DATA SECURITY · SWITZERLAND · ALSO FOR CUSTOMERS ABROAD

Your data is held in Switzerland. And stays there

We build systems that read medical reports, process personnel files and check claim records. Data like that does not belong just anywhere. It is held in Swiss data centres, encrypted — and you can see at any time who opened it.

This applies even if your company is not based in Switzerland. For customers from the EU and from third countries, the Swiss location is the argument, not the obstacle — why, is set out below.

Located in SwitzerlandAlso for companies abroadStored encryptedEvery access logged

Four guarantees you can verify

Security is not a feeling and not a seal in the page footer. It consists of statements that are either true or not — and that you are allowed to check.

LocationProcessing and storage in Swiss data centres. No mirroring abroad, no relocation without your written consent.
EncryptionIn transit and at rest. The keys are held separately from the data, and every client has its own — access to one set of holdings opens no second one.
AccessGranted by role, revocable at any time, and revocation takes effect immediately. Every access is in the log — including every rejected one.
RetentionDeletion periods according to your specifications, not ours. On request from the backup copies as well, with confirmation.

For customers with sites outside Switzerland

A Swiss data centre is not an obstacle for you but the argument. What you need to know is set out here — not in the small print.

Your people may sit anywhereAccess is a question of role, not of location. Whoever works in Vienna, Singapore or São Paulo works on the same holdings — the holdings themselves do not move.
In writing, beforehandWe conclude the data processing agreement before the first document flows. We enclose the list of sub-processors unasked, together with their country of domicile.
Return and deletionYou get your data back at any time in a readable, open format. Deletion takes place on request, with written confirmation.

From the EU and the EEA

Transfer from the EU and the EEAThe European Commission recognises Switzerland as a country with an adequate level of data protection. Transfers from the EEA to Switzerland therefore need no standard contractual clauses.
Two legal orders, not oneThe basis is the revised Swiss Data Protection Act. For personal data from the EU the GDPR applies in addition — with rights of access, rectification and erasure for your data subjects.

Outside Europe

The location is the argumentFor customers from the USA, the Middle East or Asia, the advantage lies precisely in the data being held in Switzerland: a neutral legal space, no access through foreign group structures, a single place of jurisdiction.
No flow back to your home countryThe fact that your company is based in a third country does not move the data there. It stays in Switzerland, in the backup copies too.
Requests from authoritiesWe answer them exclusively on the basis of Swiss law and inform you about them as far as we are legally permitted to. Requests from foreign authorities are not served directly.
If you process personal data from the EUThen the GDPR applies to that data, regardless of where your company is based. We set the processing up accordingly — tell us at the first meeting.

Who gets to the data?

Five accesses to the same holdings, from three countries. Granting and rejection follow the role — an access from Zurich is rejected too if the authorisation is missing.

Access log · live0 of 0 granted
Rechenzentrum Schweizverschlüsselt gespeichert · Schlüssel getrennt verwahrt
Daten verlassen das Land nicht

Zugriffe auf denselben Bestand

  • R. Bianchi · accountingZurich · role with a key
    granted
  • Group auditFrankfurt · read access, time-limited
    granted
  • L. Moser · internshipZurich · role without read access
    rejected
  • S. Tanaka · claims reviewSingapore · role with a key
    granted
  • unknown counterpartorigin cannot be attributed
    rejected

The holdings do not move in any of the five cases. What is decided is the access, not the location — and the rejected access is logged just as the granted one is.

WHAT STANDS HERE, WE SET DOWN IN WRITING.

What does that mean?

Before the first documentThe data processing agreement, the location, the periods and the sub-processors are settled before any data flows — not afterwards.
Verifiable, not assertedYou may inspect the log and have the guarantees checked. We provide the documents for that.
The way out is includedYou get your data back in a readable format, and we delete it with confirmation. That is in the contract, not in goodwill.

This page describes how we work. It does not replace a contract — what is binding is what we set down in the data processing agreement and in the privacy policy.