erasure of personal data, unless a statutory retention obligation applies.
- Data portability: release or transfer of self-provided data in a common electronic format.
- Objection to certain processing, and withdrawal of consent given.
- Restriction of processing.
To exercise these rights, a message to the data protection contact named below is sufficient. There is also the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC).
Contact
For questions about data protection or to exercise the rights listed above, data subjects can contact:
- [FIRMENNAME]
- [DATENSCHUTZ-KONTAKT]
Version
This privacy policy may be adjusted if the processing or the legal framework changes. The version published on this page at the time applies.
Last updated: [DATUM].